Last updated: August 3, 2026
StrengthSync ("SS", "we", "us") is a fitness and wellness app for logging workouts, cardio sessions, nutrition, and personal health metrics, with AI-assisted features such as a coach chat and food parser. This Privacy Policy explains what we collect, how we collect it, why, who we share it with, how long we keep it, and the choices you have. It applies to your use of the StrengthSync app and our website.
What we never do. We do not sell your personal data. We do not share your data with third-party advertising networks. We do not use any data for cross-app or cross-website tracking. We do not use your personal content to train AI models.
StrengthSync is not a HIPAA covered entity and the app is not a medical device. See our Terms of Service, Section 9, for the health and medical disclaimer.
StrengthSync collects only the data you explicitly enter into the app, authorize us to read, or that is generated as a necessary part of running the service:
We do not collect contacts, browsing history outside the app, search history outside the app, or any data from other apps on your device. We access your camera, photo library, and microphone only when you actively use the photo-scan or voice-input features described in Section 10; we do not read them in the background. Precise location is only collected during GPS-tracked fitness tests (see Section 4).
We collect information through three paths:
When you run a GPS-tracked fitness test (such as the 1.5-mile Cooper test), StrengthSync uses your device's location to measure distance and pace. Location samples are processed on-device and only the aggregated test result (total distance and duration) is stored in our database. Raw GPS tracks are not sent to our servers or retained after the test session ends.
You can revoke location access at any time from iOS Settings → Privacy → Location Services → StrengthSync.
Your data is used exclusively to provide and improve the StrengthSync service:
We do not use your personal content to train AI models. We do not build advertising profiles from your data. We do not sell or rent your data to third parties for marketing.
Hosting-level metadata carve-out. Our No-AI-Training pledge and the limits above apply to your personal content. They do not restrict our infrastructure, hosting, database, edge, and analytics providers from processing standard, aggregated, hosting-level or service-level metadata and performance metrics for security, reliability, capacity, and performance-optimization purposes as described in those providers' own terms. This processing does not use your personal content to train third-party AI models.
Your data is stored using Supabase (hosted on Amazon Web Services infrastructure in the United States). Access to your data is enforced with row-level security policies in the database, so only your authenticated account can read or write rows associated with your user ID. All data is transmitted over HTTPS/TLS. Passwords are hashed by Supabase Auth and are never visible to us or stored in plaintext.
We do not store payment card information. All in-app purchases are processed by Apple via StoreKit; subscription state is relayed to us via RevenueCat without exposing card details.
No system is perfectly secure. While we apply commercially reasonable safeguards, we cannot guarantee absolute security.
Breach notification. If we confirm a data breach involving your personal information, we will notify affected users without undue delay after confirmation, and within any timelines required by applicable law. The notification will describe the nature of the breach, the categories of data involved, the steps we have taken in response, and the steps we recommend you take. We maintain encrypted daily database backups via our infrastructure provider with a target recovery-point objective of twenty-four (24) hours and a commercially reasonable best-effort recovery-time objective.
StrengthSync relies on the following third-party services. Each receives only the subset of data needed for its function, and each is bound by its own privacy policy and terms.
StrengthSync does not use any data for "tracking" purposes as defined by Apple's App Tracking Transparency framework. Specifically: we do not link your data to third-party data for targeted advertising or advertising measurement; we do not share your data with a data broker; we do not use the IDFA; and we do not display third-party advertising in the app.
The app provides optional medication flags (e.g., statin, beta blocker). These fields are optional and exist solely to refine general fitness calculations such as cardiovascular-risk-aware educational content and training-load suggestions.
StrengthSync does not interpret these fields as a clinical assessment. We do not diagnose conditions, recommend medications, or provide medical advice. See Terms of Service Section 9.
Information you enter into these fields is treated with the same row-level-security protections as the rest of your account data and is sent to AI providers only when it is relevant to the specific prompt you are running (see Section 10).
When you use an AI-assisted feature, we send your input to one of our AI providers (Google Gemini or Groq) to generate a response. Depending on the feature, that input may be:
Along with your input, we send minimal context needed to produce a useful response, typically a summary of your recent activity (up to the prior 7 days), and, when relevant to the prompt, a subset of your body profile or sensitive-health-context flags described in Section 9.
We strip your account email and your name before sending. Where we need to associate a request with your account for rate-limit or safety purposes, we send your StrengthSync user UUID — an opaque random identifier issued by our authentication provider that cannot be reversed into your name, email, or any external identifier.
