Privacy Policy
This Privacy Policy explains how Elena Magoula, operating the MorfoFit application, collects, uses, stores and protects personal data. It applies to the MorfoFit mobile application, its account services and the website at https://morfofit-api-production.up.railway.app.
1. Data controller
The data controller is Elena Magoula. Questions, requests and complaints concerning personal data may be submitted to [email protected].
2. Personal data we process
Account and profile data
- First name, last name, email address, date of birth and gender selected by the user.
- A cryptographic password hash. MorfoFit does not store the password in readable form.
- An optional profile photograph selected by the user.
- Account creation, update and last-login timestamps.
Fitness preferences and app activity
- Workout schedules and user preferences.
- Notification preferences.
- Saved content and favourites.
- Content views, workout and content progress, video position and viewing-session information.
These records describe use of fitness and educational content. MorfoFit currently does not read Apple Health, Health Connect, body-sensor, precise-location or medical-record data.
Subscription and transaction data
- Store provider, product and base-plan identifiers, subscription status and relevant dates.
- Purchase, subscription and transaction identifiers or tokens supplied by Apple App Store or Google Play.
- Store verification responses and server-notification information required to validate access, renewals, cancellations, refunds and revocations.
Payments are processed by Apple or Google. MorfoFit does not receive or store full payment-card details.
Communications and security data
- Email address and short-lived security tokens used for password-reset and account-deletion requests.
- Technical request logs, such as timestamp, route, response status and duration, for security and troubleshooting. Hosting providers may process ordinary network data, including IP addresses, as part of delivering the service.
Passwords, authentication tokens, deletion tokens, email addresses and store purchase payloads are excluded or redacted from application request logs.
3. How we use personal data
- To create, authenticate and administer MorfoFit accounts.
- To provide personalised schedules, preferences, favourites and progress features.
- To display, restore and verify paid subscription access.
- To send transactional messages requested by the user, such as password-reset or deletion-confirmation emails.
- To secure the service, investigate failures, prevent fraud and enforce the Terms of Use.
- To comply with legal obligations and establish, exercise or defend legal claims.
MorfoFit does not use solely automated decision-making that produces legal or similarly significant effects.
4. Legal bases under the GDPR
- Performance of a contract: account administration, core app features and subscription access.
- Consent: optional profile images, optional notifications and any feature for which consent is expressly requested.
- Legitimate interests: service security, fraud prevention, troubleshooting and protection of legal rights, balanced against user rights.
- Legal obligation: records that must be retained or disclosed under applicable law.
5. Service providers and recipients
Personal data is disclosed only where necessary to operate MorfoFit:
- Railway: application and database hosting.
- Cloudinary: storage and delivery of user-selected profile images and application media.
- Apple App Store and Google Play: payment processing, subscription management and purchase verification.
- Email infrastructure provider: delivery of transactional emails.
- Google Fonts infrastructure: font delivery may involve ordinary technical request data where runtime font delivery is used.
- Professional advisers or public authorities where disclosure is legally required or necessary to protect legal rights.
Providers act under their own terms and privacy notices or as processors subject to contractual and legal safeguards. MorfoFit does not sell, rent or trade personal data.
6. International transfers
Some providers may process data outside Greece or the European Economic Area. Where required, transfers rely on an adequacy decision, Standard Contractual Clauses or another lawful safeguard under the GDPR.
7. Retention
- Account, profile, preferences, favourites and progress data are retained while the account remains active.
- Technical security logs are normally retained for no more than 30 days, unless a longer period is necessary to investigate an incident or protect legal rights.
- Password-reset and account-deletion links become unusable when they expire.
- After confirmed account deletion, identifiable data is removed from active systems without undue delay and no later than 30 days. The current implementation normally completes active-system deletion immediately.
- Encrypted or restricted backups may retain residual copies until the next backup-overwrite cycle, normally no longer than 30 additional days, and are not restored except for disaster recovery.
- Minimal, detached store transaction identifiers and dates may be retained for up to 5 years where necessary for accounting reconciliation, fraud prevention, chargeback handling, regulatory compliance or legal claims. They are not used to recreate the deleted profile.
8. Account deletion
Users may initiate deletion inside the application under Settings → Account → Delete Account, or submit a verified request at https://morfofit-api-production.up.railway.app/delete-account.
Deletion removes the account and associated profile, preferences, favourites, schedules, progress, viewing history, authentication records and user-uploaded profile media. If an authorised editor has created published MorfoFit content, that editorial content may remain without the deleted author identifier. Only the limited records described in Section 7 may otherwise be retained.
Deleting a MorfoFit account does not automatically cancel an Apple App Store or Google Play subscription. Store subscriptions must be managed separately in the relevant store account.
9. Your rights
Subject to applicable law, users may request access, correction, deletion, restriction, objection and data portability, and may withdraw consent at any time where processing is based on consent. Requests may be sent to [email protected].
Users may also lodge a complaint with the Hellenic Data Protection Authority or another competent supervisory authority. Exercising a privacy right does not affect rights that have already arisen under applicable law.
10. Security
MorfoFit uses HTTPS in production, password hashing, access controls, short-lived verification links, authenticated API requests and data-minimisation measures. No internet service can guarantee absolute security; users should protect their credentials and report suspected misuse promptly.
11. Children
MorfoFit is not directed to young children. A person who has not reached the age at which they may independently consent to online services in their country should use MorfoFit only with authorisation from a parent or legal guardian.
12. Changes to this policy
This policy may be updated when MorfoFit features, providers or legal requirements change. The current version and its effective date will remain available at this URL. Material changes will be communicated through the application or another appropriate channel.
13. Contact
Elena Magoula
Email: [email protected]
Website: https://morfofit-api-production.up.railway.app