Privacy policy

Last updated: 16 June 2026.

This Privacy Policy explains how MAGIC TECH LTD ("we", "us", "our") collects, uses, shares and protects your personal information when you use the MAGIC mirror, the MAGIC mobile app and our website at magic.fit (together, the "Services").

We are the data controller. Our registered office is at 9th Floor, 107 Cheapside, London EC2V 6DN, United Kingdom. You can contact us at team@magic.fit or by post at the address above.

Markets We Serve

Our online stores sell to customers in the United Kingdom and the United States. Some products may be shipped onwards by customers to other countries, but our contracts are with UK or US customers and this Policy is written for UK users. Residents of other jurisdictions can use the Services, but the local-law rights described in this Policy may not apply in the same way. If you are unsure which rights apply to you, please contact us.

1. Information We Collect

1.1 Information you provide directly

When you create an account, set up your mirror, take a workout, or contact us we collect: name, email address, password (stored as a salted hash), billing address, payment details (processed by our payment processor Stripe — see Section 7), date of birth, gender, height, weight, fitness goals, sub-account information, customer-support messages, and any other information you choose to provide.

1.2 Information generated by your use of the Services

This includes: workout history, exercise selections, workout duration and intensity, body-scan images and derived body measurements, pose-tracking and movement data, in-app browsing and interaction (product analytics) data, subscription status, and device identifiers.

1.3 Information collected automatically

When you use the Services we collect: IP address, approximate location derived from IP address (we do not collect precise GPS location), device type and operating system, application logs, crash and diagnostic telemetry, and cookies and similar technologies (see Section 13).

1.4 Device permissions

The body-scan and pose-tracking features require access to your mirror's camera. The microphone is not used for body scanning or pose tracking. Where any Services feature requires a device permission, we will request it through the operating system's permission flow.

2. How We Use Your Information

We process your information to: provide the Services, personalise workouts and recommendations, process payments and manage subscriptions, communicate with you about your account and the Services, send marketing communications (where you have consented), improve and develop the Services, ensure security and prevent fraud, and comply with our legal obligations.

3. Legal Bases for Processing (UK users)

Under the UK GDPR, we rely on the following legal bases:

(a) Performance of a contract (Article 6(1)(b)) — to provide the Services you have asked for, including processing your subscription.

(b) Legitimate interests (Article 6(1)(f)) — to improve the Services, ensure security, and conduct analytics, where these interests are not overridden by your rights.

(c) Consent (Article 6(1)(a) and, for sensitive data, Article 9(2)(a)) — for marketing communications, health and fitness data processing, body-scan processing, and the third-party integrations described in Section 6.

(d) Legal obligation (Article 6(1)(c)) — where we are required to process your information to comply with applicable law.

4. Sensitive Personal Information

We process the following categories of special category / sensitive personal data: health and fitness data, body-scan images and derived measurements. We process this data on the basis of your explicit consent under Article 9(2)(a) of the UK GDPR. You can withdraw consent at any time by disconnecting the relevant feature or contacting us; withdrawing consent will stop further processing for that purpose but does not affect processing already carried out lawfully.

We do not use health, fitness, body-scan, pose-tracking, or integration data for advertising, marketing, use-based data mining, sale, targeted advertising, profiling, or for any decisions about credit, insurance, employment, eligibility for benefits, or similar.

5. Image and Body-Scan Data

If you choose to use the body-scan feature on your MAGIC mirror, images of you are captured and processed to derive body measurements and pose data. We process these images using a third-party service provider that securely processes and stores image data on our behalf.

Retention: body-scan images are retained for 30 days from the date of capture and are then permanently deleted from our systems and from those of the third-party service provider. Derived body measurements and pose data are retained for the life of your account so that you can see progress over time, and are deleted on account deletion or on request. We do not create biometric templates or biometric identifiers from this data. The complete retention schedule is set out in Section 11.

Where international transfers are involved, we rely on appropriate safeguards as described in Section 10.

6. Health & Fitness Data and Third-Party Integrations

When you use the MAGIC mobile app alongside your MAGIC mirror, the mobile app can share health and fitness information with platforms you choose to connect: Apple Health (Apple HealthKit), Google Health Connect, and the calendar app on your device.

We do not use health, fitness, body-scan, or integration data for advertising, marketing, use-based data mining, sale, targeted advertising, profiling, or for any decisions about credit, insurance, employment, eligibility for benefits, or similar. We do not share this data with brokers.

For UK users, we process integration data on the basis of your explicit consent under Article 9(2)(a) of the UK GDPR. You provide this consent when you connect an integration and may withdraw it at any time.

Apple HealthKit (iOS)

Where you connect Apple Health, the MAGIC app may read the following data types from Apple Health, with your permission: workouts, active energy burned, and exercise minutes. The MAGIC app may write the following data types to Apple Health: completed workouts and active energy burned. Permissions are requested through the standard iOS Health prompts. Data written to Apple Health is then governed by Apple's terms and your Apple Health settings.

