Privacy Policy
What ProgressLoop collects, why it collects it, who else ever sees it, and how to make it stop.
Who is responsible for your data
ProgressLoop is a training app for iPhone and Android phones, with companion apps for Apple Watch and Wear OS watches, and this website. The controller of the personal data described below - the person who decides why and how it is processed - is Simeon Rosenov Simeonov. ProgressLoop is not a company: it is published by an individual, and no legal entity stands behind it.
For any question, request or objection about personal data, write to privacy@progressloop.eu. That address is read by the same person, and it is the only channel for data requests.
This policy covers the ProgressLoop iPhone app and the Apple Watch app that comes with it, the ProgressLoop Android app (eu.progressloop.ProgressLoop) and the Wear OS watch app that comes with it, the one account behind all of them, and the website at progressloop.eu. The apps do the same things with your data on either platform; where they differ - Apple Health on an iPhone, Health Connect on an Android phone - this policy says which is which.
The principles this is built on
Personal data is processed lawfully, fairly and transparently; for stated purposes; in the amount those purposes need; for a limited time; and with appropriate security. Four commitments are worth stating plainly, because they are the ones a training app is most often expected to break:
- Nothing is sold, and your record never reaches an advertiser. There are no ads inside ProgressLoop. The one thing an advertising company hears from us is that a few steps in the phone app happened - installing it, signing up, finishing a first workout and the like - so that we can tell whether our own ads on Facebook and Instagram bring people who actually train. No workout, weight, measurement, photo or health reading goes with them. Beyond that, our server only asks Apple which of its own ads, if any, led to an iPhone install. The section on measuring our own ads says exactly what is sent, and how Apple's tracking prompt on an iPhone, or your ad settings on an Android phone, decide what Meta may do with it.
- The website runs no analytics and no tracking. It loads no third-party scripts and talks to no server but its own - which is why you have never been shown a cookie banner on it. That is a promise about this website; the apps are described separately below.
- Your training record is yours. It is not used to build a profile of you for any purpose other than showing you your own history. Five things widen who sees any of it, and each is yours to start: an AI reading of a week of it, recipes written by the meal assistant, a personal trainer you apply to, putting your schedule into a calendar of your own, and - if you coach - sending one of your own plans, guides or recipes to a client. None of them happens until you choose it. And a workout photo you share goes only where you send it, carrying only what is drawn on it.
- Two things are public, and you choose both. A review you give a trainer is read by everyone who browses the trainer directory, and so is your trainer profile if you switch on as a trainer. Nothing else you put into ProgressLoop is.
What we process
Your account
- Your email address, and your name if you give one. An account made by signing in with Apple can have no address at all - see how you sign in, below.
- Your password, if you set one, stored only as a cryptographic hash - the original is never written down and cannot be read back. An account made by signing in with Apple or Google has no password here at all.
- Your gender, if you set one, because some body-composition figures depend on it.
- A profile picture, if you upload one.
- Account status, when it was created, and the units you prefer to read weights and lengths in.
- When you accepted the Terms of Use and this Privacy Policy - the moment you ticked the box, and nothing else about it. It is recorded whether you registered with an address and a password or made the account by signing in with Apple or Google, since the app asks either way before the account is made.
How you sign in
- If you sign in with Apple or with Google: the identifier that provider gives us for you in ProgressLoop, the email address it passes on, if you let it, and your name, if it passes one. That is the whole of what we ask either of them for and the whole of what we receive - nothing else in your Apple or Google account is read, and nothing can be done in it on your behalf. An Apple account is recognised by that identifier from then on; a Google one is found by the address Google confirms, whatever capitals it is written in. Sign in with Apple is offered in the iPhone app; the Android app offers an address and a password, or Google, through the account picker Android itself shows. Either way you reach the same account from both.
- Sign in with Apple lets you keep your address to yourself, and we hold what you chose. Hide My Email means the address on the account is the forwarding one Apple gives us, never your own - everything below about email is then about that forwarding address, and what it forwards to is between you and Apple. Sharing no address at all means the account has none: nothing can be emailed to it, and the section on emails and notifications says what that changes.
- For Sign in with Apple, the authorisation Apple issues for your account, stored encrypted. It is used for one thing: handing it back to Apple when the account is deleted, which Apple requires of an app that offers both its sign-in and deletion in the app.
- If you signed in with a provider on an address that already had a ProgressLoop account, the two are the same account: you land on the record you already had rather than a second, empty one, and it keeps the password it had, if it had one. Choosing to hide your address gives you an account of your own instead, because the address Apple forwards from is nobody else's.
What you train
- Exercises you add or edit, workouts, training programmes and the days inside them.
- Every session you run: which sets you logged, the load and reps of each, how long you rested, when you started and when you finished.
- For sessions recorded with the Apple Watch app, your average and peak heart rate and the active energy you burned during the session. See the section on health and body data below.
- For sessions recorded with the Wear OS watch app, your average and peak heart rate during the session. See the section on Health Connect and Wear OS below.
- For a set the Apple Watch counted, the number of reps it counted, kept beside the number you logged whether or not you changed it.
- If you switch on Share workout motion, the motion your watch recorded while you trained, with your sets beside it. See the section on workout motion below.
- Which ready-made workouts and programmes you have copied to your account, so we can show how many people use each one. Only the total is shown; users are not identified.
- Notes you choose to write on a session, an exercise or a set in it, and whether you marked a session as a lighter day. See the section on health and body data below - these can say something about your health, and are treated that way.
- Skills you are working through and the levels you record against them.
- Habits you set, and which days you ticked them off.
- Your training goal, its targets for calories, protein, fat, carbohydrate and sessions - worked out from your body weight and body fat - and the phase it belongs to.
- The reminders you set, their scheduled days and, if you specify it, what each reminder is for: a workout, a habit, a weigh-in or a check-in.
- Your schedule: each workout you plan, with its name, when it starts and how long it lasts, any notes, the workout it is for if you link one, and who planned it if your trainer did. For a plan that repeats, its repeat rule - how often, on which weekdays, when it stops and the time zone it is read in - and the times of it you deleted or moved on their own.
Your body
- Body weight and the daily entries it is recorded in, with the note you write on a day, if you write one.
- Check-ins: girth measurements, skinfold readings and the dates they were taken.
- Progress photos you choose to take, and the pose each was shot in. With each photo taken in the app's camera, how it was taken: which camera, the picture's size, how the phone was tilted, the camera's exposure settings, and where your body stood in the frame, as a set of points - so the next photo can be lined up with it. See the section on health and body data below - these are treated differently from everything else.
- On an iPhone: steps, workouts, exercise minutes, active energy, walking and running distance, flights climbed, resting heart rate, heart-rate variability and VO₂ max read from Apple Health, if you allow each data type.
- On an Android phone: steps, exercise sessions, active calories burned, distance, floors climbed, resting heart rate and VO₂ max read from Health Connect, if you allow each data type. See the section on Health Connect and Wear OS below.
Your meals
- The meals you keep as recipes: the name, your own category for it, what kind of meal it is, servings, how long it takes, whether it works cold or is vegetarian, how to store it, a substitution, the ingredients with their amounts, and the steps. Its calories and macros if you give them, and whether they were typed by a person or estimated by the meal assistant. How much it fills you up and how much you like it, if you say.
- A picture of the meal, if you upload one or the meal assistant draws one, and whether it was drawn. Where the meal came from: written by you, taken from something your trainer sent, or saved from the meal assistant.
- Your food notes, if you write them: up to 500 characters on what you dislike, what you are allergic to and what your kitchen lacks. See the section on health and body data below - an allergy is health data.
- Your food diary, if you keep one: for each thing you log as eaten on a day, its name, the kind of meal, how many portions, the calories, protein, carbohydrate and fat for what you ate, whether those figures are an estimate, and which of your meals or our recipes it came from.
- Which of our ready-made recipes you have starred, so we can show which are liked most. Only the total is shown; users are not identified.
The meal assistant, if you turn it on
- Whether you have turned it on. Each request you make and the recipes it returned, for one day; and a record of each call it made - what kind, which model, and the tokens or seconds it used - holding none of your words. Off by default; see the section on the meal assistant below for what is sent.
AI training reviews, if you turn them on
- The written reading of each week that is read, the marked facts it rests on, and which model and prompt version produced it. Off by default; see the section on AI training reviews below for what is sent to produce it.
Coaching, if you use it
- If you apply to a trainer: who you applied to, the note you sent, their answer and anything they wrote with it, whether you share your progress photos with them, when the coaching started and ended, who ended it, and any note left when they did.
- Which workouts and programmes in your account a trainer put there, and which sessions a trainer started for you.
- Workouts, programmes, nutrition guides and recipes a trainer sent you: a copy of each as it was when they sent it - a guide with its recipes, pictures and any PDF attached to it - who sent it, when, the note they wrote with it, and whether you added it, removed it or have not answered yet.
- Sessions booked with your trainer: each time you asked for or they booked you in for, how long it lasts, whether it is pending, confirmed, declined or cancelled, the note each of you wrote, when it was answered, and which of you cancelled it. If a session moves, where it was before it last moved; and while a client has asked to move a confirmed session, the new time they asked for and the note they sent with it.
