Privacy Policy and Data Protection
Last updated: 2026-07-29
Before using this application we need you to read and accept how we handle your data. Because health data is involved, the law requires your explicit consent.
1. Data controller
The controller is your personal trainer, who decides about the data you record in this application in order to provide you with training and follow-up services.
- Contact for any question about your data: support@impetus.fit (platform support, who forwards your request to the controller)
2. What data we process
To provide the service we process:
- Identification and contact data: name, email address and profile picture (avatar), if you upload one.
- Health and physical data (special category): body weight, measurements, age, height, body progress photographs and how your workouts felt.
- Nutrition data: logged meals, photographs of your dishes, calories and macronutrients, goals and any allergies or intolerances you declare.
- Activity data: assigned routines, completed workouts, loads and personal records.
- Wearable data (optional): if you connect your Polar or WHOOP device, we process the health data stored in that account —heart rate, steps, sleep and its stages, recovery, heart rate variability, daily strain, workouts and GPS routes— so that your trainer can see it. Only if you connect it, and with a separate consent shown at that moment explaining what each device reads; you can disconnect it whenever you want from Settings, and when you do you may ask for everything already fetched to be deleted.
- Communications: the messages you exchange with your trainer in the chat and the documents you share.
- Technical data: the minimum required for push notifications and for the app to work.
3. For what purpose
- To design, adjust and follow up your training and nutrition plan, including the routines and meal plans produced with the help of artificial intelligence.
- To communicate with you and send you notices related to your follow-up.
- To analyse your progress in order to help you improve your results.
4. Legal basis
Processing is based on your consent (art. 6.1.a GDPR), which you give by signing this document. As it includes health data (a special category), your consent is explicit (art. 9.2.a GDPR). You may withdraw it at any time, without affecting the lawfulness of processing carried out beforehand.
5. Recipients and processors
Your data is hosted on Microsoft Azure servers in the European Union. We rely on the following processors and services, only for the stated purpose and without transferring your data for commercial purposes:
- OpenAI: to estimate calories from the photos of your dishes, generate nutrition advice and plans, and create routines and exercise images with AI. It processes the text and images needed for that purpose; they are not used to train its models.
- Google (YouTube): to search for demonstration videos of exercise technique. Google fonts are also used on the public pages.
- Google (Firebase, servers in Belgium): technical operating logs —which operation was requested, whether it succeeded and how long it took— to detect errors and outages. No personal data travels there: no names, no email addresses, no messages, no photos, no health data. Your identifier is sent converted into an irreversible code, so it can group requests but cannot identify you. These logs are deleted automatically after 48 hours; only a daily count without identifiers is kept.
- Polar (Polar Electro Oy, Finland) and WHOOP (WHOOP Inc., United States): only if you connect your device, through their authorisation system (OAuth), to fetch your activity and rest data. It is read only; nothing is ever written to or modified in your account.
- Push notification services of your browser or operating system, to deliver notices to you.
We do not sell or transfer your data to third parties for commercial purposes.
6. Shared routines
Your trainer can publish a routine at a public link (a web page with the exercises, images and videos of that routine). Those pages do not include your personal data (not your name, not your weight, not your progress): only the training content. The trainer can disable the link at any time.
7. Retention
We keep your data while your account is active and a training relationship exists. Inbox notices are deleted automatically after 48 hours. When you request cancellation or erasure, your data will be deleted unless there is a legal obligation to keep it.
8. Your rights
You may exercise at any time your rights of access, rectification, erasure, objection, restriction and portability, and withdraw your consent, by writing to support@impetus.fit. That mailbox is attended by platform support, who forwards your request to the controller and confirms the response to you. If you consider they have not been addressed, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).
9. Security
We apply technical and organisational measures to protect your data: encryption in transit, restricted access and private storage of your photographs and documents.
10. Automated decisions
The AI features (calorie estimation, advice, plans and routines) are indicative and do not constitute automated decisions with legal effects: your trainer always supervises your follow-up.
11. Your consent
By signing I declare that I have read and understood this policy and I consent to the processing of my data, including health data, for the purposes described.
← Back to the appapp.impetus.fit · By DRPINOCODE.COM