Legal · Last updated August 23, 2026
Privacy Policy
How MoveTogether collects, uses, and protects your information, including health and fitness data, AI coaching, your privacy rights, and your choices.
DesignSpark Studio LLC ("we," "our," or "us"), an Ohio limited liability company, operates the MoveTogether mobile app and the website at https://movetogetherfitness.com (together, the "Service"). MoveTogether is a social fitness app: you track your activity, compete with friends, climb leaderboards and leagues, and get coaching from our AI coach, Mo.
This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices and rights you have. Because MoveTogether works with health and fitness data, please read Sections 1, 4, and 8 carefully.
By creating an account or using MoveTogether, you acknowledge and agree to this Privacy Policy, including as it is updated from time to time as described in Section 10. If you do not agree, please do not use the Service.
1. Information We Collect
Information you provide directly
- Account information. Email address, display name, and username. If you sign in with Apple, you may use Apple's Hide My Email relay address.
- Profile information. Optional bio, profile photo (avatar), your date of birth (used to confirm you meet our minimum age requirement and to tailor features), and fitness details you enter such as gender, age, height, current weight, and goal weight. We keep a history of weight entries to show progress over time.
- Phone number. If you choose to verify your phone number, we collect it (in E.164 format), the time and your IP address and device/browser at the moment you opted in (as a consent record), and the verification status. Verification is handled by SMS.
- Contacts (optional). If you grant contacts access to find friends, we use the phone numbers in your device contacts to match people who already use MoveTogether. We use them only for matching and do not store the contact details of people who are not MoveTogether users.
- Content you create. Messages you send in direct messages, competition group chats, and communities; your conversations with Coach Mo; reports you submit about other users or content; and other content you add to the Service.
- Voice. If you use voice features (such as talking to Coach Mo on Apple Watch or our voice support assistant), we capture and process your microphone audio to power the conversation, and we store transcripts of it. Audio is processed by our voice AI provider through a secure relay (see Section 4) solely to transcribe what you say and to generate a response. We do not create, store, or use voiceprints, voice embeddings, voice templates, speaker-recognition models, or other acoustic identifiers derived from your voice, and we do not use your voice to identify or authenticate you. We do not sell voice data.
- Location. With your permission, we collect your approximate or precise location to provide location-based features such as local weather insights. We store your most recent location and share it with our weather provider to generate those insights. Location is collected only while you use the app, and you can turn it off in your device settings.
- Support requests. When you contact us (through the in-app support chat, through Mo on our website, or by email), we collect your messages and the information needed to help you.
- Historical waitlist sign-ups. If you previously joined a website waitlist, we may retain the email address you provided to send the related updates and meet our recordkeeping obligations.
Health and fitness data
With your permission, MoveTogether reads health and fitness data from Apple Health (HealthKit), Android Health Connect, and any wearable or fitness account you connect. This may include:
- Steps, active energy / calories burned, resting and basal energy, exercise minutes, and Apple Activity ring / summary data
- Workouts, including type, duration, and distance
- Heart rate, resting heart rate, heart rate variability (HRV), and VO2 max
- Sleep analysis
- Body mass / weight
- From connected sources (Google Health/Fitbit, Garmin, WHOOP, Strava, Polar, Oura, and Ultrahuman), the comparable metrics above plus, where available, blood oxygen (SpO2) and respiratory rate
Android Health Connect. On Android, depending on your enabled features and entitlement, we may read up to six Health Connect data types if you grant the relevant permissions: steps, active calories burned, exercise sessions, sleep sessions, weight measurements, and height measurements. Starter and unknown-entitlement members request only the three activity types; Pro members can explicitly enable sleep, weight, and height from Settings → Data Sources → Health Connect, including after an upgrade. An entitlement change never opens a permission prompt automatically. Steps, active calories, and exercise sessions power activity progress; Pro members can use sleep sessions, duration, stages, and efficiency for Recovery, Morning Brief, and Coach Mo context, and weight and height measurements for automatic Weight trend/history and BMI progress without manual entry. Health Connect supplies measurements for this fitness feature, not a medical assessment, and does not provide Oura's proprietary numeric Sleep Score. We ask separately before reading in the background to keep authorized data current, and separately before reading historical data for a recovery/backfill period of up to 90 days. Health Connect access is optional. Declining or revoking one permission or data type stops only future reads covered by that revoked permission or data type; it does not delete copies already stored in your MoveTogether account (see Sections 5, 7, and 8).
