FitCraft Privacy Investigation
File FC-2026 · Reviewed Android app v1.3.197

A notice for people who used the FitCraft app

If you used FitCraft, your information may have been sent to other companies — without a clear yes.

On Google Play, FitCraft says it does not share user data with other companies. A review of the store app found it still talks to independent analytics, advertising-measurement, crash, and login companies. Their written privacy notice disagrees with itself on location and sharing.

What happened, in plain English

You should not need a law degree to understand this. Here is what the store listing, the app, and the privacy notice each say.

Count I

Play Store said “not shared”

FitCraft’s Google Play Data Safety section tells shoppers the app does not share user data with other companies or organizations. That is the sentence people see before they install.

Count II

The app still talks to other companies

The same store app includes working connections to AppsFlyer (install tracking), Amplitude (product analytics), Google Firebase Analytics, Sentry (crash reports), and a Hippogames login relay. Google Play treats data leaving your phone through these tools as sharing.

Count III

Login may go through a middleman

Sign-in with Google, Apple, Facebook, and similar services can pass through hippogames.dev — a company that is not FitCraft — instead of staying only with FitCraft’s own servers.

Count IV

Location is inferred from your connection

Play lists “approximate location” as collected. The privacy notice body also mentions location. The California table in that same notice marks geolocation as “NO.” This Android package does not ask for GPS. Companies can still see a city-level location from your IP address — the address your phone uses on the internet.

Count V

The written notice disagrees with itself

One section says they only share with your consent, or for a sale of the company. Another says they may run targeted ads with third parties. A later line says they have not disclosed personal information to third parties. Those statements cannot all be true as written.

What they wrote vs. what we found

FitCraft’s privacy notice is dated February 20, 2022. It looks like an unfinished template: blank links, a blank mailing address, and a “click here” request form that goes nowhere.

They wrote We found
California table: geolocation data not collected. Play lists approximate location. The notice body admits “country, location.” Analytics companies see your IP address.
California table: internet or app activity not collected. Amplitude, Firebase Analytics, and AppsFlyer are built to record what you do in the app.
“Has not disclosed personal information to third parties” and “will not sell.” The app ships live keys and web addresses for AppsFlyer, Amplitude, Google, Sentry, and Hippogames.
“We only share information with your consent…” Those tools are already inside the app. We found no consent screen that turns them off before they can run.
Sharing examples name a business sale — not everyday analytics companies. The notice never names AppsFlyer, Amplitude, Firebase, Sentry, RevenueCat, Statsig, or Hippogames.
Payments stored by PayPal (privacy-policy link left blank). The Android store app uses Google Play Billing and RevenueCat, not PayPal.
“What we collect” lists email, usernames, and passwords. The app also handles workout and fitness information and an advertising ID. Those are not listed there.
Notice last updated February 20, 2022. The Android app we reviewed is version 1.3.197, a 2026 store artifact.

The live page is an HTML file, not a PDF. Use your browser’s Print → Save as PDF if you want a copy you can attach to a store report. We keep an archived copy here so the February 2022 wording cannot quietly disappear.

Uninstall the app and tell the stores

You can remove FitCraft from your phone and flag the listing. Use the Privacy reason on Google Play if you see it.

Uninstall on Android

  1. Open Settings.
  2. Tap Apps (or Apps & notifications).
  3. Tap FitCraft.
  4. Tap Uninstall, then confirm.

Optional: open Settings → Privacy → Ads (wording varies) and reset or delete your advertising ID if you do not want apps to keep using that identifier.

Uninstall on iPhone

  1. On the Home Screen, touch and hold the FitCraft icon.
  2. Tap Remove App.
  3. Tap Delete App, then Delete.

Questions people ask

Short answers. No jargon unless we immediately explain it.

Is this a class action?

No court has certified a class. This site is an investigation so people can read the findings and report the app themselves. Visiting it does not join a lawsuit.

Do I need a lawyer?

We are not your lawyers. If you want legal advice about your own situation, talk to a licensed attorney in your state or country.

What information may have been shared?

Depending on how you used the app: a device or advertising ID, what you did in the app, crash reports, an account or user ID, and — if you signed in with email or a social account — your email and sometimes your name. Workout and fitness details are part of the product and can leave the phone for FitCraft’s own servers and, in some cases, analytics tools.

Did they track my location?

Play says they collect approximate location. Their privacy notice says “location” in one place and “no geolocation” in another. In the Android version we reviewed, the app does not ask for GPS. Approximate location can still come from your IP address — enough for a city or region — which Google Play counts as location.

Is my workout data involved?

Yes, as part of the app itself: workouts, goals, and similar fitness information. The 2022 privacy notice’s “what we collect” list does not mention that, even though FitCraft is a fitness game.

Do you collect my personal information?

No. This site has no sign-up form. We do not ask for your name, email, address, or account history.

What version of the app did you review?

Google Play Android package com.FitCraftStudios.FitCraft, version 1.3.197 (version code 1003197). Findings are from a static review of that store file plus the February 20, 2022 privacy notice. We did not capture live traffic, so we cannot swear every tool runs on every launch.

Was my data sent without encryption?

We did not find that. The connections we saw use HTTPS — a locked web address. The problem we are describing is who receives the data and how that was disclosed, not that it traveled in the clear.