Skip to main content
Legal

Privacy Policy

Last updated: April 2026 · UK GDPR & Data Protection Act 2018

UK GDPR Compliance Summary
  • AI prompts are processed transiently - not stored by FitOut Insider after response generation
  • Account data and your project data stored on Supabase EU-region servers, synced across your devices, isolated by project membership via row-level security
  • No analytics cookies, advertising cookies, or third-party tracking scripts
  • Authentication uses a single HttpOnly session cookie - no personal data stored
  • API inputs are not used by Anthropic to train AI models (API policy)
  • You have the right to access, correct, or erase any personal data we hold

1. Who We Are

FitOut Insider is a trading name of Dariusz Kubies Services ("we", "us", "our"). For data protection enquiries, contact: hello@fitoutinsider.com. As the data controller, we are responsible for any personal data processed by this Service.

2. What Data We Collect

We collect minimal data: • Account data: When you subscribe, Stripe collects your email and payment details. We receive only your email address to create your account. • Registration IP address: We record your IP address at the point of account creation as part of our terms-of-service acceptance record. This is retained solely as legal evidence that you agreed to our Terms of Service at a specific time and place, in accordance with our legitimate interests under UK GDPR Article 6(1)(f). It is never used for tracking or marketing, is not surfaced in your account, and is accessible only via a restricted internal compliance export. • Session authentication: A single encrypted session cookie is set when you log in. This cookie contains only a session token - no name, email, or personal data. • Tool inputs (AI processing): When you use an AI feature, the relevant text from your tool is sent to the Anthropic Claude API to generate a response. That transmitted prompt is processed transiently - it is not retained by FitOut Insider after the response is generated, and is not used to train AI models. • Project data: The project details, registers, schedules, programmes and other working data you enter into the tools are saved to your secure account in our database (Supabase, EU region) so your work persists and follows you across your signed-in devices. Each project has a membership list; on a Team plan, the colleagues you add to a project can see and edit that project's data. Access is enforced by row-level security at the database level - you can only read or edit data for projects you are a member of, and no account outside a project's membership can read it. You can delete this data at any time. • Usage tracking: We record the number of AI requests used per month (no content, just counts) to enforce your plan allowance. • Feedback and contact messages: If you submit the feedback or contact form, the message is emailed to us and held in our mailbox - it is not stored in our database. If you use the in-app AI support chat, we record only usage metrics (turns, tokens, cost), never the conversation content. See section 7. • Client portal comments: If someone comments on a client portal you have shared, we store the comment text and the name and email address they provide. This may include people who do not have an account with us. Comments are deleted when the portal is deleted, and in any case after 12 months (see section 7). • Client portals: If you create a client portal, we store the portal's title, the client name and email address you enter, an optional password, and the access token that forms the share link. Because these links are shared outside the platform, deleting your account deactivates the portal first and it is permanently deleted 90 days later (see section 7). • Account deletion record: If you delete your account, we retain a limited record of that deletion - your email, name, phone, company name, job title, the reason you gave, and the date - for 12 months for fraud prevention and dispute resolution, under our legitimate interests (UK GDPR Article 6(1)(f)). It is then permanently deleted. See section 7. • Bug reports: If you submit a bug report, we store the description you write, the page URL it was sent from, and - if you are signed in - your email address. Retained for 12 months (see section 7). • Security audit logs: We record security-relevant actions such as API key access and document exports, together with the action, the date, your account identifier and the IP address the action came from. The IP address and any associated metadata are removed after 12 months (see section 7). • Technical error logs: When a technical error occurs in the platform, we automatically record the error message, the page URL where the error occurred, your browser type, and (if you are signed in) your user account identifier. This data is used exclusively to diagnose and fix technical issues affecting the Service. It is stored in our Supabase database (EU region) and is never shared with any third party.

