FitFriend Frenzy Logo
Fit Friend Frenzy

Privacy Policy

Effective 2 September 2026 · Version 2026-09-02

How FitFriend Frenzy collects, uses, shares, and protects personal data on the website and Android app — written for India’s DPDPA.

Designed for alignment with India's Digital Personal Data Protection Act, 2023 (DPDPA). Have counsel review before commercial launch. Entity registration details will be published when finalized.

1. Who we are (Data Fiduciary)

FitFriend Frenzy ("we", "us", "our") operates the FitFriend Frenzy website, Android app, and related services (the "Service"). Under India's Digital Personal Data Protection Act, 2023 ("DPDPA"), we act as the Data Fiduciary for personal data we determine the purpose and means of processing for.

FitFriend Frenzy is the operating brand of the Service. Registered company name, CIN, and registered office address will be published on this page once incorporation documents are finalized. Until then, use the contact channels below for all privacy and grievance requests.

Contact for privacy requests: support@fitfriendfrenzy.com. General support: support@fitfriendfrenzy.com. Grievance: support@fitfriendfrenzy.com.

2. Scope

This Privacy Policy applies to personal data processed when you use our website, Android application, APIs, and customer support channels. It is designed to align with the DPDPA and related Indian rules. It is not legal advice; we will update it as regulations and our practices evolve.

Policy version: 2026-09-02. Effective: 2 September 2026. Last updated: 2 September 2026.

3. Personal data we process

Account data: name, email address, password (hashed by our authentication provider), profile photo, status text, and account identifiers.

Profile & body metrics you choose to provide: age or date of birth, gender, height, weight, and similar fields used for goals and coaching.

Activity & competition data: steps, workouts, sleep, calories, manual proofs, photos/text used for logging, leaderboard scores, challenge membership, and chat messages in competitions or DMs.

Health Connect (optional): if you grant permission on Android, we may sync aggregated daily activity metrics you authorize (for example steps or workout duration). We do not require Health Connect to use the core Service.

AI inputs you submit: text prompts, meal preferences, form-check photos/frames, and similar content sent to generate coaching outputs.

Device & usage: app/browser type, approximate diagnostics needed for security and reliability, and consent records (policy version and acceptance time).

Support data: messages you send via contact forms or tickets.

4. Purpose of processing

Provide authentication, profiles, logging, competitions, social features, coaching, nutrition tools, and customer support.

Maintain fair play on leaderboards and detect abuse or fraud.

Operate AI features you request (Pulse chat, form check, meal plans, activity parsing, goal suggestions).

Send service notices (account, security, material policy changes). Marketing messages only if you opt in where required.

Comply with law, enforce Terms, and handle grievances under DPDPA / applicable IT rules.

Improve reliability and safety of the Service using aggregated or de-identified insights where practicable.

5. Consent and other bases

We process personal data primarily based on your free, specific, informed, unconditional, and clear consent given when you create an account and accept this Policy and our Terms, and when you enable optional features (Health Connect, camera, microphone, AI tools).

Certain processing may also be necessary to provide the Service you request, to comply with law, or for employment/corporate wellness contexts where an organization administers access under a separate arrangement.

You may withdraw consent for optional processing (for example Health Connect or AI features) in settings or by contacting us. Withdrawal does not affect processing already completed lawfully. If you withdraw consent required to operate your account, we may need to close the account.

6. AI processing notice

AI features use third-party generative AI (currently Google Gemini / related Google AI services) to produce coaching text, meal plans, form feedback, and similar outputs.

Content you submit to AI features (including photos for form check) is transmitted to those processors for the purpose of generating a response. Do not submit information you are not comfortable sharing for that purpose.

AI outputs are informational only and are not medical advice. We do not sell your personal activity data to advertisers.

7. Sharing and processors

We use service providers (Data Processors) to host and operate the Service, including: Google Firebase (Auth, Firestore, Storage, Hosting) — Cloud infrastructure & authentication; Google Gemini / Generative AI APIs — AI coaching, form check, meal plans, activity parsing; Health Connect (Android) — Optional on-device health/activity sync initiated by you.

Organization / franchise admins may see limited membership and aggregate wellness information appropriate to their role when you join an organization.

Friends and competition participants may see profile information and scores you share through social or public challenge features.

We may disclose data if required by Indian law, lawful authority request, or to protect rights, safety, and integrity of the Service.

We do not sell personal data.

8. Cross-border transfers

Our infrastructure and AI providers may process data on servers located outside India (including facilities used by Google). By using the Service and providing consent, you acknowledge such transfers as needed to deliver the Service.

We will follow applicable DPDPA rules on cross-border transfers as notified by the Central Government, and update this section when those notifications require changes to our practices.

9. Retention

We retain personal data only as long as needed for the purposes above, including account life, competition integrity, legal compliance, dispute resolution, and security logs.

When you delete your account (see Data Deletion), we delete or anonymize personal data associated with the account within a reasonable period, except where retention is required by law or for legitimate unresolved disputes.

Backups may persist for a limited time before being overwritten.

10. Your rights as a Data Principal

Under the DPDPA, you may have rights to: (a) access a summary of personal data we process and processing activities; (b) seek correction and erasure; (c) withdraw consent; (d) nominate another individual to exercise rights in case of death or incapacity (as provided by law); and (e) grievance redressal.

To exercise rights, email support@fitfriendfrenzy.com from your registered email, or use in-product account/settings tools where available. We may need to verify your identity before fulfilling requests.

You may also raise a grievance as described in our Grievance Redressal page.

11. Children

The Service is intended for users aged 18 and above. We do not knowingly allow children (under 18) to create accounts without verifiable consent of a parent or lawful guardian as required by the DPDPA.

If you believe a child has provided personal data without required consent, contact us immediately so we can delete the data and close the account. See also our Children’s Privacy page.

12. Security

We use industry-standard protections including encrypted transport (HTTPS), access controls, and Firebase security rules. No method of transmission or storage is 100% secure; please use a strong unique password and protect your device.

13. Changes

We may update this Policy. Material changes will be reflected by a new policy version and effective date. Where required, we will ask for renewed consent. Continued use after notice may constitute acceptance where permitted by law; for consent-based processing we will obtain fresh consent when needed.