FitAIss
PLENContact

Privacy policy

FitAIss Privacy Policy

This Policy explains what personal data FitAIss processes, why it is needed, how long it is kept and what rights are available to the user.

Document version: 2026-07-27-v2. Effective 27 July 2026.

Controller

The controller is DAVISOFT sp. z o.o., ul. Konarskiego 22, 38-500 Sanok, Poland, KRS 0000874114, NIP 6871972749, REGON 387713266. Privacy enquiries can be submitted through the contact form or to biuro@davisoft.pl.

Account and authentication data

We process the user or guest identifier, email address, verification status, authentication provider, session and refresh-token records, plan, language, time zone, account timestamps and security metadata. Google sign-in may provide a Google subject identifier, verified email, profile name and avatar. Sign in with Apple may provide an Apple subject identifier, verified email or private relay address and, on first authorisation only, a profile name.

Wellness and diary data

Data entered by the user may include age year, calculation sex, height, weight, goals, meals, drinks, portions, calories, macros, hydration, exercise, habits, fasting, measurements, notes, recipes and shopping lists. Some combinations may reveal health information. Where Article 9 GDPR applies, FitAIss requests separate explicit consent under Article 9(2)(a). Before the first session is created, the user checks a separate 18+ field and a second field that includes explicit wellness-data consent. Despite the combined interface field, FitAIss records wellness consent as a separate versioned proof. Consent can be withdrawn in Settings without affecting earlier lawful processing; the diary, measurements, goals and dependent AI analyses then remain blocked until renewed consent or deletion of the affected data or account.

Photos, text, speech and AI

A meal or drink image is uploaded only after a user action and is sent through the FitAIss backend to the configured AI provider for an estimate. Original scan files are normally retained for up to 72 hours for processing, controlled retries and diagnostics. Speech-to-text is performed by the device speech service; FitAIss sends accepted text to its backend only when the user requests analysis. AI output is approximate and not medical advice.

Subscriptions and promotions

For Google Play and App Store purchases, FitAIss processes product and random account identifiers, protected transaction identifiers and their control hashes, signed verification evidence, status, expiry and store environment. FitAIss does not receive full card data.

The current app creates a share image and caption on the device from the meal name, estimated calories, personal code and public Google Play URL. It does not send the selected channel, layout, system share-sheet result or share asset to FitAIss solely to perform that share. FitAIss receives no publication confirmation from Facebook, Instagram or another service, and sharing alone never grants a bonus.

Compatible older clients may create a technical campaign record containing the account, meal, channel, layout, meal name, estimated calories, random token and share hand-off result. It is not used as proof of publication or to grant a bonus and is deleted after its 30-day validity period. When a referral code is redeemed, FitAIss stores the code identifier, the direct inviter-to-referred-account link, accepted Bonus Terms revision, qualification state, bonus period and daily amount, credit use and refunds, and a one-way installation identifier used to prevent repeat redemption. The Programme does not create a multi-level referral chain.

Purposes and legal bases

Account and functional diary processing necessary to supply FitAIss relies on Article 6(1)(b) GDPR. Accounting, tax and lawful-authority duties rely on Article 6(1)(c). Security, fraud prevention, essential diagnostics and legal claims rely on legitimate interests under Article 6(1)(f). The one-code-per-account-and-installation controls, self-referral prevention and minimal refusal evidence protect the service against abuse; FitAIss applies minimisation, pseudonymisation, limited retention and periodic balancing-test review. Optional product analytics, voluntary contact and specified optional operations rely on consent under Article 6(1)(a). Data revealing health relies on explicit consent under Article 9(2)(a).

Optional analytics and essential diagnostics

Optional mobile product analytics are off by default and can be changed in Settings. The /app/ website stores the user's analytics choice locally and sends promotional click events only after acceptance. Essential security, abuse prevention and crash diagnostics operate independently, are minimised and should not include passwords, full tokens, payment-card details or private images.

Recipients and international transfers

Data may be processed by hosting, storage, email, monitoring, security, AI, Google Sign-In, Sign in with Apple, Google Play Billing, App Store and support providers only to the extent needed. FitAIss does not sell personal data. Transfers outside the EEA use a GDPR-permitted mechanism such as an adequacy decision or standard contractual clauses, with supplementary safeguards where required. Details for a current provider can be requested from the controller.

Retention

Original scan images are normally retained for up to 72 hours. Technical logs are generally retained for 30–90 days unless an incident, audit or claim requires longer. Legacy technical share-campaign records are deleted after their 30-day validity period. Direct referral records, separate bonus periods, consent evidence and the minimal audit of a grant, refusal, revocation or refund are retained longer only as needed to run the promotion, handle complaints, prevent repeated redemption and protect legal claims; social-media post content is not retained for this purpose. Account and diary data are kept while the account is active. A scheduled deletion has a seven-day cancellation period. Afterwards private objects and domain data are deleted or anonymised, while minimal billing, consent, complaint, security and claim records may remain for the legally necessary period.

User rights

Subject to applicable conditions, users have rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent. They may lodge a complaint with the Polish supervisory authority (President of the Personal Data Protection Office) or the competent authority in their country. The self-service export view is hidden, but access and portability requests can be made through the contact form. Deletion is available in the app or on the public deletion page.

Automated processing

AI produces estimates that users can review and edit. FitAIss does not use those estimates to make decisions producing legal or similarly significant effects within Article 22 GDPR.

Security and policy changes

Controls include HTTPS, protected credentials, server-side AI keys, session controls, rate limits, Google Play and App Store purchase verification, secret isolation and monitored errors. No method is risk-free. Material Policy changes are communicated in the app or on the website and are versioned.

PWA local data and essential cookies

The web application stores the selected language, optional analytics choice, a random anonymous installation identifier and limited meal-photo copies in browser storage so that the interface can work consistently. Meal-photo copies are held in IndexedDB for the current FitAIss user scope and are removed on sign-out where the browser permits. Authentication uses a Secure, HttpOnly, SameSite=Lax refresh cookie restricted to FitAIss web-authentication paths. JavaScript cannot read that cookie. It is essential to maintain and rotate the signed-in session and is deleted on sign-out; no advertising cookie is required.

Web Push notifications

After an explicit browser permission, FitAIss may store a browser push endpoint, public encryption keys, language, time zone, user-agent summary, delivery status and technical error codes for habit reminders. The endpoint and keys are encrypted at rest and are not used for advertising. The browser subscription is removed on sign-out where available; invalid endpoints are deactivated automatically. Notification content is deliberately neutral and does not disclose meal, weight or other wellness details on the lock screen.

Stripe web billing data

When web billing is enabled, Stripe processes card or eligible-wallet details as an independent payment service provider under its own privacy information. FitAIss receives only the Stripe customer, checkout, price, subscription, invoice, payment-status, currency, renewal, cancellation, refund and dispute identifiers needed to supply and account for the plan, prevent duplicate subscriptions and handle support. FitAIss does not receive or store the full card number. Required accounting records are retained for the statutory period.