Privacy
Last updated 9 October 2026 (terms version 2026-10-09). NextFit exists to show you whether what you're doing is working. That takes your steps, your workouts, your weigh-ins and, if a watch or ring records it, your resting heart rate. This page says what we do with them, who else touches them, how long we keep them, and what you control — in plain words.
Who is responsible
Nextcore Technology, Philippines, is the personal information controller for your data under the Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, and the rules of the National Privacy Commission. Our Data Protection Officer answers at privacy@nextcoretechnology.com — for a question about this page, a request about your data, or a concern about how it is handled. We answer within 15 days.
What we store
- Account: email, display name, a hashed password, your weight unit, your time zone (so weekly emails, week boundaries and reminders land at sensible hours), when you accepted the terms and confirmed you are 16 or older, and — separately — when you gave your consent to the processing of your health data and which version of it you agreed to, your sharing, map-privacy and notification settings, and (if you enter them) max heart rate, birth year or a daily step goal.
- If you sign in with Apple or Google: the provider's id for your account and the email address it confirmed. For Apple, also a refresh token, which we keep sealed (encrypted) and revoke with Apple when you delete your account. Your display name starts as the first name the provider gives us — never your email address — or, without one, a neutral name like “Walker 1234” until you choose your own. We never see your Apple or Google password. You can unlink either one under Linked sign-ins on your profile, as long as another way to sign in remains.
- Steps: a daily total per calendar day, and where it came from.
- Weigh-ins: weight and/or body-fat percentage with a timestamp and where it came from (Health, Health Connect, or typed in).
- Readings you deleted: when you delete a reading that came from Apple Health or Health Connect, NextFit keeps a note of it — its id in Health and when you deleted it, never its value — so the next sync doesn't bring it back.
- Resting heart rate: one value a day, read from Apple Health or Health Connect when a watch or ring writes it there, with where it came from. NextFit has room for cardio fitness (VO2 max) beside it, but no NextFit app reads or sends VO2 max today; if one starts to, this page will say so first. Resting heart rate is treated exactly like your weight: only you ever see it.
- Workouts: type, a title, start time, duration, distance, climb, heart-rate summary and time in each zone, per-kilometre splits, heart rate, pace and cadence over the session, laps (each step of a guided session, or the laps a watch marked) and average cadence, which guided session it followed, and — if the workout had one — a simplified GPS route, with each point's time and elevation when they are known. Workouts come from Health or Health Connect, are recorded in the app, or are imported from a GPX file. The Health permission sheet also lists calories burned; NextFit does not keep them.
- Duplicate copies: when the same workout reaches NextFit from two sources — a watch through Health and the app's own recording, say — both are kept and one is marked as a copy of the other, so it counts once. If you tell NextFit they are two workouts, it keeps that pair so they are never matched again.
- GPX files you import: the workout in the file — its route, times, elevation, heart rate and cadence — becomes one of your workouts, private to you like everything else, plus a fingerprint of the file (a SHA-256 hash) so the same file isn't imported twice. The file itself is not kept.
- Where each route began and ended: for every workout with a route, its first and last point, so NextFit can group your own workouts that follow the same route (“Your routes”) and compare each effort with your usual time on it. Only you see the grouping; it is never used for anything another person sees.
- Programs: which program you follow (Walk 30, Walk to run 5 km, or a Plus program), when you started it and when you stopped, and — for a Plus program — the stretches of time it was paused because you didn't have Plus, so a session recorded then doesn't fill its weeks. Which of its sessions you recorded is read from your workouts, not kept separately.
- Personal records: your fastest kilometre, mile, 5 km, 10 km, half marathon and marathon, your longest distance on foot, on a ride and in a wheelchair (your longest push), and your longest session, worked out from your own workouts. Only you see them.
- Achievements: the badges you have earned from your steps and workouts, and when. Never anything about weight, body fat or resting heart rate.
- The monthly review (Plus): worked out from your own data each time you open it, and not stored. We keep only which months we told you a review was ready, so you are told once.
- From the phone itself (optional): the phone's step counter, if you turn it on, and — only while you have a recording running — its GPS position and, if you connect one, a Bluetooth heart-rate sensor. Location is never read outside a recording you started, and never for an indoor session.
- If you buy NextFit Plus: which plan, which store, when it renews or ends, whether a payment is being retried, and whether it reached you through the store's family sharing — sent to us by the store through RevenueCat. We never see your card or bank details; Apple or Google hold those.
- Plus notices and suggestions: the Plus notices we sent you (a free trial about to end, a payment that didn't go through) and when; and the few moments the app suggested Plus — for example when your trend first appears — with when it was shown and whether you opened or dismissed it. Labels and times only, never a weight, body-fat, heart-rate or step value. To time those moments NextFit looks at when things happened — when your eighth weigh-in arrived (the day your trend first appears) and when your training status first appeared — never at what they said.
