Privacy Policy
Last updated: 21 August 2026
This Privacy Policy explains how Chibuike Matthew Ikechukwu, doing business as GoshFit ('GoshFit', 'we', 'us', or 'our'), collects, uses, stores, shares, and protects your personal information when you use our services (the 'Services'), including when you visit https://goshfit.app, use the GoshFit application, or contact us.
GoshFit is a subscription-based fitness web application built for Nigerian users, providing structured workout plans, a Nigerian food calorie database, meal and voice-note logging, progress tracking, personal streaks, and gym-buddy accountability.
We are the data controller responsible for your personal information. If you do not agree with this policy, please do not use the Services. Questions? Email us at goshfitapp@gmail.com.
This policy is written primarily under the Nigeria Data Protection Act 2023 (NDPA). If you access GoshFit from outside Nigeria, additional local laws (such as the EU/UK GDPR) may also give you rights, as described below.
1. What information we collect
Information you provide to us. Depending on how you use GoshFit, this may include:
- Name and email address
- Account credentials (a password if you sign up with email; authentication data if you sign up with Google)
- Profile photo (provided by Google when you sign in with Google, or one you upload)
- Health and fitness data: age, gender, height, weight, body measurements (chest, waist, hips, arms, thighs), body-fat percentage, and fitness goals
- Workout and exercise logs (the sets, reps, and weights you record)
- Meal and nutrition logs, including entries created by typing, by voice note, or through the guided food scanner
- Voice recordings and their transcripts, when you use voice logging
- Photos you take of your meals using the in-app food scanner
- Gym-buddy information: your buddy code and the pairings you create
- Messages you send us when you contact support
We treat your health and fitness data as sensitive personal information and process it only to run the features you use, with your consent or as otherwise permitted by law.
Payment information.When you subscribe, payment is handled entirely by Paystack. We never see or store your full card number or card security code — Paystack processes and stores those. We receive limited records such as your subscription status, a Paystack customer or subscription reference, and whether a payment succeeded. Paystack's privacy notice is available at https://paystack.com/privacy/merchant.
Information collected automatically. When you use the Services, we and our infrastructure providers automatically collect technical data such as your IP address, device and browser type, operating system, language settings, and usage information (which features you use and when, and error or crash reports). This supports security, diagnostics, and improving the app. We also store a device push-notification token (via Firebase Cloud Messaging) if you enable notifications, so we can send workout reminders, streak nudges, and gym-buddy pings.
We do not run advertising networks, and we do not sell your personal information.
2. How we use your information
We use your information to:
- Create and manage your account and authenticate you
- Provide the Services: workout plans, food and calorie tracking, meal and voice logging, progress tracking, streaks, and gym-buddy features
- Process your subscription, trial, and payments through Paystack
- Send you service-related messages (reminders, streak nudges, gym-buddy notifications, and important account or policy updates)
- Respond to your support requests
- Keep the Services secure and prevent fraud or abuse
- Understand how the app is used so we can improve it
- Comply with legal obligations
We send a notification to a gym buddy you have mutually connected with when you complete a workout. This only happens between users who have each entered the other's buddy code, and you can turn it off.
3. Legal bases for processing
Under the NDPA (and, where it applies, the GDPR), we rely on one or more of the following:
- Consent — for example, when you enable voice logging or push notifications. You can withdraw consent at any time.
- Performance of a contract — to provide the Services you sign up and pay for.
- Legitimate interests — to secure the Services, prevent fraud, understand usage, and support workout accountability between connected users, provided these interests do not override your rights.
- Legal obligation — where we must process data to comply with the law.
- Vital interests— in rare cases, to protect someone's safety.
