FiThrive
Contact us
Platform Team Testimonials Contact us Privacy Policy Terms of Use
← Back to FiThrive

Legal

Privacy Policy

Last updated 28 August 2026

Contents

  1. Who we are
  2. Scope and the laws that apply
  3. The information we collect
  4. Why we use your information
  5. Who we share information with
  6. Zero-knowledge encryption
  7. Security
  8. Storage and international transfers
  9. How long we keep your data
  10. Your privacy rights
  11. California rights (CCPA/CPRA)
  12. Consumer health data (MHMDA)
  13. Children and minors
  14. Changes to this policy
  15. How to contact us

1. Who we are

FiThrive is a platform that helps sports teams and their staff monitor athlete readiness, plan their season, and communicate as a squad. This policy explains what personal data we handle when you use the FiThrive mobile and web application (the “App”) and the FiThrive website at fithrive.app (the “Site”), and the choices and rights you have.

For most of the data you enter into the App, your Organization decides why and how it is used – in data-protection terms your Organization is the controller, and FiThrive acts as its processor. FiThrive is the controller in its own right for a narrower set of activities that it decides on itself: administering your account, the optional in-App usage analytics you may choose to enable, diagnostic and crash data used to keep the App working, aggregation and anonymization of that analytics and diagnostic data to improve the product, and our own website and marketing activity. Privacy contact: info@fithrive.app.

This policy is issued by FiThrive, Inc., a corporation organized under the laws of the State of Delaware, United States, registration number 10727304, with its registered address at 24A Trolley Square #1265, Wilmington, DE 19806-3334, United States. Where this policy says “FiThrive,” it means FiThrive, Inc.

FiThrive, Inc. is established outside the European Economic Area (EEA), the United Kingdom, and Switzerland. Where the GDPR applies because we offer the App to individuals in the EEA, FiThrive, Inc. has appointed Data Protection Representative Limited (trading as DataRep) as its representative in the European Union under Article 27 GDPR. The same company is the representative of FiThrive, Inc. in Switzerland under the Swiss Federal Act on Data Protection, and the legal representative of FiThrive, Inc. in the European Union under Article 13 of the Digital Services Act. If you are in the EEA or Switzerland, you can raise any question or request about how we process your personal data with them, in English or in any official language of the EU:

DataRep, 77 Camden Street Lower, Dublin, D02 XE80, Ireland – digitalrequest@datarep.com – +353 (1) 919 8899

Please address correspondence to “DataRep” and mention FiThrive, Inc., otherwise it may not reach us. DataRep handles data-protection and regulatory correspondence only – for anything about the App, your account, or support, write to info@fithrive.app.

We do not offer the App to individuals in the United Kingdom, and we have therefore not appointed a representative under the UK GDPR. If that changes, we will appoint one and update this policy.

Throughout this policy, “we,” “us,” and “our” mean FiThrive, Inc. as described above.

2. Scope and the laws that apply

FiThrive is available globally. Depending on where you are, different privacy laws give you different rights. This policy is written to meet, at minimum:

  • the EU General Data Protection Regulation (GDPR);
  • the Swiss Federal Act on Data Protection (FADP);
  • the California Consumer Privacy Act, as amended by the CPRA (CCPA/CPRA); and
  • the Washington My Health My Data Act (MHMDA).

Section 11 (California) and Section 12 (consumer health data) contain rights and disclosures specific to those laws. Everything else in this policy applies to everyone. Section 15 also carries the contact information we are required to publish under the EU Digital Services Act.

How you reach FiThrive matters. FiThrive is invite-only. You receive access through a team or organization (“your Organization”) that runs FiThrive for its athletes and staff. For most of the data you enter, your Organization decides why and how it is used – in data-protection terms, your Organization is the controller and we act on its behalf as its processor. Where that is the case, your Organization’s own privacy notice may also apply to you, and you can direct requests to either your Organization or us.

3. The information we collect

We only collect what the App actually needs to work. We group it below by category.

