PTG Fitness Privacy Policy
PTG Fitness ("PTG Fitness," "we," "us," or "our") provides a fitness, nutrition-planning, and wellness application and related websites (collectively, the "Services"). This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information through the Services.
This policy is a privacy notice, not a request for consent. Where consent is required—such as for Apple Health access, optional AI processing, advertising personalization, or certain uses of sensitive data—we ask separately through the app or device controls. Refusing an optional use does not prevent you from using unrelated features.
1. Scope and Controller
This policy applies to the PTG Fitness app, ptgfitness.com, and other Services that link to it. It does not govern third-party websites or services that you choose to visit outside the Services.
PTG Fitness is the controller of the personal information described in this policy. Privacy requests may be sent to support@ptgfitness.com.
2. Information We Collect
A. Account and profile information
- Email address, authentication records, user ID, and account dates.
- Name, age, sex or gender, height, current and target weight, activity level, fitness experience, goals, equipment, schedule, dietary preferences, restrictions, and coaching preferences.
B. Health, fitness, nutrition, and wellness information
- Workout plans, exercises, sets, repetitions, duration, and workout logs.
- Meal plans, meal logs, meal photos, calorie and nutrient information.
- Hydration, weight, sleep, step, energy, and exercise-minute records.
- Estimates and inferences generated from those records, such as calorie targets, nutrition estimates, progress summaries, and recommendations.
This information may be consumer health data or sensitive personal data under applicable law. Our separate Consumer Health Data Privacy Policy provides the additional disclosures required by U.S. consumer-health privacy laws.
C. Apple Health and device permissions
If you enable Apple Health, PTG may read the categories you authorize, including steps, active and resting energy, exercise minutes, and sleep metrics. Apple Health permissions are optional and can be changed in iOS Settings. PTG does not use Apple Health data for advertising, disclose it to data brokers, or sell it.
If you grant camera or photo-library access, PTG accesses only the images you choose to capture or upload. If you enable notifications, we process a push token, notification preferences, timezone, app and iOS version, and delivery-related timestamps.
D. AI inputs and outputs
AI features are optional. Before PTG sends personal information to OpenAI, the app identifies OpenAI, describes the relevant data, and asks for permission. If you allow the processing, PTG sends only the information needed for the feature you request. Depending on that feature, this may include age, height, weight, goals, workout and nutrition records, authorized Apple Health metrics, meal details or photos, and messages you submit to the PTG Assistant.
OpenAI processes this information to return requested plans, estimates, analysis, or assistant responses. OpenAI's API terms state that API content is not used to improve its models unless the API customer expressly opts in. Default abuse-monitoring logs may be retained for up to 30 days unless a longer period is legally required. You can change PTG's AI permission under Profile > Privacy & Data.
E. Purchases and subscriptions
Apple processes App Store purchases. PTG does not receive full payment card details. We receive limited transaction and entitlement data, such as product, plan, subscription status, renewal state, transaction ID, and billing-period dates.
F. App, website, and advertising data
We and our service providers may process IP address, device and app version, device or advertising identifiers, crash and performance data, ad impressions and interactions, feature usage, and other diagnostic information.
The free tier uses Google AdMob. The Google Mobile Ads SDK may collect IP address (which can estimate general location), device identifiers, advertising data, app interactions, crash logs, and performance data for ad delivery, measurement, fraud prevention, and—where permitted—ad personalization. PTG does not provide Google with your account profile, Apple Health data, meal or workout records, meal photos, or Assistant messages for advertising.
G. Support and other information you submit
We process support messages, feedback, attachments, and related metadata when you contact us or submit content through the Services.
3. How We Use Information
- Provide, personalize, maintain, and secure the Services.
- Create accounts and sync information across authorized devices.
- Generate requested meal, workout, nutrition, and progress features.
- Provide optional AI features after the required permission.
- Deliver reminders and notifications you enable.
- Process subscriptions, restore purchases, and manage entitlements.
- Provide support, troubleshoot errors, and prevent fraud or abuse.
- Measure and improve performance and feature reliability.
- Serve and measure ads on the free tier as described below.
- Comply with law and enforce our agreements.
4. Advertising, Sale, Sharing, and Targeted Advertising
PTG does not sell personal information for money. However, when an adult user permits personalized advertising, the disclosure of advertising identifiers and app/ad interaction data to Google and advertising partners may be treated as a "sale," "sharing," "targeted advertising," or "cross-context behavioral advertising" under some U.S. state laws.
We treat that activity accordingly. It occurs only after applicable consent and, on iOS, only where Apple's App Tracking Transparency permission allows tracking. If you decline or revoke permission, PTG requests limited, non-personalized, or otherwise restricted ads where supported. You can change ATT permission in iOS Settings and, where available, use Profile > Settings > Ad Privacy Choices.
