ProgressPilot ProgressPilot
Features Pricing Support App Store

Privacy Policy

Effective date: October 2, 2026

This Privacy Policy explains what data we collect, how we use it, and your rights under the General Data Protection Regulation (GDPR) and other applicable data protection laws.

The short version: ProgressPilot is local-first. Your workout data stays on your device and your personal iCloud account. When you use an AI feature, only the data that feature needs is sent to our AI provider for that request. We don’t use third-party analytics, don’t serve ads, and don’t track your behavior across apps or websites.

1. Controller

ProgressPilot is an independent app developed and operated from Finland (EU). The controller for personal data processed in connection with the app is the operator of ProgressPilot.

The primary point of contact for all privacy matters is:

Email: [email protected]

If you require a postal address or registered business identifier in connection with a formal data-protection request (for example, a complaint to a supervisory authority), please contact us at the email above and we will provide the relevant details for your request.

If you have questions about this Privacy Policy or want to exercise your privacy rights, contact us using the email above.

2. Legal Bases for Processing

We process personal data only where we have a valid legal basis under applicable data protection law. Depending on the feature you use, these legal bases may include:

Processing ActivityLegal Basis
Account authenticationPerformance of a contract
Subscription and Custom Program purchase managementPerformance of a contract; compliance with legal obligations for financial/accounting records where applicable
AI coaching requests (including Ask Coach and Custom Program design)Performance of a contract
HealthKit reads and writes, including sending sleep and heart readings to the AI coachYour explicit consent (GDPR Art. 9(2)(a)), given through Apple’s permission screen and the in-app switch for each use
Operating and securing the service (rate limits, short-lived locks, aggregate usage counters, short-lived logs)Legitimate interests in keeping the service reliable, affordable, and free of abuse
Abuse prevention by our AI provider (a pseudonymous account tag sent with each AI request, see §3.3)Legitimate interests in preventing misuse of the AI service and keeping one account’s misuse from affecting everyone else’s access
Support communicationsLegitimate interests in providing support and maintaining service quality; performance of a contract where the request relates to your use of the app
Local notificationsGenerated on-device at your request through app settings; where personal data is processed by us for this feature, we rely on your consent/request

3. Data We Collect

3.1 Account Data

When you sign in with Apple, Google, or an email address and password, we use Firebase Authentication to create a unique account identifier (Auth UID). This UID is used to authenticate AI requests and manage your subscription and purchases. Your name, email address, and profile photo (when provided by Apple Sign-In or Google Sign-In, or the email address you register with) are held by Firebase Authentication on Google’s infrastructure under our Firebase project; we can view this information through the Firebase Console for support and account-management purposes. We do not store this data in our own application database, in your CloudKit container, or in our Cloudflare Worker.

  • What: Firebase Auth UID, authentication provider (Apple, Google, or email)
  • Where stored: Firebase Authentication (Google Cloud infrastructure)
  • Retention: Until you delete your account

3.2 Workout Data

All training data you enter — sessions, exercises, sets, reps, weights, Performance Index scores, personal records, saved routines, custom exercises you create, exercise notes, your pre-session check-ins (energy, soreness, time available, and the readiness level they produced), your coach’s saved preferences about you, your Ask Coach conversations, any Custom Program you buy (your intake answers, including any free-text notes and known lifts, the program itself, and the App Store transaction ID of the purchase), and your profile (goals, equipment, fitness level, age, sex, optional body weight, movement limitations) — is stored on your device using Apple’s SwiftData framework. Ask Coach conversations are pruned automatically after 90 days or 200 messages. Devices upgraded from an earlier version may also still hold historical weekly programs and weekly reviews created before the app moved to designing one session at a time; these are kept so your history stays readable and are no longer added to.

If iCloud is enabled on your device, this data syncs to your personal iCloud account via Apple CloudKit. This sync is between your own devices through your own Apple ID.

We do not store your workout history in our own application database. Limited account, subscription, purchase, and infrastructure data are processed by the service providers described below.