3.1 Account and profile information

  • Identity: your full name and email address, used to create and sign in to your account.
  • Profile details you choose to add: date of birth, nationality, phone number, mailing address, playing position, and a profile photo.
  • Physical attributes you enter: height and weight. These are self-reported – you type them in; we do not measure them.
  • Role and team: your role (for example athlete, coach, staff, or admin) and the team you belong to.

You provide most of this yourself during account setup. If you sign in with Google or Apple, we receive your name and email address from that provider to create your account (see Section 5).

3.2 Self-reported wellness and training data

The heart of FiThrive is athlete readiness. When you complete a training or morning-log form, you tell us things like your sleep quantity and quality, mood, muscle soreness, and fatigue, along with any other answers a form asks for. From these inputs the App computes a readiness score on your device.

This is health-related information about you. Because it is sensitive, it is end-to-end encrypted: your answers and the computed scores are encrypted on your device before they are stored, and our servers hold only ciphertext. We – and anyone with access to our database – cannot read your form answers or scores. Only you and the people your Organization authorizes, who hold the right decryption keys, can read them. See Section 6.

3.3 Messages, notes, and content you create

  • Messages you send in direct, group, and channel chats.
  • Notes and other content you write in the App.
  • Files you upload in chats, notes, and your Organization’s library.
  • Profile pictures, team and group images, and chat wallpapers you choose.

The first three are end-to-end encrypted (Section 6). We store only encrypted data; we cannot read the contents. Related metadata that is not encrypted – such as who sent a message and when – is described in Section 6.

Profile pictures, team and group images, and chat wallpapers are the exception: they are stored as ordinary image files on our servers, protected by access rules rather than by end-to-end encryption, because they are shown to other members of your Organization by design. Do not use a profile picture you would not want your Organization’s members to see.

3.4 What we do not collect

To be clear about the sensitive categories people often ask about:

  • No wearable or device-sensor health data. FiThrive does not connect to Apple Health, Google Health Connect, Google Fit, or any wearable, and does not collect heart rate, heart-rate variability, blood oxygen, step counts, workouts, or any sensor-measured health or fitness data. The only health-related data we hold is the self-reported information described in Sections 3.1 and 3.2.
  • No precise location. We do not collect GPS or device location.
  • No advertising or cross-app tracking. We do not use advertising identifiers, do not embed any third-party advertising or marketing-analytics SDKs (no Google Analytics, no Meta Pixel, no Mixpanel, and the like), and do not track you across other apps or websites.

3.5 Usage analytics

To understand how the App is used and to improve it, we collect first-party usage analytics – for example which screens are opened, which buttons are tapped, that a form was submitted or an event scheduled, how long a session lasted, and error signals. This is metadata only: it records that an action happened, never the personal content of your messages, notes, or form answers.

You control this. When you first set up your account, the App asks you to allow or decline analytics, and you can change that choice at any time in Account Settings → Privacy. If you turn analytics off, the App stops collecting it. This data is stored on our own servers and is never sold or sent to a third-party analytics company.

3.6 Diagnostics and crash reports

If the App encounters an error, we record technical diagnostic information – an error message and stack trace, the app version, and the platform (for example iOS or Android) – to find and fix bugs. Crash and error reports are stored on our own servers; we do not use Sentry, Crashlytics, or any third-party crash-reporting service.

3.7 Device and technical information

  • Push tokens and message notifications. To deliver notifications, we store the push token issued to your device by Apple (APNs) or Google (Firebase Cloud Messaging), along with the device platform. When someone messages you, the notification we send carries the sender’s name, whether an attachment is a photo, a video or a file, and the message itself still encrypted. Your own device decrypts it when it arrives, which is how the notification can show you what was said. It is decrypted nowhere else: not on our servers, and not by Apple or Google, who pass on ciphertext they have no key for. If your vault is locked when the notification arrives, your device cannot decrypt it either, and the notification only tells you a message came in.
  • Authentication identifiers. Standard identifiers needed to keep you signed in securely, and the account identifier your provider gives us if you use Google or Apple sign-in.

3.8 Website information

The Site (fithrive.app) is a largely static informational website, hosted and delivered for us by Vercel. It sets no cookies of its own and runs no advertising or third-party analytics trackers. Vercel processes your IP address, browser type, and request metadata in short-lived server logs in order to serve the pages and protect the Site from abuse. The Site’s typeface is served from our own domain, so loading a page discloses nothing about you to any font or content-delivery provider.

