Apps by Keith

Privacy Policy

Last updated September 28, 2026

FitThis is an app that reads your workouts from Apple Health or Android Health Connect and charts how hard each one was, over time, for each type of exercise.

This policy explains what the app reads, what stays on your device, what is sent to its server and to Google, and what happens to it. It is written to be read, not to be survived — if anything here is unclear, write in and ask.


The short version


Who is responsible

FitThis is published by Keith Rochkind, an individual developer based in California, United States. For the purposes of the GDPR, that is the "data controller" for the information described here.

The way to reach the developer about anything in this policy — including a request to see or delete your data — is by email to fitthis@appsbykeith.com.


Your health data

FitThis asks for permission to read two things from Apple Health (iOS) or Health Connect (Android):

| What | Why | | ------------------------------- | ------------------------------------------------------- | | Workouts (type, date, duration) | To know which exercise you did, and when | | Active calories burned | To work out how hard each workout was |

That is the whole list. The app does not read heart rate, steps, distance, routes, weight, body fat, sleep or any other health record, and on Android the other Health Connect permissions are removed from the app entirely. The app never writes to Health.

Scoring happens on your device. The score for each workout is calculated by the app itself, from the figures above. Scores are never sent anywhere.

Health data is used only to show you your own chart and, if you sign in, to keep your history for you. It is not used for advertising or marketing, not used to build profiles, not sold, and not shared with data brokers or advertisers. It is never placed in analytics or crash reports — the app is built so that it cannot be: the events it records accept only a fixed set of choices, not figures.

Health data is not stored in iCloud or in device backups. The app's copy is excluded from iCloud and Android backup and device-to-device transfer, and is rebuilt from your own Health data if you reinstall.

Use of information received from Health Connect adheres to the Google Play User Data Policy, including its Limited Use requirements.

You can withdraw the app's access at any time in Apple Health or Health Connect settings. The app will then have nothing to read, and will tell you so.


What stays on your device

| What | Where it lives | | ----------------------------------------------------- | ----------------------------------------------- | | Workout figures the app has read from Health | The app's private storage | | Scores calculated from them | The app's private storage | | Your settings (theme, chart style, last range chosen) | The app's private storage | | A random install ID (described below) | The app's private storage |

Deleting the app removes this. If you never sign in, your workout figures and scores never leave your device, apart from anything you export yourself (below).


Signing in

Signing in is optional. It lets your history follow you to a new phone. You sign in with Apple or Google; there are no passwords in FitThis.

What signing in stores. For each day and exercise type, the app uploads: the date, the exercise type, the active calories, the duration, and when that figure last changed. It is stored on the developer's server against a random account identifier. This is the only place health-derived data is kept off your device, and it happens only while you are signed in. Scores are not uploaded.

The account itself is handled by Google Firebase Authentication. It holds an account identifier and whatever your sign-in provider shares: usually your email address and name — or, if you choose "Hide My Email" with Apple, a private relay address. FitThis's own storage holds only the random account identifier, not your name or email address.

Signing out stops syncing and leaves your data on the server and on your device. Deleting your account (Settings → Account → Delete account) removes the workout history stored for it on the server and then deletes the account itself. Data already on your device is kept, so the app keeps working, until you delete the app.


What the app sends, and when

1. Launch reports

On each launch the app sends one report so the developer knows how many people use the app, on which devices, and whether a release has broken something on a particular OS version. It contains:

| Category | Fields | | ---------- | ---------------------------------------------------------- | | Identifier | The random install ID | | Device | Platform, OS version, model, manufacturer | | App | App version and build number | | Region | Language / locale and time zone |

The response tells the app whether the installed version is still supported. No health data, no workout counts and no account information is in a launch report.

2. Your workout history (only if you sign in)

As described above. On ordinary launches the app sends only what has changed since the last time, which is often nothing.

3. Error reports

If the app hits an error it did not expect, it sends a report so the fault can be fixed: what went wrong, where in the code it happened, the app version and platform, and the install ID. The description is scrubbed on your device before it is sent — workout figures, exercise types, file paths and quoted text are removed. Serious errors are kept in the developer's storage; all of them are kept in Azure's diagnostic logs.

4. Crash reports

If the app crashes, Google Firebase Crashlytics records a crash report — the stack of the failure, device model and OS version, app version, and the install ID — so the crash can be fixed. It contains no health data.

5. App-usage events

The app records a few simple events with Google Analytics for Firebase: which screen you are on (the chart, Settings, or this policy); when you start a CSV export, which date range it covered (such as "last year"), and whether it succeeded, was canceled or failed; and which empty screen was shown when the chart has nothing to display (for example, "no workouts found" or "Health permission not granted"). These tell the developer whether exporting works and where new users get stuck. Never a calorie count, duration, score, date, exercise type or number of workouts. Google also collects some standard information automatically, such as when the app is opened and the device and app version. Google may derive an approximate region from your IP address for its reports.

