Privacy Policy
The short version
MakeItFit connects personal trainers and their clients around a shared schedule. We collect the minimum needed to make that work: your sign-in account, profile, sessions, agreements, workouts, and payments, plus the minimum calendar data needed for busy/free scheduling and optional session write-back when you connect a calendar. We do not sell data or run third-party advertising. Source calendar event titles, notes, locations, and attendees are not copied to our servers.
What we collect
- Account and authentication — email address, Supabase Auth account ID, and linked authentication identifiers for Sign in with Apple, Google sign-in, email magic-link sign-in, or email-and-password sign-in where a password has been set.
- Profile — display name, optional avatar, trainer or client role, working hours and preferences you set.
- Coaching data — training agreements, booked sessions, booking and reschedule requests, session feedback, workout plans and exercises, workout completion logs, and optional client metrics you or your trainer record.
- Calendar availability — if you connect Apple Calendar, Google Calendar, or Microsoft Outlook/Microsoft 365 Calendar, the app reads busy/free time spans to prevent double-booking. Source event titles, notes, locations, and attendees are not copied into our systems and are never shown to your trainer or client; counterparts only ever see “Busy”.
- Calendar write-back — if you enable it, confirmed MakeItFit sessions are written into your own calendar. Turning it off removes upcoming events the app created.
- Digital subscriptions — trainer plan purchases made in the iOS app use Apple’s StoreKit and In-App Purchase. We receive transaction and entitlement references needed to unlock and restore the plan; Apple handles billing details.
- Person-to-person session payments — client payments for real-world training sessions use Stripe Connect and are paid to the trainer’s connected Stripe account, less the disclosed MakeItFit platform fee. Stripe’s processing costs are paid by MakeItFit and are not deducted from the trainer payout. If you explicitly choose to save a payment method for agreed late-cancellation charges, Stripe stores that payment method and MakeItFit stores the Stripe reference and your consent status. We store payment, payout, refund, and dispute references, never full card numbers.
- Push tokens — a device token so booking requests and confirmations can notify you. You can disable notifications in iOS Settings at any time.
- Diagnostics — Apple MetricKit performance aggregates and crash/hang diagnostics, such as timing data and stack frames, to keep the app stable. They do not include message or calendar-event content. A signed-in diagnostic may be linked to an account identifier; diagnostics received before sign-in are anonymous.
Authentication and account security
MakeItFit uses Supabase Auth to create and authenticate accounts. Sign in with Apple and Google sign-in provide an account identifier and, depending on what you allow the provider to share, an email address or name. Email magic links authenticate through a one-time link. Email-and-password sign-in is available only for accounts where a password has been set; Supabase verifies the password and MakeItFit does not receive or store it in readable form. We never receive your Apple ID or Google Account password.
The app stores the Supabase session access token and refresh token in device-only iOS Keychain storage so you can remain signed in. A fresh Apple, Google, magic-link, or password confirmation may be required before permanent account deletion. Authentication tokens used only for that deletion confirmation are kept in memory for the deletion attempt and are not stored as profile data.
Where it lives
App data is stored with Supabase (hosted in the EU, eu-central-1) with row-level security so each account can only read what it owns or is a party to. Digital subscription billing happens through Apple StoreKit. Session payments and trainer payouts run through Stripe Connect. Apple Calendar access is handled on-device through EventKit. Google and Microsoft OAuth access and refresh tokens for connected calendars are stored in the iOS Keychain on your device, not in our database. Supabase authentication session tokens are also stored in the iOS Keychain. Selected calendar identifiers remain in the app’s local database on your device. Supabase stores stripped busy projections and cloud write-back mirror identifiers where those features are enabled.
What we never do
- No selling or renting of personal data.
- No third-party advertising or cross-app tracking.
- No copying of source calendar event titles, notes, locations, or attendees into our servers.
Apple and Microsoft calendar data
Apple Calendar access uses Apple EventKit permission on your device. EventKit identifiers for MakeItFit-created events remain on that device. For Microsoft Outlook or Microsoft 365, MakeItFit requests delegated Calendars.ReadWrite access so it can read only the fields needed to calculate busy/free time and, when you enable write-back, create, update, or remove MakeItFit session events. Microsoft OAuth tokens remain in the iOS Keychain. For both providers, source event titles, notes, locations, and attendees are not sent to MakeItFit servers or shown to another user.
Google user data (Google Calendar)
If you choose to connect Google Calendar, MakeItFit accesses your Google user data only through Google’s official Calendar API, after you grant permission on Google’s consent screen. MakeItFit’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Google Workspace APIs will adhere to that policy, including the Limited Use requirements.
- Google API scopes requested — MakeItFit requests
https://www.googleapis.com/auth/calendar.calendarlist.readonlyto list the calendars you can select,https://www.googleapis.com/auth/calendar.events.freebusyto read only busy/free time spans from calendars you can access, andhttps://www.googleapis.com/auth/calendar.events.ownedto create, update, or delete MakeItFit session events on Google calendars you own. MakeItFit writes these events to your primary calendar and does not request permission to edit calendars owned by another person or organisation. - How we use it — the app reads busy/free time spans from your Google Calendar solely to detect scheduling conflicts, prevent double-booking, and show which of your calendars can feed availability. Only if you enable write-back, MakeItFit creates, updates, or removes the MakeItFit session events it itself created in your calendar. That is the only use. We do not use Google user data for advertising, and we do not use it to develop, improve, or train generalised AI or machine-learning models.