If you use the contact form, we collect the name, email address, and message you enter and deliver them to our own inbox through Resend so that we can reply; the IP address the request came from is held briefly to rate-limit abuse. If we add any non-essential cookies in the future, we will ask for your consent first and update this policy.

4. Why we use your information, and our legal bases

We use personal data for the purposes below. Where the GDPR applies, the legal basis for each is noted.

PurposeLegal basis (GDPR)
Create your account, authenticate you, and run the App’s core featuresPerformance of a contract; and, where your Organization directs the processing, its legitimate interests
Provide readiness tracking, messaging, notes, and other features you usePerformance of a contract
Send you service notifications (for example a new message or a scheduled event)Performance of a contract; legitimate interests
Secure the service, prevent abuse, and keep audit and delivery logsLegitimate interests (keeping the service safe and reliable)
Diagnose and fix errors and crashesLegitimate interests (maintaining a working product)
Understand usage to improve the App (analytics)Your consent (you choose at onboarding and can withdraw any time)
Comply with legal obligations and respond to lawful requestsLegal obligation
Aggregate and anonymize opt-in usage analytics and diagnostic data to improve the App and produce anonymized industry benchmarksOur legitimate interests (product improvement and benchmarking). You may object to this processing at any time – see Section 10

For self-reported wellness data and other data that may be considered a special category under Article 9 GDPR (data concerning health), your Organization is the controller and is responsible for establishing a valid legal basis, which will normally be your explicit consent and/or processing under your Organization’s athletic-performance program with appropriate safeguards. Because this data is end-to-end encrypted, we hold it only in a form we cannot read. We never use wellness, readiness, injury, or illness data for product development, analytics, benchmarking, or any other purpose of our own – this is not only a policy commitment but a technical impossibility, since we do not hold the keys required to read it.

5. Who we share information with

We do not sell your personal data, and we do not share it for cross-context behavioral advertising.

We share data only in these situations:

  • Within your Organization. People your Organization authorizes – for example your coaches or staff – can see the data relevant to their role, according to the permissions your Organization configures.
  • Service providers (subprocessors) who help us run the App. We use a small, fixed set of providers, each of which processes data only to perform services for us under contract:
ProviderWhat they do for usData involved
SupabaseCore backend – authentication, database, file storage, serverless functionsAccount/profile data, encrypted content, analytics, diagnostics
Google / FirebasePush-notification delivery (Firebase Cloud Messaging); Google Sign-In (if you use it)Push tokens; when a message notification is delivered, the sender’s name, the attachment type, and the message in encrypted form; Google account identity if you use Google sign-in
ApplePush-notification delivery (APNs); Sign in with Apple (if you use it)Push tokens; when a message notification is delivered, the sender’s name, the attachment type, and the message in encrypted form; Apple account identity if you use Apple sign-in
ResendSending transactional emails (for example invitations and account emails)Email address and the message content of those emails
CloudflareHosting and delivery of the FiThrive web app – content delivery network, TLS, and protection against attacks – and storage of our off-site backups (Cloudflare R2, European Union)IP address, browser type, and request metadata, in short-lived delivery logs; an encrypted copy of our database and copies of stored files
VercelHosting and delivery of the fithrive.app website, including its contact formIP address, browser type, and request metadata in short-lived logs; the name, email address, and message you submit through the contact form
GitHubRuns the automated job that creates our off-site backupsThe backup is produced and encrypted inside the job and then transferred to storage; GitHub does not keep a copy
  • Legal and safety reasons. We may disclose data if required by law, to respond to lawful requests, or to protect the rights, safety, and security of our users, the public, or FiThrive.
  • Business transfers. If FiThrive is involved in a merger, acquisition, or sale of assets, data may be transferred as part of that transaction; we will require the recipient to honor this policy or notify you of any material change.

Note that for your end-to-end-encrypted content (messages, notes, files, form answers), any provider that stores it – including Supabase and Cloudflare – holds only ciphertext they cannot read. Cloudflare serves two separate purposes for us: it delivers the App’s program code to your browser, and it stores our off-site backups. The database copy in those backups is encrypted with a key Cloudflare does not hold, and end-to-end-encrypted content stays encrypted inside them.

