MyFitLife Privacy Statement
Last updated: September 11, 2026
MyFitLife is a meal tracking and nutrition coaching app operated by IHP Technology LLC. This privacy policy explains what information the app collects, how it is used, and the choices available to users.
Information We Collect
Depending on how you use MyFitLife, we may collect:
- Account information such as email address and authentication identifiers.
- Food logs, saved meals, recent meals, recipes, shopping lists, hydration logs, macro goals, dietary preferences, fasting schedules and history, saved supplement labels and taken logs, weight or progress history, MyFit Score values, and profile settings you enter.
- Meal photos, selected images, generated recipe images, or food and supplement barcode scans you submit for app features.
- AI coach questions, generated responses, recipe prompts, food search queries, and related usage metadata needed to provide, secure, and improve app features.
- Technical information such as app errors, request timing, device or browser context, authentication state, quota state, and service logs needed for security, reliability, and abuse prevention.
- If you accept optional analytics on the public website, Google Analytics may receive pseudonymous page-view, browser/device, referral, and approximate location data to help us understand public-site usage. You can decline this analytics collection.
- Connected-app information such as the OAuth client, scopes you approve, token and consent status, and security events needed to operate or revoke an integration.
- If a Premium user chooses to connect Apple Health or Health Connect, MyFitLife may collect read-only daily step and active-calorie totals; workout or exercise-session summaries such as workout type, start and end time, duration, available active-calorie metadata, and bounded source-app or device display labels when supplied; source platform and time zone; sync-window, count, and timing metadata; hashed source-workout identifiers; calorie-adjustment and Coach-sharing preferences; and derived base, credited, and effective calorie targets. Current-day hourly step and active-calorie values may be used temporarily to draw Health Central charts but are not stored in MyFitLife daily history. Optional Apple Activity summaries and Health Connect activity-intensity aggregates are processed on the device for provider presentation and are not sent to MyFitLife, stored in Firestore, shared with Coach Milo, or used for calorie credit. MyFitLife does not request meals, calorie intake, nutrition, basal calories, total calories, heart data, clinical records, GPS or location data, or workout routes.
- MyFitLife may retain daily aggregate Health Central records for up to 400 local calendar days so Today, Week, Month, and Year views can show steps, active calories, workout counts, and workout minutes. Detailed workout records are limited to the current 30 local calendar days. After a daily aggregate ages out, paid historical calorie-target views may retain a target-only daily record containing only the target date; schema and policy versions; Health-derived and archive markers; calorie-adjustment status; base and static calorie targets; active-calorie credit; effective calorie target; credit percent; and archive timestamp. It does not retain raw steps or active calories, workout or source identifiers, source platform, time zone, workout counts or minutes, or sync timestamps.
- Subscription lifecycle information such as app-store purchase or transaction identifiers, product and entitlement status, purchase and expiration dates, and renewal, cancellation, refund, or billing-issue status. MyFitLife does not receive your full payment card number from Apple, Google, or RevenueCat.
- If you use Family Annual, household membership information such as the owner and member account identifiers, roles, invite status, seat count, and join timing. The owner may see each member's display name, email address when present, role, and join timing to manage seats. Family membership does not give the owner or other members access to another person's food logs, goals, weight, fasting, supplements, recipes, Coach history, or connected Health records.
How We Use Information
We use information to:
- Provide meal logging, hydration and fasting tracking, supplement-label and taken-log features, nutrition planning, progress tracking, shopping list, recipe, and AI coaching features.
- Authenticate users and protect user-scoped app data.
- Provide connected-app features that you authorize through OAuth consent.
- Sync the activity summaries you authorize, show recent workouts, and, only if you separately opt in, add 100% of daily active calories to your existing profile calorie target.
- Use a limited daily activity summary as Coach Milo context only when an eligible Premium user separately enables Coach sharing.
- Show an eligible Premium user the calorie target that applied on a past nutrition day, using the target-only record described below.
- Analyze meal photos, food search queries, recipes, and coach prompts when you request those features.
- Receive and respond to support requests that you choose to submit.
