Fitlyze (Beta) Version: 2.0 Effective date (last updated): July 7, 2026 Last reviewed: July 7, 2026 Applies to: European Union/EEA · Switzerland · Canada · United States
This Privacy Policy explains how DerMo Technologies Inc. (d/b/a Fitlyze), a corporation based in Toronto, Canada and operating as Fitlyze ("Fitlyze", "we", "us", "our"), collects, uses, shares, and protects your personal information when you use our website and Progressive Web App and related services (the "Service").
Fitlyze is a general fitness and wellness app. You can log activities, food, and body measurements, and use an AI assistant — by text, photo, or voice — to get general workout and nutrition suggestions. The Service is offered in the European Union/EEA, Switzerland, Canada, and the United States, and is currently a free beta. Fitlyze is not a medical device and does not provide medical advice, diagnosis, or treatment (see Sections 17 and 18).
In short. We collect the information you give us (including health and fitness data) and some usage data, and we use it to run the Service and power the AI assistant. We never sell your personal information. Health and fitness data is processed only with your consent. We host the Service in Canada and use a small set of service providers (our AI provider, AI observability, AI web search, hosting, email, sign-in, and analytics). We do not use your conversations to train AI models. You can access, correct, export, or delete your data at any time by emailing privacy@fitlyze.app. This summary is for convenience only — the full policy below governs.
Key terms. Controller — the organization that decides why and how your data is processed (here, DerMo Technologies Inc.). Processor — a company that processes data on the controller's instructions (e.g., our service providers). Personal data / personal information — information that identifies or relates to you. Sensitive / special-category data — protected categories such as health and biometric data (here, your fitness and health data). De-identified data — data stripped of identifiers so it no longer reasonably identifies you. Aggregated / anonymous data — combined or statistical data that identifies no individual. Sale / Sharing — as defined under applicable US state privacy laws (we do neither).
Contents
- Who we are
- The Service and beta status
- Information we collect
- How we record your consent
- Sensitive information
- How we use your information
- Marketing and communications
- How we share your information
- International data transfers
- Data retention
- Security
- Your privacy rights (everyone)
- European Economic Area and Switzerland
- Canadian residents (PIPEDA & Québec Law 25)
- United States residents
- Children's privacy
- AI and automated decisions
- Not a medical device; not medical advice
- Data breach notification
- Cookies and tracking technologies
- Accessibility
- Languages
- Changes to this Policy
- Contact
1. Who we are
The controller responsible for your personal information is:
DerMo Technologies Inc. (d/b/a Fitlyze) 2300 Yonge Street, Suite 1600, Toronto, ON M4P 1E4, Canada Privacy contact: privacy@fitlyze.app
Privacy Officer. Our Privacy Officer is accountable for our compliance with applicable privacy laws and can be reached at privacy@fitlyze.app. For Québec residents, the same individual is our designated Person in Charge of the Protection of Personal Information under Law 25.
European Union and Switzerland. If you are in the EU or Switzerland, you can contact us about your data at privacy@fitlyze.app.
Regulatory status. Fitlyze is not a regulated healthcare provider, a "health information custodian" under Ontario's PHIPA, or a HIPAA-covered entity. We are a consumer software company subject to Canada's PIPEDA, Québec's Law 25, the EU GDPR, the Swiss Federal Act on Data Protection (FADP), and applicable US state privacy and consumer-health-data laws.
2. The Service and beta status
The Service is provided as a website and an installable Progressive Web App (PWA), used through a browser on desktop and mobile (web, Android, and iOS devices). It is currently a free beta. We do not offer paid subscriptions and we do not collect or process payment-card information. Because this is a beta, features and safeguards are evolving, and we may review usage more closely than we would at general availability while we mature the product (see Section 6).
3. Information we collect
Information you provide
- Account & identity: email address (which serves as your username and sign-in identifier ), password (stored only as a one-way hash), first and last name, date of birth (used to confirm you are 18+ and to tailor age-appropriate suggestions), sex/gender, time zone, unit preference, an optional profile photo, and account timestamps. Profile photos are stored solely as your account image and are not used for facial recognition or biometric identification.
- Sign in with Google (optional): if you choose it, Google shares your email address and Google account identifier with us so we can create or link your account.
