What the Fitness
Privacy Terms

Privacy Policy

Last updated: 3 September 2026 · Version 2026-09-03

1. Who we are

What the Fitness (“we”, “us”) provides a mobile fitness tracking application.

Data controller: Codebro Nordic AB
Contact: hello@codebro.se

2. What this policy covers

This policy describes how we handle information when you use the What the Fitness mobile app on iOS and Android.

3. Data we collect

Without an account (guest mode)

If you do not create an account, workout and nutrition data is stored locally on your device. We do not receive that data on our servers.

With an account (optional)

If you create an account, we collect:

  • Email address — for sign-in and account recovery
  • Account identifier — a unique user ID from our authentication provider (Amazon Cognito)
  • Profile and fitness data you choose to sync — workouts, exercises, sets, body metrics, nutrition logs, and related preferences
  • Technical data — app version, API requests, and crash/diagnostic information
  • Feature requests (optional) — title and body you submit, your upvote flags, and your account identifier. Other signed-in users see the text, status, score, and an anonymous handle (User · plus a short id). They do not see your email.

Product analytics (optional)

If you turn on Product analytics in the app (off by default), we send usage events to PostHog, which processes them on our behalf on PostHog Cloud EU (Amazon Web Services, Frankfurt, Germany).

That may include:

  • An anonymous device/app identifier
  • App version, device type, and OS version
  • Screens you open and a small set of product actions (for example: completing sign-up, saving a workout, opening the paywall)

We do not send workout contents, nutrition logs, notes, barcodes, health values, or your email address in those events. We do not use Apple’s Identifier for Advertisers (IDFA) for this analytics.

You can turn Product analytics off at any time in Settings. The app works fully with it off. Session recordings of your screen are not enabled.

Advertising

The app may show banner advertisements (Google Mobile Ads). Ad partners may collect device identifiers according to their own policies. Personalized advertising that uses the advertising identifier is off unless you opt in; on iOS that also requires Apple’s App Tracking Transparency prompt. You can hide ads in Settings during development; paid ad removal may be offered later.

Payments

If you buy Premium or other in-app products, Apple or Google process the payment. We use RevenueCat to check subscription status. We do not receive your full payment card details.

4. How we use data

  • Provide and improve the app
  • Authenticate your account and sync your data across devices (when enabled)
  • Respond to support requests
  • Understand how the app is used when you opt in to product analytics
  • Show ads (unless you remove them) and process purchases
  • Operate the in-app feature request board (display, vote, and moderate posts)

We do not sell your personal data.

5. Legal basis (EEA / UK users)

  • Contract — processing needed to provide your account and sync service
  • Consent — Terms and Privacy Policy acceptance; product analytics; optional marketing / personalized ads
  • Legitimate interests — security, fraud prevention, and keeping the service reliable

You can withdraw analytics consent in Settings without affecting your account.

6. Where data is stored and who processes it

ProcessorPurposeLocation
Amazon Web Services (Cognito, API, DynamoDB)Account, synced fitness data, and feature-request posts/votesEU (Stockholm, eu-north-1)
PostHog, Inc. (PostHog Cloud EU)Optional product analyticsEU (Frankfurt, eu-central-1)
RevenueCatSubscription statusPer RevenueCat’s DPA / subprocessor list
Google (Mobile Ads; Sign-In if you use it)Ads; optional sign-inPer Google’s policies
Apple (Sign in with Apple; App Store payments)Optional sign-in; paymentsPer Apple’s policies

Local-only data remains on your device. PostHog acts as our processor. We will put a Data Processing Agreement in place before public launch.

7. Retention

  • Account data is kept until you delete your account
  • Product analytics events are kept according to our PostHog project retention (target: no more than 12 months)
  • Backups may persist for a limited period after deletion

8. Your rights

Depending on your location, you may have the right to access, correct, delete, or export your data, to withdraw consent, and to object to certain processing. Contact hello@codebro.se.

You may lodge a complaint with your local data protection authority.

9. Account deletion

You can delete your account in the app (Settings). This removes your cloud account and associated server data subject to backup retention. Feature-request votes are removed; posts you authored stay on the board with authorship anonymized (User · gone) so other users’ votes are not wiped. Hidden posts stay withheld from other users. You can also ask us to delete PostHog analytics records tied to your account identifier.

10. Children

What the Fitness is not directed at children under 16. We do not knowingly collect data from children.

11. Changes

We may update this policy. Material changes will be communicated in the app. Continued use after an update may require re-acceptance.

12. Contact

hello@codebro.se

Home · Terms of Service