Last updated: 15 September 2026
This policy explains what we collect, why, who else touches it, how long we keep it, and how to get it deleted. It covers three things: the Fit Nomads app on iOS and Android, the website at thefitnomadsofficial.com, and our coaching services.
Most of what follows is about the app, because the app is where the real data lives. If you only want the app, start at section 2 and read to the end of section 10.
Data controller: AJTV Limited, incorporated in Hong Kong, trading as Fit Nomads. Registered office: 2301, 23/F Bayfield Building, 99 Hennessy Road, Wan Chai, Hong Kong. Contact: support@thefitnomadsofficial.com.
| Data | Why we have it |
|---|---|
| Your email address, and your name or handle if you set one | To create and sign you in to your account, and to match your membership to it |
| A user ID generated when your account is created | To attach your data to you and nobody else |
| Food and drink you log, calories, macros, meal titles, photo scans | To run Calorie Banking, your diary and your trends |
| Weight and weigh-in history | To show your weight trend and adjust your targets |
| Workouts, exercises, sets, loads, rest, personal records and training sessions | To run the Train world and your progress charts |
| Coach-assigned workouts, their scheduled date and whether they are assigned, started, completed or withdrawn | To let an authorised Fit Nomads coach add workouts after you separately allow workout assignments |
| Private coaching messages, kept as text | To let you communicate with Tijs, Abbey and authorised Fit Nomads coaches after you separately start private chat. If fitness-data sharing is also on, the text of your last 60 messages is read by the coaching copilot. See sections 5 and 11 |
| Private coaching voice notes, kept as audio files | To let you send a coach a spoken message. The recording itself is stored in our private coaching-voice-notes storage, not transcribed and thrown away. See section 11 |
| Progress photos, which are body photos | To let you and your coach see change over time. Stored in our private coaching-progress storage and shown only to you and your current coaches. Each upload is acknowledged on its own. See section 11 |
| Habits, streaks, your Elite Score and how you say you feel | To show your week honestly and keep score of behaviour, never of weight lost |
| Body-composition figures you keep from a DEXA report | To track composition over time. Only the values you confirm are saved |
| Sleep, resting heart rate and HRV, only if you type them in yourself | To show them alongside the rest of your week. The app does not read these from any wearable |
| Your daily step count from Apple Health on iOS or Health Connect on Android, if you connect it | To open the "active day" in your Elite Score. See section 3 |
| Trips, cities and itinerary details you save | To run the travel side of the app |
| Your goal, targets, plan and unit preferences | To do the maths the way you want it done |
| Community tips you post, your votes, and reports you make | To run the community. See section 8 |
| Meal photos, DEXA report images, booking documents, place screenshots and voice recordings you choose to submit | Passed to an AI to read them, then discarded. We do not keep them as app history. See sections 4 and 5 |
| Optional, sanitised parser diagnostics | Only if you opt in, to make food and exercise recognition better. See section 6 |
| Crash reports, and a small ledger of voice timings | To find out that something broke, and how slow it was. See section 9 |
The app never asks for your location. There is no location permission and no code that requests one. We do not collect your contacts, your browsing history, or anything for advertising.
The app has no bloodwork or injury records, and no wearable integration beyond the Apple Health or Health Connect step count described below. If you have seen those mentioned in older material, they are not in the app you have.
If you connect Apple Health on iOS or Health Connect on Android, the app reads one thing: your daily step count. That is the only health data type it asks for and the only one it can see.
You can hold the mic and say what you ate or what you lifted.
When you speak a list of foods, anything the app already recognises is matched on your phone. Only the part it could not work out is forwarded, and only if you have agreed to that.
Some features in the app send what you are logging to an AI company to read it. Two companies receive anything: Anthropic, who make Claude and who handle food photos, food descriptions, the weekly summary, the coaching copilot described in the last row below and the rest of the reading features, and OpenAI, who transcribe voice on the fallback path and read the soundtrack of a travel video you import. Nothing goes to either of them without your consent.
Anthropic keeps what we send it, and what it sends back, for up to 30 days, and may review it for safety. Content its automated safety systems flag can be kept longer, up to two years for the content and seven years for the scores. OpenAI keeps the voice recordings and video soundtracks we send it for up to 30 days for abuse monitoring, and does not use them to train its models. Neither company keeps anything for us beyond that.
