Local-first logging
Core logging is written to the device so common workout, food, run, and water flows can continue through a weak connection.
This policy explains how Zenith Fitness handles information in the Zenith app, zenithfit.app website, connected wearable features, and support services.
Last updated July 22, 2026.
Core logging is written to the device so common workout, food, run, and water flows can continue through a weak connection.
Signed-in account data may sync to managed cloud services for backup, recovery, social features, storage, and cross-device continuity.
Zenith does not sell personal information or use it for third-party cross-app advertising or tracking.
Zenith Fitness ("Zenith," "we," "our," or "us") is published and operated by Alexander Serban, who is responsible for the service and the information described in this policy.
We do not publish a postal address that has not been designated for privacy correspondence. If a law requires another contact method, email us for the appropriate instructions.
Coaching and health insights are informational fitness guidance, not medical diagnosis or treatment.
Zenith is local-first. When you sign in or enable cloud-backed features, supported account data may also be stored in managed cloud services for authentication, backup, synchronization, social features, storage, exports, and recovery.
Sensitive logs, health and nutrition records, routes, account archives, and private media are scoped to the authenticated owner unless you deliberately publish or share them. Under the current social defaults, your display name, username, avatar, rank, and basic profile or network counts may be discoverable to other Zenith users; social posts and activity use the audience controls shown when you share. Private media uses access-controlled storage. Information is encrypted in transit and managed infrastructure applies access and storage safeguards appropriate to the service.
No storage or transmission method is perfectly secure. We limit access, minimize sensitive telemetry, and maintain deletion and incident-response paths, but cannot promise absolute security.
You can revoke device permissions in system settings. Disconnecting an integration stops new collection, but previously imported data remains unless the integration-specific notice or control says it will be deleted. Garmin follows the stricter revocation and deletion rules in Section 10 whenever that integration is available in your installed build.
Health information is not used for advertising, cross-app tracking, resale, or unrelated analytics.
When an installed Zenith build offers Garmin, the Garmin SDK, watch-message access, connection, and sync remain inactive until you sign in, Zenith verifies the current backend contract, and you expressly accept the current versioned Garmin notice. Consent is account-specific and is not carried to another account. Without current consent, the rest of Zenith continues to work.
The notice covers the account-to-watch link and device/app identifiers; workout and activity summaries; available fitness metrics; hydration summaries and goals; permitted planned-meal summaries; water and meal actions you request on the watch; and route location only during an outdoor route activity you deliberately start. Zenith uses that information for secure watch pairing, workout and activity sync you request, fitness progress and coaching, iPhone handoffs you request, and hydration or meal sync you request. Food search and editing remain on iPhone.
Any data you submit through the Zenith Garmin application is submitted to Zenith, not to Garmin. Garmin has no responsibility or liability for Zenith's collection, use, storage, disclosure, deletion, or other handling of that data.
Garmin location collection is off by default. It may begin only after you opt in and start an outdoor activity that requires route recording, and it stops when that activity ends.
Choosing Revoke and Unlink Garmin withdraws Garmin consent. Zenith stops new Garmin collection, invalidates the account-to-watch binding, and deletes Garmin-sourced activity and route data, hydration and permitted planned-meal projections, watch-action provenance, links, receipts, and local integration data from active Zenith systems and the verified owner's local Garmin integration state. Zenith does not retain or restore Garmin-sourced data after you revoke consent or request its deletion. Independently entered Zenith records that were not collected through Garmin remain. Zenith does not sell, rent, or transfer Garmin user or activity data.
When you perform an eligible food search or barcode lookup, Zenith sends the food phrase or normalized barcode, plus US dataset and language context, from Zenith's authenticated server to the fatsecret Platform API. Provider credentials remain on the server.
Food search and logging are available to users. When you select a FatSecret result, Zenith may retain permitted food and serving identifiers plus Zenith's permitted parity nutrition and log fields. Restricted provider-detail payloads are not durably stored: other FatSecret response content is short-lived and must be removed or replaced by a fresh request within 24 hours.