We use this data to power your rings, streaks, scores, leaderboards, competitions, and AI coaching. Some of this data syncs automatically in the background so your stats stay current. We treat health and fitness data as sensitive. We do not sell it, and we do not use it for advertising.
Information collected automatically
- Usage and product analytics. On iOS, when product analytics is enabled and PostHog is configured, we use PostHog to understand how the app is used, such as which features you use, screens you view, and session length, so we can improve the Service. On Android, PostHog is account-scoped and opt-in and sends only explicit product events; it does not automatically capture screen views or session duration in the current Android release.
- Session replay. On iOS, when product analytics is enabled and PostHog is configured, we may record masked app interactions to help us diagnose problems and improve usability. Session replay is not enabled in the current Android release.
- Diagnostics. On iOS, when product analytics is enabled and PostHog is configured, PostHog may process crash/error and performance diagnostics to help us find and fix bugs. The current Android release does not send PostHog crash/error, performance, network, or log data.
- Advertising and marketing attribution. Free-tier users may see Google AdMob banner, native, and rewarded ads. These ads are non-personalized and contextual; where required, we use Google's User Messaging Platform (UMP) to obtain consent. Pro is ad-free. At the end of new-user onboarding, after the location-permission choice, we may ask for Apple's App Tracking Transparency (ATT) permission. You can also choose to request this permission from Privacy Settings. Only if you authorize it do we start Tenjin, our mobile measurement provider, which automatically collects the IDFA, a Tenjin analytics/device identifier, and basic app, device, and network information to measure an ad-driven install and subsequent app sessions. We also send Tenjin five limited conversion outcomes: completing registration (a fixed event name distinguishes Apple from Google), completing onboarding, joining a competition (a fixed event name distinguishes public, seasonal, or invite), starting a subscription trial (event name only, with no product, source, or revenue), and completing a paid subscription. A paid subscription uses a manual transaction containing only product identifier, quantity, and the actual localized price and currency when those values are valid; otherwise, Tenjin receives only the fixed
subscription_purchasedevent name. Before transmission, limited events may be held locally on your device while ATT is undecided or, after you authorize ATT, until Tenjin starts successfully, subject to a 20-event limit. Nothing is transmitted before ATT authorization. An event is eligible to be sent for no more than seven days and expired events are discarded when the app next processes the queue; pending events are deleted if you deny or are restricted, revoke permission, or sign out. Tenjin may provide measurement or configured attribution postbacks to Meta, TikTok, and Apple Ads. We do not send Tenjin your MoveTogether account ID, profile, email, phone, precise location, health or fitness data, social data, content, competition identifiers or names, purchase source, StoreKit transaction identifiers, receipts, JWS data, or purchase tokens. While ATT is denied, restricted, or undecided, Tenjin does not start or transmit attribution data; Apple Search Ads attribution through RevenueCat and delayed, aggregate SKAdNetwork reporting remain available without IDFA or an active Tenjin SDK session. Existing decisions can be changed in iOS Settings; if you later authorize tracking, the app may start or resume Tenjin and send eligible locally pending conversion events. - Device information. Device model, operating system version, app version, and network and device characteristics.
- Website analytics, cookies, and storage. Our public marketing website uses cookieless Vercel Analytics and Speed Insights for aggregate traffic and performance. Microsoft Clarity also collects limited, cookieless page-view and basic interaction data, including clicks and scrolls, before consent or after optional analytics are declined. If you allow optional analytics, Clarity can additionally associate page views across a pseudonymous visitor and session to provide behavioral metrics, heatmaps, masked DOM reconstruction/session replay, interactions, page and device characteristics, performance, and diagnostics. Clarity may use first-party analytics cookies only after that consent. It is not loaded on authenticated portal surfaces, and we do not ask Clarity to connect its pseudonymous identifiers to a MoveTogether account or use it to track account, health, social, form, or support-chat data or for targeted advertising. If you allow optional analytics, we also load Google Analytics 4 on our public marketing pages to measure aggregate usage such as page views, sessions, and traffic sources; it sets first-party
_gacookies, is not loaded before consent or on the authenticated portal, and we do not enable Google Signals, advertising features, or ads personalization. If you allow optional analytics, we also load Searchable on our public marketing pages to measure how much of our traffic arrives from AI assistants and AI search tools such as ChatGPT, Perplexity, Gemini, and Claude; it stores a first-party visitor and session identifier on your device and records pages viewed, the referring URL and campaign parameters, and basic page and device characteristics. It is not loaded before consent or on the authenticated portal, and we do not use it for targeted advertising. With your consent, we also load the Reddit advertising pixel on our public marketing pages (never the account portal) to measure conversions from our Reddit ads and reach relevant audiences on Reddit. Unlike our analytics tools, this is advertising technology: it shares limited website event data (such as page visits and clicks on our download and other calls to action) with Reddit and sets advertising cookies, and it loads only where you have consented to advertising cookies. Consent is managed through our consent banner (c15t / consent.io), which applies prior opt-in where required (e.g. EU/UK) or opt-out elsewhere (e.g. some US states). This is cross-context behavioral advertising as described in Section 7; you can withdraw consent at any time through Cookie preferences, and we do not send Reddit your health, social, or account data. See our Cookie Policy for details. The mobile app does not use browser cookies; in-app analytics and marketing attribution are described above.
