Privacy Policy

Last updated: May 2, 2026

1. Introduction and Scope

BeFit Ai is a mobile fitness, nutrition, hydration, artificial-intelligence coaching, and social-interaction application owned and operated by Joseph Nuzhny Rybaloff (“BeFit Ai,” “we,” “us,” or “our”). BeFit Ai is designed to provide athletes and individuals with access to general workouts, personalized workout plans, personalized diet plans, hydration tracking, AI-powered coaching features, and, where available under the relevant subscription tier, social-media functionality that allows users to post, comment, add friends, and exchange messages. The application is intended for distribution through the Apple App Store and Google Play Store, and the owner has confirmed that BeFit Ai will not, at launch, connect reports with Apple Health, Google Fit, or comparable health-application ecosystems.

The present Privacy Policy explains how BeFit Ai collects, uses, stores, discloses, protects, and otherwise processes personal information when users download, access, register for, subscribe to, interact with, or otherwise use the BeFit Ai mobile application, website, account portal, customer-support channels, social features, AI coaching tools, or related services (collectively, the “Services”).

For users located in the European Union, European Economic Area, or United Kingdom, personal-data processing may be subject to Regulation (EU) 2016/679, commonly known as the General Data Protection Regulation (“GDPR”), which sets forth transparency, lawful-basis, data-subject-rights, security, and accountability obligations for controllers and processors. For users located in New Jersey, the New Jersey Data Protection Act became effective on January 15, 2025, and provides privacy rights for New Jersey residents under specified statutory conditions. Where additional United States state privacy laws apply, including the California Consumer Privacy Act as amended, BeFit Ai will apply the relevant rights to eligible users in accordance with applicable thresholds, exemptions, and legal requirements.

2. Controller and Contact Details

For purposes of applicable privacy and data-protection laws, the controller or business responsible for determining the purposes and means of processing personal information is:

Controller: Joseph Nuzhny Rybaloff, operating as BeFit Ai.
Jurisdiction: New Jersey, United States of America.
Contact Email: info@befitaiapp.com
Application Name: BeFit Ai.
Website or App URL: https://befitaiapp.com.

Privacy-related inquiries, access requests, deletion requests, correction requests, consent withdrawals, objection requests, data-portability requests, complaints, and other personal-data matters should be directed to the contact details above. When a request concerns subscription billing processed through Apple or Google, the user may also need to manage payment-related settings directly through the applicable app-store account.

3. Categories of Personal Information Collected

BeFit Ai may collect personal information directly from users, automatically through the Services, and from authorized third-party service providers. The exact categories collected may depend on the subscription tier selected, the features used, the device settings enabled, and the information voluntarily supplied by the user.

Account Information: BeFit Ai may collect name, username, email address, password credentials, authentication data, account identifiers, profile photo, user preferences, subscription tier, account status, and registration date.

Fitness and Wellness Information: BeFit Ai may collect fitness goals, workout preferences, sport type, activity level, height, weight, age range, sex or gender where voluntarily provided, body-composition goals, training frequency, equipment availability, lifestyle objectives, dietary preferences, meal-planning inputs, hydration targets, water-intake records, and related wellness responses entered through questionnaires or account settings.

Nutrition and Diet Information: BeFit Ai may collect meal preferences, food dislikes, dietary restrictions, allergy-related information voluntarily supplied by the user, nutritional goals, calorie-related objectives, macro-related preferences, and meal-plan feedback. Users should avoid entering medical diagnoses, sensitive allergy histories, or clinical diet instructions unless necessary for safe use and unless they understand that such information may be treated as sensitive personal information under applicable law.

AI Interaction Data: When users interact with the AI Coach or other AI-supported features, BeFit Ai may collect prompts, responses, chat history, plan-generation inputs, generated recommendations, correction requests, feedback, safety flags, and usage patterns. AI interaction data may be processed to deliver personalized outputs, improve app functionality, maintain safety controls, debug errors, and address user-support requests.

