FitCraft Privacy Investigation
File FC-2026 · Android app v1.3.197 reviewed August 2026

A dated record — not a live campaign

FitCraft later published a much fuller privacy policy. This page keeps what was wrong before.

In August 2026 we compared the Google Play app (version 1.3.197) with FitCraft’s February 20, 2022 privacy notice. That old notice contradicted itself and did not describe the companies the app talked to. FitCraft has since replaced it. We are not asking you to uninstall or file a store report.

What changed after the review

Two public documents that were the problem have been rewritten or updated. That is the main news.

The live policy is no longer the 2022 template

FitCraft Studios Inc now publishes a long, plain-language policy at getfitcraft.com/privacypolicy. It names approximate location from your internet address, fitness and body answers, in-app activity, advertising identifiers, analytics and crash tools, advertising measurement with Meta and Google, a working email (hello@getfitcraft.com), a postal address, in-app account deletion, and a California table that marks geolocation and internet activity as collected and some identifiers as “shared.”

Play Store

Data Safety now lists sharing

On August 28, 2026, the Play Data Safety page for com.FitCraftStudios.FitCraft no longer said “no data shared with third parties.” It lists sharing of purchase history, app interactions, email, user IDs, approximate location, and device IDs, and it lists health and fitness information as collected. It also says you can ask for deletion.

Old notice

The 2022 page is the historical record

The contradictions below refer to the February 20, 2022 notice — blank contact fields, “no geolocation,” “no internet activity,” “has not disclosed to third parties,” and PayPal — not to the current getfitcraft.com policy.

What we found then, in plain English

This is a record of August 2026. It describes the store app we unpacked and the 2022 notice that was still the public policy at that time.

Then · I

Play Store said “not shared”

In August 2026, FitCraft’s Data Safety section told shoppers the app did not share user data with other companies. That sentence has since been replaced (see above).

Then · II

The app still talked to other companies

Version 1.3.197 included working connections to AppsFlyer (install tracking), Amplitude (product analytics), Google Firebase Analytics, Sentry (crash reports), and a Hippogames login relay. Play treats data leaving the phone through those tools as sharing.

Then · III

Login could go through a middleman

Sign-in with Google, Apple, Facebook, and similar services could pass through hippogames.dev. The new policy describes Google and Apple sign-in. It does not mention Hippogames. We have not re-checked a newer app build for that relay.

Then · IV

Location came from the internet address

Play already listed approximate location. The 2022 notice body mentioned “country, location,” while its California table said geolocation was not collected. The Android package did not ask for GPS. City-level location can still come from an IP address. The new policy now says that clearly.

Then · V

The 2022 notice disagreed with itself

It said they only share with consent or in a company sale; it also said they may run targeted ads with third parties; it later said they had not disclosed personal information to third parties. Those lines could not all be true as written.

2022 notice vs. the 2026 app review

Side-by-side of the old notice and what the unpacked app showed. This table is historical. It is not a description of the current policy.

February 20, 2022 notice said August 2026 app review found
California table: geolocation data not collected. Play listed approximate location. The notice body admitted “country, location.” Analytics companies see an IP address.
California table: internet or app activity not collected. Amplitude, Firebase Analytics, and AppsFlyer are built to record what you do in the app.
“Has not disclosed personal information to third parties” and “will not sell.” The app shipped live keys and web addresses for AppsFlyer, Amplitude, Google, Sentry, and Hippogames.
“We only share information with your consent…” Those tools were already inside the app. We found no consent screen that turned them off before they could run.
Sharing examples named a business sale — not everyday analytics companies. The 2022 notice never named AppsFlyer, Amplitude, Firebase, Sentry, RevenueCat, Statsig, or Hippogames.
Payments stored by PayPal (privacy-policy link left blank). The Android store app used Google Play Billing and RevenueCat, not PayPal.
“What we collect” listed email, usernames, and passwords. The app also handled workout and fitness information and an advertising ID.
Blank mailing address, blank contact email in one section, blank “click here” request link, blank retention period. An unfinished Termly template was still the public notice years after the 2026 store app shipped.

What the new policy covers that the old one did not

Checked against getfitcraft.com/privacypolicy on August 28, 2026. We are describing their words, not re-testing a new app build.

Topic What the new policy says
Location Approximate country, region, and city from IP. No GPS permission. California table: geolocation yes, approximate only.
App activity Workouts, screens, paywalls, and similar events. California table: internet activity yes.
Fitness and body data Height, weight, BMI, goals, and workout completion treated as consumer health data, with a dedicated section.
Sharing / sale They say they do not sell for money. They say disclosures to Meta and Google for ad measurement can count as California “sharing,” with a “Do Not Sell or Share” email opt-out.
Who else sees data Role-based list: hosting, analytics, feature tests, subscriptions, mobile attribution, crash reporting, Firebase, email, payments. Most company names are “available on request,” except Google Firebase, Meta, and Google Ads.
Payments Apple and Google for store purchases; a web checkout processor through a subscription service. Not PayPal.
How to reach them / delete hello@getfitcraft.com; 224 W 35th St Ste 500 #928, New York, NY 10001. Delete Account in Settings, plus a rights request by email.

What this record does not re-verify

A better notice is not the same as a new app review. These items stay open because we have not done that work again.

Open

Vendor names

The 2026 binary named AppsFlyer, Amplitude, Sentry, RevenueCat, and Statsig. The new policy describes those roles but often withholds the company name unless you email them.

Open

Hippogames login relay

hippogames.dev was in version 1.3.197. The new policy talks about Google and Apple sign-in only. A later build may have removed the relay. We have not unpacked a newer APK.

Open

What actually leaves the phone today

We still have no live traffic capture. The new policy is a disclosure. It is not proof of every event that runs on every launch.

If you used FitCraft under the old notice and want to manage your data now, use FitCraft’s own controls: Settings → Delete Account, or email hello@getfitcraft.com (including “Do Not Sell or Share” if that is what you want). Store-report links are no longer the point of this page.

Questions

Short answers. This page is a record, not a signup.

Is this a class action?

No court has certified a class. Visiting this page does not join a lawsuit.

Did they fix the problem?

They fixed the public notice in the ways described above, and they updated Play Data Safety to list sharing. That is a real correction of the documents we criticized. We have not re-tested a new app build.

Should I uninstall or report the app?

We are not asking you to. If you want to leave FitCraft or use your privacy rights, follow FitCraft’s current policy and the in-app delete option. Store flagging is your choice, not a call to action from this page.

What information may have been shared before?

Depending on how you used the 2026 app: a device or advertising ID, what you did in the app, crash reports, an account or user ID, and — if you signed in — your email and sometimes your name. Workout details could leave the phone for FitCraft and, in some cases, analytics tools. The new policy now describes much of that.

Did they track location with GPS?

Not in the Android package we reviewed, and the new policy says the same. Approximate location from an internet address is what both Play and the new policy describe.

Do you collect my personal information?

No. This site has no sign-up form. We do not ask for your name, email, address, or account history.

What version did you review?

Google Play package com.FitCraftStudios.FitCraft, version 1.3.197 (version code 1003197), plus the February 20, 2022 notice. The new policy and Play Data Safety page were checked on August 28, 2026. We did not capture live traffic.

Was data sent without encryption?

We did not find that. The connections we saw used HTTPS. The 2026 issue was who received data and how that was disclosed, not that it traveled in the clear.