Privacy Policy
Last updated: August 29, 2026
This Privacy Policy explains what personal data Fitler collects, how it uses and protects it, and what rights you have. We process data in accordance with the Personal Data Protection Act of the Republic of Serbia and, where applicable, the EU General Data Protection Regulation (GDPR).
1. Who is the data controller
The data controller is Miloš Anđelković. The app connects trainers with their clients: for personal data a client enters as part of working with their trainer, the trainer also acts as a controller (they decide what data to collect from the client to provide their service), while we process that data on their behalf and provide the technical platform. For any questions about privacy and exercising your rights, you can contact us at contact@fitler.app.
2. What data we collect
- Account data: first and last name, email address, role (trainer or client), password (stored encrypted).
- Content you enter: training programs, exercises, notes and messages between trainer and client.
- Training data: logged sets, repetitions, the weight used (kg), exercise duration and notes attached to a workout. This is training-performance data and we process it as ordinary personal data.
- Payment data: for trainers who subscribe, subscription and transaction data is processed by an external payment processor (see section 5). We do not store card numbers. In this version of the service billing is not active, so this data is not processed.
- Technical data and analytics: anonymized/pseudonymized data about app usage (in-app events, device type) to improve the service. We do not send content you enter or your training data to analytics tools.
- What we do not collect in this version: body measurements, body circumferences, progress photos, nutrition plans, food logs and other health data are not part of this version of the app. Those features are planned for a later phase and will only be introduced with explicit consent and an updated privacy policy published in advance.
3. Legal basis for processing
- Performance of a contract (Art. 6(1)(b) GDPR) — providing the service that connects trainer and client and the app's core functionality.
- Consent (Art. 6(1)(a)) — for optional features that require it (e.g. push notifications). You can withdraw consent at any time. This version does not process special category data (health data).
- Legitimate interest (Art. 6(1)(f)) — security, abuse prevention and improving the service through aggregated analytics.
- Legal obligation (Art. 6(1)(c)) — retaining billing data where required by law, once billing is active.
4. How we use data
We use data solely to provide the service: connecting trainer and client, creating and assigning training programs, logging completed workouts, communication through the app and sending notifications. We do not sell personal data and do not share it with third parties for marketing.
5. Data sharing and processors
Only the connected trainer and client can see your data within their relationship. To provide the service we use trusted processors that process data on our behalf:
- Supabase — database, authentication and file storage (e.g. profile pictures).
- Railway — hosting for our server (API).
- Paddle — subscription payment processing (as merchant of record), when in-app payments are active.
- Resend — sending transactional emails (account confirmation, data export).
- PostHog — usage analytics (without health data).
- Expo — app delivery and push notifications; Vercel and Cloudflare — site hosting and DNS.
Some processors may process data outside Serbia/the EU (e.g. in the USA). In that case the transfer is carried out with appropriate safeguards (standard contractual clauses or an equivalent mechanism).
6. How long we keep data
We keep data while the account is active. If an account is inactive for more than 12 months, we may flag it for deletion after prior notice by email. When you delete your account (in the app, Settings → Delete account), we permanently remove your data and associated files (e.g. your profile picture), except data we are legally required to retain (e.g. billing records). If you cannot access the app, you can also request account and data deletion by email at the contact address in section 11 — we process the request without undue delay. When a trainer removes a client, or a client leaves a trainer, the personal data entered stops being visible to the trainer; the client's account and data remain under the client's control until they delete it.
7. Your rights
Under the law, you have the right to:
- access your data and obtain a copy of it;
- rectify inaccurate data;
- erase data (“right to be forgotten”) — available directly in the app;
- data portability (export in a machine-readable format);
- restrict processing and object to processing;
- withdraw consent at any time (without affecting processing before withdrawal);
- lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection (in the EU: the competent supervisory authority).
You can send your request to contact@fitler.app.
8. Security
We apply technical and organizational safeguards: password encryption, row-level access control in the database (RLS) so that only the connected trainer/client can access the data, and encrypted data transmission. No system is completely secure, but we continuously work to protect your data.
9. Children
Fitler is not intended for people under 16. We do not knowingly collect data from children. If you believe a child has provided us with data, contact us for deletion.
10. Changes to this policy
We may update this policy from time to time. We will notify you of significant changes in the app or by email. The date of the last update is shown at the top of the page.
11. Contact
For any privacy questions, write to us at contact@fitler.app.