Effective date: 4/8/2026 · Version 1.0 · English
PRIVACY POLICY
StrongKit works fully without an account. Until you sign in, your profile and training history exist only on your device.
We do not sell your personal information, and we do not share it with advertisers or data brokers.
You can export everything you have logged as a file you keep, at any time, from You → Data & privacy.
You can permanently delete everything from the same screen
Answers you give about injuries or areas to work around are used only to choose safer exercises. They are never a diagnosis and are never shared.
This summary is here for readability. The sections below are the operative terms.
StrongKit ("StrongKit", "we", "us") . For the purposes of the EU and UK General Data Protection Regulation, we are the data controller for the information described in this policy.
Privacy questions, requests and complaints: gohary.dev@gmail.com.
Training profile. During onboarding StrongKit asks seven questions, and every answer is an input to the program generator: your training goal, your experience level, whether you train at the gym, at home or both, what equipment you have at home, how many days a week you train, how long each session should be, and any areas you want extra focus on.
You may optionally add areas to work around — for example a knee, a shoulder, a lower back, no jumping, or low noise. StrongKit uses these solely to exclude movements that stress those areas and to substitute friendlier alternatives. StrongKit does not diagnose anything, does not infer a medical condition, and never asks you to train through pain.
Workout records. When you log a session StrongKit records the exercises performed, sets, repetitions, weight, reps-in-reserve, rest, session duration, completion state, personal records, and the dates of your sessions. It also records your unit preference (kg or lb) and your appearance and motion settings.
Account information — only if you create an account. Creating an account is optional and is offered after your plan is built. If you choose Continue with Apple or Continue with Google, we receive a stable user identifier and, depending on your choice at the time, an email address and display name. If you use Sign in with Apple and select Apple's private email relay, we receive only the relay address and never your real one.
Purchases. If you subscribe to StrongKit Plus, our subscription provider records your transaction identifier, product purchased, purchase and renewal dates, entitlement status, country of the store account, and a pseudonymous app user identifier. Payment itself is handled entirely by Apple or Google. We never receive or store your card number, bank details or billing address.
Diagnostics, analytics and device data. To keep the app stable we may collect crash reports, error traces, performance timings, app version, device model, operating system version, language, general region, and a randomly generated installation identifier. If you enable reminders, your device provides a push notification token.
Data
Collected
Linked to you
Shared
Purpose
Responsible
Training profile & work-arounds
Yes
Only if signed in
No
Generate and adapt your program
StrongKit
Workout logs, PRs, history
Yes
Only if signed in
No
Logging, progress, backup
StrongKit
Email address
If signed in
Yes
No
Account, backup, support
Apple / Google
User ID
If signed in
Yes
No
Sync your data to your account
Auth provider
Purchase history
If subscribed
Yes
No
Unlock and restore Plus
RevenueCat, App Store, Play
Crash logs
VERIFY
No
Processor only
Fix defects
Crash SDK
Product analytics
VERIFY
No
Processor only
Improve the app
Analytics SDK
Push token
If enabled
No
No
Send your training reminders
APNs / FCM
Exercise media requests
VERIFY
No
No
Deliver demonstration media
CDN
Advertising identifier
No
—
No
StrongKit does not advertise
—
Precise location
No
—
—
Not collected
—
Contacts, photos, microphone
No
—
—
Not accessed
—
Your logged workouts, your training profile and any areas you ask StrongKit to work around are treated as health and fitness information, and are disclosed as such in Apple's App Privacy label and Google Play's Data safety section.
Where the GDPR applies, information you provide about a physical limitation may constitute a special category of personal data under Article 9. We process it only on the basis of your explicit consent, given when you choose to enter it. Providing it is entirely optional, and StrongKit builds a complete plan without it. You can remove it at any time by editing your training profile, and doing so removes it from the exercise selection immediately.
StrongKit does not read from or write to Apple Health or Google Health Connect unless a future version asks for that permission explicitly and you grant it.
