Privacy policy

Last updated: 16 June 2026.

This Privacy Policy explains how MAGIC TECH LTD ("we", "us", "our") collects, uses, shares and protects your personal information when you use the MAGIC mirror, the MAGIC mobile app and our website at magic.fit (together, the "Services").

U.S. customer contact: team@magic.fit

Postal: 111b South Governors Avenue, Dover, Delaware 19904.

Toll-free: (844) 923-3016.

Markets We Serve

Our online stores sell to customers in the United Kingdom and the United States. Some products may be shipped onwards to other countries, but our contracts are with UK or US customers and this Policy is written for US users. Residents of other jurisdictions can use the Services but the local-law rights described here may not apply in the same way.

1. Information We Collect

1.1 Information you provide directly

Name, email address, password, billing address, payment details (processed by Stripe — see Section 10), date of birth, gender, height, weight, fitness goals, sub-account information, customer-support messages, and any other information you choose to provide.

1.2 Information generated by your use of the Services

Workout history, body-scan images and derived measurements, pose-tracking and movement data, in-app browsing and interaction (product analytics) data, subscription status, device identifiers.

1.3 Information collected automatically

IP address, approximate location (we do not collect precise GPS location), device type and operating system, application logs, crash and diagnostic telemetry, cookies and similar technologies.

1.4 Device permissions

The body-scan and pose-tracking features require access to your mirror's camera. The microphone is not used for body scanning or pose tracking.

2. Categories of Personal Information — CCPA / CPRA Notice

In the past twelve (12) months we have collected the following categories of personal information from California residents. The same categories are collected from users in other US states.

Category

Examples

Collected?

Sold/shared for cross-context advertising?

A. Identifiers

Real name, postal address, telephone or mobile number, unique personal identifier, online identifier, IP address, email address, account name, device identifiers

YES

NO

B. California Customer Records personal information

Name, contact information, financial information (payment details processed via our payment processor)

YES

NO

C. Protected classification characteristics

Gender and date of birth

YES

NO

D. Commercial information

Transaction information, purchase history, subscription history, payment information

YES

NO

E. Biometric information

Body-scan images and derived body measurements. We treat this as sensitive personal information regardless of whether it constitutes “biometric information” under any particular state law.

YES — see Section 4

NO

F. Internet or other similar network activity

Browsing history within the Services, in-app interactions, search history, interactions with features, application analytics

YES

NO

G. Geolocation data

Approximate location derived from IP address. We do not collect precise geolocation.

YES (approximate only)

NO

H. Audio, electronic, visual, thermal, olfactory, or similar information

Images and video associated with body-scan and pose-tracking features

YES

NO

I. Professional or employment-related information

Not collected

NO

NO

J. Education information

Not collected

NO

NO

K. Inferences drawn from collected personal information

Inferences drawn from the above to personalise workouts, recommendations and content

YES

NO

L. Sensitive personal information

Account login credentials, health and fitness data, body-scan images and derived measurements

YES

NO


Sources of personal information: directly from you, automatically from your use of the Services, and from our service providers.

Purposes of collection: providing the Services, personalising workouts, processing payments and subscriptions, communications, analytics and improvement, security and fraud prevention, legal compliance.

Recipient categories: payment processor (Stripe Payments UK, Ltd.); product analytics provider (Mixpanel); mobile diagnostics and crash-reporting provider (Firebase Crashlytics); cloud hosting and storage provider; customer communications provider; body-scan image-processing provider; professional advisors; and authorities where required by law.

We do not sell personal information for monetary consideration. We do not share personal information for cross-context behavioural advertising. We do not use sensitive personal information for purposes that would require a right-to-limit under California law.

3. Consumer Health Data — Washington MHMDA and Nevada SB 370

If you are a resident of Washington or Nevada, this section describes how we collect and process "consumer health data" as defined by the Washington My Health My Data Act (RCW 19.373) and Nevada SB 370 (NRS 603A.400-920).

3.1 Categories of consumer health data

The categories of consumer health data we process are: workout history and performance data; body-scan images and derived body measurements; pose and movement data; fitness goals and self-reported health information; and, where you connect the relevant integration, activity data read from Apple Health, workout data we write to Apple Health or Google Health Connect, and calendar events relating to your workout schedule that we read from or write to your device calendar.

3.2 Sources, purposes and sharing

Sources: directly from you and from your use of the Services.

Purposes: to provide the Services, generate personalised workouts and recommendations, and improve the Services.

Sharing: consumer health data is shared only with the service providers strictly necessary to deliver the body-scan feature and the platform integrations you choose to connect (Apple Health, Google Health Connect, or your calendar provider). Consumer health data is not shared with our analytics or crash-reporting providers (Mixpanel and Firebase Crashlytics) or with marketing communication providers. We do not sell consumer health data, and we will not share or sell consumer health data without your separate authorisation as required by applicable law.

