Privacy Policy
Strength Almanac is a workout tracker. This page explains, in plain language, exactly what we collect, why, who can see it, and how to get rid of it.
- We collect your email, your workout data, and — if you choose to log them — body measurements.
- Your data is private by default. Nobody else sees it unless you share it, by inviting a coach or publishing a program to the community.
- We don’t sell your data. We don’t run ads. We use no third-party advertising or tracking SDKs.
- If you opt in, we record the country and state of a workout for location-based achievements. Never a coordinate, and if you decline we don’t infer it from anything else.
- Two service providers see limited technical data about you: Sentry (crash diagnostics) and RevenueCat (subscriptions). Neither receives your training content.
- You can delete your account from inside the app. After a 7-day grace period, it’s permanently erased, except for three narrow kinds of record we keep after deletion: reports of abuse, evidence of the subscription terms you agreed to, and purchase records. Each is described under Retention and deletion below.
What we collect and why
Account information
- Email address and password — to create and secure your account. Passwords are handled by our authentication provider (Supabase Auth) and are never visible to us in plain text.
- Display name — shown on your profile and, if you publish or coach, to other users.
- Preferences — unit preference (lbs/kg), experience level, default rest timer, theme and naming preferences, notification settings.
- Optional profile extras — a short bio, your gym’s name, featured personal records, and a profile cover image, if you choose to add them.
- Sex — optional, and used for one purpose: normalising strength standards, since published strength data differs by sex. It is not used to categorise you anywhere else, it is never shown to other users, and it is not a question about gender identity or sexual orientation — neither of which we ask for or store.
Fitness and workout data
- Workout logs — sessions, exercises, sets, weight, reps, warmup flags, and any notes you write.
- Personal records — best lifts and estimated one-rep maxes, calculated from your logged sets.
- Programs — training programs you create, clone, or follow, and your progress through them.
- Body measurements — only if you log them: body weight, body fat percentage, and tape measurements (chest, waist, hips, biceps, thighs, calves, neck).
We use this data for one purpose: showing you your training history, progress charts, and analytics. Training analytics — volume and workload trends and the rest — are computed from your own logged workouts.
Apple Health is optional and off by default. If you turn it on, each workout you finish on this device is saved to this device’s Apple Health as a strength training session: when it started, when it ended, and how long it took. We never write calories or any other health data. To avoid saving a duplicate, the app checks the times of workouts already in Apple Health, on this device only. Nothing it reads from Apple Health is stored or sent to us or anyone else. Your Health data is never used for advertising and never sold. Workouts already saved to Apple Health stay there if you turn this off or delete your account; remove them in the Health app.
Notifications
- Push tokens — if you enable notifications, we store the device push token needed to deliver them (via Apple’s and Expo’s push services). You control which notification types are on, per category, in settings.
Usage events
- Onboarding and app events — lightweight events like “screen viewed” or “onboarding completed,” tied to your account. We use these to find where the app confuses people, and fix it. This is our own database, not a third-party analytics company.
Crash and error diagnostics
Strength Almanac uses Sentry for crash and error reporting. When the app crashes or hits an unexpected error, Sentry receives a technical report: the error message and stack trace, a short label identifying the part of the app it came from, your device model and operating-system version, the app version and build, and the time it happened. We do not collect performance traces or screen-load timings. Sentry also sees the network address the report arrives from, as any internet service does.
We do not attach your name or email address to these reports, and your workouts, records, measurements and notes are never included. Crash reporting is part of the builds we distribute rather than something you switch on, because an app that crashes silently is one we cannot fix.
Purchases and subscriptions
Strength Almanac is a paid app. There is no ad-supported tier and no no-cost tier — the floor is Bronze at $1/month, and it includes the complete tracker. Higher tiers add cosmetic recognition and, at Gold, advanced training analytics.
Purchases are processed by Apple’s App Store, and RevenueCat is the service we use to record which tier you are entitled to and keep it in sync across your devices. RevenueCat receives your Strength Almanac account identifier — a random id, not your email — along with which product you bought and the status and dates of your subscription. It does not receive your training data.
