Official Google Play & App Store Compliance Document
GDPR & CCPA/CPRA Compliant
Zero Raw Video Storage Guarantee
Privacy Policy
Effective Date: September 30, 2026 • Version 2.1
TuttiFitness (“we,” “our,” or “us”), operated by TuttiFitness Inc., is dedicated to protecting your privacy and ensuring transparent, ethical handling of your personal and health data. This Privacy Policy details how our application collects, uses, encrypts, and safeguards information across our web application (https://tuttifitness.com) and mobile experiences.
Core Privacy Principle: TuttiFitness operates on a strict data-minimization model. Camera feeds analyzed by the AI coach are processed ephemerally in volatile memory and never recorded, stored on disk, or transferred to third parties.
1. Camera Feed & AI Pose Coaching (Zero Video Retention)
The AI Coach utilizes camera input solely while an active exercise session is explicitly initiated by you:
- In-Memory Processing: Live video frames are converted into anatomical coordinates (33 skeletal keypoints) via our computer vision engine in volatile system RAM.
- Immediate Discard: Once kinematic angles and repetition state calculations are completed, the raw frame data is discarded instantly. We do not save, record, encode, or store your camera images or video recordings under any circumstances.
- No Biometric Facial Identification: Keypoint models detect joint angles (elbows, knees, hips) and do not extract facial templates, retinal patterns, or any identifiers capable of uniquely recognizing you as an individual.
- Session Summaries: At the conclusion of a set, only numerical workout metrics are saved to your account: exercise name, completed rep count, set duration, and form-quality percentage (the proportion of rep time performed without kinematic warnings).
2. Health, Nutritional & Biometric Information
We process health and biometric data that you enter during onboarding or daily tracking:
- Physical Measurements: Height, body weight, target weight, age, and assigned gender used solely to calculate Base Metabolic Rate (BMR) and Total Daily Energy Expenditure (TDEE) via the scientifically validated Mifflin-St Jeor equation.
- Nutritional Logs: Meal entries, macronutrients (protein, carbohydrates, fats), micronutrients, and water intake logged in your nutrition diary.
- Workout History: Exercise selection, logged sets, resistance weights, and training cadence.
- Hardware Isolation: TuttiFitness does not access third-party health data from wearable devices, Apple HealthKit, or Google Health Connect without your explicit authorization.
3. Account, Activity & Security Records (Security & Customized Experience)
To safeguard member accounts, prevent unauthorized access, and power an individualized, highly customized fitness experience, TuttiFitness systematically records operational use:
- Security & Audit Records: Log-in timestamps, authenticated session tokens, client IP addresses, device identifiers (device type, operating system, browser engine), and failed authentication attempts are continuously tracked to protect against account takeover, mitigate credential stuffing, and enforce automated rate limits (GDPR Art. 6(1)(f) Legitimate Interest; CCPA/CPRA).
- Customized Experience & Personalization Records: Workout histories, completed sets, reps, resistance weights, cadence/tempo, AI form scores, nutrition logs, and gym equipment physical pin and seat height calibrations are saved to your profile. This telemetry enables TuttiFitness to calculate personalized progressive overload curves, generate adaptive daily training splits, and remember your exact ergonomic machine settings (GDPR Art. 6(1)(b) Contractual Performance).
- Member Transparency & Control: You maintain full visibility into your records. You can inspect your own real-time security and activity audit trail at any time via your member dashboard (/api/profile/activity) and customize your coaching preferences (/api/profile/customization).
- Retention Schedules: Security telemetry is retained for 12 months for forensic audit, after which it is purged. IP addresses are truncated after 90 days. Member activity and customized training records are preserved for 24 months to support longitudinal fitness tracking. Automated nightly scripts enforce these schedules.
- Zero Sensitive Leakage: We strictly filter sensitive fields. Passwords, session secrets, credit card numbers, and live camera video frames are never recorded into telemetry logs.
4. Community Features (Strictly Optional)
If you choose to enable “Show me in the community” in your account settings:
- Only your public display name, finished workout milestones, personal bests, and streak counts are visible to fellow athletes on the public leaderboard.
- Your email, body weight, dietary diary, and camera sessions remain 100% private and are never shared publicly.
- You can revoke community visibility at any time in Profile Settings, which immediately removes your data from community feeds.
5. Payment Processing & Third-Party Services
We do not sell, rent, monetize, or trade your personal or health information to data brokers, ad networks, or third parties:
- Payment Processing: All subscription payments are processed directly by Stripe Inc. (PCI-DSS Level 1 certified). TuttiFitness servers never receive, store, or process your full credit card numbers or CVC security codes.
- Hosting & Infrastructure: Our cloud hosting infrastructure is hosted in secured data centers with strict access control.
- Network Security: Network traffic is protected by Cloudflare for DDoS mitigation, Web Application Firewall (WAF), and global CDN delivery.
6. Your Legal Data Rights (GDPR, CCPA/CPRA, UK DPA)
Regardless of your geographic location, TuttiFitness extends complete privacy rights to all members:
- Right to Access & Portability: You may request a full export of your profile, workout, and nutrition logs in machine-readable JSON format.
- Right to Rectification: You may update or correct your personal metrics at any time through the in-app Profile screen.
- Right to Erasure (“Right to be Forgotten”): You may permanently delete your account, biometric data, and logs at any time via our automated self-service portal at https://tuttifitness.com/delete-account or by emailing our privacy team. Deletions are processed within 48 hours.
- Do Not Sell or Share: We do not sell or share personal data as defined by the California Consumer Privacy Act (CCPA/CPRA).
7. Technical Data Security & Encryption
We implement defense-in-depth security standards to protect your data:
- Encryption in Transit: All communications between your client device and TuttiFitness servers are encrypted using modern Transport Layer Security (TLS 1.2 / TLS 1.3) with HSTS enforcement.
- Encryption at Rest: Application databases and configuration secrets are restricted with strict operating system access controls (POSIX 600 permissions, inaccessible to unprivileged processes).
- Modern Cryptography: Passwords are cryptographically salted and hashed using PBKDF2 with 100,000+ iterations of HMAC-SHA256. Authentication tokens use tamper-evident HMAC-SHA256 signatures with mandatory expiration.
8. Cookies & Local Storage
TuttiFitness does not use third-party advertising or cross-site tracking cookies. We utilize browser localStorage strictly for necessary functional operations: maintaining your authenticated session token (token) and saving offline interface preferences.
9. Children’s Privacy (COPPA Compliance)
TuttiFitness is designed and intended for individuals aged 16 and older (or 13 and older with verified parental or guardian consent). We do not knowingly collect, solicit, or maintain personal or biometric information from children under the age of 13. If we become aware that a child under 13 has provided us with personal data, we will immediately delete that information from our database.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect technological improvements, service features, or regulatory requirements. Any material changes will be announced via an in-app notice or email notification prior to the change becoming effective. The “Effective Date” at the top of this document will reflect the date of the latest update.
11. Contact Our Data Protection Officer
For questions, privacy requests, data export, or assistance regarding our data practices, please contact our Data Protection Officer:
Data Protection Officer: Privacy & Data Governance Team
Email: [email protected]
Mailing Address: TuttiFitness Inc., Legal & Compliance Department
Official Website: https://tuttifitness.com