6. Zero-knowledge, end-to-end encryption

FiThrive is built so that your most sensitive data is readable only by you and the people you share it with – not by us.

How it works, in plain terms. When you set up your account, the App creates a personal set of encryption keys. Your private key is protected by a key derived from your password and is stored only in an encrypted form we cannot unlock. When you send a message, write a note, or submit a readiness form, the content is encrypted on your device before it leaves it. Our servers store only the encrypted result. To share something (for example a group message), the App securely delivers the necessary keys to the other authorized members’ devices, so only they can decrypt it.

What this means:

  • We cannot read your direct, group, or channel messages; your notes; your uploaded files; or your readiness form answers and scores. Neither can anyone who gains access to our database. Profile pictures, team and group images, and chat wallpapers are the exception described in Section 3.3 – they are stored unencrypted so they can be displayed to other members.
  • What is not encrypted content (and so is technical/operational metadata we can see): account and profile fields, the fact that a message was sent and between whom and when, analytics metadata, crash logs, and push tokens. Channel names, descriptions, and system messages (such as “channel created”) are also not message content.
  • A trade-off you should understand: because only your keys can decrypt your content, if you lose your password and any recovery method your Organization provides, that encrypted content may become permanently unrecoverable. This is a deliberate consequence of protecting your data this strongly.

This design also shapes your data-export rights (Section 10): we can export the data we can read, but we cannot export the plaintext of content only your keys can decrypt.

Using FiThrive in a web browser

FiThrive is also available as a web app. It performs the same end-to-end encryption as the mobile apps – your content is encrypted in your browser before it is sent, and our servers still store only the encrypted result. Two differences are worth understanding, and we would rather state them plainly than imply the two are identical.

  • No hardware-backed key storage. On a phone, your keys can be held in hardware designed to protect them, and you can unlock with biometrics. A browser has no equivalent. In the web app your keys exist only in the memory of the open tab, are never written to your device’s storage, and are discarded when you close it or sign out. There is no biometric unlock on the web, and you will be asked for your vault password each session.
  • Code is delivered fresh each visit. A mobile app is installed once and reviewed by the app store. A web app is delivered to your browser every time you load it, which means the mobile apps offer a stronger guarantee. For the most sensitive use, we recommend the mobile apps.

What the web app stores in your browser. To keep you signed in between page loads, the App stores a single session token in your browser’s local storage. It is strictly necessary to operate the service, is not used for advertising or tracking, and is cleared when you sign out. The web app sets no advertising or analytics cookies. Your encryption keys are never stored there.

7. Security

We protect your data with, among other measures:

  • Encryption in transit (TLS) for all traffic between the App and our servers.
  • End-to-end encryption of your sensitive content, as described in Section 6.
  • Row-level security on our database, so each user and Organization can access only the data they are permitted to.
  • Multi-factor authentication (MFA). Time-based one-time-password (TOTP) MFA is available on every account and strongly encouraged for coach, staff, and admin accounts, which have broader access. Where an account has MFA enabled, its elevated permissions and sensitive administrative actions are granted only to a session that has completed the second factor.
  • Access controls and internal-access limits for our own personnel.

No system is perfectly secure, but we work to protect your data and to meet our obligations under applicable law (including Article 32 GDPR).

8. Where your data is stored, and international transfers

Your data is hosted on our providers’ infrastructure. Our primary backend (Supabase) stores your data in the European Union – Frankfurt, Germany (eu-central-1) region. This means your account data and your encrypted content are held at rest within the EU.

However, some processing happens outside the EEA. First, FiThrive, Inc. is established in the United States, and the service is administered from the United States and from Serbia, so your data may be accessed from either country to run and support the service. Second, some providers we rely on for specific functions – push-notification delivery (Google/Firebase, Apple) and transactional email (Resend) – may process limited data such as push tokens or email addresses outside the EEA, including in the United States. Third, the web app’s program code is delivered from Cloudflare’s global network, so the technical details of that request – including your IP address – may be processed outside the EEA, including in the United States. Your account data and your encrypted content remain stored in Frankfurt regardless of where you load the web app from.

