How is my data kept secure?

App data is stored in Frankfurt (EU), access is restricted in the database itself, and card details only ever go to Stripe.

Privacy & data2 min read

Where it is stored. Your account, content, photos and messages are stored with Supabase in the European Union, encrypted at rest and in transit.

Who can read it. Access is restricted in the database itself, so one person's data cannot be read from another account. A coach sees only the athletes they coach, and athlete profiles are never public. Body progress and meal photos sit in a private area and are shown through short-lived links, not public addresses.

Payments. Card details go straight to Stripe. Fitiva never sees or stores them; we only receive a reference and the result.

Your sign-in. You can turn on two-factor authentication in Settings, Account & security (see How do I turn on two-factor authentication?). Changing your email or your password asks for your current password.

As little as possible. Your exact device location is used only when you ask for it in Find a coach, and it is not stored. Abuse checks count requests with a keyed hash instead of storing your IP address.

AI. The AI features send only what the feature needs to Anthropic, which does not train its models on it (see What does the AI (Ava) see about me?).

We never sell your data. All details are in the Privacy Policy, linked in Settings under Privacy & data.

Looking for something else?