Privacy · Updated August 26, 2026
Privacy Policy
TermsWho we are
This policy applies to the App for iOS and Android and its website at fitness.olaurent.com. Olaurent is responsible for the App and website. For privacy questions, contact email@olaurent.com.
What we collect
Only what the App needs to work:
- Account: an anonymous device identifier on first launch, and your email address and a salted password hash if you create an account. Your password is never stored in plain text.
- Training data: exercises you track, logged sets (weight, reps, side, timestamps), body weight snapshots, and the training splits you build.
- Profile answers: sex, age, height, body weight, experience level and goal — the inputs the level and projection math needs.
- Nutrition: meals and macros you log, plus the named-meal library those logs create.
- Physique scans: the scores a scan produces. See “Photos” below.
- Subscription state: the store transaction identifiers and entitlement status needed to know whether your subscription is active.
- Apple Ads attribution: whether an install came from an Apple ad and the campaign, ad group, and keyword identifiers needed to measure it.
- Advertising measurement: Meta and TikTok may receive selected product events, such as first-run onboarding completion or a completed subscription, to attribute and optimize our ads. We do not send them your email, workout contents, health profile, or subscription price.
- Referrals: your referral code, a one-way device or account identity code used to prevent duplicate and self-referrals, and an anonymous label or masked referred email shown to the referrer after a trial or qualifying purchase.
- Link clicks: when you open a referral or campaign link, we count the click on our own Cloudflare infrastructure — the code, the campaign it came from, and the page it landed on. No IP address is stored with it, no cross-site tracking cookie is set, and we never fingerprint your device or browser. Your browser keeps the code locally so the app can credit the right referrer; clearing site data removes it.
- Diagnostics: standard server request logs (IP address, timestamp, path) kept briefly for security and debugging.
- Connections: connection names, hashed connection credentials, granted permissions, token expiry, last use, and an audit trail of exercises or plans created through a connected AI service.
We do not collect contacts, precise location, or browsing activity. Advertising identifier access is disabled.
Photos
Photos are never stored on our servers. When you run a physique scan, identify a gym machine, or scan a meal, the image is sent to Cloudflare Workers AI for a single inference call and discarded when that call returns. We keep only the resulting scores, machine guesses, or macro suggestions. There is no image storage bucket.
The guided physique scan runs body and face detection entirely on your device, and those detections never leave it. If you choose to keep a copy of a scan photo, it is saved in the App's private storage on your device only, and deleting the App deletes it.
Why we use it
- To provide the App: store your sets, compute levels, readiness, records and projections, and sync them across your devices.
- To authenticate you and keep your data attached to the right account.
- To process and validate subscriptions.
- To measure Apple Ads performance and compare acquisition cost with subscription revenue.
- To attribute and optimize Meta and TikTok campaigns using a small set of product events.
- To attribute paid referrals, count referral and campaign link clicks, and prevent referral fraud.
- To generate the coach's wording and scan results via AI inference.
- To keep the service secure and diagnose failures.
- To let an AI service you connect read the SET data you authorize and create exercises or plans you approve.
We do not use your data to train AI models or sell it. Meta and TikTok process the limited advertising events described above under their own privacy terms.
Who processes it
A short list of processors, each doing one job:
- Cloudflare — hosting, database (D1), transactional login email, and Workers AI inference.
- PostHog — product analytics and crash reports, hosted at q.olaurent.com. Events are tied to an anonymous install until you create an account.
- Apple / Google / Stripe — payment processing and subscription management. We never see full card details; they share transaction and entitlement state.
- Meta and TikTok — advertising attribution and campaign optimization using limited App events. Automatic payment and interface-event collection is disabled.
- AI services you connect, such as ChatGPT — receive the training and body data requested through the connection. Their handling of that data is governed by their own terms and privacy policy. Disconnect the service in Settings to stop future access.
Where it lives, and how long
Your data is stored in Cloudflare's global network and may be processed in the United States and other regions where Cloudflare operates. We keep your training data for as long as your account exists, because its whole value is the history. Server request logs are retained for a short operational window. Delete your account and we delete your rows.
Your choices
- Access or export: in the App, Settings → Account → Download all data files a request; after approval you can save a JSON export of your training rows (credentials and billing excluded). You can also email us.
- Deletion: delete your account from Settings → Access & data → Delete account, or email us. Deletion is immediate and removes your account, login records, training, splits, nutrition and scan rows; it cannot be undone. Purchase records are retained where tax law requires. Full detail at /delete-account.
- Correction: edit or delete any set, meal or scan in the App at any time.
- Notifications and permissions: camera, photos and notification access are all optional and revocable in system settings — the App degrades rather than blocks.
Depending on where you live, you may also have rights to object to or restrict processing, or to lodge a complaint with your data protection authority. Email email@olaurent.com and we will answer within 30 days.
Children
The App is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has used the App, contact us and we will remove the account.
Changes
If this policy changes materially we will update the date at the top of this page and, where the change is significant, tell you in the App before it takes effect.
Support
email@olaurent.com