Short version: Your workout data lives on your device. We never collect your health data, personal information, or usage analytics. Crash reports are opt-in, anonymous (stack traces only), and contain no health or personal data.
Fit M8 is an independent fitness-tracking application. When this policy says “we,” “us,” or “our,” it refers to the developer of Fit M8 (Elementary Inc). Questions? Email elementaryinc0@gmail.com.
We do not collect, transmit, or sell your personal information or health data. All workout logs, measurements, goals, and settings are stored locally on your device in a private SQLite database that is isolated by Android’s app sandbox (other apps cannot read it). This data never leaves your device unless you explicitly initiate a backup or export (see sections 4 and 5).
We do not use advertising SDKs, analytics libraries, or any third-party data brokers.
Fit M8 uses Firebase Crashlytics to collect crash reports. Crash reporting is off by default and only activates after you explicitly consent during first launch. You can change this choice at any time in Settings › Crash reporting.
When you opt in, crash reports contain:
Crash reports never contain:
Crashlytics is operated by Google. Their privacy practices are described in the Firebase Privacy and Security documentation.
The “Backup & Restore” feature lets you export a .fitmate file
to a location you choose (for example, your downloads folder or a cloud storage app). This
file is encrypted on-device using AES-256-GCM with a key derived from your chosen
passphrase. We never receive, store, or have access to this file or its contents.
A local automatic checkpoint is written to your device’s Downloads folder periodically as a safety net. It uses the same encryption; the file may be visible to file managers, but it is only decryptable by the app on the same device.
The “Export data (CSV)” feature writes a plaintext spreadsheet of your workout history and measurements to a file you save. Because this file is unencrypted, treat it like any sensitive document. We never receive this file.
A future update will add an optional “Link Google account” feature. It is not active in this version of the app, which works entirely without an account. When the feature ships, if you choose to use it, the app will use the Android Credential Manager to authenticate with Google and will store only your Google account’s unique subject identifier (the “sub” claim) locally on your device to recognise your account. It will not store your Google ID token and will not transmit your account information to any server. Your display name and email would be shown in the app and stored only in your device’s local preferences. This policy will be updated when the feature becomes available.
If you enable workout reminders or streak notifications, Fit M8 schedules local alarms on your device using Android’s AlarmManager. These notifications are generated entirely on-device — no notification content is sent through our servers.
Fit M8 requests only the permissions it needs:
Fit M8 is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
We may update this policy as the app gains new features. Material changes will be announced in the app’s release notes. The “Last updated” date at the top of this page always reflects the current version.
Questions or concerns about this policy? Email us at elementaryinc0@gmail.com.