Trust & transparency
FitOps is built for fitness professionals, not healthcare organizations. Here's exactly what we store, how we use it, and what we don't do.
FitOps does NOT train AI models on your client data.
We use OpenAI as our API provider. When you use AI features (intake, program generation, check-ins), your data is sent to OpenAI's API under their standard data processing terms — and we do not and will not use it to train any models. Full stop.
This means your clients' injury history, goals, and progress data stay private and are never fed back into a training pipeline.
Everything is stored in a PostgreSQL database on Render — a cloud infrastructure provider. Data is at rest within their environment.
What we store:
What we do not store:
All data transmitted between your browser and FitOps is encrypted using TLS 1.2+. This is enforced by default on Render's infrastructure.
Data at rest (database storage) is managed by Render's infrastructure. We recommend PTs also use strong, unique passwords for their accounts and enable any available multi-factor authentication.
Only the PT (account owner) can view client data.
There is no public-facing access to client information. Clients can access their own assigned programs and logs via a private portal link, but they can only see their own data — never another client's.
FitOps staff do not have routine access to PT client data. If you need to contact us about a technical issue, you control what information you share.
PTs can delete client records at any time from the dashboard. Deleting a client removes their intake data, programs, and logs from FitOps.
To delete a client: log in to your dashboard, open the client profile, and use the delete option. This action is permanent and cannot be undone.
If you need help deleting data or have questions about our data retention, contact us at support@fitops.app.
Stripe processes all payments. FitOps does not store credit card numbers, debit card numbers, or billing tokens on our servers.
When you subscribe to FitOps, you complete payment on Stripe's secure hosted page. Stripe's own compliance and security certifications apply to payment data — we never see or handle raw card details.
Not HIPAA-Compliant. Not intended for clinical use.
FitOps is a business operations tool for fitness and personal training professionals. It is not a covered entity or business associate under HIPAA and is not currently structured to meet HIPAA compliance requirements.
Do not use FitOps to store or manage clinical records, medical diagnoses, or protected health information (PHI) as defined under HIPAA. If you are a physical therapist operating under a clinical license, consult your compliance advisor before using this product.
If you need a HIPAA-compliant platform for clinical operations, please contact us and we'll help you find a suitable alternative.
FitOps is not medical advice and does not make clinical decisions.
Programs and guidance generated by FitOps are intended for generally healthy individuals whose trainers have assessed them as suitable for exercise. FitOps is not a licensed medical device, does not provide clinical decision support, and should not be used as a substitute for professional medical evaluation, diagnosis, or treatment.
Clients with known injuries, medical conditions, or special populations (post-surgical, cardiac rehab, etc.) should be assessed by a qualified healthcare provider before using any FitOps-generated program. The PT is responsible for reviewing and approving any AI-generated program before client delivery.
Email us at support@fitops.app with any questions about how we handle, store, or protect your client data. We respond to all data-related inquiries within 2 business days.
If you're a PT working with a specific compliance requirement (HIPAA, FERPA, state-specific PT board rules), we're happy to walk you through what FitOps does and doesn't do.