Consent is asked per feature, not once for everything. Before the first time a feature sends anything, the app shows you a sheet that names the company, says exactly what will be sent, and offers you a way to do it by hand instead. Agreeing to one feature does not agree to any of the others, and you can say no to all of them and keep using the app.
| Feature | Who processes it | What they receive |
|---|---|---|
| Reading your meals | Anthropic (Claude) | The photo or the words you are logging right now. Not your weight, not your Health data, not your history |
| Transcribing your voice | OpenAI | That single recording, with nothing attached to it |
| Reading your body-composition reports | Anthropic (Claude) | The DEXA report image you choose, which may show your name, your clinic and your measurements |
| Reading your bookings | Anthropic (Claude) | The booking file you pick, which may include your name and the address you are staying at |
| Reading places from screenshots, links and videos | Anthropic (Claude), and OpenAI for a video's soundtrack | The screenshots you pick, up to five at a time, or a TikTok or Instagram link you paste, or a video you saved. For a link we send the post's public caption and cover image, the text written on the post, and TikTok's own auto-generated captions, and never the video file itself. For a video, up to six still frames go to Anthropic and the soundtrack goes to OpenAI to be written down. Not the rest of your camera roll, and not the rest of your trip. To check a place is real, only its name is looked up on Google, never the image. A place that checks out is added to your trip under "Date not confirmed" with an Undo next to it, and anything uncertain waits for your yes |
| Reading your training notes | Anthropic (Claude) | The description of that session |
| Writing your weekly roundup | Anthropic (Claude) | More than the others, and we say so on the sheet: your meals and calories, your training and lifts, your habits, your weight and weight trend, your streak and your goal. Not your Apple Health or Health Connect step count, your name or your email |
| Screening community tips | Anthropic (Claude) | The text of the tip you are posting |
| Your coach's copilot, if you are a coaching client with fitness-data sharing on | Anthropic (Claude) | This is the largest thing on this page, so here it is in full. Your profile and plan, your food log, your workouts and training, your habits, your weight and weight history, and the health figures you typed in. Your coach-assigned workouts and habits, your nutrition targets and any meal examples set for you. And, when private chat is also on, the text of your last 60 private coaching messages, both sides of the conversation. Not your Apple Health or Health Connect step count, not your voice-note audio, not your progress photos, not your password or payment details |
Two rules run across that whole table.
The rule under both of those: a feature sends what its sheet says it sends, and nothing more. Where the thing you picked happens to carry your name — a DEXA report with the clinic's header on it, a hotel booking with your reservation on it — the sheet says so in advance, which is why those two are worded the way they are in the table above.
Anthropic and OpenAI act as our processors. They handle the one request, send the result back, and are not permitted to use what you send for their own purposes. None of it is used for advertising, by them or by us, and we do not sell it.
Community screening is the one that does not have its own on/off switch. Every tip is screened before anyone else can see it, so posting publicly without a check is not something we offer. It is set out in the community rules you accept before you post.
The coaching copilot has its own switch, in a different place. It is not in AI & voice. It is the fitness-data sharing switch in Profile, the same one that gives a coach read access in the first place, because the copilot never sees more than the coach already can. Turning that off stops both. Turning private chat off stops your message text going with it while leaving the rest of the sharing as it was.
Everything else in this table can be turned off in Profile → Account & units → AI & voice, which lists every feature, who it goes to, and the date you agreed. Turning one off stops anything further being sent. It does not reach back and delete what has already been processed, so if you want us to chase that up, email us.
These choices are remembered per device on purpose. Agreeing on your iPhone does not silently agree on your iPad.
Food and exercise recognition gets better when we can see the phrases it got wrong. This is off unless you switch it on, and the app works exactly the same either way.
Never leaves your device: your AI permission choices, your Apple Health or Health Connect connection choice, your parser-feedback opt-in, your acceptance of the community rules, and the local ledger holding your full spoken phrases and voice error diagnostics.
Synced to your account when you are signed in: essentially everything else you have logged. Food, weights, workouts, body composition, any sleep or heart-rate figures you typed in, today's step count, habits, trips and itineraries, your profile, plan and preferences, your voice settings and the timing ledger. It is stored in our database at Supabase so it survives a lost phone and follows you across devices.
On an iPhone, a copy is also mirrored into the app's native storage, which means it can be included in your own iCloud or iTunes device backup. That backup belongs to you, not to us.
