nombi-sioi // fitsimp
PRIVACY POLICY
$ nombi-sioi --doc=privacy-policy --product=fitsimp

Privacy Policy

How FitSimp handles your data.

Your workouts, plans, and health data stay on your devices. From version 1.1.2, FitSimp offers an optional Apple account sign-in and Meta advertising measurement with your permission.

effective: September 26, 2026route: /fitsimp/privacy-policy
// note

Workouts stay on your device

FitSimp does not send your workouts, plans, history, or Apple Health data to a FitSimp server.

// note

Optional Apple sign-in

Use FitSimp without an account. With Sign in with Apple, we keep account information and device records to operate your account.

// note

Advertising measurement is your choice

FitSimp asks permission before Meta measures app installs and sessions. You can decline without losing app features. FitSimp does not display ads.

§ 01

Information stored on your device

FitSimp keeps all training data local to the device it runs on.

  • Workout plans, exercise history, sets and reps, body weight entries, personal records, notes, exercise photos, custom icons, theme preferences, and bug-report log files are stored in the app’s local SwiftData store and Application Support directory.
  • Widgets and Live Activities use a shared container on your device. The Apple Watch companion exchanges workout state with your paired iPhone through WatchConnectivity.
  • Sign in with Apple requests your email address, not your name or contacts. Advertising identifiers are collected only for the optional Meta measurement described below.
§ 02

Optional FitSimp account

From version 1.1.2, you can create an optional account with Sign in with Apple. You can continue using FitSimp without an account.

  • Account: your verified Apple user identifier, a random FitSimp account ID, and your email address when Apple provides it. We also store the app language and the times you created and last used the account.
  • Device ID: when you sign in, the app sends a random device identifier that it creates and keeps in the Keychain, and a generic device name (for example, “iPhone”). The service keeps them, and the times the device was first and last used, to show the list of signed-in devices. An account can have a maximum of 4 signed-in devices.
  • The device identifier is linked to your account. We use it only for app functionality. We do not use it to track you.
  • Sessions: sign-in tokens. A refresh token lasts a maximum of 365 days, and signing out revokes it.
  • Apple authorization: the service stores an encrypted Apple refresh token so it can revoke the authorization when you delete your account.
  • We use account information to operate and protect your account. We do not send your account email address or FitSimp account ID to Meta.
  • Your workouts and Apple Health data are not part of your account. They stay on your device.
§ 03

Sign in with Apple

Apple authenticates you. FitSimp does not receive your Apple password.

  • Apple supplies your verified identity and, when provided, your email address. If you choose Hide My Email, Apple supplies a private relay address instead.
  • FitSimp does not ask you to create a password or send an email verification code for Apple sign-in. Google and email/password sign-in are unavailable in version 1.1.2.
  • We do not send marketing email or newsletters, and we do not add your address to a mailing list.
§ 04

Security and service logs

The account service keeps only the records it needs to run and to stop abuse.

  • The service uses your IP address to limit repeated attempts (a maximum of 5 attempts in 10 minutes). It stores only a SHA-256 hash of the IP address, and deletes that record after about 10 minutes. It does not log your IP address.
  • Service logs record events such as “device removed” or “account deleted” with the account ID only. They do not contain your email address or your workout data. We keep service logs for 1 month.
  • Amazon Web Services hosts the account service and processes IP addresses to deliver requests.
§ 05

Optional advertising measurement

From version 1.1.2, FitSimp uses the Meta iOS SDK to help measure and improve advertising for FitSimp.

  • After onboarding, FitSimp asks permission through Apple’s App Tracking Transparency prompt before it starts Meta measurement. You can decline and continue using every app feature.
  • If you allow tracking, Meta receives device identifiers, including the advertising identifier where available, and basic device, app, and network information. Meta also receives app installation, activation, and session activity.
  • Meta may combine this information with information from its services and other sources for advertising measurement and personalization. Meta’s Privacy Policy explains how it uses this information.
  • We do not send workouts, exercise choices, weights, heart rate, HealthKit data, or workout notes to Meta. We also exclude account email addresses and FitSimp account IDs. This integration does not send purchase or subscription events.
  • Change your permission in iOS Settings → Privacy & Security → Tracking. If you revoke permission, FitSimp stops subsequent advertising measurement. This does not erase information that Meta already received.
  • Meta’s Privacy Policy explains its retention practices and privacy controls. The Apple Watch app, widgets, and Live Activities do not send Meta events.
§ 06

Apple HealthKit

HealthKit access is optional and controlled by you.

  • With your permission, FitSimp reads heart rate, active energy burned, and workout sessions from Apple Health, and writes completed workout sessions (including pause/resume events) back to Apple Health.
  • Heart rate is shown live during workouts and used to compute summary stats; active energy is used to display calorie totals; workout reads are used for the history view.
  • HealthKit data is exchanged only between the app and Apple Health on your device. It is never transmitted off-device by FitSimp.
  • You can review and revoke HealthKit permissions at any time in Settings → Health → Data Access & Devices → FitSimp.
§ 07

Camera, Photos, and Notifications

These permissions are requested only when you use the feature that needs them.