3. AI Processing - Anthropic Claude API

Tool inputs are processed by Anthropic's Claude API to generate outputs. Anthropic may process inputs in accordance with their own privacy policy and API terms of service. By Anthropic's policy, API inputs are not used to train AI models. We do not retain copies of your tool inputs after the response is generated. We recommend you do not input sensitive personal data (e.g. employee names, National Insurance numbers, or medical information) into tool forms unless necessary for the specific document being generated.

4. Data Storage

Account data and your project working data (the project details, registers, schedules, programmes and outputs you create in the tools) are stored in Supabase (PostgreSQL), hosted in the EU (Frankfurt, Germany), and synced across your signed-in devices. All connections are encrypted end-to-end (TLS 1.3) and data is encrypted at rest (AES-256). Access is governed by row-level security at the database level: you can only read and edit data for projects you are a member of. On a Team plan, the colleagues you add to a project can see and edit the data for that project; no account outside the project membership can read it. A copy is also cached in your browser so the tools keep working offline and sync when you reconnect. Your data is never used to train AI models. We do not share or sell your data with any third party. Our hosting infrastructure runs on Vercel for serverless functions and global CDN delivery.

5. Cookies

We use one essential cookie: • fitout-snonce: A session authentication cookie. Essential for Service access. No personal data. HttpOnly, Secure, SameSite=Strict. Duration: session-based (expires on sign-out or browser close). We do not use analytics cookies, advertising cookies, or any third-party tracking cookies. See our Cookie Policy for full details.

6. Legal Basis for Processing (UK GDPR)

Our legal bases for processing are: • Contract performance (Article 6(1)(b)): Processing account and usage data to deliver the subscription service you have paid for. • Legitimate interests (Article 6(1)(f)): Session authentication, quota enforcement, and transient processing of tool inputs to deliver AI-generated outputs. Recording your IP address at registration to maintain an auditable record of terms-of-service acceptance (fraud prevention and legal compliance). Automatic technical error logging to identify and resolve platform issues affecting service delivery. • Consent (Article 6(1)(a)): For any optional feedback or support messages submitted.

7. Data Retention

Session cookies: Deleted on sign-out or browser close. Tool inputs (AI prompts): Not retained after AI response generation. Project data: Retained in your account until you delete it, or for the duration of your subscription plus 90 days after cancellation, then deleted. Account data: Retained for the duration of your subscription plus 90 days after cancellation, then deleted. Registration IP address: Retained for the duration of your account plus 90 days after deletion, then permanently removed. Retained solely as part of the terms-of-service acceptance record. Usage records: Retained for 13 months for billing and dispute purposes, on the basis of our legitimate interests under UK GDPR Article 6(1)(f), then automatically deleted. Feedback and contact messages: Messages you send us through the feedback or contact form are emailed to hello@fitoutinsider.com and are not stored in our database. They are kept in that mailbox for up to 12 months so that we can respond to you and improve the Service, then deleted. The in-app AI support chat stores only usage metrics (turns, tokens, cost), never the conversation content. Technical error logs: Retained for 90 days to support issue diagnosis and resolution, then automatically deleted. Account deletion record: When you delete your account we keep a limited record of the deletion (your email, name, phone, company, job title, the reason you gave, and the date). This is retained for 12 months for fraud prevention and dispute resolution, on the basis of our legitimate interests under UK GDPR Article 6(1)(f), and is then automatically and permanently deleted. Deactivated client portals: Client portals you create are shared by link, so when you delete your account (or a portal is otherwise deactivated) the portal is first deactivated rather than removed. Deactivated portals are retained for 90 days, for the same fraud-prevention and dispute-resolution purposes under UK GDPR Article 6(1)(f), and are then automatically and permanently deleted. Bug reports: Retained for 12 months, so that we can diagnose and resolve the reported issue and detect abuse of the reporting form, on the basis of our legitimate interests under UK GDPR Article 6(1)(f). The report - including any email address attached to it - is then automatically and permanently deleted. Security audit logs: The record of a security-relevant action is kept as an ongoing security measure, but the personal data attached to it is not. After 12 months the originating IP address and any associated metadata are automatically and permanently removed, leaving only the action and the date it occurred. This is done on the basis of our legitimate interests under UK GDPR Article 6(1)(f). Administrator action log: We keep a record of actions taken by our own administrators, so that account changes can be traced. These records are retained for 12 months, on the basis of our legitimate interests under UK GDPR Article 6(1)(f), and are then automatically and permanently deleted. Client portal comments: Comments left on a client portal, together with the name and email address of the person who left them, are deleted when the portal is deleted, and in any case automatically and permanently deleted after 12 months.

