Legal

Privacy Policy

V7
Effective Date: June 8, 2026

Quick summary. Refactor Fitness collects the data you enter (account info, body measurements, food, workouts, photos) plus minimal technical data needed to run the app. We do not sell your personal information. We do not share your information for cross-context behavioral advertising. We do not use your data to train AI models. Most data flows are described in Consumer Health Data Privacy; this policy explains the rest, plus your rights under California, Washington, and other US laws.

Your privacy is important to us at BOGERT CSN 443, LLC, doing business as Refactor Fitness ("Company", "We", "Us", or "Our"), a State of Washington LLC. As such, we have a few fundamental principles:

We don't and won't ask you for personally identifying information unless we truly need it. To make this Privacy Policy easier to read, the Refactor Fitness mobile application, web application, and related products and services are collectively called the "Services" throughout this policy.

We don't share your personally identifying information with anyone, except as needed to provide service support, to comply with applicable law, or to protect our rights.

You are in control of the information you share through the Services, and any User Data (as defined in the Terms of Use) you provide is your responsibility.

The Services do not require you to enter any information to view; however, to access or otherwise utilize certain features of the Services (our AI assistant Spot, for example), you will be asked to create an account. If you create an account, certain limited information which generally includes personal information will be required to deliver the Services to you. Such information shall be governed by this policy.

Please note that this Privacy Policy does not apply to the privacy practices of third parties whose links and retail products may appear on or through the Services. We are not responsible for the content or privacy practices of third parties. We recommend that you exercise caution before you voluntarily disclose personally identifiable information to other users or through third-party links on third-party websites or platforms.

This Privacy Policy applies to Users who have created an account and accepted our Terms of Use, as well as those who are viewing our Services and neither created an account nor accepted our Terms of Use. Collectively throughout this policy we use the term "you" to reference each type of user who interacts with us.

1. Personal Information We Collect

We collect the following categories of personal information. Categories in italics are also "consumer health data" under the Washington My Health My Data Act and "sensitive personal information" under the California Consumer Privacy Act, and are described in greater detail in our Consumer Health Data Privacy Policy. We collect information you provide directly to us, information generated through your use of the Services, and information from third-party services you choose to connect.

The full category-by-category "right to know" disclosure — each CCPA §1798.140 category, the specific examples we collect within it, and its source — is set out in the table in our FAQ, as updated from time to time. The prose subsections below summarize the same collection.

Information You Provide

When you create an account or use our Services, we may collect:

  • Name, username, and profile information
  • Email address and password
  • Date of birth, age range, and gender
  • Height, weight, fitness goals, and other health and wellness information you choose to provide
  • Payment and billing information (if you purchase subscriptions or other paid services)
  • Communications you send to us, including customer support inquiries and feedback

Fitness and Activity Information

To provide fitness tracking features, we may collect:

  • Workout and exercise data, including activity type, duration, intensity, distance, pace, and calories burned
  • Step count and movement data
  • Heart rate and other biometric measurements collected through compatible devices and services
  • Sleep, recovery, and wellness metrics that you choose to track
  • Progress records, achievements, and fitness goals

Location Information

With your permission, we may collect precise location information to support features such as activity mapping, route tracking, distance calculations, and location-based fitness insights. You can control location permissions through your device settings.

Information from Connected Services

If you choose to connect third-party platforms, wearable devices, or health services (such as Apple Health, Google Health Connect, Garmin, Fitbit, or similar providers), we may receive information from those services in accordance with your authorization settings and the privacy practices of the applicable provider.

Sensitive Health Information

Certain fitness, biometric, and wellness information may be considered sensitive personal information under applicable laws. We collect and process such information only as necessary to provide requested services, improve your experience, comply with legal obligations, or as otherwise permitted by applicable law and with any required consent.

