Legal
Privacy Policy
1. Who we are
FiThrive is a platform that helps sports teams and their staff monitor athlete readiness, plan their season, and communicate as a squad. This policy explains what personal data we handle when you use the FiThrive mobile and web application (the “App”) and the FiThrive website at fithrive.app (the “Site”), and the choices and rights you have.
The controller responsible for your personal data is FiThrive, the operator of the FiThrive application and the website at fithrive.app. Privacy contact: info@fithrive.app.
FiThrive is operated from outside the European Economic Area (EEA) and the United Kingdom. Where the GDPR or UK GDPR applies because we offer the App to individuals in those areas, we appoint a representative under Article 27 of the GDPR / UK GDPR. We are in the process of appointing our EEA/UK representative, and will publish their name and contact address here once the appointment is complete.
Throughout this policy, “we,” “us,” and “our” mean FiThrive as described above.
2. Scope and the laws that apply
FiThrive is available globally. Depending on where you are, different privacy laws give you different rights. This policy is written to meet, at minimum:
- the EU General Data Protection Regulation (GDPR) and the UK GDPR;
- the California Consumer Privacy Act, as amended by the CPRA (CCPA/CPRA); and
- the Washington My Health My Data Act (MHMDA).
Section 11 (California) and Section 12 (consumer health data) contain rights and disclosures specific to those laws. Everything else in this policy applies to everyone.
How you reach FiThrive matters. FiThrive is invite-only. You receive access through a team or organization (“your Organization”) that runs FiThrive for its athletes and staff. For most of the data you enter, your Organization decides why and how it is used – in data-protection terms, your Organization is a controller (or joint controller with us) and we act partly on its behalf. Where that is the case, your Organization’s own privacy notice may also apply to you, and you can direct requests to either your Organization or us.
3. The information we collect
We only collect what the App actually needs to work. We group it below by category.
3.1 Account and profile information
- Identity: your full name and email address, used to create and sign in to your account.
- Profile details you choose to add: date of birth, nationality, phone number, mailing address, playing position, and a profile photo.
- Physical attributes you enter: height and weight. These are self-reported – you type them in; we do not measure them.
- Role and team: your role (for example athlete, coach, staff, or admin) and the team you belong to.
You provide most of this yourself during account setup. If you sign in with Google or Apple, we receive your name and email address from that provider to create your account (see Section 5).
3.2 Self-reported wellness and training data
The heart of FiThrive is athlete readiness. When you complete a training or morning-log form, you tell us things like your sleep quantity and quality, mood, muscle soreness, and fatigue, along with any other answers a form asks for. From these inputs the App computes a readiness score on your device.
This is health-related information about you. Because it is sensitive, it is end-to-end encrypted: your answers and the computed scores are encrypted on your device before they are stored, and our servers hold only ciphertext. We – and anyone with access to our database – cannot read your form answers or scores. Only you and the people your Organization authorizes, who hold the right decryption keys, can read them. See Section 6.
3.3 Messages, notes, and content you create
- Messages you send in direct, group, and channel chats.
- Notes and other content you write in the App.
- Files you upload.
All of this is end-to-end encrypted (Section 6). We store only encrypted data; we cannot read the contents. Related metadata that is not encrypted – such as who sent a message and when – is described in Section 6.
3.4 What we do not collect
To be clear about the sensitive categories people often ask about:
- No wearable or device-sensor health data. FiThrive does not connect to Apple Health, Google Health Connect, Google Fit, or any wearable, and does not collect heart rate, heart-rate variability, blood oxygen, step counts, workouts, or any sensor-measured health or fitness data. The only health-related data we hold is the self-reported information described in Sections 3.1 and 3.2.
- No precise location. We do not collect GPS or device location.
- No advertising or cross-app tracking. We do not use advertising identifiers, do not embed any third-party advertising or marketing-analytics SDKs (no Google Analytics, no Meta Pixel, no Mixpanel, and the like), and do not track you across other apps or websites.
