You can accept or reject all options, or choose each purpose, in Privacy preferences. Rejecting optional purposes does not restrict access to the main content. You can change your choice at any time.
When you withdraw consent, new events are blocked, accessible analytics cookies are deleted, and the page reloads to stop external code. A previous CookieYes choice is not treated as consent for this system.
Respecting the provisions of current legislation, CLIPIN (hereinafter also referred to as the Website) commits to adopting the necessary technical and organisational measures, according to the appropriate security level based on the risk of the data collected.
This Privacy Policy applies to the website www.CLIPIN.fit and, where appropriate, to the mobile application and digital services provided by CLIPIN. For interpretative purposes, references in this text to the "Website" shall also be understood to extend to the mobile application and digital services of CLIPIN wherever applicable.
Currently, connection features with devices, connected health services, and activity or wellness data synchronization are offered only within the mobile application of CLIPIN and are not available from the web version.
This privacy policy is adapted to current Spanish and European regulations regarding the protection of personal data on the internet. Specifically, it complies with the following rules:
The data controller of the personal data collected on CLIPIN is: CLIPIN (hereinafter, Controller). Their contact details are as follows:
Contact email: hola@clipin.fit
In compliance with the provisions of the GDPR and the LOPD-GDD, we inform you that the personal data collected by CLIPIN, through the forms and features available on its pages and, where applicable, on the mobile application, will be incorporated and processed in our files in order to facilitate, expedite and fulfill the commitments established between CLIPIN and the User, maintain the legal and operational relationship arising from the use of our services, or respond to a request or query from them. Likewise, in accordance with the GDPR and LOPD-GDD, unless the exception established in Article 30.5 of the GDPR applies, a record of processing activities is maintained specifying, according to its purposes, the processing activities carried out and other circumstances established in the GDPR.
The processing of the User’s personal data shall be subject to the following principles set out in Article 5 of the GDPR and Articles 4 and following of Organic Law 3/2018, of 5 December, on the Protection of Personal Data and guarantee of digital rights:
The categories of data we process in CLIPIN may include, depending on the service used, identification and contact data, account data, subscription and billing data, usage and browsing data, as well as professional data when referring to the public directory of trainers.
In the case of the public directory of trainers, the information is limited to publicly accessible professional data (for example, name, location, and links to professional profiles or channels).
In the mobile application, if the User chooses to connect compatible services or devices, CLIPIN may process physical activity, wellbeing or health data, such as steps, active calories, heart rate, sleep, workouts, scores or daily summaries, timestamps, metadata about the connected source, and other technical data necessary to maintain the sync requested by the User.
These optional services or sources may include Garmin Connect, Apple Health and Health Connect when the User expressly enables them via the mobile application. Regarding Apple Health,CLIPIN access is only made to categories authorised by the User on the device, which may include workouts, sleep and sleep stages, heart rate, resting heart rate,, heart rate variability,, steps, active calories, basal calories, device or source tags, synchronisation timestamps and technical status necessary to maintain the connection. On Android, integration with Health Connect in this version is limited to workouts, sleep and sleep stages, heart rate, steps, active calories, total calories, device or source tags, synchronisation timestamps and technical status necessary to maintain the connection.
In the mobile app, if the User utilises nutrition features, CLIPIN it may process food logs, calorie and macronutrient goals, foods created by the User, private corrections of products, meal photographs or nutritional labels, technical metadata of those images, and nutritional analysis results generated for User review.
If the User uses artificial intelligence features, the categories processed may include messages and instructions sent by them, generated responses, their goals and preferences, and relevant account data for the request, such as biometric data, workouts, nutrition, symptoms, health metrics or test results. When the feature requires it, it may also process meal photographs or labels and PDF documents of analyses voluntarily provided by the User.
If the User enables push notifications, we may also process a random installation identifier, the push token assigned to the device, the platform, app version and channel, activation status and technical delivery data such as ticket IDs, receipts and error codes.
In the directory, we do not process special categories of personal data (Art. 9 GDPR). However, certain data synchronised from connected health devices or services may constitute special category data and will only be processed when the User has given explicit consent and solely for the purposes expressly requested within the mobile app, with the corresponding legal and technical safeguards.