Social-Platform Information: Where social features are available, BeFit Ai may collect posts, comments, uploaded images, uploaded videos, captions, friend connections, likes, reactions, messages, blocked-user actions, reports, moderation history, profile visibility settings, and other community interactions.

Subscription and Transaction Information: BeFit Ai may collect subscription tier, renewal status, cancellation status, purchase history, transaction identifiers, app-store receipts, limited billing metadata, and tax-related information. Full payment-card details are generally processed by third-party payment processors or app-store providers, and BeFit Ai does not intend to store complete card numbers.

Device and Technical Information: BeFit Ai may collect device type, operating system, app version, IP address, approximate location derived from IP address, language settings, crash logs, diagnostic data, session duration, feature interactions, notification settings, device identifiers, and security logs.

Customer-Support Information: When a user contacts BeFit Ai, we may collect the user’s name, email address, account details, inquiry content, screenshots, attachments, support history, and any additional information voluntarily supplied to resolve the request.

4. Sensitive Personal Information

Because BeFit Ai operates in the fitness, nutrition, hydration, and wellness context, certain information submitted by users may be sensitive. Fitness goals, body metrics, dietary restrictions, health-related preferences, workout limitations, injury-related comments, hydration habits, or nutrition responses may reveal information about physical condition, lifestyle, or wellness status.

BeFit Ai does not intend to operate as a covered health-care provider, health plan, or health-care clearinghouse under the Health Insurance Portability and Accountability Act (“HIPAA”), unless future facts create such status under applicable law. Even where HIPAA does not apply, the Federal Trade Commission has stated that mobile health-app developers should build sound privacy and security practices into their products, and certain non-HIPAA health apps may be subject to the FTC Health Breach Notification Rule when personal health-record information is breached.

Users should not enter emergency medical information, highly sensitive clinical records, mental-health crises, eating-disorder details, medication instructions, or physician-directed treatment plans into BeFit Ai. The Services are not intended for diagnosis, treatment, medical monitoring, emergency response, or professional health-care decision-making.

5. Purposes for Processing Personal Information

BeFit Ai may process personal information for the following purposes:

Account Administration: To create accounts, authenticate users, manage profile settings, maintain subscription access, prevent unauthorized access, and provide account-related notifications.

Personalized Fitness and Nutrition Services: To generate general workouts, personalized workout plans, personalized diet plans, hydration targets, lifestyle suggestions, sport-specific plans, and related recommendations based on user-provided information.

AI Coach Functionality: To process prompts, questionnaire responses, preferences, goals, and interaction history for the purpose of generating AI-supported coaching responses, adapting recommendations, improving user experience, and reducing unsafe or irrelevant outputs.

Social Features and Community Safety: To enable posting, commenting, messaging, friend connections, content display, moderation, user reporting, abuse prevention, harassment review, and community-integrity controls.

Subscription Management: To confirm purchases, verify app-store receipts, manage renewals, apply plan access, process cancellations, support billing questions, and detect fraudulent subscription activity.

Customer Support: To respond to inquiries, troubleshoot technical issues, investigate complaints, process account requests, and document support interactions.

Security and Fraud Prevention: To detect unauthorized access, misuse, bots, scraping, spam, fraud, harmful content, suspicious login behavior, and violations of the Terms and Conditions.

Analytics and Product Improvement: To understand feature usage, improve performance, fix bugs, test app functionality, assess user engagement, and develop safer, clearer, and more reliable Services.

Legal Compliance: To comply with applicable laws, enforce contractual rights, respond to lawful requests, preserve evidence, protect legal claims, comply with regulatory obligations, and satisfy data-protection duties.

6. Legal Bases for Processing for EU, EEA, and UK Users

Where GDPR or comparable UK data-protection law applies, BeFit Ai relies on one or more lawful bases for processing personal data.

Contractual Necessity: Processing is necessary to create and maintain user accounts, provide subscription features, generate plans requested by the user, manage access, and deliver the Services.