Logging Statistics

Like most website operators, our servers automatically collect certain types of non-personally identifying, technical information, such as the browser type, language preference, referring site, and the date and time of each visitor request. This includes information such as:

  • What portions of our website you access;
  • How long you stay for; and
  • What kind of device you are using.

We use this information to better understand how our visitors use our website and to maintain our Services.

Location Information & IP Addresses

We collect very limited personal data. If you fill out a form or create an account with your name and email address, we do link the IP address and device information to you. Additionally, we collect IP address and convert it to location for (1) security monitoring, (2) supporting some features, such as IP whitelisting and country-level location whitelisting, and (3) delivering location-based help and website details.

Locale Preferences and Device Information

When you use our Services, we may automatically collect certain information from your device, its software, and your activity using our Services. This may include information you search for on our website, locale preferences, identification numbers associated with your devices, your mobile carrier, date and time stamps associated with transactions, metadata, your Internet Service Provider, files viewed on our site, operating system, and clickstream data.

Data Aggregation

In addition to the other uses described in this policy, you agree that we may extract and use information from the information you disclose for the purposes of aggregating data in a non-identifiable method. This aggregated data may be used internally to improve services or, without limitation, to develop, analyze, combine, or publish the aggregated data for commercial purposes.

Cookies

Your use of certain services may result in the assignment and storage of session cookies and analytics tools to recognize your access privileges and generally track user preferences. A cookie is a text file that is placed on the hard disk of your computer or mobile device by a server. Session cookies expire when you end your session and close your browser interface. Cookies cannot be used to run programs or deliver viruses to your computer or mobile device. Cookies are uniquely assigned to you and can only be read by a server in the domain that issued the cookie to you. Visitors who do not wish to have cookies placed on their computers or mobile devices should deny cookies by configuring their respective browsers to do so. If cookies are denied, certain features of our Services may not function properly.

2. How We Use Personal Information

We use personal information for the following business purposes:

  • Provide the Service: create and authenticate your account, sync data across your devices, calculate fitness metrics, log workouts and nutrition, generate progress charts.
  • Provide AI features (Pro subscribers who opt in): generate workout plans, meal suggestions, daily briefings, photo-to-macros estimates, and conversational coaching through Spot. See our AI features & your data FAQ.
  • Process subscriptions: manage trial status, entitlements, renewals, and refunds through Apple, Google, or RevenueCat.
  • Customer support: respond to your questions, troubleshoot issues, and honor your privacy requests.
  • Security and fraud prevention: detect, investigate, and prevent abuse, fraud, unauthorized access, and violations of our Terms of Use.
  • Legal compliance: comply with applicable laws, respond to lawful requests, and enforce our agreements.
  • Product analytics (default-on, opt-out available): measure feature engagement and prioritize improvements. We process Firebase Analytics data by default to understand how features are used; you may turn it off at any time in Profile > Settings > Privacy. Analytics events never include health data fields.
  • Crash diagnostics (default-on, opt-out available): identify crashes and performance regressions to improve stability. Firebase Crashlytics is active by default as part of providing the Service; crash reports do not include health data fields. You may turn it off in Profile > Settings > Privacy.
  • Marketing: we may contact you with marketing and promotional information (in accordance with your marketing preferences) about any services that we offer and to send you information regarding us. See below on contacting us to modify or delete your information.

We do not:

  • Sell personal information for money or other valuable consideration.
  • Share personal information for cross-context behavioral advertising (as that term is defined under California law).
  • Use personal information to train or fine-tune any AI or machine-learning model.
  • Use sensitive personal information for any purpose other than to provide and improve the Service you requested, as permitted by California Civil Code §1798.121.

3. How We Disclose Personal Information

We disclose personal information to the categories of recipients referenced in our FAQ, as updated from time to time, in each case only as necessary to provide the Service.

Each recipient identified in our FAQ as a "service provider" processes personal information only as necessary to provide the Service to us and is contractually prohibited from using, retaining, or disclosing personal information for any other purpose, including for the recipient's own commercial benefit. These contractual restrictions are required by California Civil Code §1798.140(ag) and equivalent state-law provisions.

