Connected Device & Partner Data Policy
This policy is written for the review teams at device and platform partners, and it binds us. It is the document to read to answer, quickly: who we are, whether consent is real and revocable, whether deletion happens, whether data is sold, and whether it is used to train models.
1. WHO WE ARE
FITTSO is a consumer health, fitness, and performance platform. A person connects devices they already use; FITTSO presents one private view with FITTSO's own scoring and coaching on top.
Platform operator and partner-API licensee: FITTSO Operations, Inc., an Alaska corporation, entity 10355798.
Affiliated data custodian: FDS, Inc., an Alaska corporation — holds platform data and IP and licenses them to the operator.
Consumer application: provided free to the public by FITTSO Foundation, Inc., an Alaska nonprofit, under licence.
Correspondence: zac.s@fittso.app. Trust page: fittso.app/partners. Privacy policy: fittso.app/privacy.
FITTSO is not a HIPAA covered entity and runs no HIPAA workflow. Minimum age 18, enforced server-side at signup.
2. SCOPE
"Partner Data" means any data received from a connected device, platform, or third-party service, plus any value derived from it. This policy binds FITTSO Operations, Inc., FDS, Inc., FITTSO Foundation, Inc., every employee and contractor, and every service provider. It is reviewed at each partner onboarding and at least annually.
3. CONSENT
3.1 Consent precedes collection. No Partner Data is collected until the user has accepted the current policies and has affirmatively authorized the specific connection. Connection flows are blocked in software until a current consent record exists.
3.2 Per recipient and per purpose. Authorizing FITTSO to collect is one decision. Authorizing a named professional to view a summary is a separate decision. No bundled or implied consent.
3.3 Purposes are a closed set: service to the user; a professional the user has named; a service provider acting on FITTSO's behalf; security and fraud prevention; legal compliance.
3.4 Some purposes have no consent path. Advertising, marketing, third-party profiling, brokerage, sale, and model training on Partner Data are not available under any circumstances. No setting is offered, because offering one would imply availability.
3.5 Revocation. Any source or any professional, at any time, in-app, without explanation. Immediate.
3.6 Record. Every grant and revocation is recorded append-only with timestamp, policy version, scope, and the interaction that produced it. The complete history is available from a single ledger.
4. NO SALE, NO REDISTRIBUTION
FITTSO does not sell, rent, license, trade, or disclose Partner Data to any third party for consideration. There are two disclosure paths and no others.
4.1 A professional the user has named. A read-only summary view — never raw payloads, never partner-proprietary scores or indices, never credentials. The professional is bound by written terms no less protective than FITTSO's own partner obligations: training prohibition, 72-hour deletion, 24-hour incident notice. Professionals pay for licensed software access priced by seats and declared practice capacity; the fee does not vary with the number of authorizations, the volume of data, or the frequency of access. FITTSO does not meter, bill, or price by authorization, record, or data volume.
4.2 Service providers. Processors acting on FITTSO's behalf, under written terms at least as protective as this policy, listed in the Privacy Policy, with no independent right of use.
No aggregated, de-identified, or anonymized dataset is transferred to any broker, ad platform, or analytics purchaser. Aggregation creates no exception. FITTSO makes no de-identification claim about any dataset until a named, auditable standard has been adopted and published here.
5. NO MODEL TRAINING ON PARTNER DATA
5.1 Absolute. Partner Data is excluded from every training, fine-tuning, evaluation, and benchmark dataset — raw, derived, and any joined record that includes a partner-sourced column. No user consent unlocks this.
5.2 Enforcement. A non-nullable source label is written at ingestion. Training datasets are assembled from an explicit allow-list of sources; an unlisted source is excluded by default. We do not use exclusion filters, because a filter fails silently when a new source is added and an allow-list fails closed.
5.3 Inference is not training. The assistant layer reads and returns; it does not write its inputs to any store that feeds a training export. Third-party inference providers are bound by written terms that prohibit training on and retention of the data.
6. IMAGES
Food photographs and route imagery are user-created, not partner-received; they form a separate category with its own consent.
6.1 Captured and processed only with explicit, separately granted consent.
6.2 Processed on infrastructure FITTSO operates or contracts under section 4.2; not transmitted to any vendor with a right to retain them or to train on them.
6.3 Never joined with Partner Data for any training purpose. A named professional authorized for the nutrition category may view food images in the summary view.
6.4 A user may attach an image to their own profile — a separate, user-initiated disclosure governed by the visibility they select.
7. RETENTION AND DELETION
7.1 Disconnecting a source. The access token is revoked at the provider and every record from that source is purged within 72 hours, regardless of any account-level grace period.
7.2 Deleting an account. Requested in-app. A 30-day reversible grace period, then all personal data is purged except legally required records — consent records, security audit logs, trust-and-safety records — held for stated periods and used for no other purpose.
7.3 Scope of purge. Primary tables, derived and rollup stores, object storage, assistant memory and conversational state, search indexes. Backups are overwritten on a rolling cycle and are not restored to production after a deletion.
7.4 Verification. A scripted test proves absence by direct query against every enumerated store, and is run before each release that touches the purge path.
7.5 Deactivation is not deletion. They are distinct operations, described separately to the user and never presented as interchangeable.
7.6 Retention tiers. Wearable streams, body-composition readings, and nutrition logs are held at full resolution for 30 days, consolidated weekly through day 90, and only the consolidated form persists after that. Raw provider payloads are pruned nightly after normalization.
8. SECURITY
Encryption in transit and at rest; physiological records sealed under a per-account key with an hourly zero-plaintext check. Row-level security, deny-by-default, on every table holding user data. Least-privilege staff access. Credential rotation on schedule and on suspicion. A documented incident-response plan; partner notice within 24 hours of discovery of an incident affecting that partner's data. Detail at fittso.app/legal/security.
9. ATTRIBUTION AND MARKS
Every displayed measure carries its source. Partner names appear for compatibility and provenance only. No partner marks are used without written permission, and no endorsement is claimed. FITTSCORE, MacroSnap, and FITTSO Mapping are FITTSO's own; partner-proprietary scores and indices are not displayed, reproduced, or resold.
10. CLAIMS
No clinical or diagnostic claim on any surface. FITTSO is not a medical device. Consumer-device values are presented as what they are.
11. PARTNER-SPECIFIC TERMS
Where a device partner requires handling stricter than this baseline, that partner receives its own named subsection here, drafted from that partner's own agreement, from the day its integration goes live. Data from such a partner is held to the protected tier: attribution to the source on every display; no income derived from the data without the partner's written permission; deletion when the user disconnects the source or deletes the account; breach notice to the partner inside the partner's own window; and any AI processing of the data disclosed in the Privacy Policy. No partner subsection appears here until that integration is live, because naming a partner implies a relationship.
12. COMMITMENTS IN SUMMARY
- Consent before collection, per recipient and per purpose, revocable in-app.
- No sale, rental, licensing, or brokerage of Partner Data — aggregated or otherwise.
- No model training on Partner Data — provenance label plus allow-list.
- No advertising, marketing, or third-party profiling; no consent path exists.
- 72-hour per-source purge on disconnect; 30-day account purge on deletion.
- 24-hour partner incident notice.
- Professional access is the only third-party path — consent-gated, named, logged, revocable, read-only, summary-only.
- Downstream recipients bound by no-less-protective written terms.
- Source attribution on every measure; no partner marks without permission.
- Reviewed at every partner onboarding and at least annually.
Version 2026-09-12.1, effective September 12, 2026. Questions: zac.s@fittso.app.