1RM.fit1RM.fit
Get Started Free
Back to Home

Privacy Policy

Last updated: April 4, 2026

1. Introduction

Welcome to 1RM.fit ("we," "our," or "us"). We are committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and website (collectively, the "Service").

By using 1RM.fit, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our Service.

1A. Data Controller

The data controller responsible for your personal information is:

1RM.fit

Location: Israel

Email: privacy@1rm.fit

If you are located in the European Economic Area (EEA), you may contact us at privacy@1rm.fit for any data protection inquiries. We are committed to cooperating with EU data protection authorities and complying with their guidance regarding the transfer and processing of personal data.

2. Information We Collect

2.1 Information You Provide

We collect information that you voluntarily provide when using our Service:

  • Account Information: Name, email address, username, and password
  • Profile Information: Age, weight, height, fitness goals, and profile photo (optional)
  • Workout Data: Exercise routines, sets, reps, weight lifted, workout duration, and personal records
  • Progress Photos: Images you upload to track your fitness progress (optional)
  • Communication Data: Messages you send to our support team or feedback you provide

2.2 Automatically Collected Information

When you use our Service, we automatically collect certain information:

  • Usage Data: App features used, session duration, workout frequency, and interaction patterns
  • Device Information: Device type, operating system, unique device identifiers, and mobile network information
  • Location Data: Approximate location based on IP address (we do not collect precise GPS location)
  • Analytics Data: App performance, crash reports, and error logs to improve our Service

2.3 Third-Party Authentication

If you sign in using Google or other third-party authentication services, we receive basic profile information from those services, such as your name and email address, in accordance with their privacy policies.

3. How We Use Your Information

We use the collected information for the following purposes:

  • Provide and Maintain Service: Create and manage your account, track your workouts, and save your progress
  • Improve User Experience: Personalize workout recommendations and analyze usage patterns to enhance features
  • Communication: Send workout reminders, achievement notifications, and service updates
  • Analytics: Generate insights about your fitness progress and training patterns
  • Customer Support: Respond to your questions, requests, and technical issues
  • Security: Detect and prevent fraud, abuse, and security incidents
  • Legal Compliance: Comply with applicable laws, regulations, and legal processes

3A. Legal Basis for Processing (GDPR)

If you are located in the EEA or UK, we process your personal data based on the following legal grounds under Article 6 of the GDPR:

  • Contract Performance (Art. 6(1)(b)): Processing necessary to provide the Service, manage your account, track workouts, and process subscriptions
  • Consent (Art. 6(1)(a)): For analytics cookies (Google Analytics), marketing communications, and optional data collection like progress photos. You may withdraw consent at any time
  • Legitimate Interests (Art. 6(1)(f)): For fraud prevention, security monitoring, service improvement, and customer support — where our interests do not override your fundamental rights
  • Legal Obligation (Art. 6(1)(c)): To comply with applicable laws, regulations, tax requirements, and legal processes

4. Data Sharing and Disclosure

We do not sell your personal information. We may share your information in the following circumstances:

4.1 Service Providers

We may share your information with third-party service providers who perform services on our behalf, such as cloud hosting (Supabase), analytics (Google Analytics), and customer support tools. These providers are contractually obligated to protect your information and use it only for the purposes we specify.

4.2 Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities, such as:

  • Comply with a subpoena, court order, or legal process
  • Protect and defend our rights or property
  • Investigate potential violations of our Terms of Service
  • Protect the safety of users or the public

4.3 Business Transfers

If 1RM.fit is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice in our app before your information is transferred and becomes subject to a different privacy policy.

4.4 With Your Consent

We may share your information with third parties when you explicitly consent to such sharing, such as when you choose to share your workout achievements on social media.

5. Data Security

We implement industry-standard security measures to protect your information from unauthorized access, disclosure, alteration, and destruction. These measures include:

  • Encryption of data in transit using TLS/SSL protocols
  • Encryption of sensitive data at rest
  • Regular security assessments and vulnerability testing
  • Access controls and authentication requirements for our systems
  • Employee training on data protection and security practices

However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

6. Data Retention

We retain your personal information for as long as necessary to provide our Service and fulfill the purposes outlined in this Privacy Policy. Specifically:

  • Account Data: Retained while your account is active and for 90 days after deletion
  • Workout Data: Retained for the duration of your account and deleted upon account deletion
  • Analytics Data: Retained in anonymized form for up to 2 years for service improvement
  • Legal Requirements: Some data may be retained longer if required by law or for legitimate business purposes

7. Your Rights and Choices

Depending on your location, you may have the following rights regarding your personal information:

7.1 Access and Portability

You can access your personal information through your account settings. You may also request a copy of your data in a portable format by contacting us at privacy@1rm.fit.

7.2 Correction and Update

You can update your account information, profile settings, and workout data directly in the app at any time.

7.3 Deletion

You can delete your account and associated data through the app settings or by contacting us. Upon deletion, we will remove your personal information within 90 days, except where retention is required by law.

7.4 Opt-Out of Communications

You can opt out of promotional emails by clicking the "unsubscribe" link in any marketing email. You can manage push notifications through your device settings.

