Skip to content
score.fit

Legal

Privacy Policy

Last updated August 9, 2026

Applies to the score.fit member app. See also our Terms of Use · Contact support@score.fit

1. Introduction

Appspade Technologies Private Limited ("Appspade", "we", "us", or "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use the score.fit member mobile application, related websites (including https://score.fit), and associated cloud services (collectively, the "Services").

score.fit is a preventive fitness companion for gym members and individuals. It helps you join fitness facilities, check in, view membership and payment history, track workouts, participate in community chat, receive notifications, and use optional AI wellness features such as fitness scoring and food analysis.

By using the Services, you acknowledge that you have read this Privacy Policy. If you do not agree, please do not use the Services. Our Terms of Use (https://score.fit/terms/) govern your use of the Services and should be read together with this policy.

Gym and studio operators who use score.fit Business should also review the business privacy policy at https://business.score.fit/privacy.

2. Who This Policy Applies To

This policy applies to:

  • App users — individuals who download, register for, or use the score.fit member app;
  • Gym members — users who join or link to a fitness facility through the app;
  • Visitors — individuals who browse public pages such as this Privacy Policy or Terms of Use without signing in.

3. Controller and Processor Roles

For your score.fit account registration data (such as name, email, phone, authentication identifiers), push notification tokens, in-app preferences, telemetry we collect to operate the app, and photos you submit for optional AI features, Appspade is generally the data controller.

For member records managed by your gym or studio (such as date of birth, gender, address, membership status, attendance history stored in the gym workspace, subscriptions, and payments recorded by the facility), your gym is typically the data controller. Appspade acts as a data processor, processing such data on the gym's instructions to provide the Services.

If you have questions about how your gym handles your personal information, please contact that facility directly. We process gym-held member information only as directed by the gym and as needed to operate the Platform.

4. Information We Collect

The information we collect depends on how you use the Services. Categories include:

  • Account and profile information — name, email address, phone number, and authentication identifiers when you register with email/password or phone OTP (SMS verification via Firebase Auth);
  • Gym membership information — gym and branch associations, linked member profile details (which may include date of birth, gender, and address entered by your gym), membership status, and join dates;
  • Attendance and activity — check-in timestamps, device app identifier, attendance streaks, session redemptions, and workout assignments assigned by your gym;
  • Payment and subscription history — amounts, payment methods (such as UPI, cash, or card as recorded by your gym), dates, status, transaction identifiers, and plan details displayed in the app. The app does not process card payments itself;
  • Community content — messages you send in gym community chat, including sender name and timestamps;
  • Communications — support requests, feedback, and records of service-related notifications;
  • Photos you choose to submit — images captured or selected for QR scanning, fitness score analysis, or food analysis.

5. Information Collected Automatically

When you use the Services, we and our infrastructure providers may automatically collect:

  • Device and app information (operating system, platform, app version);
  • Session identifiers and authentication tokens;
  • Usage and diagnostic events (such as authentication flows, QR verify/join actions, attendance, and feature views), which may include your user ID and active gym/branch context;
  • IP address and approximate location derived from IP (we do not use GPS or device location services);
  • Push notification (FCM) device tokens if you enable notifications;
  • Local preferences stored on your device (such as theme and onboarding state).

6. Cookies and Website Analytics

On our public website (https://score.fit), we use Google Analytics to understand how visitors find and use the site so we can improve it. Google Analytics uses cookies and similar local storage to recognize repeat visits and measure usage such as pages viewed, approximate location derived from IP, device and browser type, and referral source.

Analytics only run if you accept them in the cookie banner shown on your first visit. If you decline, no analytics cookies are set and no usage data is sent to Google. You can change your choice at any time using the "Cookie preferences" link in the site footer.

We do not use these cookies for advertising, ad personalization, or cross-site tracking, and we do not sell data collected through website analytics. This is separate from the member app, which does not use Google Analytics — see "Information Collected Automatically" above for what the app itself collects.

7. Photos and AI Processing

Certain features use your device camera or photo library:

  • QR scanning — camera access to scan gym QR codes for check-in or joining a facility;
  • Fitness score — a body or posture photo you capture or select may be sent to our cloud functions for automated analysis and recommendations;
  • Food analysis — a meal photo you capture or select may be sent to our cloud functions for nutritional estimates and related notes.

8. Photos and AI Processing — Use and Retention

Images submitted for AI features are processed server-side to generate wellness insights. These outputs are informational only and are not medical diagnoses, clinical assessments, or professional nutrition advice.

We process submitted images to provide the requested feature. We do not sell your photos. Retention of image data is limited to what is needed to deliver the feature, maintain security, and improve reliability, unless a longer period is required by law.

You choose whether to use AI photo features. Declining camera or photo library permission may limit those features but does not prevent core membership functions that do not require photos.

9. Community and Social Features

If your gym enables community chat, messages you send (and your display name) may be visible to other members and staff in that gym community, depending on the gym's chat mode (open or broadcast).

Attendance leaderboards may show member names and streak information to other members of the same gym. Do not share sensitive personal information in community chat that you do not want others in your gym to see.

10. How We Use Information

We use personal information for the following purposes:

  • Providing, operating, and maintaining the Services;
  • Creating and managing your account and authentication;
  • Enabling gym joining, member profile linking (with your consent), multi-gym switching, and attendance check-in;
  • Displaying membership, subscription, payment history, workouts, and session information;
  • Delivering push and in-app notifications;
  • Operating community chat and leaderboard features;
  • Providing optional AI fitness and food insights;
  • Crowd forecasting and similar features based on aggregated attendance patterns;
  • Monitoring usage, troubleshooting, and improving performance and reliability;
  • Detecting, preventing, and addressing fraud, abuse, or security incidents;
  • Complying with legal obligations and enforcing our Terms of Use;
  • Generating aggregated or de-identified analytics that do not identify individuals.