We never see or store your card number, billing address, or full payment details. Apple handles the transaction. What reaches us, through RevenueCat, is a record of the purchase itself — which product, the price, and the transaction references and dates — and how long we keep it is described under Retention and deletion.
Records we keep to protect users
- Coach activity log — actions within a coaching relationship (comments added, suggestions made, relationship changes) are logged. Both parties can see this log. It exists so coaching stays accountable.
- Consent records — when you accept the coach or coachee terms, we record which version you accepted and when.
- Coaching agreements you withdraw. Before you can coach someone, or be coached, you have to agree to a short set of terms about what a coach can and cannot see. If you later withdraw that agreement, we keep the record of it — that you agreed, which version you agreed to, when you agreed, and when you withdrew. We do not delete it, and we do not currently set a time limit on how long we keep it. We keep it because the record exists to show what was agreed, and a record that can be erased by either side cannot do that — it also lets us settle a dispute about a coaching relationship fairly. The record holds an internal account identifier, the role, the version of the terms, and the two dates. It holds none of your training data. Withdrawing is not the same as deleting your account: if you delete your account, this record is removed with everything else.
- Abuse-prevention counters — things like invite-code lookup attempts are counted to rate-limit guessing attacks. Moderation reports you file, about coaches or community programs, are stored for our review.
- Email-change safety records — when you change your account email, we briefly keep the old and new address (up to 7 days) as an account-security safeguard.
Beta participation
- Beta cohort flag — while the app is in TestFlight beta, your account is marked as a beta participant. That is how we recognise early testers afterward, including the permanent Beta Founder badge. The flag is permanent; it contains no extra personal information.
- Feedback — if you email us or send feedback through TestFlight, we receive whatever you include. TestFlight feedback and screenshots travel through Apple; see Apple’s terms for how TestFlight itself handles data.
In-app feedback
The app has a built-in feedback form. When you send one, we receive what you wrote — a title, the details, and optionally steps to reproduce and a screenshot you choose to attach — plus some context captured automatically so a report is actionable without us having to ask you questions: your account id, your tier, the app version, the platform and OS version, your device model, and which screen you were on. That is the whole list. It is used to fix the thing you reported, and nothing else.
Location — coarse, and only if you allow it
Some achievements are about where you have trained. If you turn that on and grant permission, we record, on a completed workout, the country and the state or province you were in — for example US and US-TX.
We never store a coordinate. There is no latitude or longitude anywhere in our database, and there is no column to put one in. That is deliberate: for most people a gym address is close enough to a home address, and knowing you lifted in Texas does not require knowing where in Texas.
If you do not grant it, we do not infer it. Location-based achievements are simply disabled — we do not guess your country from your timezone, your IP address, or anything else, because working around a permission you declined is the same as ignoring it.
What we do not collect
No precise location — no coordinates, ever; see above for the coarse country/region data, which is optional and permission-gated. No contacts. No advertising identifiers. No third-party advertising or tracking SDKs. No Apple Health data stored on our servers. No card numbers or billing details.
Who can see your data
By default: only you. Every table in our database enforces row-level security — your workouts, records, measurements, and programs are readable only by your account.
There are exactly three ways anyone else sees your data, and all three start with an action you take.
1. Inviting a coach, or accepting a coachee
If you connect with a coach in the app, that coach can view your workouts, programs, personal records, training analytics, and body measurements for as long as the relationship is active. Two things to know:
- You can hide body measurements from your coach with the “Hide body measurements from coach” toggle — the rest of the sharing still works.
- You can revoke the relationship at any time, which immediately cuts off the coach’s access.
Coaches never get your password, email settings, or account controls — read access to training data only, plus the ability to comment and suggest program edits.
2. Publishing a program to the community
Publishing is always an explicit action. When you publish a program, its name, description, structure, and your display name become visible to other Strength Almanac users, along with upvote and clone counts. Your workout logs, records, and measurements are never included. If someone clones your program, your display name travels with it as attribution.
