WHAM

Privacy Policy

Last updated August 23, 2026

Data controller
Liam Tyndale
Contact
gymtrackapp25@gmail.com

WHAM ("we," "us," "our") provides this app to help you track workouts and connect with friends. This policy explains what data we collect, why, and how it's handled.

01 What we collect

Account data

  • Email address (used for authentication and account recovery).
  • If you sign in with Apple, we receive the identifier Apple provides for that sign-in; we do not receive your Apple ID password.
  • We do not collect your real name unless you choose to add one to your profile.

Workout data

  • Exercises logged, sets, reps, weights, session dates and duration, personal bests, and training streaks.
  • This data is used to power your training history, PB detection, and progress stats. It's stored so it's available across devices you sign into.

Health & fitness data (optional, Apple Health)

  • If you choose to connect Apple Health (a separate, explicit permission prompt — off by default), we read your heart rate and active energy (calories) for the duration of a logged workout, to enrich your post-workout recap with real numbers instead of an estimate.
  • This is read-only: we never write anything back to Apple Health.
  • This data stays on your device — it's stored locally alongside your workout and is never sent to our servers or any third party.
  • If you don't connect Apple Health, calories are estimated from your bodyweight and workout duration instead.

Location (optional, one-time)

  • If you tap "Detect my gym," we ask iOS for your device's current location a single time to match you against a community-built list of gyms. We never request background or "Always" location access, and we never track your location passively.
  • That single location reading is used on your device to find nearby gyms and is not itself transmitted to our servers.
  • If your gym isn't already on the list and you choose to add it, the coordinates for that new gym are saved to our servers and become part of the shared community gym list — visible to other WHAM users searching for that gym, the same way any community-contributed gym listing is. Don't add a gym at a location you don't want associated with that gym's public listing.

Contacts (optional)

  • If you allow contacts access to find friends already using WHAM, phone numbers from your contacts are hashed on your device before anything is sent — we only ever transmit and store the hashes, never the plaintext numbers themselves, and matching happens by comparing hashes.
  • This is a real privacy improvement over sending raw numbers, but hashes of low-entropy data like phone numbers aren't a cryptographic guarantee against a determined, direct-database-access attacker — treat it as meaningfully better than plaintext, not unbreakable.

Photos and videos (optional)

  • Profile picture: if you set one, it's stored in a public bucket and visible to anyone who can see your profile.
  • Post attachments: a photo or video you choose to attach to a feed post is stored privately and served only via short-lived signed links to people who can see that post.
  • Progress photos/videos: before/after clips you record for your own progress tracking are stored privately, visible only to you.

Voice input (optional)

  • If you tap the mic to log a set by voice, WHAM uses iOS's built-in Speech Recognition. Depending on your device and settings, iOS may process that audio on-device or send it to Apple's own servers for transcription — that's governed by Apple's own privacy practices, not ours.
  • WHAM itself never stores or transmits your raw voice audio anywhere. We only use the transcribed text, locally, to fill in a set's weight and reps.

Social and friend data

  • Friend connections you create within the app.
  • Content you choose to share to your activity feed (sessions, PBs, achievements).
  • Leaderboard participation (weekly volume/strength rankings visible to friends, if you opt in).
  • Privacy controls let you decide what's visible to friends vs. kept private.

Diagnostics and product analytics

  • We use Sentry to capture crash and error reports, so we can find and fix bugs. Reports are tagged with an internal account ID, never your email — and are automatically screened to strip anything that looks like Apple Health data (heart rate, calories) or another user's identifiers before being sent.
  • We use PostHog to understand how the app is used in aggregate (e.g. which features get used, how often), tied to your internal account ID when you're signed in. These events are plain counts and app-usage facts (like session count or workout duration) — never your email, name, or any Apple Health data.
  • Neither tool is used for advertising, and neither ever receives your email or Apple Health data — see What we do not do.

Technical data

  • Basic device information used only to keep the app reliable.

02 What we do not do

  • We never track your location in the background or ask for "Always" location access — see Location above for the one-time, on-demand lookup we do use.
  • We do not collect Apple Health data unless you explicitly connect it, and even then only heart rate and active energy for your logged workouts, kept on your device only — nothing else from Health is read or written, and none of it is sent to us or anyone else.
  • We do not sell your data to third parties.
  • As of this version, WHAM shows no ads and shares no data with any ad network — see Subscriptions and Advertising for what's planned.
  • Our analytics and crash reporting (see Diagnostics and product analytics) never receive your email, real name, or any Apple Health data — by construction, not just policy: the code that talks to those tools doesn't accept those fields as input.

03 How data is stored and secured

Data is stored using Supabase (PostgreSQL), a third-party infrastructure provider, with row-level security policies restricting access so that only you can read your private data, and only accepted friends can see data you've explicitly shared. Photos and videos you attach to posts or progress logs are stored in private buckets served only through short-lived signed links, not public URLs. All traffic between the app and our servers is encrypted in transit (HTTPS/TLS).

04 Third-party services

WHAM uses the following third-party service providers to operate:

  • Supabase (database, authentication, file storage)
  • Apple HealthKit (only if you explicitly connect it — data is read directly from your device, not from an Apple server, and stays on your device)
  • Apple Speech Recognition (only if you use voice logging — processes your spoken words into text per Apple's own privacy practices; see Voice input)
  • Giphy (powers GIF search/sharing in the social feed — search terms you enter are sent to Giphy to return results; no account or personal identifiers are sent alongside them)
  • Sentry (crash and error reporting; see Diagnostics and product analytics)
  • PostHog (product usage analytics; see Diagnostics and product analytics)
  • Expo/EAS (app build and update delivery infrastructure)

Each of these providers only receives the data necessary to perform their function and is bound by their own privacy and security terms.

05 Subscriptions and advertising planned

The base app is, and will remain, free to use. We plan to introduce an optional premium subscription and an ad-supported free tier in a future update.

  • Subscriptions will be handled entirely through Apple's In-App Purchase system. We receive confirmation of your subscription and its status, but never your payment details — Apple handles billing directly.
  • Ads, when introduced, will be served by a third-party ad network (named here once chosen). If that network uses your device's advertising identifier to personalize ads or track you across apps, we'll ask your permission first via Apple's App Tracking Transparency prompt, as required.
Note: this section will be filled in with specifics — and this policy re-reviewed — before either feature ships in a released version of the app, not simply announced after the fact.

06 Community content and moderation

WHAM's activity feed lets you share workouts and see friends' activity. We have zero tolerance for objectionable content or abusive behavior.

  • Any post can be reported directly from the feed.
  • Any user can be blocked directly from the feed, which immediately hides their content from you.
  • Reports are reviewed and acted on, which may include content removal or account restriction.

Contact us at the address above to report anything our in-app tools don't cover.

07 Your rights and controls

  • You can edit or delete workout data within the app at any time.
  • You can remove friend connections and control what's visible on your feed and leaderboards.
  • You can delete your account at any time from within the app (Settings → Account → Delete account). This immediately and permanently removes your account, workout history, and social connections from our systems — there's no waiting period and no need to contact support.
  • You can request a copy of your data by contacting us at the address above.

08 Children's privacy

WHAM is not directed at children under 13 (or the minimum age required in your territory), and we do not knowingly collect data from children under this age.

09 Changes to this policy

We may update this policy as the app evolves. Material changes will be reflected here with an updated "Last updated" date.

10 Contact

Questions about this policy or your data: gymtrackapp25@gmail.com