GritPrivacy Policy
Grit holds health and fitness information, which we treat as sensitive. We only collect what you give us or what the app needs to work. We do not buy data about you, and we do not track you across other apps or websites.
The short version
Grit stores your training, nutrition and body data against an account so it syncs across your devices. Training partners see your workouts and nothing else. Nothing is sold, and there is no advertising.
Who we are
Grit is a fitness tracking app for logging workouts, nutrition and gym attendance, operated by Divyansh Karan, trading as Stelr Studio (Remote · India) — the data controller for the purposes of the UK GDPR and GDPR. Contact: karandivyansh01@gmail.com.
Account information
| Data | Why | Required |
|---|---|---|
| Email address | To create your account, sign you in and send password resets | Yes |
| Password | Stored only as a salted hash — never in plain text | Yes |
| Display name | Shown to you and to training partners you add | Optional |
| Profile photo | Shown to you and to training partners you add | Optional |
Health and fitness information
This is the core of what the app does. All of it is entered by you.
- Workouts — exercise names, sets, repetitions, weight lifted, rest and work durations, session start and end times
- Personal records — your best lifts per exercise
- Nutrition — foods logged with calories, protein, carbohydrates and fat; water intake
- Body measurements — body weight, height, and optional measurements you add
- Attendance — the dates you record a gym check-in, and the streaks derived from them
- Optional profile details — biological sex and year of birth, used only to calculate calorie and macronutrient targets
Technical and diagnostic information
Crash reports and error diagnostics: the error message and stack trace, your device model, operating system version, and app version, processed by Sentry. Email addresses, authentication tokens and API keys are automatically removed before a report is sent, and your account is identified only by a random internal ID.
Camera: the app requests camera access so you can scan food barcodes. Images are processed on your device and are never uploaded or stored by us. You can decline this permission and use the rest of the app normally.
What we do not collect
- Precise or approximate location
- Contacts, calendar, SMS, call logs or photos beyond a profile picture you pick
- Microphone or audio — explicitly disabled in the app's build configuration
- Advertising identifiers
- Any data used for advertising or profiling
How we use your information
| Purpose | Data used |
|---|---|
| Provide the app's core features | Account, health and fitness data |
| Sign you in and keep you signed in | Email, password, session tokens |
| Show your progress, streaks and records | Health and fitness data |
| Let you train with partners | Social data, display name, photo |
| Fix crashes and bugs | Diagnostic data |
| Respond when you contact support | Email and whatever you tell us |
We do not use your data for advertising, we do not sell it, and we do not share it with data brokers.
Legal bases for processing (GDPR)
If you are in the UK or EEA:
- Contract — providing the app you signed up for.
- Consent — optional profile details, profile photo, and camera access. You can withdraw consent at any time by removing the data or revoking the permission in your device settings.
- Legitimate interests — crash diagnostics used to keep the app working, balanced against your privacy by the scrubbing described above.
Where your data is stored
Your data is stored on Supabase infrastructure in the project's configured region. If you are in the UK or EEA and that region is outside it, the transfer relies on the processor's Standard Contractual Clauses.
How long we keep it
- While your account exists — as long as you keep it.
- When you delete your account — immediately and permanently.
- Crash reports — retained by Sentry for 90 days, then deleted.
- Database backups may retain deleted data until they rotate out on the hosting plan's retention schedule.
Security
The protections actually in place:
No system is perfectly secure. If you find a vulnerability, email karandivyansh01@gmail.com — we will acknowledge within five working days.
- All traffic between the app and our servers uses HTTPS/TLS.
- Passwords are stored only as a salted hash by the authentication provider — we never see them.
- Session tokens are held in the device's hardware-backed secure storage (Keychain on iOS, encrypted storage on Android), never in plain app storage.
- Row-level security is enforced at the database level, so one account's queries cannot read or modify another account's rows.
- Sign-in uses the PKCE authorization-code flow.
- Profile photos are stored in a private bucket and served only via short-lived signed links.
Your rights
Wherever you live, you can exercise all of the following. If you are in the UK or EEA these are your rights under the UK GDPR and GDPR; in California, under the CCPA/CPRA.
To exercise any right, email karandivyansh01@gmail.com. We respond within 30 days.
- Access — everything we hold is visible inside the app.
- Correct — edit any entry or profile field directly.
- Export — request a machine-readable copy of your data.
- Delete — Profile → Danger zone → Delete account, described below.
- Withdraw consent for anything optional, by removing the data or revoking the permission in your device settings.
- Object or restrict processing, and lodge a complaint with your data protection authority (in the UK, the ICO at ico.org.uk).
Deleting your account
Profile → Danger zone → Delete account. You will be asked to type DELETE to confirm. This is immediate and irreversible.
It erases your profile, all workouts and sets, all nutrition and water logs, body measurements and weight history, attendance records, routines (including ones you shared), partner connections, and your profile photo.
If you cannot access the app, email karandivyansh01@gmail.com from your registered address and we will delete the account within 30 days.
Children
Grit is not intended for children under 16. We do not knowingly collect data from children. If you believe a child has created an account, email karandivyansh01@gmail.com and we will delete it.
Changes to this policy
If this policy changes, the updated version ships with the Grit release it applies to and the date at the top changes. Material changes are surfaced in the app before they take effect.
Contact
Questions about this policy, or about the data the app holds on you, go to karandivyansh01@gmail.com. The data controller is Divyansh Karan, trading as Stelr Studio (Remote · India).
This policy covers Grit only. Other Stelr apps have their own policies, listed on the apps page.
Social information
Only if you choose to use the partner features: