LEGAL
Privacy Policy
This policy explains what OPTIV.FIT collects, how we use it, when we share it with processors (including OpenAI for AI coaching), and the choices you have. OPTIV is currently invite-only. This is a product-accurate draft for the live beta — not a substitute for formal legal review before a broad public launch.
1. Who we are
OPTIV.FIT (“OPTIV,” “we,” “us”) provides a personal performance system — training, nutrition, recovery logging, decision support, and optional AI coaching — via the website at optiv.fit, the coach app at coach.optiv.fit, and the native iOS app.
For privacy requests, email privacy@optiv.fit.
2. What we collect
Account & profile
- Username and authentication credentials (passwords are hashed; we never store plaintext passwords)
- Email address (for account, invites, and optional briefing emails)
- Preferred / first name, goals, targets, coach notes, and similar profile settings
- Sensitive profile fields may be encrypted at rest when encryption is configured
Performance logs you enter or sync
- Workouts (type, duration, calories, heart rate, distance, RPE, zones, notes)
- Food and nutrition (meal name, macros, notes; optional photo for recognition)
- Body and recovery metrics (weight, sleep, energy, mood, water, steps, and related fields)
- Scores, decision feedback, Momentum commitments, brags, and similar in-product records
Coach chat & facts
- Messages you send in Ask Coach / AI chat
- Optional “Coach facts” you explicitly save (capped; used in Ask Coach, daily decisions, and AI briefing emails; you can review and remove them)
Technical & product data
- Basic server logs (path, status, timing, authenticated user id) — request bodies and secrets are not logged
- Product analytics events when analytics is enabled (see below)
- Device/local preferences stored in the browser or app (e.g. session tokens, consent flags)
3. How we use data
- Provide logging, scoring, Decision Engine, Momentum, Progress, and related product features
- Power optional AI coaching, commentary, food recognition, and AI-assisted email briefs when you consent
- Send transactional and optional product emails (e.g. password reset, daily briefing if enabled)
- Secure the service (auth, rate limits, abuse prevention)
- Understand product usage and improve reliability (analytics)
We do not sell your personal data.
4. AI coaching & OpenAI
When you enable AI Coach consent, OPTIV may send relevant context to OpenAI’s API to generate coaching replies, analysis, score commentary, food-photo recognition, and (if daily email is on) AI-written briefing narratives.
Typically included when AI runs:
- Fitness logs and goals described above
- Your preferred or first name if set (so the coach can address you)
- Ask Coach chat messages and any saved coach facts you opted into
- Optional food photos you choose to scan (sent for recognition; not stored by OPTIV after the request)
Not sent to OpenAI: your email address.
Per OpenAI’s API data usage policy, API inputs are not used to train OpenAI models. OpenAI may retain data briefly for abuse and safety monitoring under their terms.
You can withdraw AI consent in Settings at any time. Withdrawing stops interactive AI, AI score commentary, and AI email narratives. Deterministic (rules-based) coaching and your logged data remain available.
5. Service providers (processors)
We use trusted vendors to operate OPTIV. They process data only to provide their service to us:
- Railway — application hosting and PostgreSQL database (US)
- OpenAI — AI coaching features when you consent
- Resend — transactional and optional briefing emails
- PostHog — product analytics (when configured)
- OpenStreetMap Nominatim — optional reverse geocoding for coarse place labels
- Open-Meteo — optional weather context for logs
- Apple — HealthKit sync on iOS when you grant Health permissions
6. Apple Health (HealthKit)
On iOS, if you grant Health permissions, OPTIV may read workouts, sleep, resting heart rate, active energy, steps, and related samples you allow. OPTIV does not write data back to Apple Health. Health access stays under your Apple Health permissions; you can revoke it in iOS Settings. Imported values become part of your OPTIV logs and may be included in AI context when AI consent is on.
7. Location & weather
When you manually save certain logs and grant location access, the app may reverse-geocode your position to a coarse place (city / region / country) and fetch weather. We store those coarse labels and weather fields — not raw GPS coordinates — with the log entry.
8. Analytics
When PostHog is configured, we collect product usage events to understand feature adoption and reliability. Identity may include an internal user id and username. Session recording, if enabled, uses text and attribute masking. Autocapture is disabled in our client config.
An in-app analytics opt-out is not yet available; contact us if you need analytics disabled for your account during the beta.
9. Storage & security
- Primary datastore: PostgreSQL hosted on Railway (US)
- Transport: HTTPS
- Auth: JWT access tokens and hashed refresh tokens; passwords hashed with bcrypt
- Security headers, CORS allowlisting, and rate limits on auth and AI endpoints
- On web/iOS WebView, session tokens are currently stored in local storage on the device — protect your device and sign out on shared devices
10. Retention & deletion
We keep your account and logs while your account is active so the product can coach over time. Ask Coach / coach facts are capped and can be removed by you in Settings.
You can delete your account in Settings (app or web coach). Deletion permanently removes your account and associated logs from OPTIV after password confirmation.
Self-serve data export is not yet in the product. To request an export during the beta, email privacy@optiv.fit.
11. Your choices
- AI consent — enable or disable in Settings; required for AI features
- Coach facts — separate opt-in; review/remove saved snippets anytime
- Email briefings — optional daily/weekly emails via settings
- Apple Health — controlled in iOS Health / Settings (read-only sync)
- Location — controlled by OS permission prompts; used only on manual log save when allowed
- Account deletion — Settings → Delete Account (or email privacy@optiv.fit)
12. Children
OPTIV is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has created an account, contact us and we will delete it.
13. Changes to this policy
We may update this page as the product evolves. The “Last updated” date at the top will change when we do. Material changes will be called out in-product or by email when practical.
14. Contact
Privacy questions, export, or deletion requests:
privacy@optiv.fit
Product / access:
Request access on optiv.fit
·
Coach login
This page describes OPTIV’s current beta practices as implemented in the product. Have a lawyer review before relying on it for App Store, paid, or regulated launches.