Our Approach to Privacy
Strenua was built on a fundamental belief: your health and fitness data belongs to you and only you. Unlike most fitness applications that collect, store, and monetise user data through cloud servers, Strenua processes your workouts entirely on your iPhone using on-device intelligence.
This isn't just a feature — it's the foundation of our architecture. Your workout data, exercise performance, and training history never leave your device. The intelligence that generates your programmes runs locally on your iPhone's Neural Engine.
If you choose to sign in for backup and sync, Strenua stores a small amount of account data. This section explains exactly what data is involved, why, and how it's handled.
What We Collect
Strenua collects the minimum data necessary to operate the service. Here is the complete list:
Account Data (Collected)
When you optionally sign in with Apple or Google, we receive:
- Unique user identifier — a random ID assigned by Apple or Google to identify your account. This is not your Apple ID or Google account ID.
- Email address — provided by you or, if using Sign in with Apple, Apple's private relay email address (e.g., randomstring@privaterelay.appleid.com). Used for account recovery and critical service communications only.
- Display name — only if you choose to share it during sign-in. Optional.
We do not receive or store your password. Authentication is handled entirely by Apple's or Google's secure identity services.
Subscription Data (Managed by Apple)
Your subscription is processed and managed by Apple through the App Store. We receive:
- Subscription status — whether your subscription is active, in trial, expired, or cancelled
- Transaction identifiers — Apple-assigned transaction IDs for subscription verification
- Subscription period — start and end dates of your current billing period
We do not receive your payment method, credit card details, billing address, or any financial information. All payment processing is handled by Apple.
Data We Do Not Collect
Strenua does not collect, transmit, or store any of the following:
- Workout data — exercise performance, sets, reps, weights, training history
- Health data — body measurements, heart rate, HealthKit data
- Device identifiers — IDFA, IDFV, or device fingerprints
- Usage analytics — screen views, tap events, session duration, feature usage
- Location data — GPS coordinates, gym locations, movement patterns
- Biometric data — heart rate, step counts, or Apple Watch sensor data
Your training data stays on your device. We cannot see it, access it, or recover it.
On-Device Intelligence Processing
All workout intelligence in Strenua runs locally on your iPhone through Apple's CoreML framework. This means:
- Workout generation happens entirely on your device's Neural Engine
- Progressive overload calculations are computed locally
- Periodisation decisions are made without any server communication
- Recovery modelling uses only data stored in your device's local storage
- Exercise recommendations are generated without sending your training history anywhere
The intelligence models are bundled with the application at download time. No model updates require transmitting your personal data.
Apple HealthKit Integration
Strenua integrates with Apple HealthKit to read and write workout data. This integration follows Apple's strict HealthKit guidelines:
- Read access: With your explicit permission, Strenua reads workout history and activity data from HealthKit to inform its programming decisions
- Write access: With your explicit permission, Strenua writes completed workout sessions to HealthKit so they appear in your Apple Health records
- Data stays local: All HealthKit data remains on your device and in your iCloud Health data (managed by Apple, not Strenua)
- No third-party sharing: HealthKit data is never shared with third parties, advertisers, or data brokers — this is enforced by both our architecture and Apple's HealthKit policies
- Revocable: You can revoke HealthKit permissions at any time through Settings → Health → Data Access & Devices
Local Data Storage
Strenua stores your workout data, preferences, and intelligence model state using Apple's on-device storage frameworks (SwiftData and UserDefaults). This data:
- Is stored exclusively on your device
- Is included in your encrypted iCloud backups if you have iCloud Backup enabled
- Is protected by your device passcode and iOS data protection
- Is not accessible to other applications on your device
When you delete the application, all locally stored workout data is permanently removed from your device.
Authentication Services
Strenua uses Apple Sign In and Google Sign In for authentication. These are the only third-party services integrated into the App.
Sign in with Apple:
- Managed by Apple's identity services
- Supports private relay email addresses for enhanced privacy
- You control what information is shared (name, email)
- Apple's privacy policy applies: apple.com/legal/privacy
Sign in with Google:
- Managed by Google's identity services
- We request only basic profile information (email, name)
- Google's privacy policy applies: policies.google.com/privacy
We store the minimum authentication tokens required to verify your identity and sync your account data. These tokens do not contain your personal information.
Third-Party Services
Beyond authentication providers (Apple and Google) and subscription processing (Apple App Store), Strenua does not integrate with any third-party data services. There are:
- No analytics SDKs (no Google Analytics, Firebase, Mixpanel, or Amplitude)
- No advertising frameworks (no ad networks or attribution tracking)
- No crash reporting services (no Crashlytics, Sentry, or Bugsnag)
- No social media SDKs (no Facebook, Twitter, or social login beyond Apple/Google)
- No third-party data processors handling your workout or health data
Cookies and Web Tracking
The Strenua website (strenua.app) does not use cookies, tracking pixels, or any web analytics tools. We do not track visitors, build user profiles, or engage in retargeting.
Children's Privacy
Strenua is not intended for children under the age of 17. We do not knowingly collect information from anyone under 17. If we become aware that we have collected account data from someone under 17, we will delete that information promptly.
Data Retention
Account data (user identifier, email, name) is retained for as long as your account exists. When you delete your account:
- Your authentication tokens are revoked
- Your account identifier and email are removed from our system
- Your subscription is cancelled (if active)
- Your on-device training data is not affected — it remains on your device until you uninstall the App
Subscription records may be retained as required for financial and legal compliance (e.g., transaction records for tax purposes). These records contain only Apple-assigned transaction identifiers, not personal information.
On-device data (workouts, preferences, model state) is stored only on your device and is deleted when you uninstall the App or reset your device.
Your Rights
Data Access and Portability
You can view your account data (email, name) within the App's settings. Your workout data is stored on your device and is accessible to you at all times.
Account Deletion
You can delete your account at any time through the App's settings. This removes your account data from our authentication system. Alternatively, contact us at privacy@strenua.app and we will delete your account within 30 days.
UK and EU Residents
If you are located in the United Kingdom or European Economic Area, you have additional rights under UK GDPR and EU GDPR respectively, including the right to access, rectification, erasure, data portability, and the right to object to or restrict processing. Since Strenua collects minimal account data and processes no health data server-side, most of these rights are satisfied by our architecture. For any data rights requests, contact privacy@strenua.app.
Legal basis for processing: We process your account data on the basis of contract performance (providing the subscription service you signed up for). We do not process data based on legitimate interest or consent for marketing purposes.
Data controller: Strenua is the data controller for the account data described in this policy.
California Residents
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA). Strenua does not sell personal information. We do not share personal information for cross-context behavioural advertising. For any CCPA-related requests, contact privacy@strenua.app.
Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or for legal compliance. Any changes will be posted on this page with an updated revision date. If we make material changes that affect how we handle your data, we will notify you through the App or by email before the changes take effect.
Contact
If you have questions about this Privacy Policy or Strenua's privacy practices, contact us at:
Email: privacy@strenua.app
App Store
Strenua is distributed exclusively through the Apple App Store and complies with Apple's App Store Review Guidelines, including all privacy and data handling requirements. Our App Store privacy nutrition labels accurately reflect that Strenua collects account data for authentication and does not collect health or fitness data server-side.