- Sign in with Apple (optional): if you choose it, Apple shares your name and email address with us; if you use Apple's "Hide My Email" feature, Apple provides a private relay email address that forwards to you instead of your real address.
- Body & health measurements: height, weight, body-fat percentage, waist/chest/hip measurements, resting heart rate, calories burned, body-weight snapshots, and any free-text notes you add.
- Food & nutrition: foods and meals you create or log, quantities, water intake, nutrition plans (calorie and macro targets), photos of food and nutrition labels, and free-text notes.
- Activity & fitness: activities, workout plans, exercises (sets, reps, weights), and durations.
- AI assistant: your chat messages (free text), photos you attach (such as meals and nutrition labels), voice input you record (which is transcribed), conversation titles, and any example prompts you save.
- Communications: support messages and survey responses you send us.
Information collected automatically
- Consent & acceptance records: when you accept our documents (Section 4), we record your IP address, browser/device (user-agent), app version, platform (web/Android/iOS), and the date and time.
- Security & abuse-prevention data: we log events such as sign-in attempts, IP addresses, and security-relevant actions for account security, fraud prevention, and abuse detection.
- Usage & device data: through our analytics provider, we collect information such as device and browser type, pages and screens viewed, interactions, and diagnostic data. Analytics data is used primarily in aggregate, to understand performance and feature usage rather than to identify you individually (see Section 20).
- Approximate location: derived from your IP address only. We do not collect precise or GPS location.
About the AI assistant. To answer you, we send your message — together with relevant profile context — to our AI provider for processing, along with any photo or voice input you provide. When the assistant needs current information from the web, it may also send a search query — generated from your request, and never including your name, email, or account identifiers — to our web-search provider (Tavily, United States; see our Sub-processor & Service Provider List, available in the References section of the User Agreements page, both during sign-up and at any time afterward). We store your conversation history so the assistant can keep continuity and context within a conversation. Please don't share information in the chat that you wouldn't want processed by an AI service, such as government IDs, financial documents, or other people's personal or medical information.
Why we use your key data
| Data | Purpose |
|---|---|
| Height | Workout and exercise personalization |
| Weight | Calorie and energy estimates |
| Sex/gender | Account for physiological differences in suggestions |
| Age (from date of birth) | 18+ verification and age-appropriate suggestions |
| Activity & fitness history | Improve workout recommendations |
| Goals | Tailor workout and nutrition suggestions |
We follow the principles of purpose limitation and data minimization: we collect this information to provide the features above, and not for unrelated purposes.
4. How we record your consent
When you create an account, you must agree to our Terms of Service, Beta Testing Agreement, and Health & AI Disclaimer. Also acknowledge that you have read this Privacy Policy . Separately, you give an explicit, opt-in consent to the processing of your health and fitness data under our Consumer Health Data Privacy Policy (Health Data Policy). Analytics and marketing consents are separate, optional, and never required to use the Service. To demonstrate your acceptance and consent, we record your IP address, browser/device, the version of each document you accepted, your platform, and the date and time. We keep these records for as long as needed to evidence your consent and to comply with our legal obligations.
5. Sensitive information
Much of what you provide is sensitive / special-category information under the GDPR (Article 9), the Swiss FADP, Québec Law 25, and US state laws — in particular your health, fitness, body-measurement, and dietary data, and anything health-related you put into the AI assistant.
We process this information on the basis of your explicit consent, which you give through a separate opt-in at sign-up and by choosing to enter the information after we explain, in the app, what is collected and why — so you can make an informed decision before sensitive data is collected. Marketing consent and analytics/cookie consent are separate and optional — they are never required to use the core Service. You can withdraw consent at any time (Section 12); for sensitive data this generally means deleting your account, as granular per-field withdrawal is not currently supported.
6. How we use your information
- Provide the Service — create and manage your account, generate AI workout and nutrition suggestions, and power logging and tracking.
- Operate, secure, and improve the Service — debugging, account security, fraud prevention, and abuse detection.
