Privacy Policy
How we handle personal data, and your rights.
Last updated: 24-09-2026 · Version 1.5
This Privacy Policy explains how SMVMC.LDA (“NoteFit”, “we”, “our”, “us”) collects, uses, stores, shares, and protects personal data when you use the NoteFit website, mobile application, and related services (collectively, the “Service”).
By using the Service, you acknowledge this Privacy Policy.
1. Who we are
Data Controller
SMVMC.LDA
Avenida dom rodrigo da cunha 6, 6ºE
admin@notefit.app
2. Scope
This Privacy Policy applies to personal data we process when you:
- create an account on the NoteFit website or mobile app;
- sign in through your browser via our hosted authentication;
- use NoteFit as a coach, trainer, or other user;
- create or manage athlete profiles;
- create workouts, workout plans, macrocycles, mesocycles, and microcycles;
- share or accept access to athletes or training plans via invite links;
- contact us; or
- otherwise interact with the Service.
Minimum age. The Service is not intended for children under 16. We do not knowingly collect personal data from anyone under that age. Where the law of your country requires a parent or legal guardian to consent for someone aged 16 or 17, that consent must be in place before the account is used. If you are a parent or guardian and believe a child has given us personal data, contact admin@notefit.app and we will delete it promptly. Whether a 16- or 17-year-old needs that consent depends on where they live — under Article 8 GDPR each Member State sets its own digital consent age between 13 and 16 — so we tie the requirement to your local law rather than to a single figure. NoteFit is not designed for, marketed to, or directed at children under 16, and nothing in it is intended to appeal to them.
3. Personal data we collect
Depending on how you use NoteFit, we may collect:
A. Account and profile information — full name, username, email address, password or authentication credentials (or, when you sign in with Google or Apple, the account identifier and email address that provider returns), gender, year of birth, and the answers you give during onboarding: training experience, fitness goal, preferred training setting (for example gym or home — a category, never your location) and how you heard about NoteFit. We also store your language, measurement, theme and notification preferences, your progress through the in-app guided tour, and the date on which you accepted these documents. Name, username, gender, year of birth and training experience are required to finish onboarding; the fitness goal, training setting and referral answers can be skipped.
B. Athlete records you create — for each athlete profile: full name, sex, nationality, and optionally a date of birth, an email address, a telephone number and a photo. Only the name is required. If you are a coach these details describe another person, and §4 explains your responsibilities for them.
C. Body measurements and training data — optionally, for each athlete: body weight, height, muscle mass, fat mass, body-fat percentage, basal metabolic rate, visceral fat level, testosterone level, somatotype, and how and with which scale a measurement was taken. On a training cycle you may also set a minimum and maximum daily calorie target. Training content itself: workout plans, macrocycles, mesocycles, microcycles, exercise selections, sets, reps, loads, rest times, completion state, and any free-text comment you write on a workout.
D. Photos — the profile photo you set for your own account, and the photo you may attach to an athlete record. Both are uploaded to private, access-controlled storage and are readable only by you and by accounts you have shared that athlete with. Photos and videos you pick as a background in the share composer are different: they are combined with your workout card on your device and handed straight to the app you choose to share with. They never reach our servers.
E. Sharing and collaboration data — the inviter, the invitee, the resource shared, the granted role (viewer/editor), the share code, its expiry, and timestamps for invite, accept and revocation events. A share link also carries a copy of the training content being shared, so that whoever opens it can preview and import it. For each training cycle, training week and workout we also record which account created it, which account changed it last, and when, so that a plan several people work on says who did what. Anyone with access to that resource can see it, and a share link never carries it. Records created before 19 September 2026 carry no author. If you delete your account, your identifier is removed from these fields on rows that remain with the athlete's owner.
F. Technical, usage and diagnostic data — when you have accepted analytics: product-usage events (screens opened, features used, forms started and completed) together with the app version, the platform, an identifier for that single app launch, and a visitor identifier that persists in a first-party cookie so that a returning visit is counted once rather than twice. That visitor identifier is created only once you accept, and it is erased if you later withdraw. Whether or not you accept, we record one reliability signal: an error that was shown to you, with a redacted description of what failed. On the website we process your IP address, browser type and device information as part of serving the site, and we derive from that request a two-letter country code which is stored on each analytics record; the IP address itself is not stored on those records. The mobile app no longer resolves a country and stores none on any record. A network request cannot hide the address it comes from, so the server receiving an event does see the connection’s IP address; we do not store it on the record, and on mobile we no longer derive anything from it.
F2. Service state that is not analytics — a small amount of usage state is stored because a feature depends on it rather than to measure you: which athletes you opened most recently, so the app can offer a “recently opened” list, and how far you got through the in-app guided tour.
G. Push notification registration — if you allow notifications: the push token issued by the operating system through the Expo push service, the platform (iOS or Android) and the app version. We collect no device identifier and no advertising identifier. The mobile app contains no advertising or third-party tracking software of any kind; on the website the only third-party analytics is Google Analytics, which loads solely after you accept it (§8).
