PrivacyTermsBGEN

Privacy Policy — FitnesMe

Version: 1.0 Effective date: 11 July 2026 Last updated: 11 July 2026

This Privacy Policy explains how TIGER SOFT Ltd (ТАЙГЪР СОФТ ЕООД), company ID 208799985, registered at 41 Maystor Aleksi Rilets St, Sofia 1619, Bulgaria ("FitnesMe", "we", "us"), acting as the data controller, collects, uses and protects your personal data when you use the FitnesMe mobile application and services (the "App").

We process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and the Bulgarian Personal Data Protection Act.

For questions about this policy: clients@tigersoftbg.com.


1. Data we collect

1.1. Data you provide

  • Account data: email address, password (stored only as a cryptographic hash — never in plain text), full name, nickname, interface language.
  • Profile photo / avatar.
  • Trainer data: bio, specializations, service price, city, photo.
  • Health and progress data (see section 4): weight and body measurements (waist, chest, arms, thighs, forearms, calves, biceps), workout and nutrition plans.
  • Communications: chat messages (text and images), trainer reviews and ratings, food requests.

1.2. Data collected automatically

  • Technical identifiers: push notification token, device identifier (to deliver notifications).
  • Google sign-in data: if you choose to sign in with Google, we receive your email and basic profile information, along with access tokens from Google.

1.3. Google Calendar data (trainers only, optional)

If you are a trainer on the ELITE plan and choose to connect your Google Calendar, FitnesMe requests the calendar.events and calendar.readonly scopes and accesses:

  • Events FitnesMe itself created — training sessions you schedule in the app are mirrored into your primary Google Calendar. We store only the Google event ID of those events, so we can later update or cancel them and reflect changes you make in Google back into the app.
  • Free/busy intervals — when you open the week view we query busy times across your calendars so the app can show existing commitments and prevent double-booking a client. These intervals are used live, while the screen renders, and are not stored.
  • Access credentials — your Google refresh token, encrypted at rest, together with the identifier of your primary calendar.

We do not read, store or share the content of calendar events that FitnesMe did not create; such events are ignored and never written to our database. You can disconnect at any time from the Schedule screen — this deletes the stored token — and you may also revoke access at myaccount.google.com/permissions.

Limited Use. FitnesMe's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google Calendar data for advertising, we do not sell it, and we do not use it to train generalised AI or ML models. No human reads it, except where necessary for security purposes, to comply with applicable law, or with your explicit consent.

1.4. Data from third parties

  • Payments: when you pay, Stripe provides us with the status of the transaction and subscription. We do not receive or store your payment card details.

2. Purposes and legal bases

Purpose Data categories Legal basis (GDPR)
Account creation and management Account, profile Art. 6(1)(b) — contract
Core features (plans, library, progress) Profile, plans Art. 6(1)(b) — contract
Processing health data (weight, measurements, plans) Special category Art. 9(2)(a) — explicit consent
Trainer–client relationship and chat Profile, messages Art. 6(1)(b) — contract
Payments and subscriptions Financial Art. 6(1)(b) — contract; Art. 6(1)(c) — accounting
Push notifications Push token Art. 6(1)(a) — consent
Google Calendar sync (trainers, optional) Calendar events created by the app, free/busy times Art. 6(1)(a) — consent
Emails (verification, password reset) Email Art. 6(1)(b) — contract
Security, fraud prevention Technical Art. 6(1)(f) — legitimate interest
Legal compliance Various Art. 6(1)(c) — legal obligation

3. Who we share data with (processors)

We do not sell your personal data. We share it only with service providers ("processors") acting on our instructions under data processing agreements (DPAs):

Provider Purpose Location
Stripe Payment and subscription processing EU / US
Cloudinary Image storage (avatars, chat, logos) US
Resend Sending transactional emails US
Google (OAuth) Authentication via Google sign-in US
Google Calendar Calendar sync for trainers who connect it (see 1.3) US
Expo / Apple (APNs) / Google (FCM) Delivering push notifications US
YouTube (Google) Displaying exercise videos US
netcup GmbH Server and database hosting Germany (EU)

We may also disclose data to competent authorities where required by law.


4. Special category data (health data)

FitnesMe lets you enter weight, body measurements and workout/nutrition plans. This data qualifies as health data under Art. 9 GDPR and is processed only on the basis of your explicit consent, given when you first enter such data.

  • You may withdraw your consent at any time via settings or by deleting your progress data.
  • Withdrawal does not affect the lawfulness of prior processing.
  • If you are a trainer's client, your plans and (where shared) progress become visible to that trainer so they can provide the service.

5. International transfers

Some of our providers (Stripe, Cloudinary, Resend, Google, Expo) process data outside the EEA (mainly in the US). These transfers are safeguarded by:

  • Standard Contractual Clauses (SCCs) of the European Commission, and/or
  • certification under the EU-U.S. Data Privacy Framework.

6. Retention

  • Account data: while the account is active; deleted within 30 days of a deletion request or account closure.
  • Health / progress data: until you delete it or close your account.
  • Financial / accounting data: up to 11 years, as required by accounting and tax law.
  • Email logs: up to 90 days.
  • Chat messages: while the trainer–client relationship exists or until deleted.
  • Google Calendar credentials: until you disconnect the calendar or delete your account — the encrypted token is erased immediately in both cases.

7. Your rights

Under GDPR you have the right to:

  • Access your data (Art. 15);
  • Rectification of inaccurate data (Art. 16);
  • Erasure ("right to be forgotten", Art. 17);
  • Restriction of processing (Art. 18);
  • Portability of data (Art. 20);
  • Object to processing based on legitimate interest (Art. 21);
  • Withdraw consent at any time (Art. 7(3));
  • Lodge a complaint with a supervisory authority.

To exercise your rights: clients@tigersoftbg.com. We respond within 30 days.

Supervisory authority in Bulgaria: Commission for Personal Data Protection (CPDP), Sofia, 2 Prof. Tsvetan Lazarov Blvd., cpdp.bg.


8. Security

We apply technical and organizational measures to protect data, including: password hashing (bcrypt), JWT-based authentication, storage of tokens in the device's secure storage (Secure Store), HTTPS communication, and restricted database access. However, no system is fully secure and we cannot guarantee absolute protection.


9. Children

The App is not intended for persons under 16 years of age. We do not knowingly collect data from children below this age. If we discover such data, we will delete it.


10. Data stored on your device

We store locally on your device: login tokens (Secure Store), cached data (AsyncStorage), and biometric settings (expo-local-authentication). Biometric data never leaves your device and is not sent to us.


11. Changes to this policy

We may update this policy. Material changes will be communicated in the App or by email. The last-updated date is shown at the top.


12. Contact

TIGER SOFT Ltd (ТАЙГЪР СОФТ ЕООД) Address: 41 Maystor Aleksi Rilets St, Sofia 1619, Bulgaria Email: clients@tigersoftbg.com Data protection email: clients@tigersoftbg.com

FitnesMe · TIGER SOFT Ltd