Information from third parties
- Sign in with Apple. If you sign in with Apple, we receive your Apple ID and, if you choose to share it, your name and an email address (which may be a private relay address).
- Sign in with Google. If you sign in with Google, we receive your Google profile name and email address.
- Connected wearables and fitness services. When you connect a wearable or fitness account, we receive the activity and health metrics listed above from that provider on your behalf.
- App stores and payment providers. Apple, our subscription manager (RevenueCat), and our web payment processor (Stripe) tell us your subscription and entitlement status so we can unlock features.
What we do not do
- Free-tier users may see non-personalized, contextual third-party ads through Google AdMob; Pro is ad-free. We do not use health or fitness data, Apple's Identifier for Advertisers (IDFA), or cross-context behavioral advertising to serve those ads.
- We do not sell your personal information.
- We do not use your health and fitness data for advertising.
2. How We Use Your Information
We use the information we collect to:
- Provide MoveTogether's core features: activity tracking, rings, streaks, scoring, friends, competitions, leagues, leaderboards, communities, and direct messages
- Generate AI coaching, weekly reports, and personalized notifications through Coach Mo (see Section 4)
- Verify your phone number and protect account security
- Help you find friends who already use MoveTogether (contacts matching, with your permission)
- Send push notifications and service messages you have not turned off
- Process subscriptions
- Show non-personalized, contextual ads to free-tier users and measure advertising campaigns using the privacy-preserving methods described in Section 1
- Provide customer support
- Understand usage and measure how our marketing performs so we can improve the Service
- Detect, prevent, and address fraud, abuse, cheating, and violations of our Terms or Acceptable Use Policy
- Comply with legal obligations
We do not use your information to make solely automated decisions that produce legal or similarly significant effects on you.
3. How We Share Your Information with Other Users
MoveTogether is social, so some information is shared with other users by design:
- Public profile. Depending on your privacy settings, your username, abbreviated name, avatar, bio, subscription status, and fitness signals such as current and longest streak, ring progress, rings-closed counts, competition points, and achievements may be visible to others.
- Friends. People you add as friends can see your activity and ring progress and may see you in shared activity feeds.
- Competitions, leagues, and leaderboards. Your rank, points, and identity are visible to other participants, and may appear on global leaderboards.
- Communities and chats. Content you post in communities, group chats, and direct messages is shared with the participants of those spaces.
You can control much of this through your in-app privacy settings (for example, profile visibility). Please use them to set the level of sharing you are comfortable with.
4. Service Providers and Other Third Parties
We use service providers to operate the Service and advertising platforms to deliver contextual ads or measure our campaigns. Our service providers may access only the data needed to perform their function and are required to protect it. Advertising platforms may process the limited advertising and attribution data described below under their own terms and privacy policies. Some third parties apply only to specific versions or platforms of the app.