StrongKit is offline-first. Your plan, your history and your records are written to a database on your device, and logging a workout never requires a network connection.
If you do not sign in, that device database is the only copy in existence. We cannot see it, cannot recover it, and cannot restore it if you delete the app or lose the phone.
If you sign in, StrongKit backs your profile and history up to our cloud infrastructure so you can restore them on a new device. Data is encrypted in transit using TLS and encrypted at rest by our hosting provider.
Our infrastructure and processors may store . Where personal data is transferred out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses or another lawful transfer mechanism.
To build and adapt your program — from your onboarding answers and logged sessions. Basis: performance of our contract with you.
To show your progress — charts, personal records, history and achievements. Basis: performance of our contract.
To back up and restore your account, where you have created one. Basis: performance of our contract.
To avoid movements you asked us to work around. Basis: your explicit consent.
To send the training reminders you set up. Basis: your consent, withdrawable in the app or in system settings.
To deliver and restore StrongKit Plus. Basis: performance of our contract and compliance with legal obligations.
To keep the app stable and secure, through crash and diagnostic data. Basis: our legitimate interest in providing a working product.
We do not use your data to make decisions producing legal or similarly significant effects about you, and we do not profile you for advertising.
We share personal data only with service providers acting on our instructions under a data processing agreement, and only to the extent needed to run StrongKit:
Apple and Google — app distribution, sign-in, payment processing and subscription management.
Our subscription management provider — to determine whether your Plus entitlement is active and to restore it across devices.
Our cloud hosting and database provider — to store account backups.
Our crash reporting and analytics providers — to receive diagnostic data.
Our content delivery network — to serve exercise demonstration media.
We may also disclose data where we are legally required to, or to establish or defend legal claims. If StrongKit is ever involved in a merger or acquisition, we will give you notice before your data becomes subject to a different privacy policy.
What we do not do: we do not sell personal information; we do not share it for cross-context behavioural advertising; we do not use tracking as defined by Apple's App Tracking Transparency framework, and StrongKit does not present an ATT prompt.
On-device data is kept until you delete it in the app or uninstall StrongKit.
Account backups are kept while your account is active, and deleted within days of a deletion request.
Diagnostic and crash data is retained for up to days.
Purchase records are retained for as long as required by tax and accounting law in the relevant jurisdiction, typically several years, even after account deletion.
Built into the app
Export everything — You → Data & privacy → Export produces a file containing your profile and every workout you have logged.
Delete all my data — You → Data & privacy → Delete permanently removes your profile, history and records. StrongKit asks you to confirm twice and offers an export first. There is no undo.
Edit your training profile — including removing any work-around you previously entered.
Turn reminders off — in the app or in your device notification settings.
If you created an account, you can also request deletion of your account and its associated cloud data without installing the app, .
If you are in the EEA or the UK. You have the right to access, rectify, erase, restrict and object to processing of your personal data, the right to data portability, and the right to withdraw consent at any time without affecting processing already carried out. You also have the right to lodge a complaint with your local supervisory authority.
If you are in California. You have the right to know what personal information we collect and how we use it, to request deletion or correction, and to limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not knowingly collect personal information from anyone under 16. We will not discriminate against you for exercising any of these rights.
Everywhere else. Whatever your jurisdiction, write to gohary.dev@gmail.com and we will honour access, correction and deletion requests. We respond within 30 days. To protect your data we may need to verify that a request comes from you.
StrongKit is not directed to children and is intended for people aged 18 or older. We do not knowingly collect personal data from children below that age. If you believe a child has provided us personal data, contact gohary.dev@gmail.com and we will delete it.
We use encryption in transit, encryption at rest with our hosting provider, access controls limiting who can reach production data, and the principle of collecting as little as the product needs. No system is perfectly secure, and we cannot guarantee absolute security — but the design decision to keep your training data on your device by default is itself part of how we limit risk.
If we change this policy we will update the effective date above. For changes that materially affect how we use your data, we will notify you in the app before the change takes effect, and where required by law we will ask for your consent.