Privacy Policy
What we collect across the app, the website and coaching, why we collect it, who we share it with, and how to get it deleted.
LAST UPDATED
This policy covers befitwithjess.com, the BeFit app and our online coaching. It lists the data we actually hold — not the data a template says we might. Every section starts with a plain-language summary; the full text below it is what counts.
Who we are
Be Fit For Life Co., Ltd. in Bangkok. We decide how your data is used, so we are the ones answerable for it.
Be Fit For Life Co., Ltd. (registered in Thailand, Tax ID 0105564061089) runs the Be Fit With Jess website, the BeFit — AI นับแคล & Workout app on the App Store and Google Play, and our online 1-to-1 coaching. In this policy we call all of that "the Service", and we call ourselves "we" or "us".
For the personal data described here we are the data controller under Thailand's Personal Data Protection Act B.E. 2562 (2019), the PDPA. If you use the Service from the EU or the UK, we also apply the rights the GDPR gives you.
Be Fit For Life Co., Ltd.
Tax ID 0105564061089
269 Soi Phueng Mee 11, Bang Chak, Phra Khanong, Bangkok 10260, Thailand
info@befitforlife.co
What the name "Jess" means here
Jess is a name the company works under. It can be her, a team member, or an AI tool a team member uses.
Please read this before the rest of the policy, because it changes how you should read the word "Jess" everywhere else.
When you see the name Jess — in the app, on a program, in a chat reply, in an email, in a video or on this website — it may mean any of the following:
- Jess herself;
- a member of our team working under that name;
- an automated tool, including artificial intelligence, used as a tool by a member of our team.
We will not always tell you which of the three it was, and you should not assume that a message signed "Jess" was typed by one specific person. What we do promise is this: anything sent to you under the name Jess comes from the company, and the company is responsible for it. Section 06 explains where AI is used and what it does with your data.
The data we collect
Your account and profile, what you log (food, workouts, weight, photos), your purchases, and basic device data.
We collect what the Service needs to work. Grouped by what it is:
- Account — your email address, first name, gender, date of birth and profile picture. Sign-in is handled by Google Firebase Authentication: if you use a password, we never see it; if you sign in with Google, we receive your name and email from Google.
- Your profile answers — height, current weight, target weight, your goal, fitness level, how many minutes a day and days a week you want to train, the equipment you have, any event you are training for, what you find hard about training, and how you found us.
- Food and drink — the meals you log, foods you create yourself, portion sizes, favourites, photos of food you take for the AI tracker, your water intake, your fasting windows, and your calorie and macro targets. Also any food you report as wrong or ask us to add.
- Training — your program, which days and exercises you complete, reps and weights you enter, notes you write on an exercise, ratings you give a program, badges, milestones, and events you join.
- Body and health — your weight history, body-transformation photos, the health conditions you tell us about, period-cycle entries and the statistics we build from them, and daily mood entries. Section 04 covers this group separately, because it needs your consent.
- Community — photos you post to the Picture Wall and the reactions you give or receive. See section 09 — this part is not private.
- Purchases — which plan you are on, when it renews or expires, and the transaction identifiers the app stores give us. We never receive your card number.
- Device and usage — app version, device model, operating system, language, IP address, crash and error reports, which screens and features you use, and which advert or link brought you to the app.
- Messages — your push-notification token, the emails we send you, your support messages, and your conversations with coaching (including anything you attach).
- Job applications — if you apply for a role from our Careers page, whatever you send us: CV, contact details and anything else in your application.
We do not collect precise GPS location, we do not read your contacts, and the app does not connect to Apple Health or Health Connect.
Health and body data
Health conditions, period tracking, mood and body photos are sensitive. We ask consent first and you can withdraw it.
Some of what the Service is built for is sensitive personal data under section 26 of the PDPA — data about your health. In our case that means: the health conditions you enter, your period-cycle entries and statistics, your daily mood entries, your weight history, and your body-transformation photos.
We ask for your explicit consent before collecting this, at the point the feature asks for it. We use it only to build and adjust your plan, to show you your own progress, and — if you buy coaching — to let your coach do their job. It is not sold, and it is not used to target adverts at you.
You can withdraw consent or delete individual entries at any time in the app, or by emailing us. Withdrawing consent stops that feature from working properly — a period tracker with no cycle data cannot predict anything — but the rest of the Service keeps running.