- Reviews you write of a trainer: the stars, any comment, when you wrote it and last changed it, and whether the trainer is showing the comment.
- If you switch on as a trainer: your headline, your bio, whether you are taking clients, the hours you take sessions in - how long a session lasts, the rest you usually keep between clients, your weekly windows and your time zone - and the same record of each application, client, booking, review and plan you sent from your side, including the rest you set after each booked session. The nutrition guides you write for your clients: the title, a summary, the blocks of advice and recipes in them, and any PDF you attach.
Steps you reach in the app
- Which of a fixed list of steps have happened on your phone - such as creating an account, picking a plan or finishing your first workout - and whether each was already reported to Meta, kept on the phone so that none is reported twice. What is sent, and what never is, is set out in the section on measuring our own ads below.
- The install the account was made on: a random install identifier the app makes up, the kind of phone and the app version, and the ad campaign it came from where Apple, Google Play or Meta can say - set out in the same section, under which ad brought you.
Notifications and calendars
- How you want each kind of message to reach you - by email, as a notification or both - for each topic you have changed. A topic you never changed stores nothing and uses the default.
- Each phone signed in to your account that can receive notifications: the address the app on that phone is issued to deliver them to - by Apple on an iPhone, by Google's Firebase Cloud Messaging on an Android phone - whether it is an iPhone or an Android phone, for an iPhone whether it is a development or an App Store build, the app version, and when it last checked in. Not the phone's name or model.
- If you connect Google Calendar: the email address of the Google account you connected, the permission Google gave us to write to it (stored encrypted), the calendar we created there, the title start, alert and colour you chose, whether you let us set that colour in Google, whether it is still connected, when it was last brought up to date, and which event in it belongs to which of your plans.
Emails
- Your answer for each of the three kinds of optional email - news and offers, tips and progress, and feedback requests - and when you last gave it.
- A record of each time you turned one on or off: which kind, which way, how - a box at sign-up, the app's settings, the link in one of those emails, your mail program's own unsubscribe button, our staff at your request, or reporting one as spam - and when. Where it was our staff, which member of staff.
- A random code that the links in those emails carry, so the page they open knows whose choices to show without asking you to sign in.
- For each survey we email you, if you get feedback requests: when it was sent, the score from 0 to 10 you chose, the comment you wrote, if any, and when you answered. And a random code that the survey's links carry, so the page they open knows which survey it is without asking you to sign in; we keep only a one-way scrambled form of it.
- For every email we send you, optional or not: what kind of email it was, the address it went to, when, and what Amazon's mail service reported about it afterwards - delivered, bounced, reported as spam, and when it was opened and which of its links was followed. Never the words of the email itself, and never a link that carries a code of yours, such as the one that resets a password.
Technical and security data
- A session token on your device, which is what keeps you signed in, and a record of the sessions issued to your account, with when each was last used, to within an hour. Each session also records the phone app's platform, version and build number, reported with requests, so we can diagnose problems and show relevant update notices.
- Server logs: the IP address a request came from, the time, and what was asked for. These exist to keep the service working and to notice abuse.
Not on this list: a workout photo you take or pick in the app to share. It never reaches us. The section on workout photos below says what happens to it.
Health and body data, and why it is treated differently
Body weight, girths, skinfolds, progress photos, the health and fitness data you let the app read from Apple Health or Health Connect, the heart rate a watch measures while you train, the notes you write on your workouts and your days, and marking a session as a lighter day all say something about your physical condition. Data protection law treats data concerning health as a special category, which needs a stronger basis than ordinary personal data does. ProgressLoop relies on your explicit consent for it, given by choosing to record it.
In practice that means every one of these is optional and separately given. You can use the app to plan and log training and never enter a weight, never take a measurement and never take a photo. Turning any of them off, or withdrawing consent, stops future processing and does not affect your account or anything else in it.
On an iPhone, Apple Health is where this goes the other way. When you train with the Apple Watch app, the watch records that session in Apple Health as a workout. That is what lets it keep running with your wrist down, and it is what gives it your heart rate and the energy you burn while the session lasts. Writing needs a permission of its own in iOS, asked for and withdrawn separately from the ones that let the app read. ProgressLoop keeps three figures from that workout: your average heart rate, your peak heart rate and the active energy you burned during the session. These are saved with the session in your account for you to review afterwards. They are health data, processed on the basis of the same explicit consent you give when you allow the watch to read your heart rate and active energy. If you withdraw that permission in the Health app, no new figures are saved. Individual heart-rate readings remain in Apple Health. The section on Apple Health below sets out exactly what is written, what is kept, and who else can read it.
A Wear OS watch works the same way, with less kept. While you train with the Wear OS app, the watch measures your heart rate, with the permission Wear OS asks you for, and when you finish it keeps two figures with the session in your account: your average and your peak heart rate. They are health data, processed on your explicit consent, given in that permission prompt; refusing or withdrawing it means no heart rate is measured or kept. The Android phone then records the session in Health Connect, with a permission of its own, as the section on Health Connect and Wear OS below describes.
So are your food notes, where they name an allergy. What you are allergic to says something about your health, so the food notes are handled on the same basis as the rest of your health and body data: they exist only if you write them, you can clear them at any time, and they are never shown to a trainer. They are sent anywhere only if you turn on the meal assistant, as described below.
Workout notes and lighter days are part of this too. While you log a workout you can write a note on the whole session, or on an exercise or set in it - how the day went, or what you trained around, such as a sore elbow - and you can mark the session as a lighter day, meaning you deliberately trained below plan because you were injured, ill or run down. A note may say nothing about your health at all, but because it can, every note is handled on the same basis as the rest of your health and body data, and so is the lighter-day marker. Both are kept with the session in your history. The same holds for the note you can write on a whole day, on the app's "Log the day" screen: it is kept with that day's entry and handled the same way.
- Both are only ever recorded by a person: a note exists only if you write one, and a session is a lighter day only if you switch it on - or, if you have a personal trainer and they log a session with you, if they do, as part of the coaching you agreed to by applying. The app never marks a lighter day on its own. Nothing in the app reads a note for what it means, with one exception you choose: if you turn on AI training reviews, the notes on a week's sessions and days are sent to OpenAI and read by its model, as described below.
- A lighter day does two things: nothing in that session pushes the load up, and its weights are not where the next session starts from. It hides and deletes nothing - the session stays in your history, your charts and your totals exactly as you lifted it.
- Neither is used for advertising. Both are part of an AI training review only if you turn those on, and never otherwise.
- You can clear a note or switch the marker off by editing the session, at any time, without touching the rest of it. Deleting the session or your account removes them too.
Progress photos deserve their own sentence. They are stored in a private bucket that is not readable from the internet; the app is handed a short-lived signed address each time it needs to show you one, and that address expires. They are never used for anything but showing them back to you. They are shown to nobody else, with one exception you control: while you have a personal trainer and have turned on photo sharing for them, that trainer can see them too. Sharing is off until you turn it on, and turning it off hides them again straight away. They are never part of an AI training review.
The app's camera looks for your body while you frame a progress photo, and only on the phone. So that this week's photo lines up with last week's, the camera finds where you are standing in the picture and tells you to step or tilt the phone. That is worked out on the phone itself - on an iPhone by iOS, on an Android phone by Google's ML Kit running on the device - and no picture is sent anywhere to do it. What is kept with the photo is the result described above: how the phone was held and where your body stood in the frame, as points. Nothing reads a photo once it is taken. On an Android phone you can also turn on voice commands in that camera, so you can say "photo" instead of reaching for the screen; the microphone is then listened to by the phone's own speech recogniser, on the phone, for the few command words alone, and nothing you say is recorded or sent anywhere. A phone that cannot recognise speech on its own does not offer voice commands at all. The same camera has a second, separate use in the iPhone app - a photo of a finished workout to share - and that photo is never stored; the section on workout photos below describes it.
Three uses of body data need a consent of their own. The first is having a personal trainer. Once a trainer accepts your application, they can see your body weight, your measurements and check-ins, the steps and workouts that reach your daily entries from Apple Health or Health Connect, the heart rate kept from a watch session, and the notes on your sessions and exercises and which sessions you marked as lighter days, alongside the rest of your record. Applying is what agrees to that - the screen you apply on lists what they will see - and ending the coaching, which you can do at any time, withdraws it at once. See the section on personal trainers below.
The second is the AI training reviews. If you turn them on, your average body weight and how your waist and skinfold readings moved over the weeks being read are sent to OpenAI as part of the week's figures, and so are the notes on that week's sessions and days (a long note shortened, and only a limited number sent) and which sessions were lighter days. Recording a weight, writing a note or marking a lighter day does not agree to that; only turning the reviews on does, and the screen that turns them on says so.
The third is the meal assistant. If you turn it on, each request sends OpenAI your food notes - allergies included - and, from your active goal, your body weight. Writing food notes or setting a goal does not agree to that; only turning the assistant on does, and it is a separate switch from the training reviews'.
Where the data comes from
- From you, directly, when you register, set the app up, and use it.