6. Attestation

To make sure requests come from a genuine copy of FitThis, the app asks Firebase App Check to vouch for it. On Android this uses Google Play Integrity; on iOS, Apple App Attest. This checks the app and device, not you, and carries no health data.

7. Written documents

When you open this policy, the app requests the current text from the server. Nothing about you is sent with that request beyond the ordinary technical details described next.

8. Ordinary technical details

Like any app that talks to a server, requests carry your device's IP address in transit. FitThis's own records do not store IP addresses; the hosting platform may include them in its own diagnostic logs.


Exporting your own data

FitThis can export the chart's figures to a CSV file. That is entirely started by you and saved or shared through your device — the file does not pass through the developer's server. Where you send it afterward is your choice.


What the app never collects

The permissions the app declares are only: internet access, and read access to workouts and active calories in Health.


Why this information is used

| Purpose | What is used | | ---------------------------------------------- | ---------------------------------------------- | | Showing your chart | Workouts and active calories, on your device | | Keeping your history and carrying it to a new phone | Synced workout figures (if you sign in) | | Understanding how many people use the app, and on what | Launch reports, app-usage events | | Finding and fixing faults | Error reports, crash reports, diagnostic logs | | Keeping the service from being abused | App Check attestation |

Under the GDPR, the lawful basis for launch reports, usage events and error and crash reports is legitimate interest — keeping an app the developer maintains alone working, and understanding whether it is. The lawful basis for processing your workouts, which are health data, is your explicit consent: you give it by granting Health access, and again by choosing to sign in before anything is synced. You can withdraw it as described below.

Nothing here is used to build advertising profiles, is sold, or is shared for cross-context behavioral advertising.


Who else sees it

Microsoft Azure hosts the server, stores the records described above (including synced workout figures) and its diagnostic logs. Microsoft acts as a service provider and processes this information on the developer's instructions. Data is stored in the United States.

Google (Firebase) provides sign-in, app-usage events, crash reports and App Check attestation, as described above. Apple and Google operate the sign-in providers you choose from, and the stores you buy the app from.

None of them is given your workout figures for their own purposes; the only service that receives workout figures is the developer's Azure server, and only if you sign in.

Information may also be disclosed if required by law, or to protect the rights and safety of users or the developer. Beyond that, nothing is shared with anyone.


International transfers

The servers are in the United States. If you use FitThis from outside the United States — including from the United Kingdom or the European Economic Area — the information described here is transferred there. Where the GDPR or UK GDPR applies, that transfer relies on the European Commission's Standard Contractual Clauses as implemented in the data protection terms of Microsoft and Google.


How long it is kept

Synced workout history is kept until you delete your account, at which point it is removed. Launch and error records have no fixed schedule; they are kept for as long as FitThis is operated and deleted if it is retired. Crash reports and app-usage events are kept by Google for the periods its Firebase settings allow. Anything on your own device is kept until you delete it, or delete the app.


Security

Traffic between the app and the server is encrypted in transit with HTTPS. Stored records are encrypted at rest by Azure. Requests to the server are checked with App Check, and access to your synced history requires your signed-in identity. Access to the stored records is restricted to the developer through an identity-based sign-in rather than a shared key.

No system is perfectly secure, and no promise is made that one is.


Your choices and rights

Everyone.

About launch, error and usage records. These are keyed to a random install ID that is not shown to you and is not connected to your account, name or email address. The developer therefore cannot look up "your" launch or error records from an email address; they are not held in a way that can be tied to you.

If you are in California, the CCPA as amended by the CPRA gives you the right to know what personal information is collected and why; to obtain a copy of it; to have it corrected; and to have it deleted. You also have the right not to be discriminated against for exercising any of these rights. FitThis does not sell personal information, and does not share it for cross-context behavioral advertising. Workout data is health information, which the CPRA treats as sensitive; FitThis uses it only to provide the service you asked for.

If you are in the United Kingdom or the European Economic Area, the GDPR gives you the rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent at any time — for synced workouts, by signing out and deleting your account. You also have the right to complain to your national supervisory authority.

To exercise any of these, or to ask for a copy of what is held for your account, write to fitthis@appsbykeith.com. A request will be answered within 30 days. No fee is charged.


Children

FitThis is not directed to children under 13, and is not intended for their use. No information is knowingly collected from a child under 13. If you believe a child under 13 has used the app and information has been collected, write to the contact address below and it will be deleted.


Changes to this policy

This policy is delivered to the app from the server, so a change appears without needing an app update. Where a change materially affects what is collected or what it is used for, the effective date at the top will be updated.


Contact

Questions, requests and complaints about this policy all go to the same place: fitthis@appsbykeith.com.