Aida Zolj
Privacy Policy
Last updated: July 12, 2026
This Privacy Policy applies to the services, website and mobile application of Aida Zolj ("we", "us", "our"). Our personal training and coaching services are delivered through the Trainera platform, developed and operated by TRAINERA.FIT LLC ("Trainera", "the Platform"), including its iOS and Android applications and associated services.
Aida Zolj is the provider of your coaching and fitness services; Trainera is our technology provider and processes data on our behalf on secure infrastructure. This policy explains how your information is collected, used, disclosed and safeguarded across both, including our integration with Google, Facebook, Apple and other third-party services for authentication and optional fitness data access.
By using our services, you agree to the collection and use of information in accordance with this Privacy Policy.
1. Authentication Methods
You can create an account and sign in in several ways. Here is what data each method involves:
- Google Sign-In - scopes requested: openid, email, profile. We receive and store your email, name and profile picture.
- Facebook Sign-In - scopes requested: email, public_profile. We receive and store your email, name and profile picture.
- Apple Sign-In - scopes requested: email, name. We receive your email (which may be a private relay address) and name (provided on first sign-in only), and store your Apple user identifier, email and name.
- Email & password - we collect your email address, name and password. Passwords are hashed with bcrypt and never stored in plain text.
- Phone number verification - we collect your phone number and a verification code. SMS codes are delivered via Twilio, which receives your phone number for that purpose.
These sign-in methods are used for authentication and account creation only. Use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. No other Google API scopes (such as Google Drive, Gmail or Google Photos) are requested or used.
2. Optional Health & Fitness Integrations
The app can optionally connect to health platforms to display your health and fitness data alongside your training. Every integration below is completely optional, must be enabled manually, and can be disconnected at any time without affecting any core functionality (workouts, coaching, nutrition tracking).
Apple HealthKit (iOS)
With your explicit permission, the app may request read access to: steps, active energy burned, basal energy burned, heart rate (during workouts), resting heart rate, walking/running distance, flights climbed, exercise minutes, stand hours, workout sessions, sleep analysis, body mass, body fat percentage, lean body mass, blood pressure, blood oxygen saturation (SpO2), respiratory rate, body temperature, water intake and mindful minutes.
- Synced HealthKit data is retained on the Platform's servers for up to 30 days to provide progress charts, analytics and historical comparisons; older data is automatically deleted.
- HealthKit data is NOT shared with third parties, AI services, advertisers or data brokers, and is never used for advertising or marketing.
- Your trainer do NOT have access to your HealthKit data unless you explicitly share specific metrics.
- When you disconnect Apple Health, all synced HealthKit data is deleted from the servers. You can revoke access at any time in iOS Settings > Privacy & Security > Health, and choose which specific data types to share.
Google Fit
Read-only scopes: fitness.activity.read (steps, distance, calories, active minutes), fitness.body.read (weight, height, body composition), fitness.heart_rate.read (heart rate) and fitness.location.read (workout routes, if logged in Google Fit).
- Read-only access - your Google Fit data is never written, modified or deleted.
- Data is fetched in real-time for display and not permanently stored; temporary caches are deleted within 24 hours.
- Your trainer do NOT automatically see your Google Fit data.
- You can disconnect anytime in account settings or revoke access at Google Account Permissions (myaccount.google.com/permissions); all cached data is then immediately deleted.
Huawei Health Kit
Read-only access to activity data (steps, distance, calories), sleep data and basic body measurements, used only to display your health information inside the app.
- Only a single historical data record is requested when you grant permission, to initialize your health overview.
- No background, continuous or cross-device data synchronization is performed, and no medical diagnosis or health analysis.
- Huawei Health Kit data is not permanently stored, not shared with trainers or third parties, and not transmitted back to Huawei by the app.
- You can disconnect anytime in account settings or through your Huawei account settings.
Smartwatch Heart Rate Monitoring
With explicit permission on your smartwatch (Apple HealthKit heart rate / Android BODY_SENSORS), the app captures real-time heart rate during active workouts for per-set tracking and intensity analytics.
- Heart rate is read ONLY while a workout is in progress - never in the background.
- Per-set and session heart rate samples are saved as part of your workout progress data and may be visible to your trainer.
- You can deny the permission at any time; workouts function normally without heart rate data.