| Provider | Purpose | Data involved |
|---|---|---|
| Apple | Sign in with Apple, HealthKit, push (APNs), App Store purchases | Identity, health data (on device), purchase status |
| Google / Android Health Connect | Sign in with Google; Android Health Connect; AdMob advertising and UMP consent where required | Google identity, name, email; Health Connect data read from the on-device Health Connect store only after your permission; app, device, and network information used to request non-personalized/contextual ads; ad impressions or interactions; applicable consent choices. We do not send your Health Connect data to Google for advertising. |
| Meta | Ad delivery, aggregate SKAdNetwork reporting, and configured Tenjin measurement postbacks | Advertising engagement and limited ATT-authorized install, session, registration, onboarding, competition-join, trial, and paid-subscription attribution data Meta receives under its own terms; no direct MoveTogether account, profile, health, fitness, social, content, competition-identifier, or transaction-identifier sharing |
| TikTok | Ad delivery, aggregate SKAdNetwork reporting, and configured Tenjin measurement postbacks | Advertising engagement and limited ATT-authorized install, session, registration, onboarding, competition-join, trial, and paid-subscription attribution data TikTok receives under its own terms; no direct MoveTogether account, profile, health, fitness, social, content, competition-identifier, or transaction-identifier sharing |
| Tenjin | ATT-authorized mobile install, session, and limited conversion attribution; configured measurement postbacks | IDFA, Tenjin analytics/device identifier, basic app/device/network information, fixed registration, onboarding, competition-join and trial events, and either a fixed paid-subscription event or paid product identifier, quantity, localized price and currency as described in Section 1, only after ATT authorization; no MoveTogether account, profile, health, fitness, precise location, social/content, competition identifier, purchase source, receipt, JWS, purchase token, or transaction identifier |
| Supabase | Database, authentication, file storage, backend functions | All account, profile, fitness, social, and content data |
| PostHog | Product analytics, session replay, diagnostics | iOS, when analytics is enabled and PostHog is configured: persistent Supabase account UUID, usage events, screen/session usage, masked replays, and crash/error and performance diagnostics. Android, account-scoped and opt-in: persistent Supabase account UUID and explicit product events only; no automatic screen/session capture, replay, crash/error, performance, network, or log data in the current Android release. |
| RevenueCat | Subscription management and Apple Search Ads attribution | App user ID, purchase/entitlement status, Apple Search Ads attribution token |
| Stripe | Website subscription payments and billing | Payment and billing information |
| Stream (getstream.io) | Chat, communities, feeds, and content moderation (text and images) | User ID, name, avatar, messages, posts, and content submitted for moderation |
| OneSignal | Push notifications | Push token, user ID, notification preferences |
| Anthropic (Claude) | Coach Mo AI coaching, insights, reports, and AI-assisted support | Relevant fitness context, goals, profile details, chat or support messages, and report data; Coach text prompts replace direct names with placeholders and do not include your MoveTogether user ID |
| ElevenLabs | Coach Mo voice (where available) and the Mo support assistant | Spoken audio and the relevant fitness context, first name, and user ID |
| Twilio | SMS phone-number verification | Phone number |
| Resend | Transactional email and permitted marketing email | Email address, first name, non-health product-usage summary, subscription-preference state, and message content. We do not use health or fitness data to personalize marketing email. |
| OpenWearables | Aggregating data from connected wearables | Account identifiers and normalized health/activity data |
| Linear | Support ticketing | Support content and account identifiers |
| Giphy | GIFs in chat | GIF search queries |
| Open-Meteo | Weather data for location-based insights | Approximate location (latitude/longitude) |
| Cloudflare | Secure relay for voice conversations | Voice session audio and data in transit |
| Featurebase | Feature-request / feedback portal | Account identifiers you sign up with there and feedback you post |
| Vercel | Website hosting and website analytics | Website usage data |
| Searchable | Optional public-marketing-site analytics measuring traffic referred by AI assistants and AI search tools | Website usage data (pages viewed, referring URL and campaign parameters, page and device characteristics) and a pseudonymous first-party visitor and session identifier stored on your device, all only after optional analytics consent; loaded only on marketing pages, never the account portal |
| Microsoft Clarity | Optional public-marketing-site analytics, heatmaps, masked session replay, performance, and diagnostics | Behavioral and interaction data; page-event and page-dimension data; page and device characteristics; performance metrics; diagnostic events; masked DOM reconstruction/session replay; and, after optional analytics consent, pseudonymous first-party visitor and session cookies |
| Google Analytics (Google) | Optional public-marketing-site analytics (page views, sessions, traffic sources) | Aggregate website usage data; pseudonymous first-party visitor and session cookies set only after optional analytics consent |
| Reddit (Reddit pixel) | Optional public-marketing-site advertising: measuring Reddit ad conversions and reaching/retargeting audiences on Reddit | Website event data (page visits; clicks on our download and other calls to action); first-party and Reddit advertising cookies set only where you consent to advertising cookies; loaded only on marketing pages, never the portal; no health, social, or account data |
AI coaching. For Coach Mo text coaching, insights, and reports, we send Anthropic the relevant fitness context (such as your goals, recent activity, and streaks), messages, and report data needed to generate the feature. The Coach text pipeline replaces your name and other people's names with placeholders before submitting prompts and does not include your MoveTogether user ID in those prompts. Other Anthropic-assisted support workflows may receive the content you submit and the minimum context needed to answer it. For Coach Mo voice and the Mo support assistant, ElevenLabs receives spoken audio, relevant fitness context, your first name, and your user ID. These providers process data on our behalf to generate responses and voice, and do not use it to train their own models. Conversation data sent to our AI providers may be retained by them for a limited period for safety, debugging, and quality purposes, then deleted, in line with their terms. We also use automated tools to help detect content that may indicate self-harm or crisis, so we can surface support resources. Coach Mo's responses are AI-generated and are not medical or professional advice (see our Terms). You can delete your Coach Mo conversation history in the app, and deleting your account removes it.
