Privacy Policy
How WeeFit collects, protects, shares and deletes your data, written plainly for coaches and trainees.
Last updated:
At a glance
- WeeFit is a coaching platform. We hold what you and your coach put into it: plans, meals, check-ins, messages.
- Personal data (phone, birthdate, gender, health profile, check-in values, messages) is encrypted field by field before it is stored. The keys never reach the app or the browser.
- You decide what your coach may see (health, progress, photos), and ending a coaching relationship cuts their access immediately.
- We never see or store card numbers. Payments run on the payment company’s hosted page.
- We sell nothing about you and show no advertising. The marketing website sets no cookies and runs no analytics.
- You can delete your account yourself, from the app, at any time. Deletion is irreversible.
- Questions: support@weefit.app
Who we are
WeeFit is operated by [Company legal name], [registered address] (“WeeFit”, “we”, “us”). This policy explains what we collect when you use the WeeFit web app, the iOS and Android apps and the weefit.app website, why we collect it, who else sees it, and how you stay in control.
“You” is anyone with a WeeFit account: a trainee, a coach, or a member of a gym or studio team once gyms open. Where a rule applies to one of these roles only, we say so.
What WeeFit is
Coaches use WeeFit to manage their clients: training plans, meal plans, chat, check-ins and billing. Trainees use the app because a coach invited them. Self sign-up and a personal paid subscription (training on your own, without a coach) are not open yet; this policy already covers them. Gyms and studios are planned.
WeeFit is in Arabic and English; prices are in Israeli shekels (ILS).
What we collect
We collect only what the product needs to work. Grouped by what it is for:
Your account. Name (Arabic and/or English), email, avatar, language, timezone, role (trainee, coach, gym staff), birthdate and gender. Gender is optional; it is used, for example, to show you the matching 3D body model on the training screen.
Contact. Phone number (optional). A coach may type it when inviting you so the invite reaches you by SMS, and a gym front desk may use it to find your record.
Coaching content. Training plans and sessions, exercise logs, meal plans, and the notes your coach writes for you.
Health and body. Your health profile (allergies, medical conditions, diet preferences, disliked foods, height); your check-ins (weight, body fat, a note, InBody readings and InBody PDF reports); your progress photos.
Messages. Chat between coach and trainee, including attachments.
Payments. When a client pays a coach through WeeFit, or a coach or trainee pays WeeFit: the amount, currency, status, invoice and pay-link details, and the payer name and email we pass to the payment company. We never collect or store card numbers. The card is entered on the payment company’s own hosted page; we receive a token and a result. Cash payments that a coach logs are records only; no money passes through us.
Presence. Whether you are online and when you were last seen: a short-lived status you can hide in your settings.
Device and technical. Push tokens (Expo push tokens on iOS and Android, Web Push subscriptions in browsers), the app version, and basic server logs kept for security and debugging.
Consents. Your data-scope switches (what your coach may see of your health profile, progress and photos) and when you changed them.
The marketing website (the weefit.app pages that are not the app) sets no cookies and runs no analytics. If that ever changes, this policy is updated first.
We do not ask for a government ID, and we do not collect precise location.
Where it comes from
Most of it you type yourself. Some is written by your coach: your plan, your meals, their notes, and the name and phone number they typed when inviting you, yours to correct once you sign in. Some is generated by use: logs, presence, push tokens. If you sign in with Google or Apple, we receive your email and name from them.
Why we use it
- To run the service: show you your plan and meals, deliver messages, record check-ins, let your coach bill you.
- To keep you signed in safely: authentication, a check against known breached passwords when you set one, session security.
- To notify you: invites, billing reminders, a coach’s message, a check-in that is due, by email, push notification or, for invites only, SMS.
- To take and record payments, and to keep the accounting records the law requires.
- To help the coach work: the coach’s AI assistant drafts plan changes from the plan and meal context the coach already has (see “Third parties”).
- To protect the service: prevent abuse, investigate security incidents, fix faults.
We do not sell personal data, we do not run advertising, and we do not build profiles for anyone outside the coaching relationship you chose.
Legal basis
We process your data because it is necessary to provide the service you and your coach asked for (contract); because you agreed to it (consent: your data-scope switches, optional fields, push notifications); because the law requires it (accounting records); and where we have a legitimate interest that does not override your rights (security, fraud prevention, debugging).
We handle personal data in line with the Israeli Protection of Privacy Law, including Amendment 13, and, where they apply to you, the rights recognised by the GDPR: access, rectification, erasure, portability and objection. We do not claim any certification.
Who can see what
Your coach sees your plan, meals and messages, and, only while your coaching relationship is active and only within the scope you allow, your health profile, check-ins and progress photos. Three switches in your settings (health, progress, photos) control this. Ending the relationship cuts the coach’s access immediately. Archiving deletes nothing of yours; it ends their access.
