PISTAFIT privacy policy
Effective date: 13 September 2026
Published at https://pistafit.pistasspot.com/privacy, the URL given to Google Play and to Google sign-in.
who we are
PISTAFIT is an Android app made and run by PISTA, an independent developer. PISTA is the data controller for everything described here.
Questions and requests, or a deletion you would rather not do in the app: freeaccforu98@gmail.com
the short version
PISTAFIT is an offline-first app. Everything you log is written to your device first and the app works fully with the network off. Nothing is sent anywhere unless you create an account or sign in, and even then your progress photos stay on the device. There is no advertising, no analytics SDK, no tracking across other apps or websites, and nothing is sold or handed to data brokers.
what we collect
if you never sign in
Nothing leaves your device. The app stores your logs locally and generates a random device identifier (a UUID) so that a future sign-in can tell one device from another. That identifier is not tied to you, your hardware, your advertising ID, or anything Google holds, and it is not transmitted while you are signed out. Deleting the app deletes it.
if you create an account or sign in
Account information
- Email address. It is the account identifier you sign in with, and it is where the transactional email described below goes.
- Display name, if you provide one, or the name attached to the Google account you sign in with.
- A password hash, if you sign up with email and password. The password itself is never stored.
Your logs, synced from the device
Once you are signed in, the app syncs the log it has been keeping locally. It is stored as an append-only event log — each entry is a record of something that happened, with a timestamp and the device identifier — plus the current state of each item. It covers:
- body weight entries and, if you record them, waist measurements
- water intake
- the daily step counts you type in yourself. Steps counted by the device's own step sensor are kept there and are not sent
- food entries: item names, portions, calories, protein, carbohydrate and fat
- the foods you add to your own food list, with their per-100 g macros
- sleep hours and the daily tick-boxes, including the creatine dose
- workouts: exercises, sets, weights, reps, rest timers, session start and end times, personal records
- workout templates and any custom exercises you add
- streaks, and the freeze tokens you spend on them
- weekly check-ins: the week's average weight and its delta, waist, your best working sets on bench, squat and deadlift, and a true/false flag recording whether you attached a progress photo. The photo itself is never sent.
- the profile answers you gave during onboarding: goal, starting weight, target weight, training days per week and which days, activity level, job type, daily targets (calories, protein, carbohydrate, fat, water, steps), unit preferences, height, birth year and gender
Device identifier
The random UUID generated on first launch is sent with synced events so that edits made on two devices can be reconciled.
the permissions the app asks for
Android permissions are listed here because a permission is a question about your data, and you should be able to see what each one is for. Nothing in this list sends anything anywhere.
| Permission | What it is for | Where it goes |
|---|---|---|
| Physical activity (activity recognition) | Reading the built-in step counter so the steps card fills itself in. Asked for the first time you open the steps screen, never at startup, and the app works without it — you can type steps in by hand | The sensor reading is written to the device only |
| Notifications | The rest-timer countdown, the buzz at the end of a set, and the weigh-in, water, creatine, workout and missed-workout reminders you switch on | On the device |
| Alarms and reminders (exact alarm) | Firing the buzz at the end of a rest set on time. Without it the buzz is scheduled inexactly and may be late | On the device |
| Run at startup, wake lock, vibrate | Rescheduling those reminders after a reboot, and the vibration itself | On the device |
The app declares no camera, photo-library, location, contacts or microphone permission. A progress photo comes back from the Android photo picker or the camera app as a single file you chose, which needs no permission grant.
what we never collect
- Progress photos. Photos you attach to a weekly check-in are saved in the app's private storage on your device and are never uploaded, in this version of the app. If you are signed in, a synced check-in carries only a true/false flag saying that a photo exists — never the image, and never its file name. Uninstalling removes the photos.
- Precise location, contacts, call logs, SMS, browsing history, the contents of other apps, or your advertising ID.