- From Apple or Google, if you choose to sign in with them: the identifier, address and name described above, and nothing else.
- From Apple Health on your device, for the data types listed above, and only after you grant each permission in iOS. Reading is only half of that relationship: the watch writes each session you finish into Apple Health, on a permission of its own, as the section on Apple Health below describes.
- From Health Connect on your Android phone, for the data types listed above, and only after you grant each permission in Health Connect. The phone also writes the sessions your Wear OS watch measured into Health Connect, on a permission of its own.
- From your watch, if you train with one: the heart rate it measures during a session, the reps it counts in a set, and - only if you switch on sharing workout motion - the motion it recorded while you trained.
- From your trainer, if you have one: the workouts, programmes, exercises and sessions they create or log in your account, the workouts, programmes, nutrition guides and recipes they send you, what they put on your schedule, the sessions they book you in for, and the notes they write to you.
- From other people, if you are a trainer: the name and note of each person who applies to you or asks you for a session, whether each client added or removed a plan, guide or recipe you sent them, and the reviews your clients and former clients write.
- From OpenAI, if you use the meal assistant: the recipes it writes, the text it hears in a recording, and the pictures it draws.
- From Apple, Google Play and Meta: which ad campaign, if any, an install of the app came from, as the section on measuring our own ads describes.
- Automatically from your device and the network, for the technical and security data above.
Why we process it, and on what basis
| Purpose | Data | Legal basis |
|---|---|---|
| Creating your account and signing you in | Your email address if the account has one, your password hash if you set one, your name, session tokens, and the identifier Apple or Google gives us if you sign in with one | Performance of the contract between you and us |
| Running the app: your plans, sessions and history | Exercises, workouts, programmes, sessions, sets, skills, habits, goals | Performance of the contract |
| Keeping your meals and recipes | Each meal's recipe, numbers and where they came from, picture and where the meal came from; your food diary; the recipes you starred | Performance of the contract |
| Keeping your food notes | What you dislike, are allergic to and cannot cook with | Your explicit consent, given by writing them |
| Writing recipes for you, reading recipes out of text you paste, turning a recording into text and drawing a meal's picture, if you turn the meal assistant on | What you typed, pasted or said and the month; your gender; from your active goal your body weight, goal type and estimated daily calories; your food notes; for a picture, the recipe's name and main ingredients | Your explicit consent, given by turning the meal assistant on - the only basis on which food notes and body weight are sent |
| Your schedule: planning when you will train | Each planned workout's name, start, length and notes, the linked workout, and who planned it | Performance of the contract |
| Adding a planned workout to Apple Calendar or Google Calendar from the iPhone app, when you tap it | That plan's name, start and end, notes and linked workout name | Performance of the contract, at your request, carried out on your phone |
| Keeping your phone's calendar - iPhone Calendar, or a calendar on your Android phone - in step with your schedule, if you switch it on | Each plan's name, start and end, repeat rule, notes and linked workout name; for a trainer, each booked session with the client's name and both people's notes. Written on your phone, not by our servers | Performance of the contract, at your request |
| Keeping your Google Calendar in step with your schedule, if you connect it | The same as for your phone's calendar, plus your Google account's email address and the encrypted permission to write to it | Performance of the contract, at your request |
| Telling you about coaching, sessions and plans sent to you, and reminding you of a session the next day or of requests waiting for your answer, by notification or email as you chose | Your choice per topic; each registered phone's notification address, whether it is an iPhone or an Android phone, an iPhone's build type, and the app version; the message itself - the other person's name, their note, a plan's name or when a session starts, and for a trainer how many applications and session requests are waiting | Performance of the contract |
| Body weight, measurements, check-ins and progress photos | Health and body data | Your explicit consent, given by recording it |
| Notes on your workouts, exercises and days, and marking a session as a lighter day | Session, exercise, set and day notes, the lighter-day marker | Your explicit consent, given by writing the note or switching the marker on - or, for a session your trainer logs with you, by applying to them |
| Reading the health and fitness data you select in Apple Health | Health data from HealthKit | Your explicit consent, given in the iOS permission prompt |
| Reading the health and fitness data you select in Health Connect, filling your daily entries from it and showing you the rest on your phone | Health data from Health Connect; of it, only each day's steps, the activities you linked to a kind of workout, and a step goal's tick reach your account | Your explicit consent, given in Health Connect's permission screen |
| Measuring your heart rate on a Wear OS watch while you train, keeping your average and peak with the session, and recording the session in Health Connect | Heart rate during the session (health data); in Health Connect, a strength training session with its name, start and end, which Health Connect keeps on your phone, not us | Your explicit consent, given in the Wear OS prompt to measure heart rate and in Health Connect's permission screen to write exercise |
| Recording the session you just trained in Apple Health, from the Apple Watch app | A strength training workout: its start and end, how long it lasted, the active energy and the heart rate the watch measured. It is kept by Apple Health on your device, not by us | Your explicit consent, given in the iOS permission prompt that asks to write to Apple Health |
| Showing you and your trainer, if you have one, your heart rate and active energy for sessions recorded with Apple Watch | Your average and peak heart rate and active energy for the session (health data) | Your explicit consent, given in the iOS permission prompt that lets the watch read your heart rate and energy |
| Checking and improving how the watch counts reps, if you switch on sharing workout motion | The watch's motion while a workout was open, the workout's set marks, each set's movement, load, logged and counted reps and length, and the watch's model, system, app version and wrist | Your explicit consent, given by switching it on - and withdrawn, with every recording deleted, by switching it off |
| Reading a week of your training back to you, if you turn AI reviews on | Aggregates of that week: body weight and measurement change, sessions against plan, movements with set counts and estimated maxes, steps against target, goal targets. And that week's sessions: which were lighter days, movements skipped, and the session, exercise and set notes. And the note on each of that week's days. Every note cut at 500 characters, and at most 40 of them in all | Your explicit consent, given by turning AI reviews on - the only basis on which notes and lighter days are sent |
| Listing you in the trainer directory, if you switch on as a trainer | Name, profile picture, headline, bio, whether you are taking clients, how many clients you have | Performance of the contract, at your request |
| Applying to a trainer, answering, ending it, and the emails each step sends | Both people's names, the notes each writes, where the coaching stands | Performance of the contract, at your request |
| Publishing a trainer's session hours; asking for, booking, confirming, declining, moving and cancelling sessions, and asking for a new time; putting a confirmed one on the client's schedule; and the emails each step sends | The trainer's hours and time zone; each booking's time, length, status, notes and who cancelled it; a new time asked for and its note, and the time before the last move; both people's names | Performance of the contract, at your request |
| A trainer sending a client a workout, programme, nutrition guide or recipe, the client adding or removing it, the trainer withdrawing it, and the email that tells the client it arrived | A copy of what was sent - with the trainer's own exercises a plan uses, or a guide's recipes, pictures and PDF; both people's names; the trainer's note; when it was sent; whether it was added, removed or not yet answered | Performance of the contract, at your request |
| Showing reviews in the trainer directory, and each trainer's rating | Stars and comment, the reviewer's first name and last initial, whether the comment is shown; the trainer's average and number of reviews | Performance of the contract: at the reviewer's request, and as part of being listed as a trainer |
| Showing your record to the trainer you applied to, while they coach you | Your training, including session and exercise notes and lighter days, schedule, goals, habits, skills, meals (not the food diary), settings, body weight, measurements, check-ins, steps and workouts from Apple Health or Health Connect, heart rate kept from a watch session, AI training reviews already produced; your name, email address, gender and profile picture | Your explicit consent, given by applying, for as long as the coaching lasts |
| Showing your progress photos to your trainer | Progress photos | Your explicit consent, given by turning photo sharing on |
| Measuring whether ProgressLoop's own ads on Facebook and Instagram bring people who go on to train, and steering them towards those people | That one of the listed steps happened on a phone, once per account, and whether it is an athlete or a trainer step; the technical details Meta's SDK attaches to any event; an iPhone's advertising identifier only if you allow tracking, and an Android phone's unless you have deleted it in the phone's ad settings | Our legitimate interest in knowing whether our advertising works. On an iPhone, your consent, given in Apple's tracking prompt, for linking it to the advertising identifier; on an Android phone, that same interest, within the ad settings you choose for the phone |
| Counting how many people each of our ad campaigns brought, and how far they got | A random install identifier, the kind of phone and the app version, the campaign, ad group and ad the install came from where Apple, Google Play or Meta provide them, and the account it was linked to when the account was made | Our legitimate interest in knowing whether our advertising works. Meta's campaign on an iPhone is read only after your consent in Apple's tracking prompt |
| Sending the optional emails you asked for: news and offers, tips and progress, and feedback requests | Your email address, name and language, and which kinds you turned on. For the weekly summary in tips and progress, figures from your own record for the week: sessions finished against your target and whether it was met, working sets, average body weight and how it moved, whether you were on track for your goal, and average steps against your target; for a trainer, counts across their clients, never names. For a nudge, the days since you last trained or opened the app; for a first-steps tip, whether you have set a goal, picked a plan or finished a workout. For news and offers, also whether you have a trainer profile, since some are sent only to trainers or only to everybody else. For the survey, how long you have had your account and how many workouts you have finished, and when you were last asked. For a request to review a trainer, which trainer it is about and their name, how many confirmed sessions with them are over, whether they coach or coached you, and whether you have already reviewed them | Your consent, given separately for each kind by ticking its box at sign-up or turning it on in the app, and withdrawn whenever you turn it off. For tips and progress, that is also your explicit consent to your body weight being put in an email to you |
| Being able to show when and how you agreed to those emails, and when you stopped them | Each time a kind was turned on or off, how and when, and for a change our staff made at your request, which member of staff | Our legal obligation to be able to show that you consented |
| Understanding what people think of ProgressLoop, from the surveys they answer | The score and any comment you gave, when you answered, and the account they belong to | Your consent: the survey goes only to people who turned feedback requests on, and answering it is up to you |
| Knowing whether our emails arrive, keeping addresses that bounce or complain off our list, and seeing which emails are read | Which email went to which address and when, and what Amazon's mail service reported about it: delivered, bounced, reported as spam, opened, and which link was followed | Our legitimate interest in mail that works and is not unwanted; for the optional emails, the consent you gave to receive them |
| Reminders you asked for | Reminder settings and weekdays | Performance of the contract, at your request |
| Being able to show that you accepted the Terms of Use and this policy | When you ticked the box at registration | Our legitimate interest in knowing what each account agreed to |
| Keeping the service working, and noticing abuse | IP address, technical logs, session records | Our legitimate interest in a service that works and is not abused |
| Improving the app from feedback you choose to send | Account, topic, rating, comment, platform, app version, language and date | Our legitimate interest in finding problems and improving the service |
| Answering you when you write in | Your message and the address you sent it from | Our legitimate interest in replying; legal obligation where one applies |
Where we rely on legitimate interest
Legitimate interest is used for the purposes below and for the optional app feedback described in its own section. The first is keeping the service running and secure. That covers server logs, the IP address a request arrived from, and the record of which sessions are signed in. Weighing it up: the interest is in a service that stays up and is not abused, which is also your interest in it; the data is technical rather than about your training or your body; logs are kept briefly and session records with the account; and it is what anyone would expect a service they signed into to record.
