Privacy policy
OmniFit plans and records fitness activity. You can use personal training without an account. We do not sell your data, run advertising trackers or upload your personal training history to our servers.
Your device and backups
Plans, workouts, soreness and energy check-ins, journal drafts and entries, measurements, photos, equipment and preferences are saved in this app’s local storage. Photos are stored separately in the device database. This data is not synced between devices by an OmniFit account.
JSON backups include your local data and photos. CSV exports contain readable records. You choose where exported files go; another app, a cloud drive or an operating system backup may then store them under its own policy. Exports are not password protected. Keep them somewhere private. A recovery copy of the previous data is retained locally when you restore a backup.
Accounts, friends and groups
Signing up sends your email, chosen display name and authentication information to Amazon Cognito in AWS us-east-1 (Northern Virginia, USA). Passwords go directly to Cognito over an encrypted connection; they are not stored in OmniFit’s groups database. The app keeps session tokens locally to maintain your sign-in and can remember an unverified account email for up to 24 hours.
The AWS service stores your account identifier, display name, group memberships and ownership, invitation codes, friend connections and blocked account identifiers. Group members see members’ display names and shared goals. Friends see each other’s display names after an invitation is accepted. There is no contact upload or public account search. Give invitation codes only to people you intend to invite.
Challenge contributions are optional. Before each share you review the number and explicitly agree to send that number, your display name and update time to the group. Individual workouts, photos, journal entries and Apple Health readings are not sent. Updating replaces your earlier total. You can withdraw a contribution, leave a group, remove a friend or block future friend connections. Blocking a friend does not remove you from shared groups.
Apple Health
On supported iPhones, you can choose to read steps, active energy, heart rate, resting heart rate, heart rate variability, sleep, body mass, VO₂ max and exercise minutes. Values are read on request and shown locally. With separate writing permission and your action, OmniFit can save a completed workout, body mass or a completed mindful interval to Apple Health. It does not invent calories or distance. Health data is not sent to our AWS service, used for advertising or shared automatically with friends.
Apple controls Health permissions. You can change them in the Health app or iPhone Settings. For privacy, Apple does not tell apps whether a missing read result means denial or no data. Revoking permission does not delete records already saved to Apple Health; manage those in Apple Health.
Photos, notifications and diagnostics
Photo or camera access is requested when you use a photo feature. Selected images stay in local storage unless you export or share them. Optional reminders are scheduled on your iPhone, with up to 14 days of pending reminders refreshed when you open OmniFit. They do not use remote push servers.
Local diagnostic recording is off by default. If enabled, it retains up to 50 event codes, timestamps, app version and platform for up to 7 days. It does not record error messages, stack traces, names, emails, workout details or Health readings. Nothing is sent automatically. You may export these codes and decide whether to send them to support. Turning diagnostics off removes the local report.
Why information is processed
Account and membership information is used to provide the account and sharing features you request. Optional challenge sharing is based on your explicit consent, which you can withdraw. Limited operational information is used to maintain security, investigate errors and prevent misuse. Support correspondence is used to answer the request you send. We do not use these records for targeted advertising.
Service providers and locations
Amazon Web Services provides authentication, the groups API, database and hosting. Account and social information is processed in the USA; hosted web files may be delivered through AWS’s global content delivery network. Apple provides Health and operating system services under its own terms. Emailing support also passes your message through email providers. Contact us for information about applicable international transfer safeguards.
Retention and deletion
Local training data remains until you remove it, reset the app, clear browser/app storage or uninstall it. Before deleting data, export a backup if you want to keep it. Reset everything in Profile clears local training data, photos and recovery snapshots and signs you out; it does not delete your online account.
Delete account in Profile removes your Cognito account, connections, memberships and their shared contributions. Ownership of a group with remaining members transfers to a remaining member; an empty group is removed. Your local fitness history and files you previously exported remain under your control. Challenge titles and group names may remain for other members; avoid putting private health information in them.
A minimal deleted-account identifier is retained for 48 hours to reject still-valid session tokens and is then eligible for automatic database expiry, which can take several additional days. Active account security records, including blocks, remain while the account exists. Pending friend invites expire after 7 days but remain visible to their creator until cancelled. Each group retains at most 20 challenges; removed challenge totals may remain in membership records until a later contribution update or membership deletion. Operational Lambda logs are configured to expire after 14 days. Separately retained cloud backups, if enabled by the operator, expire under their configured retention.
Your choices and rights
Contact us to request access, correction, deletion, restriction or portability of information we hold, or to object to relevant processing. Some rights depend on the circumstances. You may withdraw optional sharing and Health permissions at any time. If you are in the UK, you can complain to the Information Commissioner’s Office; other locations may have a local data protection authority.
Contact
Omnixco Ltd · mahir.gilani@gmail.com. Please avoid emailing passwords, verification codes, detailed Health records or unredacted backups unless necessary for your request and agreed with support.