- Confirm Premium access, restore purchases, synchronize subscription status, and administer MyFitLife Family memberships.
- Maintain app security, diagnose errors, prevent abuse, enforce quotas, and improve reliability.
- Comply with legal, safety, and platform requirements.
Service Providers
MyFitLife uses service providers to operate the app, including Google Firebase for authentication, Firestore data storage, and Firebase Storage; Google Cloud services for backend hosting, job processing, and AI processing; Google Vertex AI and Gemini; Google Analytics for optional public-site measurement; Apple App Store and Google Play for subscription purchase and account management; RevenueCat for purchase validation, entitlement access, and subscription lifecycle synchronization; Stytch for connected-app OAuth authorization and token management; OpenAI when you direct MyFitLife to provide data to Codex; Open Food Facts; USDA food data services; and ERPNext/Frappe Helpdesk for support ticket handling when you submit a support request. These providers process information only as needed to support app functionality, security, reliability, and support operations.
Subscriptions and Billing
Apple or Google processes subscription payments through the store account you use. RevenueCat helps MyFitLife validate store purchases and synchronize Premium entitlement, renewal, expiration, cancellation, refund, and billing-issue status. MyFitLife may receive store purchase or transaction identifiers and subscription product and status details, but does not receive or store your full payment card number.
Family Annual Accounts
Family Annual shares Premium access through a MyFitLife-managed household for one owner and up to five invited members. Each person uses a separate MyFitLife account. The owner can create short-lived invite codes, view the limited roster information described above, and remove a member. A member can view their own membership status and leave the household. These controls change household access; they do not transfer or expose another member's nutrition or wellness records.
Family Annual is separate from Apple Family Sharing and Google Play Family Library. MyFitLife uses the owner's eligible subscription entitlement to determine whether a member receives Premium, while authentication and owner-scoped access controls continue to determine whose records can be read or changed.
Codex and Connected Apps
Connecting MyFitLife to Codex is optional. The consent screen identifies the app and requested scopes before access is granted. The initial integration is read-only and can provide only the MyFitLife account goals and preferences, one requested nutrition day, recent progress check-ins, and grocery-list items covered by the scopes you approve.
When you ask Codex to use a MyFitLife tool, the requested tool output is sent to OpenAI to complete your request and is then handled under the terms and privacy choices that apply to your OpenAI account. MyFitLife does not send your password, payment-card data, support tickets, photos, coach conversations, or unrestricted profile record through these connected-app tools.
Photos, Camera, and AI Features
MyFitLife may request camera or photo library access when you choose to scan a food or supplement barcode, attach a food image, or analyze a meal photo. These features are optional. Nutrition estimates generated by AI or food databases may be inaccurate and should be reviewed before relying on them.
When you optionally submit a supplement-label photo, MyFitLife sends the image through its authenticated backend and an AI processing service to extract limited identity clues and search NIH dietary-supplement label records. MyFitLife does not save the uploaded image or extracted label text in your supplement record. If you select a candidate, the saved record contains the chosen label information and your schedule or occurrence data. Avoid including faces, prescription labels, addresses, or unrelated personal information in the image.
Apple Health and Health Connect
Connecting Apple Health or Health Connect is an optional Premium feature. MyFitLife asks for read-only access to steps, active calories, and workout or exercise sessions. Apple Activity Summary and Health Connect Activity Intensity are separate optional presentation reads; declining either does not disconnect the core health source. On the first successful foreground sync, the app requests up to the most recent 30 days. Later app-open or resume foreground syncs request the most recent two days and may be debounced or rate limited. MyFitLife does not write to Apple Health or Health Connect, request background access, or sync health data in the background.
Connecting does not enable either optional use of the data. Calorie adjustment and Coach sharing are separate opt-ins, and both are off by default. If calorie adjustment is enabled, MyFitLife keeps the existing profile calorie target and adds 100% of the synced daily active-calorie total. That provider total may include walking energy when the provider reports it; MyFitLife never estimates calories from step counts. Zero or missing active calories leave the profile target unchanged. Apple Activity rings and Health Connect intensity minutes are informational and never supply an additional calorie total. Workout active-calorie metadata may be shown for context but is not added again, which avoids double counting.
