FitChecked
BetaFAQContactRequest access

FitChecked Privacy Policy.

Effective date: 2022-07-22

Who We Are

FitChecked is a fashion and social app operated by FitChecked Inc.

Contact:

  • Privacy contact: privacy@fitchecked.app

What This Policy Covers

This policy covers the FitChecked mobile app, website, account features, privacy request workflows, direct messages, user-generated content, closet and product features, notifications, ads and analytics preferences, and support/privacy requests.

This policy does not cover third-party websites, stores, payment flows, or services that are not controlled by FitChecked. If FitChecked links to a third-party product, brand, or website, that third party controls its own privacy practices.

Personal Information We Collect

FitChecked collects personal information directly from users, automatically from app and service use, and from service providers that support account, security, notification, storage, analytics, and communication features.

CategoryExamplesSource
Account identityEmail, username, display name, profile details, account status, authentication identifierYou, authentication systems
Profile and user contentPhotos, videos, captions, posts, lookbooks, comments, tags, tagged-product assignments, profile visibility choicesYou, other users who interact with you
Social graph and interactionsFollows, followers, likes, comments, saves, reports, tagged-user relationships, product-tag relationshipsYou and other users
Closet and product dataCloset items, product metadata, wardrobe information, product links, auto-tag attributionYou, product data services
Direct message records and metadataConversation membership, encrypted message envelopes, timestamps, delivery/read status, encrypted attachment metadata, device/key registration metadata, safety-number verification metadataYou and other conversation participants
Privacy choices and request historyConsent records, ad preferences, ATT status, communication preferences, privacy request type, due dates, outcomes, retained-data exceptionsYou, app settings, privacy operations
Notifications and communicationsNotification preferences, device tokens, delivery metadata, transactional emails, support messagesYou, device settings, service providers
Age assurance and eligibility stateBirthday or age-related state, age-limited settings, verification metadata where enabledYou, age assurance provider if enabled
Security and session dataLogin/session metadata, IP address, device/user agent, reset tokens, trusted-device metadata, security audit eventsYour device, FitChecked systems
Reports and moderation recordsReports submitted by you, report metadata, safety notes, enforcement state, moderation evidenceYou, other users, FitChecked moderators
Business account linksBusiness workspace claims, linked account metadata, role/claim statusYou, business account systems
Analytics and diagnosticsApp events, crash/error data, aggregate usage metrics, device/app metadataYour device, analytics/monitoring services

How We Use Personal Information

FitChecked uses personal information for the purposes below.

PurposeData used
Create and manage accountsAccount identity, authentication data, profile information, session metadata
Provide app featuresPosts, lookbooks, comments, tags, closet data, follows, interactions, profile visibility settings
Deliver E2EE direct messagesConversation metadata, encrypted message envelopes, encrypted attachment metadata, delivery/read metadata, device/key metadata
Protect users and the serviceSecurity logs, reports, moderation evidence, account status, device/session metadata, age assurance state
Personalize settings and app experiencePrivacy settings, notification preferences, profile/content settings, closet/product preferences, optional analytics and ads settings
Send communicationsTransactional email, security notices, account notices, optional marketing or promotional notifications where enabled
Support privacy rightsPrivacy request records, export payloads, retained-data exceptions, verification metadata, request communications
Improve reliability and safetyDiagnostics, error logs, aggregate usage data, security events, abuse-prevention signals
Comply with legal dutiesPrivacy request records, consent/audit logs, incident records, retained safety/security/moderation records

Direct Messages and End-to-End Encryption

FitChecked direct messages are designed to use end-to-end encryption.

FitChecked stores and relays encrypted message envelopes and operational metadata needed to deliver messages. FitChecked does not store server-side private keys that allow it to decrypt message bodies or media attachments.

FitChecked can process:

  • Conversation membership and participant identifiers;
  • Encrypted message envelopes;
  • Encrypted attachment metadata and private media pointers;
  • Timestamps, delivery status, read status, disappearing-message state, and device/key metadata;
  • Safety-number verification metadata;
  • Reports, moderation metadata, and safety evidence submitted by users.

If a user requests their data, FitChecked can export direct message metadata and encrypted records associated with that user where technically available. FitChecked cannot provide plaintext DM message bodies or decrypted media from a server export.

Reports, safety reviews, legal holds, or moderation records may preserve limited DM-related evidence. Those retained categories must be documented as retained-data exceptions during deletion processing.

Ads, Analytics, and Tracking

FitChecked supports privacy settings for personalized ads, analytics, marketing, and related choices. On iOS, device-level App Tracking Transparency status is treated as authoritative for whether tracking can be used on that device.

If iOS ATT is denied, restricted, unavailable, or not granted, FitChecked should not use that device for personalized tracking. Users can choose non-personalized ads where supported.

