Privacy Policy

Effective date: April 1, 2026

Last updated: April 1, 2026

About This Policy

This Privacy Policy explains how Solo Innovations LLC (“Solo Innovations,” “we,” “us,” or “our”) collects, uses, shares, and protects your personal information when you use the Solo Fitness mobile application (“Solo Fitness” or “the app”). Solo Innovations LLC is the data controller responsible for your personal data.

This policy applies to all users, including residents of the European Union/European Economic Area, California, Washington State, and all other jurisdictions with applicable privacy laws.

Solo Innovations LLC Seattle, Washington, United States Email: privacy@soloinnovationshq.com


Information We Collect

Account and Profile Information

When you create an account, we collect:

Health and Fitness Data (Sensitive Data)

With your explicit permission, we collect health and fitness data from Apple HealthKit (iOS) and Google Health Connect (Android), including:

We also write certain data back to HealthKit/Health Connect with your permission, including workout sessions, active calories, distance, water intake, caffeine, menstrual flow, and mindfulness sessions.

Data from Connected Devices

If you connect third-party devices, we sync data from their official APIs:

Device sync occurs automatically every 30 minutes via our servers. You can disconnect at any time.

Location Data (Sensitive Data)

GPS route data is stored with your workout record. You control whether workouts are public or private.

Nutrition Data

Social and Communication Data

Journal and Wellness Data

Device and Technical Information

Subscription and Payment Data


How We Use Your Information

We use your information for the following purposes, along with the legal basis for each (as required by GDPR):

PurposeLegal Basis
Provide and maintain your Solo Fitness account and core featuresPerformance of contract
Sync and display health, fitness, and workout dataPerformance of contract; your explicit consent (for sensitive data)
Power AI-driven coaching, recommendations, and health pattern detectionYour explicit consent
Scan food and menu images for nutritional analysisPerformance of contract; your explicit consent
Track workouts with GPS route mappingYour explicit consent
Sync data with Oura, Garmin, and WHOOPYour explicit consent
Send notifications about goals, streaks, and achievementsLegitimate interest; your consent (for marketing)
Moderate social content for safetyLegitimate interest
Process subscriptions and manage billing statusPerformance of contract
Diagnose bugs and improve app stability via error logsLegitimate interest
Improve the app and develop new featuresLegitimate interest
Respond to support requestsPerformance of contract
Comply with legal obligationsLegal obligation

How We Use Artificial Intelligence

Solo Fitness uses AI to provide personalized coaching, workout recommendations, health pattern detection, nutrition analysis, and food/menu scanning.

What data AI receives

To generate personalized responses, our AI features send a context summary to our AI provider that may include:

Important: This data includes personally identifiable and sensitive health information. It is sent securely to our AI provider to generate responses tailored to you.

AI providers

AI data protections


Third-Party Services

Solo Fitness integrates with the following third-party services. We share only the minimum data necessary for each service to function. We do not sell your personal data to any third party.

ServiceData SharedPurpose
SupabaseAll core app dataDatabase hosting, user authentication, file storage, real-time features
Google Gemini AIHealth context, journal notes, food/menu images (see AI section above)AI-powered coaching, analysis, and recommendations
OpenAISocial post text and photo URLsAutomated content moderation
RevenueCatAnonymous user ID, subscription statusSubscription and entitlement management
Apple HealthKitHealth and fitness data (with your permission)Bidirectional health data sync
Google Health ConnectHealth and fitness data (with your permission)Bidirectional health data sync (Android)
Oura, Garmin, WHOOPOAuth tokens; receives fitness/recovery dataDevice data synchronization
Expo Push ServicePush tokens, notification contentDelivering push notifications
USDA FoodData CentralFood name search queries (not linked to your identity)Nutrition database lookups
Open Food FactsBarcode numbers (not linked to your identity)Barcode-based nutrition lookups
OpenWeatherMapApproximate GPS coordinates (rounded to 0.1 degree)Weather data for workout recommendations
Apple Maps / Google MapsMap tile requests (standard, via device)Displaying workout routes and heatmaps
Apple Sign-In / Google OAuthAuthentication tokensAccount sign-in
ResendUsername, support ticket category, and descriptionSending admin notification emails for support tickets

Apple HealthKit Data

Solo Fitness accesses Apple HealthKit data with your explicit permission. Our use of HealthKit data is strictly governed by Apple’s guidelines:


Data Security

We implement technical and organizational measures to protect your personal data:

No method of electronic storage or transmission is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.


International Data Transfers

Solo Fitness is operated from the United States. If you are located in the European Union, European Economic Area, or another jurisdiction with data transfer restrictions, your personal data will be transferred to and processed in the United States.

We rely on the following safeguards for international data transfers:

By using Solo Fitness, you acknowledge that your data will be processed in the United States, where data protection laws may differ from those in your jurisdiction.


Data Retention and Deletion

Data TypeRetention Period
Account and profile dataRetained while your account is active
Health, fitness, and workout dataRetained while your account is active
Food scan imagesRetained while your account is active
AI coaching conversationsAutomatically deleted after 21 days
AI cache responsesAutomatically expire after 48 hours
Error logsRetained for up to 90 days, then deleted
Login audit logsRetained for up to 30 days, then deleted
Subscription event logsRetained for up to 90 days, then deleted

Account deletion

You can delete your account at any time from within the app. Upon deletion:

You can also request deletion by emailing privacy@soloinnovationshq.com.

Data export

You can export all your personal data in a portable, machine-readable JSON format from within the app, in accordance with your right to data portability.


Your Privacy Rights

Depending on your jurisdiction, you have some or all of the following rights regarding your personal data:

How to exercise your rights

We will respond to verified requests within 30 days (or 45 days if we notify you of an extension). If we deny a request, you may appeal by contacting us at the same email address, and we will respond to the appeal within 60 days.

Universal opt-out signals

We honor the Global Privacy Control (GPC) signal. If your browser or device sends a GPC signal, we will treat it as a valid opt-out request under applicable laws, including the California Consumer Privacy Act and other state privacy laws that recognize universal opt-out mechanisms.


Washington My Health My Data Act (MHMDA)

As a Washington State company that collects consumer health data, we comply with the Washington My Health My Data Act. The following disclosures apply:

For complete disclosures required by the Washington My Health My Data Act, see our standalone Consumer Health Data Privacy Policy.

To exercise your rights under MHMDA, contact us at privacy@soloinnovationshq.com.


California Privacy Rights (CCPA/CPRA)

If you are a California resident, the following additional disclosures apply under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:


European Privacy Rights (GDPR)

If you are located in the European Union or European Economic Area, the following additional disclosures apply under the General Data Protection Regulation:


Children’s Privacy

Solo Fitness is not intended for children under 16 years of age (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children under 16. If we learn that we have collected data from a child under 16, we will delete that information promptly.

If you believe a child under 16 has provided us with personal data, please contact us at privacy@soloinnovationshq.com.


Data Breach Notification

In the event of a data breach that affects your personal data, we will:


Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational reasons. When we make material changes, we will:

Your continued use of Solo Fitness after the effective date of any changes constitutes your acceptance of the updated policy. If you do not agree with the changes, you may delete your account.


Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us:

If you are located in the EU/EEA and are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.