Where personal data of individuals in the EEA or Switzerland is transferred outside those areas, we rely on appropriate safeguards – principally the European Commission’s Standard Contractual Clauses – to protect it. You can ask us for more information about these safeguards using the contact details in Section 15.

9. How long we keep your data

We keep personal data for as long as your account is active and as needed to provide the service, and then only as long as we have a legitimate or legal reason to retain it. In particular:

  • While your account is active, we keep your account, profile, content, and related data so the App works.
  • When you delete your account (Section 10), we anonymize your profile and remove or render permanently unreadable your personal identifiers and your private encryption keys, so your encrypted content can no longer be decrypted. Some records are retained in anonymized or minimized form where necessary – for example to preserve the integrity of an Organization’s shared data (such as a team record a former member contributed to), to keep security and audit logs, or to meet legal obligations.
  • Invitations that are not accepted have their personal details removed after they expire.
  • Backups. There are two kinds. Our hosting provider keeps its own encrypted backups for a limited window and overwrites them on a rolling basis. We also keep an off-site backup of our own – a copy of the database, encrypted with a key the storage provider does not hold, together with copies of the files stored in the App – in Cloudflare R2 storage located in the European Union. Daily copies are deleted after 30 days and weekly copies after 84 days; one copy each month is held in unalterable form for 12 months, so that it cannot be tampered with or destroyed. Copies of uploaded media are not deleted on a schedule, so that Organizations do not lose material they are entitled to keep. Those copies are stored encrypted, and deleting an account destroys the keys that open them – so media belonging to a deleted account remains only as ciphertext that nobody, ourselves included, can turn back into a file. Data you delete therefore remains in backups until those copies expire, and if we ever restore from a backup we re-apply any deletion requests to the restored data.

We do not currently operate a fixed automatic deletion schedule for active-account data; we retain it under the principles above and delete it when it is no longer needed.

10. Your privacy rights

Subject to your local law, you have some or all of the following rights over your personal data:

  • Access – get a copy of the data we hold about you.
  • Rectification – correct data that is inaccurate or incomplete.
  • Erasure – ask us to delete your data (“right to be forgotten”).
  • Restriction and objection – limit or object to certain processing, including processing based on legitimate interests.
  • Portability – receive certain data in a portable, machine-readable format.
  • Withdraw consent – where we rely on consent (for example analytics), withdraw it at any time, without affecting processing that already happened.

How to exercise them. You can access and correct much of your profile directly in the App, toggle analytics in Account Settings → Privacy, export your data using the in-App data-export feature, and delete your account from settings. You can also contact us at info@fithrive.app and we will respond within the timeframes required by law.

One limitation to be transparent about: because of the end-to-end encryption described in Section 6, a data export or access request can include the data we are able to read, but cannot include the plaintext of content that only your keys can decrypt (your messages, notes, files, and form answers). Those remain available to you inside the App, where your device can decrypt them.

If you believe we have not handled your data properly, you have the right to complain to your local data protection authority (in the EEA, your national supervisory authority; and in Switzerland, the Federal Data Protection and Information Commissioner). We would appreciate the chance to address your concern first.

11. California privacy rights (CCPA/CPRA)

If you are a California resident, you have the rights to know/access, delete, correct, and to opt out of the sale or sharing of your personal information, as well as the right not to be discriminated against for exercising these rights.

Notice at collection. The categories of personal information we collect, the purposes, and the parties we disclose to are described in Sections 3-5. We collect identifiers, contact and profile data, self-reported physical and wellness information, user-generated content (encrypted), internet/usage activity (analytics), and inferences drawn from readiness inputs (computed on your device and encrypted).

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the preceding 12 months. Because we do not sell or share, no “Do Not Sell or Share My Personal Information” action is required – but you may still contact us to confirm this or to exercise any right.

Sensitive personal information. The self-reported health-related data described in Sections 3.1-3.2 may be “sensitive personal information.” We use it only to provide the readiness features you and your Organization use – not to infer characteristics about you for any other purpose – so the CPRA “right to limit the use of sensitive personal information” is already reflected in how the product works. You may still contact us with any request.

