This Privacy Policy explains how Globalio LLC (“Globalio”, “Fitliner”, “we”, “us”) collects and uses personal data through the Fitliner and BeFitliner mobile applications, websites, Health Card, AI Coach, gym and trainer tools, messaging, access-control, payment and support services (together, the “Services”).
This Policy is a notice, not a request for blanket consent. Where consent is required—especially for health data, optional marketing or tracking—we ask for it separately and you may withdraw it as described below.
1. Who is responsible for your data
For the core Fitliner platform, the data controller is:
Globalio LLC 16192 Coastal Hwy Lewes, Delaware 19958-3608 United States Email: hello@befitliner.com Website: globaliollc.com
Globalio is established in the United States and offers the Services to people in the European Economic Area (“EEA”), United Kingdom and other countries. Privacy requests from those regions may be sent to the email above.
Gyms, trainers, laboratories, health partners and sellers may be separate controllers for their own memberships, appointments, premises, professional services, medical services, payments or records. They must provide their own privacy information. Where Globalio processes data only on a business customer’s documented instructions, that customer is the controller and Globalio acts as its processor.
2. Data we collect
Depending on the features you use, we collect the following categories.
2.1 Account and identity data
- email address, user ID, authentication records, session and account status;
- name, profile photo, public handle, language, time zone and communication preferences;
- declared role or intent, such as member, trainer or gym owner;
- support correspondence and information used to verify a privacy or account-deletion request.
2.2 Profile, fitness, food and progress data
- date of birth, age range, height, current and target weight and measurement units;
- activity level, training experience, goals, plans, exercises, workout history and progress entries;
- food entries, portions, estimated calories and nutrients, nutrition targets, favourite or disliked foods;
- information about injuries, limitations, health issues or other information you choose to enter for personalisation.
Some of this information can reveal health information and is treated as sensitive data where applicable law classifies it that way.
2.3 Fitliner Health data
- onboarding and health-questionnaire answers;
- laboratory reports, diagnostic-scale reports, photographs or PDF files that you upload;
- biomarkers, measurements, units, reference intervals, dates, source labels and extracted values;
- your corrections, confirmations, notes, check-ins, recommendations and metric history;
- consent records showing what you agreed to and when.
Do not upload another person’s report unless you are legally authorised to do so. We instruct our extraction provider to ignore patient names and identifiers where they are not needed, but you should redact unnecessary identifiers before upload whenever possible.
2.4 Gym, trainer and access data
- gym or trainer relationships, invitations, bookings, memberships, entitlements and validity;
- entry and unlock attempts, timestamps, gym and lock identifiers, success or error status and fraud/security signals;
- gym reviews, review replies, public gym information and aggregated gym-traffic information;
- business account, product, payout, billing and invoice information for gym owners or trainers.
Bluetooth or nearby-device access is used to communicate with supported door hardware. Fitliner does not need continuous precise GPS tracking for this purpose. Your operating system may nevertheless classify nearby-device permissions as sensitive and the lock provider may receive technical access data needed to perform an unlock.
2.5 Communications and user content
- direct messages, AI Coach conversations, support requests, reviews, profile content and invitations;
- message metadata such as sender, recipient, conversation ID, delivery time and notification status;
- reports about illegal, unsafe or Terms-violating content and our moderation decisions.
Messages are not end-to-end encrypted. Do not use Fitliner Messenger for emergencies or send highly confidential medical, financial or identity information.
2.6 Payment and transaction data
- product, price, currency, tax and subscription status;
- checkout, customer, connected-account, payment, refund, dispute and invoice identifiers;
- billing name, address, tax information and transaction confirmation where supplied to us;
- seller, gym, trainer or merchant information associated with a purchase.
Payment details are entered on the payment provider’s checkout. We do not store your full payment-card number or card security code.
2.7 Device, diagnostics and usage data
- IP address, device and operating-system type, app version, language, time zone and approximate country/region;
- push-notification token, notification preferences and app-instance identifiers;
- app opens, onboarding steps, feature interactions, gym unlock events, checkout events and other product analytics;
- crash reports, stack traces, performance diagnostics, security logs and abuse signals.
2.8 Website, funnel and marketing data
- pages and campaign links used, source URL and first-party campaign parameters such as UTM source, medium, campaign, content or term;
- email address and answers saved during the Fitliner Health purchase funnel, including an incomplete funnel where you asked us to save your progress;
- marketing consent, unsubscribe status and email engagement or delivery information supplied by our email provider;
- an advertising click identifier such as
fbclidonly where the relevant optional marketing-tracking choice permits its collection.
3. Where data comes from
We obtain data:
- directly from you, your device and your use of the Services;
- from a gym, trainer or business you join or interact with;
- from payment providers, app stores, access-control providers and communication providers;
- from another user when they invite, message, review, report or interact with you;
- from public sources when a gym owner asks us to create or verify a public gym listing.
