CLIPIN Privacy Policy

website, mobile app and digital services

Privacy preferences on this website

You can accept or reject all options, or choose each purpose, in Privacy preferences. Rejecting optional purposes does not restrict access to the main content. You can change your choice at any time.

  • Necessary: clipin_consent stores your choice for 180 days. clipin_locale remembers the language you choose for 180 days. Both apply to the Spanish and English versions.
  • Optional analytics: Google Analytics loads only after you accept this purpose. It may create _ga and _ga_* to measure visits. We do not send calculator values, filter parameters or private invitation links. Advertising and ad personalisation remain disabled. Google
  • Optional external content: Spotify plays music and Mapbox displays the map. They load only after you accept this purpose. These providers receive connection data, including your IP address. Their policies describe how they process it. Spotify · Mapbox
  • Calculators: when changing language, values are stored temporarily in sessionStorage for up to 15 minutes and removed when restored. They are not sent to the server or analytics services. The visual theme is stored in localStorage.

When you withdraw consent, new events are blocked, accessible analytics cookies are deleted, and the page reloads to stop external code. A previous CookieYes choice is not treated as consent for this system.

I. PRIVACY AND DATA PROTECTION POLICY

Respecting the provisions of current legislation, CLIPIN (hereinafter also referred to as the Website) commits to adopting the necessary technical and organisational measures, according to the appropriate security level based on the risk of the data collected.

This Privacy Policy applies to the website www.CLIPIN.fit and, where appropriate, to the mobile application and digital services provided by CLIPIN. For interpretative purposes, references in this text to the "Website" shall also be understood to extend to the mobile application and digital services of CLIPIN wherever applicable.

Currently, connection features with devices, connected health services, and activity or wellness data synchronization are offered only within the mobile application of CLIPIN and are not available from the web version.

Laws incorporated into this privacy policy

This privacy policy is adapted to current Spanish and European regulations regarding the protection of personal data on the internet. Specifically, it complies with the following rules:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, regarding the protection of natural persons with regard to the processing of personal data and the free movement of such data (GDPR).
  • Organic Law 3/2018, of 5 December, on the Protection of Personal Data and guarantee of digital rights (LOPD-GDD).
  • Royal Decree 1720/2007, of 21 December, which approves the Regulation for the development of Organic Law 15/1999, of 13 December, on the Protection of Personal Data (RDLOPD).
  • Law 34/2002, of 11 July, on Information Society Services and Electronic Commerce (LSSI-CE).

Identity of the data controller

The data controller of the personal data collected on CLIPIN is: CLIPIN (hereinafter, Controller). Their contact details are as follows:

Contact email: hola@clipin.fit

Personal Data Register

In compliance with the provisions of the GDPR and the LOPD-GDD, we inform you that the personal data collected by CLIPIN, through the forms and features available on its pages and, where applicable, on the mobile application, will be incorporated and processed in our files in order to facilitate, expedite and fulfill the commitments established between CLIPIN and the User, maintain the legal and operational relationship arising from the use of our services, or respond to a request or query from them. Likewise, in accordance with the GDPR and LOPD-GDD, unless the exception established in Article 30.5 of the GDPR applies, a record of processing activities is maintained specifying, according to its purposes, the processing activities carried out and other circumstances established in the GDPR.

Principles applicable to the processing of personal data

The processing of the User’s personal data shall be subject to the following principles set out in Article 5 of the GDPR and Articles 4 and following of Organic Law 3/2018, of 5 December, on the Protection of Personal Data and guarantee of digital rights:

  • Principle of lawfulness, fairness and transparency: the User’s consent will be required at all times following full and transparent information about the purposes for which the personal data are collected.
  • Principle of purpose limitation: personal data will be collected for specified, explicit, and legitimate purposes.
  • Principle of data minimisation: only the strictly necessary personal data regarding the purposes for which they are processed will be collected.
  • Principle of accuracy: personal data must be accurate and kept up to date.
  • Principle of storage limitation: personal data will only be retained in a way that permits the identification of the User for as long as necessary for the purposes of processing.
  • Principle of integrity and confidentiality: personal data will be processed in a manner that ensures their security and confidentiality.
  • Principle of accountability: the Controller is responsible for ensuring that the above principles are complied with.

