Information We Collect
We collect information you provide directly, information generated through your use of the app, and limited technical information needed to operate the service.
Account Information
| Data Type | Examples | How Collected |
|---|---|---|
| Identity | Name, email address | Provided during sign-up |
| Authentication | Hashed password, access token, refresh token | Generated at login; stored securely on device |
Onboarding & Profile Data
| Data Type | Examples | Purpose |
|---|---|---|
| Body metrics | Age, height, weight, goal weight, sex | Calculating calorie targets and plan intensity |
| Fitness profile | Goal, fitness level, days per week, session length, training location, pace preference | Generating your personalised workout plan |
| Physical limitations | Injury flags (knee, shoulder, lower back, etc.) | Excluding contraindicated exercises from your plan |
| Dietary information | Diet style, dietary restrictions | Personalising nutrition tracking and meal suggestions |
| Equipment | Available equipment (gym, home, outdoors) | Filtering exercises to what you can actually do |
Activity Data
| Data Type | Examples | Purpose |
|---|---|---|
| Workout logs | Exercises completed, sets, reps, weight, session duration, notes | Tracking progress and triggering progressive overload |
| Nutrition logs | Food name, meal type, calories, protein, carbs, fat, portion size, scan method used | Daily macro tracking and nutrition summaries |
| Progress entries | Bodyweight check-ins, body fat percentage, notes | Tracking body composition over time |
| Coach AI conversations | Messages you send to the in-app AI coach and responses received | Providing personalised coaching and building conversational memory |
Camera & Media
When you use the food photo scanning feature, ArchieFit requests access to your camera and/or photo library. The image is converted to a compressed base64 representation and sent securely to our backend for AI-powered food recognition. Images are processed in real time and are not stored permanently on our servers after analysis is complete.
Device & Notification Data
If you enable push notifications (workout reminders, meal check-ins), we collect a device push token tied to your account. This token is used solely to deliver notifications you have opted into. You can disable notifications at any time in the app under Settings → Notifications, or in your device's system settings.
Usage Data
We automatically collect limited usage information including app version, device operating system type, features accessed, and session activity. This data is linked to your account and used only to improve app performance and diagnose technical issues.
How We Use Your Information
| Use | Description |
|---|---|
| Service delivery | Creating your account, generating your AI workout plan, logging nutrition, tracking progress |
| AI plan generation | Your onboarding profile is sent to our backend to generate a personalised 30, 60, or 90-day training plan with exercises matched to your goals, level, limitations, and equipment |
| AI coaching | Your profile, active plan, today's workout, today's nutrition, and a summary of past conversations are assembled into a coaching context on each message to make Coach Archie responses specific to you |
| Nutrition analysis | Food photos are analysed by AI to identify items and estimate macros; barcode scans are looked up against food databases |
| Notifications | Sending workout reminders and meal check-in prompts you have opted into |
| Subscription management | Verifying your subscription status via Stripe to grant or restrict access to Pro features |
| App improvement | Aggregated, anonymised usage patterns are used to improve features and fix bugs |
| Account management | Responding to support requests, account deletion requests, and privacy inquiries |
How We Share Your Information
We do not sell your personal information. We share data only with the following service providers who operate infrastructure on our behalf, and only to the extent necessary for them to provide their service.
Infrastructure & Service Providers
| Provider | Role | Data Involved |
|---|---|---|
| Railway | Backend application hosting — all API requests from the app go through our Railway-hosted server | All user data transmitted to and from the app |
| OpenAI | Powers the AI workout plan generator, food photo recognition, and Coach Archie responses | Your profile context, coaching conversation history, and food images (processed in real time, not stored by OpenAI under our API agreement) |
| Stripe | Subscription billing and payment processing | User identifier and subscription status. Payment card details are handled entirely by Stripe and are never seen or stored by ArchieFit |
| Apple (App Store) | App distribution and in-app purchase infrastructure | Apple ID, purchase records as handled by Apple's own systems |
All providers are contractually required to protect your data and are prohibited from using it for any purpose other than delivering their service to ArchieFit.
