Skip to content
skip to content

privacy policy

last updated: may 21, 2026

introduction

scalefit lda. ("scalefit", "we", "us") is the data controller for personal information you provide while using the scalefit web and mobile applications. we are committed to processing your data lawfully, transparently, and only for the purposes described in this policy.

this policy is written to comply with the eu general data protection regulation (gdpr), the portuguese data protection law (lei n.º 58/2019), the uk gdpr, the brazilian lgpd, and the california consumer privacy act (ccpa/cpra). if you have questions about how it applies to you, contact our data protection officer at privacy@scalefit.app.

by using scalefit, you confirm you have read and understood this policy. you do not waive any statutory rights by accepting it.

data collection

we collect three categories of data:

  • account data you provide: name, email address, phone number, hashed password, profile photo, date of birth, and role (athlete, coach, or brand admin)
  • health and fitness data: body weight, body measurements, training history, workout logs, nutrition entries, progress photos, and check-in submissions
  • wearable and integration data: steps, heart rate, sleep, and workout sessions imported from apple health, health connect, fitbit, whoop, and oura when you connect them
  • payment data: billing address and the last four digits of payment cards. full card details are tokenized by stripe and never reach our servers
  • communications: messages exchanged with coaches and support staff via in-app chat
  • device and usage data collected automatically: ip address, device type, operating system, browser, app version, pages visited, and timestamps

legal bases for processing under article 6 gdpr are: performance of a contract (to provide the service), legitimate interests (to secure the platform and improve features), legal obligation (tax and accounting records), and your explicit consent for sensitive health data under article 9.

we keep account and health data for as long as your account is active — coaching can run for more than a year, and your before and after photos are part of it. when you delete your account, or ask us to delete your data, identifiable data is removed within 30 days and any backups containing it are deleted within 90 days of that request. anonymised aggregates may be kept for analysis. financial records are kept for 10 years as required by portuguese tax law.

user rights (gdpr)

as a data subject, you have the following rights regarding the personal data we hold about you:

  • right of access (art. 15): obtain a copy of the personal data we process about you
  • right to rectification (art. 16): ask us to correct inaccurate or incomplete data
  • right to erasure (art. 17): request deletion of your data, also known as the right to be forgotten
  • right to restriction of processing (art. 18): pause our processing while a request is reviewed
  • right to data portability (art. 20): receive your data in a structured, machine-readable format and transfer it to another controller
  • right to object (art. 21): object to processing based on legitimate interests, including direct marketing
  • right to withdraw consent (art. 7): withdraw consent for processing that relies on it, without affecting prior lawful processing
  • right to lodge a complaint with the portuguese data protection authority (cnpd) or your local supervisory authority

to exercise any right, email privacy@scalefit.app or use the in-app "export data" and "delete account" tools under settings. we respond within 30 days, extendable by a further 60 days for complex requests, and we will explain any delay.

data sharing

we do not sell your personal data. we share limited data with carefully selected processors who help us operate the service, each bound by a data processing agreement under article 28 gdpr:

  • hetzner online gmbh (germany): hosting of databases and application servers within the eu
  • cloudflare, inc.: cdn, ddos protection, and edge caching with eu data residency
  • stripe payments europe, ltd. (ireland): payment processing and subscription billing
  • expo (united states): push notification delivery to ios and android devices
  • sentry (united states): aggregated error reports and performance traces with pii scrubbing enabled
  • google gemini api (united states/eu): ai-assisted coaching prompts using anonymized fitness data only

transfers outside the european economic area rely on the european commission's standard contractual clauses (scc 2021/914) and the eu-us data privacy framework where applicable. coaches you choose to work with see only the data you share with them inside the platform.

we may disclose data when required by law, valid legal process, or to protect the rights, property, or safety of scalefit, our users, or the public.

security

we apply layered technical and organizational measures to protect your data:

  • tls 1.3 encryption for all data in transit between clients, servers, and processors
  • aes-256 encryption at rest for postgresql databases and s3-compatible object storage
  • passwords hashed with argon2id and per-user salts; api tokens stored in platform keychains
  • principle of least privilege for staff access, with audit logging of all administrative actions
  • continuous vulnerability scanning, quarterly third-party penetration testing, and an active bug bounty program
  • documented incident response process with notification to affected users and supervisory authorities within 72 hours of a confirmed personal data breach

no system is ever fully secure. if you suspect your account has been compromised, contact security@scalefit.app immediately.

contact

reach our data protection team for any privacy-related question or request: