Isofit Privacy Policy
Version: 1.1 Effective Date: [Insert Date] Data Controller: [Your Legal Entity Name] Contact Email: privacy@isofit.app Governing Frameworks: CCPA (California) | GDPR (EU, where applicable)
Your Privacy Matters to Us
Isofit processes personal data including workout logs, health and fitness information, AI coaching conversations, and social interactions. We take our responsibility to protect this data seriously.
This Privacy Policy explains what data we collect, why we collect it, how we use it, who we share it with, and what your rights are.
We do not sell personal information. We do not share your individual health or fitness data with advertisers.
1. Who We Are and How to Contact Us
Isofit is a fitness platform providing AI-powered coaching, workout logging, a community social layer, and a rewards economy through a native iOS application and web services at isofit.app.
For any privacy-related questions, concerns, or requests:
- Privacy Contact: privacy@isofit.app
- General Support: ops@isofit.app
2. What Personal Data We Collect
We collect the minimum data necessary to provide our services. The data we collect falls into the following categories.
2.1 Data You Provide Directly
- Account and Identity Data: First name, last name, email address, phone number, username, display name, avatar image, and bio. Collected during account creation and profile setup.
- Preferences and Settings: Timezone, measurement units (imperial or metric), default post visibility, notification preferences, and feature toggles such as Atlas AI opt-in.
- Workout and Training Data: Activity sessions, exercises performed, sets, reps, weight, RPE (Rate of Perceived Exertion), session notes, and freeform quick logs entered via text or voice.
- Atlas AI Conversations: Messages you send to Atlas (our AI coach), including text messages, images submitted for form checks, and any voice transcriptions. If you opt in to Atlas personalization, Atlas also stores persistent memory items it learns about you over time — such as your goals, injuries, and preferences.
- Bonfire Community Content: Posts, comments, reactions, and media (photos and videos) you share in Bonfire, our community feed. Includes your chosen Bonfire nickname.
- Music Preferences: If you connect a music service, your platform connection details, session tracks played during workouts, and any pinned "listening to" track on your profile.
- Payment Information: Billing details are processed securely through Stripe. Isofit does not store your credit card number, CVV, or full card details on our servers.
- Communications Data: Messages you send to our support team and feedback you provide.
2.2 Data Generated by Your Use of the Platform
- $ISO Economy Data: Your in-app currency balance, transaction ledger (earning, spending, and redemptions), streak history, and reward tier status. This data is generated automatically as you log workouts, maintain streaks, and interact with the platform.
- Training Analytics: Muscle group frequency data, personal records, training volume trends, and insights synthesized from your workout history.
- Usage Data: Login events, features accessed, session duration, and app interaction patterns.
- Technical Data: Device type, operating system version, IP address, and push notification tokens. Used for delivering notifications and maintaining platform security.
- Moderation Data: If your Bonfire content is flagged or reported, moderation records are generated. These are not visible to other members.
2.3 Data Collected Through ISO Sync (Optional Add-On)
If you subscribe to ISO Sync and connect external platforms, we collect fitness and health data from those services — only with your express permission, granted when you connect each platform:
- Apple Health (via HealthKit): Workouts, steps, heart rate, sleep data, body metrics, and VO2 max. See Section 5 for how we handle HealthKit data specifically.
- Strava: Activities, routes, heart rate zones, power data, and training load.
- Fitbit: Activities, steps, heart rate, sleep stages, SpO2, and stress scores.
- Garmin: Activities, sleep data, body composition, stress, and pulse oximetry.
You can disconnect any platform at any time.
2.4 Data We Do NOT Collect
We do not collect or store:
- Your precise GPS location (Isofit is not a location-based service).
- Data from your contacts, calendar, or camera roll unless you explicitly choose to upload a photo or video.
- Financial data beyond what Stripe processes for billing.
- Social media data from platforms you have not explicitly connected.
3. How and Why We Use Your Data
We process your data only where we have a valid basis. The purposes are as follows.
- Provide workout logging and training analytics. Your workout data, quick logs, and training history are the core of the Isofit experience. Without this data, the app cannot function.
- Deliver Atlas AI coaching. When you message Atlas, your recent workout history, training insights, and profile data are included as context so Atlas can provide personalized coaching. If you opt in to personalization, Atlas also draws on persistent memory items it has built from prior conversations.
- Operate the $ISO economy. Your workout logs, streak activity, and membership tier determine your $ISO earnings. Spending, redemptions, and balance tracking require ledger data.
- Power the Bonfire community. Posts, comments, reactions, and media you share are displayed to other members. Moderation systems process content to maintain community standards.
- Generate cross-platform insights (ISO Sync). With your express permission, data from your connected platforms is processed by frontier AI models to generate a unified training analysis — including training load trends, recovery scores, sleep quality, and cross-platform insights. This data is never used to train those models.
- Process payments. Stripe processes your subscription and billing data to manage your membership.
- Send notifications. Push notification tokens are used to send you streak reminders, reward alerts, social notifications, and system messages via Apple Push Notification service.
