Privacy Policy
Last updated: 1 August 2026
Data controller
Gabriel Pająk Rozwiązania Informatyczne
Wojska Polskiego 267, 05-152 Janów Mikołajówka, Poland
NIP 8191670978
Privacy contact: privacy@hirdfit.com
Hirdfit is a fitness app for planning running routes, keeping your workouts in one place, and
tracking body measurements. This policy explains exactly what data the app handles, who it is
shared with, and what you can ask us to do with it. It covers the Hirdfit mobile app, the web app
at hirdfit.com, and the API at api.hirdfit.com.
Most of what Hirdfit stores is health data — training records, heart rate, body measurements. Under the GDPR that is a special category of personal data, and we treat it as such.
1. What we collect
Account
- Your display name and email address, and a timestamp that is set when the account is created and refreshed each time you sign in.
- Your password is handled by Firebase Authentication and is never visible to us. If you sign in with Google, we receive your Google account identity but not your Google password.
- Your height, if you enter it.
- A record that you accepted these documents: which version, and when. Your explicit consent to us processing your health data is recorded separately, with its own timestamp, because it is a separate decision (see section 3).
- A record that you were shown the notice about the AI coach sending data outside the EU, if you have used the coach.
Workouts
- Workout title, type (strength or cardio), start time and duration.
- For strength sessions: every exercise title, any notes you type against an exercise, and every set — weight, repetitions, set type (including warm-up sets) and RPE.
- For cardio: distance, pace, moving time, sport type, average and maximum heart rate, and calories, where the source provides them.
Body measurements
- Any of: weight, body fat percentage, neck, shoulders, chest, waist, hips, bicep, forearm, thigh and calf, each with the date taken, plus any free-text note you add.
Running routes
- When you plan a route we use your device location, or a start point you drop on the map.
- Routes you save are stored with their start coordinate and the full route geometry.
AI coach
- The full text of your conversations with the coach, and the coach's replies.
- Your credit balance, and a record of each purchase and each charge.
Connected services
- The credentials needed to keep an integration working: your Hevy API key, and your Strava access and refresh tokens.
What we do not collect
- No analytics and no crash reporting. The app contains no analytics SDK, no advertising SDK and no third-party tracker.
- No advertising, and no sale of personal data — not now, and not planned.
- Our API servers do not write your IP address to any log. The server does resolve your real address — it needs it to rate-limit abuse — but the logger is deliberately configured to drop it, along with request query strings and authorization headers. Note that this is not true of every party below: Firebase Hosting does see your IP address, because your device contacts it directly.
- Map tiles are fetched by our server, not by your device. The map images you see are requested from MapTiler by the Hirdfit API on your behalf, so the tile provider never receives your IP address. The app's typeface is bundled inside the app, so nothing is fetched from a font CDN either.
2. Where the data comes from
All training data reaches Hirdfit in one of four ways, all of which you choose to enable:
- You enter it — manual workouts, the live workout tracker, measurements.
- Hevy — if you supply a Hevy API key, our server fetches your Hevy workout history, including per-set detail.
- Strava — if you connect Strava, our server imports your activity list.
The permission Strava asks for (
activity:read_all) includes activities you have marked private on Strava. We import summary data only; we do not import GPS tracks. - Health Connect (Android) or Apple Health (iOS) — if you grant access, the app reads workouts and heart rate from your phone. On Android it also requests distance, calories and steps, because the platform requires those permissions before it will return the workout records at all; step counts themselves are never stored. All of these are read-only permissions and are read on your device.
You can disconnect any integration at any time. Disconnecting stops future imports; workouts that were already imported stay in your Hirdfit account until you ask us to delete them.
3. Why we use it, and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Storing and displaying your workouts, measurements and routes — health data | Your explicit consent, Art. 9(2)(a), given by ticking a separate box — not bundled into your acceptance of the Terms — when you create your account, or on your next sign-in if your account predates that box. Given again when you enable each data source. You can withdraw it at any time (section 8). |
| Running your account and providing the app | Performance of a contract, Art. 6(1)(b) |
| Answering your questions through the AI coach, when you use it | Performance of a contract, Art. 6(1)(b), plus your explicit consent for the health data involved, Art. 9(2)(a). Before your first coach message the app shows you a notice that your data is sent to Anthropic in the United States, and asks you to confirm you have read it. |
| Taking payment for coach credits and keeping accounting records | Performance of a contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c) |
| Keeping the service secure and working (rate limiting, error logs) | Legitimate interests, Art. 6(1)(f) |
We do not use your data to train any machine-learning model of our own, and we do not profile you for advertising.
