Skip to content

Your data

Privacy

What stays on your phone, what goes elsewhere, and why.

What stays on your phone

Your profile, your programme, your sessions, your meals, your weight and your measurements are stored in the app, on the device. Without an account, none of it goes anywhere.

The account

A Azetta account (an email address, or signing in with Google or Apple) opens the AI coach, the gyms, the community, Strava and the backup. It is never needed to train. The address is verified when you sign up: a code is sent to you, and the account opens only once it is entered.

The backup

With an account, your data is copied to the server when it changes, so you find it again on another device. On our server this backup is encrypted at rest: the key is not stored with it. It is downloaded and erased from the app — downloading it is also how you take your data with you.

Diagnostic reports

The app automatically sends a technical diagnostic report when it has crashed, frozen or closed by itself: it leaves at the next start, without you doing anything. It holds the reason for the stop and what Android recorded about it (including the technical stack of a “not responding”), the last screens opened, actions and calls to the phone with their duration, the device model, the system version and the app version. If you are signed in, it is attached to your account. Screens appear in it by their name, without any code or identifier, and never what you log: sessions, meals, measurements, messages. It is only used to fix crashes and freezes. You can stop this in Settings › Help › “Send a diagnostic report”, or send one yourself.

The coach and the photos

What you write to the coach goes to the server, which asks a language model. A photo of a machine or a plate travels the same way, to be recognised. Nothing is sent unless you ask for it.

Scanned products

A scanned barcode is looked up in Open Food Facts: only the code leaves, never your log.

Watches and apps

Data imported from Health Connect or from a file stays on the device. Strava goes through your Azetta account, and is disconnected from the app.

The community

What you post on the wall is visible to members: a text, a photo, a session or a meal you chose to share. Weight and measurements are never shared. A post can be deleted, and reporting one takes two taps.

“Near me”: your approximate position

Off by default. If you turn it on, your phone measures your position once, coarsely, and only sends the square of about 5 km by 5 km you are in: your exact position never leaves your phone and is never stored. Other members see no map and no coordinates, only a rounded distance (“less than 5 km away”, “~10 km away”), and only if they share theirs too. Your profile has to be public. Without an update for 30 days the square is erased; it is erased at once when you turn the setting off, make your profile private or delete your account.

This site

The site sets no advertising tracker and does not measure your visit. The only cookies it uses are listed further down, and there are no others.

The contact form

The name, address, topic and message sent from this site are kept in order to answer.

Why, and on what basis

Every use of your data has a purpose and a legal basis. Here is the list, one line per purpose.

  • Running the app, your account and the backup — performance of the contract between us.
  • Recording your weight, measurements, workouts and meals — your explicit consent, given in a separate box when you sign up, because this is health data.
  • Answering your questions and recognising your photos — your consent, given each time you send one.
  • Posting on the wall and following other members — your consent, given each time you post.
  • “Near me”, to find members around you — your consent, given by turning the setting on and withdrawn by turning it off.
  • Connecting Strava, a watch or Health Connect — your consent, which you can withdraw whenever you like.
  • Taking payment for the subscription, issuing invoices and keeping them — performance of the contract, then a legal obligation.
  • Answering a message sent from this site — our legitimate interest in replying to you.
  • Keeping the service working and preventing abuse: technical logs, rate limiting — our legitimate interest.
  • Fixing the app's crashes and freezes from the diagnostic reports — our legitimate interest; you object by turning their sending off in the settings.

How long

Nothing is kept without a reason, and nothing is kept forever.

  • The account and what it holds — profile, workouts, runs, meals, weight, measurements, posts, backup: as long as the account exists. Deleting it erases them the same day, with no delay and no bin.
  • Your approximate position for “Near me”: at most 30 days after your last update, then erased; at once if you turn the setting off.
  • Your conversations with the coach and the photos you send it: not kept. The server passes them on and answers; it keeps only one accounting line per call — date, model, token count, cost — without the content. When the account is deleted, that line loses its link to you and becomes anonymous.
  • Messages from the contact form: 24 months after the reply.
  • The server's technical logs (IP address, time, page requested): 30 days at most.
  • Invoices and proof of payment: 10 years, because accounting law requires it (art. 958f of the Swiss Code of Obligations).
  • Server backups: 30 days at most, overwritten in turn.
  • Diagnostic reports: 90 days, then erased.

Who else sees them

Nobody, apart from the services below, and each one only gets the part it needs. Your data is never sold, rented or traded.