3. Reports and moderation
If a user reports a coach or a community program, a small number of administrators can view the report and the minimum related records needed to act on it — the reported program, say, or the coaching relationship’s activity log. Administrators can also view aggregated onboarding statistics. Admin moderation actions are themselves audit-logged.
We never sell your data, share it with advertisers, or hand it to third parties for their own purposes.
Where your data lives
Your data is stored in our backend, hosted on Supabase, in a United States region. Data is encrypted in transit. The service providers we rely on to run the app:
- Supabase — database, authentication, and backend hosting
- Expo and the Apple Push Notification service — delivering push notifications (device push tokens only)
- Sentry — crash and error diagnostics
- RevenueCat — subscription and entitlement management
- Apple — App Store distribution, purchases, and TestFlight beta feedback (governed by Apple’s terms)
These providers process data only to provide their service to us.
Retention and deletion
- Delete your account any time, in the app: Profile → Danger zone → Delete my account. Deletion starts a 7-day grace period during which you can restore everything just by signing back in. After 7 days, your account and its data are permanently and automatically purged. That includes the database backups we take: they are kept on a rolling 7-day cycle, so after those 7 days none of them holds your account. Our hosting provider also keeps its own daily backups of the database for seven days, so a deleted account can remain in one of those for up to about two weeks after you ask; they are used only to recover from a failure, and they expire on their own. There are three narrow exceptions, described next.
- Reports of abuse are kept, even after you delete. If another member reports your account for abuse, harassment, spam, or impersonation, we keep a record of that report — the reason given, what was written, and how it was resolved — and that record includes an internal identifier for the reported account so we can recognise repeat reports. It does not include your email or any of your training data, but it can include the display name the account had when the report or the moderation action was recorded. We keep it because a moderation record that disappeared along with the reported account would let the same behaviour start over unchecked. Apart from this record and the two described next, everything else described in this policy is removed when you delete.
- Subscription-consent evidence is kept, even after you delete. After account deletion, we retain limited subscription-consent evidence: when and how consent was given, the offer and wording accepted, the associated subscription or transaction reference, and the contract termination date. Where California's automatic-renewal law applies, we retain this evidence until the later of three years after consent or one year after contract termination. We retain only the identifying link necessary to associate the evidence with the relevant subscription. Access is restricted to compliance and dispute handling. We delete the evidence when its retention period ends, unless a specific legal obligation or documented legal hold requires longer retention. This retention does not include your body measurements or workout history. We apply this same schedule to every subscriber, not only where California's law applies.
- Purchase records are kept, even after you delete. Each time a subscription is bought, renewed, or changes status, RevenueCat sends us a record of it, and we keep that record after your account is deleted: your internal account identifier, which product it was, the price and currency, the store, the transaction references and dates, and the rest of the notice RevenueCat sent. It does not include your name, your email, or any of your training data. Our current practice is to keep these records for seven years, to meet tax and accounting obligations and to handle chargebacks, and then delete them. RevenueCat also keeps its own record of your purchases under the same account identifier; we do not currently ask RevenueCat to delete it when you delete your account.
- Dormant accounts: inactivity alone does not currently clear your profile or delete your training history. If your subscription lapses and the account then sits unopened, your display name, email address, bio and gym stay as you left them, your logged training is not deleted, and signing back in and resubscribing picks up where you left off.
- Email-change safety records expire after 7 days.
- Everything else is kept while your account exists, because it is your training history. That is the product.
You can also email us at the address below to request deletion or a copy of your data, and we will handle it.
Children
You must be at least 13 to have an account — or older, if your country sets a higher minimum age for digital consent. Strength Almanac is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has created an account, contact us and we will delete it.
Coach Mode — where another lifter can see and comment on your training — requires you to be 18 or older, or to have a parent or guardian's permission.
Changes to this policy
If we change what we collect or how we use it, we will update this page, change the effective date at the top, and — for anything meaningful — tell you inside the app before the change applies. We will not quietly move the goalposts.
Contact
Questions, deletion requests, or anything else:
Curious how the numbers in the app are calculated? That is documented too, on the Measurement Science pages.