Privacy policy
Last updated: September 10, 2026
Who is responsible
Corbello Inc., 1515 Aurora Dr., Unit 201c, San Leandro, CA 94577, United States, is the controller responsible for personal data used to operate FitGlade. This policy covers the website, purchase funnel, member app and support. Paddle separately controls the information it needs as the seller of your purchase.
FitGlade is intended for adults aged 18 and over. If you believe a child has provided personal data, contact us so we can investigate and address the information.
Information you provide
Account information: your email, account identifier, sign-in details, display name and preferences such as language, measurement units and fitness level. We also record the terms and privacy versions acknowledged and your consent choices.
Workout information: programs you choose, workout sessions, completion and progress, time spent exercising and related activity estimates. Where a feature offers it and you choose to provide it, optional health information can include height, weight, target weight and areas of the body you want to work around.
Support information: what you send us about your account, purchase or problem. Please avoid sending medical records or other information that is not needed to resolve your request.
Information from use and other sources
Our infrastructure receives technical information such as IP address, device and browser details, request times, errors and security events. With optional analytics or advertising consent, we also receive usage events, campaign parameters, click identifiers and browser identifiers.
Paddle supplies purchase and billing records such as transaction and customer identifiers, products purchased, amounts, currency, payment status, refunds and access dates. We do not receive or store your full payment-card number or security code.
Quiz answers are stored in your browser during the quiz. Submitting your email sends it for purchase checks and, if you opt in, marketing-lead capture. After sign-in, supported quiz preferences may be imported into your account; health answers are imported only with the separate health consent. Quiz answer values are not included in our analytics or advertising events.
How we use your data
We use account, purchase and workout information to sign you in, check purchase eligibility, unlock content, remember preferences, save progress and respond to support requests. Without the account or payment information needed for these functions, we may be unable to provide paid access.
We use technical and transaction records to maintain the service, prevent duplicate purchases and fraud, investigate errors, handle disputes and meet legal obligations. Optional health information supports the features for which you provide it; refusing it may limit those features, but is not permission to deny unrelated account or privacy rights.
With your consent, analytics helps us understand use and fix problems, and advertising data helps measure campaigns. We may qualify offers using purchase or checkout history. We do not use automated decisions to determine legal rights or make similarly significant decisions about you. Workout suggestions and offer qualification are not medical assessments.
Legal bases and optional health information
For the EEA and UK, account access and requested workout features rely on performing our contract with you. Security, fraud prevention, troubleshooting and handling claims rely on our legitimate interests, balanced against your rights. Required legal and financial records rely on legal obligations.
Optional analytics, advertising and marketing rely on consent. Optional health-metric storage requires explicit consent as well as the legal basis for the requested feature. You can withdraw consent at any time without making earlier lawful processing unlawful. Other countries may require a different basis or additional permission; we must meet those requirements where they apply.
In Account → Privacy, withdrawing health-metric consent deletes the stored optional health-metric record. It does not by itself delete all workout history. To request deletion of other fitness or health-related information, contact us or use account deletion.
Who receives data
Vercel hosts the website; Supabase provides authentication and database storage; Cloudflare supports infrastructure, security and workout-media delivery; Resend delivers sign-in emails. These providers receive information needed for their service, such as account records, email addresses or network requests.
Paddle handles checkout and billing as merchant of record under its own privacy notice. PostHog receives consented analytics, technical events and pseudonymous identifiers. After sign-in, consented analytics can associate earlier browser activity with your account identifier. Session recording is disabled.
Meta, when enabled and consented, receives advertising events, purchase value and currency, campaign or click identifiers and technical information. If you also give ad-identity consent, a hashed version of your email may be used to match activity to an ad account. Hashing does not make an email anonymous. We do not include quiz answers or stored health metrics in these events.
We may disclose information to professional advisers, authorities or parties to a business transfer where necessary and legally permitted, with appropriate restrictions. A recipient’s role depends on what it does: Paddle and advertising providers may use information under their own legal responsibilities.
