Privacy Policy
Last updated: July 27, 2026
Scope
This policy covers the OmniFit website and coach workspace, and the OmniFit mobile application for iOS and Android. If you use OmniFit because a coach invited you, the “Coaches and shared data” section below also applies to you.
What we collect
We collect only what the product needs to function. We do not run advertising, we do not use third-party analytics or tracking SDKs, and we do not sell or rent personal data.
Account: email address, display name, and your password stored only as a one-way hash. If you use Sign in with Apple, the identifier Apple returns and the email address Apple shares with you, which may be Apple’s private relay address. Invitation records linking a student to the coach who invited them.
Training: workouts you log — exercises, sets, weight, repetitions, RPE and set type; routines and programs; personal records and estimated one-rep-max history; custom exercises and any changes you make to an exercise’s muscle-contribution split.
Health and wellness, always self-reported by you: daily check-in ratings for sleep, stress, fatigue and muscle soreness; body weight, height and optional circumference measurements. We use these solely to compute the training-load and recovery-context metrics shown to you. We do not read from Apple Health, HealthKit or Google Health Connect, and we access no sensor, step or heart-rate data.
Content: messages between you and your coach, coaching notes, and a profile photo if you upload one.
Technical: a user identifier and session tokens; IP address and request metadata used for rate limiting and abuse prevention; error and availability logs.
Not collected: location, contacts, calendar, microphone, browsing history, advertising identifiers, or any cross-app tracking data.
Not medical data processing
OmniFit does not provide medical advice, diagnosis, or injury prediction, and is not a medical device. Every metric is an estimate produced by a model from the data you entered.
How your data is stored on your device
On iOS and Android your login token is stored in the operating system’s secure storage — Keychain or Keystore. Unsent workouts and check-ins may be stored on your device so a poor connection or the app closing does not lose your session; they are removed once the server confirms them. On the web the login token is kept in memory only, so reloading requires signing in again — this means a browser-based attack cannot recover a long-lived token from browser storage.
Why we process it
Operating your account and showing your analytics: performance of a contract. Processing health and wellness inputs to produce readiness and load metrics: your explicit consent, which you can withdraw at any time by not completing daily check-ins — the rest of the app continues to work. Sharing data with a coach you are connected to: performance of a contract. Abuse prevention, rate limiting and security logging: legitimate interests. Legal and accounting obligations: legal obligation.
Sharing
We do not sell personal data. We share it only with infrastructure providers that host the application, database and file storage and send transactional email, acting on our instructions; with your coach, if you are connected to one; and with authorities where legally required. If we later add a payment or subscription provider, this policy will be updated before that provider processes any of your data.
Coaches and shared data
If you join a coach’s workspace, that coach can see the data needed to coach you: your logged workouts, programs, personal records, daily check-in entries and the metrics derived from them, body measurements, and your messages with them. Your coach cannot see data from any period in which you were not connected to them, and cannot see other coaches’ athletes. When the coaching relationship ends, the coach’s access ends. Independent athletes are not connected to any coach, and no one else can see their data.
International transfers
OmniFit is operated from Türkiye. If you are in the European Economic Area or the United Kingdom, your data may be transferred outside that area. Where that happens we rely on appropriate safeguards, including standard contractual clauses with our providers.
Security
Passwords are stored using one-way hashes. Raw password-reset and invitation tokens are not stored in the database. Production safeguards include HTTPS, security headers, rate limits, access controls, session revocation on password or email change, and regular backups.
Retention and deletion
We keep your data for as long as your account is active. Security and audit logs are kept for a limited period for abuse prevention. Records we must retain for legal or accounting reasons are kept for the period the law requires, stripped of unnecessary identifiers where possible.
To delete your account, contact us at support@omnifitanalytics.com from the address on your account. We verify the request and complete it within 30 days. Deleting your OmniFit account does not cancel a subscription purchased through the App Store or Google Play — cancel that in your store account settings.
Your rights
Depending on where you live, you have the right to access your data, correct it, delete it, restrict or object to processing, withdraw consent, and receive a copy in a portable format. You may also complain to your local data protection authority — in Türkiye, the Personal Data Protection Authority (KVKK). To exercise any of these, write to support@omnifitanalytics.com. We respond within 30 days.
Children
OmniFit is not directed at children under 16 and we do not knowingly create accounts for them. If you believe a child has an account with us, contact us and we will remove it.
Changes
If we make a material change — for example adding a payment provider or an analytics tool — we will update this page and notify you in the app before the change takes effect.