  • What: Training sessions, sets, reps, weights, PI scores, personal records, saved routines, custom exercises, exercise notes, check-ins, coach preferences, Ask Coach conversations, Custom Programs, user profile (plus historical weekly programs and reviews on upgraded devices)
  • Where stored: On your device (SwiftData) + your iCloud account (CloudKit), if enabled

3.3 AI Coaching Requests

When you use AI features — designing a session on demand, building a custom workout, suggesting an exercise swap, suggesting an extra exercise when you finish a session’s plan with energy to spare, generating a warm-up or cool-down, the pre-session briefing, the post-session summary (including optional training fuel tips), the Coach Summary, the Coach Check-In, the weekly recap, Ask Coach, or designing, revising, or adjusting a Custom Program — the app sends only the workout and profile fields needed to generate that specific coaching response.

Examples of fields that may be included, depending on the feature, are: exercise names (including the names of custom exercises you create), sets, reps, weights, Performance Index scores, equipment access / gym tier, training goal, fitness level, age, sex, how often you train, session length, readiness/soreness feedback, the preferences your coach has saved about you, and training constraints you choose to provide in the app (such as movement limitations, avoided movements, or areas you have listed under Limitations).

Because your coach designs each session from your history rather than from a stored plan, a request may also include a summary of your recent training — recent sessions in detail (roughly the last three weeks), and aggregate weekly training volume across a window of up to 16 weeks. These are summaries of the workout data described in §3.2, not additional categories of data.

Text you write. Some features send text you type: your Ask Coach question together with the last few messages of the conversation, the optional “anything I should know?” note in the workout builder, soreness notes at check-in, post-session notes, Limitations notes, and the free-text answers and revision requests in the Custom Program intake. Each is length-limited and sent only with the request it belongs to.

Special category data. Apple Health readings (see §3.5) and free text you enter in fields like Limitations notes or soreness notes may qualify as health data (special category data) under the GDPR. You decide what to enter and which Apple Health switches to turn on. We rely on your explicit consent — given by turning on the relevant switch, or by entering and saving the information — to include it in AI coaching requests so the coach can adapt your training to your situation. You can remove or change these entries, or turn the switches off, at any time in the app.

We do not intentionally include your name, email address, photos, precise location, advertising identifiers, or contacts in AI prompts, and we do not include the body weight you may have entered in the app, nor do we read body weight from Apple Health at all. Training volume totals may be included; for bodyweight exercises they are calculated on your device from that body weight (see §3.5). Apple Health cardio summaries and, when you turn it on, sleep and heart readings may be included as described in §3.5.

  • How: Sent via encrypted HTTPS to our Cloudflare Worker proxy, which forwards the request through Cloudflare AI Gateway to the OpenAI API. The gateway is configured not to log request or response content; it records only metadata such as the feature, token counts, latency, and a pseudonymous account tag.
  • Account tag: Each request forwarded to OpenAI carries a pseudonymous account tag — a one-way hash of your Firebase Auth UID, never the UID itself, your name, or your email address — so that OpenAI’s abuse monitoring can attribute misuse to a single account rather than to the app as a whole.
  • Retention: We do not store full AI prompt history in our own application database, and the proxy does not log prompt content. The proxy stores limited operational data, listed in §8. One exception concerns AI output: a newly designed Custom Program is held by the proxy for up to 24 hours so a paid generation is not lost if your connection drops before it reaches your device. Our service providers may retain limited request data for security, abuse prevention, and service integrity purposes under their own contractual terms and policies. OpenAI processes requests under their API Data Usage Policy; API inputs and outputs are not used by OpenAI to train its models by default.

No solely automated decisions with legal or similarly significant effects (GDPR Art. 22). AI-designed sessions, targets, and coaching notes are suggestions for guidance only. You remain in full control of your training and can edit, skip, swap, or override any AI-generated exercise, weight, rep, or set at any time. The app does not use these outputs to make decisions that produce legal or similarly significant effects about you.

3.4 Subscription and Purchase Data

Your subscription and any Custom Program purchase are processed by Apple and managed through RevenueCat. We check your subscription status to determine whether you have access to premium features, and your purchase history to determine how many Custom Programs you have bought.

