Security

Encryption

Backups are sealed on your device with AES-256-GCM before they ever leave the app. No backdoor, no master key, no password recovery — by design.

Overview

  • Cipher: AES-256-GCM (authenticated encryption)
  • Key derivation: PBKDF2-HMAC-SHA256, 120,000 iterations
  • Salt: 128-bit random, per backup
  • Nonce: 96-bit random, per backup
  • Compression: gzip of JSON before encryption

AES-256-GCM

AES-256 is the standard symmetric cipher used for highly sensitive data. GCM adds integrity: if ciphertext is tampered with, decryption fails instead of producing garbage. You get confidentiality, integrity, and authenticity together.

Key derivation (PBKDF2)

Your password is never used raw as the key. FitBuddy derives a 256-bit key with PBKDF2-HMAC-SHA256 (120k iterations) and a fresh random salt each backup — defeating rainbow tables and making brute force expensive.

Default cloud backups can derive from your Support ID when you haven’t set a custom password. Custom passwords live in the Android Keystore on-device only.

Cloud chunk chains

Large histories upload as an append-only chain of sealed chunks. Routine uploads refresh the tip when content changed; restore downloads and merges the full chain into one snapshot.

Zero-knowledge design

The server only ever stores encrypted envelopes. Forgetting a custom password means that backup cannot be recovered. Keep the password somewhere safe.

Also read Privacy for what leaves the device at all.