Privacy Notice

Last updated: June 1, 2026

1. Who we are

This Privacy Notice is issued by HisFitai ("HisFitai", "we", "us", or "our"), the operator of the HisFitai service and websites (the "Service"). HisFitai is the data controller for personal data processed in connection with the Service. You can contact us at support@hisfitai.com.

2. Personal data we collect

  • Account data: name, email address, login credentials, profile photo.
  • Fitness profile: goals, fitness level, equipment, schedule, injuries, dietary preferences.
  • Coaching content: messages you send to the AI coach, generated plans, completed/missed workouts.
  • Usage & device data: log data, pages viewed, IP address, browser/device identifiers, approximate location.
  • Support data: any messages you send to our support team.
  • Order data: subscription tier, status, and billing history (collected by Paddle on our behalf — see Section 5).

3. How we use personal data

  • Create and operate your account.
  • Deliver the Service, including personalized workouts, meal plans, and AI coaching.
  • Process subscriptions and manage entitlements.
  • Provide customer support and respond to your requests.
  • Detect, prevent, and respond to fraud, abuse, and security incidents.
  • Measure and improve the Service, troubleshoot issues, and develop new features.
  • Send service communications and, where permitted, marketing communications.
  • Comply with legal obligations.

4. Legal bases

We rely on the following legal bases: performance of a contract (to provide the Service you sign up for), legitimate interests (to secure and improve the Service and to communicate with you), consent (where required, e.g. certain cookies or marketing), and legal obligation (to comply with applicable law).

5. Sharing with third parties

  • Paddle.com Market Ltd ("Paddle") — our Merchant of Record. Paddle handles checkout, payment processing, billing, tax compliance, invoicing, subscription management, fraud prevention, and refunds. Paddle acts as a separate controller for the personal data it collects during these activities. See Paddle's privacy notice at paddle.com/legal/privacy.
  • Hosting & infrastructure providers used to run the Service.
  • AI model providers used to power the AI coach.
  • Analytics and error-monitoring providers used to measure and debug the Service.
  • Professional advisers (legal, accounting, insurance) where strictly necessary.
  • Authorities or other parties where required by law or to protect rights, safety, or property.

6. International transfers

Your personal data may be transferred to and processed in countries outside your country of residence, including outside the UK/EEA. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions.

7. Data retention

We retain personal data for as long as your account is active and for a reasonable period after to comply with legal, tax, accounting, and dispute-resolution obligations. When data is no longer needed, we delete or anonymise it.

8. Your rights

Depending on your location, you may have rights to access, rectify, erase, restrict, or port your personal data, to object to processing, and to withdraw consent. You can also lodge a complaint with your local data protection authority. To exercise these rights, contact support@hisfitai.com. We aim to respond within one month.

9. Security

We use appropriate technical and organisational measures, including encryption in transit, access controls, and least-privilege practices, to protect personal data. No system is 100% secure, but we work to continually improve our protections.

10. Cookies

We use strictly necessary cookies to operate the Service (e.g. authentication) and, where permitted, analytics cookies to understand usage. You can control cookies through your browser settings.

11. Children

The Service is not intended for individuals under 16. We do not knowingly collect personal data from children.

12. Changes to this notice

We may update this Privacy Notice from time to time. The "Last updated" date at the top reflects the latest changes.