H. Communications — messages, support requests, feedback, survey responses.
4. Special-category data / health-related data
Some of the data listed in §3C relates to physical condition and may qualify as health data under Article 9 GDPR: body weight, height, muscle mass, fat mass, body-fat percentage, basal metabolic rate, visceral fat level, testosterone level, and the calorie targets set on a training cycle. All of it is entered by hand — NoteFit reads no health platform, no wearable and no device sensor, and asks for no health, activity-recognition or body-sensor permission.
NoteFit is a training planning and logging tool. It is not a medical device, it does not diagnose, treat, monitor or prevent any condition, and nothing it displays is medical advice. See our Fitness Disclaimer.
Where required by law, we will only process such data when a valid legal basis applies. If you record information about other individuals — an athlete or a client — you decide what to enter about them, and you are responsible for having an appropriate legal basis and any required permission before you submit their name, contact details, date of birth, photo or body measurements to the Service. That person can ask us to delete their data through the contact address in §14, and we will act on it even where the record was created by someone else.
5. How we collect data
We collect personal data:
- directly from you when you sign up, fill in forms, or use the Service;
- from your actions inside the website or app;
- from our authentication and infrastructure providers (e.g. Supabase);
- from your browser or device through logs, cookies, local storage, session storage, and similar technologies (web only — see §8);
- when another user invites or shares a resource with you, we record the relationship and the granted role.
6. Why we use personal data
We use personal data to:
- create and manage user accounts and browser sessions;
- provide the Service and its features;
- store and organize athlete and workout data;
- enable planning, tracking, and training workflows;
- process sharing invitations and collaboration permissions;
- send transactional emails (sign-up confirmation, password reset, share notifications);
- personalize the user experience;
- provide customer support;
- improve performance, reliability, and security;
- detect fraud, abuse, and unauthorized activity;
- comply with legal obligations;
- communicate service-related notices and updates.
7. Legal bases for processing
Where the GDPR or similar laws apply, we rely on:
- Performance of a contract — to provide the Service you request.
- Legitimate interests — to improve, secure, maintain, and operate the Service.
- Consent — where required, including for non-essential cookies, web analytics, and marketing emails.
- Legal obligation — where we must process data to comply with applicable law.
If we rely on consent, you may withdraw it at any time.
8. Cookies, local storage, and similar technologies (web)
The NoteFit website uses cookies, browser local storage, and session storage to:
- keep you signed in (Supabase Auth session cookies — strictly necessary, set regardless of consent);
- remember your theme, language, and unit preferences (functional, first-party only);
- measure aggregated product usage via Google Analytics — only after you accept the cookie banner. If you decline, no analytics cookies are set and Google Analytics is never loaded.
Analytics require your consent. Product-usage analytics — which screens you visit, which features you use, how you move through the app — are optional on both web and mobile. Nothing optional is collected until you actively accept, and neither choice is preselected. You can change your mind at any time in Account → Analytics on the web or Settings → Analytics in the mobile app; turning it off stops further optional collection immediately. NoteFit works exactly the same either way — no feature depends on accepting.
What we keep regardless. One signal from the app or website is not covered by that choice and relies on our legitimate interests: an error that was shown to you. It records what failed and where, with emails, identifiers, quoted values and long digit sequences removed before it leaves your device, and the message and stack trace truncated. It exists so that a broken release is still visible to us when nobody has accepted analytics. It names the screen you were on and the action that failed, because an error with no location in the app is not actionable; it is written only when something fails, never as you move around, so it cannot describe how you use the app. On the website such a record also carries the country we derive from the request; in the mobile app it does not, because the app no longer resolves a country at all.
Until September 2026 three further signals were also exempt: failed sign-ins, failed sign-ups and failed saves. Current versions of the app and website no longer emit them, and the exemption has been withdrawn, so a version released from September 2026 onward collects none of them without your consent. Records gathered under the old exemption, including from installed older app versions that have not yet been updated, are retained under §10 and can be erased on request under §11.
One further record is made server-side. If you connect an AI assistant (§9), we log each tool call it makes on your behalf — the tool name and the time, linked to your account, never the training data itself. That log is how we keep the connector secure and within its limits, so it does not depend on your analytics choice either.
A second server-side record is your daily presence. On each day you use NoteFit while signed in, our servers note that your account was active, on which platform — web, iOS or Android — and how many times it was opened. The date, the platform and a count: nothing else. No screens, no actions, no session identifier, no IP address, no device information, and nothing is stored on or read from your device to produce it. It relies on our legitimate interests (Art. 6(1)(f)) in knowing whether the service is actually being used and whether a release reached people, because the analytics above only ever describe those who accepted them. It cannot describe how you use NoteFit, only that you did. You can object to it at any time, and it is kept for 400 days and removed with your account.
The NoteFit mobile app does not use browser cookies. It uses secure on-device storage (encrypted via the OS keychain or equivalent) for authentication tokens and preferences. See our separate Cookie Policy for the full list of cookies and vendors.