4. Who we share it with
Hirdfit is a small operation built on third-party infrastructure. The table below lists every external party your data reaches, and exactly what reaches them.
| Recipient | What they receive | Why |
|---|---|---|
| Google / Firebase Ireland / USA |
Your account identity and every piece of content described in section 1. Firebase Hosting also sees your IP address when you load the web app. | Authentication, database and web hosting. This is where your data lives. |
| Anthropic USA |
Only if you use the AI coach or connect an external AI assistant. Your chat messages, and the training data the coach looks up to answer them: workout titles, dates, durations, per-set weights, repetitions and RPE, exercise notes, heart rate, calories, distances, paces, and your body measurements including any notes. Your display name and height are also included, because the coach's overview lookup returns them. Your email address, user id, IP address and route data are not sent, and neither are workouts imported from Strava, which are withheld from all AI features. | Generating the coach's replies. |
| Stripe Ireland / USA |
Only your Hirdfit user id, attached to the checkout session, plus the package and amount. Your card details and the email you give Stripe are collected by Stripe on their own payment page and never pass through our servers. Used for purchases made on the website only. | Taking payment for coach credits bought on the web. |
| Google Play Ireland / USA |
Purchases made in the Android app go through Google Play, which is the seller of record. We send Google a one-way scrambled form of your Hirdfit user id (a SHA-256 hash) so the purchase can be matched back to your account, and we ask Google to confirm a purchase you made. Your payment details, name and billing address are collected by Google under their own privacy policy and never pass through our servers; we cannot see what you paid, only which package you bought. | Taking payment for coach credits bought in the Android app. |
| Hevy USA |
Your Hevy API key, in order to read your own Hevy workout history. No Hirdfit data is sent to Hevy. | Importing your workouts, if you connect Hevy. |
| Strava USA |
Your Strava access token, in order to read your own activity list. No Hirdfit data is sent to Strava. | Importing your activities, if you connect Strava. |
| OpenRouteService (HeiGIT) Germany |
The start coordinate of a route you are planning, and any address text you type into the location search. No account identifier is attached — these requests are anonymous. | Calculating running routes and resolving addresses. |
| MapTiler Switzerland |
The coordinates of the map area on screen, requested by our server on your behalf. Your IP address is not sent, and no account identifier is attached — these requests are anonymous. | Serving map tiles. Map data is © OpenStreetMap contributors. |
| An AI assistant you connect yourself varies |
Only if you have AI access enabled and connect one. Read-only access to the same views the coach uses: your overview, workouts and per-set detail, exercise history, and body measurements — again excluding workouts imported from Strava. | Letting you query your own data from an assistant such as Claude. You choose whether to connect one, and you can disconnect it at any time. |
| OVH France |
Hosts our API server. Data is processed there in transit. | Server hosting. |
| Grafana Labs EU region |
Our server's technical logs and operational metrics: the method, route, status code and latency of each request, error messages, and security events such as failed sign-ins. No IP addresses and no query strings. Your account identifier appears only on payment events and on account-security events — for example, an account waiting for approval. No workout, measurement or coach-conversation content is included. | Monitoring that the service is up, diagnosing errors, and detecting abuse. |
The subprocessor list sets out which of these process data on our behalf, which are merely sources or direct connections from your device, and what agreement covers each.
We do not share your data with anyone else. We may disclose data if we are legally required to, and we would tell you unless prohibited from doing so.
5. Where your data is stored, and transfers outside the EU
Your data is stored in the European Union. The database sits in Google Cloud's
europe-west1 region in Belgium, our API server runs on an OVH machine in France, and
our server logs and monitoring metrics are held in Grafana Labs' EU-region service.
Some of the recipients in section 4 are based outside the EU — Anthropic, Stripe, Hevy, Strava, Google and Grafana Labs are US companies, even where the data itself stays in Europe. Where data reaches them, the transfer relies on the European Commission's Standard Contractual Clauses and, where the recipient is certified, the EU–US Data Privacy Framework. MapTiler is Swiss, a country the European Commission has found to provide an adequate level of protection, so no additional safeguard is needed there.
One point worth being explicit about: when you use the AI coach, your training data and the text of your messages are sent to Anthropic in the United States, under Anthropic's commercial API terms and the data processing agreement incorporated into them. Under those terms Anthropic does not retain conversation content by default — prompts and responses are not stored after the reply is returned — and retained data is never used to train models without express permission. The exception is content flagged by Anthropic's automated safety systems, which may be kept for up to two years. We have not negotiated an additional zero-retention arrangement; if that changes, this policy will be updated. If you would rather no training data left the EU, do not use the AI coach and do not enable AI access.