3.5 Usage analytics
To understand how the App is used and to improve it, we collect first-party usage analytics – for example which screens are opened, which buttons are tapped, that a form was submitted or an event scheduled, how long a session lasted, and error signals. This is metadata only: it records that an action happened, never the personal content of your messages, notes, or form answers.
You control this. When you first set up your account, the App asks you to allow or decline analytics, and you can change that choice at any time in Account Settings → Privacy. If you turn analytics off, the App stops collecting it. This data is stored on our own servers and is never sold or sent to a third-party analytics company.
3.6 Diagnostics and crash reports
If the App encounters an error, we record technical diagnostic information – an error message and stack trace, the app version, and the platform (for example iOS or Android) – to find and fix bugs. Crash and error reports are stored on our own servers; we do not use Sentry, Crashlytics, or any third-party crash-reporting service.
3.7 Device and technical information
- Push tokens. To deliver notifications, we store the push token issued to your device by Apple (APNs) or Google (Firebase Cloud Messaging), along with the device platform. Notification previews are generic (for example “You have a new message”) and never contain the content of a message.
- Authentication identifiers. Standard identifiers needed to keep you signed in securely, and the account identifier your provider gives us if you use Google or Apple sign-in.
3.8 Website information
The Site (fithrive.app) is a largely static informational website. It uses only the cookies and local storage strictly necessary to serve the pages and remember basic preferences; it does not run advertising or third-party analytics trackers. If we add any non-essential cookies in the future, we will ask for your consent first and update this policy.
4. Why we use your information, and our legal bases
We use personal data for the purposes below. Where the GDPR / UK GDPR applies, the legal basis for each is noted.
| Purpose | Legal basis (GDPR / UK GDPR) |
|---|---|
| Create your account, authenticate you, and run the App’s core features | Performance of a contract; and, where your Organization directs the processing, its legitimate interests |
| Provide readiness tracking, messaging, notes, and other features you use | Performance of a contract |
| Send you service notifications (for example a new message or a scheduled event) | Performance of a contract; legitimate interests |
| Secure the service, prevent abuse, and keep audit and delivery logs | Legitimate interests (keeping the service safe and reliable) |
| Diagnose and fix errors and crashes | Legitimate interests (maintaining a working product) |
| Understand usage to improve the App (analytics) | Your consent (you choose at onboarding and can withdraw any time) |
| Comply with legal obligations and respond to lawful requests | Legal obligation |
For self-reported wellness data and other data that may be considered a special category under Article 9 GDPR (data concerning health), we rely on your explicit consent, and/or on the fact that the data is processed under your Organization’s occupational/athletic-performance program with appropriate safeguards. Because this data is end-to-end encrypted, we hold it in a form we cannot read.
5. Who we share information with
We do not sell your personal data, and we do not share it for cross-context behavioral advertising.
We share data only in these situations:
- Within your Organization. People your Organization authorizes – for example your coaches or staff – can see the data relevant to their role, according to the permissions your Organization configures.
- Service providers (subprocessors) who help us run the App. We use a small, fixed set of providers, each of which processes data only to perform services for us under contract:
| Provider | What they do for us | Data involved |
|---|---|---|
| Supabase | Core backend – authentication, database, file storage, serverless functions | Account/profile data, encrypted content, analytics, diagnostics |
| Google / Firebase | Push-notification delivery (Firebase Cloud Messaging); Google Sign-In (if you use it) | Push tokens; Google account identity if you use Google sign-in |
| Apple | Push-notification delivery (APNs); Sign in with Apple (if you use it) | Push tokens; Apple account identity if you use Apple sign-in |
| Resend | Sending transactional emails (for example invitations and account emails) | Email address and the message content of those emails |
- Legal and safety reasons. We may disclose data if required by law, to respond to lawful requests, or to protect the rights, safety, and security of our users, the public, or FiThrive.
- Business transfers. If FiThrive is involved in a merger, acquisition, or sale of assets, data may be transferred as part of that transaction; we will require the recipient to honor this policy or notify you of any material change.
Note that for your end-to-end-encrypted content (messages, notes, files, form answers), any provider that stores it – including Supabase – holds only ciphertext they cannot read.