We do not disclose personal information to advertisers, advertising networks, social media platforms, or data brokers. Our marketing website (refactorfitness.app) does not use cookies, ad pixels, or third-party analytics. All static assets (fonts, stylesheets, scripts, images) are served from our own infrastructure; the marketing website makes no third-party requests when you load it.

We take all measures reasonably necessary to protect against the unauthorized access, use, alteration, or destruction of potentially personally identifying information.

We disclose potentially personally identifying information only on an as-needed (or as-required) basis as follows:

  • To employees that (i) need to know that information in order to process it on our behalf or to provide the services, and (ii) have expressly agreed not to disclose it to others. Note: some of those employees and contractors may be located outside of your home country; by using the services you consent to the transfer of such information to them.
  • As required by law, such as to comply with a subpoena or similar legal process. To the extent we are legally permitted to do so, we will take commercially reasonable steps to notify you in the event that we are required to provide your personal information to third parties as part of a legal process.
  • When we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a written government request.
  • In the event of a merger, acquisition, or any form of sale of some or all of our assets, we will ensure that the acquiring organization agrees to protect personal information in accordance with the commitments we have made in this Privacy Policy, and that the acquiring organization will provide notice before personal information, customer information, or business information becomes subject to a different privacy policy.
  • To any other third party with your prior consent to do so. We do not sell your personal information to third parties.

4. Security and Storage

  • On your device: Data is stored locally using AES-256 encrypted storage with keys managed by Android Keystore or iOS Keychain. Your device is the primary source of truth.
  • In the cloud: Data is synced to AWS infrastructure. DynamoDB and S3 storage is encrypted at rest with AES-256. Photos and exports are stored in private S3 buckets behind signed URLs.
  • In transit: All traffic between your device and our servers is encrypted with TLS 1.2 or higher.
  • Authentication: Account credentials are managed by AWS Cognito. We never see, store, or transmit your password in plain text.

To prevent unauthorized access, safeguard data accuracy, and maintain the appropriate use of information, we have put in place appropriate physical, technical, and administrative procedures to protect the personal information data you submit. We make every effort to ensure the integrity and security of our network and systems. However, since the Internet is not 100% secure and as new technology evolves and emerges, we cannot guarantee that our security measures will prevent third-party interferences from illegally obtaining or tampering with your personal information.

We encourage you to help us by also taking precautions to protect your personal data when you use the services.

5. Data Retention

We will retain your personal information for as long as needed for the purposes described above and/or as required by law. A user may request access to certain data about themselves by emailing privacy@refactorfitness.app.

6. Your Rights Under US Privacy Laws

Depending on your state of residence, you may have the rights described below. We honor these rights regardless of where you live, except where the law itself draws a distinction (for example, the right to opt out of "sale" applies only where applicable).

6.1 California (CCPA / CPRA)

  • Right to know: categories and specific pieces of personal information we have collected, the sources, the business purposes, and the categories of recipients.
  • Right to access / data portability: a copy of the personal information we hold about you.
  • Right to delete: deletion of personal information we have collected from you, subject to legal exceptions.
  • Right to correct: correction of inaccurate personal information.
  • Right to opt out of sale or sharing: we do not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of.
  • Right to limit use of sensitive personal information: we already use sensitive personal information only for the purposes permitted by Civil Code §1798.121 (providing the Service you requested). You can also turn off optional analytics processing at any time in Profile > Settings > Privacy.
  • Right to non-discrimination: we will not deny service, charge a different price, or provide a different level of service because you exercised your privacy rights.

To exercise these rights, email privacy@refactorfitness.app or use the in-app controls (Profile > Settings > Privacy > Export Data, Delete Account, Withdraw Health Data Consent). We will verify your identity, typically by confirming you control the account email. You may use an authorized agent; we will require written proof of authorization.

