Privacy Policy
Information we collect
We collect the following, all of which you provide or generate by using the App:
- Account information: your email address (for sign-in and account management) and an account identifier (UUID).
- Profile information (optional): a display name; and, to tailor the App's coaching to you, your training experience level, your current training goal (building, maintaining, or cutting), your training days per week, and your sex. Every one of these is optional, is used only to adapt the App's suggestions and defaults to you, and is never used for advertising, sold, or shared with third parties.
- Health & fitness data you enter: workouts, exercises, sets, reps, weights, Reps-In-Reserve (RIR), cardio time and distance, bodyweight entries, and derived metrics such as per-muscle weekly volume. This is the core purpose of the App.
- Body measurements you enter (optional): girth/circumference measurements at sites such as chest, shoulders, arm, forearm, waist, thigh, hips, calf, and neck; each a number, a unit (in or cm), and a date. See Health and body data below.
- Progress photos (optional): physique photos you choose to add, private by design. See Progress photos below.
- Recovery metrics (optional): heart-rate variability (HRV), resting heart rate, and sleep duration; typed in yourself each morning, or read automatically if you choose to connect Apple Health on iPhone or Health Connect on Android. See Health and body data below.
- Health markers (optional): readings you log such as blood pressure and blood-work results (for example cholesterol, hematocrit, or liver enzymes); each a value, a unit, and a date; kept only to show you your own trends over time. See Health and body data below.
- Content you create: program and exercise names, notes and cues, and the text of any bug reports or feature requests you submit through the App, together with an optional screenshot you may choose to attach to a report. See Screenshots attached to feedback below.
- Usage data: first-party feature-usage events, which features are used (for example “session saved” or “report card viewed”), each with the app version and a random app-generated device identifier so we can count unique installs. When something in the App fails, we also record a short technical error message (no longer than 140 characters) so the failure can be diagnosed and fixed. This is how we find bugs that testers hit but cannot easily describe. These events carry no training values, no health or body data, and no contact details; error messages are produced by the App’s own code rather than by anything you type. They go only to our own database (no third-party analytics service ever receives them), they are deleted automatically after 6 months, and we use them solely to understand which features work and what breaks during the beta.
Information we do NOT collect
We do not collect your precise or approximate location, financial information, videos (progress photos are collected only if you choose to add them; see Progress photos), audio (the optional voice-logging feature uses your microphone for speech recognition performed by your device’s own platform, but no audio is ever recorded, stored, or sent to us; see Voice logging), contacts, calendar, SMS or call logs, browsing history, a list of installed apps, or any advertising identifier. Recovery metrics are values you type in yourself, or, only if you choose to connect your platform’s health service, read automatically with your explicit permission (see Health and body data). The App never connects to any health platform without you turning that connection on. The App ships no third-party analytics, crash-reporting, or advertising software.
How we use your information
We use your information solely to:
- provide, operate, and sync the App and your account;
- store and display the training data you enter;
- respond to bug reports and feature requests you send us;
- understand which features are used during the beta (see “Usage data” above); and
- maintain security and prevent abuse.
Health and body data
A few kinds of more sensitive data are collected only if you choose to provide them: by typing them in, or (for recovery metrics) by optionally connecting Apple Health on iPhone or Health Connect on Android:
- Recovery metrics: heart-rate variability (HRV, in milliseconds), resting heart rate (in bpm), and sleep duration (in hours). You enter these yourself, typically each morning from your wearable's reading, or see Connected health sources below.
- Body measurements: girth/circumference at sites such as chest, shoulders, arm, forearm, waist, thigh, hips, calf, and neck; each a value, a unit (in or cm), and a date.
- Health markers: optional readings you log, such as blood pressure, resting heart rate, and blood-work results (such as HDL/LDL cholesterol, triglycerides, hematocrit, hemoglobin, ALT/AST, and eGFR); each a value, a unit, and a date. These are a log for your own trends only: they do not change any training recommendation, and STRIATE does not interpret or diagnose them. It is a log, not medical advice.
Why we collect it: solely to run the App for you. Recovery metrics feed the readiness score that auto-regulates your training, and both recovery and measurements power the coaching engine and show you your own progress over time. This data is never used for advertising, never sold, and never shared with third parties.
Connected health sources (optional: Health Connect on Android, Apple Health on iOS)
If you choose to connect your platform’s health service in the App (Coach tab), Health Connect on Android or Apple Health (HealthKit) on iOS, STRIATE reads only the recovery metrics you approve in that platform’s permission screen (heart-rate variability, resting heart rate, and sleep duration) and nothing else. These readings are stored in your STRIATE account exactly like a manually entered recovery value (a manual entry for a day is never overwritten), are used solely to compute your daily readiness and adjust your training recommendations, and are never used for advertising, never sold, and never shared with third parties. You can revoke the App's access at any time in Health Connect (Android) or the Health app's Sharing settings (iOS), disconnect within STRIATE, and deleting your account removes every imported reading (You → Delete account, or privacy@striatetraining.com).