6. Zero-knowledge, end-to-end encryption
FiThrive is built so that your most sensitive data is readable only by you and the people you share it with – not by us.
How it works, in plain terms. When you set up your account, the App creates a personal set of encryption keys. Your private key is protected by a key derived from your password and is stored only in an encrypted form we cannot unlock. When you send a message, write a note, or submit a readiness form, the content is encrypted on your device before it leaves it. Our servers store only the encrypted result. To share something (for example a group message), the App securely delivers the necessary keys to the other authorized members’ devices, so only they can decrypt it.
What this means:
- We cannot read your direct, group, or channel messages; your notes; your uploaded files; or your readiness form answers and scores. Neither can anyone who gains access to our database.
- What is not encrypted content (and so is technical/operational metadata we can see): account and profile fields, the fact that a message was sent and between whom and when, analytics metadata, crash logs, and push tokens. Channel names, descriptions, and system messages (such as “channel created”) are also not message content.
- A trade-off you should understand: because only your keys can decrypt your content, if you lose your password and any recovery method your Organization provides, that encrypted content may become permanently unrecoverable. This is a deliberate consequence of protecting your data this strongly.
This design also shapes your data-export rights (Section 10): we can export the data we can read, but we cannot export the plaintext of content only your keys can decrypt.
7. Security
We protect your data with, among other measures:
- Encryption in transit (TLS) for all traffic between the App and our servers.
- End-to-end encryption of your sensitive content, as described in Section 6.
- Row-level security on our database, so each user and Organization can access only the data they are permitted to.
- Multi-factor authentication (MFA). Time-based one-time-password (TOTP) MFA is required for coach, staff, and admin accounts, which have broader access. Athlete accounts may use the standard sign-in methods.
- Access controls and internal-access limits for our own personnel.
No system is perfectly secure, but we work to protect your data and to meet our obligations under applicable law (including Article 32 GDPR).
8. Where your data is stored, and international transfers
Your data is hosted on our providers’ infrastructure. Our primary backend (Supabase) stores your data in the European Union – Frankfurt, Germany (eu-central-1) region. This means your account data and your encrypted content are held at rest within the EU.
However, two things involve processing outside the EEA. First, FiThrive is operated from outside the EEA – currently from Serbia, and in future from the United States – so your data may be accessed from there to run and support the service. Second, some providers we rely on for specific functions – push-notification delivery (Google/Firebase, Apple) and transactional email (Resend) – may process limited data such as push tokens or email addresses outside the EEA, including in the United States.
Where personal data of individuals in the EEA or UK is transferred outside those areas, we rely on appropriate safeguards – principally the European Commission’s Standard Contractual Clauses (and, for the UK, the International Data Transfer Addendum) – to protect it. You can ask us for more information about these safeguards using the contact details in Section 15.
9. How long we keep your data
We keep personal data for as long as your account is active and as needed to provide the service, and then only as long as we have a legitimate or legal reason to retain it. In particular:
- While your account is active, we keep your account, profile, content, and related data so the App works.
- When you delete your account (Section 10), we anonymize your profile and remove or render permanently unreadable your personal identifiers and your private encryption keys, so your encrypted content can no longer be decrypted. Some records are retained in anonymized or minimized form where necessary – for example to preserve the integrity of an Organization’s shared data (such as a team record a former member contributed to), to keep security and audit logs, or to meet legal obligations.
- Invitations that are not accepted have their personal details removed after they expire.
- Backups. Encrypted backups are kept for a limited window by our infrastructure provider and are overwritten on a rolling basis; data you delete persists in backups only until those backups cycle out.
We do not currently operate a fixed automatic deletion schedule for active-account data; we retain it under the principles above and delete it when it is no longer needed.
10. Your privacy rights
Subject to your local law, you have some or all of the following rights over your personal data:
- Access – get a copy of the data we hold about you.
- Rectification – correct data that is inaccurate or incomplete.
- Erasure – ask us to delete your data (“right to be forgotten”).
- Restriction and objection – limit or object to certain processing, including processing based on legitimate interests.
- Portability – receive certain data in a portable, machine-readable format.