We may also disclose information:
- For legal reasons, if required by law, regulation, legal process, or a valid government request.
- For safety, to protect the rights, property, or safety of DesignSpark Studio LLC, our users, or the public, including to enforce our Terms and investigate abuse.
- In a business transfer, if we are involved in a merger, acquisition, or sale of assets, in which case we will notify you.
5. Data Retention
- Account and profile data: retained while your account is active.
- Health, fitness, social, and content data: retained while your account is active so the Service can function.
- Android Health Connect data: copies of the six Health Connect data types listed in Section 1 are retained while your account is active to provide the features you enable. A separately granted background-read permission can keep those copies current, and a separately granted history permission can allow a recovery/backfill read of up to 90 days. Revoking a data-type, background, or history permission stops only future reads covered by that permission; it does not remove copies already stored by MoveTogether. Delete your account to remove or de-identify those copies within the 30-day period described below.
- Voice audio and transcripts: we retain transcripts of your voice interactions while your account is active, and we delete them when you delete your Coach Mo history or your account. Our voice provider retains transcripts only for a limited period (currently up to 30 days) to help us troubleshoot, and does not retain your voice audio. Audio is used only to generate a response and is then discarded. Your voice is never used to build a voice profile.
- Analytics and diagnostics: where collected, including iOS analytics, replay, and diagnostics and Android explicit product analytics, retained for up to 12 months, then deleted or aggregated.
- Microsoft Clarity website analytics: Microsoft ordinarily retains playback data for 30 days, with longer published periods for aggregate heatmaps and selected or favorited recordings. These are Microsoft service-level periods that may change; see Microsoft's current retention documentation.
- Google Analytics website analytics: Google retains user- and event-level Analytics data according to the property's data-retention setting (configurable up to 14 months); aggregated reporting may persist longer. These are Google service-level periods that may change; see Google's current data retention documentation.
- Reddit website advertising: where you consent, Reddit processes the website event data and advertising cookies from the Reddit pixel under its own retention practices; we do not attach these to your MoveTogether account. See Reddit's Privacy Policy.
- Advertising and marketing attribution: Apple's Search Ads attribution token is used once to retrieve campaign information and is not separately retained by us. The resulting campaign, ad group, and keyword records are stored with your subscription profile (at RevenueCat) while your account is active, and are deleted when you delete your account. Before transmission, the limited conversion events described in Section 1 may remain only on your device in a 20-event local queue while ATT is undecided or, after ATT authorization, until Tenjin starts successfully. Nothing is transmitted before ATT authorization. Events older than seven days are discarded before any transmission when the app next processes the queue, and the queue is cleared on denial, restriction, revocation, or sign-out. On the ATT-authorized path, Tenjin processes the IDFA, a Tenjin analytics/device identifier, automatic install/session data, and those limited conversion events or paid-transaction fields under its own retention practices; we do not attach these identifiers or events to your MoveTogether account. Google, Meta, TikTok, Apple Ads, and Tenjin may retain advertising engagement or attribution data they hold under their own privacy policies; SKAdNetwork reporting is aggregated and may be delayed.
- Consent and verification records (e.g., phone opt-in): retained as needed to evidence consent and for security.
- De-identified or aggregated data: we may retain and use data that no longer identifies you (for example, aggregate usage statistics) indefinitely to operate and improve the Service.
When you delete your account, we delete or de-identify your personal data within 30 days, except where we must retain certain records to comply with law, resolve disputes, or prevent fraud and abuse. You can request data export and account deletion from within the app or through your authenticated web account controls at any time.
Deleting specific data. Your health and fitness data syncs continuously from Apple Health and any services you connect, so we do not support deleting individual days, workouts, or metrics on their own while your account is active. To have us delete the health and fitness data we store, delete your account, which removes or de-identifies it as described above.
