Privacy policy
This policy explains how Liam Kenneth trading as LRK Tech ("we", "us" or "our") handles personal data when you use the Fitonic Android application and this website. For data-protection purposes, Liam Kenneth trading as LRK Tech is the controller of personal data handled for Fitonic.
Information we handle
Account information
When you choose Google Sign-In, we receive your Google account identifier, email address, display name and profile image. We use these details to create and secure your Fitonic account and associate it with your subscription access. We do not receive your Google password. Fitonic does not provide cloud synchronisation of diary or health data between devices.
Health, fitness and profile information
If you connect Health Connect, Fitonic requests read access to steps, active calories burned, distance, exercise sessions, sleep sessions and weight, including historical records where you grant that permission. Records can include values, dates and times, duration, exercise type, title or notes, source application and Health Connect record identifiers. Fitonic does not write to, change or delete your Health Connect records.
You may also provide age, sex, height, weight and goal information, activity level, unit preferences, food and nutrition entries, water intake, fasting records, training routines, schedules, exercise sets and notes. Depending on the feature you use, Fitonic derives summaries, targets, trends and other analytics from this information.
Coach and AI feature content
Fitonic handles messages you send to Coach, Coach replies, conversation history, saved coaching context, generated insights and reviews. To generate AI features, we send the information needed for that request to the configured AI provider. This may include your message, food description or photo and a compact summary of relevant health, fitness, nutrition, fasting, goal and training information. We do not intentionally send your name or email address in AI prompts.
Photos, camera and food search
Camera or photo-library access is used only when you choose a food-photo feature. A compressed copy of the selected image and relevant context is sent through our server to the configured AI provider to estimate the meal. A local copy is kept on your device when you save the result to your diary; Fitonic does not store the image itself in our cloud database. Nutrition estimates and diary metadata remain on your device.
When you search for a food or scan a barcode, the search words or barcode are sent directly to Open Food Facts to retrieve product and nutrition information. Open Food Facts may receive technical information such as your IP address as part of the request.
Technical information
Our infrastructure providers may process IP addresses, request times, device or browser information and security or error logs needed to deliver, protect and troubleshoot Fitonic. We do not currently use third-party advertising SDKs or cross-app tracking in Fitonic.
Subscription information
If you subscribe to Fitonic Premium, Google Play processes the payment and RevenueCat processes subscription records needed to confirm your access. Fitonic receives subscription product, entitlement, status, expiry, environment and account-linking identifiers. We do not receive or store your full payment-card details.
Why we use information
- To provide your account, locally stored diary, dashboard, training, food estimation and Coach features.
- To read the Health Connect categories you select and turn them into user-facing history, summaries, trends and personalised insights.
- To keep Fitonic secure, prevent misuse, diagnose failures and maintain the service.
- To respond to support, privacy and account-deletion requests.
- To comply with legal obligations and establish, exercise or defend legal claims where necessary.
Where UK or EEA data-protection law applies, our legal bases are performance of our contract with you for core account and app services, our legitimate interests in securing and improving the service, compliance with legal obligations, and consent where we ask for it. Because health information is special-category data, we rely on your explicit consent to process it for Fitonic's health and personalisation features. You can withdraw Health Connect permissions in Android settings and can withdraw consent for our continued processing by deleting your Fitonic account.
Who receives information
We use service providers only as needed to operate the features you request:
- Cloudflare provides application hosting, network security, serverless processing and the D1 database.
- Google provides Google Sign-In and, when configured, the Gemini API used to generate AI outputs.
- OpenAI may be the configured provider used to generate AI outputs.
- Open Food Facts supplies food product and nutrition information for searches and barcode lookups.
- RevenueCat manages subscription entitlements and receives the account-linking identifier and purchase information needed to do so. Google Play processes Android subscription payments.
Google and OpenAI may retain API inputs and outputs for limited safety and abuse-monitoring periods under their applicable service terms. We may also disclose information if required by law, to protect users or the service, or as part of a business transfer subject to appropriate safeguards. We do not sell personal data or Health Connect data and do not share it with advertisers or data brokers.
Storage, security and international transfers
Fitonic keeps its diary, health cache, training data, goals, Coach conversations, generated insights, reviews, analytics and progress photos on your Android device. The app token is stored using Android-protected secure storage. Our Cloudflare-hosted systems store the account details needed for sign-in and subscription-entitlement records. When you use an AI feature, the minimum request content needed for that feature is transmitted through our server to the configured AI provider and the response is returned to your device; our server does not persist the AI request or response.
We use encrypted HTTPS connections, access controls and other technical and organisational safeguards designed to protect personal data. No system is completely secure. Our providers may process information outside the UK or EEA. Where required, we rely on recognised adequacy arrangements or contractual safeguards for those transfers.
Retention and deletion
We retain your active Fitonic account details and subscription-entitlement record while your account remains open. AI providers may keep request data for their documented safety and abuse-monitoring periods.
When your deletion is completed, we delete your Fitonic account, profile and subscription-entitlement link from the live Fitonic database. Cloudflare point-in-time recovery history may contain residual copies for up to 30 days, after which they expire. We may retain only information required by law or necessary to resolve disputes, enforce agreements, or prevent fraud, and will isolate it from ordinary use.
Account deletion does not cancel or delete subscription and transaction records held by Google Play or RevenueCat, or records held by Health Connect, Google or other source apps. Cancel an active subscription in Google Play before deleting your Fitonic account. You can manage or delete other source records in Health Connect or the source app. Deleting through the app clears Fitonic's account-scoped local database and progress photos stored by Fitonic, but gallery originals or other operating-system storage may remain until you delete them or uninstall Fitonic. A deletion request completed by email cannot remotely erase data that exists only on your device; clear Fitonic's app storage or uninstall it to remove that local data.
See Account and data deletion for both the in-app route and the web request route.
Your choices and rights
You can choose which Health Connect categories to grant and revoke them at any time in Health Connect settings. You can correct diary and profile information in Fitonic, delete your account in the app, or contact us to request access, correction, deletion, restriction, objection, portability or withdrawal of consent where those rights apply. You may also complain to your local data-protection authority; in the UK this is the Information Commissioner's Office.
Children
Fitonic is intended for adults and is not directed to children under 18. We do not knowingly collect personal data from children. Contact us if you believe a child has provided personal data.
Changes to this policy
We may update this policy as Fitonic changes. We will update the date above and provide additional notice in the app when a change materially affects how we use personal data.
Contact
For privacy questions or requests, email liam.kenneth@hotmail.co.uk. Controller: Liam Kenneth trading as LRK Tech, United Kingdom.