Legal Requirements
We may disclose your information if required to do so by law, court order, or governmental authority, or where we reasonably believe disclosure is necessary to protect the rights, safety, or property of ArchieFit, our users, or the public.
Business Transfers
In the event of a merger, acquisition, or sale of ArchieFit LLC, your data may be transferred as part of that transaction. We will notify you via email or in-app notice before your data becomes subject to a different privacy policy.
Data Retention
| Data Type | Retention Period |
|---|---|
| Account, profile, and onboarding data | Until you delete your account |
| Workout and nutrition logs | Until you delete your account |
| Coach AI conversation history | Until you delete your account or request deletion of conversation history |
| Food scan images | Processed in real time and not retained on our servers after analysis |
| Push notification device tokens | Until you disable notifications or delete your account |
| Usage and session data | Up to 24 months, then anonymised |
| Billing and payment records | As required by applicable law (typically 7 years); managed by Stripe |
When you delete your account, we will delete or anonymise your personal data within 30 days, except where retention is required by law. You can delete your account at any time in Settings → Account → Delete Account.
Your Rights
Depending on your location you may have the following rights regarding your personal data. To exercise any of them, contact us at privacy@archiefit.com and we will respond within 30 days.
| Right | Description |
|---|---|
| Access | Request a copy of the personal data we hold about you |
| Correction | Request correction of inaccurate or incomplete data |
| Deletion | Request deletion of your personal data. You can also do this directly in the app: Settings → Account → Delete Account |
| Portability | Request your data in a structured, machine-readable format |
| Objection | Object to certain types of processing |
| Withdraw consent | Withdraw consent at any time where processing is consent-based (e.g. push notifications can be disabled in Settings → Notifications) |
Children's Privacy
ArchieFit is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@archiefit.com and we will promptly delete it.
Users between the ages of 13 and 17 should use the app only with parental or guardian consent.
Security
| Measure | Description |
|---|---|
| Encryption in transit | All data between the app and our backend is encrypted via HTTPS/TLS |
| Token storage | Authentication tokens are stored in expo-secure-store (iOS Keychain / Android Keystore) — never in plain storage |
| Token refresh | Short-lived access tokens with automatic silent refresh using refresh tokens; 401 responses trigger immediate session re-validation |
| Access controls | User data on our backend is scoped per user account — no user can access another user's data |
| Payment security | Card details are handled entirely by Stripe and are never transmitted to or stored on ArchieFit servers |
While we implement industry-standard security measures, no method of electronic transmission or storage is 100% secure. We are committed to protecting your data and will notify you promptly in the event of a breach that affects your personal information.
Third-Party Services
The following third-party services are integrated into ArchieFit. Each governs their own handling of data under their respective privacy policies.
| Service | Purpose in ArchieFit | Privacy Policy |
|---|---|---|
| Railway | Backend hosting | railway.app/legal/privacy |
| OpenAI | AI plan generation, food scanning, Coach AI | openai.com/privacy |
| Stripe | Subscription billing | stripe.com/privacy |
| Apple | App Store distribution, Sign In with Apple, push notifications | apple.com/legal/privacy |
| Sign In with Google (optional) | policies.google.com/privacy |
ArchieFit does not integrate with any advertising networks, data brokers, or third-party analytics platforms.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes we will notify you via email to your registered address and display a notice within the ArchieFit app. The "Last Updated" date at the top of this page will always reflect the most recent revision.
Your continued use of ArchieFit after the effective date of any changes constitutes your acceptance of the updated policy. If you do not agree, you may delete your account at any time.
Contact Us
For any questions, requests, or concerns about this Privacy Policy or how your data is handled:
North Bergen, NJ 07047
United States
Email: privacy@archiefit.com
Website: archiefit.app
We aim to respond to all privacy-related requests within 30 days of receipt.