FitScan legal
Privacy policy
FitScan by MiamiFitBox · Effective September 16, 2026 · Operations timezone America/New_York
This policy describes how MiamiFitBox (“we”, “us”) handles information when you use FitScan — the meal QR, account, and coaching app that sits next to miamifitbox.com. FitScan does not take payments. Checkout stays on MiamiFitBox / Shopify. Our kitchen and support operations use America/New_York calendar dates (Eastern Time).
This is FitScan-specific product language, not a substitute for a lawyer-reviewed enterprise policy. If something here conflicts with a signed MiamiFitBox agreement, that agreement controls.
Who this covers
Customers who scan a box, type a meal code, create a FitScan account, or use coaching tools. Kitchen staff who sign in at the separate kitchen login are MiamiFitBox operators; their use is for preparing meals, labels, and customer support — not a consumer FitScan profile.
Information we collect
- Accounts. Name, email, password hash (we do not store the plain password), optional phone number for kitchen SMS, and a private profile photo if you upload one.
- Meal scans. The meal or plan code on the sticker, time of the scan (Eastern Time for daily totals), and whether you were signed in so the plate can count toward your log.
- Steps and water. Daily totals you type on Progress, plus optional auto-counted steps from this phone’s motion sensors while FitScan is open (PWA or native shell). Day keys are America/New_York. All-day Apple Health / Health Connect is not enabled until a later native release with a paid Apple Developer account.
- Weigh-ins and goals. Start weight, target weight, and dated scale entries you choose to log.
- Progress photos. Pictures you upload of yourself for diet progress. These are stored privately (Vercel Blob in production) and are served only to the signed-in owner — not on a public CDN URL.
- AI food estimates. Photos of extra food (not a FitScan box) that you submit so we can suggest a name and protein / carbs / fat. You confirm or edit before save. Estimates are coaching aids, not lab analysis or medical advice.
- Messages and SMS. In-app notes the kitchen sends to your FitScan inbox, AI coach questions you type, and SMS the kitchen sends to a number on your account (via Twilio when configured).
- Shopify order email sync. If you use the same email on miamifitbox.com and FitScan, we may attach matching Shopify orders (create / update / cancel webhooks and optional Admin API backfill on signup or login). We do not store unmatched shop orders for emails that have no FitScan customer yet.
- Technical logs. Approximate IP, user agent, and error logs needed to keep login, scans, and AI calls working and to apply abuse limits.
How we use it
We use this information to:
- Show the ingredients, nutrition, and tips for the box you scanned.
- Keep your meal log, weekly macros, rewards, and progress recap.
- Show Health-sourced activity on Progress when you connect Apple Health or Health Connect in the native app. We only read the types you approve (steps, workouts, active energy, walking/running distance). We do not write samples back.
- Recommend published FitScan meals and plans through the in-app coach.
- Let the kitchen message you in-app or by SMS about orders, rewards, or account issues.
- Match MiamiFitBox purchases to your FitScan profile when emails line up.
- Protect the service (rate limits, disabling abused accounts, debugging failures).
We do not sell your personal information. We do not use progress photos or extra-food photos for public marketing.
AI providers
Extra-food photo estimates and some coach replies may be processed by Google Gemini and/or OpenAI when those keys are configured. Images and prompts are sent for that request only. If live AI is over quota or unset, FitScan falls back to a built-in coach or hand entry so you can still log food. Do not upload photos of other people without their permission, or documents you do not want processed.
Sharing
We share data only as needed to run FitScan:
- Hosting, database, and private file storage (e.g. Vercel / Postgres / Blob).
- Shopify, to import orders that already belong to your email.
- Twilio, when the kitchen sends SMS to a number you provided.
- AI providers, as described above.
- Apple Health / Health Connect, only on device, when you tap Connect in the native app. FitScan then stores daily totals on your account. Denying permission leaves typed steps in place.
- The law, if we are required to disclose.
Kitchen staff at MiamiFitBox can see customer accounts they manage (orders, rewards, inbox, SMS history) in order to fulfill meals and support you. Other customers cannot open your private photos or inbox.
Retention
Account, scan, order, weigh-in, photo, and message data stay until you ask us to delete the account, or we deactivate it for abuse, or we no longer need it to operate FitScan. Rate-limit counters are short-lived. Server logs are kept only as long as needed for operations and security.
Your choices
You can sign out, stop uploading photos, or stop using the coach at any time. On a native install you can disconnect Health or decline the system permission sheet — Progress then stays on typed steps and water. To correct a mistaken scan or extra-food line, use the remove actions in your account. To deactivate or delete a FitScan account, contact MiamiFitBox through miamifitbox.com. Shopify checkout, shipping, and payment records are governed by MiamiFitBox / Shopify — not this app.
Children
FitScan is for MiamiFitBox customers and is not directed at children under 13. Do not create an account for a child under 13.
Contact
MiamiFitBox operates FitScan from Miami, Florida, using America/New_York business days (including Wednesday upcoming-week menu publish). Privacy questions: reach us via the store at miamifitbox.com. Also see our Terms of use.
Questions? Back to FitScan.