Version: 2026-10-06
Fath Göktuğ Pamukçu. Contact: fitrotaaa@gmail.com. Location: Türkiye, Adana/Çukurova. Postal address: Yüzüncü Yıl Mahallesi, 85012 Sokak, Florya B Blok, Kat: 4, Daire: 7, 01000 Çukurova/Adana, Türkiye
Account identifiers, provider-shared email and basic profile details, session cookies, network/device information, subscription status, selected service requests and the health-related categories listed in the separate Consumer Health Data Privacy Policy. Google/Apple passwords, Gmail, contacts and Drive files are not requested. Apple may provide a private relay email.
To provide sign-in, account isolation, requested tracking, optional backup/AI, paid membership, security and customer support. Server credentials and provider tokens are not exposed to browser code. Apple credentials needed for authorization revocation remain encrypted in the server-issued session. We do not send health records as advertising parameters.
When you choose Sign in with Google, Google and Supabase authenticate you. FitRota receives your account identifier, email address and verification status, and basic profile fields such as your name and profile picture when supplied. Sign-in uses basic identity, email and profile permissions. FitRota does not request your Google password, Gmail messages, contacts, Google Drive files or calendar contents.
We use this information to create and recognize your FitRota account, maintain your sign-in session, keep account records separate, provide account support and protect access. Supabase processes authentication and account identity; the Render-hosted FitRota server handles account requests through the Cloudflare gateway. Signing in with Google does not itself upload your local health records or send your Google profile to OpenAI. Optional cloud backup and AI features require separate choices. We do not sell Google sign-in data or use it for advertising targeting. We limit Google user data use to the purposes described in this policy.
Account identity is stored by Supabase and processed by the FitRota server. The browser uses an encrypted, HttpOnly session cookie to maintain access. Active account information remains while your account exists; provider backups and operational or security logs follow the retention notice below. In FitRota, open Settings, then Account, then Delete my account to request deletion of the online account and its linked active cloud backup. A recent sign-in may be required. Delete local records on each device separately. If you cannot sign in, email fitrotaaa@gmail.com for help. You may also remove FitRota access from your Google Account third-party connections at https://myaccount.google.com/connections. Removing Google access does not by itself delete FitRota records or cancel a subscription.
Profile entries, age, height, weight, dietary and allergy preferences, meals, water, workouts, measurements, notes and coach messages support the features you select. These can include health information. Local records are stored in your browser. Optional backup sends selected records through Render to Supabase; private notes and AI history require an additional choice. Optional AI sends submitted messages and separately selected context through Render to OpenAI. Turning off sharing stops future submissions but does not erase previous submissions. The Consumer Health Data Privacy Policy linked above provides further details.
The web checkout integration uses Paddle when enabled, including its sandbox during testing. Paddle receives checkout information you enter, transaction and subscription details, and a FitRota account identifier used to match subscription access to your account. FitRota stores linked transaction and subscription identifiers and status in Supabase. Card entry is handled by the payment provider; FitRota does not receive your full card number. RevenueCat is used only for separately enabled integrations that use that provider. Cancel subscriptions through their billing portal; deleting a FitRota account does not automatically cancel billing or erase payment records required by the provider.
Render application hosting is in Frankfurt (EU Central), Germany. The Supabase primary database is in Tokyo, Japan. These regions were supplied by the operator and do not determine all provider or subprocessor processing locations. OpenAI and Google may process information in additional countries under their applicable service arrangements. Cloudflare Workers operates the country-access gateway. Requests pass through Cloudflare before reaching Render. Cloudflare processes IP addresses, network/request metadata and the country derived from the connection; forwarded requests may include sign-in requests, selected cloud-backup records and AI messages. Cloudflare uses its global network, so gateway processing is not restricted to the United States. Application request-body logging is disabled in the supplied Worker configuration. Selected services use Render, Supabase, OpenAI, Google, Apple when enabled, Paddle for enabled web checkout, RevenueCat when its integration is enabled, and Open Food Facts as described in the health policy. Any additional gateway must be disclosed in the actual location notice. Cross-border storage is not changed by selecting the US launch market. FitRota is operated from Türkiye and intended for the US market. Selecting the US market does not make processing US-only. Render application hosting is in Frankfurt, Germany; the Supabase primary database is in Tokyo, Japan. Google receives sign-in requests; Supabase processes the returned account identity. OpenAI receives submitted AI messages and separately selected context. These providers and their subprocessors may process information in additional countries under their applicable terms and data-processing arrangements. Optional cloud backup and AI sharing can be disabled separately; this stops future sharing but does not automatically delete previously disclosed records or provider security logs. This notice describes processing locations and choices; it does not itself execute a provider contract or establish a legal transfer mechanism.
Email fitrotaaa@gmail.com for access, correction, deletion, a copy of records, withdrawal, recipient information or an appeal. We request only information needed to verify the request and never passwords. Authorized agents may contact us; verification may be required. Applicable state rights, response deadlines and appeal rights apply. Washington health-data requests receive a response within 45 days, with one additional 45-day extension when permitted and explained within the first period. Washington appeals receive a response within 45 days; complaints may be submitted at https://www.atg.wa.gov/file-complaint. Nevada health-data requests receive the applicable 45-day response period and any permitted extension. We do not discriminate for exercising privacy rights. Use Advertising privacy to opt out of ad technology. Browser Global Privacy Control takes priority. Essential session cookies remain necessary for sign-in. Health sharing choices are separate from terms acceptance.
Records stored on your device remain until you delete them. Cloud backups remain until you delete the backup or your account. Offline copies on other devices must be deleted separately. Provider operational and security logs follow each provider's retention policies and may remain after account deletion. OpenAI abuse-monitoring logs may be retained for up to 30 days by default, or longer when required for legal or security reasons. Deleting your FitRota account does not immediately erase provider security logs or temporary caches.
FitRota is intended for adults 18+. Do not submit children’s personal information. Contact us if you believe a child’s data has been submitted. Material new health-data categories or uses require an updated notice and any required new consent before processing. Effective version: 2026-10-06