1.Introduction
FitHuddle ("FitHuddle", "we", "our", or "us") is an independent app project based in India that builds a social fitness app that lets you track walks, runs, rides and other activities, set goals, and take part in challenges with other people. This Privacy Policy explains what personal information the FitHuddle mobile application (the "App") collects, why we collect it, who we share it with, how long we keep it, and the choices and rights you have.
This Policy covers the FitHuddle Android application published on Google Play under the package name app.fithuddle.android, together with the backend services that support it. It should be read alongside our Terms of Service. By creating an account or using the App, you agree to the practices described here. If you do not agree, please stop using the App and, if you have an account, request its deletion as described in Section 12.
2.Privacy at a Glance
- We do not sell your personal information to anyone, and we never have.
- We do not use your health, fitness, or location data for advertising — ours or anyone else's. The App contains no advertising SDKs.
- Location is only collected while you are actively tracking an activity. Start a workout and GPS runs; end it and GPS stops.
- Health Connect data stays in your control. We read only the data types you approve, and you can revoke access at any time in Health Connect.
- Your activity history lives on your device first. A local database on your phone is the primary copy; the cloud copy exists so your data survives a lost phone and so challenges can be scored.
- You can delete your account and all associated data from inside the App, in two taps, without asking us — see Section 12.
3.Information We Collect
We collect only what the App needs to work. The table below lists every category of personal information FitHuddle processes, what it is used for, and whether it leaves your device.
| Category | What it includes | Why we collect it | Leaves device? |
|---|---|---|---|
| Account credentials | Email address and password (stored only as a salted hash by our authentication provider), or your Google account identifier and email if you sign in with Google. | To create and secure your account and to sign you in. | Yes |
| Profile information | Display name, profile photo, date of birth, gender, height, weight, time zone. | To personalise the App, calculate calorie and pace estimates accurately, and identify you to other participants in challenges you join. | Yes |
| Health & fitness data | Steps, distance, duration, moving time, pace, speed, active and total calories burned, elevation gain and loss, exercise session type, daily totals, and streaks. | To record your activities, show your history and progress, calculate goal completion, and score challenges. | Yes |
| Precise location (GPS) | Latitude, longitude, altitude, and timestamps recorded during an active tracking session, stored as a route trace. | To measure distance, pace and elevation, and to draw your route on a map. See Section 5. | Yes |
| Device sensor data | Readings from your device's hardware step counter and, where available, barometer. | To count steps and estimate elevation change during indoor and outdoor activities. | Only as aggregated activity metrics |
| Health Connect data | Steps, distance, calories, speed, exercise sessions, and exercise routes read from Android Health Connect with your explicit permission. See Section 4. | To import activities you recorded in other fitness apps so your FitHuddle history is complete. | Yes |
| Social & challenge data | Challenges you create or join, your progress within them, leaderboard standings, challenge invitations you send or accept, and huddles (groups) you belong to. | To run challenges and show leaderboards to other participants of the same challenge. | Yes |
| App settings | Theme, units of measure, week start day, notification preferences, and goal targets. | To keep the App configured the way you like it across sessions and devices. | Yes |
| Diagnostics | Crash reports and stack traces, app performance traces, app version, device model, operating system version, and a randomly generated app instance identifier. See Section 8. | To find and fix crashes and performance problems. | Yes |
FitHuddle does not collect your contacts, your calendar, your photos or media library (beyond the single image you choose as a profile photo), your call or SMS history, your device's advertising identifier, or a list of the other apps installed on your device.
4.Health Connect Data
FitHuddle integrates with Android Health Connect so that activities you record in other fitness apps and on connected wearables appear in FitHuddle, and so that activities you record in FitHuddle can be shared back to the apps you choose.
What we read and write
With your explicit, per-data-type permission granted through the Health Connect permission screen, FitHuddle reads and writes the following: steps, distance, total calories burned, active calories burned, speed, exercise sessions, and exercise routes. We also request permission to read health data in the background and to read historical health data, so that scheduled syncs stay accurate and so a first-time import can bring in up to the past 365 days of your history rather than only the last 30 days.
