← Back to sign up

Privacy Policy

Last updated July 24, 2026

This Privacy Policy explains how Parsa Bolourinejad ("MisFIT," "we," "us") collects, uses, stores, and protects information when you use the MisFIT Tracker web app and any related mobile apps (the "Service"). MisFIT stores health and fitness data, including body weight and workout history, and we treat this information as sensitive.

1. Information We Collect

Account information

  • Email address and password (via Supabase Auth)
  • Display name, unit preference (metric/imperial), and gender (if you choose to provide it)

Health & fitness data

  • Body weight (if you choose to log it)
  • Height, date of birth, and gender — collected only if you enter them, and used solely to estimate calories burned during workouts
  • Estimated calories burned, derived from the above and stored alongside each completed workout
  • Workout sessions: start/finish times, names, notes
  • Exercises performed and their position/order within a workout
  • Individual set data: reps, weight, duration, distance, RPE (perceived exertion), and set completion timestamps that you log
  • Routines and routine folders you create or save

Push notifications

If you enable push notifications, we store a device push token, your timezone, and your notification preferences (types, days, and times you want to receive notifications). We also log when a notification was sent and, if you tap it, that it was opened. You can withdraw this permission at any time through your device or browser settings.

Feedback

If you submit feedback through the app, we store the message text, the page you were on when you submitted it, and basic device context (browser, OS, screen size).

Usage & device data

  • Basic usage analytics via PostHog and Vercel Analytics (pages viewed, feature interactions, general performance data)
  • Standard technical data such as browser type and IP address, for security and debugging

2. How We Use Your Data

  • To provide core features: logging workouts, tracking streaks, and generating your progress charts
  • To estimate calories burned during workouts using height, date of birth, gender, and body weight — this calculation happens on our servers and the result is stored on your account
  • To send push notifications if you have opted in, and to log delivery and open events
  • To respond to feedback you submit through the app
  • To maintain your account and authenticate you securely
  • To process payments for Premium subscriptions via ZarinPal
  • To maintain and improve the reliability and security of the Service
  • To communicate with you about your account or material changes to our policies

We do not sell your personal or health data, and we do not use your workout, body-weight, or biometric data for third-party advertising.

3. How We Store & Protect Your Data

Your data is stored in a Supabase-managed PostgreSQL database and protected by Row Level Security (RLS) policies, meaning your workout and account records are only accessible to you and to systems acting on your behalf. Access to production data by MisFIT personnel is limited to what is necessary for support and maintenance.

Your data is stored on servers located in Ireland (EU West), operated by Supabase. By using MisFIT, you consent to your personal and health data being transferred to and processed in Ireland. Supabase maintains appropriate technical and organizational safeguards for data it processes on our behalf.

4. Who We Share Data With

We share data only with service providers that help us run MisFIT, specifically:

  • Supabase: database, authentication
  • Vercel: hosting and basic product analytics
  • PostHog: product analytics (feature usage, event tracking)
  • ZarinPal: payment processing for subscriptions

We do not share your health or fitness data with advertisers, data brokers, or any party for marketing purposes. We may disclose information if required by law or to protect the rights, safety, or property of MisFIT or our users.

5. Data Retention

We retain your account and workout data for as long as your account is active. If you delete your account, we will delete or anonymize your personal and health data within a reasonable period, except where we are required to retain limited records for legal, security, or billing purposes (for example, transaction records related to a completed payment).

6. Your Rights

You can, at any time:

  • Access the personal and health data we hold about you
  • Correct inaccurate information directly from your profile settings
  • Request export of your workout history
  • Request deletion of your account and associated data
  • Withdraw push notification consent through your device or browser settings

To exercise any of these rights, use the in-app settings where available, or contact us at support@joinmisfit.org. We will respond within a reasonable timeframe.

7. Children's Privacy

MisFIT is not directed at children under 16, and we do not knowingly collect data from anyone under that age. If you believe a child has provided us with personal data, contact us so we can remove it.

8. Cookies & Analytics

We use minimal analytics (PostHog and Vercel Analytics) to understand how the Service is used and to improve performance. We do not use third-party advertising cookies or cross-site trackers.

9. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the Service or by email before they take effect.

10. Contact

Questions about this Privacy Policy or how your data is handled can be sent to support@joinmisfit.org.