Saved meals, diary export and restore, and insight features may use user-entered data, permitted Zenith log fields, and identifiers within this boundary; they do not retain or reproduce restricted provider detail. FatSecret content is not used for diet, nutrition, or health advice unless Zenith has written permission for that use.
Operational telemetry may retain a stable internal account identifier with request status, timing, cache state, result count, and provider-call count for rate limits, continuity, reliability, and abuse investigation.
It excludes raw food queries, barcodes, returned foods, nutrient payloads, credentials, and OAuth signatures and is not used for advertising. Other food datasets may provide fallback or complementary results under their applicable terms.
If you deliberately connect Zenith in ChatGPT, ChatGPT may send the literal date and time zone, food and workout details, and nutrition estimates needed for the action you request. ChatGPT and OpenAI process the conversation and host and transport the embedded review surface under your ChatGPT account, workspace settings, plan, and applicable OpenAI terms. Zenith does not call the OpenAI API, hold an OpenAI API key, or pay for model reasoning on your behalf.
The integration uses a dedicated OAuth authorization-code flow with PKCE and short-lived opaque Zenith coordinator credentials. ChatGPT does not receive your normal Zenith or Supabase session. Zenith resolves the real account owner only inside its private backend. Detailed drafts, match displays, confirmation capabilities, receipts, undo controls, and daily summaries are kept out of model-visible tool text, but they are still transported and rendered by the ChatGPT host.
Preparing a review does not search a food provider, run a workout lookup, or write your diary. You first review the exact date, foods, workouts, and estimates, then choose either Use ChatGPT estimates or Use Zenith Search. ChatGPT estimates make zero food-provider calls and zero workout lookups. Zenith Search checks saved foods and Zenith's food catalog first, then may make at most six confirmed FatSecret attempts for unresolved foods; separately, it checks saved workouts and Zenith's internal exercise catalog with at most six workout match attempts and no external workout provider. Neither lane retries automatically, no result is chosen automatically, saving requires a separate final confirmation, and past dates are supported.
Saved estimates are remembered privately for your own future repeats. Optional contribution to Zenith's provider-free catalog-review queue is off by default, and repetition alone never makes an estimate authoritative. Cancelled drafts are redacted promptly; expired workflow bodies are removed by a monitored retention process; committed entries remain in Zenith until edited, deleted, or removed through account deletion. You may disconnect the app in ChatGPT or revoke its Zenith grant to stop new access.
We disclose information only as needed:
Zenith does not sell personal information and does not use it for third-party cross-app advertising or tracking.
Core tools are unlocked. No Premium product, price, trial, subscription, purchase, checkout, or restore flow is active. If purchases are enabled later, Apple or Google processes the store transaction and Zenith does not receive full payment-card details. A subscription-management provider would receive only the identifiers and transaction information needed to manage entitlements.
The in-app Delete Account flow removes the authenticated account and account-scoped active-service data, including any Garmin integration data, after the server confirms deletion, then clears local Zenith data on that installation. A limited deletion receipt or tombstone may remain to confirm completion and prevent unsafe retries; it does not contain Garmin activity, route, installation, binding, or receipt data.
Residual encrypted backups, provider logs, or records required for legal, security, billing, or safety purposes may remain until their ordinary retention period expires and are not restored as an active account. Deleting the app alone does not delete signed-in cloud data.
Depending on where you live, you may request access, correction, deletion, portability, restriction, or objection, or appeal a decision. We may verify identity and authority before completing a request.
Zenith does not sell or share personal information for cross-context behavioral advertising, so there is no sale or targeted-ad sharing to opt out of.
Zenith is operated in the United States. Information may be processed in the United States and other locations where service providers operate. Where required, we use contractual or other lawful safeguards for international transfers.
Zenith is not directed to children under 13 and does not knowingly collect personal information from a child under 13. Contact privacy@zenithfit.app if you believe a child supplied personal information.
We may update this policy as Zenith or applicable requirements change. We will post the revised policy with a new Last Updated date and provide additional notice when a material change requires it.