Privacy Policy
Afia · Last updated 29 August 2026
Afia is an AI-assisted personal training platform that connects clients with coaches. This policy explains what we collect, why, who we share it with, and what you can ask us to do about it.
Afia is operated from Dubai, United Arab Emirates. For any question about this policy or your data, write to privacy@afia.fit.
Who this applies to
Afia has two kinds of user, and this policy covers both.
Coaches hold an Afia account, pay for the service, and use it to manage their clients. Clients are invited by a coach and use Afia to follow programmes, log training and nutrition, and communicate with that coach. Clients do not pay Afia anything.
Afia is for adults. You must be 18 or older to use it, and we do not knowingly collect data from anyone under 18. If you believe a child has given us data, contact us and we will delete it.
What we collect
Account and identity
Your name, email address, and whether you are a coach or a client. Coaches may add a business profile. We never see or store your password — authentication is handled by Supabase.
Health information
This is the most sensitive category we hold, and it is central to what Afia does. Depending on what you provide, it includes:
- Your answers to the PAR-Q pre-exercise screening questionnaire, including questions about heart conditions
- Current and previous injuries, and the body areas affected
- Medications and medical conditions you tell us about
- Body measurements, body weight, and progress photographs
- Nutrition information including food logs, meals, macronutrient targets and supplements
- Reproductive and female health information, where you choose to provide it \u2014 menstrual cycle and regularity, pregnancy status, contraception, and menopausal status
The reproductive health section is optional. It exists because training and nutrition needs change across a cycle, through pregnancy and after it, and a coach cannot programme around something they have not been told. Leaving it blank does not restrict any other part of Afia.
Under data protection law this is special category data and it gets stricter treatment. We collect and use it only with your explicit consent, which you give during onboarding and can withdraw at any time. Withdrawing it means we can no longer generate safe programmes for you, so in practice it ends your use of the service.
Training and activity
Programmes assigned to you, sessions completed, the exercises, sets, repetitions, loads and RPE you record, habits, check-ins, and progress entries over time.
Communications
Messages between you and your coach, coach notes about a client, and voice notes where used.
Technical
Push notification tokens for your device, and diagnostic information when something goes wrong — see the table below for what our error monitoring receives.
Payment
Coaches pay through Stripe. Afia never receives or stores your card details. We hold only the subscription status and billing events Stripe reports back to us.
How we use it
- To run the service — deliver your programme, record your training, show your progress, and carry messages between you and your coach.
- To generate programmes safely — your injuries and PAR-Q answers are used to exclude exercises that are inappropriate for you. This is the primary reason we ask for health information at all.
- To communicate — transactional email such as invitations and account notices, and push notifications you can turn off.
- To take payment — for coaches only.
- To keep the service working — diagnosing errors and preventing abuse.
We do not sell your data. We do not use it for advertising. We do not run analytics or marketing trackers.
AI processing
Afia uses Anthropic's Claude API to generate training programmes and written insights. When a programme is generated, information about the client is sent to Anthropic for processing — this can include training history, goals, injuries and PAR-Q-derived constraints, because those are exactly the inputs that make a programme safe.
Anthropic processes this on our behalf as a sub-processor. Your data is not used to train Anthropic's models.
Legal bases
Where GDPR or comparable law applies, we rely on:
- Contract — to provide the service you or your coach signed up for.
- Explicit consent — for all health information, under Article 9(2)(a).
- Legitimate interests — to secure the service, diagnose faults and prevent abuse.
- Legal obligation — where we must retain records, for example for tax.
Who we share it with
Your coach sees the data you enter — that is the point of the service. Beyond that, we use the following processors. Each handles data only on our instructions.
| Service | What it does | Where |
|---|---|---|
| Supabase | Database, authentication and file storage — all user data at rest | Bahrain |
| Railway | Backend hosting | United States (California) |
| Netlify | Web hosting | Global CDN, United States primary |
| Anthropic | AI programme and insight generation | United States |
| Stripe | Payment processing (coaches only) | United Arab Emirates |
| Sentry | Error monitoring — receives your user ID and email address with error reports | United States |
| Resend | Transactional email | United States |
| Expo | Push notifications and mobile build delivery | United States / global |
| YouTube (Google) | Embedded exercise demonstration videos | Global |
| Google Workspace | Our business email | United States |
Exercise demonstration videos are embedded from YouTube. When one loads, Google may set cookies and receive your IP address under its own privacy policy, which we do not control.
We may also disclose data where the law requires it, or to protect someone's safety or our legal rights.
International transfers
Your data is stored in Bahrain and processed in the United States and the United Arab Emirates. Where data leaves a jurisdiction that restricts transfers, we rely on Standard Contractual Clauses with the processors concerned.
How long we keep it
- While your account is active — we keep your data so the service works and your history stays intact.
- After cancellation — 30 days, then permanent deletion.
- After 24 months of inactivity — we contact you first; if we hear nothing, the account and its data are deleted.
- Where law requires — some billing records are kept longer to meet tax and accounting obligations.
Deletion is permanent. We cannot recover a deleted account.
Your rights
You can ask us to:
- Give you a copy of the data we hold about you
- Correct anything inaccurate
- Delete your account and everything in it
- Export your data in a portable format
- Restrict or object to particular processing
- Withdraw your consent to health data processing
Write to privacy@afia.fit and we will respond within 30 days. You can also delete your account from within the app.
If you are a client, some of what your coach holds about you — their own notes, for instance — is theirs. We will help you reach them.
Security
Data is encrypted in transit and at rest. Access is controlled per-account through row-level security, so one coach cannot see another's clients. We limit what our error monitoring receives: request bodies, headers, cookies and query strings are filtered before an error report leaves our servers, and IP address and location are not attached.
No system is perfectly secure. If a breach affects your data, we will tell you and the relevant regulator as the law requires.
Cookies
We use only what the service needs to work: an authentication token so you stay signed in, and hosting cookies set by Netlify. There are no analytics, advertising or tracking cookies. Embedded YouTube videos may set their own — see above.
Changes
If we change this policy we will update the date at the top, and tell you directly when the change is significant.
Contact
Privacy and data requests: privacy@afia.fit
General support: support@afia.fit
Afia, Dubai, United Arab Emirates. This policy is governed by the laws of the United Arab Emirates, and disputes are subject to the courts of Dubai.