The Spanish version of this Privacy Policy is the official legal text. This English translation is provided for convenience. If there is any conflict, the Spanish version prevails.
This Privacy Policy describes how EresFitness ("we", "our" or the "Company") collects, uses, processes and protects your personal data when you use:- The Eres Fitness Woman mobile app (the "App"), available on the Apple App Store and Google Play Store.
- The website https://mujer.eresfitness.com and related domains (the "Website").
1. Data Controller
The controller of your personal data is:- Legal name: EresFitness S.A.S
- Address: Av 3 de mayo 2605, Puebla, Mexico
- Contact email: hola@eresfitness.com
- Website: https://mujer.eresfitness.com
2. Data We Collect
We collect information to provide a personalized training, nutrition and community experience.2.1. Data you provide directly
- Identity information: Name, nickname, email address, profile photo and banner (when you sign up with Google, Facebook, Apple, email, or when you complete an anonymous account).
- Health and biometric data:
- Weight, height, gender, date of birth or age.
- Body measurements (waist, arms, legs, body-fat percentage, etc.).
- Activity level, training limitations, fitness goals and muscle focus areas.
- Calorie, macro, micronutrient, water and step goals.
- Training data:
- Workout history, exercises, sets, reps and weights.
- Custom routines created manually or generated by the App, including AI-generated plans.
- Challenges, achievements, training streak, experience and level.
- Nutrition and hydration data: meal logs, calories, macros, micronutrients and water intake.
- Media: Progress photos or routine images imported from the camera, gallery or other apps.
- Social interactions: Friends, blocked users, follows, followers, profile visibility (public or private) and your leaderboard position, unless you hide your profile from the ranking.
- Social links: Instagram or TikTok usernames if you add them to your profile.
- Community content (UGC):
- Text posts in the Community feed.
- Images uploaded with those posts (stored in Firebase Storage).
- Comments and replies.
- Likes on posts and comments.
- Workout data you choose to share: When you share a report or training day in the Community, data such as calories burned, duration, completed exercises, plan name and day number may be published.
- User search: Recent Community user searches are stored locally on your device.
- Support: Messages you send to the in-app support assistant or to our contact email, including recent chat history.
- Marketing preferences: Whether you want promotional emails and push notifications.
2.2. Data collected automatically
- Technical identifiers: IP address, device ID (IDFA on iOS if you grant ATT, Android Advertising ID, IDFV), device model, operating system, time zone, language and approximate country.
- Usage and behavior: Interactions with the App and Website, screens visited, session length, ad clicks, onboarding events, experiments (for example Remote Config variants) and crash events.
- Subscription data: Subscription status (Free, trial or Premium), purchase and renewal history (processed through Google Play, the App Store and RevenueCat).
- Notification tokens: Device token used to send push notifications (APNs / FCM via Pushwoosh).
2.3. Apple Health and Health Connect data
If you enable sync, the App may read from Apple Health (HealthKit) or Health Connect (Android):- Steps, distance, exercise minutes and active calories.
- Completed workouts, weight, hydration and nutrition (calories and macros).
2.4. Contacts (find friends)
If you use "find friends from contacts", the App reads email addresses only from your address book, converts them into an irreversible hash (SHA-256) and sends those hashes to our servers to find matches with existing users. We do not upload names, phone numbers or your full address book. The hashes are not kept as a copy of your contacts.2.5. Anonymous accounts and deferred sign-up
You can start onboarding with a Firebase Auth anonymous session, without creating an email or social account yet. In that case we assign a technical identifier and store your quiz answers (goals, weight, equipment, etc.) so you do not lose progress. When you later link Google, Apple, Facebook or email, that data is attached to your permanent account.2.6. Website data
If you use the Website, we may also process:- Sign-up and sign-in data (email, name, authentication method).
- The
efw_authsession cookie, required to keep you signed in to the dashboard. - Local preferences (light/dark theme and sound) stored in your browser.
- Site performance data (Vercel Speed Insights): load times and technical metrics, not a marketing profile.
- Contact-form messages, which open in your email client toward hola@eresfitness.com. We do not store that form on our servers unless you send the email.