Push notifications are optional. The app requests permission before enabling them and the User can disable them from within the app or via the operating system settings. Their purpose is to inform when User-requested tasks are completed, for example, when a routine is ready.
The text visible on the lock screen is generic and does not include the content of the routine, health or nutrition data, private messages or other sensitive details. Diagnostic technical logs also do not store the notification text or such sensitive content.
CLIPIN offers certain features through its mobile app, including user account management, access to subscription plans, and where applicable, connection with third-party services or devices expressly authorised by the User, such as Garmin Connect.
Where available, Apple Health and Health Connect are offered as optional sources of health data stored on the device. The User must explicitly initiate the connection, grant permissions on the operating system and may revoke them later from device settings or from the app where a disconnect option exists.
CLIPIN offers optional artificial intelligence features to generate chat responses, routines, nutritional estimates and analysis of health images or documents. To provide the requested function, it may send to external AI providers the information entered by the User and the context of their account relevant to that request.
On the first access to the main screen, before using these features, the application informs about the categories of data that may be sent and requests affirmative action from the User. Refusing or withdrawing such authorisation prevents new submissions to external AI providers but does not block the functions of CLIPIN that do not depend on artificial intelligence. The User can withdraw authorisation from their account information. If the User later requests an AI function, the application will show this information again before continuing.
Data is used to generate the requested result, maintain the history that the User chooses to keep, protect the service and resolve incidents. CLIPIN does not sell this data, does not use it for behavioural advertising and does not require its providers to use it for training general-purpose models. Generated responses or estimates may contain errors and should be reviewed by the User.
When the User has connected a health source and explicitly activated AI functions, CLIPIN may select a minimal context of relevant activity or health for the request, such as daily summaries, recent activities, sleep, recovery or weight trends. Complete histories, routes, coordinates, account or device identifiers, credentials, activity files or unlimited sensor streams are not sent.
This section applies to data authorised by the User and imported from compatible sources such as Garmin Connect, Apple Health and Health Connect. Connecting a source alone does not enable its use in AI: the User must also accept the current global AI consent.
Where useful for a fitness, nutrition or health function, CLIPIN may send to its AI providers only selected fields and limited periods. The application applies technical limits on categories, number of activities and duration of time series, and only enables sources reviewed for this processing.
External AI providers act as processors or sub-processors to generate the requested response. They cannot use this context for advertising, data sale, profiling outside the service or training general-purpose models. CLIPIN does not use this data to make autonomous medical decisions.
Withdrawing AI consent stops new submissions of this context without disconnecting the source or blocking non-AI screens. Disconnecting a source stops new synchronisations; previously imported history is kept or deleted according to the periods and rights described in this Policy.
CLIPIN offers a public directory of fitness professionals to support the ecosystem and give free visibility to trainers. We do not request payment for appearing in the directory: our goal is to make it easier for users to find the right professional.
If you detect inaccurate data or wish to exercise your rights, contact us and we will manage correction or removal as soon as possible.
The legal basis for processing personal data may vary depending on the purpose and context (for example, consent, compliance with legal obligations or legitimate interest).
In particular, the public directory of trainers is based on the legitimate interest (art. 6.1.f GDPR) to promote free professional visibility and facilitate contact with potential clients. In any case, any data subject can object to this processing and request data removal.
In the mobile application, processing data necessary to create and manage the account, provide contracted functionalities, administer the subscription and support the relationship with the User is generally based on execution of the contractual or pre-contractual relationship (art. 6.1.b GDPR), as well as, when applicable, compliance with legal obligations and the legitimate interest of the Controller to ensure security, prevent abuse and improve service operations.
When the User decides to use photo analysis of meals or nutrition labels, the legal basis will be the service requested by the User within the application and, where required due to the nature of the data processed, the User's consent. These functions are voluntary and always have alternatives such as barcode scanning, food search or manual creation.
Processing of strictly necessary ordinary personal data to provide requested artificial intelligence functions is based on execution of the contractual relationship (art. 6.1.b GDPR). When such functions process health data or other special categories, CLIPIN explicit consent from the data subject is also requested (Art. 9.2.a GDPR). The application requires prior affirmative action, retains evidence of the version and date accepted and, if applicable, the date of withdrawal. Consent can be withdrawn from the account information without affecting the lawfulness of prior processing.