How Health Connect data is used
- Imported activities are shown in your FitHuddle activity history and count towards your daily totals, goals, streaks, and any challenges you have joined.
- Imported exercise routes are used only to draw the map for that activity inside the App.
- Activities you record with FitHuddle's own tracker are written back to Health Connect so other apps you have authorised can see them. This write is under your control through your Health Connect sharing settings.
Our Health Connect commitments
- We never use Health Connect data for advertising, marketing, or any similar commercial purpose.
- We never sell Health Connect data or transfer it to data brokers, information resellers, credit agencies, or insurers.
- We do not use Health Connect data to determine creditworthiness or for any lending or underwriting purpose.
- We do not transfer Health Connect data to any third party except the providers listed in Section 10, who process it solely to deliver a feature you are using.
- We do not ourselves use Health Connect data to train machine learning models. Note that daily and weekly totals derived from Health Connect data may be included in the aggregate metrics sent to Google's Gemini API to generate your insights — please read Section 7, which explains how Google may use that data under the tier we currently operate on.
- Health Connect data is deleted from our servers when you delete your FitHuddle account.
Revoking access
You can review and withdraw FitHuddle's Health Connect permissions at any time in Settings → Health & fitness → Health Connect → App permissions on your device, or from within the Health Connect app. Revoking access stops all further reading and writing immediately. Activities already imported into FitHuddle remain in your FitHuddle history until you delete them or delete your account.
5.Location & Background Location
FitHuddle requests precise location (ACCESS_FINE_LOCATION) and background location (ACCESS_BACKGROUND_LOCATION) permissions. Here is exactly how each is used.
When location is collected
Location is collected only while an activity tracking session is running. Collection begins when you tap Start on the Track screen and stops the moment you finish or discard the session. FitHuddle does not collect your location when you are simply browsing the App, and it does not collect your location when the App is closed and no session is active.
Why background location is needed
Once you start a session, FitHuddle runs a foreground service that keeps recording GPS while your screen is off, while you switch to another app, or while your phone is in your pocket. Without this, a run or ride would stop recording the moment the screen locked, and your distance and route would be wrong. This is a core, user-initiated feature of the App, not incidental background collection.
While a session is active, Android displays a persistent notification so you always know tracking is in progress. Ending the session removes the notification and stops location collection.
What we do with route data
Route points are used to compute distance, pace, speed and elevation change, and to draw the route map on the activity detail screen. Routes are stored with the activity they belong to. Route data is not used to profile you, to infer where you live or work, or for any advertising purpose.
Your control
You can grant location access "while using the app" only, or deny it entirely, and you can revoke it at any time in Android Settings. Denying location prevents outdoor route recording; the rest of the App — step counting, indoor activities, challenges, goals, and history — continues to work.
6.How We Use Your Information
We use the information described above for the following purposes, and no others:
- To create, authenticate, and secure your account.
- To record, store, and display your activities, routes, daily totals, streaks, and progress towards goals.
- To operate challenges — calculating each participant's progress and ranking them on a leaderboard visible to the other participants of that challenge.
- To synchronise your data between your device and your account, so that it survives reinstalling the App or moving to a new phone.
- To generate the personalised daily and weekly insights described in Section 7, where you use that feature.
- To send you the notifications you have enabled — goal reminders, streak alerts, challenge updates, and achievements. All notification types can be turned off individually in Settings.
- To diagnose crashes, fix bugs, and monitor performance, as described in Section 8.
- To control the rollout of new features safely, using remote configuration flags that do not depend on your personal data.
- To respond to your support requests, feedback, and rights requests.
- To detect and prevent fraud, abuse, cheating in challenges, and violations of our Terms of Service.
- To comply with legal obligations that apply to us.
7.AI-Powered Insights
FitHuddle can generate short daily and weekly coaching summaries — a headline, a focus area, a suggested next action, and a tip — to help you interpret your own numbers.
