What they may do · DPDP §6(4)
What Cult.fit / Cure.fit does with your data
Cult.fit collects biometric, genetic and health data plus gym CCTV, builds an interest profile through targeting cookies, may run user information through AI and machine-learning systems, and warns that some information stays in its private records after you delete it.
-
Shares your data with partners
Passed to group companies, advertisers or analytics firms you never chose.
What this costs you. Your number and habits travel to companies you have never heard of and never agreed to. This is the step where the spam calls start.
Show me where they say that
Cult.fit / Cure.fit’s own policy says “We may contact you, by email or other means; for example, we, or persons we share your Personal Information with may send you promotional offers on behalf of other businesses, or communicate with you about your use of the Mobile App or the Product.”
Our summary section 6 confirms personal information is shared with other persons who may then send promotional offers on behalf of other businesses; section 7 separately permits sharing with affiliated businesses, agents, and acquirers in a business transfer.
-
Builds an advertising profile of you
They watch what you view, tap and buy, and use it to decide which ads you see.
What this costs you. Your attention gets priced. What you hesitate over becomes a bid — and a profile built to predict you is a profile built to persuade you.
Show me where they say that
Cult.fit / Cure.fit’s own policy says “Your interest profile can be removed by deleting your browser's cookies.”
Our summary section 5.2 is headed 'Delete targeting cookies' and confirms an interest profile exists; section 5.3 describes the stored profile as 'User segment hits' recording a specific product, service, brand or model the user showed interest in.
-
Keeps your records long-term
Held on after you stop using the service.
What this costs you. Years after you delete the app, the record is still sitting there — and every year it sits there is another year it can leak.
Show me where they say that
Cult.fit / Cure.fit’s own policy says “Please note that some information may remain in our private records after your deletion of such information from your account. We may use (or transfer to our affiliates, group entities or authorised third parties) any aggregated data derived from or incorporating your personal information after you update or delete it, but not in a manner that would identify you personally.”
Our summary section 11.2 states that some information remains in the company's private records after the user deletes it, and that aggregated data derived from the user's personal information may still be used or transferred to affiliates and third parties post-deletion.
-
Processes your face or other biometrics
Face matching, liveness checks or similar.
What this costs you. You can change a leaked password in a minute. You cannot change your face. A biometric breach is permanent in a way nothing else is.
Show me where they say that
Cult.fit / Cure.fit’s own policy says “workout related data (including outputs from your device camera for “live energy” tracking or conducting live workout sessions), physical activity, photographs, biometric information, genetic information”
Our summary section 4.1(a)(ii) lists biometric information and genetic information, plus device-camera output for 'live energy' tracking, among the sensitive personal data collected; section 4.1(a)(vi) adds CCTV footage of common areas at physical premises.
-
Trains AI models on your content
Your photos, messages or activity are used to train machine-learning models.
What this costs you. This one has no undo. Once your content is inside a trained model, no erasure request can lift it back out.
Show me where they say that
Cult.fit / Cure.fit’s own policy says “We may use artificial intelligence, machine learning technologies and automated systems to provide, improve, personalize and support our Services... Information provided by users may be processed by such systems for the foregoing purposes.”
Our summary section 7(c) 'AI and Automated Processing' states that information provided by users may be processed by AI and machine-learning systems, with improving the services and platform functionality among the stated purposes. The policy does not use the word 'training'.
What the policy does not mention
These are uses Cult.fit / Cure.fit’s policy is silent on. Silence is not a promise — it means the document does not say, and we do not infer either way.
- Follows you onto other websites and apps
Cult.fit / Cure.fit is one app. How many are on your phone?
Most people carry twenty to forty. Add yours and see the total in one screen — how many share your data, profile you for ads, or follow you across the web. Then take it back from all of them at once.
Manage my data with Saaph.in →Free to check · no account needed · built in India for the DPDP Act
Questions
What does Cult.fit / Cure.fit do with my personal data?
According to Cult.fit / Cure.fit's own privacy policy, read on 2026-08-14, it discloses 5 of the six uses we track: shares your data with partners, builds an advertising profile of you, keeps your records long-term, processes your face or other biometrics, trains ai models on your content.
Can I withdraw my consent from Cult.fit / Cure.fit?
Section 6(4) of India's Digital Personal Data Protection Act 2023 gives you the right to withdraw consent for processing you agreed to. The Act's substantive provisions commence in stages up to May 2027, so a request made now asks for voluntary compliance and puts the date on record. Processing a company carries out under a legal obligation — such as KYC records the RBI requires — cannot be withdrawn.
Does Cult.fit / Cure.fit track me for advertising?
Yes — Cult.fit / Cure.fit's published policy discloses this. The exact sentence it is based on is quoted on this page, with the date we read it and a link to the source.
Every use above is one Cult.fit / Cure.fit declared in its own published privacy policy, which we
read on 2026-08-14. Quotes are verbatim; the summary beside each one is ours
and is labelled as ours. Nothing here is inferred.
Saaph.in is a DPDP consent and request management platform operated by Ronin Works
Private Limited. It is a communication facilitator, not your legal or authorised
representative. The DPDP Act 2023 commences in stages up to May 2027, so a request
made today asks for voluntary compliance and records the date you asked.
Our privacy policy