Home
Legal

Privacy Policy

Our Approach to Privacy

Strenua was built on a fundamental belief: your health and fitness data belongs to you and only you. Unlike most fitness applications that collect, store, and monetise user data through cloud servers, Strenua processes your workouts entirely on your iPhone using on-device intelligence.

This isn't just a feature — it's the foundation of our architecture. Your workout data, exercise performance, and training history never leave your device. The intelligence that generates your programmes runs locally on your iPhone's Neural Engine.

If you choose to sign in for backup and sync, Strenua stores a small amount of account data. This section explains exactly what data is involved, why, and how it's handled.

What We Collect

Strenua collects the minimum data necessary to operate the service. Here is the complete list:

Account Data (Collected)

When you optionally sign in with Apple or Google, we receive:

  • Unique user identifier — a random ID assigned by Apple or Google to identify your account. This is not your Apple ID or Google account ID.
  • Email address — provided by you or, if using Sign in with Apple, Apple's private relay email address (e.g., randomstring@privaterelay.appleid.com). Used for account recovery and critical service communications only.
  • Display name — only if you choose to share it during sign-in. Optional.

We do not receive or store your password. Authentication is handled entirely by Apple's or Google's secure identity services.

Subscription Data (Managed by Apple)

Your subscription is processed and managed by Apple through the App Store. We receive:

  • Subscription status — whether your subscription is active, in trial, expired, or cancelled
  • Transaction identifiers — Apple-assigned transaction IDs for subscription verification
  • Subscription period — start and end dates of your current billing period

We do not receive your payment method, credit card details, billing address, or any financial information. All payment processing is handled by Apple.

Data We Do Not Collect

Strenua does not collect, transmit, or store any of the following:

  • Workout data — exercise performance, sets, reps, weights, training history
  • Health data — body measurements, heart rate, HealthKit data
  • Device identifiers — IDFA, IDFV, or device fingerprints
  • Usage analytics — screen views, tap events, session duration, feature usage
  • Location data — GPS coordinates, gym locations, movement patterns
  • Biometric data — heart rate, step counts, or Apple Watch sensor data

Your training data stays on your device. We cannot see it, access it, or recover it.

On-Device Intelligence Processing

All workout intelligence in Strenua runs locally on your iPhone through Apple's CoreML framework. This means:

  • Workout generation happens entirely on your device's Neural Engine
  • Progressive overload calculations are computed locally
  • Periodisation decisions are made without any server communication
  • Recovery modelling uses only data stored in your device's local storage
  • Exercise recommendations are generated without sending your training history anywhere

The intelligence models are bundled with the application at download time. No model updates require transmitting your personal data.

Apple HealthKit Integration

Strenua integrates with Apple HealthKit to read and write workout data. This integration follows Apple's strict HealthKit guidelines:

  • Read access: With your explicit permission, Strenua reads workout history and activity data from HealthKit to inform its programming decisions
  • Write access: With your explicit permission, Strenua writes completed workout sessions to HealthKit so they appear in your Apple Health records
  • Data stays local: All HealthKit data remains on your device and in your iCloud Health data (managed by Apple, not Strenua)
  • No third-party sharing: HealthKit data is never shared with third parties, advertisers, or data brokers — this is enforced by both our architecture and Apple's HealthKit policies
  • Revocable: You can revoke HealthKit permissions at any time through Settings → Health → Data Access & Devices

Local Data Storage

Strenua stores your workout data, preferences, and intelligence model state using Apple's on-device storage frameworks (SwiftData and UserDefaults). This data:

  • Is stored exclusively on your device
  • Is included in your encrypted iCloud backups if you have iCloud Backup enabled
  • Is protected by your device passcode and iOS data protection
  • Is not accessible to other applications on your device

When you delete the application, all locally stored workout data is permanently removed from your device.

Authentication Services

Strenua uses Apple Sign In and Google Sign In for authentication. These are the only third-party services integrated into the App.

Sign in with Apple:

  • Managed by Apple's identity services
  • Supports private relay email addresses for enhanced privacy
  • You control what information is shared (name, email)
  • Apple's privacy policy applies: apple.com/legal/privacy

Sign in with Google:

  • Managed by Google's identity services
  • We request only basic profile information (email, name)
  • Google's privacy policy applies: policies.google.com/privacy

We store the minimum authentication tokens required to verify your identity and sync your account data. These tokens do not contain your personal information.

Third-Party Services

Beyond authentication providers (Apple and Google) and subscription processing (Apple App Store), Strenua does not integrate with any third-party data services. There are:

  • No analytics SDKs (no Google Analytics, Firebase, Mixpanel, or Amplitude)
  • No advertising frameworks (no ad networks or attribution tracking)
  • No crash reporting services (no Crashlytics, Sentry, or Bugsnag)
  • No social media SDKs (no Facebook, Twitter, or social login beyond Apple/Google)
  • No third-party data processors handling your workout or health data

Cookies and Web Tracking

The Strenua website (strenua.app) does not use cookies, tracking pixels, or any web analytics tools. We do not track visitors, build user profiles, or engage in retargeting.

Children's Privacy

Strenua is not intended for children under the age of 17. We do not knowingly collect information from anyone under 17. If we become aware that we have collected account data from someone under 17, we will delete that information promptly.

Data Retention

Account data (user identifier, email, name) is retained for as long as your account exists. When you delete your account:

  • Your authentication tokens are revoked
  • Your account identifier and email are removed from our system
  • Your subscription is cancelled (if active)
  • Your on-device training data is not affected — it remains on your device until you uninstall the App

Subscription records may be retained as required for financial and legal compliance (e.g., transaction records for tax purposes). These records contain only Apple-assigned transaction identifiers, not personal information.

On-device data (workouts, preferences, model state) is stored only on your device and is deleted when you uninstall the App or reset your device.

Your Rights

Data Access and Portability

You can view your account data (email, name) within the App's settings. Your workout data is stored on your device and is accessible to you at all times.

Account Deletion

You can delete your account at any time through the App's settings. This removes your account data from our authentication system. Alternatively, contact us at privacy@strenua.app and we will delete your account within 30 days.

UK and EU Residents

If you are located in the United Kingdom or European Economic Area, you have additional rights under UK GDPR and EU GDPR respectively, including the right to access, rectification, erasure, data portability, and the right to object to or restrict processing. Since Strenua collects minimal account data and processes no health data server-side, most of these rights are satisfied by our architecture. For any data rights requests, contact privacy@strenua.app.

Legal basis for processing: We process your account data on the basis of contract performance (providing the subscription service you signed up for). We do not process data based on legitimate interest or consent for marketing purposes.

Data controller: Strenua is the data controller for the account data described in this policy.

California Residents

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA). Strenua does not sell personal information. We do not share personal information for cross-context behavioural advertising. For any CCPA-related requests, contact privacy@strenua.app.

Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or for legal compliance. Any changes will be posted on this page with an updated revision date. If we make material changes that affect how we handle your data, we will notify you through the App or by email before the changes take effect.

Contact

If you have questions about this Privacy Policy or Strenua's privacy practices, contact us at:

Email: privacy@strenua.app

App Store

Strenua is distributed exclusively through the Apple App Store and complies with Apple's App Store Review Guidelines, including all privacy and data handling requirements. Our App Store privacy nutrition labels accurately reflect that Strenua collects account data for authentication and does not collect health or fitness data server-side.