Who this covers
This policy applies to Fragile Labs websites, accounts, Fit, Sunday Money, Fragile Admin, and other services that link to it. “Fragile Labs,” “we,” and “us” refer to the operator of those services. A gym, household owner, or other organization may separately control information it enters or manages; contact that organization about its own practices.
Information we collect
| Category | Examples | Why we use it |
|---|---|---|
| Account and identity | Name, email, account identifier, verification state, passkey or MFA enrollment metadata, organization memberships, roles | Create and secure your account, sign you into products, recover access, and enforce permissions |
| Fit data | Height, weight, target weight, exercise records, strength benchmarks, workouts, programs, class attendance, and training plans | Provide fitness tracking, coaching, gym, class, and training features |
| Sunday Money data | Household membership, financial institution and account details, balances, transactions, merchants, categories, budgets, recurring items, and settings | Provide household budgeting, account connection, transaction, and financial-management features |
| Payments and access | Stripe customer and subscription identifiers, subscription status, price, payer type, and entitlement history | Process subscriptions, determine product access, prevent fraud, and keep accounting records. We do not store full card numbers. |
| Device and usage | IP-derived request information, browser or operating system, app version, route, timestamps, session identifiers, crash and security logs | Operate, secure, debug, and improve the services |
| Support and reports | Messages, bug descriptions, screenshots or recordings you submit, reporter email, route, platform, and app version | Answer requests, reproduce problems, and improve the products |
Where information comes from
- You, when you create an account, enter data, connect an account, subscribe, or contact us.
- Your gym, coach, household owner, or another authorized member when they invite you, assign access, create a plan, or manage shared information.
- Your connected financial institution through Plaid, only after you choose the institution and authorize the connection.
- Stripe and app stores for payment, subscription, and purchase status.
- Your browser, device, and our systems when you use or secure the service.
How we use information
We use personal data to provide requested features; authenticate users; isolate gyms and households; process subscriptions; send verification, recovery, invitation, access, and service messages; prevent fraud and abuse; troubleshoot bugs; protect the services; comply with law; and improve product reliability. We do not use fitness or financial data to determine credit, employment, insurance, housing, or eligibility for unrelated services.
When information is shared
We disclose only what is reasonably needed for the service:
- Authorized people in your tenant. Gym owners, coaches, or administrators may see member and training information allowed by their role. Sunday Money household members may see shared household financial information allowed by their role.
- Infrastructure and identity. Railway hosts application services and databases; Ory software provides identity and authorization infrastructure; Cloudflare provides DNS, routing, and security services.
- Payments and email. Stripe processes payments and subscription events. Resend delivers account and service email.
- Connected finance. Plaid connects Sunday Money to financial institutions and processes the data scopes shown during Plaid Link. Plaid’s own privacy policy also applies.
- App platforms. Apple or Google may process app distribution, purchase, device, and diagnostic information under their own terms.
- Legal and safety. We may disclose information when reasonably necessary to comply with law, protect people or the service, investigate fraud or abuse, or complete a business transaction subject to appropriate protections.
We do not sell personal data. We do not share personal data for cross-context behavioral or targeted advertising. We honor legally required universal opt-out signals such as Global Privacy Control where they apply, although our current practices do not involve sale or targeted advertising.
Consumer health data privacy notice
This section is our consumer health data privacy policy for laws such as Washington’s My Health My Data Act. Fit information can reveal or permit inferences about physical condition or fitness and is treated as sensitive.
Categories and purposes
We collect body measurements and goals, workout and exercise activity, strength benchmarks, training plans, class attendance, and related fitness profile information to provide the Fit features you or your gym request, maintain progress history, personalize training, secure the service, and provide support.
Sources
Consumer health data comes from you; from a gym, coach, or administrator acting in connection with your membership; and from your use of Fit. We do not currently collect this information from advertising data brokers.
Sharing
We may share the categories above with your authorized gym, coaches, or administrators; with Railway as our hosting provider; and with technical providers strictly as needed for security, support, and service delivery. We do not sell consumer health data and do not share it for advertising. We have no affiliates with which we share consumer health data.
Your health-data choices
You may ask whether we collect or share your consumer health data, request access, request a list of recipients, withdraw consent for future collection or sharing, or request deletion. Email [email protected]. You may use an existing account to help us verify the request, but you do not need to create a new one. Withdrawing or deleting data may prevent Fit from providing some features. We will not discriminate against you for exercising a privacy right.
Retention and deletion
We keep information only while reasonably needed for the purposes above. Account and product data generally remain while your account or relevant gym/household relationship is active. Authentication credentials and active grants are removed or disabled when an account is deleted. Security and administrative audit records are retained as reasonably needed to investigate incidents, prevent abuse, and document access changes; billing and transaction records may be kept longer when required for tax, accounting, dispute, fraud-prevention, or legal obligations. When backups contain personal data, they expire on their normal rotation. We may retain deidentified information and records necessary to protect other users’ shared household or organization data.
Your rights and choices
You may request confirmation of processing, access, correction, deletion, or a portable copy of personal data. Where applicable, you may also opt out of sale, targeted advertising, or certain profiling and appeal a denied request. Fragile Labs does not currently perform those opt-out activities. Manage available profile and security settings in your account or email [email protected]. We will verify requests to protect your account and normally respond within 45 days. If we deny a request, reply with “Privacy appeal” and explain why you believe the decision should be reconsidered.
Security and breaches
We use administrative, technical, and organizational safeguards described in our Security Policy. No method is perfectly secure. If a breach requires notice, we will notify affected people and regulators as required, including under applicable consumer-health breach rules.
Children
Fragile Labs is not directed to children under 13, and we do not knowingly create accounts for them. Sunday Money and financial-account connections are for adults. A minor age 13 or older may use Fit only with permission and oversight from a parent or legal guardian and, where relevant, the participating gym. Contact us to request deletion of a child’s information.
Changes and contact
We may update this policy as products or legal requirements change. We will post the updated date and provide additional notice when a change is material. Questions, accessible-format requests, and privacy requests can be sent to [email protected].