11. Legal Bases for Processing

Where applicable, we rely on one or more of the following legal bases to process personal information:

  • Contract — processing necessary to provide the Services under our agreement with you;
  • Legitimate interests — securing the app, improving features, preventing abuse, and communicating about the Services, balanced against your rights;
  • Consent — where you have given consent, such as linking a gym member profile, enabling push notifications, or using optional AI photo features;
  • Legal obligation — where processing is required by applicable law, regulation, or court order.

12. Legal Bases — India

Our processing is also intended to align with the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and, where applicable, the Digital Personal Data Protection Act, 2023 and rules thereunder.

13. How We Share Information

We do not sell your personal information. We may share information in the following circumstances:

  • With your gym(s) and gym staff — when you join or link to a facility, relevant profile, attendance, chat, and membership data is available within that gym's workspace according to their access controls;
  • With other gym members — limited information such as community chat messages and leaderboard names/streaks, where those features are enabled;
  • Service providers — vendors who help us host, operate, and support the Services (see Service Providers and Infrastructure);
  • SMS / authentication providers — Firebase phone authentication delivers one-time passwords via SMS;
  • Legal and safety — when required by law, regulation, legal process, or governmental request, or to protect rights, safety, and security of Appspade, users, or others;
  • Business transfers — in connection with a merger, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality protections;
  • With your direction or consent — when you explicitly authorize sharing.

14. Service Providers and Infrastructure

We use trusted third-party providers to deliver the Services. These may include:

  • Google Firebase and Google Cloud — authentication, Firestore database, Cloud Functions, Cloud Messaging (FCM), and related infrastructure. Data is primarily processed in India (asia-south1, Mumbai) with certain functions operating in other regions as required for reliability;
  • Google AI / cloud AI services — for optional fitness score and food analysis features, which may process photos you submit to generate outputs in the app;
  • Notifee and related notification tooling — for displaying local notifications on your device;
  • Optional telemetry endpoints — if configured in production, usage events may be sent to our monitoring infrastructure over HTTPS.

15. Service Providers — Additional Notes

These providers process data on our behalf under contractual terms that require appropriate security and confidentiality. Their use of information may also be governed by their own privacy policies.

We do not currently use dedicated third-party crash reporting SDKs (such as Firebase Crashlytics or Sentry) in the member app, and we do not integrate Apple HealthKit or Google Health Connect.

16. Push Notifications

If you enable push notifications, we collect and store a device messaging token (FCM) to deliver alerts about membership activity, gym communications, and service messages. You can disable notifications through your device settings; some in-app notices may still appear when you use the app.

17. Device Permissions

The app may request the following device permissions:

  • Camera — QR check-in / joining and capturing photos for AI features;
  • Photo library — selecting images for optional fitness score or food analysis;
  • Notifications — delivering push alerts;
  • Storage (Android) — sharing payment receipts as images.

18. Device Permissions — Location

We do not request or use GPS / precise device location for the Services. You can deny optional permissions; some features may be unavailable without them.

19. Data Retention

We retain personal information for as long as necessary to provide the Services, fulfill the purposes described in this policy, comply with legal obligations, resolve disputes, and enforce our agreements.

Account data is generally retained while your account remains active and for a reasonable period afterward. Gym-held member data retention is governed by your gym. When you leave a gym or request deletion, we will process eligible deletions subject to legal and operational requirements.

20. Security

We implement commercially reasonable technical and organizational measures designed to protect personal information against unauthorized access, loss, misuse, or alteration. These measures include access controls, encryption in transit (HTTPS), Firebase security rules, authentication safeguards, and monitoring of our cloud infrastructure.

No method of transmission or storage is completely secure. You are responsible for maintaining the confidentiality of your login credentials and for securing devices used to access the Services.

21. Your Rights and Account Deletion

Depending on applicable law, you may have rights regarding your personal information, including:

  • Accessing and obtaining a copy of information we hold about you;
  • Correcting inaccurate or incomplete information (certain profile fields can be updated in the app; gym-managed fields such as address or date of birth should be corrected through your gym);
  • Requesting deletion of your score.fit account and related personal information we control, subject to legal and contractual limits;
  • Restricting or objecting to certain processing;
  • Withdrawing consent where processing is based on consent;
  • Lodging a complaint with a supervisory authority where applicable.

22. Exercising Your Rights

To exercise these rights, including to request account deletion, contact us at support@score.fit. We may need to verify your identity before responding. Deleting your score.fit account may not automatically erase all records held by your gym; contact your gym for gym-managed member records.

23. Children's Privacy

The Services are not directed to children under 13. We do not knowingly collect personal information from children under 13 through account registration. You must meet the minimum age stated in our Terms of Use (generally 18, or the age of majority in your jurisdiction) to create an account.

If a gym records information about a minor member as part of its operations, the gym is responsible for obtaining appropriate parental or guardian consent and complying with applicable laws.

24. International Data Transfers

We primarily host and process data using infrastructure located in India. Some service providers may process data in other countries where they or their subprocessors operate. When information is transferred across borders, we take steps designed to ensure appropriate safeguards consistent with applicable law.

25. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will post the updated policy at https://score.fit/privacy-policy/ and update the "Last updated" date. We may also notify you by email or in-app notice where appropriate. Your continued use of the Services after changes become effective constitutes acceptance of the revised policy.

26. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, contact:

  • Appspade Technologies Private Limited
  • Email: support@score.fit
  • Website: https://score.fit
  • Product: score.fit member app