NotSoSure Fitness · Privacy Policy

Privacy Policy

Last updated 2026-09-18

NotSoSure Fitness (“the app”, “we”, “us”) is a personal health and fitness tracker operated by Shivam Talwar. This policy explains what data the app collects, how it is used, and the choices you have. Your data is used to power features for you; we do not sell it.

Information we collect

  • Account & profile: name, email, date of birth, sex, height, weight and goals you provide (authentication via Firebase Authentication, including optional Google or Apple sign-in).
  • Health & fitness logs: nutrition, water, supplements, exercises, body measurements, sleep, steps, and notes you enter.
  • Connected-device data: with your permission — recovery, HRV, resting heart rate, sleep, strain and steps from services you link (WHOOP, Apple Health, Google Health Connect, or a paired BLE heart-rate sensor).
  • Google Health data (Android): if you connect Google Health, we read — with your explicit Google consent, one scope at a time — your activity & fitness data (steps and distance) to power the home step ring and training-load tracking; your sleep data (sleep sessions and stages) to power the sleep score and sleep coaching; your nutrition data (meals you log in Google Health) to confirm the scope is genuinely used, with an in-app food-log import planned to avoid double-entry; and your health metrics & measurements (resting heart rate, HRV, SpO2, respiratory rate, weight, body fat) to compute your readiness/recovery score. Each scope is used only for the feature named above — we request the narrowest scope that feature needs, never a broader one. This connection is read-only: we never write data back to Google Health. You can disconnect at any time from Settings → Health & Devices, which stops all future reads immediately.
  • Progress photos: photos you choose to add, stored on your device and (if enabled) in your private cloud storage.
  • Camera / pose data: live form tracking analyses your movement on-device to count reps and check form.
  • Location (optional): automatic gym-visit detection uses geofencing to detect arrival at a location you set. Off by default.
  • AI interactions: messages and context you send to the in-app assistant and insight features.
  • Device & usage: basic technical and crash/usage data needed to run and improve the app.

Lab reports and blood markers

You may optionally add values from a laboratory report by typing them in, uploading a PDF, or photographing the report. The app extracts the marker values (name, value, unit and date) and stores them with your other health data. The original image or PDF is processed only to extract these values and is not kept longer than needed for that extraction, unless you choose to keep it. These values are used only to show trends and general wellness context inside the app — they are never sold or used for advertising, and are covered by the same encryption, retention and deletion rules as your other health data. You can delete lab values at any time from the app. This feature is informational only and is not a medical service.

How we use your information

  • To provide core features: tracking, charts, readiness/recovery scoring, predictions, reminders and reports.
  • To compute a personalized readiness/recovery score from your HRV, resting heart rate and sleep relative to your own baseline.
  • To generate AI insights and coaching (see below).
  • To sync and back up your data across your devices and reinstalls.

Connected services

When you link a device or platform, you authorize the app to read the data you approve. We use it only to provide features to you. You can revoke access in the app’s Health & Devices screen and in the provider’s own settings.

AI processing

Two features send data to a third-party AI model to generate a response shown back to you: (1) when you attach a photo in the in-app assistant chat, the photo and your typed message are sent to Google Gemini (vision, via the Generative Language API) to generate a reply; and (2) Scan-a-Meal food-photo recognition sends the food photo to Google Geminito identify what’s on your plate. Only the data needed for that one request is sent — never your full history, and never data read from Google Health.

Most of what the app calls “AI” — FitBrain’s daily narrative, food and meal recommendations, and cycle predictions — runs entirely on your device, with no network call at all, using Google’s on-device ML Kit models (for pose and barcode scanning) and our own rule-based engines. These self-hosted, offline models never send your data, including any data connected from Google Health, to us or to any third-party model provider.

Limited Use compliance

NotSoSure Fitness’s use and transfer of information received from Google APIs, including the Google Health API, adheres to the Google API Services User Data Policy, including the Limited Use requirements. Raw or derived data received through the Google Health API is never transferred to any third-party AI or advertising service, and Google Gemini — the only third-party AI provider we use — never receives or trains on Google Health data.

Storage & security

Your data, including anything read from Google Health, is stored encrypted on your device first (encrypted local database), then mirrored to a per-user, encrypted copy in our Firestore backend for backup and cross-device sync — accessible only to your account. Manual backups can be exported and are encrypted. The app supports a PIN and biometric lock. No method of transmission or storage is 100% secure, but we take reasonable measures to protect your data.

Sharing

We do not sell your personal data, and we do not use it for advertising — the app has no advertising SDK of any kind. We share it only with the service providers needed to run the app (e.g. Google Firebase for auth/sync/storage, and the AI providers above) acting on our behalf, and where required by law. Reports or files are shared only when you choose to export/share them.

Your choices & rights

  • Access & export: export your data anytime as PDF, CSV or JSON.
  • Disconnect devices: unlink any connected source at any time.
  • Delete: delete your account and associated data from the app; contact us if you need help.

Data retention

We keep your data, including anything read from connected sources such as Google Health, while your account is active. Locally stored data is encrypted on your device and is removed when you delete the app or its data. When you delete your account (Settings → Account & Data → Delete My Account), your synced data — including all data derived from Google Health connections — is deleted from our servers. The one exception: if you had ever turned on the optional “AI improvement” setting, an already-anonymised, aggregate cuisine-preference signal may already be folded into a shared statistical model and cannot be individually withdrawn after the fact — this never includes health, sleep or nutrition values themselves, only a coarse cuisine-liking direction.

Children

The app is not intended for children under 16, and we do not knowingly collect their data.

Health disclaimer

NotSoSure Fitness is a wellness and fitness tool, not a medical device. Recovery, readiness, prediction and analysis features are for general guidance only and are not medical advice, diagnosis or treatment. Always consult a qualified professional before making health decisions.

Changes to this policy

We may update this policy; the “last updated” date will change accordingly.

Contact

Questions or requests: sam65666@gmail.com