Writing your workouts back (optional): if your platform’s health service is connected, STRIATE can also write each workout you save to that service as a strength-training session (the workout's start and end time, its name, and set/volume totals) so your other health apps can see that you trained. This requires a separate write permission that your platform asks you for the first time; decline it and everything else works identically. The write only ever contains the session summary above (never your individual sets, weights, recovery metrics, or any other data), and you can revoke the write permission at any time in Health Connect (Android) or the Health app (iOS), or delete the written sessions there directly.
How it's protected: it is private to your account. It is transmitted encrypted in transit (TLS) and stored under row-level security so that only your account can read it. STRIATE is a training and information tool, not medical advice.
Your control: you can export all of your data, and you can delete your account and everything in it at any time in the App (You → Delete account). You may also email privacy@striatetraining.com to request an export or deletion. Deletion is permanent and removes your recovery and measurement data along with the rest of your account.
Scanning a lab report (optional, on-device)
To save you typing, the App can read the numbers out of a bloodwork report you photograph or select (Progress → Body → Health markers → Scan). The image is processed entirely on your device by its on-device text recognition; the picture is never uploaded to us and never stored. It is discarded as soon as the text has been read. Nothing is saved until you review every value and tap Save, and only the values you confirm are kept (exactly as if you had typed them). STRIATE does not interpret or diagnose your results. It is a log, not medical advice.
Voice logging (optional, microphone)
The App offers an optional hands-free way to fill in a set (“225 for 8, RIR 2”). If you tap the voice button, your device will ask for microphone permission. Your speech is converted to text by your device’s own speech-recognition service (on Android this is normally performed on-device; on iPhone, Apple’s Speech framework may send the audio to Apple to transcribe it, under Apple’s own privacy policy). STRIATE never records, stores, or transmits audio, and no audio ever reaches our servers. Only the recognized text is used, and only to fill the weight/reps fields on your screen; nothing is saved until you tap the checkmark yourself. You can deny or revoke the microphone permission at any time in your device settings. Every feature except the voice button works identically without it.
Screenshots attached to feedback (optional)
When you report a bug or request a feature in the App, you may attach a screenshot. This is entirely optional: reports send perfectly well without one, and nothing is ever captured automatically. You choose the image, and the App tells you before you attach it that a screenshot may show your training or body data.
An attached screenshot is resized on your device and uploaded to private storage scoped to your account, the same arrangement as progress photos. It is never public, never shared, and is used for exactly one thing: understanding and fixing the issue you reported. Alongside it we store the app version and build, your platform and operating-system version, a coarse device model, and which screen you were on, so a bug can be traced to the right build and device. Deleting your account deletes these along with everything else.
Progress photos (optional, private by design)
You can add physique progress photos to track visual change over time (Progress → Body). These exist for exactly one purpose: showing you your own before/after. They are private by design: stored in a private bucket readable only by your account (row-level security; images load through short-lived signed links), never shared with anyone (not even a linked coach), never used to train anything, never analyzed, never used for advertising, and never sold. Before upload, each photo is re-encoded on your device, which strips embedded metadata such as GPS location. You can delete any photo at any time, and deleting your account permanently removes every photo along with the rest of your data.
Legal bases (EEA/UK users)
Where the GDPR applies, we process your information to perform our contract with you (providing the App) and, where relevant, based on your consent (which you may withdraw) and our legitimate interests in securing and improving the App.
How your data is stored and who processes it
Your data is stored in a database hosted by Supabase, Inc., our infrastructure processor, which provides authentication, database, and hosting services on our behalf. Data is protected in transit by TLS encryption and, at rest, by row-level security so that your account can access only its own data. Data may be processed and stored on servers located in the United States.
We do not share your personal data with any other third parties except as required to operate the App (as above) or as required by law.
Data retention and deletion
We keep your data for as long as your account exists. You can delete your account and its associated data at any time in the App: You → Delete account. You may also request deletion by emailing privacy@striatetraining.com. Deletion is permanent.
Usage data is deleted automatically. The feature-usage events described above are kept for a maximum of 6 months: an automatic daily job permanently deletes any usage-event rows older than 6 months. We do not keep aggregated copies of deleted events.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, and to object to or restrict certain processing. To exercise these rights, email privacy@striatetraining.com. We will not discriminate against you for exercising them. (California residents: we do not sell or share personal information as defined by the CCPA/CPRA.)
Children
STRIATE is intended for users 18 and older. It is not directed to children, and we do not knowingly collect data from anyone under 13 (or the minimum age in your jurisdiction). If you believe a child has provided us data, contact us and we will delete it.
Security
We use TLS in transit and row-level security at rest, and limit access to your data. No system is perfectly secure, but we take reasonable measures to protect your information.
Changes to this policy
We may update this policy as the App evolves. We will post the updated version here and revise the effective date; material changes may be signaled in the App.
Contact
Questions or requests: privacy@striatetraining.com
This policy is provided for transparency and is not legal advice. STRIATE is operated as an independent project; business-entity details will be updated here upon formation.
← Back to STRIATE