FitCraft later published a much fuller privacy policy.
This page keeps what was wrong before.
In August 2026 we compared the Google Play app (version 1.3.197)
with FitCraft’s February 20, 2022 privacy notice. That old notice
contradicted itself and did not describe the companies the app
talked to. FitCraft has since replaced it. We are not asking you
to uninstall or file a store report.
Two public documents that were the problem have been rewritten
or updated. That is the main news.
The live policy is no longer the 2022 template
FitCraft Studios Inc now publishes a long, plain-language policy
at
getfitcraft.com/privacypolicy.
It names approximate location from your internet address, fitness
and body answers, in-app activity, advertising identifiers,
analytics and crash tools, advertising measurement with Meta and
Google, a working email
(hello@getfitcraft.com),
a postal address, in-app account deletion, and a California table
that marks geolocation and internet activity as collected and
some identifiers as “shared.”
Play Store
Data Safety now lists sharing
On August 28, 2026, the Play Data Safety page for
com.FitCraftStudios.FitCraft no longer said “no data shared
with third parties.” It lists sharing of purchase history, app
interactions, email, user IDs, approximate location, and device
IDs, and it lists health and fitness information as collected.
It also says you can ask for deletion.
Old notice
The 2022 page is the historical record
The contradictions below refer to the February 20, 2022 notice
— blank contact fields, “no geolocation,” “no internet
activity,” “has not disclosed to third parties,” and PayPal —
not to the current getfitcraft.com policy.
02
What we found then, in plain English
This is a record of August 2026. It describes the store app
we unpacked and the 2022 notice that was still the public
policy at that time.
Then · I
Play Store said “not shared”
In August 2026, FitCraft’s Data Safety section told shoppers
the app did not share user data with other companies. That
sentence has since been replaced (see above).
Then · II
The app still talked to other companies
Version 1.3.197 included working connections to AppsFlyer
(install tracking), Amplitude (product analytics), Google
Firebase Analytics, Sentry (crash reports), and a Hippogames
login relay. Play treats data leaving the phone through those
tools as sharing.
Then · III
Login could go through a middleman
Sign-in with Google, Apple, Facebook, and similar services
could pass through hippogames.dev. The new policy describes
Google and Apple sign-in. It does not mention Hippogames. We
have not re-checked a newer app build for that relay.
Then · IV
Location came from the internet address
Play already listed approximate location. The 2022 notice body
mentioned “country, location,” while its California table said
geolocation was not collected. The Android package did not ask
for GPS. City-level location can still come from an IP
address. The new policy now says that clearly.
Then · V
The 2022 notice disagreed with itself
It said they only share with consent or in a company sale; it
also said they may run targeted ads with third parties; it
later said they had not disclosed personal information to
third parties. Those lines could not all be true as written.
03
2022 notice vs. the 2026 app review
Side-by-side of the old notice and what the unpacked app
showed. This table is historical. It is not a description of
the current policy.
February 20, 2022 notice said
August 2026 app review found
California table: geolocation data
not collected.
Play listed approximate location. The notice body admitted
“country, location.” Analytics companies see an IP address.
California table: internet or app activity
not collected.
Amplitude, Firebase Analytics, and AppsFlyer are built to
record what you do in the app.
“Has not disclosed personal information to third parties”
and “will not sell.”
The app shipped live keys and web addresses for AppsFlyer,
Amplitude, Google, Sentry, and Hippogames.
“We only share information with your consent…”
Those tools were already inside the app. We found no consent
screen that turned them off before they could run.
Sharing examples named a business sale — not everyday
analytics companies.
The 2022 notice never named AppsFlyer, Amplitude, Firebase,
Sentry, RevenueCat, Statsig, or Hippogames.
Payments stored by PayPal (privacy-policy link left blank).
The Android store app used Google Play Billing and
RevenueCat, not PayPal.
“What we collect” listed email, usernames, and passwords.
The app also handled workout and fitness information and an
advertising ID.
Blank mailing address, blank contact email in one section,
blank “click here” request link, blank retention period.
An unfinished Termly template was still the public notice
years after the 2026 store app shipped.
What the new policy covers that the old one did not
Checked against
getfitcraft.com/privacypolicy
on August 28, 2026. We are describing their words, not
re-testing a new app build.
Topic
What the new policy says
Location
Approximate country, region, and city from IP. No GPS
permission. California table: geolocation yes, approximate
only.
App activity
Workouts, screens, paywalls, and similar events. California
table: internet activity yes.
Fitness and body data
Height, weight, BMI, goals, and workout completion treated
as consumer health data, with a dedicated section.
Sharing / sale
They say they do not sell for money. They say disclosures to
Meta and Google for ad measurement can count as California
“sharing,” with a “Do Not Sell or Share” email opt-out.
Who else sees data
Role-based list: hosting, analytics, feature tests,
subscriptions, mobile attribution, crash reporting, Firebase,
email, payments. Most company names are “available on
request,” except Google Firebase, Meta, and Google Ads.
Payments
Apple and Google for store purchases; a web checkout
processor through a subscription service. Not PayPal.
How to reach them / delete
hello@getfitcraft.com; 224 W 35th St Ste 500 #928, New York,
NY 10001. Delete Account in Settings, plus a rights request
by email.
05
What this record does not re-verify
A better notice is not the same as a new app review. These
items stay open because we have not done that work again.
Open
Vendor names
The 2026 binary named AppsFlyer, Amplitude, Sentry, RevenueCat,
and Statsig. The new policy describes those roles but often
withholds the company name unless you email them.
Open
Hippogames login relay
hippogames.dev was in version 1.3.197. The new policy talks
about Google and Apple sign-in only. A later build may have
removed the relay. We have not unpacked a newer APK.
Open
What actually leaves the phone today
We still have no live traffic capture. The new policy is a
disclosure. It is not proof of every event that runs on every
launch.
If you used FitCraft under the old notice and want to manage your
data now, use FitCraft’s own controls: Settings → Delete Account,
or email hello@getfitcraft.com (including “Do Not Sell or Share”
if that is what you want). Store-report links are no longer the
point of this page.
06
Questions
Short answers. This page is a record, not a signup.
Is this a class action?
No court has certified a class. Visiting this page does not join
a lawsuit.
Did they fix the problem?
They fixed the public notice in the ways described above, and
they updated Play Data Safety to list sharing. That is a real
correction of the documents we criticized. We have not re-tested
a new app build.
Should I uninstall or report the app?
We are not asking you to. If you want to leave FitCraft or use
your privacy rights, follow FitCraft’s current policy and the
in-app delete option. Store flagging is your choice, not a call
to action from this page.
What information may have been shared before?
Depending on how you used the 2026 app: a device or advertising
ID, what you did in the app, crash reports, an account or user
ID, and — if you signed in — your email and sometimes your name.
Workout details could leave the phone for FitCraft and, in some
cases, analytics tools. The new policy now describes much of
that.
Did they track location with GPS?
Not in the Android package we reviewed, and the new policy says
the same. Approximate location from an internet address is what
both Play and the new policy describe.
Do you collect my personal information?
No. This site has no sign-up form. We do not ask for your name,
email, address, or account history.
What version did you review?
Google Play package com.FitCraftStudios.FitCraft, version
1.3.197 (version code 1003197), plus the February 20, 2022
notice. The new policy and Play Data Safety page were checked
on August 28, 2026. We did not capture live traffic.
Was data sent without encryption?
We did not find that. The connections we saw used HTTPS. The
2026 issue was who received data and how that was disclosed, not
that it traveled in the clear.