Consent: Consent may be relied upon for certain optional processing, including non-essential cookies, marketing communications, sensitive wellness inputs where required, certain AI personalization choices, and optional community functions.

Legitimate Interests: Processing may be based on legitimate interests in securing the Services, preventing fraud, improving app functionality, responding to support requests, enforcing community rules, protecting users, and maintaining operational integrity, provided that such interests are not overridden by user rights and freedoms.

Legal Obligation: Processing may be necessary to comply with tax rules, consumer-protection duties, data-protection obligations, lawful requests, dispute records, or regulatory requirements.

Vital Interests: In limited circumstances, processing may occur where necessary to protect a person’s vital interests, although BeFit Ai is not designed as an emergency service.

Articles 13 and 14 of the GDPR require transparent information to be provided when personal data is collected from the data subject or obtained from other sources, and Articles 15 through 22 set forth rights including access, rectification, erasure, restriction, portability, objection, and rights concerning certain automated decision-making.

7. Artificial Intelligence and Automated Processing

BeFit Ai may use artificial intelligence technologies, machine-learning systems, natural-language-processing models, recommendation engines, and automated rule-based tools to provide personalized fitness, nutrition, hydration, and coaching features. AI-supported functions may analyze user-provided goals, questionnaire responses, workout preferences, sport selections, dietary inputs, and interaction patterns to generate or adjust recommendations.

AI-generated outputs may be inaccurate, incomplete, unsuitable, or inappropriate for a specific user’s circumstances. BeFit Ai’s Privacy Policy explains the data-processing aspect of AI features, while the Terms and Conditions govern user responsibility, health disclaimers, and limitations of reliance. Users should not submit information into the AI Coach that they do not wish to be processed for the purposes described in the present Policy.

Where applicable law requires transparency regarding automated decision-making or profiling, BeFit Ai will provide meaningful information about the logic involved, the significance of the processing, and the expected consequences, to the extent required and technically feasible. BeFit Ai does not intend to make decisions producing legal effects, or similarly significant effects, solely by automated processing within the meaning of Article 22 GDPR, unless specifically disclosed and supported by a valid lawful basis.

8. Cookies, SDKs, Analytics, and Similar Technologies

BeFit Ai may use cookies, software development kits, mobile identifiers, analytics tools, local storage, crash-reporting tools, and similar technologies to operate the Services, maintain login sessions, remember preferences, detect errors, analyze performance, prevent abuse, measure engagement, and improve functionality.

Strictly Necessary Technologies: Certain technologies are required for authentication, subscription access, security, fraud prevention, app stability, and core service delivery.

Analytics Technologies: Analytics tools may help BeFit Ai understand how users navigate the Services, which features are used, where errors occur, and how performance can be improved.

Preference Technologies: Preference tools may remember language settings, notification choices, interface preferences, and feature settings.

Marketing Technologies: Where used, marketing or advertising technologies will be addressed in a separate Cookie Policy or consent interface, and non-essential tracking will be subject to consent where required by applicable law.

Users may manage certain tracking settings through device settings, app settings, browser controls, or consent-management tools. Disabling essential technologies may impair the functionality or security of the Services.

9. Disclosure of Personal Information

BeFit Ai may disclose personal information only as reasonably necessary for the purposes described in the present Policy.

Service Providers: Personal information may be shared with hosting providers, cloud-storage vendors, AI-service providers, analytics providers, crash-reporting tools, customer-support systems, email providers, security vendors, and payment or receipt-verification providers.

App Stores and Payment Providers: Subscription and purchase-related information may be processed by Apple, Google, or other authorized payment providers, depending on where the user purchases the subscription.

Professional Advisers: Information may be disclosed to attorneys, accountants, consultants, auditors, insurers, or other professional advisers where reasonably necessary for business, compliance, or legal purposes.

Legal and Safety Disclosures: Information may be disclosed where required by law, subpoena, court order, regulatory request, law-enforcement request, legal process, or where disclosure is reasonably necessary to protect rights, safety, users, property, or the integrity of the Services.