If a gym or trainer adds your membership data, they are responsible for having a valid reason to provide it and for giving you any notice required by law.
4. Why we use data and our legal bases
We use personal data only where a legal basis applies.
To perform our contract or take steps you request
We use account, profile, membership, access, messaging, training, food, progress, subscription and support data to create your account, authenticate you, provide requested features, unlock supported doors, fulfil entitlements, deliver digital services, communicate service information and resolve support issues.
With your consent
We rely on consent for processing health data in Fitliner Health and for health-aware AI personalisation where required by Article 9(2)(a) GDPR or comparable law. We also rely on consent for optional marketing emails, optional campaign tracking, device permissions and any other feature that clearly asks for consent.
You may withdraw consent at any time. Withdrawal does not make earlier lawful processing unlawful. Withdrawing health-data consent disables health-dependent processing and may require deletion or isolation of affected Health data; core features that do not need that data can remain available.
For our legitimate interests
We process limited data to secure the Services, prevent fraud and abuse, enforce our Terms, maintain door-access audit trails, diagnose failures, measure non-sensitive feature performance, improve usability, protect legal claims and operate our business. Our interests do not override your rights, and you may object where the law gives you that right.
We do not use health results or health-questionnaire answers for advertising profiles.
To comply with law
We process billing, tax, transaction, safety, legal-request and recordkeeping data where required by accounting, consumer, payment, sanctions, law-enforcement or other applicable obligations.
To protect vital interests
In a genuine emergency, we may use or disclose strictly necessary data to protect someone’s life or physical safety where the law permits. Fitliner is not an emergency-monitoring service and does not promise to identify emergencies.
5. Health data and artificial intelligence
Fitliner Health uses automated tools to extract structured measurements from documents. You can review extracted values before confirming them. The source report—not the extracted value, chart, score, recommendation or AI response—remains authoritative.
The AI Coach may process your message together with relevant profile, fitness, food, training, progress and, where you enabled it, health observations. It can produce estimates, summaries and recommendations and may propose limited profile or training-plan updates. Fitliner applies server-side validation before supported updates are stored.
Health documents and relevant contextual data may be transmitted to our AI processing provider solely to perform the requested inference. For document extraction, our integration requests that the provider not store the API response for product-improvement training. Provider security and abuse-retention practices may still apply under its business terms.
We do not use solely automated Fitliner decisions to make decisions that produce legal or similarly significant effects about you. Payment providers may make their own automated fraud or payment decisions under their policies.
6. When data is visible to other people
Your name, photo, public handle and role may be visible to other signed-in users so that they can find or message you. When a public-profile or trainer-review feature is enabled, profile, public progress entries and recent food information may be visible to the users or trainers authorised by that feature. A field marked public may be shown outside your private account.
Direct messages are shared with conversation participants and processed by us to deliver, secure and moderate the service. Reviews and review replies are intended to be public. Gym owners or trainers can see member information reasonably necessary to manage the relationship, access, booking or service you requested.
Check the audience before posting or sharing. If a visibility control is available, your latest choice applies prospectively; copies already received by others or records we must retain may remain.
7. Recipients and service providers
We disclose only the data reasonably needed for the relevant purpose to:
- Supabase for authentication, database, storage, real-time communication and server functions;
- OpenAI for AI Coach responses, food estimates and Health document extraction;
- Google Firebase for analytics, crash reporting and push notifications, and Google services for maps/place information where used;
- Apple and Google for app distribution, platform services and purchases made through their systems;
- Stripe, Link/Sold through Link and connected payment accounts, and where still used ThriveCart, for checkout, billing, tax, fraud, subscription, refund and transaction support;
- MailerSend and other communication providers for operational and consented marketing emails;
- TTLock or another configured access-control provider to operate supported locks;
- Vercel and other hosting, security and delivery providers for our websites;
- gyms, trainers, laboratories or partners you choose to interact with;
- professional advisers, auditors, insurers, acquirers or investors subject to confidentiality;
- authorities or other parties when legally required or reasonably necessary to protect rights, safety and security.
Some recipients, including app stores, payment merchants of record, gyms, trainers and laboratories, act as independent controllers. Their terms and privacy notices also apply.
We do not sell personal data. We do not share personal data for cross-context behavioural advertising as those terms are defined by applicable US state privacy laws. On Fitliner Health pages, we do not intentionally send Meta an email address, questionnaire answer, health result, uploaded document or purchase detail through Meta Pixel or Conversions API.
8. International transfers
Globalio is in the United States and our providers operate internationally. Data may therefore be processed outside your country, including in the United States.
Where EEA, UK or Swiss transfer rules apply, we use a lawful mechanism appropriate to the recipient, such as an adequacy decision, the relevant Data Privacy Framework certification, European Commission Standard Contractual Clauses or another permitted safeguard. We also assess supplementary technical and organisational measures where required. Contact us to request information about the safeguard relevant to your data; commercially confidential details may be redacted.