Google Calendar
Optional sync of your scheduled training sessions to your personal Google Calendar (scope: calendar.events).
- Only events created by the app are created, updated or deleted - your other calendar events are never read or modified.
- Only calendar event IDs are stored to track synced sessions; no calendar content is stored on the servers.
- Your trainer have no access to your Google Calendar data.
- When disconnected, synced events remain in your calendar but are no longer updated.
3. Information We Collect
Account and Profile Information
- Name and email address (from Google, Facebook, Apple Sign-In or direct registration).
- Phone number (for account verification and contact).
- Profile information: age, gender, fitness goals, experience level, profile and cover photos.
- Medical conditions and allergies - special category data you provide voluntarily so training and nutrition can be adjusted safely.
Health and Fitness Data
- Body measurements (weight, height, body fat percentage, muscle mass, circumference measurements).
- Progress photos (before/after images you upload).
- Workout data (exercises, sets, reps, weights, duration, sessions) and training/nutrition plans assigned to you.
- Nutrition data (meal logs, calorie tracking, macronutrients, water intake).
- Data from connected health providers (Apple HealthKit, Google Fit, Huawei Health Kit) and smartwatch heart rate, as described in Section 2.
Communication Data
- Direct messages between you and us (text, images, files) and group chat messages within training groups.
- Support communications and AI Coach chat conversations.
- Transactional emails and notifications.
Payment and Financial Data
The data collected depends on the payment method used. Card details are never stored on the servers.
- Apple App Store / Google Play (in-app purchases): only purchase confirmation data is received - plan, purchase date, expiration date and transaction identifiers.
- Stripe (card payments on the web): card details go directly to Stripe; only Stripe customer ID, subscription ID, payment status and transaction metadata are stored.
- PayPal: transaction ID, payment status and payer email.
- Bank transfer: IBAN, SWIFT/BIC, account holder name and bank name, used solely to verify received payments and process refunds.
- Cash payments: only the amount, date and confirmation status are recorded.
Location, Usage and Technical Data
- IP-based geolocation (country, city) for content localization and security.
- GPS location (mobile app, only when explicitly permitted) for finding nearby gyms and trainers.
- Device information (type, operating system, browser, app version), usage patterns, cookies and session tokens.
- Push notification tokens (Firebase Cloud Messaging, Expo), error logs and crash reports (Sentry), and login history (timestamps, IP, device) retained 90 days for security auditing.
AI-Related Data
- Food photos submitted for AI nutritional analysis.
- Chat messages sent to the AI Coach (processed by OpenAI and Anthropic Claude).
- Anonymized fitness context data used for AI-generated training and nutrition plans.
4. How We Use Your Information
Your information is used to:
- Provide our personal training and coaching services: personalized training and nutrition plans, progress tracking and communication with us.
- Create and authenticate your account, process payments and manage subscriptions.
- Display health data from connected providers, generate progress charts, analytics and historical comparisons.
- Provide AI-powered insights and plan generation, and send transactional emails and push notifications.
- Ensure security, prevent fraud and abuse, and comply with legal obligations.
Your data is not used for third-party advertising, and your personal information is never sold.
5. Data Storage, Retention and Deletion
- Account data is stored securely and retained while your account is active; it is deleted or anonymized within 90 days of account deletion. Backups are kept for 30 days for disaster recovery.
- Apple HealthKit data: up to 30 days, deleted immediately on disconnect. Google Fit data: not permanently stored (24-hour cache). Huawei Health Kit data: not permanently stored.
- Body measurements, progress photos, workout and nutrition logs: retained while your account is active, deleted upon account deletion.
- Chat messages: retained while your account is active and for 30 days after deletion.
- Payment transaction records: retained for the legally required period (typically 7 years for tax and financial reporting).
- OAuth tokens are stored encrypted and deleted when a connection is revoked or the account is deleted.
You can delete your account and data at any time using the account deletion option in settings, or by contacting us or support@trainera.fit. Requests are processed within 30 days.
6. Data Sharing and Third Parties
Your personal information is never sold, rented or traded for marketing purposes. Data is shared only with:
- Aida Zolj and team members who assist in delivering your coaching - your profile data, workout data, measurements, nutrition logs and communications. Connected health data (HealthKit, Google Fit, Huawei) is NOT automatically shared with anyone.
