Transparency Center.
Effective from: August 23, 2026
Privacy Policy
At TheFittClub we look after your data with the same calm we look after your body. Here we explain, with no small print, what data we process, why, for how long, and what control you have over it, under Regulation (EU) 2016/679 (GDPR) and Spain's Organic Law 3/2018 (LOPDGDD).
1. Data controller
- Controller: Virginia Galadriel Calero López (Gala Calero).
- Contact: hola@thefittclub.com
- Full identification (tax ID and address): see the Legal Notice.
2. What data we process, why, and on what legal basis
- Account and access (email, name, encrypted credentials): to create and manage your account. Basis: performance of the contract (Art. 6(1)(b) GDPR).
- Physical profile and onboarding answers (level, goals and, if you choose to personalise, postpartum status, births, physical considerations): to calibrate your plan and avoid movements that aren't recommended. Basis: the contract for ordinary data and your explicit consent (Art. 9(2)(a) GDPR) for health data.
- Journal and AI tags (if you enable the journal): to give your own reflections back to you, organised. Basis: your explicit consent for that feature.
- Session progress: to show you your evolution. Basis: the contract.
- Product analytics (events with no identifying data): to improve the product. Basis: your consent (cookie banner).
- Error monitoring (when something breaks: internal identifier, page, language and browser): to keep the service stable and secure. Basis: legitimate interest (Art. 6(1)(f) GDPR).
- Billing (when payments apply): to charge and meet tax obligations. Basis: contract and legal obligation (Art. 6(1)(b) and 6(1)(c)).
- Testimonials (your name, email, country and the answers you write in the “Your story” form): to publish your experience with the attribution level you choose — your full name, your first name only, or anonymously — on our website, on our social media and in our email communications. Basis: your consent (Art. 6(1)(a)) and, where your story mentions health data, your explicit consent (Art. 9(2)(a)). Nothing is published without that permission, and you can withdraw it at any time by writing to hola@thefittclub.com.
- Emails we send you and their metrics (if you gave us permission to write to you: which email we sent, whether it arrived, whether it was opened, which link you clicked and whether it bounced): to learn which content actually helps you, stop sending what does not interest you, and keep our emails arriving. Opens are measured with a small pixel and clicks with measurement links from our sending provider (Resend); we use no third-party trackers. Basis: your consent (Art. 6(1)(a) GDPR), the same consent under which you accepted these emails; technical delivery and bounce notices rest on our legitimate interest in stable sending (Art. 6(1)(f)). Unsubscribing (link in every email) stops both the sending and the measuring.
3. Health data (special category)
We treat your postpartum status, the physical considerations you share, and your journal text as health data (Art. 9 GDPR). We only store them with your explicit consent. You can use the product you paid for without sharing them: if you choose to enter without personalising, you get a base plan and none of this is stored. TheFittClub is a wellbeing and fitness product; it is not a medical service and does not diagnose or treat any condition.
We also treat the text of the testimonials you send us as health data, because in telling your experience you may mention your postpartum situation or physical considerations. They are published only with your explicit consent and with the attribution you chose; if you withdraw your permission, we stop publishing it and it is not used again anywhere new.
4. Who else processes your data (processors)
We work with providers that process data on our behalf, under contract (Art. 28 GDPR):
- Cloudflare — hosting and database (data in the EU; US parent entity).
- Anthropic — AI analysis of journal text (USA).
- Resend — service and news email delivery, and its delivery/engagement metrics (USA; EU sending infrastructure).
- PostHog — product analytics (data in the EU, Frankfurt; US parent entity).
- Sentry — error monitoring (data received in the EU, Germany; US parent entity).
- Stripe — payments (once enabled; Irish and US entities).
- Meta Platforms — publication of testimonials on Instagram, only where you have consented (USA).
We do not sell your data nor share it with third parties for their own purposes.
5. International transfers
Several of these providers have a US parent entity (Anthropic, Resend, Cloudflare, PostHog, Sentry, Meta and, once enabled, Stripe), although in several cases the data is hosted in the EU. Where a transfer to the USA exists, it relies on the European Commission's standard contractual clauses, with appropriate safeguards.
6. How long we keep your data
- Account and profile data: while you have an account; after you request closure, a 30-day grace period and then deletion.
- Health data: while you have an account or until you withdraw consent; after your withdrawal or request, we delete it within one month at most.
- Testimonials: while they remain published and, in any case, until you withdraw your consent; on withdrawal we unpublish them and stop using them for anything new. What was already printed or shared before the withdrawal cannot always be recalled, which is why we ask for permission before publishing. If your story is never published — because it is still awaiting review or because we decide not to publish it — we delete it 12 months after you sent it, without you having to ask. And if you withdraw your permission for a story we already published, we unpublish it and delete your name and email at that same moment; the record that it was published with permission and then withdrawn is kept for 12 more months, no longer identifying you, and is then deleted entirely.
- Consent records: 3 years after the relationship ends, as proof.
- Billing: the legal accounting period (7 years) when payments apply; if you delete your account, we detach and redact your personal data and keep the financial row under legal obligation (Art. 17(3)(b) GDPR).
- Email metrics (deliveries, opens, clicks and bounces): 24 months from the event; deleted earlier if you delete your account or exercise erasure.
- Security audit log: 7 years; kept even if you delete your account, as a legal-defence record (Art. 17(3)(e) GDPR).
- Error logs: 90 days (deleted automatically).
- AI provider logs (Anthropic): 30 days at the provider; it offers no per-user deletion, which is why we scrub identifying data from the text before sending it.
- Product analytics: up to 7 years at the provider (PostHog), with earlier deletion when you exercise erasure.
- Backups: 90-day rolling window; deleted data also ages out of the backups within that period.
7. Your rights
At any time you can exercise your rights of access, rectification, erasure, objection, restriction, portability and withdrawal of consent (without affecting the lawfulness of prior processing). To exercise them, write to hola@thefittclub.com; we'll respond within one month at most.
8. Complaint to the supervisory authority
If you believe we haven't handled your data correctly, you can complain to the Spanish Data Protection Agency (AEPD), C/ Jorge Juan 6, 28001 Madrid — www.aepd.es.
9. Changes to this policy
If we change anything material, we'll update this page and the effective date, and ask you again where needed.