Privacy policy
FitnessFeed is a personal health and fitness reporting integration operated by Jerry Fireman. This policy describes its current personal reporting workflow.
Data accessed and purpose
With the account owner’s permission, the workflow reads Google Health activity and heart-rate zone summaries, calorie expenditure, sleep duration and stages, and nutrition records including calories and protein. It reads Hevy exercise names, workout dates, set types, weights, repetitions, and related workout details. These records are used to prepare and compare monthly personal reports. Google Health access is read-only.
Processing and sharing
Records provided to the reporting workflow may be processed in ChatGPT and its execution environment to calculate report metrics. Saved reports and uploaded records may remain in the account’s conversations and file storage, subject to its settings and the service provider’s policies. Google, Hevy, and MyFitnessPal retain their source records under their own policies. No health records or credentials are published on this website. FitnessFeed does not sell data or use it for advertising.
Storage and credentials
The private reporting dashboard stores Google OAuth credentials and the Hevy API key encrypted with AES-GCM in its hosted database; the encryption key is held separately as a server runtime secret. Stored credentials are used server-side to retrieve authorized records and are not returned to the browser after saving. Monthly report summaries are stored in the private dashboard database. Raw source records are processed to calculate reports but are not persistently stored by the dashboard. Access to the dashboard requires the owner’s ChatGPT sign-in. This public information site does not store API keys, OAuth tokens, or personal health records. The owner can remove stored credentials in the dashboard. To request removal of stored report summaries, contact the operator. Planned monthly PDF delivery is to the owner’s email address; email delivery is not yet active. Once activated, the email provider will also process and retain the report attachment under its own policies.
Retention and deletion
The account owner controls retained uploads and reports and can delete them using the relevant service’s controls. Deletion from the reporting account does not delete records held by Google Health, Hevy, or MyFitnessPal. Provider retention and backup periods may apply.
Revoke access
Google authorization can be revoked through Google Account connections. Hevy access can be revoked by deleting or replacing its API key. Revocation stops future authorized retrieval but does not automatically delete existing reports.
Website and contact
This site uses no analytics or advertising scripts and has no health-data forms. Its hosting provider may process standard technical request information to serve and protect the pages. FitnessFeed is intended for its operator’s personal use. Contact the operator using the support email shown on the Google OAuth consent screen.
Google API data use
FitnessFeed’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.