  • Camera: used to capture photos for individual exercises in your library. Photos are stored locally inside the FitSimp app container.
  • Photo Library (add-only): used when you save a workout summary image from FitSimp to your Photos library. FitSimp does not read your existing photo library.
  • Notifications: used for local workout reminders that you configure. Reminders are scheduled on-device via the iOS notification system; no push notification server is involved.
§ 08

Apple Watch companion

The optional FitSimpWatch app talks only to your paired iPhone.

  • Workout state (start/end, current exercise, timer) is exchanged between the iPhone and Apple Watch through Apple’s WatchConnectivity framework on your devices.
  • If you start a workout on Apple Watch, it can read heart rate locally through the watch’s HealthKit store. Nothing is sent to a FitSimp server.
§ 09

Subscriptions and payments

FitSimp Pro is a subscription handled entirely by Apple.

  • Apple processes subscription purchases and renewals through your Apple Account. FitSimp does not receive your payment card details. This release does not send subscription records to the FitSimp account service or Meta.
  • Subscription status is verified locally via Apple’s StoreKit framework. Product identifiers are `com.nombi_sioi.fitsimp.pro.monthly` and `com.nombi_sioi.fitsimp.pro.annual`.
  • You can manage or cancel your subscription at any time in Settings → Apple ID → Subscriptions.
§ 10

Diagnostics and crash reports

Diagnostics stay on your device until you decide to send them.

  • In TestFlight and debug builds, FitSimp subscribes to Apple’s MetricKit framework so that crash, hang, CPU, and disk-write diagnostics from the previous launch can be saved locally under Library/Caches/Diagnostics. App Store builds do not persist these payloads.
  • The optional Meta integration measures app installs and sessions as described above. FitSimp does not send its bug-report logs, workout data, or locally stored MetricKit reports to Meta.
  • If you opt in to share diagnostics with Apple at the iOS level, your device may include FitSimp in those reports under Apple’s privacy policy. This is controlled by iOS, not FitSimp.
  • When you tap “Report a Bug” inside FitSimp, the app prepares an email draft to support@nombi-sioi.com that includes app version metadata and, if available, a JSONL log file plus any locally stored MetricKit diagnostics as attachments. You choose whether to send it and you can remove any attachment first.
§ 11

Data we receive when you contact us

  • If you email support@nombi-sioi.com, we receive your email address and the contents of your message so we can reply.
  • We do not use that information for marketing and we do not share it with third parties.
§ 12

Sharing and disclosure

  • Amazon Web Services hosts our account service. Apple verifies your identity when you choose Sign in with Apple.
  • If you allow tracking, we share the device and app activity information described above with Meta for advertising measurement and personalization.
  • We do not share your training data with Meta. Your FitSimp account email address and account ID are not sent to Meta.
  • Any data you choose to export (CSV, screenshots, share sheets) is sent through the destinations you pick at that moment.
§ 13

Retention and deletion

  • To delete your account, open Profile → Account → Delete Account in the app. FitSimp revokes its stored Apple authorization and deletes the server account, email address, device records, and sessions. Your local workouts and Apple Health data remain on your devices.
  • Signing out revokes the sign-in tokens of that device.
  • Account deletion does not erase information already received by Meta. Use the tracking permission and Meta privacy controls described above to manage advertising measurement.
  • We keep an account while it is in use. We delete an account that no one has used for 24 months and that has no active FitSimp Pro subscription.
  • Delete the FitSimp app to remove all locally stored training data, exercise photos, logs, and diagnostics from that device. Deleting the app does not delete your account.
  • You can also wipe individual sections (logs, diagnostics, workout history) from inside Profile → Data Management without uninstalling.
  • Restoring an iCloud or device backup that includes FitSimp will restore the data captured in that backup. Workouts already written to Apple Health remain in Apple Health and must be removed there separately.
  • Because we do not store your training data on a server, we cannot recover it after a deletion.
§ 14

Children

  • FitSimp is not directed at children under 13. We do not knowingly collect data from children.

// your controls

You stay in charge of your data

FitSimp keeps your training data on your device, and the account is optional.

  • Use FitSimp without an account, or delete your account at any time in Profile → Account → Delete Account.
  • Revoke HealthKit, Camera, Photos, or Notification permissions any time in iOS Settings → FitSimp (or Settings → Health for HealthKit).
  • Allow or decline Meta measurement in Apple’s tracking prompt. Change your choice in iOS Settings → Privacy & Security → Tracking.
  • Manage or cancel your subscription in iOS Settings → Apple ID → Subscriptions.
  • Export your workouts as CSV, or your full library (with or without exercise photos) as a `.fitsimp.json` / `.fitsimp.zip` backup from Profile → Data Management.
  • Contact support@nombi-sioi.com with questions about your data or this policy.