Strenua is a fitness application that generates training recommendations on your device. This policy explains what information is processed locally, what is sent to service providers, and the choices available to you.
Information We Process
On your device
Strenua stores workout history, training plans, personal records, preferences, recovery calculations, and cached exercise media locally using Apple platform storage. Workout generation and training calculations run on your device.
If you grant HealthKit access, Strenua reads only the HealthKit categories shown in Apple's permission prompt and writes completed workouts and factual workout information. Strenua does not estimate or write active-energy samples. HealthKit data is used for app functionality. Strenua does not use HealthKit data for advertising or sell it. HealthKit records are not included in Strenua's Firebase cloud backup; information you enter directly into your Strenua profile, such as age, height, weight, and training preferences, may be included.
Account and cloud backup data
When you sign in, Strenua uses Firebase Authentication and receives an account identifier and, when supplied by the sign-in provider, an email address and display name. Signed-in accounts use Firebase Cloud Firestore to back up and restore:
- profile information and app preferences;
- workout sessions, exercises, sets, and personal records;
- custom workout templates and custom exercises; and
- backup timestamps and synchronization metadata.
This cloud data is linked to your account so that backup, restore, and account deletion work correctly. Firebase protects data in transit and at rest using its platform security controls. Strenua cloud backups are not end-to-end encrypted, and authorized service infrastructure can process them to provide the service.
Previous-account migration
For a limited compatibility period, existing users can choose to reconnect the same Apple or Google account they previously used with Strenua. When you choose this option, Strenua uses Supabase to retrieve that account's previous profile, workout history, personal records, custom templates, and custom exercises, then copies them to your Firebase backup. Strenua verifies the email address and sign-in provider before importing, leaves the previous Supabase records unchanged, and does not use Supabase for new workout data.
Subscription data
Purchases are processed by Apple. RevenueCat is used to validate subscription status and associate entitlements with your Strenua account. Strenua and RevenueCat may process your account identifier, optional email/display name, product and transaction identifiers, subscription status, and purchase dates. Strenua does not receive your payment card details.
Support requests
If you use the support form, Strenua processes the request type, reply email address, and message you submit. Do not include passwords, payment credentials, or Apple Health records. The Strenua website and support form are hosted by Netlify, which processes form submissions on Strenua's behalf so that we can receive and respond to your request.
How We Use Information
We use information only to provide authentication, cloud backup and restore, workout and profile functionality, subscription access, security, and customer support. Strenua does not use advertising SDKs, sell personal information, or track you across apps and websites.
Service Providers and International Processing
Strenua uses:
- Apple for Sign in with Apple, HealthKit, and App Store purchases;
- Google Firebase for authentication, App Check abuse protection, and Cloud Firestore backup;
- Supabase only for user-requested migration of previous Strenua account data;
- RevenueCat for subscription verification and entitlement management; and
- Netlify for website hosting and support-form processing.
These providers process information under their own security and privacy terms. The Strenua Firestore database is configured in the London region (europe-west2), while authentication and service-provider operations may involve processing in other countries subject to applicable transfer safeguards.
Retention and Deletion
Local data remains on your device until you delete it, reset the app's local data, or uninstall the app. Cloud backup data remains while your Strenua account exists. Support submissions are retained only for as long as reasonably needed to respond, handle related follow-up, meet legal obligations, and protect the service; they are periodically deleted when no longer needed.
You can delete your account in Settings → Account → Delete Account. The app removes the account's local Strenua data and Firestore backup, revokes the current Sign in with Apple authorization when applicable, and deletes the Firebase Authentication account. Deleting a Strenua account does not automatically cancel an App Store subscription; subscriptions are managed in your Apple account settings. Apple and RevenueCat may retain transaction records where required for purchase restoration, fraud prevention, accounting, or legal obligations.
You can export your locally stored training data from the app before deletion.
Your Choices and Rights
You can decline sign-in and HealthKit permissions, revoke HealthKit access in iOS Settings, manage subscriptions through Apple, export local data, and delete your Strenua account in the app. Depending on where you live, you may also have rights to access, correct, delete, restrict, object to processing of, or receive a portable copy of your personal data.
For a privacy request, use the Strenua support form and select Privacy request. We may need to verify that the request concerns your account before acting on it.
Children
Strenua is not directed to children under 13. The onboarding flow requires users to be at least 13. If you believe a child has provided account data contrary to this policy, contact us so we can investigate and delete it.
Security
Strenua uses Firebase Authentication, per-user Firestore security rules, Firebase App Check, TLS network transport, and Apple platform data protection. No security method is guaranteed to prevent every incident.
Changes
We may update this policy when the product or legal requirements change. The current version and its effective date will be published on this page.
Contact
Privacy questions and requests: Strenua support form