- Review AI conversations for safety and quality — during the beta, a limited number of authorized employees who are subject to confidentiality obligations (and, under contract, authorized providers) may review selected conversations solely for debugging, quality assurance, safety, and service improvement. We use an AI observability tool (LangSmith, hosted in the European Union - see our Sub-processor & Service Provider List) to record traces of AI assistant interactions for this purpose. Access is restricted and logged.
- Improve our product — we do not use your conversations to train AI models, neither our own nor our AI provider's, and our AI provider does not use our API data to train its models. We may use de-identified or aggregated data to improve our prompts and the Service.
- Communicate with you — see Section 7.
- Comply with legal obligations, and enforce our Terms and protect rights, property, and safety.
7. Marketing and communications
Transactional and security messages — such as account confirmation, password resets, legal-document updates, and safety notices — are necessary to operate your account and are not optional.
Marketing emails are optional and are sent only with your express prior consent (we never pre-tick consent boxes), consistent with Canada's Anti-Spam Legislation (CASL) and applicable EU and Swiss rules. Every marketing email identifies us as the sender and includes a one-click unsubscribe link that does not require you to log in. We honor unsubscribe requests without delay (within 10 business days at the latest) and at no cost. You can also withdraw consent any time by emailing privacy@fitlyze.app (subject: "Marketing Unsubscribe"). Withdrawing marketing consent does not affect transactional or security messages.
8. How we share your information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising (as those terms are defined under US state laws). We share information only with the following categories of recipients, under contracts that restrict their use of your information to providing services to us:
- Processors acting on our instructions — our AI provider, our AI observability provider, our AI web-search provider, our email-delivery provider, our product-analytics provider, and our cloud-hosting provider. None of them may use your data for its own purposes, and none of them trains AI models on your data.
- Optional sign-in providers (independent controllers) — if you choose "Sign in with Google" or "Sign in with Apple," Google or Apple processes your sign-in under its own privacy policy.
The identity of each current provider — including its role, the personal data involved, its location, and the applicable safeguards — is published in our Sub-processor & Service Provider List, which forms part of this Section. We update that list before adding or replacing a provider that handles your personal data, and we give notice of material changes by in-app notice or email.
Other disclosures.
- Legal and safety: where we believe in good faith it is necessary to comply with law, a court order, or a government request; to enforce our Terms; to address fraud, security, or technical issues; or to protect the rights, property, or safety of Fitlyze, our users, or others. Where legally permitted, we will seek to limit the scope of, and challenge, requests we consider unlawful or overly broad.
- Business transfers: in a merger, acquisition, financing, reorganization, or sale of assets, your information may be transferred as part of that transaction, subject to this Policy or equivalent protections; we will notify you of any change of ownership.
- With your consent: for other purposes you agree to.
9. International data transfers
We are based in Canada and host the Service entirely in Canada (Toronto) — our servers, database, load balancer, and object storage are all located in Canada. Regardless of where you live, your personal data is stored and processed primarily in Canada. A small number of service providers process limited data elsewhere: our analytics, email-delivery, and AI observability providers in the European Union, and our AI provider, our AI web-search provider, and the optional sign-in providers (Google and Apple) in the United States. The current providers and their locations are listed in our Sub-processor & Service Provider List.
Where this involves a cross-border transfer of your personal data, we use appropriate safeguards:
- To Canada. The European Union and Switzerland recognize Canada as providing an adequate level of protection for personal data transferred to organizations subject to PIPEDA. Transfers of your data to Canada therefore rely on those adequacy decisions. Where adequacy does not apply, we use Standard Contractual Clauses (SCCs).
- To the United States — our processors (our AI provider and our AI web-search provider). We rely on the EU Standard Contractual Clauses — together with the Swiss addendum, as applicable — and the EU–US and Swiss–US Data Privacy Framework where a recipient is certified, supported by a transfer risk assessment.
- To the United States — the optional sign-in providers (Google and Apple). These act as independent controllers, not as our processors. If you choose to sign in with them, you initiate that transfer and it takes place under the provider's own privacy policy; we do not, and cannot, conclude Standard Contractual Clauses with them for sign-in. Both are certified under the EU–US and Swiss–US Data Privacy Framework.