6. Data Security
We use technical and organizational measures to protect your information, including:
- Encryption in transit (TLS/HTTPS) for all network communications
- Encryption at rest for stored data, and secure storage for credentials on device
- Strict server-side access controls; the app speaks only to our backend APIs, which enforce access rules
- Regular review of our data practices
No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we take commercially reasonable steps to protect your data.
Where your data is stored. We are based in the United States, and we and our service providers store and process your information primarily on cloud infrastructure in the United States (including Amazon Web Services). Some features rely on additional providers (for example, our feedback portal runs on separate hosting); see Section 4.
Security incident notification. If we become aware of a security breach affecting your personal information, we will notify you and any regulators as required by applicable law, generally by email to the address associated with your account.
7. Your Privacy Rights and Choices
Wherever you live, you can:
- Access / export your data (in-app data export)
- Correct your profile and account information
- Delete your account and associated data from the app or through your authenticated web account controls. Deletion stops future Health Connect collection and removes or de-identifies the Health Connect data we stored within 30 days, subject to the Section 5 exceptions.
- Control sharing through your in-app privacy settings
- Turn product analytics on or off with the "Help improve MoveTogether" toggle in the app's Privacy settings (Data & analytics).
- Manage website analytics and advertising consent through Cookie preferences or the Do Not Sell or Share My Personal Information link in the public marketing-site footer (both open the same controls). Optional Microsoft Clarity, Google Analytics, and Searchable cookies and identifiers and the Reddit advertising pixel use consent as their basis. Consent is managed by our consent platform (c15t / consent.io), which applies the model required for your location — prior opt-in where required (e.g. EU/UK) or opt-out elsewhere (e.g. some US states); you can grant, decline, or withdraw at any time from the footer controls. Declining or withdrawing serves as your opt-out of the Reddit cross-context behavioral advertising described below, and where your browser sends a recognized opt-out preference signal such as Global Privacy Control, our consent platform treats it as an opt-out of both advertising and analytics cookies, so neither the Reddit pixel nor Google Analytics, Microsoft Clarity, and Searchable load. Vercel's aggregate cookieless analytics remain available.
- Request or manage advertising tracking permission from Privacy Settings or in iOS Settings > Privacy & Security > Tracking > MoveTogether. While ATT is denied, restricted, or undecided, Tenjin does not start or transmit attribution data; aggregate SKAdNetwork reporting remains available. If you later authorize tracking, MoveTogether may start or resume Tenjin for install, session, and limited conversion attribution and send eligible locally pending conversion events. Revoking permission stops Tenjin and clears any pending events.
- Advertising consent where applicable: where required by law, Google's UMP presents the applicable choices before AdMob ads are requested. The available choices and their handling are determined by Google and local law.
- Manage push notifications in app and device settings, and connected services in Settings → Data Sources
- Manage Android Health Connect access in Health Connect or Android settings. You can revoke any of the six data-type permissions, background access, or history access at any time. Revoking a permission or data type stops only future reads covered by that revoked permission or data type: revoking Sleep stops only future sleep reads, revoking Weight stops only future automatic-weight reads, and revoking Height stops only future automatic-height/BMI-input reads. Core activity syncing continues where authorized, manual body entry remains available, and account deletion is required to remove health data already stored by MoveTogether.
To make a request or ask a question, email privacy@movetogetherfitness.com, contact Mo, our support assistant, or use the in-app support chat. We may need to verify your identity before acting on a request. We respond within the time required by applicable law — generally one month for EEA/UK (GDPR) requests and 45 days for California (CCPA) requests — and we will tell you if we need an extension the law allows.
For residents of the EEA and UK (GDPR / UK GDPR)
- Data controller: DesignSpark Studio LLC. Contact via privacy@movetogetherfitness.com or Mo.
- Lawful bases. We process your data to perform our contract with you (providing the Service), based on your consent (optional Microsoft Clarity, Google Analytics, and Searchable website analytics and the Reddit advertising pixel where consent applies; reading Health data and connecting wearables; SMS verification; contacts matching), and for our legitimate interests (security, fraud prevention, limited cookieless website measurement, and improving the Service). We rely on legitimate interests for Clarity's no-consent mode only where applicable law permits it and after any required balancing test; it does not replace consent where the use of storage or access technologies, or related processing, requires consent.
- Your rights. Access, rectification, erasure, restriction, portability, objection to processing based on legitimate interests, and withdrawal of consent at any time.
