FactoryFit

Privacy Policy

Effective 2026-09-14

This Privacy Policy describes how FactoryFit LLC (“FactoryFit,” “we,” “us,” or “our”) collects, uses, discloses, and retains personal information in connection with the FactoryFit software platform — the trainer dashboard and the client portal (together, the “Service”). It applies to Trainers (fitness professionals who subscribe to or hold beta access to the Service) and Clients (individuals a Trainer invites to a client portal). This Policy is incorporated by reference into, and should be read together with, our Terms of Service.

1. Introduction

FactoryFit provides software tools that help independent fitness trainers manage their coaching business, including training-programme and nutrition-guidance tools, check-in tracking, progress-photo storage, and AI-assisted drafting features. This Policy explains what personal information the Service processes, why, who it is shared with, and the choices available to you. It does not describe the professional services a Trainer provides to their Client — that relationship is between the Trainer and the Client, as described in our Terms of Service.

2. Scope

This Policy covers personal information processed through the Service itself. It does not cover: (a) information a Trainer or Client shares outside the Service (for example, in person, by phone, or through a different app); (b) third-party websites or services linked from or embedded in the Service, which are governed by their own privacy practices (see Section 11); or (c) information processed by a Trainer’s own separate business tools that are not part of the Service.

3. Eligibility / U.S.-Only Service

You must be 18 years of age or older to use the Service, whether as a Trainer or as a Client; the Service is not directed to, and does not knowingly permit use by, anyone under 18 (see Section 18). The Service is currently intended for Users located in the United States. We do not represent that the Service complies with the data-protection or other laws of any other country, and we do not currently offer region-specific terms or disclosures for users located outside the United States.

4. Information We Collect

We collect the following categories of information. Some categories apply only to Trainers, some only to Clients, and some to both.

Trainer information. Name, email address, phone number, business name, profile/logo/hero photo, authentication credentials (managed by our authentication provider, Supabase), subscription and billing status (plan tier, subscription status — not full payment-card numbers, which are handled directly by Stripe; see Section 4’s “Subscription and payment information” below and Section 11), beta/access-code status, coaching-profile information the Trainer chooses to enter (coaching methodology, programming preferences, a free-text “certifications” field the Trainer may fill in), the Trainer’s “Programming DNA” profile and authored rules (see Section 12), support-ticket content, and records of the Trainer’s own edits to AI-generated content (used as described in Section 12).

Client information. Name, email address, phone number, and information a Trainer collects through the Service’s intake process or a Client provides directly, which may include: date of birth, sex, height, current weight, target weight, fitness goals, training history, and workout/session data (exercises, sets, reps, load, completion history). Because intake also asks about injuries, medical conditions, medication, and medical-clearance status, this can include free-text entries in those categories where a Trainer or Client chooses to provide them — see “Fitness, nutrition, and health-context information” below.

Fitness, nutrition, and health-context information. The Service is built around collecting and using this kind of information to provide its core functionality, and it deserves its own description because of its sensitivity. This can include:

  • Injury and physical-limitation notes;
  • Free-text medical-condition, medication, and medical-clearance entries a Trainer or Client chooses to enter during intake;
  • Dietary restrictions and allergy/intolerance notes;
  • Nutrition targets and meal-plan content;
  • Weekly check-in responses (a free-text note plus 1–5 ratings for sleep quality, energy level, stress level, and nutrition adherence, along with reported body weight); and
  • AI-generated summaries or reports derived from this information (see Section 7).

This information is provided to enable the Trainer’s coaching functionality and FactoryFit’s related AI-assisted features — it is not reviewed or used by FactoryFit for any purpose unrelated to operating the Service.

Photos. Two distinct categories, stored and protected differently:

  • Profile/avatar photos (for a Trainer’s own profile/logo, or a Client’s profile photo) are stored in a storage location that is publicly readable by anyone with the file’s address, though the address itself is not published or indexed.
  • Progress/body photos — a Client’s uploaded “before/after” or timeline progress photos — are stored in a private storage location and are only ever made accessible through time-limited signed links generated when a Trainer or Client with legitimate access views them; they are not publicly reachable.

See Section 8 for how progress photos are used, including AI analysis.

Communications. The content of in-app messages between a Trainer and Client, AI-drafted message content a Trainer reviews before it is sent (see Section 7), and, where a Trainer sends a message by email or (if enabled) WhatsApp, the content of that message and the Client’s email address or phone number as applicable (see Section 11).

Subscription and payment information. A Trainer’s plan tier, subscription status, and an identifier linking the Trainer’s account to our payment processor, Stripe. FactoryFit’s own systems do not receive or store full payment card numbers — card entry happens directly on Stripe’s own hosted checkout and billing-management pages. Clients are never charged by FactoryFit for a subscription (see our Terms of Service, Section 13).