8. Your Rights Under UK GDPR

You have the right to: • Access: Request a copy of any personal data we hold about you • Rectification: Correct any inaccurate personal data • Erasure: Request deletion of your personal data ("right to be forgotten") • Restriction: Request we limit processing of your data • Portability: Receive your data in a portable format • Objection: Object to processing based on legitimate interests To exercise any of these rights, contact: hello@fitoutinsider.com. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

9. Security

We implement appropriate technical and organisational measures to protect data, including: HTTPS/TLS 1.3 encryption for all data in transit; AES-256 encryption for data at rest (Supabase); HttpOnly and Secure flags on authentication cookies; Row Level Security (RLS) ensuring users can only access their own data. However, no system is entirely secure, and we cannot guarantee absolute security. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of the breach, and notify affected individuals without undue delay where the breach is likely to result in a high risk.

10. Sub-Processors and International Transfers

We use the following third-party sub-processors to deliver the Service: • Supabase (EU region) - Database and authentication. Your account data stays in the EU. • Anthropic (USA) - AI processing of tool inputs via API. Inputs are processed transiently and not retained. Anthropic operates under standard contractual clauses. • Vercel (USA/EU) - Hosting and serverless function delivery. EU region used where possible. • Stripe (USA/EU) - Payment processing. We receive only your email; Stripe holds payment card data. • SignWell (USA) - E-signature processing for documents sent for signing via the E-Signatures tool. SignWell processes signatory email addresses and document content. Governed by standard contractual clauses. Data transfers to the USA (Anthropic, Vercel, Stripe, SignWell) are governed by standard contractual clauses (SCCs) or equivalent adequacy mechanisms under UK GDPR and EU GDPR.

11. Data Processing Agreement

Data Processing Agreements (DPAs) are in place with each sub-processor via their standard contractual terms. We do not share personal data with any processor that does not provide adequate data protection guarantees. A formal DPA with FitOut Insider is available on request for Professional and Enterprise plan subscribers. Contact hello@fitoutinsider.com to request one.

12. EU GDPR and RODO

FitOut Insider is a trading name of Dariusz Kubies Services, established in Poland (EU). As such, we are also subject to EU GDPR - known in Poland as RODO (Rozporządzenie Parlamentu Europejskiego i Rady (UE) 2016/679). UK GDPR and EU GDPR are substantively identical and we apply the higher standard where any difference exists. FitOut Insider is operated by a company established in Poland and is therefore an EU-established entity. UK users may raise complaints with the ICO. EU users may raise complaints with the UODO as the lead supervisory authority under the one-stop-shop mechanism. Both authorities apply because the Service processes data from both UK and EU-based users. Our lead supervisory authority for EU matters is the Polish data protection authority: UODO (Urząd Ochrony Danych Osobowych). EU-based data subjects may lodge complaints with UODO at uodo.gov.pl. UK-based data subjects may lodge complaints with the ICO at ico.org.uk.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Where changes are significant, we will notify subscribers by email at least 14 days before the changes take effect. The date of the most recent revision is noted at the top of this page.

14. Contact

Data controller: Dariusz Kubies Services (trading as FitOut Insider) Email: hello@fitoutinsider.com Privacy enquiries: hello@fitoutinsider.com ICO complaints: ico.org.uk UODO complaints (EU): uodo.gov.pl UK Article 27 representative: We are in the process of appointing a UK GDPR Article 27 representative. Details will be updated here once confirmed.