9. Retention
We keep data only for the purpose stated and then delete or anonymise it, subject to legal holds, disputes and mandatory records. Unless a shorter period is shown in the feature:
- account, profile and service data is kept while the account is active and is scheduled for deletion within 30 days after a verified deletion request;
- Health observations and confirmed records remain until you delete them, withdraw the relevant consent or delete the account;
- uploaded Health source files remain until you delete the import or account; failed or abandoned uploads may be removed earlier;
- messages and user content remain until deleted, the account is deleted or they are no longer needed for the conversation, moderation or legal purpose;
- gym access and security logs are normally retained for up to 24 months, longer if needed for an active membership, incident, dispute or legal obligation;
- an incomplete Health funnel and its questionnaire are retained for up to 24 months from the last interaction, or earlier on request; marketing contact data remains until unsubscribe or objection;
- analytics and diagnostics follow the configured provider retention period and are then deleted or aggregated;
- transaction, invoice, tax, refund and dispute records are retained for 7–10 years where accounting or tax law requires;
- encrypted backups may persist for up to 90 additional days before rotation, without being returned to normal use.
Deletion from Fitliner does not automatically delete a separate record held by a gym, trainer, app store, payment provider, merchant of record or other independent controller.
10. Security
We use access controls, authentication, row-level database controls, encrypted transport, restricted service credentials, logging, backups and other measures appropriate to the nature of the data. Access to health and payment-related data is limited by role and service need.
No system is completely secure. You are responsible for protecting your email account, device and login links and for promptly telling us about suspected unauthorised access. Do not send passwords, one-time codes or full card details to support or Messenger.
11. Your choices and rights
Depending on your location, you may have the right to:
- be informed and obtain access to your personal data;
- correct inaccurate or incomplete data;
- delete data or your account;
- restrict processing or object to processing based on legitimate interests;
- withdraw consent, including health or marketing consent;
- receive data you provided in a portable format where applicable;
- object at any time to direct marketing;
- obtain human review of a qualifying automated decision;
- lodge a complaint with a data protection authority;
- appeal a refusal of a US state privacy request where applicable;
- use an authorised agent where applicable law permits.
Use in-app controls where available, visit the account-deletion page, or email hello@befitliner.com. You may use the deletion page in your language by replacing /en/ with your locale. We may verify identity and authority before acting. We normally respond within one month under GDPR or within the period required by applicable law. We do not discriminate against you for exercising a privacy right.
To stop marketing emails, use the unsubscribe link in the message. Service, safety, billing and account messages are not marketing and may continue while relevant.
EEA users may find their national supervisory authority through the European Data Protection Board member list. You may complain to the authority where you live, work or believe an infringement occurred.
12. Account deletion and subscriptions
Deleting a Fitliner account does not by itself cancel a subscription or payment mandate managed by Apple, Google, Link, Stripe, a gym, trainer or another seller. Cancel the subscription through the seller or subscription-management link shown at checkout before deleting the account. We will tell you when we identify an active subscription, but you remain responsible for completing cancellation with the billing provider.
We may retain the minimum data necessary for an unresolved payment, fraud investigation, legal claim or statutory record after account deletion. It will be isolated from ordinary product use.
13. Device permissions
Notifications, Bluetooth/nearby devices, photo library, camera and file access are requested through your device when needed. You can change permissions in device settings, but the related feature may stop working. Selecting a file or photo sends only the item you choose; Fitliner does not need general access to all files when the operating system offers a picker.
14. Children
The Services are intended only for people aged 18 or older. We do not knowingly offer Fitliner accounts or Fitliner Health to children. If you believe a child has provided data, contact us so that we can investigate and delete it. Gyms remain responsible for their own lawful rules concerning minors outside the Fitliner account service.
15. Region-specific disclosures
Residents of jurisdictions with additional privacy rights—including California and other US states, the UK, Switzerland, Brazil or other countries—may exercise those rights through the same contact. The categories collected, sources, business purposes and recipients are described above. We do not offer a financial incentive in exchange for personal data unless separate rules clearly describe it.
Globalio does not currently respond to browser “Do Not Track” signals because there is no uniform standard. Where a legally recognised opt-out preference signal applies to a processing activity we perform, we will honour it as required.
16. Changes to this Policy
We may update this Policy when the Services, providers or law change. We will change the date above and, for a material change, provide reasonable in-app, website or email notice before it takes effect where required. We will request new consent when a new purpose legally requires it.
17. Contact
For privacy questions, requests, complaints or a suspected data incident, contact:
Globalio LLC – Fitliner Privacy Email: hello@befitliner.com 16192 Coastal Hwy, Lewes, Delaware 19958-3608, United States