3.3 Your rights

You have the right to: confirm whether we are collecting your consumer health data, access it, withdraw consent to its collection, request its deletion, and authorise (or decline) the sharing or sale of consumer health data. To exercise these rights, contact us using the details at the top of this Policy. We will action your request within the time required by applicable law.

3.4 No use for advertising

We do not use consumer health data, Apple Health / HealthKit data, Google Health Connect data, body-scan or biometric data, or other health and fitness integration data for advertising, marketing, use-based data mining, sale, targeted advertising, or eligibility decisions for credit, insurance, employment or lending.

3.5 No geofencing

We do not use geofences around healthcare facilities to collect, identify, track, or send notifications to consumers based on their proximity to such facilities.

4. Biometric Information

If you use the body-scan feature on your MAGIC mirror, we collect images of you and derive body measurements and pose data from those images. Depending on how this data is processed, it may constitute a "biometric identifier" under the laws of certain US states, including the Illinois Biometric Information Privacy Act, 740 ILCS 14 ("BIPA").

4.1 Data collected and purpose

We collect: photographic images of you taken by the MAGIC mirror's camera during body-scan sessions; and derived body measurements and pose data calculated from those images. The purpose of this collection is to provide the body-scan feature and to allow you to track changes in your measurements over time. We do not create biometric templates or biometric identifiers from this data and we do not use the data for identification purposes.

4.2 Consent

Before any body scan is captured, you will be asked to confirm that you have read this Section and consent to the collection and processing of body-scan data as described. By choosing to use the body-scan feature you provide affirmative consent to the collection, use and storage described in this Policy.

4.3 Retention and destruction schedule

Body-scan images: retained for 30 days from the date of capture and then permanently deleted from our systems and from those of the third-party service provider that processes them on our behalf. Derived body measurements and pose data: retained for the life of your account so that you can see progress over time, and in any event for no longer than 3 years from your last interaction with the Services. Deleted earlier on account deletion or on request. This is our written retention and destruction schedule for biometric and biometric-related data.

4.4 Disclosure and sale

We do not sell biometric information. We do not disclose biometric information to third parties except (a) to our service providers strictly to provide the body-scan feature, (b) with your separate consent, or (c) as required by law.

4.5 Deletion

To delete body-scan data we hold about you, email team@magic.fit; we will action the deletion within the time required by applicable law.

5. State Privacy Rights

This section sets out additional rights for residents of US states with comprehensive consumer privacy laws.

5.1 California (CCPA / CPRA)

California residents have the right to know what personal information we collect, the right to delete personal information, the right to correct inaccurate information, the right to opt out of sale or sharing (we do not sell or share), the right to limit use of sensitive personal information, and the right to non-discrimination.

To exercise these rights, contact us using the details at the top of this Policy.

5.2 Colorado, Connecticut, Utah, Virginia

Residents of Colorado (CPA), Connecticut (CTDPA), Utah (UCPA) and Virginia (VCDPA) have rights to access, deletion, correction (where applicable), portability, and opt-out of targeted advertising, sale and certain profiling.

5.3 Texas, Oregon, Florida, Montana

Residents of Texas (TDPSA), Oregon (OCPA), Florida (FDBR) and Montana (MCDPA) have substantially similar rights. Oregon residents have the right to receive a list of specific third parties to which their personal data has been disclosed; contact us using the details at the top of this Policy. Texas residents are notified that we do not sell sensitive personal data and do not engage in targeted advertising.

5.4 2025 and 2026 state laws

Residents of Iowa (ICDPA), Delaware (DPDPA), New Hampshire, New Jersey (NJDPA), Tennessee (TIPA), Minnesota, Maryland (MODPA), Indiana, Kentucky, Rhode Island and Nebraska have rights under their respective state laws as those laws come into effect. Maryland residents are notified that we do not sell sensitive personal data, which is prohibited under MODPA.

5.5 Right to appeal

If we deny your privacy-rights request, you have the right to appeal. To appeal, reply to our response email or contact us at team@magic.fit with the subject line “Privacy Rights Appeal”. We will respond to your appeal within 45 days (or 60 days where permitted by state law). If we deny your appeal, you may contact your state attorney general.

6. Global Privacy Control and Universal Opt-Out

Some browsers and browser extensions send a Global Privacy Control (GPC) signal, which is treated under certain US state privacy laws as a request to opt out of the sale or sharing of personal information. We do not sell personal information, and we do not share personal information for cross-context behavioural advertising or targeted advertising. Because we do not engage in these activities, no opt-out signal is required to give effect to your privacy preferences with respect to sale or sharing.