Categories of personal data

The categories of data we process in CLIPIN may include, depending on the service used, identification and contact data, account data, subscription and billing data, usage and browsing data, as well as professional data when referring to the public directory of trainers.

In the case of the public directory of trainers, the information is limited to publicly accessible professional data (for example, name, location, and links to professional profiles or channels).

In the mobile application, if the User chooses to connect compatible services or devices, CLIPIN may process physical activity, wellbeing or health data, such as steps, active calories, heart rate, sleep, workouts, scores or daily summaries, timestamps, metadata about the connected source, and other technical data necessary to maintain the sync requested by the User.

These optional services or sources may include Garmin Connect, Apple Health and Health Connect when the User expressly enables them via the mobile application. Regarding Apple Health,CLIPIN access is only made to categories authorised by the User on the device, which may include workouts, sleep and sleep stages, heart rate, resting heart rate,, heart rate variability,, steps, active calories, basal calories, device or source tags, synchronisation timestamps and technical status necessary to maintain the connection. On Android, integration with Health Connect in this version is limited to workouts, sleep and sleep stages, heart rate, steps, active calories, total calories, device or source tags, synchronisation timestamps and technical status necessary to maintain the connection.

In the mobile app, if the User utilises nutrition features, CLIPIN it may process food logs, calorie and macronutrient goals, foods created by the User, private corrections of products, meal photographs or nutritional labels, technical metadata of those images, and nutritional analysis results generated for User review.

If the User uses artificial intelligence features, the categories processed may include messages and instructions sent by them, generated responses, their goals and preferences, and relevant account data for the request, such as biometric data, workouts, nutrition, symptoms, health metrics or test results. When the feature requires it, it may also process meal photographs or labels and PDF documents of analyses voluntarily provided by the User.

If the User enables push notifications, we may also process a random installation identifier, the push token assigned to the device, the platform, app version and channel, activation status and technical delivery data such as ticket IDs, receipts and error codes.

In the directory, we do not process special categories of personal data (Art. 9 GDPR). However, certain data synchronised from connected health devices or services may constitute special category data and will only be processed when the User has given explicit consent and solely for the purposes expressly requested within the mobile app, with the corresponding legal and technical safeguards.

Push notifications

Push notifications are optional. The app requests permission before enabling them and the User can disable them from within the app or via the operating system settings. Their purpose is to inform when User-requested tasks are completed, for example, when a routine is ready.

The text visible on the lock screen is generic and does not include the content of the routine, health or nutrition data, private messages or other sensitive details. Diagnostic technical logs also do not store the notification text or such sensitive content.

Mobile application, subscriptions and device connections

CLIPIN offers certain features through its mobile app, including user account management, access to subscription plans, and where applicable, connection with third-party services or devices expressly authorised by the User, such as Garmin Connect.

Where available, Apple Health and Health Connect are offered as optional sources of health data stored on the device. The User must explicitly initiate the connection, grant permissions on the operating system and may revoke them later from device settings or from the app where a disconnect option exists.