6. How long we keep it
| Data | Retention |
|---|---|
| Account, workouts, measurements, saved routes | Kept until you ask us to delete them, or until you delete them individually in the app. |
| AI coach conversations | Kept indefinitely until you ask us to delete them. There is currently no automatic expiry and no in-app delete for conversations. Email us and we will remove them. |
| Purchase and credit records | Retained for as long as accounting and tax law requires — under Polish law, five years from the end of the relevant tax year. These records survive account deletion, but your user identifier is replaced with an irreversible hash, so what remains is the amount, date and payment reference and cannot be traced back to you. Internal records of individual coach charges are deleted outright. |
| Integration credentials (Hevy key, Strava tokens) | Deleted when you disconnect the integration, or when the account is deleted. |
| Server logs | On our server, a rotating buffer of at most 30 MB per service, overwritten automatically. A copy is also sent to our monitoring provider (Grafana Labs, EU region), where it is kept for 14 days and then deleted automatically. Operational metrics — counts and timings, carrying no personal data — are kept for 14 days as well. Logs contain no IP addresses and no query strings; they do contain a user id on payment and account-security events. None of it is used for analytics. |
| Backups | We keep disaster-recovery copies of the database so a failure or a mistake on our side cannot lose your training history: a rolling 7-day point-in-time window and daily snapshots kept for 7 days. They are held by Google in the same Belgian region as the live database. Anything you delete disappears from the live service immediately and from these copies within 7 days, when they expire automatically. We do not read them except to recover the whole database, and we never use them to restore an individual account. |
7. Security
- All traffic is encrypted in transit (HTTPS).
- Database rules restrict every record to the account that owns it. Sensitive server-side collections — including your Hevy API key, your Strava tokens, coach billing records and AI-access credentials — are not readable by any client at all.
- AI access uses short-lived access tokens; refresh tokens are stored hashed and are single-use.
- Every endpoint is rate-limited per client, and security-relevant events — failed sign-ins, refused authorization requests, rate-limit trips — are recorded so we can spot an attack in progress. Those records identify the account where there is one; they never contain your IP address.
- The database is backed up daily and can be rolled back to any minute in the past seven days, so a fault on our side should not cost you your training history. Backups stay in the same Belgian region as the live data — see section 6 for what that means for deletion.
- No system is perfectly secure. If we ever suffer a breach affecting your personal data, we will notify the Polish supervisory authority within 72 hours and inform you where the law requires it.
8. Your rights
Under the GDPR you can ask us to:
- Access — get a copy of the data we hold about you.
- Rectify — correct anything inaccurate.
- Erase — delete your account and its data.
- Restrict or object to certain processing.
- Port — receive your data in a machine-readable format.
- Withdraw consent at any time. Withdrawing consent does not affect processing that already happened, and it means we can no longer provide the app — so in practice the way to withdraw it is to delete your account, which is self-service (below). We are honest that this is all-or-nothing: there is no way to keep the account but revoke the health-data consent, because the health data is the app.
Access and portability are self-service. Profile → Your data → Export my data gives you a single JSON file containing everything we hold about you.
Erasure is self-service too. Profile → Your data → Delete account deletes your account and its data from the live service immediately and irreversibly; disaster-recovery copies expire within 7 days (section 6). See how to delete your account for exactly what is removed and what is kept. Both actions are also available on the waiting screen if your account has not been approved yet.
You can delete individual measurements, saved routes and manually-entered workouts yourself, inside the app, at any time.
For anything else — rectification, restriction, objection, or deletion when you can no longer sign in — email privacy@hirdfit.com from the address on your account. We handle those manually and will respond within one month.
If you think we have handled your data badly, you can complain to the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland — or to the authority in your own EU country.
9. Children
Hirdfit is not for people under 16. You confirm that you are at least 16 when you create your account. We do not otherwise verify age, and we do not knowingly collect data from anyone under 16. If you believe a child has an account, email us and we will delete it.
10. Automated decision-making
The AI coach generates training suggestions from your data. These are suggestions only — they produce no legal or similarly significant effect, and no decision about you is made automatically. The coach can be wrong; see the Terms of Service for the medical disclaimer.
11. Changes to this policy
If we change this policy we will update the date at the top. For a material change, the app will ask you to read and accept the new version before you carry on using it — the acceptance we hold records which version you agreed to, so a new version means a new prompt.