When you use this feature, the App sends your fitness metrics (such as your step count, calories, active minutes, and distance for the relevant period) and your time zone to our backend, which computes your statistics and then passes a summarised, numeric view of them to Google's Gemini API (model gemini-3.1-flash-lite) to produce the advisory wording.
- The numbers you see — rings, targets, pace projections, streaks, and challenge standings — are calculated deterministically by our own backend. The AI model generates only the advisory text; it is never the source of a figure shown to you.
- We do not send your name, email address, profile photo, date of birth, or GPS route coordinates to Google's Gemini API. The data sent consists of aggregate numbers and your time zone.
- Important: FitHuddle currently uses the free (unpaid) tier of the Gemini API. Under Google's terms for that tier, Google uses the content submitted to it — and the responses returned — to provide, improve, and develop Google's products, services, and machine learning technologies, and human reviewers may read and annotate that content. This applies to the aggregate fitness metrics described above. Google's handling of this data is governed by the Gemini API Additional Terms of Service and the Google Privacy Policy.
- This feature is currently enabled by default. Your daily summary is generated automatically when you open the Home screen, which means the aggregate metrics described above are sent to Google's Gemini API without a separate prompt each time. We are adding a setting to turn this off; until it ships, if you would prefer that none of your data reach Google's Gemini API, please contact us at support@fithuddle.app and we will disable the feature for your account.
- We intend to move to the paid tier of the Gemini API, under which Google does not use submitted data to train its models. When we do, we will update this section and the "Last updated" date above.
- These insights are for general motivation only. They are not medical advice — see the health disclaimer in Section 14 below.
8.Analytics & Crash Reporting
FitHuddle uses Google Firebase to keep the App stable. Specifically:
- Firebase Crashlytics — collects crash reports and non-fatal error reports, including the stack trace, the device model, the operating system version, and the app version at the time of the crash.
- Firebase Analytics — collects standard, automatically-generated app usage events such as app opens, session duration, and screen transitions, associated with a randomly generated app instance identifier rather than your name or email.
- Firebase Performance Monitoring — collects timing measurements such as how long the App takes to start.
- Firebase Remote Config — retrieves feature flags from our servers. It does not send us personal information about you.
This diagnostic data is used solely to keep the App working correctly. It is not combined with your health or location data, and it is not used for advertising. Firebase's own processing is governed by the Firebase Privacy and Security policy.
The Mapbox Maps SDK, which renders the maps used for activity routes, receives map tile requests from your device in order to serve the map imagery and may collect its own usage telemetry as described in the Mapbox Privacy Policy.
9.Where Your Data Is Stored
On your device
FitHuddle keeps a local database on your phone holding your activities and routes, your profile, your daily statistics, your goals, your settings, your notifications, and cached challenge details. This local copy is what makes the App usable offline and is the primary source for what you see on screen.
Your authentication tokens are held in encrypted storage on the device, and are explicitly excluded from Android cloud backup and from device-to-device transfer, so your credentials cannot follow a device clone or a restored backup.
Uninstalling the App deletes this local database and the stored tokens from your device. It does not delete your account or the cloud copy of your data — for that, see Section 12.
In the cloud
Your account, profile, activities, goals, settings, and challenge participation are synchronised to our backend, which is hosted on Supabase (managed PostgreSQL, authentication, file storage, and serverless functions). Your profile photo is stored in Supabase file storage. All traffic between the App and our backend travels over encrypted HTTPS/TLS connections; the App is configured to refuse unencrypted connections.
10.Data Sharing & Third Parties
We share personal information only in the limited circumstances set out below.
With other FitHuddle users
When you join or create a challenge, the other participants in that challenge can see your display name, profile photo, and your progress on the metric being tracked (for example, your total steps or distance for the challenge period), together with your position on the leaderboard. Other participants cannot see your email address, date of birth, height, weight, gender, individual activity routes, or any activity that is not part of that challenge.