- Payment details. There are no in-app purchases in this release; when a subscription is added, Google Play will process payment and PISTAFIT will only see the purchase token Google issues.
why we use it
| Purpose | What it uses |
|---|---|
| Running the app's features — showing your history, averages, streaks, charts and share cards | your logs, on your device |
| Backing your log up on the server | your logs, account email, device identifier |
| Restoring your profile and targets when you sign in on a new device | your profile answers |
| Signing you in and keeping the session alive | email, password hash or Google sign-in, device identifier |
| Account email: verifying your address and resetting a password, plus the weekly recap | email address, display name |
| Keeping the service working and secure — rate limiting, abuse prevention, debugging a failed sync | account identifier, device identifier, request metadata |
About the backup. Your log is uploaded and kept, but this release has no way to pull it back down: signing in on a new device restores the profile and targets you set during onboarding, not your history. Export your log from the MORE tab → export if you want a copy you can carry. If that changes, this policy changes with it.
About the weekly recap. While you are signed in, the server emails you a summary of your week on a Sunday. It is sent automatically and there is no switch to turn it off in this release, so if you do not want it, delete the account.
We do not use your data for advertising or for third-party profiling, and it feeds no automated decision with legal effects. Nothing is used to train a model. If that ever changes, it is a new purpose, and the section on changes below says how you will hear about it first.
who else handles it
These are the only third parties involved, and each acts as a processor on PISTAFIT's instructions:
| Provider | What it does | What it sees |
|---|---|---|
| MongoDB Atlas | Hosts the database for signed-in accounts | Account records and synced logs |
| Vercel | Hosts the API the app talks to | API requests in transit, plus server logs containing IP address and request metadata |
| Resend | Sends transactional email (verification, password reset, weekly recap) | Email address and the content of those messages |
| Google (Sign-In) | Verifies your identity if you choose "continue with Google" | The sign-in itself; PISTAFIT receives your email, name and a Google account identifier |
Your data is stored on servers operated by these providers, which may be located outside your country, including in the United States and the European Union. Nothing is sold or rented for anyone else's marketing, and nothing is shared for that purpose.
We will disclose data if we are legally required to, and will tell you unless the law forbids it.
security
Every connection between the app and the API uses HTTPS with TLS. Access tokens are short-lived (15 minutes); refresh tokens are rotated on each use, stored hashed on the server, bound to a device, and kept on the device in the platform's encrypted secure storage. Passwords are hashed. Every database query is scoped to the account that owns the record. No system is perfect, but data is encrypted in transit and at rest by the hosting providers.
how long we keep it
Your logs are kept while your account exists, because the whole point is the history. Server logs and rate-limiting records are kept for up to 30 days. Nothing is kept in an anonymised or derived copy after you delete the account: deletion removes the lot.
deleting your data
In the app: the MORE tab → account → delete account. This deletes your account and every server-side record attached to it immediately, and it cannot be undone. In line with Google Play's requirement, any residual copy in backups is purged within 24 hours.
By email: write to freeaccforu98@gmail.com from the address on the account and ask for deletion. We will action it within 30 days, and normally the same day.
Locally: uninstalling the app removes everything stored on the device, including progress photos. If you are signed in, uninstalling alone does not delete the server copy — use the in-app deletion for that.
You can also export everything the app holds about you at any time, as CSV or JSON, from the MORE tab → export. You may write to the address above to have anything inaccurate corrected or your consent withdrawn, and to restrict or object to processing.
children
PISTAFIT is not directed at children. It is not intended for anyone under 13, and we do not knowingly collect information from anyone under 13. If you believe a child has created an account, write to freeaccforu98@gmail.com and we will delete it.
changes to this policy
If this policy changes, the new version is published at this URL with a new effective date. Material changes are also announced inside the app before they take effect. That includes a new category of data, a new purpose, a new third party, or a new place your data is stored. The date at the top always tells you which version you are reading.
contact
PISTA — freeaccforu98@gmail.com
The terms of use sit alongside this policy and cover the app itself.