The second is recording when you accepted the Terms of Use and this policy. It is one date on your account, kept only as long as the account, and it is what lets either of us show what was agreed if that is ever in question.
The third is measuring ProgressLoop's own advertising. ProgressLoop is free and is found largely through ads on Facebook and Instagram; without knowing which of them bring people who go on to train, the money goes to the ones that bring installs nobody opens twice. Weighing it up: what is sent is limited to a short list of steps, each once, with no name, email address, account id or anything you recorded; on an iPhone it is never linked to your advertising identifier unless you allow it in Apple's prompt, and on an Android phone it goes with the advertising identifier only while the phone's own ad settings give the app one, which you can stop at any time; and what Meta reports back to us is counts, never people. The same holds for the campaign each install came from, which our own server records: it is linked to an account only so it can be counted per campaign, it is never shown against a person, and it goes with the account. The section on measuring our own ads sets it out.
The fourth is the record of the emails we send: which went to which address, and whether each was delivered, bounced, reported as spam, opened, or had a link followed. Weighing it up: without it we could not tell an email that arrived from one that did not, or stop writing to an address that bounces or that asked us to stop; it holds no words of the emails and no link that carries a code of yours; it is seen only by our own staff; and it goes with the account. An opened email is counted because the email shows a tiny image fetched from Amazon's mail service, and a followed link because it passes through that service on its way. A mail program that does not load images counts no open, and some, Apple Mail among them, load the image for every email whether you read it or not, so an open is only ever an estimate.
You can object to processing based on legitimate interest - see your rights below. No body or health data is processed on this basis, and nothing about what you train beyond the fact that a numbered workout was finished.
Apple Health
Apple Health is read in one direction and written in the other, and each direction is a separate permission you give in iOS and can take back there. What is read is listed first; what the watch writes is listed after it.
What ProgressLoop reads
On an iPhone, if you allow it, ProgressLoop reads steps, workouts, exercise minutes, active energy, walking and running distance, flights climbed, resting heart rate, heart-rate variability and VO₂ max from Apple Health. Permission is granted in iOS per data type and can be withdrawn at any time in the Health app, which stops future reading immediately.
Steps and summaries derived from workouts can fill your account's daily entries. The other readings stay only on this device and are shown on the Apple Health history screen; they are removed from the device when you sign out, delete the account or uninstall the app. What ProgressLoop reads from HealthKit is never used for advertising or marketing, never sold and never disclosed to a third party for its own purposes. The ad measurement described below learns only that you connected Apple Health, once, and never any reading from it.
Two exceptions exist, and each only if you choose it. An AI training review includes your average daily steps for the week, and those steps may have come from Apple Health. They are sent to OpenAI solely to produce that reading, as described in the next section, and no other Apple Health reading is sent. And if you have a personal trainer, the steps and workout summaries in your daily entries are part of the record they can see, solely so they can coach you. The readings that stay on this device never reach them.
What the Apple Watch app writes
When you train with the watch, ProgressLoop records that session in Apple Health as one traditional strength training workout. Holding a workout open is what lets a watch app keep running with your wrist down, and it is what makes your heart rate and the energy you are burning available to the watch while you train.
The workout carries what Apple Health keeps for any workout: when it started and ended, how long it lasted, the active energy burned, and the heart-rate samples the watch collected while it ran. Nothing else goes into it. No exercise names, no loads, no reps, no notes and no body data - the training itself is recorded in your ProgressLoop account, not in Apple Health.
ProgressLoop keeps only three figures from this Apple Health workout. When you finish, the watch sends our server your average heart rate, peak heart rate and active energy for the session. These are saved with the session in your account. You can review them afterwards, and your personal trainer, if you have one, can see them alongside your other session details. They are not sent for AI training reviews. Individual heart-rate readings remain in Apple Health and are never sent to us. Sessions recorded only on your phone do not include these figures. Nothing about that workout is used for advertising, sold, or given to anyone for their own purposes.
The watch asks for permission to read four types of data: heart rate, active energy, step count and your Activity summary. It also asks for permission to save workouts. Apart from the three figures above, the data it reads is displayed only on the watch and is not sent elsewhere. Step count is used only for the watch's steps ring.
Writing is asked for in iOS separately from reading and can be withdrawn at any time in the Health app, which stops future writing immediately. Once a workout is in Apple Health it is Apple Health's: it is yours to keep or delete in the Health app, and - this is Apple's model rather than ours - any other app you have allowed to read your workouts can read that one, exactly as it can read a workout written by any other app on your device. It is the one way something you did in ProgressLoop can reach an app we have nothing to do with, and the permission that decides it is given to that app by you, in iOS.
Health Connect and Wear OS
On an Android phone, Health Connect is where Android keeps health and fitness data, and ProgressLoop uses it the way the iPhone app uses Apple Health: it reads from it, if you allow it, and it writes into it only the sessions your Wear OS watch measured. Reading each data type and writing exercise are separate permissions, which you give in Health Connect when you choose to connect it - from Settings or from Today, never on its own - and can take back there at any time, which stops future reading or writing immediately.
What ProgressLoop reads, and why
- Steps - to fill in each day's step count, show it against your step target and tick a habit whose goal is a number of steps.
- Exercise sessions - so that a workout another app recorded, such as a run or a ride, can count towards an activity you track, and so you can see it in the app. The sessions ProgressLoop wrote itself are left out.
- Active calories burned, distance, floors climbed, resting heart rate and VO₂ max - to show you, day by day, on the app's Health Connect screen.
- Your history. When you first connect, the app reads up to 90 days back, with the permission Health Connect asks for older data; without it, Health Connect hands over the last 30 days. After that it reads only while the app is open, and never in the background.
What leaves your phone
Three things read from Health Connect reach your ProgressLoop account, as part of your daily entries on our servers in the European Union: each day's step count; for each activity you linked to a kind of workout, whether you did it, or its minutes or count; and the tick on a step-goal habit. Everything else stays on your phone, in the app's own storage, for up to a year; it is shown only there, and it is deleted from the phone when you sign out, delete your account or uninstall the app. It is never included in a backup or a transfer to a new phone.
Those daily entries then go where the rest of your record goes and nowhere else: to a personal trainer you apply to, while they coach you, solely so they can coach you; and, if you turn on AI training reviews, your average daily steps for the week go to OpenAI solely to produce that reading. No other Health Connect reading is sent to anyone.
What the phone writes
When you finish a session on your Wear OS watch, your phone records it in Health Connect as one strength training exercise session: when it started and ended, and its name - the name of the workout you trained. Nothing else goes into it: no heart rate, no calories, no exercises, loads, reps or notes. A session logged on the phone alone is not written. Once it is there it belongs to Health Connect on your phone: it is yours to keep or delete there, deleting your ProgressLoop account does not remove it, and - this is Android's model rather than ours - any other app you have allowed to read your exercise can read it, as it can any other app's.