When the User chooses to connect a compatible service or device and authorises access to health, activity, or wellness data, the legal basis will be the explicit consent of the data subject (Art. 6.1.a and Art. 9.2.a GDPR). Withdrawal of such consent may be carried out by disconnecting the integration, using the settings available in the application, or by a request to the Data Controller, without affecting the lawfulness of prior processing.
The User has the right to withdraw their consent at any time. It will be as easy to withdraw consent as it was to give it. As a general rule, withdrawal of consent will not affect the use of the Website.
On occasions when the User must or may provide their data through forms to make enquiries, request information or for reasons related to the Website content, they will be informed if completion of any of these is mandatory because they are essential for the proper carrying out of the operation.
Personal data are collected and managed by CLIPIN in order to facilitate, speed up and fulfil the commitments established between the Website and the User or to maintain the relationship established through the forms completed by the User or to attend to a request or enquiry.
Likewise, data may be used for commercial purposes such as personalisation, operational and statistical activities, and activities inherent to the corporate purpose of CLIPIN, as well as for data extraction, storage and marketing studies to tailor the Content offered to the User, and to improve the quality, functioning and navigation of the Website.
In particular, within the mobile application, data may be processed to authenticate the User, manage their profile and subscription, enable payment functions, allow connection to compatible services or devices, synchronise and import authorised data, display metrics, summaries, sleep or training history, and maintain proper operation, security, traceability and support of these integrations.
Nutrition functions may process data to log foods, calculate calories and macronutrients, save nutritional goals, retain foods created or edited by the User, analyse meal photos or nutritional labels, show estimated results for review, and allow the User to confirm, edit or delete such records.
Artificial intelligence functions may process the data described in this Policy to generate chat, routines, analysis, extraction or estimation expressly requested by the User and present the results within the application.
When the User has enabled push notifications, the associated technical data may be processed to send requested alerts, verify their delivery, resolve errors and prevent duplicate or invalid sends.
At the time personal data are obtained, the User will be informed of the specific purpose(s) for which the personal data will be used; that is, how the information collected will be used.
Personal data will only be retained for the minimum time necessary for the purposes of processing and, in any case, only while the User maintains a registered account with us or until they request its deletion, where applicable. We may need to keep transaction records for up to 4 years to comply with tax obligations.
For connections to compatible services or devices, the technical data necessary to maintain the active integration will be kept while such connection is in force and there is a legal basis for doing so. If the User revokes the connection, requests deletion, deletes their account or no longer meets the access conditions for a subscription-associated functionality, CLIPIN may cease synchronising new data and disable the relevant connection.
Previously imported information linked to the account may be retained as part of the User's history while the account remains active and where necessary to provide the service, unless deletion is requested by the data subject or required by law.
Photos of meals or nutritional labels will be retained while necessary to provide the requested feature, maintain a record saved by the User, or comply with technical retention criteria of the service. Failed, cancelled or abandoned captures may be automatically deleted when no longer necessary, and images linked to saved records will be deleted when the record or account is removed, except where legal retention applies.
Technical events and diagnostics for push notification delivery are retained for up to 30 days. Token records are kept while necessary to provide the function and are disabled when the User disables notifications, logs out, or the provider informs that the token is no longer valid. The associated data are also subject to account deletion and the exercise of User rights.
At the time personal data are obtained, the User will be informed about the period during which the personal data will be retained or, if that is not possible, the criteria used to determine this period.
The User’s personal data will be shared with the following recipients or categories of recipients:
CLIPIN S.L. and, where necessary to provide the service, technology providers acting as data processors in areas such as hosting, infrastructure, authentication, payment processing, transactional communications and secure storage.
When the User authorises connection with external services or compatible devices, the respective third-party provider may process certain data within the scope of its own service and according to its own privacy policies, acting as an independent controller regarding processing carried out on its platform. This includes, for example, sports or wellness integration providers such as Garmin when the User has authorised such connection.
For artificial intelligence functions, CLIPIN may use providers like OpenAI, Groq and Mistral AI, as processors or sub-processors as appropriate. These providers receive only the information necessary to generate the chat, routine, document analysis or nutritional estimate requested by the User. The specific provider depends on the function and the model available at the time.