Sensitive health context is sent only when relevant. The sensitive-health-context fields described in Section 9 (medication flags) are sent to AI providers only when the specific prompt you are running requires them — for example, when you explicitly ask about training or nutrition adjustments given a medication. These fields are not included automatically with every AI request.
We do not authorize our AI providers (Google Gemini and Groq) to train their models on your inputs or the responses generated for you.
StrengthSync keeps a record of your coach chat interactions: the message you send, the response you receive, and technical details about how it was produced (which AI provider answered, how long it took, the prompt version, and which knowledge-base entries were used to ground the answer), along with any feedback you give on whether a response was helpful. We use these records only to review and improve the accuracy and quality of the coach. They are stored under your account with the same row-level-security protections as the rest of your data (Section 6), are not used to train AI models, are never sold or shared with third parties, and are retained and deleted in line with Section 12.
Our upstream AI providers may retain traces on their side for a limited period for safety moderation, abuse prevention, and operational purposes, per their own privacy policies. We do not control how long those provider-side logs are retained. See each provider's privacy policy for details.
StrengthSync operates alongside sibling products under the same LLC. Inter-product data sharing is opt-in only and requires your explicit acceptance of a per-flow consent prompt.
No data flows to a Periodize coach or to Metacor unless and until you opt in via the per-flow consent prompt.
StrengthSync retains your account data — body profile, workouts, cardio sessions, nutrition entries, health metrics, HealthKit data we have read, AI chat history, and purchase events — for as long as your account is active, so that your progress charts and history remain available to you.
Leaving a coach's roster does not delete your StrengthSync account or training history; your account data remains subject to this Privacy Policy unless you separately delete your account. If your subscription, trial, coach-sponsored access, promotional access, or other entitlement ends, expires, is canceled, is revoked, or cannot be renewed due to failed payment, or if your account remains inactive for an extended period, we may retain your account data for a limited period to allow account recovery or resubscription. After that period, we may delete or de-identify account data in accordance with this Privacy Policy, backup-rotation practices, legal-retention needs, and applicable law.
You can delete your account and all associated data at any time from inside the app (Settings → Account → Delete Account) or by emailing support@strengthsync.net. Upon a deletion request, your account data is permanently removed from our active databases within thirty (30) days. Encrypted backups containing historical snapshots may persist for up to an additional ninety (90) days before they are overwritten in the normal backup rotation, after which no copy of your data remains in those backups, except for limited records we are legally permitted or required to retain.
Unconverted-trial purge. If you start a paid subscription via a free trial and the trial concludes without converting to paid (for example, the trial ends without a successful charge, or you cancel before conversion), we retain your account data for thirty (30) days after the trial-end date and then automatically purge it from our active databases (with the same backup-rotation tail described above). We send a reminder email at fourteen (14) days post-trial-end so you can reactivate or export your data before purge. Reactivating during the 30-day window restores your account; reactivating after purge requires creating a new account.
Data sent to Google, Groq, RevenueCat, Stripe, PostHog, Vercel, Upstash, or other third-party services is governed by each provider's own retention policy. We do not control how long those providers retain transaction logs on their side. See each provider's privacy policy for details.
Regardless of where you live, we honor the following rights on a non-territorial basis:
StrengthSync is not currently offered to users in the EU, EEA, United Kingdom, Brazil, China, or South Korea. Account creation from those jurisdictions is not supported; if we identify an account that appears to be located in or operated from one of these jurisdictions, we may suspend the account pending dedicated regional compliance work. The rights above are honored for users in jurisdictions where the app is available, including CCPA (California), VCDPA (Virginia), CPA (Colorado), CTDPA (Connecticut), and similar U.S. state privacy frameworks.
StrengthSync is not intended for users under 18, and accounts may only be created by individuals who are 18 or older. We do not knowingly collect personal information from users under 18. If we learn that we have collected personal information from a user under 18, we will delete that account and the associated data. Parents or legal guardians who believe their child has provided us information may contact privacy@strengthsync.net.
Apple requires every app on the App Store to publish a Privacy Nutrition Label describing the categories of data collected and how that data is used. StrengthSync's Privacy Nutrition Label is visible on the App Store product page for the app. The categories declared there correspond to the data types and purposes described in this Privacy Policy, including: Contact Info (email), Identifiers (user ID), Health & Fitness, Sensitive Info, Usage Data, Diagnostics, Purchases, and User Content (coach chat messages).
StrengthSync does not declare any data under Apple's "Used to Track You" category — see Section 8.
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page and bump the internal Privacy Policy version. Material changes will trigger an in-app re-consent prompt on your next authenticated app open; minor changes will be posted here without a separate notice.
Privacy questions, data-access requests, deletion requests, or portability requests:
General support: