Privacy Policy
Last updated 30 June 2026
FAFO Coach ("FAFO Coach", "we", "us") is a personal training and nutrition coaching app operated by Anis Dhahir. This policy explains what we collect, why, and the choices you have. We keep it short and honest: your data exists only to coach you, and we never sell it.
Who we are
The data controller is Anis Dhahir, reachable at anis@dondemina.com. If you are in the EU/EEA or UK, this policy is written to meet the GDPR/UK GDPR.
What we collect
Account
- Your email address and a securely hashed password.
- Your training profile: chosen sport, goal, body stats (weight, goal weight, age) and preferences you enter.
Data from services you connect
We only ever pull data from a service after you explicitly connect it, and only the data needed to coach you:
- Strava — your activities, including distance, duration, heart rate, calories and route/GPS data, plus your basic athlete profile.
- WHOOP — recovery, sleep, strain, heart rate and workout data.
- Garmin / Apple Health — body weight, steps, active energy, sleep, heart-rate variability and resting heart rate.
- Nutrition apps (e.g. Lifesum via Apple Health) — calories and macronutrients you log.
- Google Calendar — only the start and end times of your events, to schedule sessions around when you are busy. We never read event titles, descriptions, attendees or any other detail.
Some of this is health-related data, which is a special category under the GDPR. We process it only with your explicit consent, given when you connect each service, and only to provide the coaching you asked for.
How we use your data
- To generate your personalised training and nutrition coaching, recovery insights and progress tracking.
- To send you the notifications you enable (e.g. a morning brief or a weigh-in reminder).
- To operate, secure and improve the service.
We do not use your data for advertising, and we do not sell or rent it to anyone. There is no third-party ad or analytics tracking in the app.
Legal bases (GDPR)
- Consent — for connecting services and processing health-related data. You can withdraw it at any time by disconnecting a service or deleting your account.
- Contract — to provide the coaching service you signed up for.
Who we share it with
We never sell your data. We rely on a small number of processors purely to run the service:
- Fly.io — cloud hosting where your data is stored.
- Resend — to send transactional email (e.g. password resets).
The services you connect (Strava, WHOOP, Google, etc.) receive only the API requests needed to fetch your own data, and each has its own privacy policy. Depending on the hosting region, data may be processed on servers in the EU and/or the United States; where data leaves the EEA we rely on appropriate safeguards such as the provider's Standard Contractual Clauses.
How long we keep it
We keep your data while your account is active. If you close your account or ask us to delete it, we remove your personal data and connected-service data within 30 days, except where we must retain something to meet a legal obligation.
Your rights
You can ask us to:
- access a copy of your data, or have it exported;
- correct or update it;
- delete it ("right to be forgotten");
- restrict or object to processing; and
- withdraw consent — disconnecting any service in the app stops further data collection from it immediately.
Email anis@dondemina.com and we'll action it. You also have the right to complain to your local data-protection authority (in Sweden, the IMY).
Security
All traffic is encrypted with HTTPS, passwords are hashed, and each user's data is isolated. No method is perfectly secure, but we take reasonable steps to protect your information.
Cookies
We use a single essential cookie to keep you signed in. There are no advertising or cross-site tracking cookies.
Children
FAFO Coach is not intended for anyone under 16, and we don't knowingly collect their data.
Changes
If we change this policy we'll update the date above and, for material changes, let you know in the app.