Privacy Policy

How we handle your data.

Last updated: April 27, 2026 · Effective immediately
The short version Your training data is yours. We never sell it, never train external models on your conversations, and you can delete everything with one click. The detail below explains exactly what we collect, why, and your rights.
Contents
  1. Who we are
  2. What we collect
  3. How we use it
  4. Who we share with
  5. International transfers
  6. How long we keep it
  7. Security
  8. Your rights
  9. California residents
  10. EU/UK residents (GDPR)
  11. Children
  12. Cookies
  13. Changes to this policy
  14. Contact

1.Who we are

This Privacy Policy describes how PHITER.ai ("PHITER," "we," "us," or "our") collects, uses, and shares personal information when you use our website at phiter.ai, our application at test.phiter.ai, and any related services (collectively, the "Service").

For privacy questions or to exercise your rights, contact us at privacy@phiter.ai.

2.What we collect

Account information

When you sign up, we collect your email address and a password (stored as a salted hash — we never see your plaintext password). You may optionally provide a display name.

Profile and health data

To deliver personalized coaching, you may provide:

This data is sensitive. You provide it voluntarily and can delete it any time.

Training and nutrition data

Conversations with Phit

Your chat messages with Phit are stored to provide continuity (Phit remembers your training history). We extract short factual snippets (e.g., "user's bench PR is 225lb," "user has knee injury") into a structured memory store to improve coaching over time.

Payment information

We use Stripe to process subscriptions. We never see or store your credit card number. We retain limited metadata (subscription status, plan, billing dates).

Technical data

3.How we use it

We do not sell your personal information. We do not use your conversations to train third-party AI models.

4.Who we share with

We share data only with vendors that help us run the Service. Each is bound by contractual confidentiality and security obligations.

VendorPurposeData shared
AnthropicPowers Phit AI coachYour chat messages (per request)
Google (Gemini)Food & video form analysisPhotos / videos you submit
SupabaseDatabase, authenticationAll account & training data
StripeSubscription billingEmail, payment metadata
VercelWeb hosting, edge computeTechnical request data

We may also share information when legally required (subpoena, court order), to protect rights or safety, or in connection with a corporate transaction (merger, acquisition) — with notice to affected users.

5.International transfers

PHITER's primary infrastructure is located in the United States. If you access the Service from the European Union, United Kingdom, or other jurisdictions outside the U.S., your data is transferred to and processed in the U.S.

For EU/UK transfers we rely on Standard Contractual Clauses (SCCs) approved by the European Commission as the legal basis for transfer.

6.How long we keep it

7.Security

We protect your data using:

No system is perfectly secure. If we detect a breach affecting your data, we will notify you and the appropriate regulators within the timeframes required by applicable law.

8.Your rights

Regardless of where you live, you can:

Most rights can be exercised directly in the app (Settings → Privacy → Delete account / Export data). For anything else, email privacy@phiter.ai. We will respond within 30 days.

9.California residents (CCPA / CPRA)

If you are a California resident, you have the additional rights under the California Consumer Privacy Act:

To exercise these rights, email privacy@phiter.ai with subject line "California Privacy Request."

10.EU / UK residents (GDPR)

The legal bases on which we process your personal data:

You have the right to lodge a complaint with your local data protection authority. We do not have an EU representative at this time; for now, please contact privacy@phiter.ai directly.

11.Children

The Service is not directed at children under 16, and we do not knowingly collect personal information from anyone under 16. If we discover that we have collected information from a child under 16, we will delete it promptly. If you believe a child has provided us with personal information, contact privacy@phiter.ai.

12.Cookies

We use cookies and similar technologies for:

We do not use third-party advertising cookies. You can disable non-essential cookies via your browser settings.

13.Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and/or by a prominent notice in the app at least 14 days before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.

14.Contact

For privacy questions, requests, or complaints: