Last updated · August 2026

Data Safety

Summary

Intense Fit collects only what is needed to run your training, recovery and coaching features. We do not sell data and we run no advertising trackers. Most collection categories below are optional and off until you switch them on. You can export or delete everything from Profile > Privacy & data.

Location — approximate (collected, required for basic hosting analytics)

Country-level approximate location derived from IP address by our hosting platform's built-in analytics. Purpose: analytics. Precise location is never collected, and no GPS permission is requested.

Personal info — name (collected, optional)

An optional display name, and a coach display name if you publish a coach profile. Purpose: app functionality, account management. Coach display names are visible to other users by design.

Personal info — email address (collected, required)

Required to create an account. Purpose: account management, app functionality, transactional email, and — only if you opt in — the weekly journal.

Personal info — user IDs (collected, required)

An account identifier, and a Stripe customer identifier if you subscribe. Purpose: app functionality, account management.

Personal info — other (collected, optional)

Coach credential details you submit for review (credential type, issuer, number, jurisdiction, expiry and supporting evidence), onboarding questionnaire answers, feedback and testimonials. Purpose: app functionality and, for credentials, fraud prevention and safety.

Financial info — purchase history (collected, optional)

If you subscribe, we retain subscription status and Stripe customer/subscription identifiers. Card numbers are handled by Stripe and are never seen or stored by Intense Fit. Purpose: app functionality.

Health and fitness — health info and fitness info (collected)

Fitness information is required for the core product: workout logs you create, including exercises, weights, reps, time under load, session dates, goals and derived progress. Health information is optional: readiness answers and any heart rate, resting heart rate, HRV, sleep, weight or body-composition data you choose to import or connect. Purpose: app functionality and personalisation.

Messages — other in-app messages (collected, optional)

Coach chat messages, coach notes, invitation messages and in-app notifications. Purpose: app functionality. Visible to the other participant in the conversation.

Photos and videos — photos (collected, optional)

Machine-scanner frames are sent through Lovable's AI gateway to the configured Google vision model only when you use the scanner; Intense Fit saves the resulting equipment details, not the source frame. A feedback screenshot is uploaded only while the visible attach option is enabled, and a Google profile image URL may be used as an avatar. Purpose: app functionality, support and account personalisation.

Photos and videos — videos (collected, optional, off by default)

Set recordings. New accounts start with recording and cloud sync switched off. When you enable recording, clips are stored on your device; when you also enable sync, they are stored privately in your account. Purpose: app functionality. Not visible to other users. Deletable at any time from Profile > Camera & recordings.

Audio — voice or sound recordings (collected, optional, off by default)

Three separate optional paths. (1) Microphone audio inside set recordings: the microphone switch is off for new accounts, and clips stay on your device unless you also enable sync. (2) Live coaching call audio: transported in real time to the other participant; call recording is disabled in this release, so no call media is stored. (3) Voice weight entry: while you hold the voice control during a workout, a short WAV clip is sent over your authenticated session to our transcription endpoint and forwarded to OpenAI's gpt-4o-mini-transcribe model through Lovable's AI gateway; only the returned text is used and the clip is not added to your clip library. Purpose: app functionality.

Calendar — calendar events (collected, optional)

Only if you connect Google Calendar. We store the connected Google account email and OAuth tokens, and read your events and create or delete Intense Fit workout events. Purpose: app functionality. Disconnecting, or deleting your account, revokes the grant and deletes the tokens.

App activity — app interactions (collected, required)

Screen and funnel events needed to run and improve the product, plus last-active timestamps used for reminders. Events are recorded without advertising identifiers. Purpose: analytics, app functionality.

App info and performance — diagnostics (collected, required)

We do not operate a third-party crash-reporting or session-replay SDK in this release. Server-side error logs may record an account identifier, the failing request path and technical diagnostic details for a limited period. Purpose: app functionality and stability.

Device or other IDs (collected, optional)

Only when you enable push notifications. OneSignal, our push processor, assigns and receives a push subscription / device identifier along with the push endpoint, its encryption keys and the technical browser and device information needed to deliver a message. No advertising ID, no device fingerprinting. Turning notifications off removes the subscription linkage held by the app. Purpose: app functionality.

Contacts, SMS, files, browsing history, precise location, installed apps

Not collected.

Data sharing

We do not sell data and we do not share data for advertising. Data is transferred to the vendors that run the service on our behalf under contract, and only for that purpose: Supabase (database, authentication, file storage), Lovable (hosting and built-in analytics), Resend (email delivery), Stripe (payments), LiveKit (live coaching transport), OneSignal (push notification delivery, only when you enable notifications), OpenAI through Lovable's AI gateway (only for the voice weight entry you invoke), Google (only when you sign in with Google or connect Calendar). None of these are advertising partners and none of this is sharing for advertising. Where you start a live coaching session or accept a coach, the audio, video and derived form signals you choose to share are transferred to that person at your initiation. We describe these as service-provider processing and user-initiated transfers rather than claiming nothing leaves the app.

Data is encrypted in transit

Yes. All traffic between the app and our backend uses HTTPS / TLS.

Data is encrypted at rest

Yes. The managed Postgres database and the file storage buckets are encrypted at rest by the provider.

Users can request data deletion

Yes. Profile > Privacy & data > Delete account, or https://intensefit.co/account-deletion, or email meunierfilipe@gmail.com. Personal data is removed within 30 days; backups purge on rotation. Shared gym, equipment and organisation records are kept with your authorship reference removed, and email suppression records are kept so we can never mail the address again.

Users can request data export

Yes. Profile > Privacy & data > Export my data returns an immediate JSON download, or email meunierfilipe@gmail.com. OAuth tokens, push keys and passwords are deliberately excluded from the export.

Independent security review

The app follows the OWASP Mobile Top 10 checklist. No third-party penetration test has been published yet.

Children and families

Intense Fit is not intended for users under 18 and is not part of the Designed for Families programme.

Android wrapper permissions

The Play wrapper declares android.permission.CAMERA and android.permission.RECORD_AUDIO. They are requested at runtime only when you affirmatively start camera/form analysis, a set recording, or a live coaching call, and only for trusted intensefit.co pages. You can deny or revoke both: workout logging and the exercise-demo fallback stay fully usable. This wrapper release does not request POST_NOTIFICATIONS, location or Health Connect permissions.

Not medical care

Training and recovery guidance in Intense Fit is not medical advice, diagnosis or treatment, and the app is not a medical device.

Contact

Privacy questions, deletion requests, data exports: meunierfilipe@gmail.com.