- Withdraw consent – where we rely on consent (for example analytics), withdraw it at any time, without affecting processing that already happened.
How to exercise them. You can access and correct much of your profile directly in the App, toggle analytics in Account Settings → Privacy, export your data using the in-App data-export feature, and delete your account from settings. You can also contact us at info@fithrive.app and we will respond within the timeframes required by law.
One limitation to be transparent about: because of the end-to-end encryption described in Section 6, a data export or access request can include the data we are able to read, but cannot include the plaintext of content that only your keys can decrypt (your messages, notes, files, and form answers). Those remain available to you inside the App, where your device can decrypt them.
If you believe we have not handled your data properly, you have the right to complain to your local data protection authority (in the EEA, your national supervisory authority; in the UK, the Information Commissioner’s Office). We would appreciate the chance to address your concern first.
11. California privacy rights (CCPA/CPRA)
If you are a California resident, you have the rights to know/access, delete, correct, and to opt out of the sale or sharing of your personal information, as well as the right not to be discriminated against for exercising these rights.
Notice at collection. The categories of personal information we collect, the purposes, and the parties we disclose to are described in Sections 3-5. We collect identifiers, contact and profile data, self-reported physical and wellness information, user-generated content (encrypted), internet/usage activity (analytics), and inferences drawn from readiness inputs (computed on your device and encrypted).
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the preceding 12 months. Because we do not sell or share, no “Do Not Sell or Share My Personal Information” action is required – but you may still contact us to confirm this or to exercise any right.
Sensitive personal information. The self-reported health-related data described in Sections 3.1-3.2 may be “sensitive personal information.” We use it only to provide the readiness features you and your Organization use – not to infer characteristics about you for any other purpose – so the CPRA “right to limit the use of sensitive personal information” is already reflected in how the product works. You may still contact us with any request.
To exercise California rights, contact info@fithrive.app. We will verify your request as required and will not discriminate against you for making one. Authorized agents may submit requests on your behalf with proof of authorization.
12. Consumer health data (Washington My Health My Data Act)
Some of the data FiThrive processes – your self-reported sleep, mood, soreness, fatigue, other readiness form answers, and your height and weight – may be “consumer health data” under Washington’s My Health My Data Act and similar laws.
- We collect it only with your involvement and to provide the readiness features you and your Organization use. We do not use it for advertising, and we do not sell it.
- It is end-to-end encrypted (Section 6), so we store it in a form we cannot read.
- We do not share consumer health data except as needed to store it in encrypted form with our infrastructure provider (which cannot read it) and with the people in your Organization you or it authorizes. We will not sell consumer health data, which would require your separate valid authorization under the MHMDA – and we do not do so.
- Your rights. You may request to access, or to delete, your consumer health data, and to withdraw consent to its collection, by contacting info@fithrive.app or using the in-App controls.
13. Children and minors
FiThrive is designed for use by sports organizations, which may include youth athletes. FiThrive is intended for people aged 16 and over. People aged 16 or older may use the App under their Organization’s program. A person under 16 may be enrolled only through their Organization and only where the parental or guardian consent required by law in their jurisdiction has been obtained; the Organization is responsible for obtaining that consent and confirming it has the authority to place the minor’s data in the App. In no case do we knowingly create accounts for children under 13.
At account setup we collect date of birth, and for anyone under 16 we require an explicit confirmation that the necessary parental, guardian, or organizational consent has been obtained. If we learn that we have collected data from a child under 13, or from an under-16 user without the required consent, we will delete it. If you believe a child has provided us data improperly, contact us at info@fithrive.app.
14. Changes to this policy
We may update this policy as the App and the law evolve. When we make a material change, we will update the “Last updated” date and, where appropriate, notify you in the App or by email and (where required) ask for renewed consent. The App records which version of this policy you have acknowledged.
15. How to contact us
FiThrive
Privacy contact: info@fithrive.app
EEA/UK representative (Article 27): being appointed – contact details will be published here once confirmed.
If you are in the EEA or UK, you also have the right to lodge a complaint with your local supervisory authority.