Legal · Privacy
Privacy Policy
Last updated: August 17, 2026
FitSend copies supported Google Health data into the Apple Health app on your iPhone, then shows on-device summaries and trends. Handling health data is the whole job, so we designed FitSend around a simple idea: the less we hold, the less can ever go wrong. This policy explains exactly what passes through our hands, what little we keep, and what we will never do. We wrote it in plain English on purpose. If anything is unclear, ask us at privacy@fitsend.app.
The short version
- Your health measurements pass through our servers in memory. They are never written to our databases, logs, or backups.
- We don’t know who you are. No name, no email, no Google profile. Your account is a random identifier.
- No ads, no trackers, no analytics SDKs, no selling data. Not now, not later, not “anonymized.”
- Your data lands in the Health app on your iPhone, under your control, and never in any FitSend-run cloud copy.
- You can disconnect, export, or delete everything from inside the app. Deletion is real: primary systems within 24 hours, backups within 30 days.
- Free and PRO get identical privacy. Paying changes features, never how your data is treated.
1. What FitSend is
FitSend is an iOS app with a small supporting service. When you connect Google Health, FitSend reads the supported records you authorize and writes them into the Health app on your iPhone. The sync is one-way: from Google Health to the Health app, never the reverse. FitSend also shows summaries, trends, and a daily score computed on your device from the records you allow in the Health app.
Our server exists to coordinate: it handles Google sign-in, receives change notices, and relays the records your phone asks for. It is deliberately built so it does not become a health-data warehouse.
2. The health data that passes through
When a sync runs, our server fetches the records you authorized from the Google Health API and hands them to your iPhone over an encrypted connection. Those measurements are processed in memory only:
- They are never saved to our databases.
- They are never written to logs, crash reports, or diagnostics: our logging is built to refuse health values, not just avoid them.
- They are never included in backups, because they were never stored.
The only durable copy of your synced health data is the one written to the Health app on your iPhone.
3. What we do keep
Running a reliable sync requires some bookkeeping. Here is the complete list of what our servers hold for your account, and why:
| What | Why we need it |
|---|---|
| A random account identifier | Identifies your account without knowing who you are. It is not your email, name, or any Google identifier. |
| Your encrypted Google connection | The credential that lets FitSend read your authorized data, encrypted with per-record envelope encryption, plus a one-way cryptographic digest of your Google Health user ID so we can recognize the same connection later. We never store the raw ID. |
| Device and session credentials | Random tokens that keep your app signed in securely. Stored on your iPhone in the Keychain. |
| A push notification token | Lets Apple wake the app for background sync. The notification itself never contains health information, only an opaque “something changed” hint. |
| Your category choices | Which data types you allowed (for example steps but not sleep), so we request only what you selected. |
| Sync bookkeeping | Which time ranges changed and whether each sync step succeeded: cursors, intervals, and status codes. Never the measurements themselves. |
| Subscription state | Apple transaction identifiers and whether PRO is active. Apple handles payment; we never see your payment details. |
| Redacted operational logs | Short-lived technical records (timings, error codes, counts) for keeping the service healthy. They are built to exclude health values, tokens, and identities. |
That is the whole inventory. If we ever wanted to store more, we would have to change this policy first, and we would have to tell you.
4. What stays on your iPhone
- Your records in the Health app. Once written, they remain under your control. FitSend can later correct or delete only the records it created, and only to mirror the source.
- A local sync ledger. Identifiers, versions, and statuses that make repeat syncs exact. Stored with iOS file protection, excluded from device backups, and holding no measurement values by design.
- On-device insights. Trends, scores, and dashboards are computed in memory from records in the Health app on your phone. They are never uploaded.
- No FitSend cloud copy. FitSend puts nothing in iCloud and runs no cross-device sync of your health data.
5. What we never do
- We never sell your data — health or otherwise.
- We never show ads, embed advertising or analytics SDKs, or share data with data brokers.
- We never use health data for advertising, credit, employment, insurance, pricing, or any kind of profiling.
- We never ask for your name, email address, contacts, or Google profile.
- We never vary features, prices, or priority based on your health data. Free and PRO receive identical data treatment.
- We never pressure you to grant more access. If you authorize only some categories, FitSend works with those and asks again only when you choose to add more.
6. Google data and Limited Use
FitSend’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. In practice that means Google Health data is used only to provide the sync and insights you asked for — never for ads, never sold, and never read by humans except with your explicit consent, for security, or where the law requires it.
FitSend requests only read-only Google Health scopes, and only for the categories you select. Before you ever see Google’s consent screen, the app tells you exactly what it will request and where the data goes.
7. The Health app
FitSend reads and writes records in the Apple Health app only with the permissions you grant in iOS, requested only after FitSend explains why. That health data is never used for advertising or marketing and is never disclosed to third parties for anything other than providing the feature you asked for. FitSend deletes only records it authored, and your Health app privacy settings always win.
8. How long things last
| Data | Kept for |
|---|---|
| Health measurements in transit | Seconds to minutes, in memory only |
| Account, connection, and settings | Until you disconnect or delete |
| Redacted operational logs | Up to 30 days |
| Security audit records | Up to 365 days |
| Subscription identifiers after expiry | Up to 90 days past the active entitlement, for refund and fraud handling |
| After account deletion: primary systems | Erased within 24 hours |
| After account deletion: encrypted backups | Age out within 30 days |
| Anti-recreation marker after deletion | Up to 30 days: a minimal, keyed marker that stops background events from silently recreating a deleted account. It cannot identify you. |
9. Your controls
- Choose categories. Grant, deny, or later add individual data types. Partial permission is a respected choice, not an error.
- Disconnect Google. Revokes FitSend’s access and erases the stored connection, while keeping your records in the Health app untouched.
- Export your data. Get a copy of everything FitSend’s servers hold about your account, from inside the app, as readable JSON.
- Delete your account. A full, in-app erasure, and you choose whether records FitSend wrote to the Health app stay on your phone or are removed with it. Step-by-step details.
- Manage your subscription. PRO is billed by Apple and managed in your App Store settings. Deleting your FitSend account does not cancel an Apple subscription; the app warns you and links you to the right place first.
10. Security
Every connection uses TLS. Google credentials are protected with per-record envelope encryption, with keys managed in a dedicated key management service in production. On your iPhone, FitSend uses the Keychain and iOS file protection, and keeps its local files out of device backups. Access to production systems is restricted, logged, and protected by phishing-resistant multi-factor authentication. Our staff cannot browse your health data, because it isn’t there.
Found a vulnerability? Please tell us: fitsend.app/security.
11. Where FitSend operates
FitSend is operated from the United States, and our servers are located in the United States. FitSend launches on the U.S. App Store; if we expand to other regions, we will meet the privacy requirements that apply there and update this policy.
12. Children
FitSend is not directed at children under 13, and we do not knowingly handle their data. Because we never collect names or emails, we rely on Apple’s age gates and Google’s account rules; if you believe a child is using FitSend, contact us and we will delete the account.
13. Changes to this policy
If we change this policy, the new version appears here with a new date. For material changes — anything that expands what we collect or how we use it — we will tell you in the app before the change applies to you.
14. Contact
One caution: because FitSend never has your email address, writing to us from your personal email does not identify your FitSend account. That’s by design. Please don’t include health readings or screenshots of health data in email; we don’t need them to help you.