Google Health Connect (Android)

Where you connect Google Health Connect, the MAGIC app may write the following data types to Health Connect: completed workout sessions and active calories burned. The MAGIC app does not read data from Health Connect. Permissions are requested through the standard Health Connect flow. Data written to Health Connect is then governed by Google's Health Connect terms and your Health Connect settings.

Device Calendar

Where you connect your device calendar, the MAGIC app may read and write calendar events relating to your weekly workout schedule. Calendar data stays on your device unless your calendar app itself syncs with a cloud service (such as iCloud, Google Calendar or Microsoft 365), in which case events the MAGIC app writes will sync the same way. We do not directly access any cloud calendar service.

Storage, retention and deletion by MAGIC

Apple Health activity data we read is used in-session to personalise your experience and is not separately stored by MAGIC in identifiable form. Health Connect is write-only — we do not read or store data back from Health Connect. Calendar events we write are stored only as part of your workout schedule and are subject to the retention schedule in this Policy.

To delete integration data held by MAGIC, request account or data deletion as described in the Your Rights section of this Policy. To delete data that has been written to Apple Health, Health Connect, or your calendar, use the Apple Health app, Health Connect app, or your calendar app directly — once data has been written there, it is held by Apple, Google, or your calendar provider rather than by MAGIC.

Disconnecting integrations

You can disconnect any of these integrations at any time from within the MAGIC app or from your device's system settings. When you disconnect, the MAGIC app will stop syncing further data. Data already written to Apple Health, Health Connect or your calendar will not be removed automatically; remove it through those apps as described above.

7. Subscription and Payment Data

When you subscribe to MAGIC+ we process your payment information through Stripe Payments UK, Ltd. (“Stripe”), our payment processor. Stripe is a PCI-DSS Level 1 compliant service provider. We do not store full card numbers or CVV codes ourselves; we store limited payment metadata (the plan, the amount, the date, the payment method type, the last four digits of the card, and the card expiry month and year).

Stripe processes your payment information on our behalf as a service provider / processor under our contract with them. Stripe may also process certain payment information for its own purposes (such as fraud prevention) as an independent controller; that processing is governed by Stripe's own terms and privacy notice.

8. How We Share Your Information

We share information with: our service providers (see Section 9), our payment processor Stripe, Apple, Google and your calendar provider where you enable the relevant integrations, professional advisors, and authorities where required by law. We require service providers to handle your information in accordance with this Policy. We do not sell your personal information and we do not share personal information for cross-context behavioural advertising.

9. Service Providers

We use the following categories of service provider to operate the Services:

  • Payment processing for MAGIC+ subscriptions: Stripe Payments UK, Ltd.

  • Payment processing for hardware purchases: Visa, Mastercard, American Express, and PayPal (UK) Ltd. (where you choose PayPal). PayPal's handling of your payment information is governed by PayPal's own terms and privacy policy.

  • Financing for hardware purchases (where you choose financing): Klarna Bank AB (publ). Klarna's handling of your information is governed by Klarna's own terms and privacy policy.

  • Product analytics: Mixpanel.

  • Mobile diagnostics, crash reporting and telemetry: Firebase Crashlytics.

  • Cloud hosting and storage, customer communications, AI/ML services, and the third-party body-scan image processor: details available on request.

We require all service providers to handle your information in accordance with this Policy and applicable data-protection law. Health and fitness data, body-scan data, and pose/movement data are not shared with our product-analytics or crash-reporting providers (Mixpanel and Firebase Crashlytics).

10. International Transfers

Where we transfer your information outside the UK, we use appropriate safeguards including the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, issued by the Information Commissioner. Where we transfer personal data to recipients in the United States that are self-certified to the UK Extension to the EU-US Data Privacy Framework, we may rely on that framework as an additional safeguard.

11. Data Retention

We retain your personal information for as long as it is necessary for the purposes set out in this Policy, unless a longer retention period is required or permitted by law. The specific retention periods we apply are set out in the table below.

Data category

Retention period

Account information (name, email, account credentials, profile details, billing address, sub-account information)

For the life of your account. When you request account deletion, your account and the personal information associated with it are deleted without undue delay, except for information we are required to retain by law (see other rows in this table).

Workout history, exercise selections, workout duration and intensity, subscription status

For the life of your account; deleted on account deletion.

Body-scan images

30 days from the date of capture, then permanently deleted from our systems and from those of the third-party service provider that processes them on our behalf.

Derived body measurements and pose / movement data from body scans

For the life of your account (so you can see progress over time), and in any event for no longer than 3 years from your last interaction with the Services. Deleted earlier on account deletion or on request via the body-scan-data deletion route. No biometric templates or biometric identifiers are created from this data.