Paddle privacy noticeCookies
Essential cookies and browser storage support sign-in, purchase continuity, security and remembering choices. Optional analytics and advertising are off until you agree. You can refuse them in the consent prompt; account holders can change them in Account → Privacy.
The quiz record has a seven-day expiry checked when the app next reads it. Session identifiers last for the browser session. Persistent preferences and consent records remain until replaced or cleared. Consented analytics and advertising may set provider cookies, including Meta’s _fbp and _fbc, and persistent browser identifiers.
You can clear or block cookies and site storage through your browser. This may sign you out or remove saved quiz progress. Different browsers and devices may need separate choices. Essential server processing still occurs when you visit the service.
Do not sell or share
We do not sell personal information for money. Optional disclosures to advertising providers may count as “sharing”, targeted advertising or a “sale” under some privacy laws. They can include online identifiers, hashed email when separately consented, and purchase-event information. We do not sell health metrics or use them for advertising.
Refuse advertising and ad identity consent, or turn them off in Account → Privacy, to stop this optional sharing. Global Privacy Control turns these purposes off unless you explicitly change the choice in settings. The older Do Not Track browser signal does not change our settings.
You can also email a privacy request without creating an account. Withdrawing browser consent stops future optional collection and clears associated identifiers; it does not automatically erase information previously held by providers. Contact us to request deletion or assistance with a provider request. We do not penalise you for exercising applicable privacy rights.
Emails
Sign-in and other necessary account or purchase messages support the service and are separate from marketing. At launch, FitGlade saves marketing opt-ins but does not send marketing campaigns. You can withdraw that permission in Account → Privacy or by contacting us. Any future marketing must include a way to unsubscribe.
Retention and deletion
Account, preference and workout records are kept while needed to provide your account. Purchase, dispute, consent and security records may need to be retained for legal obligations, proof of choices or handling claims. Retention depends on the record’s purpose, the relevant legal period and any unresolved dispute; storage capacity alone is not a reason to keep a record.
Account deletion has a 14-day recovery period. After it expires, the deletion process removes account data from the active service. The confirmation shows the scheduled date. Restoring the account during that period cancels the pending deletion.
Supabase service logs are retained for seven days and Cloudflare Workers logs for three days. These are service-log periods, not a promise that all providers, backups or financial records use those periods. Paddle keeps its own records under its privacy notice and legal obligations. Contact us for retention information about a particular record.
International processing and security
Corbello operates in the United States. Our providers operate internationally, so information may be processed outside your country, where privacy laws differ. Transfers must have the protection required by the law that applies to them. Contact us for the destinations and safeguards relevant to your information; using FitGlade does not itself waive transfer requirements.
We use access controls, authentication and encrypted connections to protect information. No service can guarantee absolute security. Keep your account credentials private and tell us if you suspect a security problem.
Your privacy rights
Depending on where you live, you can ask us to confirm whether we hold data, access or correct it, provide a portable copy, delete it, restrict its use, withdraw consent or object to processing. You may also have rights to opt out of sale, sharing or targeted advertising and to challenge a refused request. Some records must be retained or requests limited where the law permits.
Email us with the request and the email used for your account or purchase. You do not need to open a new account. We may ask for proportionate information to verify identity or an authorised agent’s permission, but do not send identity documents unless we explain why they are necessary.
We respond within the period required by the applicable law. EEA and UK requests normally receive a response within one month; eligible California consumer requests generally within 45 days. If a permitted extension is needed, we will explain it. Requests are normally free; any lawful exception will be explained.
EEA and UK residents can complain to their data protection authority, including the UK ICO. Residents elsewhere can contact the competent privacy or consumer authority. If we refuse a request, reply asking for a review or appeal; this does not affect any right to complain directly to a regulator.
app.fitglade@corbello.coPolicy changes and contact
The revision date identifies this policy version. We will post updates and provide additional notice or request new consent for material changes where required. We will not treat an earlier consent as permission for an unrelated new use.
For privacy questions or requests, email us or write to Corbello Inc., 1515 Aurora Dr., Unit 201c, San Leandro, CA 94577, United States.
app.fitglade@corbello.co