With service providers
We use the following processors to run the App. Each receives only the data necessary to perform its function and is bound to protect it.
| Provider | Function | Data it processes |
|---|---|---|
| Supabase | Database, authentication, file storage, and serverless backend functions | Account credentials, profile, activities and routes, goals, settings, challenge data |
| Google (Firebase) | Crash reporting, analytics, performance monitoring, remote configuration | Crash reports, device and app version, usage events, pseudonymous app instance ID |
| Google (Sign-In) | Optional sign-in with a Google account | Your email address and Google account identifier, only if you choose this sign-in method |
| Mapbox | Map rendering for activity routes | Map tile requests and SDK usage telemetry |
| Google (Gemini API) | Generating the advisory text for daily and weekly insights | Aggregated fitness metrics and time zone only — no name, email, photo, or GPS coordinates |
Health Connect and Google Play services location run on your device as part of the Android platform; using them does not transmit your data to us or to Google beyond what those platform components do under Google's own policies.
For legal reasons
We may disclose personal information if we reasonably believe it is necessary to comply with a law, regulation, legal process, or enforceable governmental request; to enforce our Terms of Service; to detect or prevent fraud or security issues; or to protect the rights, property, or safety of FitHuddle, our users, or the public.
Business transfers
If FitHuddle is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your personal information becomes subject to a materially different privacy policy, and you will have the opportunity to delete your account first.
11.No Sale, No Advertising
We do not sell, rent, or trade your personal information. We do not share it with data brokers, information resellers, credit bureaus, or insurers. FitHuddle contains no advertising SDKs, serves no third-party ads, and does not use your health, fitness, or location data to build advertising or marketing profiles — for us or for anyone else.
12.Retention & Deletion
How long we keep your data
We keep your account information and activity data for as long as your account remains active, because the App's core purpose is to show you your own history over time. Diagnostic data such as crash reports is retained for a shorter period in line with our provider's default retention settings, and is not linked to your account.
Deleting individual activities
You can delete any individual activity from within the App. Deleting an activity removes it and its route from your device and from our servers.
Deleting your account
You can delete your account and all of its data directly in the App, at any time, without contacting us:
Open FitHuddle → Profile → scroll to the bottom → tap "Delete Account" → confirm.
The App shows a confirmation dialog before anything is deleted. Deletion is immediate and cannot be undone.
Confirming the dialog permanently erases, on our servers and on your device:
- Your login credentials and authentication account — you will no longer be able to sign in.
- Your profile, including your display name, photo, date of birth, gender, height, and weight.
- All of your activities and GPS routes, and all health and fitness data, including anything imported from Health Connect.
- Your daily statistics, streaks, goals, settings, and stored notifications.
- Your challenge participation records and leaderboard entries.
Deletion is permanent and irreversible — we keep no backup copy from which your account can be restored. Anonymous, aggregate statistics that cannot be linked back to you may be retained, and we may keep a minimal record where the law requires it or where it is necessary to resolve a dispute or enforce our agreements; any such record is kept only for as long as that purpose requires.
If you cannot access the App — for example, because you have lost access to your account — email support@fithuddle.app from the address registered to your account with the subject line "Account deletion request". We will verify the request and complete deletion within 30 days.
Note that uninstalling the App is not the same as deleting your account. Uninstalling removes the local copy of your data from your device, but your account and its cloud data remain until you delete them using one of the methods above.
13.Data Security
We take the security of your data seriously and apply measures appropriate to its sensitivity, including:
- All network traffic between the App and our backend is encrypted in transit using HTTPS/TLS, and the App is configured to reject unencrypted connections.
- Passwords are never stored in plain text; our authentication provider stores only a salted hash.
- Authentication tokens are stored in encrypted storage on your device and are excluded from Android backup and device transfer.
- Access to stored data is enforced at the database layer, so one user's records cannot be read by another.
- Data at rest in our cloud database is encrypted by our infrastructure provider.
No method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security. If you believe your account has been compromised, contact us immediately at support@fithuddle.app.
