Last updated 14 August 2026
payFit decides whether you trained, and takes money from a balance you funded when you didn't. That is a lot of trust to ask for, so this page is specific rather than reassuring.
A photo is how you clear a day. When you check in, payFit saves that photo inside its own private storage on your phone and records that a check-in happened for that date.
The photo is never uploaded. There is no server to upload it to. Nobody at payFit reviews it, no automated system inspects it, and it is not attached to any payment. It exists so that you can look back at your own evidence.
It is also not added to your photo library, and it is excluded from iCloud and iTunes backups — so a photograph of your home gym does not end up in a backup you never thought about. It is stored with iOS file protection, which keeps it encrypted whenever your phone is locked.
How long we keep it: until you delete it or delete the app. There is no expiry and no copy anywhere else, because there is nowhere else. Deleting payFit removes every check-in photo with it.
payFit asks for camera access to take these photos. If the camera is unavailable, it can use a photo you choose from your library instead; only the photo you pick is used.
With your permission, payFit reads workout records from Apple Health — the start time, end time, type of activity, energy burned, and which app or device recorded it. Workouts recorded on a paired Apple Watch reach payFit the same way, because they sync into the same Apple Health store.
payFit does not read heart rate, steps, sleep, body measurements, cycle tracking, nutrition, or any other category in Apple Health.
Workout data is stored on your device only, inside the app's private storage, protected by iOS file encryption. It is not transmitted to us or to anyone else. We cannot see your workouts.
In line with Apple's requirements, health data is never used for advertising or marketing, never sold, and never disclosed to third parties for advertising or data-mining purposes. It is not stored in iCloud.
payFit can also write a single test workout to Apple Health, but only if you ask it to from the app's test tools. It writes nothing otherwise.
payFit works from a balance you fund in advance. A missed day is taken from that balance rather than charged to your card at the time. The balance is your money: you can withdraw whatever is left at any point, and it is refunded to the card that funded it.
Your balance, and the statement of what went in and out of it, are stored on your device alongside the rest of your history.
When you add a card, the details go to our payment processor, which returns a token — a reference that lets a charge be made without the card number itself. payFit stores only that token, the card brand, the last four digits, and the expiry date, held in the device Keychain.
We never store your full card number or security code. They are not written to disk and are discarded as soon as the processor has them.
When a charge is made, the payment processor receives the amount, the currency, the date of the missed day, and your payment token. It does not receive your workouts, your goals, or any health information.
Beta builds of payFit run in a sandbox mode that moves no real money and transmits nothing. Where sandbox mode is active, the app says so.
During setup payFit asks what you are training for, roughly what you weigh, what you would like to weigh, where you train and what kind of training you do. Every one of those questions is optional, and the weight questions can be skipped outright.
This is stored on your device and shown only back to you. It is not uploaded, not used for advertising, and not shared with anyone.
payFit has no accounts. If you choose Continue with Apple, Apple gives payFit your name, which is used to greet you on the home screen and is stored on your device. payFit does not request your email address. You can use the whole app without ever signing in.
payFit Pro is billed by Apple through your Apple Account. Apple handles the payment; payFit never sees your Apple Account details. Managing or cancelling a subscription is done in the App Store, under Settings › your name › Subscriptions.
All of this is stored on your device.
payFit contains no analytics, no advertising, and no third-party tracking. We do not track you across apps or websites, and there is no advertising identifier in the app.
If you allow notifications, payFit sends reminders while you can still clear the day, and a plain note afterwards if you were charged. Notifications are scheduled on your device; their contents are not sent to a server.
Reset everything in Settings clears your history, settings, profile, check-in photos, balance and saved payment method from the device, and detaches the payment token so no further charges can be made.
Deleting the app removes everything payFit stored on the device — including every check-in photo. Revoking payFit's access in the Health app stops it reading workouts immediately.
Withdraw your balance before deleting the app if you want the remaining money back; deleting the app does not withdraw it for you.
Charges already collected are transaction records held by the payment processor, and both we and they may be required to retain them for accounting and legal reasons. Deleting your data does not reverse a completed charge.
payFit is not directed at children and is not intended for anyone under 18. We do not knowingly collect information from children.
If this policy changes in a way that affects what payFit reads or what leaves your device, we will say so in the app before the change takes effect.
Questions about this policy, or about data payFit holds: privacy@payfit-app.com.