GymTrack Privacy Policy
GymTrack is built local-first: your training data belongs on your phone, and our default answer to “where does this data go?” is nowhere.
The short version
- Your workout log never leaves your device. Sets, reps, weights, RPE, rest times, notes, and workout history are stored only in the app’s local database on your phone (and your paired Apple Watch during a session).
- AI coaching runs on your device. Insights, summaries, and coach answers are generated by models running locally. The model weights are downloaded from our content network; your data is not uploaded to produce a response.
- Apple Health data stays on your phone. With your permission we read heart rate, HRV, resting heart rate, sleep, energy, and body mass to inform coaching, and write finished workouts to the Fitness app. None of this is transmitted to us.
- If you create a Coach account, we store the minimum needed to make it work: your sign-in email, your stated goals, and coarse de-identified training summaries — never your raw workout log.
- We don’t sell data, we don’t advertise, and we don’t track you across other apps or websites.
What we collect, and when
Without an account (default)
Nothing. The app makes network requests only to download AI model files and their catalog from our content network. Those requests carry no account or workout information.
With a Coach Mode account
| Data | What exactly | Why |
|---|---|---|
| Account email | The email you sign up/sign in with (or the relay address from Sign in with Apple) | Authentication, password reset |
| Account identifier | A random ID (GUID) — not your name or email — keys all service data | Keeping your data yours |
| Declared goals | Choices you type/select: e.g. strength vs. size, bulk/cut/maintain, training days per week, available equipment | Powering coach recommendations |
| Derived training summaries | Coarse, de-identified aggregates: weekly volume band (not exact numbers), adherence percentage, progression trend, plateau flag | Coaching continuity across devices |
| Product analytics (opt-out) | A fixed allowlist of product events: feature usage, funnel steps, whether AI suggestions were accepted | Improving the app |
Explicitly never collected: your raw workout entries (exact weights, reps, RPE, timestamps), free-text session notes, anything from Apple Health, your contacts, your location, or advertising identifiers.
You can turn product analytics off in Settings at any time; the allowlist is enforced in code, and health details are prohibited from it.
Where service data lives
Coach account data is stored with our cloud provider (Amazon Web Services) in access-controlled, per-account-isolated tables. AI model files are served from Cloudflare R2. Transport is encrypted (TLS) everywhere; the on-device database is protected by iOS Data Protection.
Deleting your account
Settings → Account → Delete Account, in the app. This permanently deactivates your account and deletes your sign-in credential — you will no longer be able to sign in, and your email is removed from the authentication system. Analytics already collected are retained in de-identified form, disassociated from your deleted account, and your goals and training summaries are no longer accessible to anyone through the service. Your local workout data on your phone is untouched (delete it any time via Settings → Delete All Data, or by removing the app).
Data export
Settings → Export produces a complete CSV of your workout history at any time, no account required.
Children
GymTrack is not directed at children under 13 and we do not knowingly collect personal information from them.
Changes
We’ll update this policy when the app’s data practices change (for example, if an optional cloud coach feature ships later, it will be described here before it is enabled) and note the effective date above. Material changes will be called out in the app.
Contact
Questions or requests (including data deletion requests):
support@cresca-ai.app