CTS Fitness

Privacy Policy

Last updated 21 September 2026

This policy explains what CTS Fitness collects, why, who else sees it, how long it is kept, and how to get rid of it. It covers the CTS Fitness mobile app and its backend. If anything here is unclear, email josh@camotechsolutions.com.au and ask.

The short version. We collect the account details you give us and the training data you enter. We do not sell it, we do not advertise to you, we run no analytics or tracking SDKs, and we do not build a profile of you. You can delete everything from inside the app at any time.

1. Who we are

CTS Fitness is operated by Camotech Solutions, Australia. Contact: josh@camotechsolutions.com.au.

2. What we collect, and how

All of it is either given to us directly by you, or generated by your own use of the app. We do not buy data, and we do not compile information about you from public databases or any other outside source.

CategoryWhat it isHow we get it
Account Email address; password (stored only as a salted hash, never in plain text) You enter it when you sign up
Profile Username and display name You choose them
Training data Exercises, sets, reps, weights, units, personal records, cardio sessions, workout presets, and any notes you write You enter it as you log workouts
Social Friend requests and friendships; posts you share, including their captions; likes; comments Created when you use the social features
AI usage A timestamped record that a generation happened, used only to enforce the daily limit. The prompt you type is passed through to the AI provider and is not stored by us. Created when you use the AI generator
Technical IP address, device platform and app version, recorded transiently by our hosting and app-update providers Sent automatically by your device when the app connects

What we do not collect: we request no location, no contacts, no photos, no camera, no microphone, no health-app data, and no advertising identifier. The app contains no analytics SDK, no advertising SDK and no cross-app or cross-site tracking of any kind, so the App Tracking Transparency prompt does not apply to it.

3. How we use it

We do not use your data for advertising, marketing, profiling or automated decision-making about you, and we never sell it.

4. Who else sees it

We share data with the service providers below, and with nobody else. Each is bound by its own agreement to protect your data to a standard at least equal to this policy, to process it only on our instructions, and not to use it for its own purposes.

ProviderWhat it receivesWhy
Supabase All account, training and social data; email and password hash Database hosting, authentication, and the server-side functions the app runs on
Google (Gemini API) Only when you use the AI workout generator: the prompt you typed, plus the names and dates of your workouts from the last 30 days and which of them were personal records Generating the workout suggestion
Expo / EAS Device platform, app version and IP address Delivering over-the-air app updates
Apple Download and purchase metadata, handled by Apple under its own privacy policy Distributing the app through the App Store

About the AI generator specifically

The AI workout generator is opt-in: nothing is sent to Google unless you open it and ask for a workout. When you do, your prompt and a summary of your recent training (exercise names, dates, and whether each was a personal record) are sent to Google's Gemini API to produce the suggestion. Your email address, username and password are never sent. If you would rather share nothing with a third-party AI provider, simply do not use that feature — the rest of the app works exactly the same without it.

Other disclosures

We may disclose data if we are legally required to, or where it is necessary to protect someone's safety or our legal rights. If CTS Fitness is ever sold or transferred, your data may transfer with it, and this policy continues to apply until you are told otherwise.

5. Who can see your data inside the app

6. Storage, security and location

Data is stored in Supabase's managed Postgres infrastructure. Traffic between the app and our backend is encrypted in transit with TLS. Passwords are stored only as salted hashes. Access between users is restricted by row-level security policies enforced by the database. Our servers may be located outside Australia, which means your data may be stored and processed overseas.

No system is perfectly secure, and we cannot guarantee absolute security.

7. How long we keep it, and how to delete it

We keep your data for as long as your account exists. We do not keep it on any fixed schedule beyond that.

You can delete your account and all of its data at any time, from inside the app: Settings → Delete Account. Deletion is immediate and permanent. Your account, training log, cardio sessions, presets, profile, posts, comments, likes and friendships are erased and cannot be recovered. You do not need to ask us, and there is no waiting period.

Two things survive deletion, and only these: content reports you submitted about other people, retained in a form that no longer identifies you so that safety decisions remain reviewable; and ordinary server logs held briefly by our providers before rotating out. Backups are purged on our providers' normal rotation.

If you cannot sign in, email us from the address on the account and we will delete it for you.

8. Your rights and your consent

You can access, correct, export or delete your data. Most of it you can do yourself: your training log is editable in the app, your username and password are changeable in Settings, and account deletion is one screen away. For an export, or for anything you cannot do in the app, email us and we will respond within 30 days.

You give consent by creating an account and using the app, and you withdraw it by deleting your account — which also erases the data. Consent to the AI feature is separate and is given each time you choose to use it. No paid feature, and no part of the app, is conditional on giving us data beyond what it needs to function.

Depending on where you live you may have additional rights under the Australian Privacy Act, the GDPR or similar laws, including the right to complain to your local data protection authority. Please contact us first — we would rather fix it.

9. Children

CTS Fitness is not directed at children and is not intended for anyone under 13. We do not knowingly collect data from children under 13. If you believe a child has created an account, email us and we will delete it.

10. Changes to this policy

If we change this policy we will update the date at the top of this page, and we will notify you in the app before any change that materially affects how your data is used.

11. Contact

josh@camotechsolutions.com.au