  • Purpose: to enable the mobile service experience, activate subscription-related features, connect compatible services, import User-authorised data and display them within the app as metrics, summaries, history or visualisations.
  • Nutrition and images: when the User logs foods or uses photo analysis features, CLIPIN may store the selected or captured image, its technical metadata and the structured result of the analysis to display it to the User, allow review, save the nutritional log and maintain the history linked to their account.
  • Source of data: data provided by the User, data generated through the use of the mobile app and, where appropriate, data sent by the external provider or device that the User has chosen to connect. Apple Health, Health Connect, Garmin, Samsung Health and other source apps or devices are independent services and are also governed by their own privacy policies.
  • User control: connection with external services or compatible devices is voluntary. The User may revoke consent, disconnect the integration or request deletion of their data at any time, in accordance with applicable law.
  • Subscription status: when a feature depends on an active paid plan, CLIPIN may cease synchronising new data and deactivate the connection if the User no longer meets access conditions for that feature, without prejudice to retaining the history already imported under the terms of this Policy.
  • Usage restrictions: health, activity or wellbeing data imported from Apple Health, Health Connect, Garmin or other connected services are not sold, not transferred to data brokers, not used for behavioural advertising or unrelated marketing, and not used to train, tune or evaluate external artificial intelligence models.

Artificial intelligence features

CLIPIN offers optional artificial intelligence features to generate chat responses, routines, nutritional estimates and analysis of health images or documents. To provide the requested function, it may send to external AI providers the information entered by the User and the context of their account relevant to that request.

On the first access to the main screen, before using these features, the application informs about the categories of data that may be sent and requests affirmative action from the User. Refusing or withdrawing such authorisation prevents new submissions to external AI providers but does not block the functions of CLIPIN that do not depend on artificial intelligence. The User can withdraw authorisation from their account information. If the User later requests an AI function, the application will show this information again before continuing.

Data is used to generate the requested result, maintain the history that the User chooses to keep, protect the service and resolve incidents. CLIPIN does not sell this data, does not use it for behavioural advertising and does not require its providers to use it for training general-purpose models. Generated responses or estimates may contain errors and should be reviewed by the User.

When the User has connected a health source and explicitly activated AI functions, CLIPIN may select a minimal context of relevant activity or health for the request, such as daily summaries, recent activities, sleep, recovery or weight trends. Complete histories, routes, coordinates, account or device identifiers, credentials, activity files or unlimited sensor streams are not sent.

Connected health data and artificial intelligence

This section applies to data authorised by the User and imported from compatible sources such as Garmin Connect, Apple Health and Health Connect. Connecting a source alone does not enable its use in AI: the User must also accept the current global AI consent.

Where useful for a fitness, nutrition or health function, CLIPIN may send to its AI providers only selected fields and limited periods. The application applies technical limits on categories, number of activities and duration of time series, and only enables sources reviewed for this processing.

External AI providers act as processors or sub-processors to generate the requested response. They cannot use this context for advertising, data sale, profiling outside the service or training general-purpose models. CLIPIN does not use this data to make autonomous medical decisions.

Withdrawing AI consent stops new submissions of this context without disconnecting the source or blocking non-AI screens. Disconnecting a source stops new synchronisations; previously imported history is kept or deleted according to the periods and rights described in this Policy.

Public directory of trainers

CLIPIN offers a public directory of fitness professionals to support the ecosystem and give free visibility to trainers. We do not request payment for appearing in the directory: our goal is to make it easier for users to find the right professional.

  • Purpose: to create a professional directory to facilitate contact between users and trainers.
  • Source of data: information published by the professionals themselves in publicly accessible sources or social/professional networks (for example, LinkedIn or Instagram).
  • Included data: name, location, language and professional contact links/data (when publicly available). We do not include private information not published by the professional.
  • Legal basis: legitimate interest of the Controller (art. 6.1.f GDPR) to provide a useful tool for users and give free professional visibility to trainers.
  • Right to object / removal (opt-out): if you are the person included and prefer not to appear, you can request immediate removal by writing to hola@clipin.fit.

If you detect inaccurate data or wish to exercise your rights, contact us and we will manage correction or removal as soon as possible.

Legal basis for processing personal data

The legal basis for processing personal data may vary depending on the purpose and context (for example, consent, compliance with legal obligations or legitimate interest).

In particular, the public directory of trainers is based on the legitimate interest (art. 6.1.f GDPR) to promote free professional visibility and facilitate contact with potential clients. In any case, any data subject can object to this processing and request data removal.