  • What: Subscription status (active, expired, trial), subscription tier (monthly/annual), expiration date, and Custom Program purchases
  • Where stored: RevenueCat servers, linked by your Firebase Auth UID (not your name or email)

Custom Program purchase record. So that a one-time purchase is honored exactly once and never lost, our Cloudflare Worker keeps a small record linked to your Firebase Auth UID: how many Custom Programs you have redeemed, when your current program was generated, and how many of its included revisions you have used. It contains no training data, no intake answers, and no payment details, and it does not expire on its own — see §7 and §8.

3.5 Health Data (Apple HealthKit)

HealthKit access is entirely opt-in and requires your explicit permission through Apple’s permission controls. Inside the app, Settings → Apple Health has three independent switches — “Save workouts to Apple Health”, “Use my cardio for coaching”, and “Use my sleep and heart data for coaching”. The first time you turn one on, iOS shows a single permission screen covering every data type the app can use; the app reads a type only while the switch that needs it is on.

  • What we read (cardio): Your workouts, from which we keep recent cardio sessions (running, cycling, swimming, walking, hiking, rowing, elliptical, stair climbing), with their walking/running, cycling, or swimming distance. Apple does not let apps limit a workout permission to particular activity types, so other workouts — including strength sessions logged elsewhere — are read and discarded unread.
  • What we read (sleep and heart): Last night’s sleep (total time asleep between the previous evening and midday), your most recent heart rate variability (SDNN) reading and its average over the past 7 days, and your most recent resting heart rate. The app uses these to show the Recovery & Readiness card on Home and to inform the session your coach designs.
  • What we keep: Sleep, heart rate variability, and resting heart rate values are never saved to your sessions, synced to iCloud, or written to the app’s on-device event log. A session keeps only the readiness level they produced (Ready, Moderate, or Take it easier).
  • What we write: Completed strength training workouts with their duration (capped at three hours, so an abandoned session cannot be recorded as a multi-hour workout), plus an active-energy estimate when you have entered a body weight in the app. The estimate is calculated on your device and is flagged in Apple Health as user-entered rather than measured.
  • Body weight: We do not read body weight from Apple Health. You can optionally enter a body weight in the app (Settings → Training Profile → About you); it is stored on your device, syncs only through your own iCloud account, is never transmitted to our servers or to OpenAI, and is used for two things on your device: estimating the calorie figure attached to workouts we write back to Apple Health, and counting the share of your body you lift in bodyweight exercises (push-ups, pull-ups and the like) toward your training volume. Volume totals that include it can be part of an AI request; the weight itself never is. Leave it unset and those workouts carry no calorie figure, and bodyweight exercises add no volume.
  • Cardio summaries: When you use AI coaching features, summary fields from up to five recent Apple Health cardio workouts (activity type, duration, distance, and a relative recency such as “2 days ago” — never an absolute date) may be included as context in the prompt sent to our Cloudflare Worker and forwarded to OpenAI. This allows the AI coach to balance your strength training against recent cross-training. Cardio summaries are processed transiently for that request and are not retained outside the request lifecycle. If you do not want this data sent, turn off “Use my cardio for coaching” in Settings → Apple Health — that switch alone stops the reading and the sending, and leaves saving your workouts to Apple Health unaffected. You can also deny or revoke HealthKit access in iOS Settings. The rest of the app continues to work either way.
  • Sleep and heart readings in AI requests: When the sleep and heart switch is on and the coach designs a session after your pre-session check-in, the request sent to our Cloudflare Worker and forwarded to OpenAI includes last night’s sleep in hours, your latest heart rate variability with its percentage difference from your 7-day average, and your latest resting heart rate. Other AI features receive only the derived readiness level, never the readings. The readings are processed for that request and are not retained by our proxy. Turning off “Use my sleep and heart data for coaching” stops both the reading and the sending.
  • Revocation: You can revoke HealthKit permissions at any time in iOS Settings > Privacy & Security > Health, and turn each switch off independently in Settings → Apple Health inside the app.
  • Deletion: Workouts we have written into Apple Health are your own health record and stay in the Health app when you delete your ProgressPilot account, unless you turn on “Also delete Apple Health workouts” in Settings → Danger Zone before deleting. You can always remove them yourself in the Health app under Browse → Workouts.