- Within the European Union/EEA (our analytics, email-delivery, and AI observability providers). These providers host your data in the EU/EEA, where the GDPR applies directly, so no additional transfer tool is needed for EU/EEA users. Where a provider's US parent company could access the data — for example, for support or operations — that access is treated as a transfer to the United States and is covered by Standard Contractual Clauses. For users outside the EU/EEA, these are transfers to a jurisdiction with strong data-protection law; Switzerland recognizes the EU/EEA as providing adequate protection.
Wherever your personal data is processed in another country, it may become subject to lawful access requests by that country's courts, law enforcement, and national-security authorities under that country's laws. We assess this risk before transferring and apply contractual and technical safeguards — including Standard Contractual Clauses and encryption — to protect your data.
For transfers of Québec residents' personal data outside Québec, we conduct a Privacy Impact Assessment as required under Law 25. You can request a copy of the relevant safeguards by emailing privacy@fitlyze.app.
10. Data retention
We keep personal information only as long as necessary for the purposes in this Policy, then delete or de-identify it.
- Account, profile, logs, and measurements: while your account is active. When you delete your account, we delete or de-identify this information from our active systems — including your conversation history and uploaded images — within 30 days, except where a longer period is required by law.
- AI conversation history: retained to give the assistant continuity and context within your conversations (so it remembers what you discussed) until you delete the conversation or your account. Our AI provider retains the data it processes only for a short period (about 7 days by default) for safety and abuse-prevention purposes, then deletes it. Traces recorded by our AI observability provider (hosted in the European Union) expire automatically after a short period (14 days by default).
- Consent and acceptance records (Section 4): retained for as long as needed to evidence your consent and meet legal obligations.
- Backups: encrypted backups roll off on an approximately 30–90 day cycle. Deleted information may persist in backups until the backup rotation completes, after which it is overwritten.
- De-identified or aggregated data: may be retained indefinitely.
11. Security
We use technical and organizational measures appropriate to the risk to protect your information, including:
- Encryption of data in transit using TLS;
- Strong one-way hashing of passwords (your password is never stored or transmitted in readable form);
- Access controls and authentication limiting who can reach personal data; and
- Private storage of uploaded images, served only through signed links that expire.
Because Fitlyze is a beta, we are actively strengthening our safeguards as the product matures. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Please keep your password confidential, and contact privacy@fitlyze.app immediately if you believe your account has been compromised.
12. Your privacy rights (everyone)
Subject to applicable law and verification of your identity, you can:
- Access the personal information we hold about you;
- Correct inaccurate information;
- Delete your account and associated personal information (subject to legal retention exceptions);
- Export your data (data portability); and
- Withdraw consent where processing is based on consent.
To exercise a right, email privacy@fitlyze.app (subject: "Privacy Request"). We respond within the time required by law — generally one month in the EU/EEA and Switzerland and 30 days in Canada (extendable for complex requests), and 45 days for most US states (extendable by a further 45). We will not discriminate against you for exercising your rights.
Rights at a glance
| Right | EU/EEA & Switzerland | Canada (incl. Québec) | US (state laws) |
|---|---|---|---|
| Access / know | Yes | Yes | Yes |
| Correct | Yes | Yes | Yes |
| Delete | Yes | Yes | Yes |
| Export / portability | Yes | Yes (Québec; on request under PIPEDA) | Yes |
| Withdraw consent | Yes | Yes | Yes |
| Restrict / object to processing | Yes | Marketing (CASL) | Opt-out |
| Opt out of sale / sharing / targeted ads | We do none | We do none | Yes |
| Limit use of sensitive data | Via consent | Via consent | Yes (California) |
| Info on automated decisions | Yes | Yes (Québec) | Yes (some states) |
| Complain to a regulator | Yes (local DPA / FDPIC) | Yes (OPC / CAI) | Yes (state AG / CPPA) |
Region-specific details and complaint routes are in Sections 13–15.
13. European Economic Area and Switzerland
If you are in the EU/EEA or Switzerland, the EU GDPR and the Swiss Federal Act on Data Protection (FADP) respectively give you the rights and protections described here.