- Send transactional emails. Your email address is used for account-related communications such as billing confirmations and referral notifications.
- Maintain platform security. Technical data and login events are used for fraud detection, abuse prevention, and security monitoring.
- Improve the platform. Aggregated, de-identified usage patterns help us understand how features are used and where to focus development.
4. Atlas AI and Your Data
This section describes how your personal data interacts with the Atlas AI coaching system.
4.1 What Atlas Receives About You
When you interact with Atlas, the following data is provided to the AI system to generate responses:
- Your profile context: Membership tier, current streak, $ISO balance.
- Training insights: Muscle group activity data from your workout history (frequency, volume, last trained date, average RPE per muscle group).
- Recent workout logs: Your last 30 days of structured workout data, including exercises, sets, reps, and weights.
- Conversation history: Recent messages from your current Atlas thread for conversational continuity.
- Your current message: The text, image, or voice transcription you send.
- Memory items (if opted in): Persistent facts Atlas has learned about you — such as goals, injuries, and preferences — drawn from prior conversations.
4.2 How Atlas Uses Your Data
- Model routing: Your message content and attachments determine which AI model processes your request. Simple questions are handled by a lighter model; form checks, injury-related queries, and deep analysis requests are routed to a more capable model. This routing is handled automatically.
- Form checks: If you submit an image or video for form analysis, it is processed by a vision-capable AI model to generate feedback.
- Memory building: If you have opted in to personalization, Atlas analyzes your conversations after extended exchanges to extract persistent facts. These memory items are stored in your account and used to improve future coaching.
4.3 AI and Automated Decision-Making
Atlas does not make decisions that produce legal or similarly significant effects on you. Atlas provides fitness coaching suggestions only. No training plan, exercise recommendation, or form feedback constitutes medical advice, and Atlas is not a substitute for professional medical or fitness guidance.
4.4 Withdrawing Consent for Atlas Personalization
You can withdraw consent for Atlas memory at any time by toggling off the personalization setting in your account. Doing so will delete your stored Atlas memory items. Withdrawal does not affect messages already sent or coaching already delivered.
5. Apple Health and HealthKit Data
Isofit accesses Apple Health data only if you subscribe to ISO Sync and grant permission through the standard iOS HealthKit authorization flow. We treat HealthKit data with special care:
- Express permission first. Before you enroll in ISO Sync, we ask for your express permission to collect your HealthKit data and process it through frontier AI models to generate your personal synthesis reports. You will see exactly which data types are requested in the iOS permission screen, and you can grant or deny each one individually.
- Purpose limitation. HealthKit data is used solely to provide ISO Sync features for you — sync, display, and synthesis of your own training and recovery insights.
- No advertising or data mining. We do not use HealthKit data for advertising, marketing, or use-based data mining, and we do not sell it or disclose it to third parties for those purposes.
- No AI training. Your HealthKit data is never used to train AI models. It is processed by frontier AI models only to generate your reports, under terms that prohibit the model provider from training on it.
- No disclosure without permission. We do not disclose your HealthKit data to any third party without your express permission.
- Revocable at any time. You can revoke HealthKit access at any time through iOS Settings (Privacy & Security → Health) or by disconnecting Apple Health within the app. Revoking access stops future syncs; previously synced data follows the retention rules in Section 8.
6. Who We Share Your Data With
6.1 Other Isofit Members
Your Bonfire posts, comments, reactions, profile information (display name, avatar, bio, nickname), and leaderboard position are visible to other members according to your visibility settings. Your workout data is private by default unless you explicitly change your visibility setting.
The Online Now counter displays an anonymous count of active members — no individual identity is exposed.
6.2 Isofit Business Partners
If you redeem an ISO Gravy reward with a partner merchant, the merchant receives only the information necessary to fulfill the redemption (for example, a verified promo code). Partners do not receive your workout data, AI conversations, health data, or $ISO balance.
6.3 Technology Service Providers
We use the following service providers to deliver Isofit. All are bound by their respective data processing terms.
- Supabase: Backend infrastructure, database hosting, user authentication, and real-time features.
- Stripe: Payment processing. Handles all credit card data directly; Isofit servers never see or store your full card number. Stripe is PCI-DSS Level 1 compliant.
- OpenAI: Processes Atlas AI coaching requests. Your message content and training context are sent to OpenAI's API to generate responses. Under OpenAI's API terms, data submitted through the API is not used to train OpenAI's models by default; Isofit does not opt in to any such data sharing.
- Frontier AI model providers (ISO Sync synthesis): With your express permission obtained at ISO Sync enrollment, your synced fitness and health data is processed by frontier AI models solely to generate your synthesis reports. This data is never used to train those models.
- Google (Gemini): Processes playlist recommendation requests. Song context and workout type are sent to generate music suggestions.
- Resend: Delivers transactional emails. Receives your email address only.
- Apple Push Notification service (APNs): Delivers push notifications to your iOS device. Receives a device-specific push token, not your personal information.
