Privacy Policy — fit2health
Last updated: July 21, 2026
fit2health (“the app”) is an iOS app that transfers your Fitbit health data from your Google account to Apple Health on your iPhone. It is operated by Florian Alber, Brockhausstraße 4, 04229 Leipzig, Germany, support@fit2health.app (“we”).
The short version: your health data goes directly from Google to Apple Health on your device. We never see it. We run no servers, we store nothing about you, and we show no ads.
1. How the app works
The app runs entirely on your iPhone. When you connect your Google account, the app requests your Fitbit health data (such as steps, distance, heart rate, sleep, workouts, blood oxygen) directly from the Google Health API and writes it into Apple Health on your device. There is no backend server operated by us. Your health data is never transmitted to us or to any third party by the app.
2. What data the app accesses
- Fitbit health and activity data from your Google account, read via the Google Health API with your explicit consent. Specifically: steps, distance, sleep (including sleep stages), workouts, active energy burned, heart rate, resting heart rate, blood oxygen (SpO₂) and overnight respiratory rate. The app reads only these data types.
- Existing health data in Apple Health (read access), used only on your device to detect which time windows already contain data from other sources (for example your Apple Watch or iPhone), so the app writes only into gaps and does not create duplicates.
- Your Google account authorization token, stored securely in the iOS Keychain on your device only.
3. What we do NOT do
- We do not collect, store, or process your health data on any server.
- We do not use analytics or tracking SDKs, and we show no advertising.
- We do not sell or share any data. There is no user account with us.
- Health data is never used for advertising, marketing, or any purpose other than performing the sync you requested. Data written to or read from Apple Health (HealthKit) is used solely to provide the app's sync functionality, in accordance with Apple's HealthKit guidelines.
4. Google API Services — Limited Use disclosure
fit2health's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically: data obtained through Google APIs is used only to provide the sync feature you see in the app, is processed only on your device, is never transferred to us or to third parties (except as required to write it into Apple Health at your request), and is never used for advertising.
This applies to both raw and aggregated or anonymized data. fit2health does not create, use, transfer, or sell any aggregated or anonymized derivatives of Google user data, and does not use any Google user data to develop, improve, or train AI or machine-learning models.
5. How your data is protected
- Your health data travels directly from the Google Health API to Apple Health on your device. It never passes through a server operated by us.
- All communication with Google is encrypted in transit over HTTPS (TLS), enforced by iOS App Transport Security.
- Your Google authorization token is stored in the iOS Keychain, marked as device-only, so it is never included in device backups and cannot be migrated to another device.
- Health data retrieved from Google is held only in memory while a sync runs and is never written to an on-disk cache or a log file.
- The app requests read-only Google scopes and only the minimum set of Apple Health data types it actually writes.
6. Data retention and deletion
Because we operate no servers, we retain no data about you. On your device, the app stores only your Google authorization token (in the Keychain) and non-identifying sync bookkeeping (timestamps and counters — never health values).
When you disconnect your Google account in the app, the app revokes the token with Google and deletes the token together with all local sync bookkeeping from your device. You can also revoke access at myaccount.google.com/permissions. Apple Health permissions can be revoked in the iOS Health app. Data already written to Apple Health remains there under your control and can be deleted in the Health app. Deleting the app removes all remaining app data from your device.
7. Purchases
Subscriptions and one-time purchases are processed by Apple through the App Store. We receive no payment details. Apple's privacy policy applies to the payment process.
8. Legal basis (GDPR)
Where the GDPR applies: processing of your health data happens exclusively on your device, initiated by you. To the extent we are considered a controller for this on-device processing, the legal basis is your explicit consent (Art. 9(2)(a) GDPR, Art. 6(1)(a) GDPR), given when you connect your Google account and grant Apple Health permissions. You can withdraw consent at any time as described in section 5. Since we hold no personal data about you, requests for access, deletion, or portability of health data are fulfilled directly through the controls in section 5.
9. Website
This website is a static site hosted by Vercel Inc. (USA) and sets no cookies. Vercel processes technical request data (including your IP address and time of access) to deliver the site and ensure security; legal basis is our legitimate interest (Art. 6(1)(f) GDPR). Vercel acts as our data processor; data may be processed in the United States — Vercel is certified under the EU-U.S. Data Privacy Framework.
10. Contact
Florian Alber
Brockhausstraße 4
04229 Leipzig, Germany
support@fit2health.app
11. Changes
We may update this policy. The current version is always available at this URL; material changes will be noted in the app.