FITLY
LEGAL

Privacy Policy

This is a provisional policy, published to meet the requirements of third-party integrations FITLY connects to (such as wearable device providers). It has not yet been reviewed by a Victorian solicitor and should not be relied on as final legal advice. It will be replaced with a reviewed version before FITLY is generally available to the public.

v1.2 · 2026-08-07

Who we are

FITLY is a personal training and coaching service operated by Matthew Totton, based in Melbourne, Australia. This policy covers the FITLY app and website, at fitlyapp.net and its subdomains.

What we collect

Account details (name, email, phone), health and fitness information you provide (training history, screening answers, measurements, progress photos, nutrition logs), training and check-in data generated by using the app, and — if you choose to connect one — data from a wearable device or health app (steps, sleep, heart rate).

If you are 16 or 17, we also collect a parent or guardian's name, email and phone number, to obtain and record their consent to your coaching.

The optional Health Screen in Settings, and the initial PAR-Q, can collect further sensitive health categories where you choose to answer: sleep-apnoea risk, medication that may interact with training, bone density and fall risk, screening for Relative Energy Deficiency in Sport (RED-S), menstrual-cycle phase logs, life stage (including pregnancy or postpartum detail), and GP or allied-health clearance status. Every question is optional, a "yes" is recorded only as a referral flag for your coach to raise with you — never a diagnosis and never something that changes your program or targets by itself.

If you use the referral program, we record your referral code, who referred you (if anyone), and any credit granted. If you make a one-off purchase of a digital product, we record the purchase and its payment status, separately from ongoing coaching billing.

Why we collect it

To provide coaching: programming your training, understanding your progress, and personalising nutrition education. Health information is sensitive information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and is treated accordingly — collected only with your consent, used only for coaching, and never sold.

Wearable device data

If you connect a wearable device or health app (such as Oura, Polar or Fitbit), FITLY requests read access to the specific data types shown on the connection screen at the time you connect — typically steps, sleep and heart rate. You can disconnect at any time, which stops any future access immediately. FITLY never posts to, or writes back to, your wearable account.

Where it's stored

Data is stored digitally via secure, password-protected systems — Supabase (database), Cloudflare (hosting), and Stripe (payments, once enabled) — each of which maintains its own security standards. Progress photos are private by default and never shared beyond you and your coach without your separate, revocable, written permission. We take reasonable steps to protect data from misuse, interference, loss, unauthorised access, modification or disclosure.

Who sees it

Your coach, for the purpose of coaching you. We do not sell personal information. Beyond your coach, information may be disclosed only to: payment processors (e.g. Stripe), the software providers that run the app (Supabase, Cloudflare), insurers if required, medical professionals with your consent, or where required by law. FITLY has no advertising and no data brokers. A parent or guardian's contact details, collected for a 16-17 year old client, are seen only by your coach and are never shared further.

Automated account and billing messages

The app sends automated in-app and push notifications based on your account status — for example, a reminder if a coaching payment fails to process (via Stripe), or an invitation to come back if your coaching has ended. These use only the account and billing status already described above, are never based on health information, and are not advertising.

How long we keep it

Client records — including health information, session and program history, and signed agreements — are retained for a minimum of seven years for legal and insurance purposes. After that period, information may be securely deleted.

Your rights

You can request access to or correction of your information at any time by contacting your coach directly — we respond within a reasonable timeframe. You may withdraw consent for certain uses of your information in writing; withdrawing consent for optional tracking (like a wearable connection) takes effect immediately and stops future collection, but may affect our ability to continue providing services safely, and does not retroactively delete what was already recorded unless you separately request deletion.

Cookies and analytics

The FITLY website may use cookies or analytics tools to collect anonymous usage data, to help us understand and improve the site. This is separate from the health and coaching data described above, which is never used for advertising.

Data breach notification

If we experience a data breach that is likely to result in serious harm to you, we will assess it and, where required by the Notifiable Data Breaches scheme under the Privacy Act 1988, notify both you and the Office of the Australian Information Commissioner (OAIC) as soon as practicable, along with what happened and what steps we recommend you take.

Complaints

If you believe your privacy rights have been breached, contact us directly using the details below. If the matter remains unresolved, you may contact the Office of the Australian Information Commissioner (OAIC).

Contact

Questions about this policy or your data can be sent to fitly4fitness@gmail.com.