FitFatta
Download
Privacy

Your data, your terms.

FitFatta is built on a simple promise: the food you eat and the workouts you do are nobody's business but yours. This page explains what we collect, why, and the controls you always have over it.

Last updated · 28 August 2026

Who we are

FitFatta is a mobile application operated by STONiFi CX Ltd, a company registered in the United Kingdom (the "Service"). "We", "us", and "FitFatta" refer to STONiFi CX Ltd. You can reach our privacy team at support@fitfatta.com.

This policy is written to comply with Saudi Arabia's PDPL, the UAE's PDPL, the EU's GDPR, and California's CCPA — and we honour it for every user, wherever you live.

What we collect

Account information — your email, a hashed password (never stored in plain text), your language preference, country, and timezone. If you sign in with Apple or Google, we receive your email, its verified status, and your display name — nothing else from those accounts.

Profile information you enter during onboarding — date of birth, gender at birth (used only for calorie calculations), height, weight, target weight, activity level, goal, dietary preferences, allergies, cuisine preferences, and health conditions. All optional, and you can edit or delete any of it at any time.

Health and activity logs — the meals, water, and supplements you record, weight logs, body measurements, workout sessions, and any progress photos you choose to upload.

Progress photos are stored privately in Cloudflare R2 and encrypted at rest. Only you can see them. They are never sent to AI providers, never used for advertising, and never sold or shared.

Device and usage information — push notification token, approximate device model and OS version, and an anonymised IP address used for rate limiting. Crash reports (via Sentry) are scrubbed of your name, email, and health data; product analytics (via PostHog) carry only an anonymised id and event counts.

What we do not collect: your contacts, calendar, phone number, precise location, photo library (beyond what you explicitly upload), microphone, or health records from Apple Health. No ad-network trackers, no device fingerprinting.

How we use it

To deliver the Service — generate meal plans and workouts, calculate macros, track progress, and remind you about meals or workouts you scheduled.

To improve the Service — fix bugs, study which features work, and make the AI better at understanding Arabic dialects. We use aggregated, de-identified data for this. We do not sell or share individual logs.

To communicate with you — service updates (password resets, billing receipts) and, only if you opt in, product newsletters.

To meet legal obligations — for example, responding to a valid law-enforcement request, or complying with tax and consumer-protection laws.

How AI processes your data

FitFatta routes your AI requests across several providers — currently DeepSeek as the primary, with Anthropic (Claude), OpenAI, and Google (Gemini) as fallbacks for reliability.

Every request is anonymised. A provider receives only the prompt needed for that request — your goals, preferences, and constraints — never your name, email, or progress photos. Our agreements contractually bar every provider from using your data to train their models.

AI-generated plans are suggestions, not medical advice. See the Terms of Service for the full disclaimer.

Who we share data with

We do not sell your data. We do not show third-party advertising in the app or on this website.

We share the minimum necessary with processors who help us run the Service — Neon (database), Cloudflare (hosting, CDN, R2 photo storage, and background queues), Upstash (rate limiting and session cache), Resend (transactional email), Sentry (error reporting), PostHog (aggregate product analytics), Expo (push notification delivery via Apple's push service), Apple (subscription billing), and the AI providers listed above. Each is contractually bound to use your data only to provide their service to us.

If FitFatta is ever acquired or merges with another company, we will notify users in advance and your data will continue to be handled under a policy at least as protective as this one.

Where your data lives

Our primary database (Neon) runs in the Bahrain region (me-south-1). Some of our processors store data in the EU or the US — Cloudflare R2 (progress photos), Upstash, Resend, Sentry, and PostHog.

Whenever data crosses borders, the transfer is protected by contractual safeguards — GDPR Standard Contractual Clauses, PDPL-compliant transfer clauses, or equivalent terms.

How long we keep it

Your account, profile, and health data are kept for as long as your account is active.

Crash reports are kept for 90 days, product analytics events for 12 months, and AI usage logs for 12 months. Anonymised billing and AI-usage records may be retained for up to 7 years for legal and accounting purposes.

You can export everything we hold on you in a machine-readable format from Profile → Export data.

Deleting your account

When you request deletion, your account is deactivated immediately — you are signed out on every device and sign-in is blocked.

You then have a 30-day grace window in which you can change your mind: cancel the deletion in the app with "Cancel deletion", or via the link in the confirmation email we send you. After the 30 days end, your data is hard-deleted and cannot be recovered.

Security

All traffic is encrypted in transit (TLS) and data is encrypted at rest. Passwords are hashed, never stored in plain text, and sessions use scoped, short-lived tokens.

No system is perfectly secure. If you discover a vulnerability, tell us at support@fitfatta.com and we will act on it quickly.

Your rights

You can access, correct, and export your data from inside the app (Profile → Export data), delete your account (with the cancellable 30-day grace window described above), opt out of analytics in the in-app privacy settings, and withdraw consent for push notifications at any time. You can also ask us to restrict or object to processing.

Depending on where you live, these rights are also statutory — under Saudi Arabia's PDPL, the UAE's PDPL, the EU's GDPR, or California's CCPA. We honour them globally; you do not have to live in a specific country to exercise them.

Email support@fitfatta.com and we will respond within 30 days. If you are not satisfied with our response, you can complain to your local data-protection authority — in Saudi Arabia, that is SDAIA.

Children

FitFatta is not directed at children under 13, and we do not knowingly collect data from anyone under 13. Users aged 13 to 18 need the consent of a parent or guardian. If you believe a child has created an account, contact us and we will remove it.

Changes to this policy

We will update this page when our practices change. Material changes will be announced inside the app and by email at least 30 days before they take effect. The "Last updated" date at the top of this page always reflects the current version.

Contact

Questions, requests, or complaints — support@fitfatta.com.