3. Purposes and Legal Bases
Under the LFPDPPP and GDPR, we process your data on the following legal bases:| Purpose | Data involved | Legal basis |
|---|---|---|
| Service delivery: Account management (including anonymous accounts), workout, nutrition, hydration and step tracking, and routine creation in the App and Website. | Identity data, health data, nutrition, workouts. | Contract performance: Needed to provide the basic features under our Terms of Use. |
| Personalization: Adapt training plans, calorie goals and suggestions. | Health data, usage history. | Explicit consent: By providing health data you consent to processing for fitness purposes (also GDPR Art. 9). |
| Apple Health / Health Connect sync: Read activity and write workouts, weight, water and meals. | Steps, distance, calories, workouts, weight, hydration, nutrition. | Explicit consent: Only if you enable sync and grant the system permission. |
| AI plans and support: Generate personalized routines and answer product questions using Google models (Gemini / Vertex AI). | Fitness profile, training preferences, recent history, hydration, nutrition, Premium status and the text of your support messages. | Contract / Consent: You start plan generation or the support chat. Health data is processed with explicit consent. |
| Analytics and improvement: Analyze errors, performance, sign-up funnels and usage trends. | Technical identifiers, usage data, profile attributes (including weight, height, goals and Premium status sent to Mixpanel and Firebase Analytics). | Legitimate interest: Keep the service reliable and improve it. |
| Advertising (free version): Show personalized ads. | Advertising IDs (IDFA/AAID), approximate usage data. | Consent: Requested through tracking prompts (ATT on iOS, CMP in Europe). |
| Marketing attribution: Understand which ad or campaign led to an install or purchase. | Device identifiers, IP, email (if available) via RevenueCat and, where applicable, Meta. | Consent / Legitimate interest: ATT on iOS for IDFA; email is used to match conversions if you are signed in. |
| Notifications and marketing: Workout reminders, transactional notices, in-app messages and, unless you opt out, promotional emails. | Device token, user ID, email, language, country. | Consent / Legitimate interest: Push requires the system permission. Promotional email can be turned off in notification settings. |
| Social features and ranking: Show progress on the global leaderboard and allow interaction with other users. | Username, profile photo, experience points/stats. | Contract / Legitimate interest: Provide a motivating community. You can hide yourself from the ranking. |
| Find friends from contacts: Find users who already use the App. | Hashes of emails from your address book. | Consent: Only if you grant contacts permission. |
| Community and social content: Create and view posts, comments, likes and shared workout data. | Username, nickname, profile photo, post and comment text, images, shared workout data, like IDs. | Contract / Consent: You choose to publish content visible to other users. |
| Content moderation: Handle reports and hide or remove content that violates the rules. | Reporter ID, post ID, reason, date and time. | Legitimate interest: Keep a safe community. |
| UX improvement (Microsoft Clarity): Understand how you use the App through session recordings and heatmaps. | Navigation data, taps, clicks. | Legitimate interest: Improve usability. |
| Legal compliance: Billing, taxes and fraud prevention. | Transaction data. | Legal obligation: Tax and accounting laws. |
4. Device Permissions
The App may request access to:- Camera: Profile photos, progress photos, scanning routines or Community images.
- Photo library / storage: Upload profile photos or import routines and Community images.
- Contacts: Emails only, hashed, to find friends who already use the App.
- Health (HealthKit / Health Connect): Sync steps, activity, workouts, weight, water and nutrition if you enable it.
- Motion / physical activity: Count steps and daily activity.
- Notifications: Workout reminders, streak alerts, community and system notices.
- Microphone: Only if a video feature requires it.
- Network / Internet: Cloud sync and authentication.
- Advertising identifier: Relevant ads (only with your consent).
5. Data Sharing and Third Parties
We do not sell your personal data. We share information only with service providers needed to operate the service ("processors") and, when you post, with other users of the App.Visibility of Community content
When you post in the Community, your username, nickname and profile photo are embedded in each post and comment and are visible to all users of the App. Images are stored in Firebase Storage (community/posts/) for as long as the post exists.
Main service providers:
- Google Firebase (USA):
- Role: Authentication (including anonymous), Firestore, Storage, Cloud Functions, Analytics, Crashlytics, Remote Config and App Check.
- Data: Email or anonymous UID, profile, workouts, nutrition, images, community content, crash logs and remote configuration.
- Google Vertex AI / Gemini (USA):
- Role: Generate training plans and power the support assistant.
- Data: Fitness profile, preferences, relevant recent history and the text of your messages.
- Google AdMob (USA):
- Role: Ads for the free version.
- Data: Advertising identifiers, approximate location, usage data.
