Privacy notice
Version 2026-10-07.2-2fe4d0618941c78b
Draft for review. Provider and deployment details are incomplete. Commercial publication is blocked until completed.
Information and purposes
We process account name and username, hashed password, language, plan, amount, expiry and last login to provide and administer the service. Routines, workouts, measurements, preferences, declared conditions, food records, supplements and photos you provide are used for your tracking. We do not request identity documents or bank cards. Do not place unnecessary information or information about others in notes.
Choices and sensitive data
For the published service, acceptance of terms and authorization to process basic account data are recorded. Personal tracking modules require separate authorization for data that may reveal health information and photos. You can decline or withdraw this authorization under My rights. This limits use and does not automatically delete existing records. You may request deletion. We do not diagnose or medically analyze your photos.
Who may access
Each account sees its own profiles. The application administrator manages access, prices and expiry, and the interface prevents access to clients’ workouts and photos. Authorized infrastructure staff may have technical access to files and backups for maintenance or incidents under confidentiality duties. We do not promise end-to-end encryption: the application does not encrypt the database and photos on disk.
External services and countries
The hosting and backup providers identified below provide infrastructure. If you choose photo recognition, a reduced image is sent to the Anthropic API. The application does not save it. The provider has its own retention policy, generally up to 30 days with legal and safety exceptions, and may process it outside your country. Album photos are not sent to Anthropic. Strava connects only with your authorization and can be disconnected. WhatsApp opens only when you select the support link and has its own policy.
Cookies and device storage
Technical logs may include IP, date, route, result and duration, without photos or passwords. Login limits store hashed IP/user identifiers. We use an HttpOnly session cookie (up to 12 hours), a language preference (up to one year) and a temporary authorization cookie when connecting Strava. Theme and selected profile are stored on your device. No advertising, marketing pixels or analytics cookies are included. Personal data is served without caching. Downloads and shared copies remain under your control.
Retention and deletion
Tracking records are retained within the maximum period shown below. The provider reviews and applies this period manually. The application does not automatically delete accounts. You may request earlier deletion. Expiry or suspension does not delete them. Records and photos can be deleted and records exported per profile; the JSON export excludes album image files. Deletion from active storage does not immediately destroy old copies. Configured external backups may retain them for up to 12 months. Local photo backups must be purged when handling deletion. Web technical logs are limited to 30 days in the deployment template. Audit records and receipts are kept only as needed for security and justified obligations.
Your rights and requests
You may request access, correction, deletion, objection or withdrawal through My rights or the listed contact. Submitting a request is free. Identity is verified in proportion to the risk without asking for your password. Requests receive an identifier and are stored for the administrator to process. They do not automatically send an email or guarantee that the provider has read them. Expired accounts can contact the provider directly. Any legal retention, restriction and complaint channel will be explained.
Security and incidents
We apply account access controls, limited sessions, browser protection, request limits and backup provisions for deployment. No system is infallible. If an incident affects your data, we will investigate, contain it and inform you through available contact where appropriate, with concrete steps. We do not sell data or use it for advertising.
Provider and contact
- Provider
- Avigo Group
- Address
- Urbanización Caperuza, San Francisco de Macorís, provincia Duarte
- Country
- República Dominicana
- Privacy / support
- jobf0001@gmail.com
- Hosting / country
- DigitalOcean / Canadá
- Backup / country
- PENDIENTE / PENDIENTE
- Refund policy
- Vigencia 365 días sin renovación automática. Reembolso íntegro solicitado dentro de 2 horas desde compra confirmada. Después no hay reembolso comercial por desistimiento ni tiempo no usado; se conservan los derechos obligatorios por incumplimiento y cobros indebidos. Contacto: jobf0001@gmail.com.
- Maximum account retention / manual review
- 90 días después de vencer o cerrar la cuenta, con revisión manual antes de borrar. Las copias de respaldo pueden conservarla hasta 12 meses.