A short, plain-English account of what GRC Fit does and doesn't do with your data.
Sign-in is handled by Firebase Authentication, scoped to your Firebase user id. You can sign in with Google, Microsoft, Apple, or an email/password — your account works across all GRC apps.
No third-party scripts, no behavior pixels, no marketing cookies. No Google Analytics, no Segment, no anything. The only network calls the app makes are to Firebase Authentication for sign-in and to load the app shell from the host (Azure Static Web Apps).
To clear your data on this device, sign out and clear site storage in your browser settings. To delete your Firebase account entirely, ask the deployment owner.
The source code is licensed under the PolyForm Noncommercial 1.0.0 license. Use freely for personal, hobby, research, or nonprofit purposes. Commercial use is not permitted.