- International transfers. We are based in the United States, so your data is processed in the US. Where we transfer EEA/UK data, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
- Complaints. You may lodge a complaint with your local supervisory authority.
For California residents (CCPA/CPRA)
- Categories collected: identifiers (name, email, phone, user ID, and device identifiers), account/profile information, health and fitness data (sensitive personal information), photos, user content, commercial information (subscription/purchase status), internet/usage activity, and inferences used for coaching.
- Purposes: as described in Section 2.
- We do not sell your personal information. Only with your consent, we share limited marketing-website activity with Reddit through the Reddit advertising pixel for cross-context behavioral advertising (see Section 4); it applies only where you have consented to advertising cookies, and declining or withdrawing consent opts you out. You can exercise this opt-out at any time using the Do Not Sell or Share My Personal Information link (or Cookie preferences) in the marketing-site footer. Apart from that consent-based Reddit sharing (which began in August 2026), we have not sold your personal information or shared it for cross-context behavioral advertising in the 12 months before the "Last Updated" date at the top of this Policy.
- Sensitive personal information (such as health data) is used only to provide the Service and the purposes described here.
- Your rights: to know, access, correct, delete, and limit use of sensitive personal information. We will not discriminate against you for exercising your rights.
To exercise these rights, email privacy@movetogetherfitness.com or contact Mo.
For residents of other U.S. states
If you live in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another state with a comprehensive consumer privacy law, you have the right to confirm whether we process your personal data; to access, correct, and delete it; to obtain a portable copy; and to opt out of targeted advertising, the "sale" of personal data, and certain profiling. We do not sell personal data. We use personal data for targeted advertising only through the Reddit advertising pixel on our marketing website, and only where you have consented to advertising cookies; you can opt out at any time by declining or withdrawing consent in Cookie preferences. We do not use personal data for profiling that produces legal or similarly significant effects. We process sensitive data (such as health and fitness data) only to provide the Service, with your consent where required.
To make a request, email privacy@movetogetherfitness.com or contact Mo. We may need to verify your identity before we act, and you may use an authorized agent to submit a request on your behalf. Right to appeal: if we decline your request, you may appeal by replying to our decision or contacting Mo. If you have concerns about our handling of an appeal, you may contact your state attorney general.
Do Not Track and Global Privacy Control
Some browsers offer a "Do Not Track" (DNT) signal. Because there is no common industry standard for DNT, we do not currently respond to DNT signals. Where required by law, we honor recognized opt-out preference signals such as Global Privacy Control (GPC).
Marketing communications
We send service and account messages necessary to operate the Service. We send marketing or promotional messages only where permitted, and you can opt out at any time using the unsubscribe link in those messages or your in-app and notification settings. Opting out of marketing does not stop essential service messages.
California "Shine the Light"
California Civil Code Section 1798.83 permits California residents to request information about our disclosures of personal information to third parties for their own direct marketing purposes. We do not share personal information with third parties for their direct marketing. You may contact us to confirm.
8. Health and Fitness Data
Health and fitness data is sensitive, and we handle it accordingly:
- Data minimization. We collect only the health and fitness data needed to provide the features you use, such as rings, streaks, scores, competitions, leagues, leaderboards, and AI coaching.
- Apple Health (HealthKit) data is read with your explicit permission and is used only to provide app features. We do not use HealthKit data for advertising or marketing, and we do not share it with third parties except the service providers in Section 4 that are necessary to deliver features you use (for example, AI coaching).
- Android Health Connect data is read from your on-device Health Connect store only after you grant the relevant permissions. The Android app reads only steps, active calories burned, and exercise sessions. Background reads and up to 90 days of historical reads require separate Health Connect permissions. We do not use Health Connect data for advertising or marketing, and we do not send it to Google for advertising.
- You can revoke Health permissions at any time in iOS Settings, Health Connect, or Android settings, and disconnect wearables in the app. Revocation stops future collection; it does not delete the data already stored by MoveTogether. Connecting Health or a wearable is optional, but some features (such as rings, streaks, and competitions) will not work without activity data.
- To power features like leaderboards, competitions, streaks, and AI coaching, your health and fitness data is stored on our servers (US cloud infrastructure), not only on your device. It is protected as described in Section 6 and shared only with the Section 4 providers needed to deliver features you use.
- MoveTogether is a fitness and motivation product, not a medical device or medical service. Coach Mo and any insights we generate are for general fitness and motivation only and are not medical advice. See the Health & Fitness Disclaimer in our Terms.