We do not use HealthKit data for advertising, marketing profiling, or data brokerage. We do not sell HealthKit data. The only third-party disclosure of HealthKit-derived data is the transient inclusion, in AI coaching requests forwarded to OpenAI as described above, of cardio summaries (activity type, duration, distance, and a relative recency) and — when you turn it on — sleep and heart readings. Turning on the relevant switch in the app constitutes your explicit consent to that processing; you can withdraw it at any time by turning the switch off or by denying or revoking HealthKit access.

The Health app and the underlying HealthKit data store are operated by Apple on your device under Apple’s own platform and privacy terms. Your permissions and what Apple does with Health data sit outside the scope of this policy.

3.6 Push Notifications

If you enable notifications, the app schedules local notifications for training-day reminders, streak-at-risk alerts, and the weekly recap. All notifications are scheduled on your device; for premium members, the weekly recap text is written by the AI coach as described in §3.3. We do not operate a server-side push notification system.

4. Data We Do NOT Collect

  • No third-party analytics (Firebase Analytics is explicitly disabled in our app configuration)
  • No ad tracking or advertising identifiers
  • No crash-reporting SDK
  • No location data
  • No third-party SDKs that collect behavioral data
  • No App Tracking Transparency prompt (because we do not track)

Two things that are sometimes called analytics, for completeness: the app keeps a small log of in-app events on your device to help diagnose problems — the app never sends it off your device, and it is kept there until you reset your data or delete your account, which erase it. And our proxy keeps aggregate, per-feature counters (for example, how many requests a feature received, how many succeeded, and how long they took) that contain no account identifier; see §8.

5. Third-Party Services

We use the following third-party services in clearly defined roles:

ProviderPurposeRole
Firebase Authentication (Google) Sign-in and account authentication Service provider (processor)
OpenAI AI coaching request processing Service provider (processor)
RevenueCat Subscription and in-app purchase management Service provider (processor)
Cloudflare Website hosting; the AI proxy (Workers), its operational storage (KV), AI Gateway, and exercise-video hosting (R2) Service provider (processor)
Google Sign-In Sign-in with a Google account, if you choose it Service provider (processor)
Apple CloudKit / iCloud User-controlled sync between user’s devices Apple acts under its own platform terms

6. International Data Transfers

ProgressPilot is operated from Finland (EU). Some service providers we use may process personal data outside the European Economic Area, including in the United States.

Where required, we rely on appropriate safeguards under applicable data protection law, such as the European Commission’s Standard Contractual Clauses (SCCs) and/or other lawful transfer mechanisms made available under our data-processing agreements with those providers.

  • Firebase Authentication (Google) — authentication data may be processed in the United States or other regions Google operates in.
  • OpenAI — AI request content may be processed in the United States.
  • RevenueCat — subscription and purchase data may be processed in the United States.
  • Cloudflare — AI requests, the operational data listed in §8, and video requests pass through Cloudflare’s global network and may be processed in the United States or other regions Cloudflare operates in.
  • Your workout data remains on your device and in your personal iCloud account (Apple infrastructure), subject to Apple’s own platform and privacy terms.

You may contact us if you would like more information about the safeguards relevant to a specific transfer.

7. Your Rights (GDPR)

As a user in the European Economic Area, you have the following rights:

  • Right of access: Request a copy of the data we hold about you
  • Right to rectification: Correct any inaccurate personal data
  • Right to erasure: Delete your account and all associated data
  • Right to data portability: Request a copy of personal data you provided to us in a structured, commonly used, machine-readable format. All users — free or premium — can exercise this right by contacting [email protected]. Every user can also export a complete JSON copy of their training data in the app (Settings → Data → Export Data), and premium subscribers can additionally export a CSV of their sessions; these are self-serve conveniences and are not a condition of your portability right.
  • Right to restriction of processing: Request that we limit how we use your data
  • Right to object: Object to the processing of your data
  • Right to withdraw consent: Turn off any Apple Health switch in Settings → Apple Health, or revoke HealthKit access or notification permissions at any time via iOS Settings

Exercising Your Rights

To exercise any of these rights, contact us at [email protected].