To exercise California rights, contact info@fithrive.app. We will verify your request as required and will not discriminate against you for making one. Authorized agents may submit requests on your behalf with proof of authorization.

12. Consumer health data (Washington My Health My Data Act)

Some of the data FiThrive processes – your self-reported sleep, mood, soreness, fatigue, other readiness form answers, and your height and weight – may be “consumer health data” under Washington’s My Health My Data Act and similar laws.

  • We collect it only with your involvement and to provide the readiness features you and your Organization use. We do not use it for advertising, and we do not sell it.
  • It is end-to-end encrypted (Section 6), so we store it in a form we cannot read.
  • We do not share consumer health data except as needed to store it in encrypted form with our infrastructure provider (which cannot read it) and with the people in your Organization you or it authorizes. We will not sell consumer health data, which would require your separate valid authorization under the MHMDA – and we do not do so.
  • Your rights. You may request to access, or to delete, your consumer health data, and to withdraw consent to its collection, by contacting info@fithrive.app or using the in-App controls.

13. Children and minors

FiThrive is intended for people aged 18 and over, and we do not create accounts for anyone under 16 under any circumstances, including with parental consent. Account setup requires a date of birth, and the App does not accept one that indicates an age under 16.

An athlete aged 16 or 17 may use FiThrive only where a parent or guardian has consented. That consent is given to, and held by, the Organization that invites them, which is the controller for it, under the process set out in its agreement with us. We do not receive, verify, or store parental consent forms, and we ask Organizations not to send them to us – collecting them would mean holding personal data about parents and guardians that we have no need for.

What we do instead is require the Organization to confirm it, on the record. Before an invitation is issued, the administrator sending it must confirm that the person being invited is 18 or over, or is aged 16 or 17 with parental or guardian consent already obtained. We record who gave that confirmation, for whom, and when, and we keep those records for as long as we may need them to show that consent was obtained.

Because Organizations invite their own members and know who they are, they are best placed both to know an athlete’s age and to hold the consent, and they are responsible for both under their agreement with us. We do not knowingly collect or process personal data from anyone under 16. If we learn that an account belongs to someone under 16, or to a 16- or 17-year-old for whom the required consent was not obtained, we will delete it.

If you are a parent or guardian and believe a minor is using FiThrive without your consent, contact us at info@fithrive.app, or the Organization that invited them, and we will act on it. You may also ask us to delete the account and the data associated with it, as described in Section 10.

14. Changes to this policy

We may update this policy as the App and the law evolve. When we make a material change, we will update the “Last updated” date and, where appropriate, notify you in the App or by email and (where required) ask for renewed consent. The App records which version of this policy you have acknowledged.

15. How to contact us

FiThrive, Inc.

24A Trolley Square #1265, Wilmington, DE 19806-3334, United States

Registered in Delaware, United States – registration number 10727304

Privacy contact: info@fithrive.app

EU and Swiss representative: Data Protection Representative Limited (trading as DataRep) is the representative of FiThrive, Inc. under Article 27 GDPR and under the Swiss Federal Act on Data Protection.

DataRep, 77 Camden Street Lower, Dublin, D02 XE80, Ireland – digitalrequest@datarep.com – +353 (1) 919 8899

Please address correspondence to “DataRep” and mention FiThrive, Inc. They can be contacted in English or in any official language of the EU. For questions about the App, your account, or support, contact info@fithrive.app instead – DataRep cannot help with those.

Digital Services Act

Data Protection Representative Limited (trading as DataRep), at the address above, is also the legal representative of FiThrive, Inc. in the European Union under Article 13 of Regulation (EU) 2022/2065 (the Digital Services Act). Our single point of contact under Article 11 (for the authorities of the Member States, the European Commission, and the European Board for Digital Services) and under Article 12 (for recipients of the service) is info@fithrive.app. Both can be addressed in English.

If you are in the EEA or Switzerland, you also have the right to lodge a complaint with your local supervisory authority.

© 2026 FiThrive. All rights reserved.

Home Privacy Policy Terms of Use info@fithrive.app