Privacy Policy

Last updated: August 18, 2026

This policy explains what data the OpenFit app collects, what it is used for, who processes it, and what your rights are under the Brazilian General Data Protection Law (Law No. 13,709/2018 — LGPD).

1. Controller and contact

The data controller is the developer of OpenFit. For any privacy matter — to ask a question, make a request, or exercise your rights — write to xxfrabettixx@gmail.com. This is also the channel for reaching the data protection officer (LGPD, art. 41), and we respond within 15 days.

2. What we collect and why

DataPurpose
Account identifier (login email and an internal ID)Authenticate you and sync your data across devices
Content you create in the app (workouts, diet, measurements, weight, progress photos)Provide the service. It stays in your account and never enters telemetry
Water and steps synced with Apple Health on iPhoneShow and record your water and steps cards — see section 4
Messages, photos, and files you send to the AI assistantGenerate the assistant's reply — see section 5
Subscription status (purchase identifier, plan, expiration)Unlock paid features and credit your monthly quota — see section 6
Usage events (screens visited, taps on features, workout completion)Understand what works and what confuses people, and improve the product
Session screen recording, with text and images maskedDiagnose usability problems. Can be turned off in the app
Error and performance reports (device model, app and OS version, stack traces)Find and fix defects
Where installs and link clicks come from (UTM parameters, store referrer)Understand how people discover the app

What never enters telemetry: weight, height, body measurements, personal records, workouts, diet, photos, Apple Health data, name, and email. This data exists only in your account, so the app can work.

3. Health data is sensitive data

Weight, height, body measurements, progress photos, workout and food logs, and the numbers coming from Apple Health are sensitive personal data as defined by the LGPD (art. 5, II). That changes how they must be processed, and so we handle this data as follows:

4. Apple Health (HealthKit)

On iPhone, with your explicit authorization in the system dialog, the app reads and writes water and steps in Apple Health. The authorization is yours, and iOS keeps it under your control: you can review or revoke it at any time in Settings → Health → Data Access & Devices.

These numbers stay in your OpenFit account so the cards work across devices. As Apple's rules and this policy require, data from Apple Health is never used for advertising or marketing, never enters telemetry, and is never shared with third parties.

5. AI assistant

When you chat with the assistant, the content of the conversation is sent to Anthropic (USA), which processes it and returns the reply. We also send what the assistant needs for its reply to make sense: your message, the photos or PDFs you attach, and the profile and goal data your plan is based on — which may include health data.

The assistant is not a health professional. The workout and meal plans it produces are automated suggestions. They do not replace evaluation by a physician, dietitian, or fitness professional, and you have the right to request a review of these automated decisions (LGPD, art. 20) using the contact details in section 1.

6. Subscription and payment

The PRO subscription is charged by the App Store, using the payment method registered with your Apple ID. We neither receive nor store card data — the payment is processed by Apple, not by us.

We use RevenueCat to know whether your subscription is active. For that, it receives your account's internal identifier and the purchase data (product, dates, status) — not your name, email, or any health data.

7. Legal basis

8. Operators (processors) and international transfer

We use services that process data on our behalf, under a data processing agreement, and that may store it outside Brazil (United States). The transfer relies on specific contractual safeguard clauses signed with each operator (LGPD, art. 33, II) and, for health data, on your specific consent (art. 33, VIII):

None of these providers receives your data for its own purposes, and no personal data is sold or transferred to third parties.

9. Retention

Deleting your account in the app erases your account data, including content, photos, and conversations. Whatever the law requires us to keep is retained for the legal period and then erased. The anti-fraud record described above remains, because it cannot identify you.

10. Security

We use technical and administrative safeguards to protect your data (LGPD, art. 46): traffic encrypted in transit (TLS), data encrypted at rest on Google Cloud infrastructure, database access restricted by authorization rules that isolate each person's account, authentication through an external provider (we never store your password), and restricted administrative access.

No system is infallible. In the event of a security incident that poses a significant risk to your rights, we will notify you and the ANPD as required by art. 48 of the LGPD.

11. Your rights (LGPD, art. 18)

At any time, you may request: confirmation that processing takes place, access, correction, anonymization, blocking, portability, deletion of data, information about data sharing, review of automated decisions, and withdrawal of consent. Just write to us at the email address in section 1. Deleting your account in the app erases your account data.

If the answer does not resolve the matter, you may file a complaint with the Brazilian National Data Protection Authority (ANPD).

12. How to turn off telemetry

In Profile → Privacy, inside the app, there are two separate controls: Share usage data and Allow screen recording. Turning a switch off takes effect immediately and stops any further data from being sent. Error reports are covered by the Share usage data switch.

13. Children and teenagers

OpenFit is not intended for children under 13 and we do not knowingly collect data from that age group. Users between the ages of 13 and 18 must have the consent and supervision of a parent or legal guardian, in the best interest of the teenager (LGPD, art. 14). If we identify an account belonging to a child under 13, we delete it; if you are a parent or guardian and believe this has happened, write to us at the email address in section 1.

14. Changes to this policy

We will publish any material change on this page and update the date at the top. Changes that broaden the purposes for processing sensitive data will be communicated in the app, with new consent when the law requires it.

15. Applicable law

This policy is governed by Brazilian law, in particular the LGPD and the Brazilian Internet Civil Rights Framework (Law No. 12,965/2014). Any dispute arising from this policy will be resolved in the courts where you live.