← Back to NoteFit

Data Deletion Policy

What gets deleted, what is retained, and how to request deletion.

v1.1 · Last updated: 09-09-2026

This Policy explains what happens when you delete your NoteFit account, what is retained, for how long, and how to request deletion outside the in-app flow.

1. How to delete your account

Inside the app (preferred):

  • Mobile — Settings → Danger Zone → Delete account. Re-authenticate to confirm.
  • Web — Account → Danger Zone → Delete account. Re-authenticate to confirm.

Without using the app: email admin@notefit.app from the registered account address. We will verify the request and complete deletion within 30 days.

2. What is deleted immediately

  • Your user profile, preferences, photo URL.
  • Your athletes (the athlete records you have created).
  • All macrocycles, mesocycles, microcycles, workouts, and exercises you own.
  • Sharing relationships where you are the owner — recipients lose access at the next request.
  • Your notification preferences.

3. What is deleted within 30 days

  • Authentication data (Supabase Auth row, password hash, refresh tokens, device push tokens).
  • Uploaded files (profile photos) in object storage.
  • Cached / replicated copies in backup systems (subject to a 90-day backup-retention window).
  • Aggregated analytics events are unlinked from your account ID within 30 days; aggregated counts remain.

4. What is retained, and why

  • Consent acceptance log — up to 6 years (evidentiary defense of consent).
  • Deletion request log — up to 6 years (demonstrating GDPR Art. 17 compliance).
  • Billing / tax records — period required by applicable tax law, typically 6–10 years.
  • Support correspondence — 2 years from last contact.
  • Security and abuse logs — 1 year.
  • Aggregated, anonymized usage statistics — indefinite (no longer identifies you).

5. Data shared with collaborators

Resources you have shared with other users are removed when you delete the underlying resource. If a recipient has separately created their own copy or notes in their own account, we cannot delete that data without their authorization.

6. Athletes whose data you uploaded

Data you uploaded about athletes is part of your account and is deleted with your account. If one of those athletes contacts us asking to delete data uploaded about them by you, we will route the request to you as the controller for that data.

7. App-store-specific notes

  • Apple App Store — Account deletion is offered in-app on iOS per Review Guideline 5.1.1(v). This Policy is linked from the app's privacy disclosure.
  • Google Play — This Policy is publicly accessible at this URL per the Play Data Safety form.

8. Contact

admin@notefit.app
SMVMC, LDA., Portugal

Operated by SMVMC, LDA. For privacy questions, email admin@notefit.app.