Privacy Policy

Last updated: 22 July 2026
GiFit ("the app") is an offline fitness application. In short: the app does not collect, transmit or share any personal data. Two features use the network, and you turn both on: connecting your gym, and downloading the food catalogue for your country. Until you use them, the app makes no calls at all. We explain both in full below.

Data controller: GiHouse — info@gifit.it

Data processed and where it stays

All the data you enter — profile, food diary, workouts, body metrics, settings — is stored exclusively on your device. There is no account, and no server that keeps your data or that we could access to read it. The one exception is your gym, if you connect it yourself: from then on what you send it travels encrypted through a relay of ours, which cannot open it and deletes it shortly after — explained in full under “Your gym”.

No data collection

The app does not:

If you do not connect any gym and do not open the food catalogues screen, the app makes no network calls at all and this policy ends here. This is not a promise on our word: automated tests count the requests and fail if even one is made.

Permissions

Your gym (optional)

If you scan your gym's QR code, the app connects to it. From that moment your workouts are sent to the gym, and the routines it writes for you arrive on your phone on their own, passing through a routing server we operate.

What is sent. Your workouts (always) and, only if you enable them in the settings, your profile and your body measurements. The food diary is never sent, and it isn't even an option.

How it travels. Everything is encrypted for your gym's key before it leaves the phone, and the routines you receive are encrypted for a key that lives only on your phone. We do not have those keys: we cannot read your workouts or your routines, not even if we wanted to, and not even if an authority asked us to.

What our server sees. A code that identifies your phone (it is derived from your key and does not contain your name), a gym code, the encrypted content, its size and the date. On the server there is never your name, your email or any workout data in the clear. The match between that code and you as a person exists only on the gym's computer.

How long it stays. Content not yet collected is deleted after 90 days; once collected by the recipient it is deleted within 7 days. A link inactive for 180 days deletes itself.

Legal basis. Your consent, which you give by scanning the QR code and choosing what to share (art. 6(1)(a) and, for fitness-related data, art. 9(2)(a) GDPR). You can withdraw it at any time, without having to give any reason.

How to stop it. In the app settings you can pause syncing, narrow what you share, or disconnect entirely. When you disconnect, we delete the link from the server and your phone destroys its own key: from that moment nothing the gym might still send can be recovered.

What the gym has already received, however, stays theirs. A send cannot be undone: the downloaded copies are on the gym's computer, which becomes an independent data controller for them. To have them deleted you must ask the gym: we do not have them and cannot delete them on their behalf.

Food catalogues (optional)

The app does not ship with a food database: you download it, choosing the country where you shop. That is why the app is a third smaller, and why the database can be updated without waiting for a new release.

When a request is made. Only twice, and always because of something you did: when you open the "Food catalogues" screen (to read the list of available countries) and when you tap a country to download it. If you never open that screen, nothing is ever requested.

What is sent: nothing. It is the download of a static file, the same one for everybody, from a fixed address. It carries no identifier, no profile data, no counter, no parameter: the request is indistinguishable from anyone else's for the same file. Your food diary never leaves your phone, here or anywhere else.

What happens anyway, and must be said. Like every request on the Internet, this one communicates your IP address to whoever hosts the file. The catalogues are hosted by Cloudflare, Inc., acting as our hosting provider. An IP address is personal data, which is why we write it here instead of treating it as a technical detail. We neither receive nor keep those logs, we build no profile, and we have no way of knowing who downloaded what.

Legal basis. Performance of the request you made (art. 6(1)(b) GDPR): without communicating the IP address the file cannot be delivered to you, exactly as for any web page.

You can skip it. The app remains fully usable without ever downloading anything: your custom foods, your saved meals, the common foods included in the app and your entire history keep working. A downloaded catalogue can be removed whenever you like, from Settings, and your diary stays intact because every entry keeps its own nutrition values.

Your rights

Until you connect a gym we process no data concerning you: your data is on your phone and you manage it. Downloading a food catalogue creates no data at our end — the only thing that happens is the technical communication of your IP address to the provider hosting the file, whose logs we do not receive.