- Strava, Fitbit, Garmin (ISO Sync only): If you connect these platforms, data flows between Isofit and the connected platform via authenticated APIs. Each platform's own privacy policy governs data on their side.
- Spotify, Apple Music (Music integration only): If you connect a music service, authentication tokens are exchanged to enable track display and playlist recommendations. Isofit does not access your music library or playlists beyond what is needed for the connected features.
6.4 Legal and Regulatory Disclosures
We may disclose your data where required by law, court order, or regulatory authority. We will notify you of any such disclosure unless prohibited by law.
6.5 We Do Not Sell Your Data
Isofit does not sell, rent, or trade your personal information to any third party. We do not use your data for advertising or allow third-party advertisers to access your data. We do not use your fitness or health data to train AI models.
7. Your Consent Controls
Isofit provides granular consent controls accessible in your account settings:
- Operational consent (on by default): Required for the app to function. Covers core workout logging, $ISO economy, and account management.
- Personalization consent (off by default): Controls whether Atlas AI can build and retain persistent memory items from your conversations. When off, Atlas still works but does not remember information between sessions.
- Third-party data sharing consent (off by default): Reserved for future partnership integrations. Currently not active.
In addition, ISO Sync requires its own express permission flow before any HealthKit or external platform data is collected (see Section 5).
You can change these settings at any time. Changes take effect immediately.
8. Data Retention
We retain your data only for as long as necessary to provide the service or as required by law.
- Active account data (profile, settings, workout logs, Atlas threads, $ISO ledger): Retained for the duration of your active use of Isofit.
- Atlas memory items: Retained while personalization consent is active. Deleted when you withdraw consent or close your account.
- Bonfire posts and comments: Retained while your account is active. Content deleted by you or by moderation is removed according to our data cleanup schedule.
- ISO Sync data: Retained while the ISO Sync subscription is active. After cancellation, synced data is retained for 90 days, then permanently purged by an automated cleanup process. Reactivation after purge requires reconnecting your external platforms.
- Payment and billing records: Retained as required by applicable financial regulations (typically up to 7 years).
- Security and audit logs: Retained for a limited period for security and compliance purposes, then purged.
- Account deletion: When you delete your account, your personal data is deleted. Anonymized, aggregated data that cannot identify you may be retained for platform analytics.
9. Data Security
We use reasonable administrative, technical, and organizational safeguards to protect your personal information, including industry-standard encryption of data in transit and at rest. Payment processing is handled entirely by Stripe, so your full card details never touch our servers.
No method of transmission or storage is 100% secure, but we take security seriously and review our practices regularly.
If you discover a potential security vulnerability, please report it to privacy@isofit.app.
10. Membership Cancellation and Account Deletion
Canceling your membership restricts access to paid features but does not delete your account or your personal data. To delete your personal data, request account deletion through your account settings or by contacting privacy@isofit.app.
If you cancel an ISO Sync subscription, your synced platform data follows the 90-day retention schedule described in Section 8.
11. Children's Privacy
Isofit is not intended for individuals under 18 years of age. We do not knowingly collect personal information from minors. If you believe a minor has created an account or provided us with personal information, please contact privacy@isofit.app immediately and we will delete such data.
12. Cookies and Tracking
The Isofit iOS app does not use browser cookies. The Isofit web services at isofit.app use only essential cookies necessary for authentication and session management. We do not use advertising cookies, tracking pixels, or third-party analytics that share your data with advertisers.
13. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data. To exercise any right, contact privacy@isofit.app.
- Access: Request a copy of the personal data we hold about you, including your workout logs, Atlas conversations, and $ISO ledger history.
- Correction: Request correction of any inaccurate data we hold about you, either through your account settings or by contacting us.
- Deletion: Request deletion of your personal data. Note that some records may be subject to legal retention requirements.
- Data Portability: Request your personal data in a structured, machine-readable format.
- Withdraw Consent: Withdraw any consent you have given at any time, including consent for Atlas personalization and ISO Sync data collection. Effective for future processing.
- Opt Out of Sale (CCPA): We do not sell personal information, so there is nothing to opt out of. If this changes, we will provide a clear mechanism.
- Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
We will respond to verified requests within 30 days (or sooner where required by law).
14. International Data Transfers
Isofit's backend infrastructure is hosted by Supabase. Your data may be transferred to and processed in countries other than your country of residence. Where such transfers occur, we ensure appropriate safeguards are in place, including compliance with applicable data transfer mechanisms under GDPR (such as Standard Contractual Clauses) where required.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification, and we will update the "Effective Date" at the top of this document. Your continued use of Isofit after notification of changes constitutes acceptance of the updated Privacy Policy.
16. Contact Us
For any questions, concerns, or requests relating to this Privacy Policy or your personal data:
- Privacy Contact: privacy@isofit.app
- General Support: ops@isofit.app
- Website: https://isofit.app
If you are a California resident, you may have additional rights under the CCPA. If you are located in the EEA, you may lodge a complaint with your local EU data protection authority.
End of Privacy Policy | Isofit | v1.1 | [Insert Date]