What Health Connect data is never used for
Data from Health Connect is never used for advertising or marketing, never sold, never used to decide anything about you such as credit or insurance, and never passed to anyone for their own purposes. One fact about it does reach an advertising company, and it is not a reading: the first time you connect Health Connect, the app tells Meta that the step "Apple Health or Health Connect was connected" happened, as the section on measuring our own ads describes - without a single reading from it. ProgressLoop's use of data received from Health Connect follows Google Play's policy for health permissions.
The Wear OS watch
The Wear OS app has no sign-in of its own: your Android phone hands it your session over the connection between them, and it then talks to our server itself, over the watch's own connection. While you train it keeps the workout running in the foreground, which is what lets it carry on with your wrist down, and reads your heart rate from the watch's sensors, with the permission Wear OS asks for when you start your first workout. It also asks to recognise your physical activity, which is how it counts your steps for its steps ring.
Your live heart rate is shown on the watch. When you finish, the watch sends our server two figures: your average and your peak heart rate for the session, which are kept with the session in your account and seen by your trainer, if you have one, with the rest of it. They are not sent for AI training reviews. The watch measures no calories, and no single heart-rate reading leaves it. The steps it counts draw its ring and are never sent anywhere; your phone's reading from Health Connect is what fills your day. A session or a change to your day that the watch has not yet delivered waits on the watch until our server has it.
Workout motion from the watch
The Apple Watch app is learning to count a set's reps from how your wrist moves. To check how well it counts, and to make it count more movements correctly, you can choose to send us the motion your watch recorded while you trained. The switch is Share workout motion, in the iPhone app's settings for the watch.
It is off until you switch it on, and while it is off no motion leaves your phone. It belongs to your account rather than to one phone, so a second phone takes the same answer, and switching it off is honoured everywhere.
What is sent
- The motion your watch measured while a workout was open: how it accelerated, which way was down, how it turned and how it was oriented, about a hundred readings a second, each with the moment it was taken.
- The moments in that workout the readings are lined up against: when a set was started, ticked off, cancelled or taken back, when a rest started and ended, and when the watch's workout session started, failed or ended.
- Each set you logged while it recorded: the movement, the kind of set, the load, the reps you logged and the reps the watch counted, how long it took and when you finished it.
- Your watch's model and system version, the app's version, which wrist you wear it on and which side its crown is on, and how often it was asked to measure.
Nothing else goes with it: no location, no heart rate or other Apple Health reading, no notes, photos or body data, and not your name or email address. The phone uploads each recording once its workout is finished, over Wi-Fi unless you allow otherwise, and deletes its own copy a week after we have it. The watch sends nothing itself.
What it is used for, and who sees it
A recording is used for one thing: checking and improving how the watch counts reps - whether the watch recorded properly, how the counter read each set, and how often it was right for each movement. It is kept in the private store our server uses for progress photos, in Amazon Web Services' Frankfurt region (eu-central-1), inside the European Union, which only our server can read. The ProgressLoop team looks at recordings in our administration console, where a recording carries a number for its account and never your name or address. It is not shown to a personal trainer, not sent to OpenAI, not part of anything Meta is told, never sold and never used for advertising.
Stopping, and deleting it
Switching it off deletes every recording you shared, from our store and from our database, and nothing more is sent. Deleting your account does the same. Even while it stays on, a recording is kept for at most 24 months.
AI training reviews
The app can read a week of your training back to you in words: a sentence about the week as a whole, which lifts have stalled, where volume moved, whether you trained as often as your programme asked, and whether anything is worth changing. The reading is produced by a language model run by OpenAI, and producing it means sending a description of that week - including the notes written on its workouts - to OpenAI's servers in the United States.
It is off until you turn it on, from Settings, on a screen that says what is sent before you agree; the full list is the one below. While it is off, nothing about your account is sent anywhere. While it is on, the app asks for a reading of the week that has just finished by itself, once and without a tap, if that week does not have one yet - so a week can be sent to OpenAI without your asking for its reading. You can turn it off again on the same screen at any time, which stops any new reading being asked for. Readings already produced stay in your account unless you ask for them to be erased: write to privacy@progressloop.eu and they will be, without your having to delete the account.
What is sent
- The dates of the week being read. Its trends are measured over the eight weeks ending in it.
- Your average body weight and how it changed, and how your waist and skinfold readings moved over those weeks.
- How many sessions you finished against how many your programme asked for.
- The movements you trained, by name, with how many working sets each got and the estimated one-rep max they started and ended at. Not the individual sets.
- Working sets per muscle group, this week and over the weeks before.
- Your average daily steps against your own target - which may have come from Apple Health or Health Connect.
- Your goal type, target weight and expected weekly change, if you set a goal.
- The facts the server itself marked as worth reading - a stalled lift, a drop in volume, missed sessions - each with one sentence of evidence.
- Each session you finished in the week being read: its date, whether you marked it as a lighter day, and which movements in it you skipped. Nothing from sessions you did not finish, and no lighter-day marker from earlier weeks.
- The notes written on those sessions: on the session, on an exercise in it and on a set in it, with the movement and set number each belongs to. That includes any your trainer wrote. Only notes from the week being read are sent, each cut off after 500 characters, and at most 40 from any one week, taken in the order the sessions were trained. Shortening a note is not removing what is in it: whatever you wrote in the part that is sent goes to OpenAI as you wrote it.
- The note on each day of that week, from the app's "Log the day" screen, with the date it belongs to and nothing else from that day's entry. A day's note is held to the same limits: cut off after 500 characters, and counted in the same 40 as the notes on sessions, exercises and sets. A day with no note sends nothing.
What is not sent
- Your name, email address, account id, gender or anything else from your account that identifies you.
- Your photos, of any kind.
- Notes anywhere else: on a check-in, a meal, a programme, a template or an exercise in the library, on a session you did not finish, and on any day or session outside the week being read.
- The rest of your daily entries, the load and reps of individual sets, or any Apple Health or Health Connect reading other than steps.
A note is your own words, and it goes as you wrote it. Nothing reads a note before it is sent, and apart from the cut at 500 characters nothing is taken out of it. So whatever is in a note on a session you finished, or on a day of that week, goes to OpenAI with the week - how you slept, an injury, an illness, a medication, or a name, a place or anything else that could identify you or somebody else. Like the lighter-day marker, a note is health data here, and it is sent only because you turned the reviews on: that consent is the whole of the basis for it. If you would rather something not reach OpenAI, leave it out of your notes, clear the note before the week is read, or turn the reviews off. The model is told to use a note only to explain what happened in the week, and never to diagnose anything or to give health, diet, injury or supplement advice.
The request carries no account id, name or email address. Apart from what your notes say, the only words of yours in it are the name of your programme and the names of any exercises you created. All of it is sent as data for the model to read and never as instructions to it.
Under OpenAI's API terms, what is sent is not used to train or improve its models. OpenAI may keep a copy for up to 30 days to monitor for abuse of its service, and deletes it after that. ProgressLoop stores the reading that comes back, the marked facts it rested on, the model that produced it and a count of tokens spent; it does not store the prompt.
Each reading costs money, so a reading of any one week can be generated at most once every two minutes and ten times in all. Those ten count every attempt at that week, including the first reading and any retry after a failure.
If you have a personal trainer, they can read the readings already produced of your weeks. They cannot ask for one on your behalf, turn the feature on for you, or cause anything to be sent to OpenAI: that consent is only yours to give. A note they write on one of your sessions, or a lighter day they mark, is sent with the week like your own - but only because you turned the reviews on.
The meal assistant
The app can write recipes for you: from a few words about what you want to eat, or out of a food guide or other text you paste in, which it turns into recipes you can keep. You can say your request instead of typing it, and it can draw a picture of a meal you saved. All of that is done by models run by OpenAI, and using it means sending what is listed below to OpenAI's servers in the United States.
It is off until you turn it on, in the app, on a screen that says what is sent before you agree. It is a switch of its own: turning on the AI training reviews does not turn it on, and turning it on does not turn the reviews on. While it is off, nothing is sent for it. You can turn it off again at any time, which stops anything new being sent; the meals you already saved from it stay yours.
What is sent
- What you asked for, as you typed it or as it was heard - and with it the ingredients you said you have, the kind of meal, how many servings and how many ideas you want - or the text you pasted in to be turned into recipes.
- The current month, so the recipes use what is in season.
- Your gender, if you set one.
- From your active goal, if you have one: your body weight, your goal type (losing, gaining or keeping weight) and an estimate of the calories you use in a day. The estimate is sent as a guide, not as a target to build a menu to.
- Your food notes, as you wrote them: what you dislike, what you are allergic to and what your kitchen lacks, up to 500 characters. An allergy is health data, and it is sent only because you turned the assistant on.
- A recording, if you speak your request. It is sent to OpenAI to be turned into text, which you can read and correct before anything is asked for. ProgressLoop does not store the recording, and neither it nor what you said is written into our logs.
- For a picture: the recipe's name and its main ingredients, and nothing about you. A picture is drawn when you ask for one, and also when you save a recipe the assistant wrote, if you have not used up the day's pictures - so saving one can send its name and ingredients without a separate tap.