We may need to verify your identity before completing a request. We aim to respond within one month, subject to extensions permitted by applicable law. In some cases, we may need to retain limited information where required for legal, accounting, fraud-prevention, or security reasons.

You can initiate account deletion directly in the app under Settings → Danger Zone → Delete Account. After you confirm your identity by signing in again, the app revokes its Sign in with Apple access (if you use Apple sign-in), deletes your Firebase account, revokes its access to your Google account (if you use Google sign-in; if that last step fails, for example because you are offline, you can remove ProgressPilot from your Google account’s third-party access settings yourself), and erases your ProgressPilot data on the device and in your iCloud copy. Two things are not removed automatically: the Custom Program purchase record on our proxy (§3.4), which we delete when you email us, and records RevenueCat keeps for accounting and legal purposes (§8). Contacting support is optional if you need additional help or believe some associated data still remains.

You also have the right to lodge a complaint with the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), Finland’s supervisory authority: tietosuoja.fi.

8. Data Retention

  • Workout data: Stored on your device indefinitely until you delete it or delete your account
  • Firebase Auth: Retained until you request account deletion
  • RevenueCat: Subscription history retained per RevenueCat’s policy for accounting and legal purposes
  • Ask Coach conversations: On your device and in your iCloud copy, pruned automatically after 90 days or 200 messages, whichever comes first
  • AI requests: Full prompt history is not retained by our proxy. Subject to third-party provider retention policies for security and abuse monitoring
  • Operational data on our proxy (Cloudflare KV), keyed to your Firebase Auth UID: entitlement cache entries (60 seconds for non-premium, up to 1 hour for premium), per-day rate-limit counters (up to 24 hours), the Coach Check-In weekly cooldown (7 days), the one-time onboarding allowance marker (up to 90 days), a newly generated Custom Program awaiting delivery (up to 24 hours), short-lived locks that stop the same request from being processed twice (a Custom Program generation lock of 180 seconds, an onboarding lock of 120 seconds, and a 60-second marker that limits how often your purchases are re-checked with RevenueCat), and the Custom Program purchase record (kept until you ask us to delete it, because it is what proves a purchase has or has not been used)
  • Aggregate usage counters: per-feature, per-day totals with no account identifier, kept for 35 days
  • Proxy logs: short-lived operational logs kept by Cloudflare under its log-retention settings; they carry a pseudonymous account tag (a one-way hash, never your UID, name, or email) and never the content of your requests or of the coach’s replies

9. Website Data, Cookies & Local Storage

Our website does not use advertising cookies or third-party analytics tools for behavioral tracking.

Like most websites, our hosting and infrastructure providers may process limited technical information such as IP addresses, request metadata, and security logs to deliver the website, prevent abuse, and maintain service reliability. We do not use this information to build advertising profiles.

We do not use analytics or advertising cookies on this website. Our hosting or infrastructure providers may set strictly necessary technical cookies in limited cases (for example, to deliver a secure connection).

Cookies and local storage (ePrivacy). We do not use tracking cookies on this website. Any browser cookies or local-storage entries we use are strictly necessary for the site to work (for example, remembering that you expanded a section). No consent banner is shown because no non-essential cookies are set.

If you contact us by email, we process the information you provide to respond to your request.

10. Children’s Privacy

ProgressPilot is not directed at children under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided data to us, please contact us and we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date at the top of this page and, when the change comes with an app update, summarise it in that version’s App Store release notes (“What’s New”).

12. Contact

For privacy inquiries or to exercise your GDPR rights:

Email: [email protected]

Privacy Policy Privacy Choices Terms of Service Support

© 2026 ProgressPilot. Made in Finland.