To deliver push notifications, CLIPIN uses the Expo Push Service, which routes notifications through Apple Push Notification Service (APNs) on iOS or Google's Firebase Cloud Messaging (FCM) on Android. These providers receive the token, the generic notification payload, and strictly necessary technical data to process delivery, in accordance with their respective terms and privacy policies.
For data from connected health sources, the limits and controls in the section also apply. Connected health data and artificial intelligence.
Some technology providers may process data outside the European Economic Area. When an international transfer occurs, CLIPIN will apply the safeguards required by regulations, such as adequacy decisions, standard contractual clauses, or other legally recognised mechanisms, and will limit processing to the provision of the contracted service.
In compliance with Articles 8 of the GDPR and 7 of Organic Law 3/2018, of 5 December, on the Protection of Personal Data and Guarantee of Digital Rights, only individuals over 14 years old may lawfully give consent for the processing of their personal data by CLIPIN. If the individual is under 14 years old, parental or guardian consent is required for processing, which will only be lawful to the extent that such consent has been given.
CLIPIN commits to adopting the necessary technical and organisational measures, proportionate to the risk level of collected data, in order to guarantee the security of personal data and prevent accidental or unlawful destruction, loss or alteration of personal data transmitted, stored or otherwise processed, as well as unauthorised disclosure or access to such data.
The Website possesses an SSL (Secure Socket Layer) certificate, ensuring that personal data is transmitted securely and confidentially, with all data exchanges between the server and the User being fully encrypted.
However, since CLIPIN cannot guarantee the absolute invulnerability of the internet nor the complete absence of hackers or others who may fraudulently access personal data, the Data Controller commits to promptly inform the User without undue delay if a personal data security breach occurs that is likely to pose a high risk to the rights and freedoms of individuals. Following Article 4 of the GDPR, a personal data breach is understood as any breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access to personal data transmitted, stored or otherwise processed.
Personal data shall be treated confidentially by the Data Controller, who commits to ensuring compliance through legal or contractual obligations by its employees, associates, and any persons to whom such information is made accessible.
The User has rights over CLIPIN and may therefore exercise before the Data Controller the following rights established in the GDPR and Organic Law 3/2018, of 5 December, on the Protection of Personal Data and Guarantee of Digital Rights:
Name, surname of the User and a copy of their ID. Where representation is permitted, identification of the representative by the same means and evidence of representation are also necessary. The photocopy of the ID may be replaced by any other legally valid identification means.
Postal address: CLIPIN FIT S.L., Av. José Manuel Caballero Bonald, 4, 11405 Jerez de la Frontera, Cádiz, Spain
Email: hola@clipin.fit
Links to third-party websites.
The Website may include hyperlinks or links that provide access to third-party websites other than CLIPIN, and which therefore are not operated by CLIPIN. The owners of these websites will have their own data protection policies and will be responsible themselves, in each case, for their own files and privacy practices.
If the User considers there to be an issue or infringement of current regulations regarding the way their personal data is being handled, they shall have the right to effective judicial protection and to lodge a complaint with a supervisory authority, particularly in the State where they habitually reside, work, or where the alleged infringement took place. In Spain, the supervisory authority is the Spanish Data Protection Agency (http://www.agpd.es).
It is necessary for the User to have read and agreed to the personal data protection conditions contained in this Privacy Policy, as well as to accept the processing of their personal data so that the Data Controller can proceed with it in the manner, within the timeframes, and for the purposes indicated. Use of the Website implies acceptance of its Privacy Policy.
CLIPIN reserves the right to modify its Privacy Policy at its own discretion, or due to legislative, judicial, or doctrinal changes from the Spanish Data Protection Agency. Changes or updates to this Privacy Policy will not be explicitly notified to the User. Users are advised to consult this page periodically to stay informed of the latest changes or updates.
This Privacy Policy was updated to conform with Regulation (EU) 2016/679 of the European Parliament and Council, dated 27 April 2016, on the protection of natural persons concerning the processing of personal data and the free movement of such data (GDPR), and Organic Law 3/2018, of 5 December, on the Protection of Personal Data and guarantee of digital rights, as well as the digital services currently provided by CLIPIN, including, where applicable, the use of its mobile application.
Last update: 9 August 2026.