Business Transfers: If BeFit Ai is involved in a merger, acquisition, sale of assets, reorganization, financing, assignment, or business transfer, user information may be disclosed or transferred subject to appropriate safeguards and applicable notice requirements.

BeFit Ai does not intend to sell sensitive wellness information. Where any state privacy law defines “sale,” “sharing,” targeted advertising, profiling, or sensitive-data processing in a manner that applies to BeFit Ai, eligible users will be provided applicable disclosures and opt-out rights.

10. International Transfers

BeFit Ai is operated from the United States, and personal information may be processed in the United States and other jurisdictions where service providers maintain facilities. Users located outside the United States acknowledge that their information may be transferred to, stored in, and processed in countries that may not provide the same level of data protection as their home jurisdiction.

For users in the European Union, European Economic Area, or United Kingdom, international transfers will be handled through recognized legal mechanisms where required, such as adequacy decisions, Standard Contractual Clauses, UK International Data Transfer Addendum, transfer-risk assessments, or other lawful safeguards.

11. Data Retention

BeFit Ai retains personal information only for as long as reasonably necessary to fulfill the purposes described in the present Policy, including providing the Services, maintaining accounts, complying with legal obligations, resolving disputes, enforcing agreements, preserving security records, and supporting legitimate business operations.

Account information is generally retained for the life of the account and for a reasonable period thereafter. Subscription records may be retained as needed for accounting, tax, fraud-prevention, refund, chargeback, and audit purposes. AI interaction data and questionnaire responses may be retained for plan continuity, safety review, personalization, debugging, and support unless deletion is requested and no legal basis for retention remains. Social content may remain visible until removed by the user or moderated by BeFit Ai, subject to backup retention and legal holds.

Upon valid deletion request, BeFit Ai will delete or de-identify personal information unless retention is required or permitted by law, contractual obligation, fraud prevention, dispute resolution, security protection, or legitimate operational need.

12. User Rights

Depending on location and applicable law, users may have rights concerning their personal information.

Access: Users may request confirmation of whether BeFit Ai processes their personal information and may request access to that information.

Correction: Users may request correction of inaccurate or incomplete personal information.

Deletion: Users may request deletion of personal information, subject to legal exceptions and retention obligations.

Restriction: Users may request restriction of processing under circumstances recognized by applicable law.

Portability: Users may request a copy of certain personal information in a structured, commonly used, machine-readable format where legally required.

Objection: Users may object to processing based on legitimate interests or direct marketing, where applicable.

Consent Withdrawal: Where processing is based on consent, users may withdraw consent at any time, without affecting processing carried out before withdrawal.

Opt-Out Rights: Eligible users may have rights to opt out of sale, sharing, targeted advertising, or certain profiling, depending on applicable state privacy law.

Requests may be submitted to info@befitaiapp.com. BeFit Ai may verify identity before fulfilling a request and may request information reasonably necessary to confirm account ownership. Under GDPR Article 12(3), controllers generally must respond to data-subject requests without undue delay and within one month, subject to permitted extensions for complex or numerous requests.

13. Children and Minors

BeFit Ai is not directed to children under 13 years of age. Users under 13 may not create an account or use the Services. The Children’s Online Privacy Protection Rule imposes requirements on operators of websites or online services directed to children under 13, and on operators with actual knowledge that they collect personal information from children under 13.

Users between 13 and the age of majority in their jurisdiction may use BeFit Ai only with the consent and supervision of a parent or legal guardian. Parents or guardians who believe that a child under 13 has provided personal information to BeFit Ai should contact us promptly so that appropriate deletion or restriction measures can be taken.

14. Security Measures

BeFit Ai uses reasonable administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, accidental loss, misuse, alteration, disclosure, or destruction. Safeguards may include access controls, authentication measures, encryption in transit where appropriate, monitoring, vendor review, restricted administrative access, data minimization practices, and security logging.

