Privacy Policy
Last updated: August 1, 2026
This policy describes what information StrengthRank ("the app," "we") collects, how it's used, and the choices you have. It reflects what the app actually does today — not a future roadmap.
Information We Collect
Account information. When you sign in with Apple or Google, we receive your name and email address from that provider so we can identify your account. We never see or store your Apple ID or Google account password. On our servers, your email is stored only as a one-way hash, never in plain text.
Health data. With your explicit permission (requested the first time it's needed), StrengthRank reads recent heart rate and active energy from Health to show your training intensity, and writes your completed workouts to Health so they count toward your Activity rings. If you use the Apple Watch companion app, your workout session (including heart rate and calories) is recorded by watchOS and syncs to Health automatically — this happens through Apple's own Health sync between your paired devices, not through any StrengthRank server. We never request access to Clinical Health Records. Health data is never sold or shared with advertisers.
Workout history. The exercises, sets, reps, and weights you log are stored locally on your device (and, if you use the Watch app, shared directly between your iPhone and Apple Watch over a private on-device connection). This detailed history does not sync to any StrengthRank server — if you delete the app or change devices without a backup, it's lost. Separately, a small summary of each workout (how many you completed, total training minutes, streak days) is sent to our servers so it can power the leaderboard, alliance rankings, and challenge scores described below.
Leaderboard, alliances, and challenges. Your display name and workout summary scores are stored on our servers (Google Firestore) and are visible to other users through the leaderboard, any alliance you join, and any 1-on-1 challenge you accept — that's the intended, visible purpose of these features. If you turn on regional or "Nearby" leaderboard scope, we also store a coarse location code (derived from your device's country/region — and, for "Nearby," a broader locality approximation) alongside your score, so we can group you with other users in that area; we do not store or share your precise GPS coordinates. Location sharing defaults to off and can be changed or turned off anytime in Profile. Joining an alliance or accepting a challenge shares your display name and scores with the other members/opponent; it does not share your email, location, or Health data with them.
Invite codes. StrengthRank generates a short invite code tied to your account so other users can add you to an alliance or start a challenge without a name-search feature (names aren't unique). Sharing your code is optional and under your control — it only appears if you choose to share it.
AI-generated workouts. If you're a Premium subscriber and choose "AI Coached" workout generation, the goal, experience level, equipment, and duration you select — plus a short summary of your recent training — are sent to our server, which forwards them to Anthropic's Claude API to generate the workout. This request does not include your name, email, or any other account identifier; Anthropic processes it only to generate that response. See Anthropic's Privacy Policy for how they handle API data.
Advertising data. Free accounts see ads served by Google AdMob. Before requesting a personalized-ads identifier (IDFA), we ask for your permission via Apple's App Tracking Transparency prompt. If you decline, you'll still see ads, just less targeted ones. We don't control what Google's ad network does with data it collects directly — see Google's Privacy Policy for that.
Purchases. Premium subscription payments are handled entirely by Apple through the App Store. StrengthRank never sees or stores your payment card details — we only receive confirmation of your subscription status from Apple's StoreKit framework.
Crash and usage data. We use Firebase Crashlytics to automatically receive crash reports (with device type, OS version, and the code path that crashed) so we can fix bugs, and Firebase Analytics to see aggregate feature usage (like which workout types are popular). Neither includes your workout content or Health data.
How We Use Information
- To create and maintain your account and keep your sign-in working across app launches
- To show your workout history, training intensity, and progress inside the app
- To calculate and display leaderboard rank, alliance standings, and challenge results
- To generate AI-coached workouts for Premium subscribers who request one
- To show ads to free accounts and remove them for Premium subscribers
- To operate the Apple Watch companion app's live workout sync
- To diagnose crashes and understand aggregate feature usage
Third-Party Services We Use
- Firebase (Google) — authentication, Firestore database (leaderboard/alliance/challenge data), Cloud Functions (AI workout requests, alliance/challenge management), Crashlytics, Analytics
- Google Sign-In — one of the sign-in options
- Anthropic (Claude API) — generates AI-coached workouts from the preferences described above
- Google AdMob — ad serving
- Apple StoreKit — subscription purchases
- Apple HealthKit — reading/writing workout and health data, entirely on-device and governed by iOS's own Health permission system
- Apple WatchConnectivity — syncing workout data between your iPhone and Apple Watch, entirely on-device
Data Retention and Deletion
You can sign out at any time from Profile. You can permanently delete your sign-in account from Profile as well; this removes your account record, leaderboard entries, and invite code from our servers. When you do, you can optionally also erase your locally stored workout history from that same screen. Deleting your account does not automatically delete data already recorded in Apple Health — that's managed separately through the Health app, since it belongs to you, not to StrengthRank. If you're in an alliance or an active challenge when you delete your account, other members will still see your prior scores as historical entries but you'll no longer be reachable or addable by your old invite code.
Your Choices
- Health access: control or revoke StrengthRank's Health permissions anytime in Settings ▸ Privacy & Security ▸ Health ▸ StrengthRank.
- Ad tracking: control or revoke tracking permission anytime in Settings ▸ Privacy & Security ▸ Tracking.
- Location sharing: control your leaderboard location scope (Off / Regional / Nearby) anytime in Profile.
- Account deletion: available anytime from Profile inside the app.
Children's Privacy
StrengthRank is not directed at children under 13, and we do not knowingly collect information from children under 13.
Security
We rely on Apple's and Google's platform-level security (Sign in with Apple, Firebase Authentication, StoreKit) rather than storing credentials ourselves. Local data is protected by your device's own security (passcode, Face ID/Touch ID). Server-side data is protected by Firestore security rules that restrict each user to their own account data and to the leaderboard/alliance/challenge data that feature is designed to make visible.
Changes to This Policy
If this policy changes in a way that affects what we collect or how we use it, we'll update the "Last updated" date above.
Contact
Questions about this policy can be sent to: ahalley@ncf.edu