Why we use your data, and on what legal basis
To run the Service you paid for, to keep it working, to meet the law, and — only with consent — for health features and marketing.
Under the PDPA every use of your data needs a lawful basis. Ours are:
- To perform our contract with you — creating your account, generating and adjusting your program, tracking your food and training, running your coaching, taking payment and managing renewals, and giving you support.
- With your consent — the health and body data in section 04, sending you marketing emails and push notifications, and the optional analytics and advertising tags on the website.
- Our legitimate interest — keeping the Service secure and stable, fixing crashes, preventing fraud and abuse, understanding in aggregate which features get used so we can improve them, and defending our legal rights.
- To comply with the law — tax and accounting records, and responding to a lawful request from an authority.
We do not sell your personal data. We do not share it with data brokers. We do not use your body photos in any advertising or marketing without asking you separately, in writing, for that specific use.
AI features and what they do with your data
Food photos and profile answers go to Google Gemini; coaching chat will use Anthropic. Neither may train on your data.
Parts of the Service are automated. Here is exactly where, and what leaves our systems:
- AI food tracking — when you photograph or describe a meal, that photo or text is sent to Google's Gemini API, which returns an estimate of the food and its nutrition. You then confirm or correct it.
- AI program generation — your profile answers (goal, level, time available, equipment, health conditions you entered) are sent to the same Gemini API to draft your training program.
- Coaching assistance — our coaching app uses Anthropic's Claude API to help draft and speed up replies. A human coach is accountable for what is sent to you, as section 02 explains.
These providers process this content on our instructions only, under contracts that do not permit them to use your content to train their own models. We do not send them your name, email or payment details — only the content the feature needs.
Two limits worth knowing. First, AI output is an estimate: a calorie count from a photo is a best guess, not a measurement. Second, no automated decision here has a legal effect on you — nothing decides your price, your refund or your access. If you would rather not use these features, log your food manually and ask us for a coach-built program instead.
Who we share your data with
Your coach, and the named companies below that run parts of the Service for us. Nobody else, unless the law forces us.
We share personal data with three groups only, and we name our providers rather than hiding behind "trusted partners":
- Your coach — if you buy coaching, the coach assigned to you sees the data they need to build and adjust your plan.
- Service providers, who may use your data only to provide their service to us:
- Google — Firebase Authentication, Firestore, Cloud Messaging, Remote Config and Analytics; the Gemini API (section 06); Google Tag Manager on the website.
- Anthropic — the Claude API used by coaching (section 06).
- Amazon Web Services — the database that holds your account and logs.
- Railway — hosting for our servers and this website.
- RevenueCat — subscription and entitlement management.
- Apple and Google Play — payment for in-app subscriptions, and push delivery.
- PostHog — product analytics, hosted in the EU.
- AppsFlyer — measuring which advert or link installed the app.
- Algolia — the food search index.
- Bunny.net — storage and delivery of images and workout videos.
- Resend — the emails the Service sends you.
- Sentry — crash and error reports.
- Authorities — where a law, a court or a regulator requires it, and only to the extent required.
If the company is ever sold or reorganised, data may transfer to the buyer; you will be told, and this policy continues to apply until you are told otherwise.
Sending data outside Thailand
Most of our providers are outside Thailand. We only use ones with proper safeguards in place.
The providers in section 07 are mostly outside Thailand, so running the Service means your data crosses borders. The PDPA allows this where the destination has adequate protection or where we put appropriate safeguards in place. We rely on the providers' data-processing agreements and, where the provider offers them, the European Commission's standard contractual clauses.
You can ask us info@befitforlife.co which provider holds a particular category of your data and where.
The Picture Wall is shared, your progress photos are not
Anything you post to the Picture Wall can be seen by other members. Your body-transformation photos stay private.
This is the one place where being clear matters more than sounding reassuring.
The Picture Wall is a shared, in-app feature. A photo you post there can be seen by other members of the app for that day, and they can react to it. Do not post anything there you would not want another member to see. You can delete your own posts at any time; a deleted photo stops being shown, and reactions to it go with it.