No digital service, mobile application, AI system, cloud platform, or transmission method can be guaranteed to be completely secure. Users are responsible for maintaining strong passwords, securing their devices, updating operating systems, avoiding credential sharing, and notifying BeFit Ai promptly of suspected unauthorized access.

15. Health Breach and Security Incident Notices

Where required by applicable law, BeFit Ai will provide notices concerning certain security incidents, unauthorized disclosures, or breaches involving personal information. For health-related apps not covered by HIPAA, the FTC Health Breach Notification Rule may require notice to affected consumers, the FTC, and, in some cases, the media following breaches of unsecured, individually identifiable health information.

Security incident determinations depend on the nature of the information, the cause of the incident, the persons affected, applicable law, and whether the information was secured. BeFit Ai may investigate suspected incidents before determining whether legal notice obligations apply.

16. Marketing Communications and Push Notifications

BeFit Ai may send service-related messages, including account notices, subscription confirmations, security alerts, policy updates, technical notices, and support communications. Such communications are generally necessary for account administration and may not be fully optional.

Marketing emails, promotional messages, and non-essential push notifications may be sent where permitted by law and, where required, with user consent. Users may opt out of marketing emails by using the unsubscribe mechanism included in such messages or by contacting BeFit Ai. Push notifications may be managed through device settings or in-app settings, where available.

Text Messages (SMS). Where a user provides a mobile phone number and affirmatively opts in during account registration, BeFit Ai may send text messages relating to account verification, one-time passcodes, password resets, and changes to account settings. Message frequency varies. Message and data rates may apply. Users may opt out at any time by replying STOP to any message, and may reply HELP for assistance. Mobile phone numbers and SMS consent information collected for these purposes are not sold, rented, or shared with third parties or affiliates for their own marketing purposes. Such information is disclosed only to the telecommunications and messaging service providers engaged to deliver the messages on BeFit Ai's behalf, and only as necessary for that delivery.

17. User-Generated Content and Public Visibility

Social features may allow users to publish content visible to other users. Information posted publicly or semi-publicly, including profile information, posts, comments, photos, videos, reactions, and friend interactions, may be viewed, captured, copied, or redistributed by other users contrary to BeFit Ai’s rules. Users should not post private, sensitive, medical, financial, identifying, or safety-related information in public areas of the App.

Direct messages may not be public, but they may still be processed for delivery, safety, moderation, abuse prevention, legal compliance, and support when a user reports misconduct or where review is otherwise permitted by law and platform rules.

18. Changes to the Privacy Policy

BeFit Ai may update the present Privacy Policy from time to time to reflect changes in law, technology, app features, AI functionality, subscription structure, vendor relationships, security practices, or business operations. The updated version will be identified by a revised “Last Updated” date.

Where required by law, BeFit Ai will provide notice of material changes and obtain consent where the change affects processing that legally requires renewed consent. Continued use of the Services after an updated Privacy Policy becomes effective constitutes acknowledgment of the updated Policy, except where a different legal standard applies.

19. Complaints and Supervisory Authorities

Users are encouraged to contact BeFit Ai first regarding any privacy concern, request, or complaint. Users located in the European Union or European Economic Area may have the right to lodge a complaint with their local data-protection supervisory authority. Users located in the United Kingdom may have the right to contact the UK Information Commissioner’s Office.

Users located in applicable United States jurisdictions may also have state-law privacy rights and may be entitled to appeal certain privacy-request decisions where the applicable law provides such a mechanism. New Jersey’s privacy law provides rights for covered consumers where statutory thresholds and conditions are met.

20. Contact Information

For privacy questions, data-subject requests, deletion requests, correction requests, consent withdrawals, complaints, security concerns, or notices relating to the present Privacy Policy, please contact:

BeFit Ai
Owner: Joseph Nuzhny Rybaloff
Email: info@befitaiapp.com
Mailing Address: 377 Valley Rd, Unit #2973, Clifton, NJ 07013, United States
App/Website URL: https://befitaiapp.com

HomePrivacy PolicyTerms & Conditions
© 2026 BeFit AI