Legal bases
| Purpose | Legal basis |
|---|---|
| Create/manage your account; provide the core Service | Performance of a contract (Art. 6(1)(b)) |
| Process your health, fitness, body, and dietary data, including sending it to our AI provider | Explicit consent (Art. 9(2)(a)), with contract (Art. 6(1)(b)) |
| Security, fraud/abuse prevention, debugging, defending legal claims | Legitimate interests (Art. 6(1)(f)) |
| Analytics and cookies | Consent (Art. 6(1)(a)) |
| Marketing email | Consent (Art. 6(1)(a)) |
| Comply with legal obligations | Legal obligation (Art. 6(1)(c)) |
Your rights
In addition to the rights in Section 12, you have the right to restrict processing (Art. 18), to object to processing based on legitimate interests and, absolutely, to object to direct marketing (Art. 21), rights regarding automated decision-making (Art. 22), and the right to lodge a complaint with a supervisory authority (Art. 77) — in the EU/EEA, your local authority or, given our EU establishment in Italy, the Garante per la protezione dei dati personali; and in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC). Withdrawing consent does not affect processing carried out before withdrawal.
International transfers
Your data is hosted in Canada, which the EU and Switzerland recognize as providing adequate protection. Transfers to our US processors (AI and AI web search) are protected by Standard Contractual Clauses with the applicable Swiss addendum. The optional sign-in providers (Google and Apple) act as independent controllers under their own privacy policies and are certified under the Data Privacy Framework, as described in Section 9. You can request a copy of these safeguards at privacy@fitlyze.app.
14. Canadian residents (PIPEDA & Québec Law 25)
You have the rights in Section 12, and you may file a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca).
Meaningful consent. Before we collect sensitive information such as health-related fitness data, we explain why it is collected and how it will be used, so you can make an informed decision.
Québec (Law 25). In addition, you have the right to data portability, the right to be informed of automated decision-making based exclusively on automated processing and to submit observations, and the right to file a complaint with the Commission d'accès à l'information du Québec (cai.gouv.qc.ca). Our designated Person in Charge is reachable at privacy@fitlyze.app. We use privacy-protective default settings, we evaluate privacy risks before introducing new features that involve sensitive personal information, and we conduct Privacy Impact Assessments before transferring Québec residents' data outside Québec.
15. United States residents
Do Not Sell or Share My Personal Information
Fitlyze (DerMo Technologies Inc.) does not sell your personal information, and does not share it for cross-context behavioral advertising — as "sell" and "share" are defined under the California CPRA and other US state privacy laws. We also do not sell consumer health data under Washington's My Health My Data Act, Nevada's SB 370, or Connecticut law.
Because we do not sell or share your personal information, there is nothing for you to opt out of in that respect. This has always been our practice.
We also:
- Honor the Global Privacy Control (GPC) browser signal as a valid opt-out preference.
- Use analytics only if you opt in (off by default), and use no advertising or third-party marketing cookies.
- Never use your data to train AI models.
Your rights. Depending on where you live, you can access, correct, delete, or obtain a copy of your personal information, withdraw consent, and limit the use of sensitive data. To exercise any right, email privacy@fitlyze.app. For health and fitness data specifically, see our Health Data Policy.
DerMo Technologies Inc. (d/b/a Fitlyze), 2300 Yonge Street, Suite 1600, Toronto, ON M4P 1E4, Canada.
Your rights (California and other states)
If you live in California (CCPA/CPRA) or another state with a comprehensive privacy law (such as Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and others), you may, subject to verification: know/access, delete, correct, obtain a portable copy, opt out of any sale, sharing, targeted advertising, or certain profiling, and limit the use and disclosure of sensitive personal information to what is necessary to provide the Service. We use sensitive personal information only to provide the services you request, and not to infer characteristics unrelated to the Service.
Authorized agents. You may use an authorized agent to submit a request by giving them signed, written permission to act on your behalf; we may still ask you to verify your identity directly and to confirm the agent's authorization. If we deny a request, you may appeal by emailing privacy@fitlyze.app (subject: "Privacy Appeal"); if your appeal is denied, you may contact your state Attorney General. California residents may also contact the California Privacy Protection Agency.
Consumer health data (Washington, Nevada, Connecticut and similar)
Information such as your weight, height, sex, age, body measurements, dietary logs, and health-related inputs to the AI may be "consumer health data." We collect it only with your consent and only to provide and improve the Service as described here; we do not sell consumer health data; and you may withdraw consent and request deletion at privacy@fitlyze.app. If you are a Washington resident, please also see our separate Health Data Policy.