- How the app is used: a short list of named moments — for example that you opened the Plus screen or signed up from the phone — with a date, and, once per person on the phone, whether the app was installed from an invite link or not (one word: invite or organic — never the code or who sent it). Never a weight, body-fat, step or heart-rate value; the server refuses any number in them. We use them to see where people get stuck, they are in your export, and they are deleted after 400 days.
- Invite pages: when anyone opens an invite page on the web, we count it — whether the code named a group, a community challenge, or nothing. The count holds no person, no code and no address. To stop one visitor counting twice, a keyed hash of the code and the visitor's IP address is held in a short-lived counter that expires within an hour.
- Days you opened NextFit: the date only, nothing else, kept for 400 days. They tell us how many people are active and when someone has been away a few days (for the nudge below).
- Notifications: the in-app notifications you get (kudos, comments, new members, weekly results, achievements, nudges, your monthly review being ready, and Plus notices) — deleted 90 days after you read them, or after a year unread — and, if you allow notifications in the phone app, that phone's push token so we can reach it. Push tokens are deleted when you sign out everywhere, change or reset your password, or delete your account.
- Groups: the groups you belong to, today's step count for their board and when your steps last synced, and the notification settings you choose. When a week ends, each group's result — every member's step total for the week and rank — is kept, so the group can look back at past weeks.
- Workplaces: which workplace you joined, when, and whether you are a member or an admin there.
- What you write: comments on a group member's workout, kudos you give, workout titles, and — if you report something — the reason you typed and who you blocked.
- Technical: the IP address and time of requests in server logs for up to 30 days, and error reports (which never include a weight, body fat or heart-rate value) if error monitoring is switched on.
Cookies and the sign-in page
- One cookie, to keep you signed in. The website sets a single cookie of its own,
nf_session, when you sign in. It holds your session and nothing else, is sent only to NextFit, can't be read by scripts on the page, and lasts up to 30 days at a time (renewed while you use NextFit, and never past 180 days from when you signed in). Signing out deletes it. There are no advertising, analytics or tracking cookies. - Two small notes in your browser (its own storage, not a cookie, never sent to us): the page you were on its way to while a password-reset link is out, kept for that link's hour; and, if you chose “Not now” when asked for your consent to health data, that you did, so you are asked once.
- Sign in with Apple or Google. Their sign-in scripts load only when you reach for one of their buttons — point at it, touch it or move to it with the keyboard — not for every visitor to the sign-in page. Once loaded, Apple or Google receives your IP address and browser details, as with any site you visit, and may set its own cookies under its own privacy policy.
Why, and on what basis
- Your health data is sensitive personal information. Under the Data Privacy Act, information about your health is sensitive personal information. We treat all of it that way — weigh-ins, body fat, resting heart rate, heart rate, steps and workouts, and the routes and records worked out from them — and process it only with your consent: a separate consent, with its own box that is never ticked for you, apart from the terms. You give it when you create an account; an account made before 9 October 2026 is asked for it once, the next time it opens NextFit, and can give it later from the profile. Until an account has given it, NextFit brings in nothing new from Apple Health or Health Connect, or from the phone's step counter, and nothing already stored is deleted. A reading you type in, a workout you record in the app and a GPX file you import are still saved even then: each is something you chose to give NextFit, and we treat that act as your consent for that one item.
- What we use it for: to show it back to you; to work out your trend, training status and records; to time the few moments the app suggests Plus, from when your eighth weigh-in and your training status arrived (never their values); and — for steps and workouts only, as described below — to share with the groups you join, and as totals with a workplace you join.
- You can withdraw that consent at any time by deleting your account — download everything from your profile first if you want a copy. Deleting a reading or a workout removes that one, and switching off NextFit's access in Apple Health or Health Connect stops anything new coming in. Withdrawing doesn't undo what was lawfully done before, and NextFit can't show you a trend without the consent.
- The rest of your account — email, display name, groups, comments, purchases — we process because it is needed to give you the service you signed up for. Server logs, abuse protection, error reports and the usage counts above we keep in our legitimate interest in keeping NextFit secure and finding where it fails people; none of them carries a health value.
- Nothing is decided about you automatically. NextFit works out your trend, training status and records by itself, for you to read. None of it decides anything about you, and none of it is used to profile you for anyone else.
What groups see
- Weight, body fat and resting heart rate are never shown to anyone else. Not in a group, not on a board, not to a workplace, not in an export someone else can see. There is no setting that turns this on, because the code that runs groups cannot read them at all.
- Your display name and daily steps are on every group's board while you are a member. On a private group's board, members also see when your steps last synced (for example “2h ago”); a community challenge never shows that to anyone else. Steps typed into NextFit, and unusually high days, are shown but never ranked.