14.Children's Privacy
FitHuddle is not directed at children and is not intended for use by anyone under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us at support@fithuddle.app and we will delete it promptly.
Health disclaimer. FitHuddle is a fitness tracking and motivation tool. It is not a medical device, and nothing in the App — including any AI-generated insight — is medical advice, diagnosis, or treatment. Consult a qualified healthcare professional before beginning any new fitness programme.
15.Your Rights & Choices
Subject to the law that applies to you, you have the right to:
- Access the personal information we hold about you, and receive a copy of it.
- Correct information that is inaccurate or incomplete — most profile fields can be edited directly in the App.
- Delete your personal information, as described in Section 12.
- Withdraw consent you previously gave — for example, by revoking location or Health Connect permissions in your device settings, or turning off notification categories in the App.
- Object to or restrict certain processing of your information.
- Data portability — receive your data in a structured, commonly used, machine-readable format.
- Complain to your local data protection authority if you believe we have handled your data unlawfully.
To exercise any of these rights, email support@fithuddle.app from the address registered to your account. We will respond within the period required by applicable law, and in any event within 30 days. We will not discriminate against you for exercising your rights.
If you are in the European Economic Area or the United Kingdom, our legal bases for processing are: performance of a contract (operating the App and your account), consent (location, Health Connect access, and notifications, each of which you may withdraw), legitimate interests (keeping the App secure, stable, and free of abuse), and legal obligation where applicable. If you are in India, we process your personal data in accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000.
16.International Transfers
FitHuddle is developed and operated from India, and our service providers operate infrastructure in various countries. This means your personal information may be transferred to, stored in, and processed in a country other than your own, including countries whose data protection laws differ from those in your jurisdiction. Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
17.Android Permissions Reference
For full transparency, here is every sensitive permission the App declares and the specific feature that depends on it. Each can be denied, and each can be revoked later in Android Settings.
| Permission | Why FitHuddle needs it |
|---|---|
ACCESS_FINE_LOCATIONACCESS_COARSE_LOCATION |
To record your GPS route and measure distance, pace, and elevation during an outdoor activity. |
ACCESS_BACKGROUND_LOCATION |
To keep recording your route while the screen is off or you switch apps during an active tracking session only. |
ACTIVITY_RECOGNITION |
To read your device's hardware step counter so steps are counted accurately. |
FOREGROUND_SERVICEFOREGROUND_SERVICE_LOCATIONFOREGROUND_SERVICE_HEALTH |
To run the tracking service that records your workout, with a visible ongoing notification for the whole time it is active. |
POST_NOTIFICATIONS |
To show the tracking notification and any goal, streak, challenge, or achievement alerts you have enabled. |
health.READ_* / health.WRITE_* |
To read activities from Health Connect and write FitHuddle-recorded activities back to it — steps, distance, calories, speed, exercise sessions, and routes. See Section 4. |
health.READ_HEALTH_DATA_IN_BACKGROUND |
To keep your totals current through scheduled syncs when the App is not open. |
health.READ_HEALTH_DATA_HISTORY |
To import more than the trailing 30 days when you first connect Health Connect, so your history is complete. |
INTERNETACCESS_NETWORK_STATE |
To sync your data with your account, load maps, and detect when you are offline. |
18.Changes to This Policy
We may update this Privacy Policy as the App evolves or as the law requires. When we do, we will revise the "Last updated" date at the top of this page. If the changes are material — for example, if we begin collecting a new category of personal information or using it for a materially different purpose — we will provide prominent notice in the App before the change takes effect, and where the law requires it, we will ask for your consent. Your continued use of the App after an update takes effect constitutes acceptance of the revised Policy.
19.Contact Us
If you have questions, concerns, or requests about this Privacy Policy or about how we handle your personal information, please contact us:
FitHuddle — an independent app project based in India
Data protection contact: support@fithuddle.app
Web: https://fithuddle.app
We aim to respond to all privacy enquiries within 30 days.