Technical and usage information. We distinguish three things here, because it matters what is actually true:

  • What FactoryFit’s own application database intentionally stores: account timestamps (created/updated dates), a Trainer’s set timezone, and, where a Client opts into push notifications, a device push token (see Section 11). FactoryFit’s own database schema does not include a dedicated field for IP address, browser/device identifiers, or general web-request logs.
  • What our infrastructure providers may process as an ordinary part of running any web application: our hosting provider (Vercel) and database/authentication provider (Supabase) may, as a standard incident of operating servers, process technical request information such as IP addresses in their own infrastructure-level logs. This is standard web-infrastructure operation, not something FactoryFit separately collects into its own application data.
  • What we do not currently collect at all: we do not currently use any analytics, advertising, or audience-tracking technology, and we do not have an error-monitoring/crash-reporting tool integrated into the Service as of this Policy’s drafting. If that changes, we will update this Policy before doing so.

Local device storage. The client portal temporarily saves an in-progress, unfinished workout log to your own browser’s local storage so that a page reload does not lose your unsaved input. This information stays on your device and is not transmitted to FactoryFit until you complete and submit the workout, at which point the completed data (not the local draft file itself) is saved to your account in the ordinary course of using the Service.

5. How We Collect Information

We collect information: directly from a Trainer when they create an account, set up their profile, or use the Service; directly from a Client when they set up their portal access, respond to a check-in, upload a photo, or use portal settings; from a Trainer entering or uploading information about their Client (for example, intake responses, notes, or photos) as part of managing that coaching relationship; and, to a limited extent, automatically as an ordinary incident of our infrastructure providers operating the servers that run the Service (see Section 4).

6. How We Use Information

We use the information described above for the following purposes, and we do not use it for undisclosed or unrelated business purposes:

  • Creating and authenticating Trainer and Client accounts;
  • Operating the Trainer dashboard and the Client portal;
  • Enabling a Trainer to manage their coaching relationship with their Clients within the Service (creating and tracking programmes, nutrition plans, check-ins, and progress);
  • Workout logging and training-history tracking;
  • Nutrition-related functionality, including calculating targets and managing meal plans;
  • Storing and displaying progress photos and, where applicable, AI-assisted photo comparisons (Section 8);
  • Providing AI-assisted drafting features (Section 7);
  • Personalizing a Trainer’s own experience of AI-assisted drafting based on that Trainer’s own edits and preferences (Section 12);
  • Sending communications and notifications you or your Trainer initiate or configure through the Service;
  • Administering subscriptions and billing;
  • Maintaining the security of the Service and preventing fraud or abuse;
  • Troubleshooting, maintaining, and operating the Service;
  • Complying with legal obligations; and
  • Providing customer support.

7. AI-Assisted Processing

The Service includes several AI-assisted features, built using models from our AI provider, Anthropic. Each feature sends only the information relevant to that specific feature — for example, generating a training programme uses a Client’s intake information and training history; generating nutrition guidance uses a Client’s physical stats, nutrition targets, and any dietary-restriction or medical-context information provided; a check-in summary uses that check-in’s responses. A detailed, route-by-route account of exactly what each AI feature sends is in the companion drafting notes.

AI-generated content is a draft. For training programmes and nutrition/meal plans, a Trainer must take an explicit action to make that content visible to a Client — programmes and meal plans are not shown to a Client until the Trainer publishes them, and (for programmes) the Trainer will be asked to confirm they have reviewed the content and consider it appropriate for that Client before publishing. AI-assisted photo comparison analysis is prepared as a private draft and is not shown to a Client unless and until the Trainer explicitly chooses to share it (Section 8). Some AI-assisted output (such as an internal check-in summary) is intended for the Trainer’s own use and is not, by itself, shown to a Client.

What we can and cannot represent about our AI provider’s own data practices: we have not independently verified, and this Policy does not represent, the specific data-retention period our AI provider applies to processed data, whether it uses submitted data to train its own models, or any “zero data retention” or similar account-level setting, beyond what is stated in our own agreement with that provider. If you would like more detail on this point before or during the beta, contact legal@factoryfit.app.

8. Progress Photos and AI Analysis

Progress photos deserve their own explanation because of their sensitivity.

A Client can upload progress photos through the client portal; a Trainer can also upload a “before/after” photo pair on a Client’s behalf through the dashboard. These photos are stored privately (Section 4) and are only ever displayed through a time-limited signed link generated for someone with legitimate access to that Client’s account — not a public or permanent URL.

