• Effective date: [EFFECTIVE DATE]
  • Controller/product owner: [LEGAL ENTITY OR PERSON]
  • Contact: [PRIVACY EMAIL]
  • Postal address: [LEGAL ADDRESS]

Scope

This draft describes Fitness Age Calculator on iOS, Android, and the website. The service is intended for adults aged 18 and over. The released policy must identify the actual controller, processors, countries, and features enabled in production.

Data the product may handle

Guest and local use

You can use core assessments and calculators without an account. Guest drafts, results, scenarios, plans, preferences, and history are stored on your device or browser. The calculation is designed to run locally. Local data leaves the device only when you deliberately use an enabled network feature, such as account sync, a persistent share, export, support, or an optional contribution.

Removing the app, clearing browser/site data, or using an in-product local-data control can remove local guest data. Device backups may retain app data according to your operating-system settings.

Assessment and fitness information

Depending on the mode you choose, the product may handle chronological age, selected female or male reference curve, height, body mass, waist circumference, resting or finish heart rate, activity category, walk time and protocol, VO₂ value and uncertainty, grip strength and protocol, test conditions, timestamps, units, source/provenance, model version, confidence, ranges, explanations, and derived scores.

The product does not infer a reference curve, diagnosis, ethnicity, gender identity, medication, disability, or other sensitive characteristic. Missing information remains missing.

Optional health-platform imports

On mobile, you may choose particular relevant values from Apple Health or Health Connect. Permission is optional and granular. The product records the metric, source, time, original/canonical unit, selection or aggregation rule, and your confirmation. It does not request or copy your whole health history. You can revoke platform permission; manual entry remains available.

Account and sync information

If you create an account for cloud sync, the service may process a Supabase user identifier, provider identifier, email for magic links, profile preferences, consent records, sync state, deletion state, and the records you choose to sync. Authentication uses Google, Sign in with Apple, or email magic links; no product password is stored. Provider account data is also governed by that provider.

Purchases and entitlements

If iOS Pro is offered, Apple processes the purchase. The service may store product ID, transaction and original-transaction identifiers, signed verification status, entitlement state, purchase/expiration/revocation dates, environment, and limited audit/security events. It does not receive your full payment-card details. Android and the website may recognize a synced entitlement but do not offer the iOS purchase.

Free mobile versions may use Google Mobile Ads. Consent and privacy choices are requested where required. Personalized ads are requested only where allowed and consented to; otherwise the released configuration must request limited or non-personalized treatment as supported. Advertising systems may process device, app, coarse location, interaction, diagnostic, and advertising identifiers according to platform settings and Google’s terms. Core safety information and the basic meaning of a result are not conditioned on ad personalization.

The website will not use the mobile AdMob SDK. Web advertising remains disabled unless the owner has an eligible, approved Google-supported web publisher product and this policy/consent flow is updated.

Analytics, diagnostics, and security

If enabled in the released build, the service may send allowlisted categorical events such as assessment mode, step, confidence band, feature state, ad placement/outcome, coarse performance bucket, sync outcome, and campaign/referrer group. Analytics must not contain raw health measurements, exact Fitness Age, email, free text, magic-link/share/auth tokens, or health-import payloads.

Crash, performance, structured server, rate-limit, and security records may include app/version, platform, timestamps, coarse failure categories, request IDs, and pseudonymous identifiers. Health inputs and tokens are prohibited from logs and breadcrumbs.

Sharing and support

An exported image uses only the details you select; the default card contains Fitness Age, age difference, confidence, and branding. A persistent preview requires sign-in and stores a hashed/unguessable token reference, minimal selected preview fields, creation/expiry/revocation state, and abuse controls. Public previews are intended to be noindex and stop resolving after revocation.

If you contact support, the service processes the contact information and message you provide. Do not send unnecessary health details.

Purposes

Data is used to calculate and explain results; save drafts/history; provide optional sync, export, sharing, reminders, health import, advertising, rewarded access, and Pro entitlements; remember privacy choices; prevent abuse and fraud; operate and secure the service; comply with law; and, only with separate consent, improve future methodology.

The final policy must map each purpose to the lawful basis required in each applicable jurisdiction, such as consent, performance of a requested service/contract, legitimate interests with a balancing assessment, or legal obligation. Health-data and advertising bases require specific legal review.

Separate optional research/model-improvement contribution

Contribution is off by default and separate from terms, account creation, health processing, analytics, ads, and notifications. Declining does not limit features. If you opt in, an allowlisted contribution pipeline removes direct identifiers, precise timestamps/locations, free text, device/auth/share identifiers, and rare unsafe combinations before an approved dataset is created.

Pseudonymous data is not called anonymous. You can withdraw and remove identifiable or not-yet-irreversibly-de-identified contribution records. Data already irreversibly de-identified may no longer be linkable for removal; the release must define and review that boundary before collecting contributions.

Sharing with processors and others

The production processor list may include Supabase for authentication/database/functions, Apple and Google for platform services, Google for mobile ads/consent, selected auth providers, and separately approved analytics/crash/monitoring vendors. The final policy must name every active processor, purpose, data category, retention, location, contract/transfer mechanism, and deletion path.

Data may also be disclosed when reasonably required by law, to protect rights/safety/security, or in a reviewed business transfer. Fitness and health data is not sold as a standalone data product. Jurisdiction-specific definitions of “sale,” “sharing,” and targeted advertising require explicit review and opt-out controls where applicable.

Retention

Local guest data remains until you clear it, remove the app/site storage, or retention controls apply. Synced assessment history remains until account deletion because historical results are immutable within the product; a deletion request removes the account-level records rather than rewriting a result. Revoked shares stop resolving promptly.

Consent, support, security, billing/transaction, deletion-job, and backup records use narrow documented schedules. Backups expire under the provider schedule, and restores must replay post-backup deletion/withdrawal tombstones before serving data. The final public policy must state the production schedules, legal exceptions, and verification process.

Your choices and rights

Depending on location, you may have rights to access, correct, export, delete, restrict, object, withdraw consent, opt out of certain advertising/data uses, or complain to a regulator. Use in-product privacy options, export, research withdrawal, share management, and account deletion where available, or contact [PRIVACY EMAIL].

Withdrawing a choice does not make earlier lawful processing unlawful. Some narrow billing, fraud, security, dispute, or legal records may be retained when required and documented.

Security

The design uses encrypted transport, provider encryption at rest, row-level authorization, secure platform token storage, hashed share tokens, least-privilege server functions, validation, rate limits, immutable result/version records, and secret scanning. No method is completely secure. Contact [SECURITY EMAIL OR DISCLOSURE URL] with a suspected vulnerability; do not include real health or account data in a report.

International transfers

Processors may operate in countries different from yours. The final policy must identify applicable transfer mechanisms and safeguards, including regional hosting choices and contractual clauses where required.

Children

Fitness Age Calculator is not directed to anyone under 18 and does not support a headline for children. Contact [PRIVACY EMAIL] if you believe a child provided personal data.

Changes and contact

Material changes will be dated and communicated as required. Methodology changes do not overwrite historical results. Questions or requests: [PRIVACY EMAIL], [LEGAL ADDRESS]. Jurisdiction-specific representative or data-protection-officer details: [IF REQUIRED].