7. Children's Privacy

The Services are intended for users aged 18 or over. We do not knowingly collect personal information from children. Accounts and sub-accounts may only be created by individuals aged 18 or over. We do not knowingly collect personal information from children under 13, in accordance with the Children's Online Privacy Protection Act (COPPA). If you believe a child has provided us with personal information, contact us at team@magic.fit and we will delete it promptly.

8. Health & Fitness Data and Third-Party Integrations

When you use the MAGIC mobile app alongside your MAGIC mirror, the mobile app can share health and fitness information with platforms you choose to connect: Apple Health (Apple HealthKit), Google Health Connect, and the calendar app on your device.

We do not use health, fitness, body-scan, or integration data for advertising, marketing, use-based data mining, sale, targeted advertising, profiling, or for any decisions about credit, insurance, employment, eligibility for benefits, or similar. We do not share this data with brokers.

For US users, we process integration data only to provide the Services you have asked for and to personalise your experience. You may withdraw your authorisation at any time by disconnecting the integration.

Apple HealthKit (iOS)

Where you connect Apple Health, the MAGIC app may read the following data types from Apple Health, with your permission: workouts, active energy burned, and exercise minutes. The MAGIC app may write the following data types to Apple Health: completed workouts and active energy burned. Permissions are requested through the standard iOS Health prompts. Data written to Apple Health is then governed by Apple's terms and your Apple Health settings.

Google Health Connect (Android)

Where you connect Google Health Connect, the MAGIC app may write the following data types to Health Connect: completed workout sessions and active calories burned. The MAGIC app does not read data from Health Connect. Permissions are requested through the standard Health Connect flow. Data written to Health Connect is then governed by Google's Health Connect terms and your Health Connect settings.

Device Calendar

Where you connect your device calendar, the MAGIC app may read and write calendar events relating to your weekly workout schedule. Calendar data stays on your device unless your calendar app itself syncs with a cloud service (such as iCloud, Google Calendar or Microsoft 365), in which case events the MAGIC app writes will sync the same way. We do not directly access any cloud calendar service.

Storage, retention and deletion by MAGIC

Apple Health activity data we read is used in-session to personalise your experience and is not separately stored by MAGIC in identifiable form. Health Connect is write-only — we do not read or store data back from Health Connect. Calendar events we write are stored only as part of your workout schedule and are subject to the retention schedule in this Policy.

To delete integration data held by MAGIC, request account or data deletion as described in the Your Rights section of this Policy. To delete data that has been written to Apple Health, Health Connect, or your calendar, use the Apple Health app, Health Connect app, or your calendar app directly — once data has been written there, it is held by Apple, Google, or your calendar provider rather than by MAGIC.

Disconnecting integrations

You can disconnect any of these integrations at any time from within the MAGIC app or from your device's system settings. When you disconnect, the MAGIC app will stop syncing further data. Data already written to Apple Health, Health Connect or your calendar will not be removed automatically; remove it through those apps as described above.

9. Sale, Sharing and Targeted Advertising

We do not sell personal information for monetary consideration. We do not share personal information for cross-context behavioural advertising. We do not engage in targeted advertising. We do not process personal information for profiling in furtherance of decisions that produce legal or similarly significant effects.

10. Service Providers and Subscription Payments

We use the following categories of service provider to operate the Services:

  • Payment processing for MAGIC+ subscriptions: Stripe Payments UK, Ltd. Stripe is a PCI-DSS Level 1 compliant service provider. We do not store full card numbers or CVV codes ourselves; we store limited payment metadata (the plan, the amount, the date, the payment method type, the last four digits of the card, and the card expiry month and year).

  • Payment processing for hardware purchases: Visa, Mastercard, American Express, and PayPal (where you choose PayPal). PayPal's handling of your payment information is governed by PayPal's own terms and privacy policy.

  • Financing for hardware purchases (where offered and where you choose financing): a third-party financing provider, whose handling of your information is governed by their own terms and privacy policy.

  • Product analytics: Mixpanel.

  • Mobile diagnostics, crash reporting and telemetry: Firebase Crashlytics.

  • Cloud hosting and storage, customer communications, AI/ML services, and the third-party body-scan image processor: details available on request.

Health and fitness data, body-scan data, and pose/movement data are not shared with our product-analytics or crash-reporting providers (Mixpanel and Firebase Crashlytics).

International transfers. Where we use Stripe Payments UK, Ltd. to process payment information from US customers, your payment information is transferred to the United Kingdom for processing. The transfer is governed by Stripe's contractual safeguards and applicable cross-border transfer mechanisms.

11. Data Security and Breach Notification

We use organisational and technical measures to protect your information, including encryption of sensitive data in transit and at rest, access controls, and regular security reviews.