- TRAINERA.FIT LLC, as the platform operator and data processor described above (its platform privacy policy is at https://trainera.fit/privacy-policy).
- Service providers, only as necessary to operate the service: Google (authentication, Fit, Calendar, Cloud Storage, Places, reCAPTCHA, Analytics/GA4), Meta/Facebook (sign-in), Apple (sign-in, in-app purchases), Stripe and PayPal (payments), Twilio (SMS), Sentry (error monitoring), OpenAI and Anthropic (AI features), Firebase and Expo (push notifications), email delivery providers, Huawei (Health Kit), IP geolocation services and OpenStreetMap (maps).
- Authorities, if required by law, court order, or to protect safety and prevent fraud.
These providers are contractually bound to protect your data and use it only for the specified purposes. Google Fit and Apple HealthKit data is not shared with any third-party service providers.
7. Your Rights and Control
You can access and update your information in account settings, request a copy of your data in a portable format, and request account and data deletion (processed within 30 days). You can revoke each sign-in or integration through account settings and through the provider (Google Account Permissions, Facebook Settings > Apps and Websites, Apple ID Settings > Sign-In & Security, iOS Health permissions, Huawei account settings).
If you are in the European Economic Area (GDPR), you additionally have the right to: access, rectification, erasure ('right to be forgotten'), restriction of processing, data portability, objection to processing based on legitimate interests, and withdrawal of consent for optional features at any time. Legal bases for processing are: consent, contract performance, legal compliance and legitimate business interests. You may lodge a complaint with your supervisory authority.
California residents (CCPA) have the right to know, right to delete, right to opt out of data sales (data is not sold) and the right to non-discrimination for exercising privacy choices.
8. Security Measures
Your data is protected with industry-standard practices:
- Encryption in transit (SSL/TLS) and at rest, and encrypted storage of OAuth tokens.
- Passwords hashed with bcrypt - never stored in plain text.
- Role-based access control, secure OAuth 2.0 implementation, rate limiting on sensitive endpoints and regular security monitoring.
No internet transmission is 100% secure, but any data breach will be notified as required by law.
9. AI-Powered Features
Optional AI features include food photo analysis, personalized fitness insights, AI-assisted training and nutrition plan generation, and an AI Coach chat.
- Food photos are processed in real-time by the AI food recognition service and are not permanently stored.
- AI Coach messages are sent to OpenAI or Anthropic Claude to generate responses; anonymized fitness context (workout summaries, nutrition goals) may be used for plan generation.
- Your identity data (name, email, phone) is NOT included in AI requests, your health records are NOT sent without your explicit action, and your private messages with us are NOT processed by AI.
- You can opt out of AI features at any time in account settings. AI-generated content is informational and does not replace professional medical or nutritional advice.
10. Health Disclaimer
The fitness and nutrition information provided through our services is not medical advice. Always consult a physician before starting a new training or nutrition program, especially if you have a medical condition.
11. Children's Privacy
Our services are not intended for children under 16, and personal data of children under 16 is not knowingly collected. If you believe a child has provided personal data, contact us or support@trainera.fit and it will be deleted as quickly as possible.
12. International Data Transfers
Your information may be transferred to and processed in countries other than your own, whose data protection laws may differ. Appropriate safeguards are applied, including Standard Contractual Clauses (SCCs) where required for transfers from the EEA.
13. Cookies
The website uses cookies and similar technologies:
- Essential cookies: authentication session tokens, CSRF protection and security cookies required for the site to function.
- Functional cookies: language preferences and interface settings.
- Analytics cookies: Google Analytics (GA4) to understand usage and improve the experience.
You can manage cookies in your browser settings; disabling essential cookies may affect functionality.
14. Changes to This Policy
This policy may be updated to reflect changes in practices, technology or legal requirements. Material changes will be communicated via email or a prominent notice at least 30 days in advance. The 'Last updated' date at the top shows the current version.
15. Contact
You can reach Aida Zolj directly at aidazolj1@gmail.com, or by messaging us through the app.
For technical questions about the underlying platform (login issues, billing through the app stores, privacy and data requests), you can also contact the platform operator, TRAINERA.FIT LLC, at support@trainera.fit. Privacy-related requests (access, deletion, data portability) are answered within 30 days; we may need to verify your identity before processing them.