A coach can never edit your personal details: name, phone, email, birthdate, gender, avatar. Only you edit yourself. The coach’s pen reaches the work (plan, food, notes), not the person.
More than one coach is possible. Each sees only what happens in their own workspace with you.
Gym staff (when gyms open) see what is needed to run the front desk of their gym: membership, check-ins at the door, and matching by phone number.
WeeFit staff access personal data only to provide support you asked for, to investigate abuse or a security incident, or as the law requires.
How we protect it
We built WeeFit assuming that one day the database will be read by someone who should not. So:
- Field-level encryption before storage. Phone, birthdate, gender, health profile, check-in values, chat messages and attachment names are encrypted on our servers before they are written. The encryption keys live in a key vault; they are never in the app and never in the browser, and encryption and decryption happen only on our servers.
- A blind index for phone numbers. A phone number can be searched only through a keyed hash (HMAC). The number itself stays encrypted.
- Private storage, short-lived links. Progress photos, InBody reports and chat attachments live in private storage and are served only through signed links that expire.
- Encrypted at rest and in transit. The database and its backups are encrypted; every connection uses TLS.
- Row-level security. Every read and write is checked inside the database against the person’s permissions, not only in the app.
- What is plain is written down. Names and avatars are stored in plain form because the product shows them everywhere. Your email is the login identifier and is managed by the authentication provider.
No system is perfectly secure. If a breach affects your data, we will tell you and the authorities as the law requires.
Third parties who process data for us
We use a small number of service providers. Each receives only what its job needs:
- Supabase: database, authentication, file storage, serverless functions and realtime; the hosting of all data, encrypted as described above.
- Resend: transactional email (invites, billing reminders, notifications). Receives the recipient’s email, name and the message content.
- Anthropic (Claude): the coach’s AI assistant. Receives the relevant plan and meal context and the coach’s request (see below).
- TOGO (api.togo.ps): card payments on a hosted payment page. Receives the payer’s name, email and the amount. Card numbers stay with TOGO.
- Expo push service: delivering push notifications on iOS and Android. Receives the device push token and the notification content.
- Browser push services: Web Push in your browser. Receive the push subscription and the notification content.
- HTD (sms.htd.ps): SMS invites, when a coach chooses SMS. Receives the phone number and the invite text.
- Google and Apple: sign-in, only if you choose to use them. We receive your email and name.
- media.weefit.app (our own host): exercise library pictures and videos only. No personal data.
About the AI assistant. When a coach asks the assistant, the plan and meal context and the coach’s request are sent to Anthropic to generate a draft. Nothing is saved to a plan until the coach approves it. Your health-profile data is not sent unless the coach already has access to it and it is needed for the request. You can ask your coach not to use the assistant on your plan. Usage is metered per coach.
Some of these providers are outside Israel and Palestine. Where data crosses a border, we rely on the provider’s contractual safeguards.
How long we keep it
- While your account is active, we keep what the product needs.
- Business records (invoices, payment events, audit events) are append-only and kept as long as accounting and tax law requires, even after your account is gone; once it is deleted, they carry no name.
- Soft delete by design. Archiving a client or ending a coaching relationship does not delete your data; it ends the coach’s access. Your check-ins and photos stay yours.
- Backups roll off within 30 days of a deletion.
Your rights and controls
- See and correct your data: from your account settings, or by asking us.
- Control your coach’s view: the health, progress and photos switches, at any time.
- Hide your presence: in settings.
- Turn notifications off per channel and per kind, in the app.
- Export your data: email support@weefit.app and we will send it in a common format.
- Delete your account: in the app (Account → Delete account) or by email to support@weefit.app with the subject “Delete my account”. It is irreversible and there is no grace period. Personal data is erased or anonymised, files are deleted, the login is disabled, coaching relationships end and your coach is told. Full steps: Delete your account.
- Object or complain: write to us. You may also complain to your data-protection authority.
We answer within the legal deadline, usually much sooner.
Children
WeeFit is for people aged 16 and over. A younger person may use WeeFit only under a coach, with a parent’s or guardian’s consent given to that coach. If we learn that an account belongs to someone under 16 without that consent, we will close it.
The iOS and Android apps
The apps ask for a permission only when you use the feature that needs it: camera and photo library for progress photos and chat attachments, notifications for push. You can withdraw each permission in your device settings. Sign in with Apple is supported; if you choose to hide your email, we receive the relay address Apple creates for you.
Changes to this policy
We may update this policy. Material changes are announced in the app or by email before they take effect, and the “updated” date at the top always tells you which version you are reading.
Contact
support@weefit.app · [Postal address]