- The language you use the app in, so the recipes come back in it.
What is not sent
- Your name, email address, account id, or anything else from your account that identifies you.
- Any health condition, measurement, photo, workout, note or anything else from your record beyond the list above. It is not asked for, and the assistant does not write diets for a medical condition: it says a dietitian should plan those.
What you type is your own words, and it goes as you wrote it. Nothing reads your request, your pasted text or your food notes before they are sent, so anything in them - a name, a place, a condition - goes to OpenAI too. If you would rather something not reach it, leave it out.
What is kept
- Each request and the recipes that came back, for one day, so you can look through them and save the ones you want. After a day the words and the recipes are cleared from the request.
- A record of each call the assistant made - what kind of call, which model, the tokens or seconds it used, and when - so that it can be limited to a number each day. It holds none of your words, recipes, recordings or pictures.
- A recipe you save becomes one of your meals, like one you wrote yourself, marked as coming from the assistant, with any calories and macros marked as its estimate until you change them. A picture it draws is stored with that meal in the same private store as progress photos, and is only ever shown through short-lived signed addresses.
Under OpenAI's API terms, what is sent is not used to train or improve its models. OpenAI may keep a copy for up to 30 days to monitor for abuse of its service, and deletes it after that. Each call costs money, so there is a limit on how many recipes, pictures and recordings each account can ask for in a day.
The recipes are suggestions, with estimated nutrition, and not dietary or medical advice. If you have a personal trainer, they cannot use the assistant on your behalf or turn it on for you, and they never see your food notes; they see the meals you keep, as with the rest of your record.
Measuring our own ads
ProgressLoop is free, and people mostly find it through our ads on Facebook and Instagram. To know whether those ads bring people who actually train, rather than people who install the app and never open it again, the iPhone and Android apps use Meta's software development kit to tell Meta (Meta Platforms Ireland Limited) when certain steps happen. The watch apps do not. There are no ads inside ProgressLoop, and none of this is sold.
What is sent
That one of these steps happened on your phone:
- The app was installed and opened.
- An account was created.
- A plan was picked.
- A first, a second and a fifth workout were finished.
- Two workouts were finished within the first week.
- Apple Health or Health Connect was connected.
- If you coach: a trainer profile was created; working hours were set; a first client was approved; a first plan was sent to a client; a first session was booked.
- If you are coached: an application was sent to a trainer; a session was asked for with a trainer.
Each step is sent at most once per account on each phone, at the moment it happens, and the only detail attached to it by us is whether it is an athlete's step or a trainer's. Three of them are also sent under the name Meta itself gives such a step, with its own label: creating an account as a registration by email address, a first workout as a tutorial completed, and a fifth as level 5 reached. Installing and opening the app is reported by the SDK itself, from the first time you open it, before you sign in. The SDK adds the technical details it attaches to any event it sends: the app and its version, the phone's model and system version, its language and time zone settings, the IP address the event arrived from, and an identifier the SDK makes up for that installation of the app. On an Android phone it also reads the install referrer Google Play keeps for the app, which says which ad or link, if any, the install came from.
What is not sent
- Your name, email address, account id, or anything else from your account that identifies you.
- What you train: no workouts, exercises, sets, loads, reps, notes or lighter days - only that a first, second or fifth workout was finished.
- Your body: no weight, measurements, check-ins or photos, of any kind.
- Anything read from Apple Health or Health Connect. Meta learns that you connected one, and never a single reading.
- Anything from a watch: the watch apps send Meta nothing.
- Anything about the people you coach or who coach you - not who they are, and not what was said or planned between you.
- Anything about a workout photo. Sharing one to Instagram is not one of the steps, and no photo or figure from it goes with them. The section on workout photos below says what sharing does give Meta.
On an iPhone: Apple's tracking prompt
Once you have created an account on an iPhone, the app shows Apple's own prompt asking whether it may track you across apps and websites owned by other companies. Your answer decides what Meta may link the steps to, and not whether they are sent:
- If you allow it, Meta can link the steps to your phone's advertising identifier, which is how it tells which ad, if any, you came from and shows our ads to people like the ones who went on to train.
- If you ask the app not to track, or have not answered yet - which is the case for installing, opening and creating the account - the steps are still sent, without that identifier, and Meta reports them to us only in aggregate, through Apple's privacy-preserving ad attribution (SKAdNetwork) and its own Aggregated Event Measurement. Neither can be traced back to you.
You can change your answer at any time in iOS Settings, Privacy & Security, Tracking, and it applies from the next step onwards. Turning off "Allow Apps to Request to Track" there answers no for every app at once.
On an Android phone: your phone's ad settings
Android has no prompt like Apple's, and the Android app shows none of its own in its place. The steps are sent with your phone's advertising identifier, so that Meta can tell which ad, if any, you came from and show our ads to people like the ones who went on to train - for as long as your phone's ad settings give the app that identifier. Those settings are yours, and they apply to every app at once:
- In Android's Settings, under Privacy and then Ads (on some phones, under Google and then Ads), you can delete your advertising ID. From then on no app, ProgressLoop included, is given one, and the steps are still sent, without it.
- You can instead reset it, which replaces it with a new one that nothing already sent can be linked to.
Either applies from the next step onwards.
Which ad brought you
Separately from Meta, each app tells our own server that it has been installed. It does so under a random install identifier the app makes up the first time it is opened and keeps for as long as it is installed - not your phone's advertising identifier or anything else that identifies the phone - with the kind of phone and the app version, and, where the phone can tell, the ad campaign that led to the install:
- On an iPhone, from Apple. The app asks iOS for Apple's attribution token and our server exchanges it with Apple for the Apple Ads campaign, ad group and ad behind the install, if there was one. Apple gives this to every app without the tracking prompt, because it says only whether an Apple Ads ad led to the install, so it is read whatever you answered.
- On an iPhone, from Meta - only if you allowed tracking in Apple's prompt. Meta then hands the app the link of the Facebook or Instagram ad you installed from, and the app passes on the campaign it names. If you did not allow it, nothing of Meta's is read, and where the install came from stays unknown.
- On an Android phone, from Google Play. The install referrer Play keeps for the app says whether the install came from a Google Ads click, a Meta ad or the store itself. A Meta campaign arrives in it encrypted, and is opened with a key Meta gives us for the purpose. Where Meta also hands the app the link of the ad you installed from, the campaign that link names is passed on too; Android asks no question first, as with the steps above.
Our server keeps only what that evidence says - the ad network, and the campaign, ad group and ad by their names and numbers - and never the token, link or referrer itself. When you create an account, the install is linked to it, once. That is what lets us count, per campaign, how many of the people it brought went on to reach each of the steps above. We read it only as those counts: nobody's account is shown with where it came from, and neither the campaign nor the account it is linked to is sent to Meta, Apple, Google or anyone else. The record of the install goes when the account is deleted.
What we see, and what Meta does with it
What reaches us from Meta is numbers - how many people a campaign brought, and how many of them reached each step - never a named person.
For collecting and sending these steps, ProgressLoop and Meta Platforms Ireland Limited are jointly responsible, under the terms Meta sets for its business tools; Meta is responsible on its own for what it does with them afterwards, which includes using them to deliver and measure ads and is described in Meta's privacy policy. Questions about either half can come to us, and we will pass on what is for Meta.
Workout photos
On iPhone and Android, you can put a finished workout's figures over a photo you take or choose. The card can show the workout's title and date, start time, duration, volume, sets, exercises, muscle groups, top sets and improvements against your history. Heart rate and active energy appear only when recorded. You can add a line of your own. Nothing is uploaded to ProgressLoop or saved to your account.
The app asks for camera access to take a photo. The system photo picker gives it only the picture you choose. Saving to Photos on iPhone asks for add-only access; on Android, saving to the gallery needs no photo-library permission. You can change camera and photo permissions in your phone's settings.
You choose whether to save the card, send it through the phone's share menu or open it as an Instagram story. The receiving app handles it under its own terms. Deleting your ProgressLoop account does not delete copies you saved or shared.
For Instagram, the photo and a separate sticker with the figures are handed to its app, along with ProgressLoop's app identifier, which identifies our app, not your account. On iPhone, this uses the clipboard with a five-minute expiry. On Android, Instagram gets read access to temporary files. Android also uses temporary files for the share menu; these can remain in the app's cache until replaced or cleared.
Instagram is operated by Meta under its privacy policy. It receives the picture and figures you chose to share, including any health figures on the card. Our server sends it nothing for this, and sharing a card is not an advertising milestone we report.
Your schedule, and your calendar
You can plan when you will train: a name of your choosing, a start time and a length, notes if you want them, and one of your workouts if you link one. A plan is stored in your account like the rest of your record.
A plan can repeat - every day, week or month, or every few of them, and on chosen weekdays when it repeats by the week - and stop on a date, after a number of times, or never. We store the plan once with its rule, including the time zone it is read in, rather than a copy of every time. When you delete one time of it, we record that time as not happening; when you move one, we record it the same way and store the moved time as a plan of its own, linked back to the series. Deleting the series deletes the times moved out of it too.
