🔒 Privacy

Privacy Policy

Effective: June 25, 2026Updated: June 25, 2026Version 2.0

Introduction

Shrey.Fit, a sole proprietorship operated by Shreyas Annapureddy ("Shrey.Fit," "we," "us," or "our"), based in the State of Washington, United States, respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our fitness coaching platform and website at shrey.fit (the "Service").

Please read this Privacy Policy carefully. By using our Service, you consent to the practices described in this policy.

1. Information We Collect

1.1 Information You Provide

Account Information:

  • Name, email address, phone number
  • Date of birth, gender
  • Password (stored only in hashed/encrypted form)

Profile Information:

  • Profile photo
  • Physical address
  • Emergency contact details
  • Medical notes and health information

Fitness Information:

  • Fitness goals and workout history
  • Progress measurements
  • Exercise performance data
  • Progress photos

Payment Information:

  • Payment details processed by our payment processor (we do not store full card numbers)
  • Billing information and purchase history

1.2 Information We Collect Automatically

  • Usage data (pages visited, features used)
  • Device information (IP address, browser, OS)
  • Login/security information (timestamps, approximate location from IP)
  • Cookies and similar technologies

2. How We Use Your Information

To Provide Our Service:

  • Create and manage your account
  • Process payments, subscriptions, and session packages
  • Deliver customized workout and nutrition programs
  • Track your progress and enable trainer communication
  • Provide customer support

To Improve Our Service:

  • Analyze usage patterns and diagnose issues
  • Develop new features and conduct internal analytics

To Communicate With You:

  • Send verification codes, account/billing notices, and reminders (transactional/service messages)
  • Provide customer support and security alerts
  • With your consent, send marketing communications you can opt out of anytime

4. How We Share Your Information

With Your Trainer

We share relevant information with your assigned trainer, including:

  • Name and contact information
  • Fitness goals and progress
  • Medical information you provide
  • Emergency contact details

Service Providers (Sub-Processors)

We share information with trusted third parties who process data on our behalf:

  • PayPal: payment processing
  • Google Firebase / Google Cloud: hosting, database, authentication, file storage
  • Resend: transactional and notification email delivery
  • Google Maps Platform: address autocomplete
  • Google reCAPTCHA: bot/abuse prevention at signup
  • Google Analytics: usage analytics (aggregated/pseudonymized)

✓ We do NOT sell your personal information, and we do NOT "share" it for cross-context behavioral advertising.

5. Your Privacy Rights

Right to Access

Request a copy of your personal data and review what information we have.

Right to Data Portability

Download your data in JSON format using the "Download My Data" feature in your profile.

Right to Erasure ("Right to be Forgotten")

Request deletion of your personal data using the "Delete Account" feature. We delete personal data within 30 days, except financial/transaction records retained for legal compliance.

Right to Object

Object to processing for marketing purposes. Opt out of marketing communications anytime. To exercise any right, contact privacy@shrey.fit.

6. Data Retention

Active Accounts

We retain your data while your account is active (profile, workouts, messages, etc.).

After Account Deletion

  • Personal data: deleted within 30 days
  • Financial/transaction records: retained as required by law (generally up to 7 years)
  • Aggregated/anonymized data: may be retained indefinitely
  • Backups: purged within ~90 days

7. Data Security

We implement industry-standard security measures:

  • Encryption: TLS in transit, encryption at rest
  • Authentication: secure Firebase Authentication with password hashing
  • Access Controls: least-privilege permissions
  • Breach notification: we notify affected users and authorities as required by law (e.g., within 72 hours under the GDPR)

Important: No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

Privacy Rights by Region

European Union / UK (GDPR)

If you are in the EU/EEA/UK, you have rights under the GDPR including:

  • Right to Access (Article 15)
  • Right to Rectification (Article 16)
  • Right to Erasure (Article 17)
  • Right to Data Portability (Article 20)

California (CCPA/CPRA)

California residents have additional rights:

  • Right to Know what personal information is collected
  • Right to Delete and Correct your personal information
  • Right to Opt-Out of sale/sharing (we do not sell or share)
  • Right to Non-Discrimination

Contact Us

For privacy-related questions or to exercise your rights:

Summary

What We Collect:

  • ✓ Account and profile information
  • ✓ Fitness and health data
  • ✓ Usage and device information
  • ✓ Payment info (via PayPal)

Your Rights:

  • ✓ Access your data
  • ✓ Download your data (JSON)
  • ✓ Delete your data
  • ✓ Opt out of marketing

Security:

  • ✓ Industry-standard encryption
  • ✓ Secure Firebase infrastructure
  • ✓ Access controls
  • ✓ Breach notification

We Do NOT:

  • ✗ Sell your information
  • ✗ Share for behavioral ads
  • ✗ Use for unrelated purposes
  • ✗ Store full card numbers

Last Updated: June 25, 2026

Version: 2.0

Terms of Service | Back to Home