4. When and with whom we share your information
We do not sell your data. We share it only with service providers who help us run GoshFit, under agreements that require them to protect it and use it only on our instructions:
- Google / Firebase (Google Cloud Platform) — authentication (Google Sign-In and Firebase Authentication), database (Cloud Firestore), file storage (Cloud Storage), and push notifications (Firebase Cloud Messaging)
- Vercel — website and application hosting
- Paystack — payment processing
- OpenAI — transcribing your voice notes into text (see Section 6)
We may also disclose information where required by law, to enforce our terms, to protect our rights or someone's safety, or in connection with a business transfer (such as a merger, acquisition, or sale of assets).
5. Cookies and similar technologies
We use only the cookies and local storage strictly necessary to run the app — for example, to keep you signed in and remember your display preferences (such as your light or dark theme). We do not use advertising cookies, third-party ad trackers, or cross-site tracking pixels. Your browser can be set to refuse cookies, but some features may not work if you do.
6. Voice logging and AI-based features
GoshFit offers an optional voice meal-logging feature. When you use it, your voice recording is sent to OpenAI to transcribe what you said into text so we can match it to foods. Your recording and transcript are processed for that purpose only. If you would rather not use it, you can log meals by typing or with the guided photo scanner instead — voice logging is entirely optional.
7. How we handle Google sign-in
You can register and sign in using your Google account. If you do, we receive your name, email address, and profile photo from Google to set up and identify your account. We use this only as described in this policy. We do not receive your Google password. Review Google's own privacy policy to understand and control what Google shares.
8. International data transfers
Our service providers operate servers in Belgium and the United States, so your information may be transferred to and processed in countries other than your own. Where personal information is transferred out of Nigeria, or out of the EEA/UK for users those laws cover, we rely on appropriate safeguards (such as the service provider's contractual data-protection commitments) to keep your information protected. Details are available on request.
9. How long we keep your information
We keep your personal information only as long as needed to provide the Services and for the purposes in this policy, unless a longer period is required by law (for example, tax or accounting records). When we no longer need it, we delete or anonymise it, or securely isolate it if immediate deletion is not possible (such as in backups).
10. How we keep your information safe
We use reasonable technical and organisational measures to protect your information, including access controls and encryption in transit. No system is perfectly secure, so we cannot guarantee absolute security — please protect your account by keeping your login details private.
11. Children's data
GoshFit is for adults aged 18 and over. We do not knowingly collect data from anyone under 18. By using the Services you confirm you are at least 18. If we learn we have collected data from someone under 18, we will deactivate the account and delete the data. If you believe a minor has given us data, contact goshfitapp@gmail.com.
12. Your privacy rights
If you are in Nigeria (under the NDPA), you have the right to:
- Be informed about how your data is used
- Access the personal data we hold about you
- Have inaccurate data corrected
- Have your data deleted
- Restrict or object to certain processing
- Receive your data in a portable format
- Withdraw consent at any time (without affecting processing done before withdrawal)
- Lodge a complaint with the Nigeria Data Protection Commission (NDPC) if you believe your rights have been breached
To exercise any of these, email goshfitapp@gmail.com. We will respond in line with the NDPA. You also have the right to complain to the NDPC directly.
If you are in the EEA, UK, or Switzerland, you have equivalent rights under the GDPR/UK GDPR, including the right to complain to your local data protection authority (in the UK, the Information Commissioner's Office).
13. Do-Not-Track
Some browsers offer a 'Do-Not-Track' setting. There is no agreed industry standard for these signals, so we do not currently respond to them. If a standard is adopted, we will update this policy.
14. Updates to this policy
We may update this policy from time to time. We will change the 'Last updated' date above and, for material changes, give you a more prominent notice. Please review it periodically.
15. How to contact us
Questions or requests about this policy or your data:
Email: goshfitapp@gmail.com
Post: Chibuike Matthew Ikechukwu, Lagos, Nigeria
16. How to review, update, or delete your data
You can review or update most of your information in your account settings, or request access, correction, or deletion by emailing goshfitapp@gmail.com. We may retain limited information where the law requires or allows it (for example, to prevent fraud or meet legal obligations).