- RevenueCat (USA):
- Role: Subscriptions, trials and in-app purchases. It may also forward identifiers to Meta to attribute conversions.
- Data: User ID, email (if available), transaction history, device identifiers and IP.
- Mixpanel (USA):
- Role: Behavior analytics and cohort sync with notifications.
- Data: Usage events, user ID, email and profile attributes (goals, weight, height, Premium, country, language, etc.).
- Pushwoosh (USA):
- Role: Push notifications, in-app messages and transactional or promotional email.
- Data: User ID, device token, email, language and country.
- Meta / Facebook (USA):
- Role: Facebook Login and, where applicable, ad attribution.
- Data: Name, email and photo if you sign in with Facebook; attribution identifiers if you granted ATT.
- Apple and Google (USA):
- Role: Sign-in, app stores, HealthKit / Health Connect and push delivery (APNs / FCM).
- Microsoft Clarity (USA):
- Role: Session recordings and heatmaps in the App.
- Data: Interaction data, country, device, screens visited.
- Vercel (USA):
- Role: Website hosting and Speed Insights (performance).
- Data: IP, user-agent and technical load metrics.
6. International Data Transfers
Many of our providers (Google, RevenueCat, Mixpanel, Pushwoosh, Meta, Vercel, Microsoft) are located in the United States. For users in the European Economic Area (EEA), these transfers are made with appropriate safeguards:- EU-US Data Privacy Framework: For certified providers.
- Standard Contractual Clauses (SCCs): Contracts approved by the European Commission.
7. Cookies and Local Storage
7.1. Website
The Website uses:- Strictly necessary cookie
efw_auth: stores a session token (1 hour,SameSite=Lax,Secureon HTTPS) to keep you signed in. Without it you cannot use the private dashboard. - Browser local storage: theme preference (
efw-theme) and sound. Not used for advertising. - Vercel Speed Insights: performance metrics. It may include technical identifiers from the hosting platform.
7.2. App
The App uses local storage (SharedPreferences / Keychain) for session, preferences, health consents and recent searches. The SDKs listed in section 5 may use their own identifiers on the device.8. Data Retention
We keep your personal data only as long as needed for the purposes described:- Active account (including anonymous): For as long as the account remains open.
- Inactive accounts: If you do not use the Service for a prolonged period (e.g. 2 years), we may delete or anonymize your data, with prior notice when possible.
- Health and nutrition data: Deleted when you delete the account. The copy in Apple Health or Health Connect stays under your control on those platforms.
- Community content: Kept while it exists. You can delete your posts in the App. Deleting your account removes the associated content.
- Support chats: Recent history is used to give context to the reply and is not kept longer than needed for support and safety.
- Contact hashes: Processed for the search and not stored as an address book.
- Moderation reports: For as long as needed for community safety.
- Legal data: Billing data may be kept for 5 or 10 years under tax laws.
9. Your Rights (ARCO and GDPR)
You have the following rights:- Access: Know what data we have and obtain a copy.
- Rectification: Correct inaccurate data (you can edit your profile in the App or Website).
- Erasure ("right to be forgotten"): Request full deletion of your account and data.
- In the App:
Options > About > Delete my account. - Web instructions: mujer.eresfitness.com/en/delete-account.
- In the App:
- Restriction of processing.
- Portability: Receive your data in a structured format (e.g. JSON or CSV).
- Objection: Object to direct marketing or processing based on legitimate interest.
- Withdraw consent: Notifications, promotional email, advertising, Health and contacts can be turned off in the App or the system.
- Community content: You can delete your posts and comments and report inappropriate content.
10. Data Security
We apply technical measures to protect your information:- Encryption in transit (HTTPS/TLS) and at rest (Google servers).
- App Check and access rules on Firestore/Storage.
- Access limited to authorized staff.
- Error and vulnerability monitoring.
11. Children's Policy
This platform is not directed at children under 16 (or the minimum digital-consent age in your country). If you are between 16 and 18, use requires parental authorization and supervision, as set out in our Terms. We do not knowingly collect data from children under 16. If you are a parent and believe your child provided data, contact us so we can delete it.12. Changes to this Policy
We may update this policy to reflect legal changes or new features. If the changes are material, we will notify you via the App, the Website or email before they take effect.13. Contact and DPO
If you have questions about this Privacy Policy or want to contact our Data Protection Officer (DPO), write to:- Email: hola@eresfitness.com
- Subject: Data Privacy / GDPR / LFPDPPP