If Coach sharing is enabled, an eligible Premium user may provide Coach Milo with the date, source platform, daily step and active-calorie totals, workout count, workout minutes, base calorie target, active-calorie credit, effective calorie target, and credit percentage. Coach Milo processes this current-day context through the Google Vertex AI and Gemini services disclosed above. Coach Milo never receives historical target-only records.
Future health syncs, current-day Health use, and historical target-history display pause if Premium access expires, but the disconnect-and-delete control remains available. During each health sync, MyFitLife attempts to keep daily aggregate activity, source, time-zone, sync, and applied-target details for no more than 400 local calendar dates, including today. Detailed workout records are limited to the current 30 local calendar dates. Current-day hourly chart values are not stored in daily history. A sync can partially complete before a failure, so cleanup may also be partial; older raw details may remain until a later sync or deletion, and a later sync retries the cleanup.
After a daily aggregate ages out, a paid-only target-only record remains in MyFitLife's fitness daily history with only the fields listed above. It remains until you disconnect Health data, use Health-only deletion, or delete your full account. Turning calorie adjustment off stops current and future activity credit but does not delete earlier target-only records. Revoking MyFitLife's permission in Apple Health or Health Connect also does not delete records already stored by MyFitLife.
Health and Nutrition Information
MyFitLife is a general food logging, fasting, supplement tracking, and nutrition coaching tool. It is not medical advice, a medical device, or a replacement for professional medical care. Consult a qualified professional before making medical or diet changes based on app information. See the MyFitLife Health Disclaimer for more detail.
Data Sharing
We do not sell personal information. We may share information with service providers that operate app infrastructure, when required by law, to protect rights and security, or with your direction.
Joining a MyFitLife Family Annual household shares Premium eligibility, not personal nutrition or wellness records. The owner receives only the limited roster information needed to administer seats; members do not receive access to one another's account data.
Support requests may be routed to IHP Technology LLC's helpdesk system with the details you submit, your account contact email if available, app version, platform, support category, and an internal user or case identifier. MyFitLife does not automatically attach nutrition logs, coach history, progress data, receipts, passwords, payment card numbers, or medical records to support tickets.
Data Security
We use Firebase Authentication, owner-scoped database and storage rules, HTTPS, backend authorization checks, OAuth scopes, short-lived access tokens, service identity controls, rate limits, and operational monitoring to help protect user data. No system can guarantee absolute security.
Data Retention and Deletion
We keep information while needed to provide the app, meet legal requirements, resolve disputes, and maintain security. Signed-in users can delete their full account in the app from More, Settings, Privacy & Safety, Delete Account. Account-deletion instructions are also available on the Account Deletion page.
Deleting an account revokes its Stytch connected-app grants and active connected-app tokens before MyFitLife account data and sign-in access are deleted. You may also revoke a connection from the connected app where that option is available or contact support.
Users can also disconnect a health service from the Health Central page. Disconnecting deletes the raw daily activity summaries, workout summaries, source status, health preferences, hashed source-workout identifiers, derived calorie targets, and historical target-only records stored by MyFitLife and stops future syncs. The web Health-only deletion control removes the same MyFitLife-stored Health data. Neither action deletes source records from Apple Health or Health Connect. These controls remain available if Premium expires.
To prevent delayed billing events from recreating deleted access, MyFitLife retains a one-way hashed account-deletion marker and deletion timestamp. This marker does not contain the account UID, email, profile, nutrition data, connected-app tokens, or billing details.
Support tickets and related correspondence may be retained separately when needed to resolve a request, maintain security, or satisfy legal and operational obligations.
Children
MyFitLife is not intended for children under 13. If we learn that we collected personal information from a child under 13, we will take appropriate steps to delete it.
Changes to This Policy
We may update this policy from time to time. Updates will be posted on this page with a new last-updated date.
Contact
For privacy questions, contact IHP Technology LLC at support@ihptechnology.com.
