Privacy Policy
Last updated: March 17, 2026
1. Data controller
The data controller for your personal data is Athlo.fit, domiciled in the Autonomous City of Buenos Aires, Argentine Republic.
For any inquiries related to the protection of your personal data, you can contact us at soporte@athlo.fit.
2. Legal framework
This policy is framed within Law 25,326 on Personal Data Protection, its Regulatory Decree 1558/2001, and the provisions of the Agency for Access to Public Information (AAIP). Data processing is carried out with the consent of the data subject pursuant to Article 5 of Law 25,326.
3. Data we collect
We collect the following categories of data:
Registration data
- Full name and email address.
- Profile picture (when registering via Google OAuth).
Physical profile data
- Weight, height, training level, and fitness goals.
- This data is voluntarily entered by the user.
Training data
- Training plans, routines, exercises, and session records.
Billing data
- Subscribed plan, payment history, and subscription status.
- Payments are processed by Mercado Pago. Athlo.fit does not store credit or debit card data.
Technical data
- Session cookie for authentication (see section 7).
4. Purpose of processing
Your personal data is processed for the following purposes:
- Service provision: managing your account, storing and processing your training data.
- Authentication: verifying your identity when logging in.
- Billing: processing payments and managing subscriptions.
- Service communications: sending notifications related to your account (terms changes, security updates).
- Service improvement: analyzing platform usage in an aggregated and anonymized manner to improve the experience.
5. Legal basis for processing
The processing of your data is based on:
- Data subject consent (Article 5, Law 25,326): granted at the time of registration.
- Contractual performance: necessary for the provision of the contracted service.
- Legal obligations: retention of billing records in accordance with tax regulations.
6. Storage and security
Your data is stored in a PostgreSQL database hosted on Neon, located in the AWS sa-east-1 region (Sao Paulo, Brazil). Brazil has an adequate level of personal data protection according to international standards.
We implement the following security measures:
- All connections use TLS encryption (HTTPS).
- Sessions are managed using JWT tokens with a 30-day expiration.
- Database access is restricted to platform services.
- We do not store plaintext passwords or credit card data.
7. Cookies and similar technologies
Athlo.fit uses the following storage technologies:
Cookies
next-auth.session-token
next-auth.csrf-token
next-auth.callback-url
Local storage (localStorage)
- cookie_consent: stores your cookie consent preferences.
Currently, Athlo.fit does not use analytics or marketing cookies. If incorporated in the future, they will be optional and require your prior consent through the cookie banner.
8. Data sharing with third parties
Your data may be shared with the following third parties, exclusively for the indicated purposes:
- Google: authentication via OAuth (if the user chooses this registration method).
- Mercado Pago: payment processing and subscription management.
- Neon / AWS: database hosting.
We do not sell, rent, or share your personal data for advertising or commercial purposes of third parties.
9. Data subject rights (ARCO Rights)
In accordance with Law 25,326, you have the right to:
- Access: request a copy of the personal data we hold about you.
- Rectification: correct inaccurate or incomplete data.
- Cancellation (Deletion): request the deletion of your personal data.
- Opposition: object to the processing of your data for certain purposes.
To exercise any of these rights, send an email to soporte@athlo.fit indicating your name, the email associated with the account, and the right you wish to exercise. We will respond within 10 (ten) business days in accordance with Article 14 of Law 25,326.
The exercise of these rights is free of charge, unless the request is manifestly unfounded or excessive.
10. Data retention
- Active account: data is retained while the account remains active.
- Post-deletion: data is retained for 30 days after account deletion and then permanently deleted.
- Billing records: retained in accordance with applicable tax obligations (Law 11,683 on Tax Procedure).
11. Minors
Athlo.fit is intended for persons over 18 years of age. We do not intentionally collect data from minors. If we detect that a minor has provided data without parental authorization, we will proceed to delete it.
12. Changes to this policy
Athlo.fit may update this privacy policy at any time. Substantial changes will be notified by email at least 30 (thirty) days in advance. The date of the last update is indicated at the beginning of this document.
13. Claims before the AAIP
If you believe that the processing of your personal data violates your rights, you may file a claim with the Agency for Access to Public Information (AAIP):
- Address: Av. Pte. Gral. Julio A. Roca 710, Floor 2, Autonomous City of Buenos Aires.
- Website: www.argentina.gob.ar/aaip
14. Contact
For any inquiries about this privacy policy or the processing of your personal data:
- Email: soporte@athlo.fit
- Legal domicile: Autonomous City of Buenos Aires, Argentine Republic.