- What we store — your Google OAuth tokens are stored in the iOS Keychain on your device, never on our servers. If you select specific calendars, the selected Google calendar IDs are stored in the app’s local database on your device so your choice survives app restarts. When availability sharing is on, stripped busy/free time spans may be stored as server-side busy projections so your approved trainer or client can avoid double-booking without seeing event details. If write-back is on, we store the Google event ID, session ID, provider, start/end times, and MakeItFit session title needed to update or remove the event later. Calendar event notes, attendees, locations, and non-MakeItFit source event titles are never read into or stored on our systems. MakeItFit does not create aggregated or anonymised datasets from Google user data.
- Who we share, transfer, or disclose it to — we do not sell Google user data and we do not disclose raw Google Calendar content to other users. Supabase stores the busy-projection and write-back mirror records described above as our database processor. Vercel serves the website but does not receive Google Calendar data from the app; it may keep standard, short-lived website request logs. The only thing another MakeItFit user (your trainer or client) can see is that a time slot is “Busy” or bookable, and only when you allow availability sharing; they never see the underlying Google event. We would disclose data only where required by law, and Google user data would never be transferred as part of a merger, acquisition, or sale of assets without your explicit prior consent.
- How it is protected — all communication with Google and with our servers is encrypted in transit with TLS (HTTPS); OAuth tokens live in the hardware-backed iOS Keychain with device-only storage; our database is encrypted at rest and guarded by row-level security so users can only read records they own or records intentionally shared through an active trainer-client agreement; and the app requests only the minimum Google scopes needed for calendar availability and optional write-back.
- Human access — no human at MakeItFit reads your Google user data, except with your explicit permission for a support request, where necessary for security or abuse investigation, or where required by law.
- Revoking access — disconnect Google Calendar at any time in the app, which deletes its local tokens and stops MakeItFit from accessing Google Calendar on that device. To revoke the Google provider grant itself, remove MakeItFit’s access through Google Account permissions. Provider revocation stops access for every device holding that grant.
Website analytics and operational logs
Vercel Web Analytics provides anonymised, cookie-free website usage statistics. Vercel creates a short-lived visitor hash from request information and discards the visitor session after 24 hours; aggregate analytics may remain in our Vercel project according to its retention settings. Vercel and Supabase also keep request, security, function, and diagnostic logs for service operation, abuse prevention, and debugging. We do not combine these logs with advertising profiles.
Sharing between trainer and client
MakeItFit is a two-sided product: your counterpart sees what the relationship needs — agreements and workout plans you share, sessions and workout completions you record together, requests you send each other, your display name and avatar, and busy/free availability outcomes. They never see your raw calendar.
Retention and deletion
- While your account is active — account, authentication identity, profile, agreement, booking, workout plan, exercise, completion, message, review, and payment-reference data is kept for the service and the trainer-client relationship.
- Calendar data — disconnecting Google Calendar removes its local tokens and saved calendar choices from the device and stops future app access from that device. To revoke the Google provider grant itself, use Google Account permissions. During disconnect, MakeItFit attempts to remove future Google Calendar events it created before local credentials are cleared. Busy/free projections are replaced whenever calendars refresh and deleted when availability sharing is turned off; disconnect and account deletion delete related cloud event-mirror records. Past events may remain in your calendar history if provider removal fails or you choose to keep them. Disconnecting Microsoft Outlook removes that provider’s tokens from the device. Account deletion also removes server-side calendar connections, private calendar-feed tokens, push tokens, busy projections, and cloud event-mirror records, and clears calendar event identifiers from retained session records.
- Diagnostics and logs — retained only for the operational or security period configured with Apple, Supabase, and Vercel, then deleted or aggregated. We review retention settings and do not keep raw diagnostic payloads as account history.
- Account deletion — Avatar menu → Account → Delete account requires a recent confirmation with a sign-in method already linked to the account. After successful cleanup, MakeItFit revokes linked Sign in with Apple and Google sign-in grants, deletes the Supabase Auth identity, removes the local Supabase session access and refresh tokens, and disconnects Google or Microsoft calendar tokens on the device. It also marks the profile deleted; removes the display name, avatar, home town, specialisation, location data, private calendar-feed and push tokens, messages, private workout plans, exercises, and completion history; and stops future push and calendar sharing.
- Records that remain after deletion — shared agreements and sessions, payment, payout, subscription, refund, dispute, audit, moderation, and safety records are retained in de-identified or minimised form where the other party or applicable law still requires them. Deleting a MakeItFit account does not cancel an Apple subscription; cancel it in Apple subscription settings to stop future renewals.
- Legal records — payment, payout, refund, dispute, tax, and bookkeeping records are retained for the period required by applicable law, with identity minimised or dissociated where possible. Other data is deleted or anonymised when its purpose ends.
Your rights (GDPR)
You can request access, correction, export, or erasure of your data at any time. Contact us at daniel@garden-stack.com and we will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority; for Belgium that is the APD/GBA (dataprotectionauthority.be).
Controller and contact
The data controller is Fontaine Farm SRL, Brussels, Belgium. For any privacy question, email daniel@garden-stack.com.
Changes
If this policy changes materially we will update this page and note it in the app. The effective date above always reflects the current version.