Health and fitness data received from Apple Health (where you connect the integration)

Retained only for the duration of the active session in which it is used to personalise your experience. Not separately stored by MAGIC in identifiable form beyond that session.

Workout / activity data written by MAGIC to Apple Health, Google Health Connect, or your device calendar

Not retained by MAGIC after the write; the data is then held by Apple, Google, or your calendar provider under their terms and retention rules.

Calendar events MAGIC reads from your device calendar

Processed in-session only; not separately stored by MAGIC.

Your MAGIC workout schedule (held by us, separate from any calendar events we write to your device)

Retained for the life of your account; deleted on account deletion.

Billing and transaction records (transaction date, amount, plan type, payment method type, last four digits of the card, card expiry month and year)

7 years from the date of the transaction, as required by UK tax and accounting law.

Payment card data (full card number, CVV)

Not stored by MAGIC. Stripe processes and stores this data under their PCI-DSS-compliant systems and their own retention rules.

Marketing communication preferences and consent records

Consent and opt-out records are retained for 6 years from the date of withdrawal in order to honour your opt-out and demonstrate compliance.

In-app browsing and interaction (product analytics) data

Up to 12 months from collection, then deleted or aggregated/anonymised.

Device identifiers, IP address, approximate location (derived from IP), device type and operating system, application logs

Up to 12 months from collection, then deleted or aggregated/anonymised. Security and fraud-prevention logs may be retained for up to 24 months where lawful.

Diagnostic, crash and telemetry data (Firebase Crashlytics, Mixpanel)

Up to 90 days for active diagnosis. Aggregated or anonymised data may be retained longer.

Customer-support messages and free-text content you provide to us

Up to 24 months from the date of the message, then deleted unless retention is required to resolve an ongoing dispute or as required by law.

Cookies and similar technologies (website)

As set out in the cookie table in Section 13 of this Policy. Strictly necessary cookies persist only for the session or for a short defined period; analytics cookies up to 13 months; preference cookies up to 12 months.


Where we are required by law to retain information for longer (for example to comply with a legal obligation, resolve a dispute, or enforce our agreements), we will retain only the information needed for that purpose and for no longer than is necessary.

12. Your Rights

Under the UK GDPR you have the right to: access your personal information, correct inaccurate information, erase your information (in certain circumstances), restrict or object to processing, data portability, and withdraw consent. To exercise these rights, contact us at team@magic.fit. We will respond within one month, which may be extended by a further two months for complex requests.

Account or data deletion. You can request account or data deletion by emailing team@magic.fit. We will action your request without undue delay and in any event within the timeframes set by applicable law.

Privacy contact. You can contact our privacy team at team@magic.fit for any privacy-related question. We have not appointed a statutory Data Protection Officer as we are not required to do so under the UK GDPR.

Right to complain. You have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.

13. Cookies and Tracking

We use cookies and similar technologies on our website. Categories used:

Category

Purpose

Duration

Strictly necessary

Required for the website to function (e.g. cart, login session, security).

Session or up to 30 days.

Preferences

Remember your preferences such as language or region.

Up to 12 months.

Analytics

Help us understand how visitors use the website so we can improve it. Set only with consent.

Up to 13 months.

Marketing / advertising

Not currently used. We do not run targeted advertising or cross-context behavioural advertising.

N/A.


Where required by UK law (including the Privacy and Electronic Communications Regulations 2003), we obtain your consent through our cookie banner before setting non-essential cookies. You can manage your preferences through the banner or your browser settings.

14. Children and Minors

The Services are intended for users aged 18 or over. We do not knowingly collect personal information from children. Accounts and sub-accounts may only be created by individuals aged 18 or over. If you believe a child under 18 has provided us with personal information, please contact us at team@magic.fit and we will delete the information promptly.

15. AI and Automated Decision-Making

We use AI-driven processing to: count and score workout repetitions, generate personalised workout recommendations, and analyse body-scan data to derive measurements. These processes do not produce legal or similarly significant effects on you within the meaning of Article 22 of the UK GDPR. The outputs are not medical or diagnostic and must not be relied on for any medical purpose.

16. Security and Data Breach

We use organisational and technical measures to protect your information, including encryption of sensitive data in transit and at rest, access controls, and regular security reviews. No system is perfectly secure, and we cannot guarantee absolute security.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office and, where required by law, you, within the statutory timeframes under the UK GDPR.

17. Changes to this Policy

We may update this Policy from time to time. We will notify you of material changes by email or through the Services. The "Last updated" date at the top of this Policy reflects the most recent revision.

18. Contact

MAGIC TECH LTD, 9th Floor, 107 Cheapside, London EC2V 6DN, United Kingdom. Privacy contact: team@magic.fit.