AI comparison analysis: a Trainer can select two of a Client’s progress photos and request an AI-generated comparison. When this happens, the actual image files are sent to our AI provider, Anthropic, along with the Client’s first name and the Trainer’s own coaching-style profile text, to generate draft commentary. This draft is saved privately and is not visible to the Client by default — a Trainer must take an explicit action to share it, and the system records when and by whom it was shared. A Trainer can edit the AI’s draft before sharing it. Once an analysis has been shared with a Client, it is kept as a record and is not deleted, even if later “unshared” from the Client’s view.

Before your progress photos are analyzed by AI, you will be shown a disclosure explaining this and asked to acknowledge it.

Deletion: a Trainer can delete a legacy “before/after” photo pair, which removes both the file and the record. As of this Policy’s drafting, there is no way to delete an individual progress-photo timeline entry once uploaded — this is a known limitation we intend to address; if you need a photo removed sooner, contact legal@factoryfit.app and we will address it manually.

9. Trainer and Client Relationship

FactoryFit receives personal information in a few different ways: directly from Trainers, directly from Clients through the portal, from Trainers entering or uploading information about their Clients, and from Clients providing information about themselves. In practice: a Trainer decides much of what information to request from their Client as part of running their own coaching practice, and is responsible for that decision and for having any consent or lawful basis required to collect and share it through the Service (see our Terms of Service, Section 9). FactoryFit operates the software that stores and processes that information to provide the functionality described in this Policy, and FactoryFit separately makes its own decisions about how the platform itself operates — including security, account administration, and which service providers we use. A Client may have privacy rights and interests of their own, independent of their Trainer, with respect to their own personal information (see Section 16).

This Policy describes that practical relationship. It does not make a legal determination that FactoryFit is solely a “processor,” “service provider,” or similar role, or that a Trainer “owns” Client personal data — those characterizations depend on facts and law that may vary by category of information and by jurisdiction, and are flagged for legal review in the companion drafting notes.

10. How We Disclose Information

We disclose personal information: to the Trainer managing a Client’s account, because that is core to how the Service works; to the Client, with respect to their own Trainer’s programmes, plans, and messages; to our service providers, solely to operate the Service (Section 11); when a User directs us to (for example, sending a message to a specific recipient); to comply with a legal obligation or respond to valid legal process; to protect the rights, property, or safety of FactoryFit, our Users, or others, including in connection with fraud prevention and security incidents; and in connection with a business transfer (Section 20).

We do not sell personal information, and we do not sell Client health information or use Client health information for targeted advertising. Because operating the Service necessarily involves sharing information with the service providers described below, we do not claim that we “never share” personal information — instead, Section 11 tells you specifically who receives what.

11. Service Providers / Third Parties

Supabase

What it receives

All Service data — it is our database, authentication, and file-storage provider

Why

Core system of record for the entire Service

Status

Current

Vercel

What it receives

Application code and, as an ordinary incident of hosting, technical request data

Why

Hosting, deployment, and scheduled background tasks

Status

Current

Anthropic

What it receives

Client fitness/nutrition/health-context information and, for photo comparisons, the photos themselves, as described in Sections 7–8

Why

Powers the Service’s AI-assisted features

Status

Current

Stripe

What it receives

A Trainer’s email address and an internal account identifier — not Client personal information in the Service’s normal operation

Why

Processes Trainer subscription billing

Status

Current (billing is inactive for free beta testers, but the integration exists for paid subscribers)

Resend

What it receives

A Client’s email address and the content of an email message a Trainer sends or approves

Why

Delivers email communications

Status

Current

Firebase Cloud Messaging (Google)

What it receives

A device push token and notification text

Why

Delivers push notifications to the client portal, if a Client opts in

Status

Current, opt-in

Twilio

What it receives

A Client’s phone number and message content, if this channel is used

Why

Optional WhatsApp messaging channel

Status

Available in the Service’s code as an optional channel; whether it is actively configured for use at any given time is not something this Policy can verify from the product’s code alone

YouTube (Google)

What it receives

Nothing sent by FactoryFit directly — but viewing an embedded exercise video causes your browser to load content from YouTube

Why

Exercise-demonstration videos

Status

Current; governed by YouTube/Google’s own privacy practices, outside our control

USDA FoodData Central

What it receives

A generic food-name search term (no personal information)

Why

Nutrition-database lookups when a Trainer searches for a food

Status

Current, optional

We do not currently use Pexels for any purpose — a prior, now-inactive integration exists only as unused legacy code and is not a current data recipient. We do not currently use any analytics, advertising, or error-monitoring/crash-reporting service.

12. Trainer-Specific Personalization / Programming DNA

A Trainer’s own edits to AI-generated content, stated preferences, and authored rules may be used by FactoryFit to personalize and improve that Trainer’s own future use of the Service’s AI-assisted features — for example, so future drafts better reflect how that Trainer coaches. This is scoped to the individual Trainer: one Trainer’s programming preferences, rules, or methodology are not exposed to another Trainer. We do not currently use this information to train a broader, shared model across all Trainers; if that ever changes, we will update this Policy and disclose it specifically before doing so.

