CorFit

Last updated July 2026

Privacy Policy

We believe your health data belongs to you. Here's exactly what we collect, why, and how you can delete it.

What We Collect

Account Data

When you create an account we collect your email address and display name. If you sign in with Google, we receive your Google profile information as permitted by Google's OAuth scope.

Linked to identity Required for app function

Health & Fitness Data

You voluntarily provide body metrics (height, weight, age), fitness goals, dietary preferences, workout logs, nutrition logs, and personal records. This data is stored in your private Firestore account document and is never sold or shared with advertisers.

Linked to identity Required for app function

Apple Health (HealthKit)

If you grant permission, CorFit writes completed workout sessions (duration and estimated active calories) to Apple Health on your device. We do not read data from Apple Health. HealthKit data is never uploaded to our servers, shared with third parties, or used for advertising.

Write-only Never uploaded Not linked to identity

AI Workout & Meal Generation

When you generate an AI workout or meal plan, your profile data (age, weight, height, fitness goals, dietary preferences, activity level) is sent to Anthropic's Claude AI via our secure proxy server to generate personalised recommendations. No personally identifiable information is stored by Anthropic. See anthropic.com/privacy for details.

Sent to AI proxy Not permanently stored by Anthropic

Camera & Barcode Scanning

If you use the barcode scanner in the Nutrition section, the camera captures barcodes which are sent to the Open Food Facts public API to look up nutritional information. No images are stored or uploaded. Camera access is only used during an active scan.

Open Food Facts API No images stored

Team & Community Data

If you join a team, your display name and any workouts the team host chooses to post are visible to other members of that team. Team hosts can also lock chat or mute individual members. Workout posts, likes, and team membership are stored in Firestore and accessible only to your team members.

Visible to team members

Team Leaderboard Data

Teams display a top-3 leaderboard ranking members by personal record values (max weight and max reps per exercise). This ranking is visible only to members of your team, not to the wider CorFit user base. Leaving a team removes you from that team's leaderboard.

Visible to team members only

Team Chat & Direct Messages

If you send messages in a team chat or a direct message thread, the message content, your display name, and timestamp are stored in Firestore and visible to the recipient(s) — team members for team chat, or the other participant for a direct message. Messages are automatically screened by an on-device content filter before sending to block hateful or explicit language. You can block another user, which hides their messages from you going forward.

Visible to recipients only Client-side content filter

Subscription & Purchase Data

Subscription management is handled by RevenueCat. We receive anonymised purchase records (subscription tier, renewal status) to unlock Pro/Unlimited features. Payment details are processed by Apple and are never visible to us. See revenuecat.com/privacy.

RevenueCat No payment details stored

Usage Data

We collect anonymised usage statistics (feature interactions, app version, device OS) to improve the product. This data is not linked to your identity.

Not linked to identity Anonymised

Notifications

If you enable workout reminders or weekly digest notifications, we store a local notification schedule on your device. No device token or push token is sent to our servers — all notifications are local.

Local only No server storage

How We Use Your Data

Data Sharing

We do not sell your data. We share data only with the following third parties, solely to operate the app:

Your display name, PR values, workout posts, and chat/message content are only shared with the members of teams you join or the individuals you message directly — never with the wider CorFit user base.

Security

All data is encrypted in transit using TLS. Data stored in Firebase is encrypted at rest using AES-256 by default. We use Firebase Security Rules to ensure each user can only access their own private data, team data, and message threads.

Data Retention & Deletion

You may delete your account and all associated data at any time by contacting support@thecorfit.com. We will process deletion requests within 30 days. Leaving a team immediately removes you from that team's leaderboard and chat.

Children

CorFit is not intended for users under the age of 13. We do not knowingly collect personal data from children. If you believe a child under 13 has provided us data, please contact us immediately.

Changes to This Policy

We may update this policy from time to time. Material changes will be communicated in-app. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the app after changes constitutes acceptance.

Contact

Questions or requests regarding your privacy? Email us at support@thecorfit.com.