If you have connected a gym, encrypted content associated with a code — not with your name — exists on our server. The most direct way to exercise your rights is the app itself: by disconnecting you delete that content and the key immediately and on your own, without going through us. From the code alone we are unable to trace you (art. 11 GDPR): we do not keep or seek additional data for the sole purpose of identifying you, so to access or delete at your direct request we would need you to give us the information that links you to that code — and if you give it to us we will not refuse. For the data your gym has already downloaded, you exercise your rights toward the gym, which is an independent controller.

For any question: info@gifit.it. You also have the right to lodge a complaint with the Italian Data Protection Authority (the Garante per la protezione dei dati personali).

Data deletion

If you have not connected a gym, there is no data of yours to delete outside your own phone: there is nothing to ask us for, because we hold nothing. You delete the data you entered by uninstalling the app, or from Android Settings → Apps → GiFit → Storage → Clear data. The backup .zip file, if you created one, is wherever you saved it and you delete it yourself.

If you have connected a gym, you can delete everything yourself, immediately, without going through us: in the app, Settings → Gym → Disconnect. That command deletes the link from our server, erases encrypted content not yet collected, and destroys the key held on your phone — from that moment nothing from that link is recoverable by anyone.

If you would rather ask us in writing, write to info@gifit.it with the subject "Data deletion". We reply within 30 days (art. 12 GDPR). One honest caveat: on our server content is associated with a code and not with your name, so to act on a request we need you to give us the information that links you to that code (art. 11 GDPR). If you give it to us we will not refuse; if you no longer have it, disconnecting from within the app remains the fastest route and needs no cooperation from us.

Automatic deletion. Even if you do nothing, content not yet collected is deleted after 90 days, content already collected within 7 days, and a link inactive for 180 days is deleted on its own.

One limit we cannot get past. What your gym has already downloaded is on its computer and it is an independent controller of it: we do not have those copies and cannot delete them on its behalf. To have them erased you must ask the gym.

Backup

The backup feature creates a .zip file with your data and saves it wherever you tell it to, via the system picker. Managing that file is under your control; we have no access to it.

Purchases

The app is free to install. Unlocking the full feature set happens through Google Play; the related processing of payment data is governed by Google's privacy policy. We neither receive nor store your payment data.

Children's data

The app is not designed for children. Until you connect a gym, the app collects nothing from anyone, children included.

Connecting with a gym is based on consent: if you are under 14, consent must be given by whoever holds parental responsibility. If you train at a gym and a minor is using the app, the connection should be decided together with a parent.

This website

Everything written above concerns the app. The site you are reading is a separate thing: it is hosted on Netlify and counts visits with Cloudflare Web Analytics. No cookies, no identifier that follows you from one page to another or from one site to another, no profiling, no data handed to third parties. We see aggregate numbers: how many pages were opened and which ones, from which country, and which site people arrive from. There is no banner to accept because there are no cookies to accept.

Like any website, the server logs the IP addresses of requests for technical and security reasons: we do not use them to identify you, nor do we cross-reference them with anything else. Legal basis: our legitimate interest in knowing whether the site works and where visitors come from (art. 6(1)(f) GDPR).

In the app there is none of this: no analytics tool, not even an anonymous one. What is written in this paragraph applies only to these pages.

The gym form

On the "For gyms" page there is a form to request a quote. It is the only place in the whole site where you give us data of your own: name, email and — if you wish — phone, gym name, number of athletes and a message. Nothing else is collected, and the form is filled in only if you decide to fill it in.

The request is collected by Netlify, which hosts the site, and reaches us by email. We use it only to reply to you and prepare the quote you asked for: it is not a newsletter signup, you do not end up on any list, and we hand nothing to third parties. Legal basis: your consent and the performance of pre-contractual measures requested by you (art. 6(1)(a) and (b) GDPR).

We keep the request for as long as needed to handle the contact and the obligations arising from it. You can ask for its deletion at any time by writing to info@gifit.it: we delete it and that is the end of it.

Changes

Any updates to this policy will be published at this address with the relevant date.

Contact

For questions: info@gifit.it