If you post in the community, be aware of what is public.
When the app hits an error it sends us a small report so we find out it happened: the error message and stack, which screen you were on, the build number, your device model and OS version, and the last few taps that led up to it (screen names and button types, never what you typed or logged). These reports go to Sentry, a crash-reporting service hosted in the EU, which acts as our processor. When you are signed in the report carries your account ID (the same random identifier as analytics, never your name or email) so we can tell whether a bug hit one person or fifty. Everything else is filtered out before it leaves your phone: no weights, no calories, no food, no workout details, no voice or transcript text, no tokens. If Sentry is unavailable, a smaller report with no user ID goes to our own server logs instead.
The app also keeps a short ledger of voice timings, the last twenty or so, to work out why the mic felt slow. It holds millisecond measurements and stage names. No audio, no transcripts. It syncs with the rest of your account data and appears in your export.
Product analytics. To see which parts of the app help people, and how many members get stuck at the sign-in step, we use PostHog, a product-analytics service hosted in the EU. It records plain events, opening the app, finishing setup, logging a workout or a meal, opening a country guide, and it is set to send counts and simple categories only. When you are signed in these events are linked to your account ID (a random identifier, never your email), which makes them pseudonymous rather than fully anonymous. It never receives your weight, your calories, your food, your workouts, your injuries, your location, your photos, your email, or anything else you log, and we turn off the geographic look-up PostHog would otherwise do from your connection. It runs no advertising and sells nothing, and you can switch it off any time in Profile → Account & units.
There are three ways to hold a Fit Nomads membership, and they are handled differently.
Deleting your account does not cancel your billing. An Apple subscription must be cancelled in Settings → Apple Account → Subscriptions. A Google Play subscription must be cancelled in the Google Play Store under Payments & subscriptions → Subscriptions. A website subscription needs to be cancelled through us. Please do that first, or email us and we will sort it out. Our Terms of Service set this out in full.
If you buy coaching or use the website rather than the app, we collect your name and email, your payment through Airwallex, and the health and fitness information you choose to share so we can write your program. That includes goals, training history, measurements, dietary preferences and anything you tell us about injuries. You choose what to share and you can decline any of it.
The app has three separate coaching permissions, and one AI copilot that rides on the first of them. Allowing one permission does not allow either of the other two:
Coach approval comes first. A coaching switch cannot be enabled until Tijs or Abbey has added the client's sign-in email to the private coach dashboard. This prevents ordinary app accounts from opening coaching features on their own. Approval does not share any fitness data or start chat by itself; the client still controls each permission above.
Clients whose sign-in email has been approved receive a private Coaching tab containing only Messages and Resources. Approval only reveals the area; it does not share fitness data or start chat. Each message or resource remains protected by its own active permission. Workouts remain in Train and Today; habits, tasks, check-ins, appointments and goals remain on Today; progress measurements and photos remain in Profile. Coaches can deliver private documents, training videos, recipes, recipe books and sourced guidance. Assignment, open/completion status and delivery dates are stored in Supabase and included in the client's data export.
Optional coaching notifications. On iOS and Android you can separately choose to receive a background alert for a new coaching message or a scheduled coaching reminder. This switch is independent from fitness-data sharing, coach-assigned workouts and private-chat consent: enabling any coaching permission does not enable push notifications, and turning push off does not change those permissions. Apple Push Notification service (APNs) on iOS and Google Firebase Cloud Messaging (FCM) on Android act as delivery processors. Our server stores the device's bearer push token, platform, consent date/version and generic route/idempotency metadata needed to deliver and deduplicate the alert. The lock-screen payload says only that a coaching message or reminder is ready and where in the app to open it. It never contains a message or resource body, a person's name or email, health, nutrition, check-in answers, measurements, workout details or other sensitive content; the app fetches the actual content after it opens under the normal access rules. You can turn coaching notifications off at any time in Profile → Reminders. We then revoke the server endpoint and ask the device to unregister. Tokens are also revoked on sign-out, replaced if the provider rotates them, and deleted with your account. Failed or invalid endpoints are retired automatically; delivery records are kept only as operational metadata while needed for retries and audit.
