PISTAFIT~/privacy

PISTAFIT privacy policy

Effective date: 13 September 2026

Published at https://pistafit.pistasspot.com/privacy, the URL given to Google Play and to Google sign-in.


who we are

PISTAFIT is an Android app made and run by PISTA, an independent developer. PISTA is the data controller for everything described here.

Questions and requests, or a deletion you would rather not do in the app: freeaccforu98@gmail.com

the short version

PISTAFIT is an offline-first app. Everything you log is written to your device first and the app works fully with the network off. Nothing is sent anywhere unless you create an account or sign in, and even then your progress photos stay on the device. There is no advertising, no analytics SDK, no tracking across other apps or websites, and nothing is sold or handed to data brokers.

what we collect

if you never sign in

Nothing leaves your device. The app stores your logs locally and generates a random device identifier (a UUID) so that a future sign-in can tell one device from another. That identifier is not tied to you, your hardware, your advertising ID, or anything Google holds, and it is not transmitted while you are signed out. Deleting the app deletes it.

if you create an account or sign in

Account information

Your logs, synced from the device

Once you are signed in, the app syncs the log it has been keeping locally. It is stored as an append-only event log — each entry is a record of something that happened, with a timestamp and the device identifier — plus the current state of each item. It covers:

Device identifier

The random UUID generated on first launch is sent with synced events so that edits made on two devices can be reconciled.

the permissions the app asks for

Android permissions are listed here because a permission is a question about your data, and you should be able to see what each one is for. Nothing in this list sends anything anywhere.

PermissionWhat it is forWhere it goes
Physical activity (activity recognition)Reading the built-in step counter so the steps card fills itself in. Asked for the first time you open the steps screen, never at startup, and the app works without it — you can type steps in by handThe sensor reading is written to the device only
NotificationsThe rest-timer countdown, the buzz at the end of a set, and the weigh-in, water, creatine, workout and missed-workout reminders you switch onOn the device
Alarms and reminders (exact alarm)Firing the buzz at the end of a rest set on time. Without it the buzz is scheduled inexactly and may be lateOn the device
Run at startup, wake lock, vibrateRescheduling those reminders after a reboot, and the vibration itselfOn the device

The app declares no camera, photo-library, location, contacts or microphone permission. A progress photo comes back from the Android photo picker or the camera app as a single file you chose, which needs no permission grant.

what we never collect

why we use it

PurposeWhat it uses
Running the app's features — showing your history, averages, streaks, charts and share cardsyour logs, on your device
Backing your log up on the serveryour logs, account email, device identifier
Restoring your profile and targets when you sign in on a new deviceyour profile answers
Signing you in and keeping the session aliveemail, password hash or Google sign-in, device identifier
Account email: verifying your address and resetting a password, plus the weekly recapemail address, display name
Keeping the service working and secure — rate limiting, abuse prevention, debugging a failed syncaccount identifier, device identifier, request metadata

About the backup. Your log is uploaded and kept, but this release has no way to pull it back down: signing in on a new device restores the profile and targets you set during onboarding, not your history. Export your log from the MORE tab → export if you want a copy you can carry. If that changes, this policy changes with it.

About the weekly recap. While you are signed in, the server emails you a summary of your week on a Sunday. It is sent automatically and there is no switch to turn it off in this release, so if you do not want it, delete the account.

We do not use your data for advertising or for third-party profiling, and it feeds no automated decision with legal effects. Nothing is used to train a model. If that ever changes, it is a new purpose, and the section on changes below says how you will hear about it first.

who else handles it

These are the only third parties involved, and each acts as a processor on PISTAFIT's instructions:

ProviderWhat it doesWhat it sees
MongoDB AtlasHosts the database for signed-in accountsAccount records and synced logs
VercelHosts the API the app talks toAPI requests in transit, plus server logs containing IP address and request metadata
ResendSends transactional email (verification, password reset, weekly recap)Email address and the content of those messages
Google (Sign-In)Verifies your identity if you choose "continue with Google"The sign-in itself; PISTAFIT receives your email, name and a Google account identifier

Your data is stored on servers operated by these providers, which may be located outside your country, including in the United States and the European Union. Nothing is sold or rented for anyone else's marketing, and nothing is shared for that purpose.

We will disclose data if we are legally required to, and will tell you unless the law forbids it.

security

Every connection between the app and the API uses HTTPS with TLS. Access tokens are short-lived (15 minutes); refresh tokens are rotated on each use, stored hashed on the server, bound to a device, and kept on the device in the platform's encrypted secure storage. Passwords are hashed. Every database query is scoped to the account that owns the record. No system is perfect, but data is encrypted in transit and at rest by the hosting providers.

how long we keep it

Your logs are kept while your account exists, because the whole point is the history. Server logs and rate-limiting records are kept for up to 30 days. Nothing is kept in an anonymised or derived copy after you delete the account: deletion removes the lot.

deleting your data

In the app: the MORE tab → account → delete account. This deletes your account and every server-side record attached to it immediately, and it cannot be undone. In line with Google Play's requirement, any residual copy in backups is purged within 24 hours.

By email: write to freeaccforu98@gmail.com from the address on the account and ask for deletion. We will action it within 30 days, and normally the same day.

Locally: uninstalling the app removes everything stored on the device, including progress photos. If you are signed in, uninstalling alone does not delete the server copy — use the in-app deletion for that.

You can also export everything the app holds about you at any time, as CSV or JSON, from the MORE tab → export. You may write to the address above to have anything inaccurate corrected or your consent withdrawn, and to restrict or object to processing.

children

PISTAFIT is not directed at children. It is not intended for anyone under 13, and we do not knowingly collect information from anyone under 13. If you believe a child has created an account, write to freeaccforu98@gmail.com and we will delete it.

changes to this policy

If this policy changes, the new version is published at this URL with a new effective date. Material changes are also announced inside the app before they take effect. That includes a new category of data, a new purpose, a new third party, or a new place your data is stored. The date at the top always tells you which version you are reading.

contact

PISTA — freeaccforu98@gmail.com

The terms of use sit alongside this policy and cover the app itself.