In the mobile application, processing data necessary to create and manage the account, provide contracted functionalities, administer the subscription and support the relationship with the User is generally based on execution of the contractual or pre-contractual relationship (art. 6.1.b GDPR), as well as, when applicable, compliance with legal obligations and the legitimate interest of the Controller to ensure security, prevent abuse and improve service operations.

When the User decides to use photo analysis of meals or nutrition labels, the legal basis will be the service requested by the User within the application and, where required due to the nature of the data processed, the User's consent. These functions are voluntary and always have alternatives such as barcode scanning, food search or manual creation.

Processing of strictly necessary ordinary personal data to provide requested artificial intelligence functions is based on execution of the contractual relationship (art. 6.1.b GDPR). When such functions process health data or other special categories, CLIPIN explicit consent from the data subject is also requested (Art. 9.2.a GDPR). The application requires prior affirmative action, retains evidence of the version and date accepted and, if applicable, the date of withdrawal. Consent can be withdrawn from the account information without affecting the lawfulness of prior processing.

When the User chooses to connect a compatible service or device and authorises access to health, activity, or wellness data, the legal basis will be the explicit consent of the data subject (Art. 6.1.a and Art. 9.2.a GDPR). Withdrawal of such consent may be carried out by disconnecting the integration, using the settings available in the application, or by a request to the Data Controller, without affecting the lawfulness of prior processing.

The User has the right to withdraw their consent at any time. It will be as easy to withdraw consent as it was to give it. As a general rule, withdrawal of consent will not affect the use of the Website.

On occasions when the User must or may provide their data through forms to make enquiries, request information or for reasons related to the Website content, they will be informed if completion of any of these is mandatory because they are essential for the proper carrying out of the operation.

Purposes of processing personal data

Personal data are collected and managed by CLIPIN in order to facilitate, speed up and fulfil the commitments established between the Website and the User or to maintain the relationship established through the forms completed by the User or to attend to a request or enquiry.

Likewise, data may be used for commercial purposes such as personalisation, operational and statistical activities, and activities inherent to the corporate purpose of CLIPIN, as well as for data extraction, storage and marketing studies to tailor the Content offered to the User, and to improve the quality, functioning and navigation of the Website.

In particular, within the mobile application, data may be processed to authenticate the User, manage their profile and subscription, enable payment functions, allow connection to compatible services or devices, synchronise and import authorised data, display metrics, summaries, sleep or training history, and maintain proper operation, security, traceability and support of these integrations.

Nutrition functions may process data to log foods, calculate calories and macronutrients, save nutritional goals, retain foods created or edited by the User, analyse meal photos or nutritional labels, show estimated results for review, and allow the User to confirm, edit or delete such records.

Artificial intelligence functions may process the data described in this Policy to generate chat, routines, analysis, extraction or estimation expressly requested by the User and present the results within the application.

When the User has enabled push notifications, the associated technical data may be processed to send requested alerts, verify their delivery, resolve errors and prevent duplicate or invalid sends.

At the time personal data are obtained, the User will be informed of the specific purpose(s) for which the personal data will be used; that is, how the information collected will be used.

Retention periods for personal data

Personal data will only be retained for the minimum time necessary for the purposes of processing and, in any case, only while the User maintains a registered account with us or until they request its deletion, where applicable. We may need to keep transaction records for up to 4 years to comply with tax obligations.

For connections to compatible services or devices, the technical data necessary to maintain the active integration will be kept while such connection is in force and there is a legal basis for doing so. If the User revokes the connection, requests deletion, deletes their account or no longer meets the access conditions for a subscription-associated functionality, CLIPIN may cease synchronising new data and disable the relevant connection.

Previously imported information linked to the account may be retained as part of the User's history while the account remains active and where necessary to provide the service, unless deletion is requested by the data subject or required by law.

Photos of meals or nutritional labels will be retained while necessary to provide the requested feature, maintain a record saved by the User, or comply with technical retention criteria of the service. Failed, cancelled or abandoned captures may be automatically deleted when no longer necessary, and images linked to saved records will be deleted when the record or account is removed, except where legal retention applies.