Progress photos are body photos, and we treat them that way. They are entirely optional, and nothing in the app needs one. Each upload asks you to tick a separate acknowledgement first, saying that this specific photo contains sensitive body information and that your current Fit Nomads coaches can view it while coaching access is active. The image is stored as an image, in a private storage bucket we call coaching-progress, and it is opened through short-lived private links. The only people who can see it are you and your approved coaches, who are named humans you already know, Tijs and Abbey or a coach they have authorised. Photos are accepted as JPEG, PNG or WebP up to 10 MB. They are never sent to OpenAI, Anthropic or any other AI company, and you can permanently delete any of them from Profile. Meeting records and notes may be stored in the dashboard. If Google Workspace is connected, scheduling data and a Google Meet link are exchanged with Google. Any transcript imported for coaching is stored privately with its provenance, and it may be sent to the coaching copilot, and so to Anthropic, only under the current fitness-data and AI disclosure so the coach can review proposed actions.
We also keep private internal coaching notes where a coach needs them to deliver the service. They are available only to authorised Fit Nomads coaches while at least one relevant client permission is active. They are not placed in your public profile, chat or workout instructions. You can ask for access to personal data held about you by using the contact details in section 15.
Tijs and Abbey each have a separate copilot profile. It may learn the individual coach's communication and programming style from that coach's own work with clients who accepted the current coaching disclosure. Their profiles are not mixed, the copilot does not take action by itself, and we do not use client information to train a shared model.
To see which pages are useful we use two analytics services on the website: PostHog (EU-hosted), the same privacy-first analytics as the app, and Google Analytics 4. Neither is loaded until you say yes to the banner, and one answer covers both. Google Analytics runs in its consent mode with advertising features and Google signals switched off, and it is not linked to any advertising account. Both receive the same plain events, which page you opened, which button you pressed and whether you started checkout, along with the campaign a link came from. Neither receives your email, anything you log, or the tokens and addresses that can appear in our checkout links, which are stripped before a page address is recorded. There are no third-party advertising trackers. You can decline, and you can block cookies in your browser and the site will still work.
Only the providers we need to run this properly:
We may also disclose data where the law genuinely requires it. We do not sell your personal data and we do not share it for anyone else's advertising.
We are a Hong Kong company, our members are all over the world, and our providers are based in various countries including the United States and the EU. So your data will cross borders. Where it leaves your region we rely on our providers' standard contractual clauses and equivalent safeguards. If you would like to know where a particular provider stores data, ask us and we will tell you what we know.
Wherever you live, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it somewhere else. If you are in the UK, EU or another region with equivalent law, those are your rights under that law, and you can also complain to your local data protection authority. We would rather you came to us first.
Three of these you can do yourself, right now, without asking anyone. They all live in the same place in the app: Profile → Account & units, and then scroll to Your data.
If you would rather not do it yourself, or you no longer have the app, email support@thefitnomadsofficial.com with "Data request" in the subject and say what you want — a copy of your data, a correction, or your account deleted. We confirm within 2 business days and complete within 30 days. We will tell you if we have to keep something for legal reasons, such as invoices.
Both routes to deleting your account, step by step, along with what deletion removes and what we have to keep, are set out on our Delete your account page.
In plain terms: we process your account and logging data because we need it to give you the app you signed up for; we process health information such as your weight, your food and your step count on the basis of your explicit consent, which is why the app asks before it touches Apple Health on iOS or Health Connect on Android; we use consent for the AI features and the optional diagnostics; and we keep financial records because the law says we must. This is a description, not legal advice.
You need to be 18 or over to buy from us, to hold a Fit Nomads account, or to use the Fit Nomads app. That is the same rule on the website and in the app, and our Terms of Service say it too. The service is built for adults, it is not directed at children, and we do not knowingly collect data from anyone under 18. The App Store shows a 9+ rating, which describes the content rather than who we sign up. If you believe someone under 18 has created an account, email us and we will close it and delete the data.
Everything travels over HTTPS. Your data in our database is protected by row-level security, so your account can only reach its own rows. Card details are handled by Apple, Google or Airwallex and never by us. Health permissions are controlled by Apple Health on iOS or Health Connect on Android, alongside an in-app consent we ask for first. AI processing is purpose-by-purpose and gated on your explicit agreement, which is enforced in code and checked by our tests. No system is perfectly secure, but we take this seriously and we will tell you promptly if something material happens.
If we change this policy we will update the date at the top, and email you if the change is significant.
AJTV Limited, trading as Fit Nomads. support@thefitnomadsofficial.com. A human replies, within 2 business days.