This policy explains what the WorkItOut mobile app ("WorkItOut", "the app", "we") collects, why, where it is stored, who else can see it, and how to get rid of it. It covers the iOS and Android apps and the website at workitouttraining.com.
The short version. WorkItOut stores your training data so it is available on your devices. We do not sell your data, we do not share it with advertisers, and there is no advertising or analytics tracking in the app. Data leaves your device only to services that make a feature you asked for work. You can delete your account and all of its data from inside the app at any time.
WorkItOut is operated by Shay Dubrovsky, Tel Aviv, Israel. Contact: privacy@workitouttraining.com. For data protection questions you can also write to shay.dubrovsky@workitouttraining.com.
You can sign in with Google, with Apple (iOS), with an email address and password, or continue anonymously without an account. Where you use a sign-in provider, we receive your email address, display name and profile photo URL from that provider. Anonymous accounts carry no personal identifiers at all. Authentication is handled by Google Firebase Authentication; we never see or store your password.
The physiological and preference values you enter: functional threshold power, body weight, maximum heart rate, resting heart rate, lactate threshold heart rate, unit preference, start-of-week, and app settings. Some of these are health-related data.
For each session: start time, duration, power, heart rate, cadence, distance, elevation gain, energy expenditure, calculated training stress, and the second-by-second recording of those values. Where an activity has a recorded route, the app stores the route as an encoded GPS polyline.
The names of Bluetooth devices you pair — your trainer, heart rate strap and cadence sensor — so the app can reconnect to them automatically, including on a new phone. No other information about your devices or surroundings is recorded.
On Android, the operating system requires location permission in order to scan for Bluetooth devices. WorkItOut does not use it to determine, collect or store your location.
If you switch it on, WorkItOut reads workouts, heart rate, active energy, distance, elevation and workout routes from Apple Health or Health Connect, so that activities recorded elsewhere count towards your training load. It is off until you enable it, and enabling it is tied to one specific device, so signing into your account on someone else's phone never imports their health data.
Today this is read-only: WorkItOut does not write anything back to Apple Health or Health Connect. The app declares permission to save completed workouts because that feature is planned; if and when it is switched on, it will ask for your permission first and this policy will be updated.
If you connect Strava, completed workouts can be uploaded to your Strava account. Your Strava access and refresh tokens are held on our server, in a location the app itself cannot read, and are deleted when you disconnect or delete your account.
Crash reports and preceding log messages are collected through Google Firebase Crashlytics so that faults can be diagnosed and fixed.
Separately, for a small number of users who are explicitly enabled by us, the app records technical measurements of how a smart trainer responds to power commands — trainer model name, control protocol, and statistics about requested versus delivered power. This is used to fix compatibility problems with specific trainer hardware. It is off for everyone by default.
WorkItOut includes a conversational coaching feature that builds and adjusts workouts. When you use it, your chat messages and a compact numeric summary of your training are sent to Anthropic's Claude API to generate a response.
The summary contains derived numbers only:
It does not contain your name, email, workout files, second-by-second recordings, GPS routes, or any records imported from Apple Health or Health Connect. Data imported from Strava is excluded from this summary entirely and is never sent to any AI model.
Anthropic processes this data to return a response and, under its commercial terms, does not use it to train its models.
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Provide the app and sync across your devices | Account, profile, workouts | Performance of a contract |
| Calculate training load and suggest sessions | Profile and workout data, including health data | Explicit consent (Art. 9(2)(a)) |
| Import from Apple Health / Health Connect | Health app data | Explicit consent, withdrawable |
| Upload activities to Strava | Workout data, Strava tokens | Explicit consent, withdrawable |
| AI coaching responses | Chat messages, derived training numbers | Consent, by choosing to use the feature |
| Fix crashes and trainer faults | Crash reports, trainer telemetry | Legitimate interest in a working product |
We use a small number of service providers, each only for the function listed:
| Provider | Purpose | Location |
|---|---|---|
| Google Firebase | Authentication, database, server functions, crash reporting | United States |
| Anthropic | AI coaching responses | United States |
| Strava | Activity upload, if you connect it | United States |
| Cloudflare, Resend | Website and email for this domain | EU / United States |
We do not sell personal data, and we do not share it with anyone for advertising or marketing. Transfers outside the EEA and the UK rely on the European Commission's Standard Contractual Clauses as implemented by those providers.
Your account, profile and workout history are kept until you delete them. Deleting an individual workout removes it immediately. Crash reports are retained by Firebase Crashlytics for up to 90 days. Trainer diagnostic records are kept only while the related hardware issue is being investigated.
Activities imported from Strava are held for no longer than seven days, after which only an anonymous daily training-load figure remains, with no reference to the original activity. Disconnecting Strava deletes both immediately.
Open Settings → Delete account in the app. This permanently removes your profile, your workout history, your Strava tokens and your sign-in credentials. It cannot be undone.
You can also stop specific processing without deleting anything: turn off the Health import in Settings, or disconnect Strava. Turning off the Health import leaves already-imported activities in place; delete them individually if you want them gone.
If you would rather we did it, email privacy@workitouttraining.com and we will delete your data within 30 days.
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to withdraw consent, to object to processing, and to complain to a supervisory authority. Israeli residents have equivalent rights under the Protection of Privacy Law, 5741-1981.
Exercise any of these by writing to privacy@workitouttraining.com. We answer within 30 days.
Data in transit is encrypted with TLS. Stored data is protected by access rules that permit only your own signed-in account to read or write your records. Strava refresh tokens are held in a server-only area that no app client can read. API keys for third-party services are held on the server and are not embedded in the app.
WorkItOut is not directed at children and is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has given us data, write to us and we will remove it.
If this policy changes materially we will update the date at the top and, where the change affects how your data is used, notify you in the app before it takes effect.