Technical events and diagnostics for push notification delivery are retained for up to 30 days. Token records are kept while necessary to provide the function and are disabled when the User disables notifications, logs out, or the provider informs that the token is no longer valid. The associated data are also subject to account deletion and the exercise of User rights.

At the time personal data are obtained, the User will be informed about the period during which the personal data will be retained or, if that is not possible, the criteria used to determine this period.

Recipients of personal data

The User’s personal data will be shared with the following recipients or categories of recipients:

CLIPIN S.L. and, where necessary to provide the service, technology providers acting as data processors in areas such as hosting, infrastructure, authentication, payment processing, transactional communications and secure storage.

When the User authorises connection with external services or compatible devices, the respective third-party provider may process certain data within the scope of its own service and according to its own privacy policies, acting as an independent controller regarding processing carried out on its platform. This includes, for example, sports or wellness integration providers such as Garmin when the User has authorised such connection.

For artificial intelligence functions, CLIPIN may use providers like OpenAI, Groq and Mistral AI, as processors or sub-processors as appropriate. These providers receive only the information necessary to generate the chat, routine, document analysis or nutritional estimate requested by the User. The specific provider depends on the function and the model available at the time.

To deliver push notifications, CLIPIN uses the Expo Push Service, which routes notifications through Apple Push Notification Service (APNs) on iOS or Google's Firebase Cloud Messaging (FCM) on Android. These providers receive the token, the generic notification payload, and strictly necessary technical data to process delivery, in accordance with their respective terms and privacy policies.

For data from connected health sources, the limits and controls in the section also apply. Connected health data and artificial intelligence.

Some technology providers may process data outside the European Economic Area. When an international transfer occurs, CLIPIN will apply the safeguards required by regulations, such as adequacy decisions, standard contractual clauses, or other legally recognised mechanisms, and will limit processing to the provision of the contracted service.

Personal data of minors

In compliance with Articles 8 of the GDPR and 7 of Organic Law 3/2018, of 5 December, on the Protection of Personal Data and Guarantee of Digital Rights, only individuals over 14 years old may lawfully give consent for the processing of their personal data by CLIPIN. If the individual is under 14 years old, parental or guardian consent is required for processing, which will only be lawful to the extent that such consent has been given.

Confidentiality and security of personal data

CLIPIN commits to adopting the necessary technical and organisational measures, proportionate to the risk level of collected data, in order to guarantee the security of personal data and prevent accidental or unlawful destruction, loss or alteration of personal data transmitted, stored or otherwise processed, as well as unauthorised disclosure or access to such data.

The Website possesses an SSL (Secure Socket Layer) certificate, ensuring that personal data is transmitted securely and confidentially, with all data exchanges between the server and the User being fully encrypted.

However, since CLIPIN cannot guarantee the absolute invulnerability of the internet nor the complete absence of hackers or others who may fraudulently access personal data, the Data Controller commits to promptly inform the User without undue delay if a personal data security breach occurs that is likely to pose a high risk to the rights and freedoms of individuals. Following Article 4 of the GDPR, a personal data breach is understood as any breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access to personal data transmitted, stored or otherwise processed.

Personal data shall be treated confidentially by the Data Controller, who commits to ensuring compliance through legal or contractual obligations by its employees, associates, and any persons to whom such information is made accessible.

