Privacy Policy
Last updated: August 2026
Our Commitment to Privacy
StrengthMaxxer is designed with privacy as a core principle. Your workout data belongs to you, and we've built the app to keep it that way.
Data Collection and Storage
What We Collect
StrengthMaxxer stores your core training data locally on your device. This includes:
- Workout logs (exercises, sets, reps, weights)
- Custom exercise definitions
- Workout programs
- Personal records
- App preferences (units, rest timer settings, etc.)
Optional Cloud Features
StrengthMaxxer is local-first, but premium AI features can send limited training context to StrengthMaxxer's AI backend when you choose to use them. Progress photos remain on your device unless you explicitly attach one to Maxx AI for analysis or enable a separate backup service.
Maxx AI
Maxx AI is optional. Each request requires your general Maxx AI consent, and chat history, training settings, image reading, web search, and proposed training changes are separately controllable in the app. Requests are associated with an app-generated identifier rather than a sign-in account. Please do not include personal information in free-form messages.
Data Maxx AI may receive
- Your message and a bounded local training summary, such as body-metric trends, workout and exercise names, recent workout and personal-record dates, sets, volume, and plateau signals. Maxx AI receives this summary rather than a copy of your complete training database. Goals, experience level, schedule, equipment, units, and progression preferences are only included when you enable Training Settings for that message.
- When you use @ mentions, the mentioned exercise, workout, or program's type, stable identifier, name, revision, and a bounded summary needed to answer the request or prepare a proposal.
- If you enable chat history, a bounded rolling summary and up to eight recent text-only turns from that Maxx AI chat. Turns that used images, Training Settings, web research, @-tagged training references, or training-change proposals are never reused as history unless you share context again. You can turn this off or clear the chat at any time.
- If you enable training settings, your goal, experience level, target days, default equipment, units, and progression preferences. Maxx AI does not receive your Apple account, payment data, name, avatar, date of birth, or analytics settings.
- Maxx AI does not read or send Apple Health (HealthKit) data. HealthKit access in StrengthMaxxer is used only for on-device workout tracking, such as heart rate and calories from a paired Apple Watch, and never leaves your device.
- If you attach an image, only that image is sent for the requested analysis. Maxx AI never scans your photo library or Progress Photos automatically. The app does not store the image bytes in Maxx AI chat history; only a lightweight local descriptor is retained for the chat.
- If you enable Web Research for a message, Maxx AI may decide that a public search would help and send a short, privacy-screened query to a search service through our browser service. If a message contains direct personal details, the research planner skips search rather than sending them to that additional model call. Maxx AI receives a limited set of returned source titles and HTTPS links, not the full contents of those webpages.
What Maxx AI can do
- Provide strength-training guidance and explain the supplied summaries.
- Analyze an image you explicitly attach and show source links from Web Research you explicitly enable for that message.
- Prepare a create, update, or delete proposal for a tagged exercise, workout, or program. It cannot change your data until you review the exact diff and tap Approve in the chat; a delete requires an additional confirmation.
- AI features do not provide medical advice, diagnosis, or body-fat estimates.
Storage and retention
Attachment descriptors, Training Settings snapshots, generated skill drafts and payloads, approval state, web-source links, and Maxx AI conversation-memory settings are kept in a local-only app store. Ordinary text-only chat rows follow your app's iCloud setting, so text you type in ordinary chat can sync with iCloud when sync is on. A row that used a separately controllable data source or an @-tagged training reference is redacted in the synced record and restored only from local private context on the originating device. Generated skill transcripts and training-change proposal outcomes follow that same local boundary. Our AI service retains a replay-safe response, which can include the generated answer and source links, is scheduled for deletion one day after completion so a lost network response can be retried without creating a second request. It may remain briefly while scheduled cleanup runs. It does not intentionally retain raw prompts, image bytes or full webpage contents in its own database. It retains anonymous operational and accounting records (for example, request status and time, model/provider, token counts, quotas, entitlement verification, and limited security/error records) until you delete AI data.
The data necessary to generate a response is also processed by the configured model provider. That provider's handling and retention are governed by its applicable terms and privacy documentation.
AI Program Builder
When you ask to build a program, we process the selections you make in that flow: priority muscles, workouts per week, session length, training volume, program goal, the experience setting already stored in your profile, and equipment. Custom-equipment labels are validated and used to match custom exercises in your local library; the AI model receives only whether custom equipment is present, not the labels themselves.
The service returns a bounded weekly structure. Your device creates the exercises and prescriptions locally, and no generated program is saved until you explicitly choose to save it.
iCloud Sync (Optional)
If you enable iCloud sync, your workout data will be stored in your personal iCloud account and is subject to Apple's privacy and security practices. StrengthMaxxer does not operate iCloud's infrastructure.
- Sync is controlled through your Apple ID and device settings
- Apple's Privacy Policy applies to iCloud services
- You can turn sync off in the app settings
You can disable iCloud sync at any time in the app settings.
In-App Purchases
Purchases are processed entirely by Apple through the App Store. We do not have access to your payment information. Apple may share basic transaction information with us (such as whether a purchase was made), but not your personal financial details.
Third-Party Services
StrengthMaxxer integrates with the following third-party services:
- Apple (App Store, iCloud, StoreKit): For app distribution, optional cloud sync, and in-app purchases
- Cloudflare: For processing optional AI requests and service-security and usage records, including the browser service used for an optional web search
- Alibaba Cloud (Qwen): For generating optional AI responses when you request them. The production configuration uses Qwen's international endpoint. The data needed for the requested AI feature is sent to that provider to produce the response and may be processed internationally under its applicable terms and privacy documentation.
- Microsoft Bing: For a public web-search query Maxx AI may run only after you enable Web Research for that message
We do not sell your personal data. Optional AI feature processing is limited to operating the feature you request.
Data Deletion
You can control or delete your data through the following options:
- Using Recently Deleted in Settings → Data & Privacy to permanently remove workouts you have deleted
- Using "Delete AI Data" in Settings → Data & Privacy, which deletes local Maxx AI chats and private AI context, plus AI-service records associated with your app-generated identity, including AI request, entitlement, usage, and security records. This is available even after an AI subscription expires. It does not delete workout logs, saved programs, or app account settings stored on your device.
- Uninstalling the app (this removes local app data)
- Deleting app data from iCloud (if sync was enabled) through your device's iCloud settings
You can also email privacy@strengthmaxxer.com to request deletion.
Children's Privacy
StrengthMaxxer is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us so we can promptly remove it.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at: privacy@strengthmaxxer.com