Privacy Policy
Last updated: 2026-05-24 · Effective: 2026-05-24
RhythmFit ("RhythmFit", "we", "us") is an AI-powered rhythm coach for iPhone and Apple Watch. We are committed to keeping the data we collect minimal, transparent, and under your control. This policy describes what we collect, why we collect it, and the choices you have. If you have questions, email [email protected].
1. Summary
- No ads. No data sales. No AI training on your data.
- Heart rate, HRV, and motion data stay on your device by default. HealthKit access is optional.
- AI features send only the prompts you type (workout type, focus, duration). They never see your name, email, location, or Health data.
- Account email is stored only if you choose to sign in. You can use most of the app without an account.
2. Information we collect
2.1 Information you provide
- Account (optional): email address via Supabase Auth, used to sync workouts across your devices and restore purchases.
- Workout content you create: names, blocks, BPM, durations, your text notes. Stored locally in Core Data; uploaded to our servers only when you explicitly use Share or Sync.
- AI prompts: the text you type or dictate into the AI Create flow, and the resulting workout. Used to generate the requested workout and then discarded by us after delivery (the prompt is held briefly by Anthropic per their policy — see Section 4).
- Author name on shared workouts (optional): if you opt to attach a display name to a shared workout, it is visible to anyone who opens the share link.
- Support emails: the email and content you send to [email protected] or [email protected], used solely to respond to you.
2.2 Information collected automatically
- Device identifier for sharing rate limits: we use Apple's
identifierForVendor(resets when you uninstall the app) to enforce daily share-link limits and to associate share codes with the device that created them. This identifier is not linked to your real identity. - Crash and diagnostic logs: Apple's standard, opt-in diagnostics via TestFlight / App Store. We do not run our own analytics SDK on App Store builds.
2.3 Information from HealthKit (only with your permission)
- Heart rate, HRV, and workout sessions are read from HealthKit only after you grant permission.
- This data is processed on your device for live display, calorie estimates, and readiness checks. It is never uploaded to our servers and is never shared with the AI.
- RhythmFit can write completed workouts back to HealthKit only if you allow it.
2.4 Location (only with your permission)
- For outdoor workouts, RhythmFit reads your location while the app is in use to measure running pace and distance for live pace and distance milestones.
- Location is processed on your device. It is never uploaded to our servers and is never shared with the AI.
- You can decline or revoke this permission any time in iOS Settings → Privacy → Location Services → RhythmFit; outdoor pace features simply won't run.
2.5 Information we do not collect
- Your name, age, weight, or body measurements.
- Your contacts, photos library, or files outside what you explicitly import.
- Data from any other app on your device.
3. How we use information
- To run the features you ask for (generate workouts, sync your library, share via a short link).
- To enforce subscription entitlements and free-tier limits.
- To prevent abuse (per-device share rate limits, profanity filters on shared content).
- To respond to your support requests.
We do not sell or rent your data. We do not use your data for third-party advertising. We do not train AI models on your data.
4. Third-party services
The following providers process data on our behalf:
- Anthropic (Claude): AI workout generation and chat. Receives only your prompts and the workout context. Anthropic's API retains prompt data per their commercial policy and does not use it to train their models. See anthropic.com/legal.
- Supabase: authentication (email/password, sign-in with Apple) and shared-workout storage. Hosted in their managed infrastructure.
- Apple: App Store purchases, StoreKit subscriptions, HealthKit, Sign in with Apple, MusicKit (only if you connect Apple Music).
- RevenueCat: subscription state management. Receives a pseudonymous user ID and your purchase receipt.
Coach speech is synthesized entirely on your device by iOS system voices — coaching text is never sent to a cloud speech service.
5. Data storage and retention
- Workouts you create live on your device in Core Data. Deleting the app deletes them.
- If you sign in, your library is synced to Supabase. Deleting your account removes it from our servers within 30 days.
- Shared workouts (rhythmfit.me/w/<code>) remain online until you delete them or report them via the in-app Report flow.
- Support email is retained for 24 months for service quality, then deleted.
6. Children
RhythmFit is not directed to children under 13. If you believe a child has provided personal information, contact [email protected] and we will promptly delete it.
7. Your rights
- Access / export: sign in to the app and use Settings → Account → Export to download your data.
- Deletion: Settings → Account → Delete Account permanently removes your account and synced workouts.
- HealthKit permissions: revoke any time in iOS Settings → Privacy → Health → RhythmFit.
- Voice control (Siri): manage in iOS Settings → Siri & Search → RhythmFit.
- Push notifications: manage in iOS Settings → Notifications → RhythmFit.
- EU / UK / California residents: you have additional rights under GDPR / UK GDPR / CCPA, including the right to object to processing and to lodge a complaint with your local data protection authority. Email [email protected] to exercise any of these rights.
8. Security
We use TLS for all data in transit. Supabase data is encrypted at rest. We do not store payment card details — purchases are handled by Apple. No system is perfectly secure; please report vulnerabilities to [email protected].
9. International transfers
Our servers and our processors operate in the United States and the European Union. By using RhythmFit you consent to your data being processed in these regions, subject to the safeguards required by applicable law.
10. Changes to this policy
If we make material changes we will update the "Last updated" date and, where required, notify you in the app or by email. Continued use after a change means you accept the revised policy.
11. Contact
Questions, requests, or concerns: [email protected].
DMCA / copyright: [email protected].