FitChecked records ad and tracking settings such as:

  • Ad personalization status;
  • ATT status;
  • Ad consent mode;
  • Sale/sharing opt-out status;
  • Targeted advertising opt-out status;
  • Sensitive-use limitation status;
  • Marketing suppression and notification preferences.

When We Share Personal Information

FitChecked shares personal information only for the purposes needed to operate the service, support users, comply with legal requirements, or protect safety and security.

Current vendor categories:

  • Hosting, database, and infrastructure providers;
  • Authentication providers;
  • Media/object storage and CDN providers;
  • Transactional email providers;
  • Push notification providers;
  • Analytics, monitoring, and diagnostics providers;
  • Age assurance provider if enabled;
  • Legal, safety, and compliance advisors where needed.

FitChecked may share limited information when:

  • A user posts content publicly or shares content with other users;
  • Another user is part of a social relationship, tagged post, comment thread, lookbook, or DM conversation;
  • A service provider processes data on FitChecked's behalf;
  • Disclosure is required for legal, safety, security, fraud, dispute, or rights-request reasons;
  • FitChecked is involved in a business transaction, subject to applicable legal safeguards.

International Transfers

FitChecked is Canadian-based, but service providers may process personal information in other regions.

How Long We Keep Personal Information

FitChecked keeps personal information only as long as needed for the purposes described in this policy, unless a longer retention period is required for legal, safety, security, privacy compliance, dispute, or audit reasons.

Current retention summary:

  • Account identity is kept for the account lifetime and anonymized on final deletion;
  • Authentication and session artifacts are revoked or deleted on final deletion;
  • User content is kept for the account/content lifetime and deleted or pseudonymized where safe;
  • Media binaries are deleted from storage during content/account deletion where technically safe;
  • Privacy request and consent/audit records are retained as compliance evidence, usually pseudonymized after final deletion;
  • Direct message metadata and encrypted records follow the DM E2EE retention process and may remain for other participants or safety/legal evidence;
  • Reports and moderation records may be retained for safety or legal defense with identifiers minimized where possible;
  • Aggregate analytics may be retained if it no longer identifies a user.

The user-facing retention summary is in the Data Use and Retention Policy. Legal review required before publishing final retention periods.

Account Deactivation and Deletion

Deactivation disables normal account use without deleting the account. When a user deactivates, FitChecked logs the user out, disables active use, revokes active sessions, suppresses push tokens, and records the deactivation reason/status. Deactivation is reversible through the reactivation flow if the account is eligible.

Deletion is different. Account deletion starts a 7-day grace period. During that period, the user can cancel deletion. After the grace period, FitChecked finalizes deletion by anonymizing or deleting account data and revoking auth/session/security artifacts. Some records may be retained in minimized or pseudonymized form when required for legal, safety, security, moderation, dispute, or privacy compliance reasons.

Privacy Rights

Depending on location and applicable law, users may have rights to:

  • Access personal information;
  • Receive a structured export;
  • Request portability;
  • Correct inaccurate or incomplete information;
  • Delete personal information;
  • Deactivate or reactivate an account;
  • Restrict processing;
  • Object to processing;
  • Withdraw consent;
  • Opt out of sale, sharing, targeted advertising, or similar processing where applicable;
  • Limit certain sensitive personal information use where applicable;
  • Request human review of certain automated or assisted decisions where applicable;
  • Submit a privacy complaint;
  • Appeal a privacy decision where applicable;
  • Use an authorized agent where permitted by law.

Users can submit privacy requests in the FitChecked app or by contacting privacy@fitchecked.app. FitChecked verifies requests before disclosing or changing personal information.

Current operating targets:

  • Canada, Quebec, Alberta, and British Columbia: 30 days unless legally extended.
  • EU and UK: one month or the product's 30-day operational deadline, subject to legal review.
  • California: 45 days, with acknowledgement handling as required.
  • Account deletion: 7-day grace period before final deletion.

Security

FitChecked uses administrative, technical, and organizational safeguards intended to protect personal information. These include authentication controls, session controls, security logging, restricted internal privacy operations access, direct message encryption architecture, and vendor review processes.

No system is perfectly secure. Users should protect their login credentials and keep their devices secure.

Children and Age-Limited Users

You need to be at least 16 years or older to use FitChecked. Users under 18 years old have additional safeguards in place. FitChecked uses age-related information and age assurance state to apply eligibility and age-limited privacy controls where required.

Changes to This Policy

FitChecked may update this policy when the service, vendors, laws, or privacy practices change. Material changes should be reviewed by counsel and communicated as required by applicable law.

Contact

Questions or privacy requests can be sent to:

  • privacy@fitchecked.app
FitChecked Inc. 2026
PrivacyTermsFAQContact