- Workouts — their title, type, time (to the nearest quarter hour), duration, distance, climb, zone minutes and training load, and its lap count and average cadence when it has them — are shown to your groups by default; switch them off for every group on your profile. A workout marked as a copy of another (the same session from a second source) is left out of group feeds. Groups never see your heart-rate readings, your routes' history, your records or your programs.
- Maps of those workouts are shown to your groups by default with at least the first and last 200 metres removed — a different amount on each workout — so a map doesn't show where you started or finished. Choose Large map privacy on your profile and at least 500 metres go from each end. Your own copy stays whole. Switch maps off on your profile without switching workouts off.
- Community challenges are open step challenges that NextFit runs and anyone can join without a code. They are boards, not feeds: everyone in one sees your display name and steps, and nothing else — no workouts, maps, comments or kudos, whatever your sharing settings — and never your weight, body fat or resting heart rate. A challenge holds at most 5,000 people. You are told this before you join.
- Plus doesn't change what you share, or who can see it. It does change how far back a member can look in a group: someone with Plus sees a year of the group's weekly results — each week's top three names and step totals, the same ones every member saw when that week ended — where everyone else sees the last four weeks. Everything else Plus adds is about your own data.
What a workplace sees
If your employer runs NextFit challenges and you join its workplace with their code, the workplace's admins see:
- the names of the people who joined, and the date each joined;
- for each week, totals for everyone together: how many people walked, total steps (rounded to the nearest 1,000), the median day (rounded to the nearest 100) and the share of people active — from steps a phone or watch measured (steps typed in by hand are left out), counted only from the day each person joined, so nobody's earlier history is included;
- nothing at all for a week in which fewer than five people walked — not even how many did — and nothing for a week that isn't settled yet;
- finished weeks frozen: a week is settled on the Tuesday after it ends, and its totals are stored then and never change when people join or leave later. Everyone who was a member during that week counts toward it, including someone who left before it was settled. The totals are sums for everyone together and keep no row about any one person.
They never see one person's steps, workouts, maps, weight, body fat or resting heart rate. Workplace admins cannot remove you; you leave whenever you like, and removing someone is done by us at the workplace's request. Team groups inside a workplace are ordinary groups with everything above.
What we never do
- We only read from Health / Health Connect. The app never writes to them — not even the workouts you record in NextFit.
- We don't sell or share your data for advertising, and we don't run ads. Health data is never used for advertising, by us or anyone else.
- We don't nag about goal weight or weigh-in streaks, and we don't prescribe calorie deficits.
Who else touches it
Only companies that run a piece of the service for us (processors), each under a contract that limits them to that job:
- Neon (database, Singapore) and Vercel (servers, Singapore) store and serve your data.
- The log storage provider we connect to Vercel (a log drain, such as Axiom or Better Stack) receives the server logs — the IP address, time and kind of each request, never a weight, body-fat or heart-rate value — so we can search them and be alerted when something fails. It keeps them for up to 30 days.
- Resend sends sign-in codes, password-reset emails and, unless you switch it off, the Monday recap email. The recap carries your step totals and workouts and, if you took part in a group's weekly challenge, that group's name and your place in it — never weight, body fat or resting heart rate; it says your trend lives in the app, where only you can see it.
- Apple and Google, if you choose to sign in with them, confirm who you are and send us a signed token with your account id and email. On the website their sign-in scripts load only when you reach for their buttons (see Cookies and the sign-in page).
- The map tile provider (MapTiler, or OpenStreetMap's servers in development builds) receives your IP address and the map area being drawn whenever a map is shown. It never receives your route.
- Sentry, when enabled, receives error reports with no health values in them.
- Upstash, only if we turn it on, holds the short-lived counters that slow down password guessing and other abuse, and the invite-page counter above. Otherwise those counters are kept in our own database, under a keyed hash of your IP address, the email address being tried or your account number — never the address itself. Either way a counter expires within an hour.
- Google Firebase Cloud Messaging, when enabled, delivers phone notifications: it receives a device token and the notification's text, which never mentions weight, body fat or resting heart rate.
- RevenueCat, and Apple or Google as the store, handle Plus purchases. RevenueCat receives your NextFit account number and the purchase details from the store — no health data, no email address.
Outside the Philippines. Your data is stored in Singapore, and the services above may process parts of it there, in the United States and wherever Apple, Google and the map provider run. We remain responsible for it wherever it goes, as the Data Privacy Act requires: each processor is bound by contract to protect it and to use it only for the job it does for us.