7.5 Data Processing Objection

You may object to certain data processing activities. Contact us at privacy@1rm.fit to exercise this right.

8. Children's Privacy

Our Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@1rm.fit, and we will delete such information from our systems.

9. International Data Transfers

Your information may be transferred to and maintained on servers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ. By using our Service, you consent to the transfer of your information to the United States and other countries.

We ensure that appropriate safeguards are in place for such transfers in compliance with applicable data protection laws, including standard contractual clauses approved by the European Commission.

10. California Privacy Rights

If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: Request disclosure of personal information we collect, use, and disclose
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: Opt out of the sale of personal information (note: we do not sell personal information)
  • Right to Non-Discrimination: Not receive discriminatory treatment for exercising your privacy rights

To exercise these rights, contact us at privacy@1rm.fit. We will verify your identity before processing your request and respond within 45 days as required by law.

Do Not Sell or Share My Personal Information

We do not sell or share your personal information for monetary or other valuable consideration as defined under the CCPA/CPRA. We have not sold or shared personal information in the preceding 12 months. If this practice ever changes, we will update this policy and provide an opt-out mechanism.

11. European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), you have rights under the General Data Protection Regulation (GDPR):

  • Right of Access: Obtain confirmation of data processing and access to your personal data
  • Right to Rectification: Correct inaccurate or incomplete personal data
  • Right to Erasure: Request deletion of your personal data ("right to be forgotten")
  • Right to Restrict Processing: Limit how we process your personal data
  • Right to Data Portability: Receive your personal data in a structured, machine-readable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent for data processing at any time
  • Right to Lodge a Complaint: File a complaint with your local data protection supervisory authority if you believe your rights have been violated

To exercise these rights, contact us at privacy@1rm.fit. We will respond within 30 days as required by GDPR. If you are unsatisfied with our response, you have the right to lodge a complaint with your local EU/EEA data protection authority (e.g., the CNIL in France, the ICO in the UK, or the relevant authority in your country).

11A. Health and Fitness Data

1RM.fit collects data that may be classified as health-related data under certain privacy laws (including GDPR Article 9 "special categories of personal data"). This includes:

  • Workout data (exercises, sets, reps, weight lifted)
  • Body measurements (weight, body fat percentage, circumferences)
  • Progress photos
  • Personal records and fitness goals

We process this data only with your explicit consent, which you provide by voluntarily entering this information into the app. You may delete any or all of this data at any time through the app, or by deleting your account entirely via Profile > Account Settings > Delete Account.

We do not share your health and fitness data with third parties for their own purposes. It is used solely to provide and improve the Service for you.

11B. Brazilian Privacy Rights (LGPD)

If you are located in Brazil, you have rights under the Lei Geral de Proteção de Dados (LGPD):

  • Confirmation and Access: Confirm whether we process your data and access it
  • Correction: Request correction of incomplete, inaccurate, or outdated data
  • Anonymization, Blocking, or Deletion: Request anonymization, blocking, or deletion of unnecessary or excessive data
  • Data Portability: Request portability of your personal data to another service provider
  • Deletion: Request deletion of personal data processed with your consent
  • Information: Obtain information about entities with whom we share your data
  • Revocation of Consent: Revoke your consent at any time

To exercise these rights, contact us at privacy@1rm.fit. We will respond within 15 business days as required by LGPD.

11C. Israeli Privacy Protection

1RM.fit is operated from Israel. We comply with the Israeli Protection of Privacy Law, 5741-1981 and its regulations. As a data subject under Israeli law, you have the right to:

  • Access your personal data held in our databases
  • Request correction or deletion of inaccurate data
  • Object to the use of your data for direct marketing
  • Request information about the types of data we hold about you

Israel has been recognized by the European Commission as providing an adequate level of data protection, facilitating lawful data transfers between the EEA and Israel.

11D. Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach (as required by GDPR)
  • Notify affected users without undue delay if the breach is likely to result in a high risk to their rights
  • Document all breaches, including facts, effects, and remedial actions taken

Notifications will be sent via email to the address associated with your account and/or through an in-app notice. We maintain security incident response procedures and conduct regular security assessments to minimize the risk of breaches.

12. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience and collect usage data:

  • Essential Cookies: Required for basic functionality like authentication and security
  • Analytics Cookies: Help us understand how users interact with our Service
  • Preference Cookies: Remember your settings and preferences

You can control cookies through your browser settings or our cookie consent banner. Analytics cookies are only loaded after you provide consent. You can change your preference at any time by clearing your browser storage and revisiting the site. Disabling essential cookies may limit functionality of our Service.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by:

  • Posting the updated policy in our app with a new "Last Updated" date
  • Sending you an email notification (if you have provided your email address)
  • Displaying a prominent notice in the app

Your continued use of our Service after the effective date of the updated Privacy Policy constitutes your acceptance of the changes.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: privacy@1rm.fit

Support: support@1rm.fit

Website: https://1rm.fit

We will respond to your inquiry within 30 days of receipt.