Your body-transformation photos, your weight history, your period and mood entries and your food log are different: they are tied to your account and are visible only to you, to your coach if you have one, and to the small number of our staff who need access to support you or fix a fault.
Cookies, analytics and advertising
The website loads Google Tag Manager for every visitor. Here is what that does and how to block it.
On the website. Some cookies are strictly necessary — they make pages work. Beyond those, this site loads Google Tag Manager, which is the container we manage our analytics and advertising tags in. Those tags currently cover website analytics and advertising or conversion measurement for Google, Meta (Facebook and Instagram) and TikTok, because that is where we advertise.
We will be straight with you about the current state: these tags load when you arrive, before you have made a choice. If you do not want them, you can block cookies for this site in your browser, use a tracker blocker, or use your browser's "do not track" and privacy settings. Whichever you choose, the rest of the site keeps working.
In the app. The app does not use cookies, but PostHog, Firebase Analytics and AppsFlyer record which screens and features you use and which advert brought you in. You can limit advertising tracking on your phone: on iOS, deny the app's tracking request or turn off "Allow Apps to Request to Track"; on Android, delete or reset your advertising ID in Google settings.
Payments
App subscriptions are paid to Apple or Google, never to us directly. We never see your card number.
Subscriptions bought in the app are charged by Apple or Google Play under your own store account. They tell us — through RevenueCat — that a purchase happened, which plan it was, and when it renews or expires. Your card number, bank details and billing address stay with the store; we never receive them and cannot see them.
Coaching bought outside the app is invoiced to you directly. We keep the record of the payment — amount, date and reference — for the period Thai tax law requires. We do not store your full card number for these payments either.
How long we keep your data
While your account is active. Delete it and your personal data goes within 30 days, backups within 90.
We keep your data while your account exists, because the Service is a record of your own progress and it would be useless without history.
When you delete your account, we erase your personal data from our live systems within 30 days, and from our backups within 90 days. Two things survive that: invoices and payment records, which Thai tax law requires us to keep for at least five years, and statistics that have been fully anonymised so they can no longer be traced back to you.
You can delete your account in the app, or ask us to do it at info@befitforlife.co.
Your rights, and how to use them
Access, copy, correct, delete, object, withdraw consent — free, and we answer within 30 days.
Under the PDPA — and the GDPR where it applies to you — you have the right to:
- be told what we hold about you and get a copy of it;
- receive it in a portable, machine-readable format;
- correct anything wrong or incomplete;
- have it deleted, or have its use restricted;
- object to a particular use, including marketing;
- withdraw any consent you gave, at any time, without giving a reason.
Email info@befitforlife.co and say what you want. It is free, and we will answer within 30 days. We may need to confirm you are the account holder before we act — usually by writing to you at the email address on the account.
If you are not happy with how we handled it, you can complain to Thailand's Personal Data Protection Committee (PDPC), or to the data protection authority where you live.
Security
Encrypted connections, passwords we never see, and access limited to staff who need it.
Traffic between your device and our servers is encrypted with HTTPS/TLS. Passwords are handled by Google Firebase Authentication and are never visible to us or stored on our servers. Access to production data is limited to the staff and contractors who need it for their work, using named accounts with defined permissions. We monitor for crashes and errors so faults get found rather than sit quietly.
No system is perfect. If a breach affects your personal data, we will notify the PDPC within 72 hours of becoming aware of it where the law requires, and we will tell you directly if the risk to you is high.
Age
The Service is for adults, 18 and over. We do not knowingly collect data from anyone younger.
The Service is for people aged 18 or over. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us their data, email info@befitforlife.co and we will delete it.
Changes to this policy
The date at the top tells you the version. We tell you before a material change takes effect.
When we change this policy we update the date at the top of the page. If the change is material — new data, a new purpose, a new provider that matters — we will tell you in the app or by email before it takes effect, so you have time to object or withdraw consent. Previous versions are available on request.
Contact us
info@befitforlife.co — for anything in this policy, including deleting your data.
Be Fit For Life Co., Ltd.
269 Soi Phueng Mee 11, Bang Chak, Phra Khanong, Bangkok 10260, Thailand
Tax ID 0105564061089
info@befitforlife.co
You can also reach us from the contact page. For complaints about how we handled your personal data, the Personal Data Protection Committee (PDPC) in Thailand is the supervisory authority.