Rights arising from the processing of personal data

The User has rights over CLIPIN and may therefore exercise before the Data Controller the following rights established in the GDPR and Organic Law 3/2018, of 5 December, on the Protection of Personal Data and Guarantee of Digital Rights:

  • Right of access: the right of the User to obtain confirmation as to whether CLIPIN is processing their personal data and, if so, to access specific information about those personal data and the processing carried out, including, among others, information about the origin of such data and the recipients of communications made or planned. CLIPIN Right of rectification: the right of the User to have inaccurate personal data corrected or completed, taking into account the purposes of the processing.
  • Right of erasure ('right to be forgotten'): the right of the User, unless otherwise established by law, to obtain the deletion of their personal data when such data is no longer necessary for the purposes for which it was collected or processed; the User has withdrawn consent and there is no other legal basis; the User objects to processing and there is no overriding legitimate interest; the personal data has been unlawfully processed; to comply with a legal obligation; or the personal data was obtained from an offer of information society services directly to a child under 14 years old. In addition to deleting the data, the Data Controller shall, considering available technology and implementation costs, take reasonable measures to inform other controllers processing the personal data about the deletion request, including any links to such data.
  • Right to restriction of processing: the right of the User to restrict the processing of personal data under certain conditions, such as contesting accuracy; unlawful processing; where the Data Controller no longer needs the data but the User requires it for claims; or when the User has objected to the processing.
  • Right to data portability: when processing is carried out by automated means, the User has the right to receive their personal data in a structured, commonly used and machine-readable format, and to transmit it to another controller. When technically feasible, the Data Controller will transfer the data directly to another controller.
  • Right to object: the right of the User to object to processing of their personal data or to cease such processing by
  • Right not to be subject to a decision based solely on automated processing, including profiling: the User's right not to be subject to individual decisions based solely on automated processing of personal data, including profiling, except where otherwise provided by current legislation. CLIPIN.
  • Therefore, the User may exercise their rights by written communication addressed to the Data Controller with the reference "GDPR-www.clipin.fit", specifying:

Name, surname of the User and a copy of their ID. Where representation is permitted, identification of the representative by the same means and evidence of representation are also necessary. The photocopy of the ID may be replaced by any other legally valid identification means.

  • The request including specific reasons or the information to which access is sought.
  • Address for notification purposes.
  • Date and signature of the applicant.
  • Any document supporting the claim made.
  • This request and any additional documentation may be sent to the following postal address and/or email:

Postal address: CLIPIN FIT S.L., Av. José Manuel Caballero Bonald, 4, 11405 Jerez de la Frontera, Cádiz, Spain

Email: hola@clipin.fit

Links to third-party websites.

Links to third-party websites.

The Website may include hyperlinks or links that provide access to third-party websites other than CLIPIN, and which therefore are not operated by CLIPIN. The owners of these websites will have their own data protection policies and will be responsible themselves, in each case, for their own files and privacy practices.

Complaints to the Supervisory Authority

If the User considers there to be an issue or infringement of current regulations regarding the way their personal data is being handled, they shall have the right to effective judicial protection and to lodge a complaint with a supervisory authority, particularly in the State where they habitually reside, work, or where the alleged infringement took place. In Spain, the supervisory authority is the Spanish Data Protection Agency (http://www.agpd.es).

II. ACCEPTANCE AND CHANGES TO THIS PRIVACY POLICY

It is necessary for the User to have read and agreed to the personal data protection conditions contained in this Privacy Policy, as well as to accept the processing of their personal data so that the Data Controller can proceed with it in the manner, within the timeframes, and for the purposes indicated. Use of the Website implies acceptance of its Privacy Policy.

CLIPIN reserves the right to modify its Privacy Policy at its own discretion, or due to legislative, judicial, or doctrinal changes from the Spanish Data Protection Agency. Changes or updates to this Privacy Policy will not be explicitly notified to the User. Users are advised to consult this page periodically to stay informed of the latest changes or updates.

This Privacy Policy was updated to conform with Regulation (EU) 2016/679 of the European Parliament and Council, dated 27 April 2016, on the protection of natural persons concerning the processing of personal data and the free movement of such data (GDPR), and Organic Law 3/2018, of 5 December, on the Protection of Personal Data and guarantee of digital rights, as well as the digital services currently provided by CLIPIN, including, where applicable, the use of its mobile application.

Last update: 9 August 2026.

Privacy preferences

Necessary cookies remember your preferences. We only use analytics or external content if you accept them.