Privacy Policy
Last updated: July 31, 2026
1. Who we are
Data controller: Maxime Pigeon, doing business as Athly (Quebec, Canada).
Person responsible for personal data protection: Maxime Pigeon, owner, reachable via the contact below.
For any question or to exercise your rights: contact@athlyfit.app
This policy applies to the Athly app (mobile and web). It implements the GDPR (EU 2016/679) and applicable personal data protection laws. The app is intended for ages 16 and up.
2. Data we collect
- Account: email, name, password (hashed), language, preferred units.
- Profile and self-reported health: age, weight, height, measurements, goals, reported injuries, sleep, stress, supplements — only what you enter.
- Activity and nutrition: workouts, exercises, loads, steps, hydration, food and meals, meal plans, dietary preferences.
- Progress photos: private, never visible to other users, face-blur available; automatically analyzed only if you request it.
- Technical data: IP address and device model (login, security, referral anti-abuse), approximate IP-based geolocation (local pricing and taxes), error logs, internal usage events, never resold or shared for advertising.
- Payment: entirely handled by Apple / Google / our payment processor (RevenueCat); we only receive the subscription status, never your card.
3. Why (legal bases)
- Providing the service (contract): tracking, the Athly program, multi-device sync, backup.
- Your consent (health data, photos): you enter this data voluntarily and can delete it anytime — that's how you withdraw consent.
- Legitimate interest: security, preventing referral fraud (IP/device fingerprint), internal improvement statistics.
- Legal obligations: accounting retention of transactions.
No decision producing legal effects is made in a fully automated way: app-generated suggestions are recommendations you remain free to follow or not.
4. Your rights
Access, copy and portability (machine-readable export), rectification, deletion (individual items or the entire account: Profile → Account and privacy → Delete account), objection and restriction of processing based on legitimate interest.
We respond within 30 days. You can also file a complaint with the competent personal data protection authority, or your local authority (e.g. CNIL in France).
5. Retention
- Active account: data is kept as long as you use the app.
- Account deletion: personal data erased within 30 days (backups included).
- Transactions: retained for the period required by tax law.
- Technical and anti-abuse logs: 12 months maximum.
6. Sharing and transfers
We never sell or rent your data. It is only shared with strictly necessary processors:
- Hosting (server + database) [To complete: hosting provider and region].
- Apple App Store / Google Play / RevenueCat — subscriptions and payments.
- Resend — sending our transactional emails.
- Open Food Facts — food search (queries without your identity).
- IP geolocation service — IP address only, for currency and taxes.
Some providers may be located outside Canada/EU; transfers rely on recognized safeguards (standard contractual clauses), and every cross-border transfer of personal data is subject to a privacy impact assessment.
7. Cookies and local storage
- Mobile app: no advertising cookies. Local storage (preferences, caches, drafts) needed for offline functionality.
- Web: only session-related local storage (login token, preferences, theme). No third-party trackers, no external targeted advertising.
8. Security
Hashed passwords, encrypted communications (HTTPS), sensitive data encrypted with AES-256 on your device, data access limited to what's strictly necessary, photos private by default. No system is foolproof — let us know immediately if you notice anything unusual on your account.
Incidents: in the event of a privacy incident presenting a risk of serious harm, we notify the competent authority and affected individuals, and the competent supervisory authority within 72 hours for European users (art. 33-34 GDPR). An incident log is maintained.