Not HIPAA / not PHI. DesignSpark Studio LLC is not a "covered entity" or "business associate" under the U.S. Health Insurance Portability and Accountability Act (HIPAA), and the health and fitness information you provide through the Service is not protected health information under HIPAA.
Consumer Health Data (Washington My Health My Data Act and similar laws)
Some states, including Washington (My Health My Data Act), Nevada, and Connecticut, regulate "consumer health data" collected by apps that are not covered by HIPAA. This section describes how we handle that data and applies in addition to the rest of this Policy.
- Categories of consumer health data we collect. Activity and fitness metrics (steps, active and resting energy/calories, exercise minutes, Apple Activity ring/summary data, and workouts including type, duration, and distance); cardiovascular and physiological metrics (heart rate, resting heart rate, heart rate variability, VO2 max, and, from some wearables, blood oxygen and respiratory rate); sleep analysis; body weight and related measurements you enter (including goal weight and weight history); and information you provide to or generate with Coach Mo about your health, fitness, and goals. On Android, our Health Connect collection is limited to six types: steps, active calories burned, exercise sessions, sleep sessions, weight measurements, and height measurements. Apple Health and other connected wearables may provide the broader categories described above.
- Where it comes from. Apple Health (HealthKit), Android Health Connect, the wearable and fitness accounts you connect (see Section 1), and information you enter directly. Android Health Connect data comes from the on-device Health Connect store, only after you grant the relevant permission.
- Why we use it. To provide the features you enable: activity rings, streaks, scores, leaderboards, competitions, leagues, Pro sleep and body/BMI experiences, AI coaching, weekly reports, and personalized insights through Coach Mo. A separately granted background-read permission can keep the Android data types you authorize current; a separately granted history permission permits recovery/backfill reads of up to 90 days. We do not use consumer health data for advertising, and we do not sell it.
- Who we share it with. Only the service providers in Section 4 that are necessary to deliver the features you use, for example our backend provider (Supabase), our wearable aggregator (OpenWearables), and our AI providers (Anthropic and ElevenLabs) for Coach Mo. Each is contractually limited to processing the data on our instructions for those purposes. We do not share consumer health data with third parties for their own purposes, and we do not send Android Health Connect data to Google for advertising.
- Consent. We collect and share consumer health data based on your consent, given when you enable Apple Health access, grant Android Health Connect permissions, or connect a wearable and use the related features. Connecting is optional, and you can decline. Background and history access are separately optional on Android. Where a state requires separate consent before we share consumer health data, we obtain it before sharing.
- Your choices and rights. You can withdraw consent at any time by revoking Health permissions in iOS Settings, Health Connect, or Android settings, and by disconnecting wearables in the app. Revocation stops future collection but does not delete data previously stored by MoveTogether. You can request access to your consumer health data, a list of the categories of third parties and the specific providers we have shared it with, and deletion of the data. Because this data syncs continuously from Apple Health, Android Health Connect, and connected services, we do not support deleting individual days, workouts, or metrics on their own while your account is active; to delete the consumer health data we store, delete your account through the app or authenticated web account controls (see Section 5), and we will delete or de-identify it within 30 days, except where retention is required by law.
- How to reach us. Email privacy@movetogetherfitness.com or contact Mo, our support assistant.
9. Children's Privacy
MoveTogether is not intended for children under 13, and we do not knowingly collect or solicit personal information from anyone under 13. In the EEA and UK, where a higher digital-consent age applies (up to 16 in some countries), the Service is not intended for users below that age. By using the Service, you represent that you are old enough to do so, or that a parent or guardian has consented on your behalf where required.
If we learn that we have collected personal information from a child below the applicable age, we will deactivate the account and take reasonable steps to delete that information promptly. If you believe a child has provided us personal information, contact Mo, our support assistant and we will address it.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date, post the new version at https://movetogetherfitness.com/privacy, and, where appropriate, notify you in the app or by email. Your continued use of the Service after changes take effect constitutes acceptance.
11. Contact Us
- Privacy requests: privacy@movetogetherfitness.com
- Mo, our support assistant: use the Mo widget in the bottom-right corner on desktop, or tap "Talk to Mo" on mobile
- In-app: the support chat inside the app
- Company: DesignSpark Studio LLC (Ohio, USA)
- Mailing address: DesignSpark Studio LLC, 815 Superior Ave. E., Ste 1618-A2, Cleveland, OH 44114-2706, USA
- Website: https://movetogetherfitness.com