How long we keep it
- Your account and everything in it — weigh-ins, resting heart rate, steps, workouts, routes, records, programs, Plus notices and suggestions — for as long as the account exists. Deleting your account removes every row that belongs to it from the live database immediately, including your entries in groups' past weekly results; copies in database backups expire within 30 days. Your name leaves group boards within a few hours.
- Usage moments and days you opened NextFit: 400 days. Invite-page counts, which name no one: 400 days.
- Notifications: 90 days after you read them, or a year unread.
- Abuse counters: within an hour. Server logs: up to 30 days, with Vercel and the log storage provider.
- A note of a deleted Health reading (its id in Health and when you deleted it, never its value): as long as the account exists, so the reading never comes back; it goes with the account.
- Content reports: up to a year after they are handled, with your name removed if you delete your account.
- A workplace's frozen weekly totals stay after you leave or delete your account, because they are sums for everyone together and hold nothing that identifies you.
Your controls
- Export: a CSV of your weekly or monthly report from History (body fat and resting heart rate left out unless you tick their boxes), everything you own as one JSON file from your profile, or any workout's route as a GPX file. A GPX file is your route as NextFit keeps it — the simplified trace, with nothing cut from the ends — and it leaves NextFit only when you download it.
- Correct: your name, unit, heart-rate settings and any mislabelled session, from your profile and the activity itself. A new email address takes over only after you type the code we send to it. If NextFit marked a workout as a copy of another and it isn't, choose “These are two workouts” on it.
- Delete a reading: a weigh-in, with Delete beside it in History on the web, or from Trend's list of readings on the phone. It goes from NextFit for good, and your trend is worked out again without it. One that came from Apple Health or Health Connect stays in that app, and NextFit won't bring it back on the next sync. A workout has its own Delete, in its detail. To remove a day's steps or resting heart rate, write to us.
- Sharing: workouts and maps for groups, on or off, and how much of each map's ends is removed (Standard or Large), from your profile. Body composition and resting heart rate are not settings.
- Notifications: each kind switches off on your profile — including the weekly email, Plus notices, the monthly-review notice, and the occasional nudge after a few days away, which says how far your group has walked or, if you're in no group, your own typical day. Never weight, body fat or resting heart rate.
- Sign out everywhere: your profile on the web (click your name), or You on the phone. Every device is signed out at once.
- Report something: the three-dot button on any workout or comment in a group, or next to a person's name on a group's board; a whole group, from “Report this group” under its board. An operator looks at it, normally within 24 hours; the person is not told who reported them, and reporting does not delete anything on its own.
- Block someone: from the same three-dot button — tick “Also block” with a report, or choose “Just block” to block without reporting. Blocking is mutual — their workouts, comments and place on step boards disappear for you, and yours for them. Undo it any time from your profile.
- Leave a group or a workplace: any time, from the Groups or Workplace page.
- Delete your account: from your profile, confirmed with your password or — if you sign in with Apple or Google — with them. It removes your account and every row that belongs to it — weigh-ins, resting heart rate, steps, workouts, routes, records, programs, Plus notices and suggestions, group and workplace memberships — immediately and permanently. Groups you own are handed to the longest-standing other member, or closed if you are the only one. If you signed in with Apple, NextFit's access is revoked with Apple too. A store subscription is cancelled in the store, not here. Deleting your account is also how you withdraw your consent to health data; download everything first if you want to keep a copy.
Your rights under the Data Privacy Act
As a data subject you have the right:
- to be informed — this page, and the screens in the app that say what a group will see before you join one;
- to access your data — the JSON export from your profile, or ask us;
- to object to any processing, and to withdraw your consent, as above;
- to correct what is wrong — from your profile and the activity itself, or ask us;
- to erasure or blocking — delete a weigh-in, a workout or the whole account yourself, as above; for a day's steps or resting heart rate, or anything else, ask us;
- to data portability — the JSON, CSV and GPX exports are in common formats another service can read;
- to be paid damages if you are harmed by inaccurate, incomplete, outdated, false or unlawfully obtained data, or by its unauthorised use;
- to complain to the National Privacy Commission (privacy.gov.ph). The Commission normally asks that you write to us first and give us 15 days to put it right.
Write to our Data Protection Officer at privacy@nextcoretechnology.com for any of these. We may ask you to confirm the request from the email address on the account, so nobody else can ask for your data. These rights pass to your heirs. If a breach of your data is likely to put you at real risk of serious harm, we tell you and the National Privacy Commission within 72 hours of learning of it, as the law requires.
Children
NextFit is for people 16 and older. We do not knowingly keep an account for anyone younger; tell us and we will delete it.
Changes
When this page changes in a way that matters, the date and version at the top change and we ask you to accept the new terms when you next sign in. A change to what the health-data consent covers is asked for on its own, the same way.
Data Protection Officer: privacy@nextcoretechnology.com · Terms · Back to sign in