If a security incident results in the unauthorised acquisition of unsecured "PHR identifiable health information" (as defined by the FTC Health Breach Notification Rule, 16 CFR Part 318), we will notify affected individuals, the Federal Trade Commission, and (for breaches affecting more than 500 residents of a state) prominent media outlets in that state, within the timeframes required by the Rule. We will also comply with applicable state breach-notification laws.

12. Data Retention

We retain personal information for as long as it is necessary for the purposes set out in this Policy, unless a longer retention period is required or permitted by applicable law. The specific retention periods we apply are set out in the table below.

Data category

Retention period

Account information (name, email, account credentials, profile details, billing address, sub-account information)

For the life of your account. When you request account deletion, your account and the personal information associated with it are deleted without undue delay, except for information we are required to retain by law (see other rows in this table).

Workout history, exercise selections, workout duration and intensity, subscription status

For the life of your account; deleted on account deletion.

Body-scan images

30 days from the date of capture, then permanently deleted from our systems and from those of the third-party service provider that processes them on our behalf.

Derived body measurements and pose / movement data from body scans

For the life of your account (so you can see progress over time), and in any event for no longer than 3 years from your last interaction with the Services. Deleted earlier on account deletion or on request via the body-scan-data deletion route. No biometric templates or biometric identifiers are created from this data.

Health and fitness data received from Apple Health (where you connect the integration)

Retained only for the duration of the active session in which it is used to personalise your experience. Not separately stored by MAGIC in identifiable form beyond that session.

Workout / activity data written by MAGIC to Apple Health, Google Health Connect, or your device calendar

Not retained by MAGIC after the write; the data is then held by Apple, Google, or your calendar provider under their terms and retention rules.

Calendar events MAGIC reads from your device calendar

Processed in-session only; not separately stored by MAGIC.

Your MAGIC workout schedule (held by us, separate from any calendar events we write to your device)

Retained for the life of your account; deleted on account deletion.

Billing and transaction records (transaction date, amount, plan type, payment method type, last four digits of the card, card expiry month and year)

7 years from the date of the transaction, as required by applicable US tax and accounting law.

Payment card data (full card number, CVV)

Not stored by MAGIC. Stripe processes and stores this data under their PCI-DSS-compliant systems and their own retention rules.

Marketing communication preferences and consent records

Consent and opt-out records are retained for 6 years from the date of withdrawal in order to honour your opt-out and demonstrate compliance.

In-app browsing and interaction (product analytics) data

Up to 12 months from collection, then deleted or aggregated/anonymised.

Device identifiers, IP address, approximate location (derived from IP), device type and operating system, application logs

Up to 12 months from collection, then deleted or aggregated/anonymised. Security and fraud-prevention logs may be retained for up to 24 months where lawful.

Diagnostic, crash and telemetry data (Firebase Crashlytics, Mixpanel)

Up to 90 days for active diagnosis. Aggregated or anonymised data may be retained longer.

Customer-support messages and free-text content you provide to us

Up to 24 months from the date of the message, then deleted unless retention is required to resolve an ongoing dispute or as required by law.

Cookies and similar technologies (website)

As set out in the cookie table in Section 14 of this Policy. Strictly necessary cookies persist only for the session or for a short defined period; analytics cookies up to 13 months; preference cookies up to 12 months.


Where we are required by law to retain information for longer, we will retain only the information needed for that purpose and for no longer than is necessary.

13. HIPAA Note

MAGIC is not a HIPAA covered entity. The health and fitness data we process is not subject to HIPAA. It is, however, subject to consumer health data laws including the Washington My Health My Data Act, Nevada SB 370, and the FTC Health Breach Notification Rule, as described in this Policy.

14. Cookies and Tracking

We use cookies and similar technologies on our website. Categories used:

Category

Purpose

Duration

Strictly necessary

Required for the website to function (e.g. cart, login session, security).

Session or up to 30 days.

Preferences

Remember your preferences such as language or region.

Up to 12 months.

Analytics

Help us understand how visitors use the website so we can improve it. Set only with consent.

Up to 13 months.

Marketing / advertising

Not currently used. We do not run targeted advertising or cross-context behavioural advertising.

N/A.


Where required by applicable law, we obtain your consent through our cookie banner before setting non-essential cookies.

15. AI and Automated Decision-Making

We use AI-driven processing to count and score workout repetitions, generate personalised workout recommendations, and analyse body-scan data to derive measurements. We do not use these processes to make decisions that produce legal or similarly significant effects on you. The outputs are not medical or diagnostic and must not be relied on for any medical purpose.

16. Changes to this Policy

We may update this Policy from time to time. We will notify you of material changes by email or through the Services. The "Last updated" date reflects the most recent revision.

17. Contact

MAGIC TECH LTD.

US privacy contact: team@magic.fit.

Postal: 111b South Governors Avenue, Dover, Delaware 19904.

Toll-free: (844) 923-3016.