StrengthRank

Privacy Policy

Last updated: August 1, 2026

This policy describes what information StrengthRank ("the app," "we") collects, how it's used, and the choices you have. It reflects what the app actually does today — not a future roadmap.

Information We Collect

Account information. When you sign in with Apple or Google, we receive your name and email address from that provider so we can identify your account. We never see or store your Apple ID or Google account password. On our servers, your email is stored only as a one-way hash, never in plain text.

Health data. With your explicit permission (requested the first time it's needed), StrengthRank reads recent heart rate and active energy from Health to show your training intensity, and writes your completed workouts to Health so they count toward your Activity rings. If you use the Apple Watch companion app, your workout session (including heart rate and calories) is recorded by watchOS and syncs to Health automatically — this happens through Apple's own Health sync between your paired devices, not through any StrengthRank server. We never request access to Clinical Health Records. Health data is never sold or shared with advertisers.

Workout history. The exercises, sets, reps, and weights you log are stored locally on your device (and, if you use the Watch app, shared directly between your iPhone and Apple Watch over a private on-device connection). This detailed history does not sync to any StrengthRank server — if you delete the app or change devices without a backup, it's lost. Separately, a small summary of each workout (how many you completed, total training minutes, streak days) is sent to our servers so it can power the leaderboard, alliance rankings, and challenge scores described below.

Leaderboard, alliances, and challenges. Your display name and workout summary scores are stored on our servers (Google Firestore) and are visible to other users through the leaderboard, any alliance you join, and any 1-on-1 challenge you accept — that's the intended, visible purpose of these features. If you turn on regional or "Nearby" leaderboard scope, we also store a coarse location code (derived from your device's country/region — and, for "Nearby," a broader locality approximation) alongside your score, so we can group you with other users in that area; we do not store or share your precise GPS coordinates. Location sharing defaults to off and can be changed or turned off anytime in Profile. Joining an alliance or accepting a challenge shares your display name and scores with the other members/opponent; it does not share your email, location, or Health data with them.

Invite codes. StrengthRank generates a short invite code tied to your account so other users can add you to an alliance or start a challenge without a name-search feature (names aren't unique). Sharing your code is optional and under your control — it only appears if you choose to share it.

AI-generated workouts. If you're a Premium subscriber and choose "AI Coached" workout generation, the goal, experience level, equipment, and duration you select — plus a short summary of your recent training — are sent to our server, which forwards them to Anthropic's Claude API to generate the workout. This request does not include your name, email, or any other account identifier; Anthropic processes it only to generate that response. See Anthropic's Privacy Policy for how they handle API data.

Advertising data. Free accounts see ads served by Google AdMob. Before requesting a personalized-ads identifier (IDFA), we ask for your permission via Apple's App Tracking Transparency prompt. If you decline, you'll still see ads, just less targeted ones. We don't control what Google's ad network does with data it collects directly — see Google's Privacy Policy for that.

Purchases. Premium subscription payments are handled entirely by Apple through the App Store. StrengthRank never sees or stores your payment card details — we only receive confirmation of your subscription status from Apple's StoreKit framework.

Crash and usage data. We use Firebase Crashlytics to automatically receive crash reports (with device type, OS version, and the code path that crashed) so we can fix bugs, and Firebase Analytics to see aggregate feature usage (like which workout types are popular). Neither includes your workout content or Health data.

How We Use Information

Third-Party Services We Use

Data Retention and Deletion

You can sign out at any time from Profile. You can permanently delete your sign-in account from Profile as well; this removes your account record, leaderboard entries, and invite code from our servers. When you do, you can optionally also erase your locally stored workout history from that same screen. Deleting your account does not automatically delete data already recorded in Apple Health — that's managed separately through the Health app, since it belongs to you, not to StrengthRank. If you're in an alliance or an active challenge when you delete your account, other members will still see your prior scores as historical entries but you'll no longer be reachable or addable by your old invite code.

Your Choices

Children's Privacy

StrengthRank is not directed at children under 13, and we do not knowingly collect information from children under 13.

Security

We rely on Apple's and Google's platform-level security (Sign in with Apple, Firebase Authentication, StoreKit) rather than storing credentials ourselves. Local data is protected by your device's own security (passcode, Face ID/Touch ID). Server-side data is protected by Firestore security rules that restrict each user to their own account data and to the leaderboard/alliance/challenge data that feature is designed to make visible.

Changes to This Policy

If this policy changes in a way that affects what we collect or how we use it, we'll update the "Last updated" date above.

Contact

Questions about this policy can be sent to: ahalley@ncf.edu