← Back to GritPrivacy policy

GritPrivacy Policy

Last updated Account-based · health data, narrowly shared

Grit holds health and fitness information, which we treat as sensitive. We only collect what you give us or what the app needs to work. We do not buy data about you, and we do not track you across other apps or websites.

The short version

Grit stores your training, nutrition and body data against an account so it syncs across your devices. Training partners see your workouts and nothing else. Nothing is sold, and there is no advertising.

Who we are

Grit is a fitness tracking app for logging workouts, nutrition and gym attendance, operated by Divyansh Karan, trading as Stelr Studio (Remote · India) — the data controller for the purposes of the UK GDPR and GDPR. Contact: karandivyansh01@gmail.com.

Account information

DataWhyRequired
Email addressTo create your account, sign you in and send password resetsYes
PasswordStored only as a salted hash — never in plain textYes
Display nameShown to you and to training partners you addOptional
Profile photoShown to you and to training partners you addOptional

Health and fitness information

This is the core of what the app does. All of it is entered by you.

  • Workouts — exercise names, sets, repetitions, weight lifted, rest and work durations, session start and end times
  • Personal records — your best lifts per exercise
  • Nutrition — foods logged with calories, protein, carbohydrates and fat; water intake
  • Body measurements — body weight, height, and optional measurements you add
  • Attendance — the dates you record a gym check-in, and the streaks derived from them
  • Optional profile details — biological sex and year of birth, used only to calculate calorie and macronutrient targets

Social information

Only if you choose to use the partner features:

  • Invite codes you generate or redeem
  • Training partner connections — which accounts are linked to yours
  • Reactions you send to partners
  • Shared routines you publish by code, and records of who imported them

Technical and diagnostic information

Crash reports and error diagnostics: the error message and stack trace, your device model, operating system version, and app version, processed by Sentry. Email addresses, authentication tokens and API keys are automatically removed before a report is sent, and your account is identified only by a random internal ID.

Camera: the app requests camera access so you can scan food barcodes. Images are processed on your device and are never uploaded or stored by us. You can decline this permission and use the rest of the app normally.

What we do not collect

  • Precise or approximate location
  • Contacts, calendar, SMS, call logs or photos beyond a profile picture you pick
  • Microphone or audio — explicitly disabled in the app's build configuration
  • Advertising identifiers
  • Any data used for advertising or profiling

How we use your information

PurposeData used
Provide the app's core featuresAccount, health and fitness data
Sign you in and keep you signed inEmail, password, session tokens
Show your progress, streaks and recordsHealth and fitness data
Let you train with partnersSocial data, display name, photo
Fix crashes and bugsDiagnostic data
Respond when you contact supportEmail and whatever you tell us

We do not use your data for advertising, we do not sell it, and we do not share it with data brokers.

Who we share data with

We use these processors. We do not share your data with anyone else except where legally required.

ProcessorWhat it handlesTheir policy
SupabaseDatabase, authentication and file storage — account, health and fitness, social data, profile photosupabase.com/privacy
SentryCrash reports and device diagnosticssentry.io/privacy
Expo / EASApp builds and updates. No personal data.expo.dev/privacy

Training partners you add can see your display name, profile photo, and your workout activity — routine names, durations, sets completed. They cannot see your nutrition, body measurements, weight or email address. You can remove a partner at any time, which immediately revokes their access.

Where your data is stored

Your data is stored on Supabase infrastructure in the project's configured region. If you are in the UK or EEA and that region is outside it, the transfer relies on the processor's Standard Contractual Clauses.

How long we keep it

  • While your account exists — as long as you keep it.
  • When you delete your account — immediately and permanently.
  • Crash reports — retained by Sentry for 90 days, then deleted.
  • Database backups may retain deleted data until they rotate out on the hosting plan's retention schedule.

Security

The protections actually in place:

No system is perfectly secure. If you find a vulnerability, email karandivyansh01@gmail.com — we will acknowledge within five working days.

  • All traffic between the app and our servers uses HTTPS/TLS.
  • Passwords are stored only as a salted hash by the authentication provider — we never see them.
  • Session tokens are held in the device's hardware-backed secure storage (Keychain on iOS, encrypted storage on Android), never in plain app storage.
  • Row-level security is enforced at the database level, so one account's queries cannot read or modify another account's rows.
  • Sign-in uses the PKCE authorization-code flow.
  • Profile photos are stored in a private bucket and served only via short-lived signed links.

Your rights

Wherever you live, you can exercise all of the following. If you are in the UK or EEA these are your rights under the UK GDPR and GDPR; in California, under the CCPA/CPRA.

To exercise any right, email karandivyansh01@gmail.com. We respond within 30 days.

  • Access — everything we hold is visible inside the app.
  • Correct — edit any entry or profile field directly.
  • Export — request a machine-readable copy of your data.
  • Delete — Profile → Danger zone → Delete account, described below.
  • Withdraw consent for anything optional, by removing the data or revoking the permission in your device settings.
  • Object or restrict processing, and lodge a complaint with your data protection authority (in the UK, the ICO at ico.org.uk).

Deleting your account

Profile → Danger zone → Delete account. You will be asked to type DELETE to confirm. This is immediate and irreversible.

It erases your profile, all workouts and sets, all nutrition and water logs, body measurements and weight history, attendance records, routines (including ones you shared), partner connections, and your profile photo.

If you cannot access the app, email karandivyansh01@gmail.com from your registered address and we will delete the account within 30 days.

Children

Grit is not intended for children under 16. We do not knowingly collect data from children. If you believe a child has created an account, email karandivyansh01@gmail.com and we will delete it.

Changes to this policy

If this policy changes, the updated version ships with the Grit release it applies to and the date at the top changes. Material changes are surfaced in the app before they take effect.

Contact

Questions about this policy, or about the data the app holds on you, go to karandivyansh01@gmail.com. The data controller is Divyansh Karan, trading as Stelr Studio (Remote · India).

This policy covers Grit only. Other Stelr apps have their own policies, listed on the apps page.