13. Cookies and Similar Technologies

We currently use only essential, functional technologies — not analytics or advertising cookies. Specifically: authentication relies on session cookies/tokens managed by our authentication provider that are necessary to keep you signed in; and, as described in Section 4, the client portal uses your browser’s local storage for one narrow, functional purpose (temporarily saving an unfinished workout log on your own device). We do not currently use cookies or similar technologies for advertising, cross-site tracking, or analytics. Because we do not use non-essential cookies, we do not currently display a cookie-consent banner; if we add analytics or advertising technology in the future, we will revisit this and provide appropriate notice and choices at that time.

14. Data Retention

We retain personal information for as long as reasonably necessary to provide the Service, for the purposes described in this Policy, to maintain business records, to comply with legal obligations, and to resolve disputes or address security concerns. Specific retention periods can vary by category of information, and, as of this Policy’s drafting, we have not yet implemented an automated data-retention or deletion schedule — this is a planned improvement, not a current capability.

Today, a Trainer can “archive” a Client, which removes that Client from the active roster and billing count but keeps all of that Client’s data intact, available again if the Client is reactivated. There is currently no self-service way for a Trainer or Client to permanently delete an account or its associated data through the product interface.

If you would like to request deletion, access, or correction of your information, contact legal@factoryfit.app. During this initial beta period, we will handle such requests manually. Please understand that: we may need to verify your identity before acting on a request; we cannot promise instantaneous deletion; and we cannot guarantee removal of information from every backup or from our service providers’ own systems, though we will make reasonable efforts consistent with applicable law.

15. Data Security

We use technical and organizational measures intended to protect personal information, including authentication controls, database-level tenant isolation designed to keep each Trainer’s data separate from other Trainers’, private storage with time-limited access links for progress photos, and encryption in transit provided by our infrastructure providers. Profile/avatar photos are stored differently from progress photos — as described in Section 4, they are stored in a location that is technically publicly reachable if someone has the exact file address, unlike progress photos, which are never publicly reachable.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We do not represent that the Service is “completely secure,” “100% secure,” “HIPAA-grade,” “bank-level,” or “military-grade” — these are not accurate descriptions of any real-world system, and we do not use them.

16. Privacy Rights and Choices

Depending on where you are located and which laws apply to you, you may have rights with respect to your personal information, such as a right to know what we collect, to request access to or a copy of it, to request correction or deletion, or to opt out of certain uses. These rights depend on your location and applicable law and are not automatically the same for every User. To submit a request, contact legal@factoryfit.app. We may need to verify your identity before responding, and, where legally required, we will allow an authorized agent to submit a request on your behalf and will provide an appeals process for a denied request. We will not discriminate against you for exercising a privacy right that applies to you.

17. California / State-Specific Privacy Considerations

We have not yet completed a formal determination of whether, or which, California or other state privacy statutes (such as the California Consumer Privacy Act, as amended) currently apply to FactoryFit’s specific size and operations. Rather than assume this either way, we commit to the following regardless: we do not sell personal information, and we do not sell or use Client health information for targeted advertising. If and when a state privacy law is determined to apply to FactoryFit, we will update this section with the specific rights and mechanisms (such as a dedicated request-submission method) that law requires.

18. Children

The Service is not intended for, and is not directed to, anyone under 18 years of age, and we do not knowingly permit anyone under 18 to create or use a Trainer or Client account. If we learn that someone under 18 has provided us with personal information, we may take appropriate steps, which could include restricting or deleting the associated account.

19. Data Security Incidents

If a data-security incident occurs that affects your personal information, we will provide notification as required by applicable law. We are not in a position to promise a specific notification timeline beyond what the law requires, and this Policy should not be read to promise more than that.

20. Business Transfers

If FactoryFit is involved in a merger, acquisition, financing, reorganization, or sale of some or all of its assets, personal information may be transferred as part of that transaction, subject to this Policy and applicable law. This is a standard provision for how a business’s information moves if the business itself changes hands — it does not mean personal or health information is separately sold as a stand-alone commercial product.

21. International Access / U.S.-Only Scope

The Service is intended for use by Users located in the United States. We do not represent compliance with the GDPR, UK GDPR, or the privacy laws of Canada, Brazil, or any other country, and we have not built region-specific handling for users outside the United States. If you access the Service from outside the United States, you do so on your own initiative and are responsible for compliance with laws that may apply to you.

22. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make a material change, we will provide notice — for example, by email or an in-product notice — post a new effective date or version number, and, where required by applicable law, seek your renewed acceptance.

23. Contact Us

  • General support: hello@factoryfit.app
  • Privacy and legal inquiries: legal@factoryfit.app
  • Entity: FactoryFit LLC