Athly ATHLY
Features Support FR

Privacy Policy

Last updated: July 31, 2026

1. Who we are

Data controller: Maxime Pigeon, doing business as Athly (Quebec, Canada).

Person responsible for personal data protection: Maxime Pigeon, owner, reachable via the contact below.

For any question or to exercise your rights: contact@athlyfit.app

This policy applies to the Athly app (mobile and web). It implements the GDPR (EU 2016/679) and applicable personal data protection laws. The app is intended for ages 16 and up.

2. Data we collect

  • Account: email, name, password (hashed), language, preferred units.
  • Profile and self-reported health: age, weight, height, measurements, goals, reported injuries, sleep, stress, supplements — only what you enter.
  • Activity and nutrition: workouts, exercises, loads, steps, hydration, food and meals, meal plans, dietary preferences.
  • Progress photos: private, never visible to other users, face-blur available; automatically analyzed only if you request it.
  • Technical data: IP address and device model (login, security, referral anti-abuse), approximate IP-based geolocation (local pricing and taxes), error logs, internal usage events, never resold or shared for advertising.
  • Payment: entirely handled by Apple / Google / our payment processor (RevenueCat); we only receive the subscription status, never your card.

3. Why (legal bases)

  • Providing the service (contract): tracking, the Athly program, multi-device sync, backup.
  • Your consent (health data, photos): you enter this data voluntarily and can delete it anytime — that's how you withdraw consent.
  • Legitimate interest: security, preventing referral fraud (IP/device fingerprint), internal improvement statistics.
  • Legal obligations: accounting retention of transactions.

No decision producing legal effects is made in a fully automated way: app-generated suggestions are recommendations you remain free to follow or not.

4. Your rights

Access, copy and portability (machine-readable export), rectification, deletion (individual items or the entire account: Profile → Account and privacy → Delete account), objection and restriction of processing based on legitimate interest.

We respond within 30 days. You can also file a complaint with the competent personal data protection authority, or your local authority (e.g. CNIL in France).

5. Retention

  • Active account: data is kept as long as you use the app.
  • Account deletion: personal data erased within 30 days (backups included).
  • Transactions: retained for the period required by tax law.
  • Technical and anti-abuse logs: 12 months maximum.

6. Sharing and transfers

We never sell or rent your data. It is only shared with strictly necessary processors:

  • Hosting (server + database) [To complete: hosting provider and region].
  • Apple App Store / Google Play / RevenueCat — subscriptions and payments.
  • Resend — sending our transactional emails.
  • Open Food Facts — food search (queries without your identity).
  • IP geolocation service — IP address only, for currency and taxes.

Some providers may be located outside Canada/EU; transfers rely on recognized safeguards (standard contractual clauses), and every cross-border transfer of personal data is subject to a privacy impact assessment.

7. Cookies and local storage

  • Mobile app: no advertising cookies. Local storage (preferences, caches, drafts) needed for offline functionality.
  • Web: only session-related local storage (login token, preferences, theme). No third-party trackers, no external targeted advertising.

8. Security

Hashed passwords, encrypted communications (HTTPS), sensitive data encrypted with AES-256 on your device, data access limited to what's strictly necessary, photos private by default. No system is foolproof — let us know immediately if you notice anything unusual on your account.

Incidents: in the event of a privacy incident presenting a risk of serious harm, we notify the competent authority and affected individuals, and the competent supervisory authority within 72 hours for European users (art. 33-34 GDPR). An incident log is maintained.

Privacy Terms of use Support