We will respond within 45 days. If we need more time we will tell you, and the response time may be extended for an additional 45 days as permitted by law.

6.2 Washington (My Health My Data Act)

Washington residents have specific rights regarding consumer health data, including the right to confirm whether we are processing their consumer health data, access that data, request deletion, withdraw consent, and appeal a denial. These rights and the appeal process are described in our Consumer Health Data Privacy Policy.

6.3 Other states (Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and others)

Residents of states with comprehensive privacy laws have rights similar to those above, including access, deletion, correction (where applicable), portability, opt-out of sale, opt-out of targeted advertising, and opt-out of profiling that produces legal or similarly significant effects. We do not engage in any of those targeted-advertising or profiling activities. To exercise other rights, contact privacy@refactorfitness.app.

7. Your Choices & Controls

  • Export your data: Profile > Settings > Export Data.
  • Delete your account: Profile > Settings > Delete Account. All consumer health and fitness data is permanently deleted from our servers within 30 days.
  • Withdraw health-data consent: Profile > Settings > Privacy > Withdraw Health Data Consent.
  • Turn off AI features: Profile > Settings > AI Feature Consent.
  • Turn off product analytics: Profile > Settings > Privacy > Analytics & Crash Reporting.
  • Push notifications: manage at the OS level (Settings > Notifications > Refactor Fitness).
  • Apple Health / Google Health Connect: manage permissions in the Apple Health app or the Health Connect settings on your Android device.

8. Children's Privacy

Refactor Fitness is intended for users 18 years of age and older. We do not knowingly collect personal information from anyone under 18. If we learn we have collected personal information from a person under 18, we will promptly delete that information and any associated photos or health data. If you believe a minor has used the Service, contact privacy@refactorfitness.app.

9. International Users

The Service is offered to and intended for users in the United States. We do not target users outside the US, and we do not currently support GDPR, UK GDPR, PIPEDA, LGPD, or other non-US privacy regimes. If you are accessing the Service from outside the US, your information will be transferred to and processed in the United States. If you reside outside the US, you may not be afforded the rights provided by your local law beyond the rights described in this policy. You may delete your Account and your data at any time using the controls described in §7.

10. Feedback and Support

If you send us a request (via a support email or one of our feedback channels), we reserve the right to publish it (stripped of all personally identifying information, of course) in order to help us clarify or respond to your request or to help us support other Users.

We may provide technical support to service your account with us. In order to do so, we may use certain personally identifying information, with your consent, to access your account for the purpose of troubleshooting, running tests, and/or otherwise providing support. In providing technical support to you, we may potentially see other personally identifying information viewable on your account pages. As with all other information, we promise to hold any information we encounter in the process of providing support to the highest possible security and protection standards.

11. Business Transfers

If the ownership of the Company substantially changes, such that all of its assets were acquired, or merged into another entity, or in the unlikely event that we enter bankruptcy, you understand that any stored personally identifying and non-personally identifying information and data will likely be one of the assets that is transferred or acquired by a third party. You acknowledge that such transfers may occur and that any acquirer or merging entity of the Company may continue to use your personal information as set forth in this policy.

12. Changes to This Policy

We may update this Privacy Policy from time to time. The version number and effective date at the top of this page reflect the most recent revision. If we make material changes — for example, adding a new category of personal information, a new category of recipient, or a new purpose of processing — we will notify you in the app and ask for your renewed consent before the change applies to you. Minor clarifications may be made without re-consent.

13. Contact Us

For privacy questions, requests, or complaints, contact:

BOGERT CSN 443, LLC d/b/a Refactor Fitness
Email: privacy@refactorfitness.app
Mailing address: see Terms of Use §23 (Contact Us).

Contact appropriate authority

Should you wish to report a complaint or if you feel that we have not addressed your concern in a satisfactory manner, you have the right to contact a regulatory body or data protection authority in relation to your complaint.