Privacy Policy

TotalFit Connect Inc.  ·  Effective Date: March 12, 2026  ·  Governing Law: Ontario, Canada (PIPEDA)

Privacy & data requests: privacy@totalfitconnect.comLegal notices: legal@totalfitconnect.comSecurity disclosures: security@totalfitconnect.com

1. Who We Are

TotalFit Connect is operated by TotalFit Connect Inc., a company incorporated in Ontario, Canada. This Privacy Policy applies to our mobile app, website (totalfitconnect.com), and any related services (the “Services”). By using TotalFit Connect, you agree to this policy. If you do not agree, please stop using the Services.

2. Data We Collect

We collect data you give us directly, data generated by your use of the app, and limited data from third-party services you connect.

Account & Profile

Name, email address, username, and password (stored as a hashed value — never plain text). Optional profile details include profile photo, bio, date of birth, biological sex, height, weight, and fitness goals.

Workout & Fitness Data

Training information you log — workouts, exercises, body measurements, and performance data — as well as nutrition and body metric data you choose to track. This is your data. We consider it sensitive and treat it accordingly.

Social & Community Content

Posts, comments, likes, follows, direct messages, shared workouts, and any other content you publish to your profile or feed.

Subscription & Payment

Subscription status and entitlement data via RevenueCat. Billing is handled entirely by Apple — we never see or store your payment details.

Device & Usage

Device model, OS version, and a Vendor Identifier (IDFV) for internal analytics only. App usage data including screens viewed, session length, and crash reports — used only to improve the app. Push notification tokens so we can deliver alerts you have opted into.

What We Do Not Collect

We do not collect precise location (GPS) data, access your contacts or address book, use advertising identifiers (IDFA), use cross-app tracking, or use advertising or tracking cookies. We do not integrate with Apple HealthKit at this time — if that changes, we will update this policy and ask for your consent first.

3. How We Use Your Data

We use your data to run the app, improve it, and keep it safe. We do not use your health or fitness data for advertising, and we do not build advertising profiles. Specifically, we use your data to:

  • Provide and operate the Services, including fitness tracking and social features
  • Personalize your experience — suggesting workouts and content based on your in-app activity, not for advertising
  • Process subscriptions and verify entitlements via RevenueCat and Apple
  • Send push notifications and reminders — only with your permission, and you can disable them in device settings at any time
  • Respond to support requests and communicate service updates
  • Detect and prevent fraud, abuse, and violations of our Terms of Service
  • Analyze anonymized, aggregated usage trends to improve the Services
  • Comply with applicable laws and legal obligations

4. How We Share Your Data

We do not sell, rent, or share your personal information for advertising. We share data only in the following limited ways.

Service Providers

We share data with the vendors listed in Section 5 solely so they can provide their services to us. All are bound by data processing agreements and may not use your data for any other purpose.

Public Profile & Social Features

Your username, profile photo, bio, and posts you mark as public are visible to other users. Posts set to “followers only” are visible only to approved followers. Direct messages are visible only to the sender and recipient. You control all content visibility in your privacy settings.

Legal & Safety

We may disclose data if required by law, court order, or to protect the safety of our users or the public.

Business Transfers

If TotalFit Connect is acquired or merged, your data may transfer as part of that transaction. We will give you at least 30 days’ notice before your data becomes subject to a materially different privacy policy.

5. Third-Party Processors

The following vendors process data on our behalf. All are contractually restricted to using your data only for the services they provide to us.

VendorPurposeCountryPrivacy Policy
RevenueCatSubscription managementUnited StatesView ↑
Expo / EASPush notificationsUnited StatesView ↑
SupabaseDatabase & file storageUnited StatesView ↑
VercelHosting & edge functionsUnited StatesView ↑
AppleAuthentication & billingUnited StatesView ↑

6. Health & Fitness Data

Workout, body measurement, and nutrition data is sensitive personal information. We treat it with heightened care: we do not share it with insurers, employers, or advertisers, and we do not use it to make automated decisions that affect you.

Under GDPR, processing this data is based on your explicit consent, which you provide when you enter it into the app. You can withdraw consent by deleting the data from your profile or deleting your account. Withdrawal does not affect past processing.

Profile fields such as height, weight, and biological sex are optional — the core app works without them.

TotalFit Connect is not a medical service. Nothing in the app constitutes medical advice. Always consult a qualified professional before starting a new exercise or nutrition program.

7. App Permissions

TotalFit Connect requests only the permissions it needs. All optional permissions can be denied without losing core functionality.

  • Notifications (Optional) — workout reminders and social alerts. Revoke at any time in Device Settings → TotalFit Connect → Notifications.
  • Camera & Photos (Optional) — uploading a profile photo or attaching images to posts. Revoke at any time in Device Settings → TotalFit Connect → Photos / Camera.
  • Location & Tracking (Not Requested) — we do not request location access, advertising identifiers (IDFA), or App Tracking Transparency (ATT) permission.

8. Data Retention & Deletion

You can delete your account at any time from Settings → Account → Delete Account. Your personal data is deleted or anonymized within 30 days. Backup copies are purged within 90 days. Comments you left on other users’ posts are anonymized (shown as “Deleted User”) to preserve conversation integrity. Anonymized, aggregate analytics data may be retained indefinitely. We may retain specific data longer where required by law or for fraud-prevention purposes.

To request deletion by email, contact privacy@totalfitconnect.com from your registered address. We respond within 30 days and may ask you to verify your identity.

9. Security

We use industry-standard security measures including TLS encryption in transit, bcrypt password hashing, network-level access controls, and limited production data access. We perform regular security reviews. We will never ask for your password via support email or in-app message. To report a vulnerability, email security@totalfitconnect.com.

No system is 100% secure. If a breach occurs that affects your rights, we will notify you as required by law.

10. Your Rights

Depending on where you live, you may have rights to access, correct, delete, or export your data, and to withdraw consent or object to certain processing. To exercise any right, email privacy@totalfitconnect.com from your registered address. We respond within 30 days.

Canada (PIPEDA / Quebec Law 25)

Contact the Office of the Privacy Commissioner at www.priv.gc.ca. Quebec residents also have rights under Law 25, including portability and automated decision-making disclosure.

EU / UK (GDPR / UK GDPR)

Legal bases for processing: consent (health/body data), contract performance (account services), and legitimate interests (security, fraud prevention). You may lodge a complaint with your local supervisory authority (e.g., the ICO in the UK). As a Canadian-based company, we are monitoring our GDPR Article 27 representative obligations and will appoint one if required.

California (CCPA / CPRA)

We do not sell or share personal information for cross-context behavioral advertising. Rights requests may be submitted directly or through an authorized agent with written authorization.

Australia (Privacy Act 1988)

Contact the OAIC at www.oaic.gov.au.

11. Children’s Privacy

TotalFit Connect is not directed at children under 13 (or 16 in the EEA). We do not knowingly collect data from children under these ages. If you believe a child has created an account, contact privacy@totalfitconnect.com and we will delete it promptly.

12. International Transfers

TotalFit Connect is based in Ontario, Canada, which has been recognized by the EU as providing adequate data protection. Data processed by our US-based service providers (see Section 5) is protected by Standard Contractual Clauses. UK transfers are covered by the UK IDTA or equivalent mechanisms.

13. Changes to This Policy

We may update this policy from time to time. For material changes, we will notify you by in-app notification or email at least 14 days before the change takes effect. Continued use after that date means you accept the updated policy.

Questions? Contact us at privacy@totalfitconnect.com or security@totalfitconnect.com.

TotalFit Connect Inc. · Ontario, Canada · © 2026 All rights reserved.