16. Children's privacy
The Service is intended only for people aged 18 and over. We do not knowingly collect personal information from anyone under 18, and our sign-up flow blocks registration where the date of birth indicates the person is under 18. If we learn we have collected information from someone under 18, we will delete it. Contact privacy@fitlyze.app if you believe this has happened.
17. AI and automated decisions
You are interacting with an AI assistant. It generates general workout and nutrition suggestions based on what you provide. These are suggestions for your consideration, not binding decisions, and they do not produce legal or similarly significant effects. Fitlyze does not carry out automated decision-making or profiling that produces legal or similarly significant effects within the meaning of Article 22 GDPR, and we do not use AI to make eligibility, pricing, or other significant automated decisions about you. You are free to disregard the suggestions, and you remain responsible for any decisions you make based on AI-generated content; we encourage you to consult a qualified professional before acting on them. EU/EEA, Swiss, and Québec residents may request further information about how the AI features generate suggestions at privacy@fitlyze.app.
18. Not a medical device; not medical advice
Fitlyze is a general wellness and fitness tool. It is not a medical device, and its content (including AI outputs) is not medical advice, diagnosis, or treatment and is not a substitute for a qualified professional. AI-generated content may be incomplete, inaccurate, outdated, or inappropriate for your individual circumstances. The AI assistant is configured to decline medical requests — such as diagnosing conditions, interpreting medical tests, managing diseases, or advising on medication. Always seek the advice of a physician or other qualified provider with any questions about a medical condition, and never disregard or delay professional advice because of something in the Service. See the Health & AI Disclaimer for full details on AI limitations and your responsibilities.
19. Data breach notification
If a breach of personal information creates a real risk of significant harm, we will, as applicable and required by law:
- notify the relevant EU/EEA or Swiss supervisory authority within 72 hours of becoming aware, and notify affected individuals without undue delay where the breach is high-risk;
- report to the Office of the Privacy Commissioner of Canada (and Québec's CAI where relevant) as soon as feasible, notify affected individuals in plain language, and keep a record of the breach for at least 24 months; and
- notify affected US residents and regulators as required by applicable state breach-notification laws.
20. Cookies and tracking technologies
Our website and PWA use cookies and similar technologies (cookies, local storage, and pixels) in these categories:
- Strictly necessary — sign-in and session; required, and cannot be turned off.
- Functional — remember preferences such as language or units.
- Analytics — our analytics provider, to understand aggregate usage and improve the Service.
- Marketing — used only where you have consented; we will update this Policy if we add advertising cookies.
In the EU/EEA, Switzerland, and Québec, we obtain your prior opt-in consent before setting non-essential cookies and analytics (or operate analytics without cookies); strictly necessary cookies do not require consent. In the United States, the same applies — non-essential cookies and analytics are off by default and set only if you opt in — and we honor GPC. You can manage your choices through cookie settings under your profile section or your browser settings, and withdraw consent at any time.
21. Accessibility
We aim to make the Service and these documents accessible and to meet recognized accessibility standards (such as WCAG). If you have difficulty accessing any part of the Service or this Policy, contact privacy@fitlyze.app and we will work to help.
22. Languages
This Policy and our other legal documents are made available in the languages in which the Service is offered, including French for our users in Québec, France, and Switzerland. If there is any conflict between translations, the English version controls, except where local law requires otherwise (for example, French for Québec consumers).
23. Changes to this Policy
We may update this Policy. For material changes, we will notify you by email or in-app notice at least 30 days before they take effect, or as otherwise required by law. The effective date shows when a version took effect. Continued use after the effective date constitutes acceptance.
24. Contact
DerMo Technologies Inc. (d/b/a Fitlyze) 2300 Yonge Street, Suite 1600, Toronto, ON M4P 1E4, Canada privacy@fitlyze.app
Fitlyze — Privacy Policy, version 2.0, effective July 7, 2026. © DerMo Technologies Inc. Provided for beta users in the European Union/EEA, Switzerland, Canada, and the United States.