Health & Fitness

Cure.fit (cult.fit) β†—

Ready Score 42/100
Sushant Pasumarty
ANALYSIS SUPERVISED BY Sushant Pasumarty
πŸ“… 12 Feb 2026

cult.fit collects intimate health data β€” heart rate, body measurements, workout capacity, injury history, and mental health content engagement β€” processing what is effectively continuous health monitoring. At 42/100, treating this health data with consumer app privacy standards instead of health data protections creates significant DPDP exposure.

⚠️ Compliance Gaps

  • No DPDP Act 2023 reference
  • Health metrics data (heart rate, calories, BMI) treated as standard app data
  • Workout behavior profiling reveals physical limitations and health status
  • Mental health content (mind.fit) reveals psychological conditions
  • No data retention timelines for health metrics
  • Data Protection Board not referenced
  • Wearable device data synchronization creates continuous health monitoring

βœ… Strengths

  • Health and fitness data categories documented
  • Security measures described
  • Grievance officer designated

Overview

cult.fit (Cure.fit) operates across fitness (cult.fit), nutrition (eat.fit), mental health (mind.fit), and primary care (care.fit). This ecosystem processes intimate health data: workout performance, physical measurements, dietary habits, mental health engagement, and medical consultations. Combined with wearable device integration, cult.fit maintains continuous health monitoring.

Key DPDP Concerns

Health Data Without Health Protections

cult.fit treats health metrics as standard consumer data:

  • Heart rate and calorie data from workouts
  • Body measurements and BMI tracking
  • Injury history and physical limitations
  • Mental health content consumption (anxiety, stress, depression topics)
  • Nutritional data and dietary restrictions

Under DPDP, this comprehensive health profile requires enhanced consent, strict retention, and limited sharing.

Mental Health Data Sensitivity πŸ”΄

mind.fit engagement reveals:

  • Meditation for anxiety β€” reveals mental health concern
  • Sleep improvement content β€” reveals sleep disorders
  • Stress management β€” reveals psychological state

This is among the most sensitive personal data categories β€” processed under basic app consent.

Recommendations

  1. Classify all fitness/health data as health information under DPDP
  2. Implement separate consent per service β€” Fitness tracking, mental health, nutrition, and medical services each need independent consent
  3. Define health data retention β€” β€œWorkout data: 1 year rolling; body measurements: until user deletion; mental health engagement: 90 days; medical consultations: per medical record standards”
  4. Add mental health data special protections β€” Enhanced encryption and minimal sharing
  5. Build health data portability β€” Allow export of health metrics, workout history, and nutrition data

How Does Your Policy Compare?

πŸ” Run Your Free DPDP Audit β†’


Analysis conducted by DPDP Consulting, a Meridian Bridge Strategy initiative. For a comprehensive compliance roadmap, book a free consultation.

Fix these compliance gaps today.

Book 1:1 Consultation
πŸ“ž Free Consultation