If you have a personal trainer, they can see your schedule and plan it with you - add workouts to it, and change or delete what is on it - and a plan they made says it was them. A session your trainer confirms is written onto your schedule too. That one belongs to the booking: it moves when the session is moved, stays until the session is cancelled, and is changed through the booking rather than by editing the plan. A booked session never repeats.
Your schedule in a calendar
Nothing goes to any calendar unless you turn it on or send it there. There are three ways, each separate: keeping your phone's calendar in step, keeping a Google Calendar in step, and, in the iPhone app, adding one plan at a time.
iPhone Calendar sync is a switch under Settings, Calendar sync. When you turn it on, the app writes your plans - and, if you coach, the sessions booked with you - into a calendar called ProgressLoop that it creates in your phone's calendar account, or into another calendar you pick, and moves or removes them there when they change. To do that iOS makes it ask for full access to your calendars: iOS offers no narrower permission that lets an app find and update the events it wrote. With that access the app lists your calendars' names so you can pick one, and reads events only in the calendar it writes to, to recognise its own. It does not read the events in your other calendars, and nothing about your calendars is sent to our servers; the settings for it stay on your phone. Where the events go after that depends on the calendar account they are in, such as iCloud, and on that account's terms. You can withdraw the permission in iOS Settings at any time.
Phone calendar sync on Android is the same switch in the Android app, and asks Android for permission to read and write your calendars. By default it creates a calendar called ProgressLoop that lives on the phone alone and is synced to no account; you can pick another calendar instead, such as one in your Google account, and the events then go wherever that account keeps them, on its terms. With that permission the app lists your calendars - their names, the accounts they belong to and their colours - so you can pick one, and reads events only in the calendar it writes to, to recognise its own. It never reads or changes an event it did not write, nothing about your calendars is sent to our servers, and its settings stay on your phone. You can withdraw the permission in Android's settings at any time.
Google Calendar sync is the switch beside it, in either app. Turning it on opens Google's own sign-in, where you are asked to let ProgressLoop see your Google account's email address and manage only the calendars ProgressLoop itself creates. That permission cannot see or change any other calendar or any event in that account. Our server keeps it, encrypted, creates a calendar called ProgressLoop in your Google account, and from then on writes your plans (and, if you coach, the sessions booked with you) into it within seconds of a change, and once a night. The only thing it reads back is the list of events in that ProgressLoop calendar, by their identifiers alone, so it can notice one of its own that was deleted or split there and write it again. It never reads an event's title, time or notes, and never reads another calendar.
The same screen asks for a second, optional permission, which Google describes as letting us see, add and remove the Google calendars you are subscribed to. Google keeps each calendar's colour in that list, so it is the only way we can set one. We use it for that alone: when we create the ProgressLoop calendar and whenever you pick a colour for it in the app, we set that calendar's colour, and nothing else in your list of calendars is read or changed. If you do not give it, sync works exactly the same and the calendar keeps the colour Google gave it.
ProgressLoop's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Each synced event carries the plan's name (with any title start you chose), its start and end, how it repeats, the linked workout's name, the plan's notes and the alert you chose. A session booked with you as a trainer is named after the client and carries the note the client wrote and the one you wrote.
Turning either sync off asks whether to remove the events it wrote or keep them. Kept events are an ordinary copy from then on, belonging to that calendar, and stop being updated. Turning Google Calendar off also withdraws the permission Google gave us, whichever you choose. Signing out of the app leaves the events on your phone where they are.
Adding one plan at a time, in the iPhone app, needs no access at all. What you add is a copy, and from then on it belongs to that calendar: changing or deleting the plan in ProgressLoop does not change it, and the app keeps no record of it.
- Add to Apple Calendar hands the event - the plan's name, its start and end, your notes, and the name of the linked workout - to your phone's own Calendar, which shows it to you before anything is saved. It does not pass through ProgressLoop's servers. Where it goes after that depends on the calendar account you save it into, such as iCloud, and on that account's terms.
- Add to Google Calendar opens Google Calendar with the event filled in. Opening it passes the plan's name, its start and end and its notes to Google, whether or not you then save it, and from that moment Google's own terms and privacy policy apply to them. Google receives them as a service you chose to open, not as a provider of ours, and ProgressLoop sends Google nothing itself.
Personal trainers
Any ProgressLoop account can switch on as a trainer and be listed in a directory that every signed-in user can browse, and any account can apply to one trainer at a time. A trainer is another ProgressLoop user: an independent person who does not work for ProgressLoop or act on its behalf, and whom ProgressLoop has not vetted.
If you apply to a trainer
- Before they answer, they see your name and the note you wrote - not your email address and nothing from your record.
- Once they accept, and for as long as the coaching lasts, they can see everything you record in the app: your workouts, programmes and every session with its sets (and the notes you wrote on it, its exercises and its sets, whether you marked it as a lighter day, and the heart rate and energy kept from a watch session), your schedule, the exercises you created, your skills, habits, goals and meals (but not your food diary), settings such as your units and step target, your daily entries - including body weight and the steps and workouts that come from Apple Health or Health Connect - your check-in measurements and skinfolds, and any AI training reviews already produced. They also see your name, email address, gender and profile picture.
- They can put workouts, programmes and exercises into your account, change or delete the workouts, programmes and sessions already in it - including ones you made yourself - make a programme your active one, start and log a session with you, including its notes and whether it was a lighter day, and plan your schedule: add workouts to it, and change or delete what is on it. What they create is recorded as assigned, logged or planned by them.
- Your progress photos are not part of that. Your trainer sees them only while you have photo sharing turned on, which is off until you turn it on; turning it off hides them again straight away.
Plans, guides and recipes your trainer sends you
- Besides putting plans into your account, a trainer can send you one of their own workouts or programmes, a nutrition guide they wrote - advice set out around their own recipes, sometimes with a PDF - or a single recipe, with a note if they like. What you receive is a copy as it was when they sent it, pictures and PDF included: changing or deleting their own afterwards changes nothing you hold. It is stored with who sent it, when, and the note.
- A guide or a recipe works the way a plan does: it waits until you take a recipe from it into your meals, where it becomes an ordinary meal of yours marked as coming from your trainer, or remove it. Your trainer sees whether you did, can withdraw it, and prescribes nothing by it - the calorie targets you follow are still the ones on your goal.
- Nothing is added to your library until you add it. A sent plan waits on your ready-made shelf, under From your trainer, together with any exercises of the trainer's own that it uses, so you can read it before deciding. Adding it puts an ordinary copy into your account - with those exercises, marked as coming from your trainer - and from then on that copy is yours. You can remove a sent plan instead, which takes it off your shelf.
- Your trainer sees each plan they sent you and whether you have added it, removed it or not answered yet, and can withdraw one, which deletes it for both of you. Withdrawing never touches a copy you already added.
- Ending the coaching does not delete plans already sent: they stay on your shelf until you remove them. It does end your trainer's view of whether you added them.
What a trainer never gets
- Your reminders, your password, how and on which devices you sign in, how you chose to be notified, or any calendar you connected.
- The Apple Health or Health Connect readings that stay only on your phone.
- The ability to ask for an AI training review or to turn the feature on for you.
- Anything from your record once the coaching ends. Access is checked against a live coaching relationship on every request, and either of you can end it at any time, which shuts it at once. The record of sessions you booked with them - times, where each stood, and the notes on it - stays visible to both of you, as described under how long we keep it.
Sessions with your trainer
- A trainer who takes sessions publishes the hours they take them in: how long a session lasts, the rest they usually keep between clients, their weekly windows and their time zone. The clients they are coaching can see those hours and which times in them are still free. A client never sees who has booked any other time. Each booked session also records the rest the trainer keeps after it, which starts as their usual rest and which they can change for that session alone; that is the trainer's note about their own diary, and the client does not see it.
- While a trainer coaches you, you can ask for one of those free times, with a note if you like. Your trainer sees your name, the time you asked for and your note, and confirms or declines, with a note of their own if they like. Your trainer can also book you in directly.
- A confirmed session is written onto your schedule, with any note your trainer wrote when confirming it as its notes. Either of you can cancel a session that is pending or confirmed, with a note, and the record keeps which of you cancelled.
- A session can be moved before it starts. A client can move a request the trainer has not answered yet, or ask to move a confirmed session to another free time, with a note; the confirmed session stays where it is until the trainer answers, and the client can withdraw the ask. A trainer can move a session, which confirms it if it was still a request, or accept the client's ask by moving it there, or decline the ask and keep the time, each with a note. The booking records where the session was before it last moved, and keeps an ask only until it is answered, withdrawn or the session is cancelled.
- Ending the coaching cancels every session still pending or confirmed between you and drops any ask to move one.
- A trainer sees every session booked with them: which client booked which time, where each stands, and the notes on it.
- A trainer can keep their own calendar in step with their sessions. If they turn on phone calendar or Google Calendar sync, each session you have with them is written into that calendar with your name, the note you wrote and the note they wrote, and it is held there under that calendar provider's terms. It stays there for as long as they keep it, including after the session is over.