  • Infomaniak Network SA, Geneva, Switzerland — hosts the site, the server, the database and the backups, and sends our emails. It therefore stores everything, and does nothing with it.
  • The provider of the language model that answers the coach and reads your photos — Anthropic (Claude), Google (Gemini), OpenAI, xAI or Mistral, depending on the model in service. It receives your question and the photo, never your name or your email address, and its API terms forbid it from using them to train its models.
  • Open Food Facts — receives the barcode you scan, and nothing else: not your account, not your diary.
  • OpenStreetMap — draws the map behind the gyms and the routes. Every tile shown is requested from it: it sees your IP address and the area you are looking at, never your account. If we change map provider, this line changes with it.
  • OpenRouteService (Heidelberg, Germany) — works out the loop offered when you do not know where to run. It receives your starting position and the distance you want, nothing else, and only when you ask.
  • Pixabay — only if you look for a profile picture on the web. Our server passes on the words you type and downloads the photo you choose. The thumbnails of the results load straight from Pixabay: it sees your IP address while you browse them, never your account.
  • Strava — only if you connect your account. It then receives the access request, and sends us back the activities you allow.
  • Google and Apple — only if you sign in with them. They hand the app an identity token, which our server verifies: it gives us your email address and your name, and they know that you use Azetta.
  • The App Store and Google Play — only to download the app. No payment goes through them.
  • Stripe — only for a payment made on this site. It receives your email address and your card details, which we never see.
  • An authority or a court, if the law obliges us — and only what is asked for.

Outside Switzerland and the EU

The site, the server, the database and the backups stay in Switzerland. The language model, Strava, Google, Apple and Stripe process part of the data elsewhere, notably in the United States. Those transfers rely on the European Commission's standard contractual clauses, recognised by Switzerland, together with the security commitments of each contract. You may ask us for a copy of those clauses.

How it is protected

Everything travelling between your device and the server goes over an encrypted connection (TLS). Passwords are never kept in the clear: only an irreversible hash is. The keys of outside services are encrypted in the database, and so is your backup, at rest, on the server's disk. Access to the server and the database is limited to the people who need it, and is logged. No system is perfect: if a breach were likely to harm you, you would be told, and so would the supervisory authority.

Minimum age

Azetta is for people aged 16 and over. Below that, do not open an account. If we are told about the account of someone younger, it is deleted along with its data.

What we do not do

No decision with a legal or comparable effect is taken about you automatically: the plan the app builds and what the coach answers are training advice, not decisions. There is no advertising, no advertising profiling, no resale and no trading of your data.

Your rights

Wherever you live, you have the following rights over what is kept about you:

  • Know what is kept, and get a copy of it.
  • Have anything inaccurate or incomplete corrected.
  • Have your data erased and your account deleted — yourself, from the app (Account → Delete my account) or from the site (My account), without writing to us.
  • Ask for the processing to be restricted while a disagreement lasts.
  • Receive your data in a machine-readable format: your backup is downloaded from the app, and that is your export. Or have it sent elsewhere.
  • Object to processing based on our legitimate interest.
  • Withdraw a consent whenever you like — the coach, the posts, Strava. What was done before stays valid.

One address for all of it: the one on the contact page. The answer comes within 30 days, and costs nothing. We may ask you to show that the account is yours before we erase or send anything. Contact

Complaining to an authority

If our answer does not satisfy you, you can complain to a supervisory authority. In Switzerland: the Federal Data Protection and Information Commissioner (FDPIC / PFPDT), Feldeggweg 1, 3003 Bern. In the European Union: the authority of the country where you live or work — the list is kept by the European Data Protection Board (edpb.europa.eu). In the United Kingdom: the Information Commissioner's Office.

Cookies

This site sets three, and not one more:

  • fitcoach_lang — remembers the language you chose, so the right one shows next time. One year.
  • fitcoach-session — keeps the thread of your visit and keeps you signed in. Two hours without activity and it expires.
  • XSRF-TOKEN — the token proving that a submitted form really came from this site. Same lifetime as the session.

All three are strictly necessary: without them, no language, no sign-in, no form. That is why there is no banner to accept — consent is only required for cookies the service could do without. There is no analytics, no advertising tracker, and no social button following you around.

Deleting your account

How to ask for your account and everything in it to be erased, what goes, what stays and how long it takes: Delete my account

Who is responsible for your data

Sami Zaghbani, route de Mon-Idée, 1226 Thônex, Switzerland — contact@fitcoach.com. Write to this address to learn what is kept about you, to have it corrected or erased.

Last updated: 2026-10-06. · Terms · Delete my account · Legal notice