PTG does not sell consumer health data and does not disclose Apple Health data, meal or workout records, health goals, meal photos, or Assistant messages for advertising.
5. Legal Bases for EEA and UK Processing
Where the GDPR or UK GDPR applies, our legal bases include:
- Contract: providing account, planning, logging, subscription, and support features you request.
- Consent: optional permissions and uses, including Article 9(2)(a) explicit consent where required for health or other special-category data, AI sharing, and personalized advertising.
- Legitimate interests: security, fraud prevention, service reliability, and proportionate product improvement.
- Legal obligation: records or disclosures required by applicable law.
You may withdraw consent at any time without affecting processing that occurred before withdrawal. A privacy policy or acceptance of the Terms is not used as a substitute for explicit consent.
6. How We Disclose Information
- Supabase: authentication, database, storage, and server functions.
- OpenAI: optional AI features after the permission described above.
- Google AdMob: advertising delivery, measurement, security, and permitted personalization; no consumer health data is provided for advertising.
- Edamam: recipe search using meal queries, dietary filters, calorie targets, and a pseudonymous service identifier where used.
- Open Food Facts: barcode and food-search queries; PTG does not send account or health records with those lookups.
- Apple: App Store transactions, notifications, and user-controlled Apple Health integration.
- Authorities or professional advisers where required by law or reasonably necessary to protect rights, safety, and security.
- A successor in a merger, acquisition, financing, reorganization, or sale, subject to applicable notice and privacy obligations.
Service providers may process information only for contracted services or other legally permitted purposes. Third-party sites you choose to visit are governed by their own policies.
7. Retention and Deletion
We retain account and service records while your account is active and as needed to provide requested features. We retain support, billing, security, tax, and legal records only for the applicable operational or legal period.
After a verified deletion request, we delete or de-identify covered information from active systems without undue delay and within the period required by applicable law. Where permitted, deletion from encrypted backups may occur when the backup is overwritten or restored; consumer health data in backups will be deleted within no more than six months where Washington law applies. We also direct applicable processors and recipients to honor deletion requests.
8. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. No system is completely secure. Contact us promptly if you believe your account or information has been compromised.
9. Your Choices and Rights
Depending on where you live, you may have the right to:
- Access or confirm the information we process about you.
- Correct inaccurate information.
- Delete information, subject to lawful exceptions.
- Receive a portable copy of certain information.
- Withdraw consent or object to or restrict certain processing.
- Opt out of sale, sharing, targeted advertising, or certain profiling.
- Appeal a denied privacy request.
- Not receive unlawful discrimination for exercising a privacy right.
Use in-app account deletion and privacy controls where available, or email support@ptgfitness.com. Include "Privacy Request" in the subject and describe the request. We may verify your identity and authority before acting. We respond within the period required by applicable law, generally within 30 to 45 days. To appeal, reply with "Privacy Appeal" and the reason you disagree.
10. U.S. State and Consumer Health Rights
U.S. state law may provide the rights described above. Because health and wellness data can receive additional protection outside HIPAA, PTG also publishes a dedicated Consumer Health Data Privacy Policy. PTG is a consumer wellness service and is not a healthcare provider or health plan; information in the Services may therefore not be protected by HIPAA even when other privacy laws apply.
11. EEA and UK Rights and Representatives
EEA and UK users may also have rights to object, restrict processing, complain to a supervisory authority, and receive information about international-transfer safeguards.
PTG Fitness is based in the United States and does not have an establishment in the EEA or UK. Because the Services are available there, PTG is arranging the EU/EEA and UK representative appointments addressed by Article 27. Appointment details are not yet available and will be published here when the written appointments take effect. Until then, users and supervisory authorities may contact PTG directly at support@ptgfitness.com. This status disclosure does not limit any right or legal obligation.
12. International Transfers
Information may be processed in the United States and other countries where our providers operate. Where required, we use recognized transfer safeguards, such as the European Commission's Standard Contractual Clauses, the UK Addendum, adequacy decisions, or another lawful transfer mechanism.
13. Children and Teens
The Services are not directed to children under 13, or a higher minimum age where required. Users under the age of majority may use the Services only with a parent or guardian's permission. PTG applies age-appropriate advertising restrictions based on the age provided in the profile and does not knowingly use minors' data for personalized advertising where prohibited. Contact us if you believe a child provided information without the required permission.
14. Changes to This Policy
We will post updates with a revised date and provide additional notice for material changes where required. We will obtain new consent before using consumer health or other sensitive data for a materially different purpose when law requires it.
15. Contact
PTG Fitness
Privacy & Data Inquiries: support@ptgfitness.com