9. Sharing of personal data
We share personal data only with the following categories of recipients:
- Other users you have invited. When you share an athlete or training plan, the recipient sees only the data within that shared resource.
- Anyone holding a share link you created. A share link is an unguessable 128-bit code. It is not listed anywhere and cannot be found by guessing, but it is not password-protected either: whoever has the link can open the preview until it expires or you revoke it. The preview shows the title, a short subtitle and the training content being shared — never an athlete’s contact details, photo or body measurements, and never anything about your account beyond what you put in that title. Revoke a link at any time from the share screen.
- AI assistants you connect. Only if you choose to connect an assistant (Claude, from Anthropic PBC, or ChatGPT, from OpenAI L.L.C.) to your account through Account → Connected apps. You connect it with your own account at that provider, so they act for you rather than on NoteFit’s instructions. Nothing is sent unless you connect one, and you can disconnect at any time. Once connected, the assistant can read the training data your account can already see: your athletes’ names, sex, date of birth, nationality and body measurements — weight, height, muscle and fat mass, body-fat percentage, metabolic rate, visceral fat, and testosterone level where one has been recorded — together with their mesocycles, training weeks, workouts and exercises. If you leave edit access on, it can also create and change that training data. NoteFit does not disclose athletes’ contact details (email address, telephone number) to the assistant. What the assistant receives is then handled under that provider’s own terms and privacy policy, and may be processed outside the EEA. If you coach other people, connecting an assistant sends their data too — satisfy yourself that you may share it before you connect.
- Service providers acting on our instructions:
- Supabase Inc. — database, authentication, and storage hosting.
- Netlify, Inc. — website hosting and edge delivery.
- Resend, Inc. — transactional email delivery (sign-up confirmation, password reset, share-accepted notifications).
- Google LLC (Google Analytics) — aggregated, opt-in web product analytics. Loaded only after you accept the cookie banner.
- 650 Industries, Inc. (Expo) — issues the push token for your install and relays a notification to the platform service. It receives the token and the notification, not your training data.
- Apple Inc. and Google LLC — for mobile app delivery and push-notification routing (APNs / FCM) on iOS and Android. Google Firebase Installations, which the Android notification service requires, generates an installation identifier held by Google; NoteFit never reads or stores it.
- Authorities, if legally required by valid court order or law.
- In a corporate transaction (merger, acquisition, asset sale), data may be transferred to the successor entity, subject to this Policy.
We do not sell personal data. We do not share personal data with advertisers.
10. Data retention
We retain personal data for as long as your account is active or as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements.
When you delete your account (Account → Delete account on the web, or Settings → Danger Zone → Delete account on mobile), we delete or anonymize your personal data, subject to legal retention obligations. See our Data Deletion Policy for what is removed immediately, what is removed within 30 days, and what is retained for legal evidentiary purposes.
11. Your rights
Depending on your jurisdiction, you may have the right to:
- access your personal data;
- rectify inaccurate personal data;
- erase your personal data;
- restrict or object to processing;
- data portability;
- withdraw consent;
- lodge a complaint with a supervisory authority.
To exercise your rights, contact us at admin@notefit.app. We will respond within the timeframes required by applicable law (typically one calendar month under GDPR Art. 12(3)).
Data portability (Art. 20) — how the export is delivered. You can request a machine-readable copy of your data from Account → Data export in the web app, or Settings → Privacy & Legal → Request a data export in the mobile app. We prepare the export as a structured JSON document, usually within a few minutes, and place it in private, access-controlled storage that only your own account can read. The export is never sent by email and never stored in publicly accessible storage. It is kept for 7 days and is then deleted automatically. Downloading it directly from the app is being finished; until that ships, write to admin@notefit.app after requesting and we will hand you the file over a link only your account can open, within the time limit in this section. Exports are free. A new request is accepted once any request in progress has finished and once 30 days have passed since your last completed export — the limit Art. 12(5) allows for repetitive requests. If you need one sooner, write to us and we will arrange it.
12. Security
We protect personal data using industry-standard measures including TLS in transit, encryption at rest (via Supabase), hashed passwords (managed by Supabase Auth), row-level security policies, least-privilege access for our staff, and routine monitoring. However, no system is completely secure, and we cannot guarantee absolute security. If we become aware of a breach involving your personal data, we will notify you and the competent supervisory authority within the timeframes required by applicable law.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time.
If we make material changes, we will provide notice by appropriate means, such as through the Service or by email. The “Last updated” date at the top indicates when this Privacy Policy was most recently revised. Each substantive update increments the version number; you may be prompted to re-accept the policy on your next sign-in.
14. Contact
If you have questions about this Privacy Policy, contact us at:
SMVMC.LDA
Avenida dom rodrigo da cunha 6, 6ºE
admin@notefit.app
Operated by SMVMC, LDA. For privacy questions, email admin@notefit.app.