If you are a trainer
- Your name, profile picture, headline, bio, whether you are taking clients and how many you have are shown to every signed-in user who browses the directory, together with your average star rating, how many reviews you have, and the review comments you have not hidden - see the section on reviews below. Hiding your profile takes it out of the directory, and the clients you already have stay with you.
- The hours you take sessions in, and your time zone, are shown to the clients you are coaching, together with which times are still free.
- A workout or programme you send a client is copied to them, with your note and your name, and any exercises you created that it uses can be read by that client while the plan is on their shelf and are copied into their account if they add it. A copy they added is theirs, and withdrawing the plan does not take it back.
- Your nutrition guides are private to you until you send one. Sending a guide or a recipe copies it to that client, with its pictures, any PDF, your note and your name; a recipe they take into their meals is theirs, and withdrawing does not take it back.
- What you see of a client is shown to you so that you can coach that client, and for nothing else. If you take any of it out of the app - a screenshot, a figure written down elsewhere - that copy is yours to answer for, as the person who made it, under the data protection law that applies to you.
Notes and emails
Applying, answering and ending can each carry a note of up to 2,000 characters. It is stored with the coaching record, shown to the other person, and included in the email that tells them. Asking for, confirming, declining, moving and cancelling a session, and asking for or declining a new time, can each carry a note too, stored with the booking, shown to the other person and included in the email that tells them, along with when the session starts - and, when it has moved, when it was before. Withdrawing an ask to move a session tells the trainer nothing. A trainer sending a plan can add a note too, stored with the plan, shown to the client and included in the email that tells them it arrived; that one runs to 1,000 characters rather than 2,000. A note on a guide or a recipe runs to 2,000, and goes the same way. Every one of those emails names you by your name and never gives away your email address. Withdrawing an application before it has been answered tells the trainer nothing, and adding, removing or withdrawing a sent plan, guide or recipe emails nobody.
Feedback about the app
Sending feedback is optional. We keep the topic, your rating from 1 to 5 and any comment (up to 2,000 characters), linked to your account, with the platform, app version, language and date. Our staff read these answers to find problems and improve the app. They are not published or sent to an AI provider. Please leave health details out of comments.
We rely on legitimate interest in improving the service: you choose what to send, access is limited to our staff, and you can object or ask us to delete your answer. Answers are otherwise kept until you delete your account. The phone and watch keep a local record of prompts and your choices so they do not keep asking. Muting prompts does not delete answers already sent. Email feedback requests have separate preferences.
An App Store or Google Play review is separate, handled by the store under its own rules. Its prompt is not based on the rating you gave us.
Reviews of trainers
Anyone a trainer coaches, or has coached, can review them: one to five stars and, if they want, a comment of up to 1,000 characters. Each person has one review per trainer, and writing again changes it.
A review's comment is public. Every signed-in user who browses the trainer directory can read it on that trainer's profile, beside your first name and the initial of your last name. Your stars are added to the trainer's average rating, which the directory shows with the number of reviews, and by which it can be sorted and filtered. Write a comment only if you are content for anyone using ProgressLoop to read it.
You can change your review or delete it whenever you like. Deleting it takes the comment off the profile and the stars out of the average.
A trainer can hide a comment, but not its stars. A trainer sees every review of them, and chooses for each one whether its comment is shown on their public profile. Hiding a comment takes only the words off the profile: the stars stay in the average either way. That is deliberate, so that a trainer cannot raise their rating by hiding the reviews they would rather nobody read.
That is the whole of the control over a review: its author can edit or delete it, and the trainer can show or hide its comment. ProgressLoop does not check reviews before they appear, and does not edit or remove them. Writing a review sends no email.
If you turned on feedback requests, you may be emailed once about a trainer, asking whether you would review them; the emails we send below say when. The review, if you write one, is written in the app as any other, and nothing is recorded from the email.
Who else touches the data
Data is passed on only where a stated purpose needs it, and only with the contractual and technical protections that purpose requires.
- Amazon Web Services - hosting, the database, backups, the private store that holds progress photos, meal pictures, guides' PDFs and the workout motion you choose to share, and the mail service that sends the emails below. All of it runs in Amazon Web Services' Frankfurt region (eu-central-1), inside the European Union.
- OpenAI (OpenAI Ireland Ltd) - produces the AI training reviews, only for accounts that turned them on, from the week's figures and workout notes described above; and runs the meal assistant, only for accounts that turned it on, from the requests, food notes and goal figures described above. Neither carries a name, email address or account id. Processing happens in the United States; see the next section.
- Meta (Meta Platforms Ireland Limited) - learns from the iPhone and Android apps when one of the steps listed under measuring our own ads happens, with no name, email address, account id or anything you recorded, so that we can measure our own ads. Linked to an iPhone's advertising identifier only if you allow it in Apple's tracking prompt, and to an Android phone's unless you delete it in the phone's ad settings. Separately, if you share a workout photo to an Instagram story, Instagram receives that picture from the Instagram app on your phone, because you posted it; we send Meta nothing for it, as the section on workout photos describes.
- Your personal trainer, if you apply to one and they accept - another ProgressLoop user rather than a provider of ours, who sees your record, your schedule, the sessions you book and whether you added the plans, guides and recipes they sent you as the section on personal trainers describes, only while the coaching lasts.
- Other signed-in users - if you switch on as a trainer and are listed, they see your trainer profile in the directory with your rating and the review comments you have not hidden, and the clients you coach also see your session hours, your time zone and which times are free; if you review a trainer, they see your comment beside your first name and last initial, and your stars as part of that trainer's average. Nothing else about you.
- Apple - as the provider of Sign in with Apple if you use it, which means Apple knows you signed in to ProgressLoop and is handed the authorisation back when you delete the account; as the operator of the App Store and of your device, of your phone's Calendar if you add a plan to it or sync with it, and of the Apple Push Notification service, which carries each notification we send to your iPhone: its title and text, which can name the other person, quote their note, or give a plan's name or a session's time. On an iPhone, Apple also receives the attribution token the app hands our server, and answers with the Apple Ads campaign that led to the install, if any. Apple never receives your training record from us. The workout the watch records goes into Apple Health on your own device, and is governed by Apple's terms for it.
- Any other app you have given access to Apple Health - it can read the workout the watch recorded there, the same as any other workout on your device, because that is how Apple Health works. We send it to no one: the permission is one you gave that app in iOS, and you can take it back in the Health app. Nothing else about your ProgressLoop account is reachable that way.
- Google - only if you choose it, in one of three ways. If you sign in with Google, Google knows you signed in to ProgressLoop and tells us the identifier, address and name described above. If you connect Google Calendar, our server writes your plans (and, if you coach, your booked sessions with each client's name and notes) into your own Google account, which holds them under Google's terms as the provider of that account. If you tap Add to Google Calendar on a plan, that plan's name, times and notes go to Google as a service you chose to open, and ProgressLoop sends nothing itself. See the section on your schedule.
- Google, for Android - as the operator of Google Play, which the Android app is installed from, and of Android on your phone. As the operator of Firebase Cloud Messaging, which carries each notification we send to your Android phone: Google issues the app on your phone the address notifications are delivered to, and carries each one's title and text, which can name the other person, quote their note, or give a plan's name or a session's time. As the maker of Health Connect and of the ML Kit body detection in the progress camera, both of which run on your phone: what the app reads from or writes to Health Connect stays in Health Connect on your phone, and ML Kit sends Google no picture, only, under Google's terms for it, technical statistics about how it runs. Google never receives your training record from us.
- Any other app you have given access to Health Connect - it can read the sessions your phone wrote there from your Wear OS watch, the same as any other app's, because that is how Health Connect works. We send them to no one: the permission is one you gave that app, and you can take it back in Health Connect.
- Lawyers, accountants or a competent authority, if that ever becomes legally necessary.
Apart from Meta, for the one purpose above, there is no analytics provider, no advertising network, no email marketing platform and no data broker on this list, because none is used. The optional emails you can ask for, news and offers included, are written by our own staff and sent the same way as every other email from us, by the Amazon mail service above. Your answers to our surveys are read only by our own staff.
Data leaving the European Union
Your account, your training record, your body data and your photos are stored and processed inside the European Union, and nothing about them leaves it - with the exceptions below. Each of them exists only if you use the feature it belongs to.
A notification about coaching, a session or a plan sent to you is delivered through Apple's push notification service to an iPhone, and through Google's Firebase Cloud Messaging to an Android phone. Both run worldwide, so its title and text may be processed outside the European Union on the way to your phone. That happens only for those messages, and only while they are set to reach you as a notification; setting a topic to email under Settings, Notifications keeps it from both services.
If you turn on AI training reviews, the week's figures and the workout and day notes described above are sent to OpenAI and processed in the United States. Under its data processing addendum, OpenAI Ireland Ltd makes onward transfers outside the EEA under agreements containing the European Commission's standard contractual clauses or an applicable adequacy decision. The safeguards described above also apply: the request carries no account id, name or email address, and it is kept briefly and not used to train models. A copy of the applicable safeguards is available on request. Turning the reviews off ends the transfer.
The meal assistant works the same way and on the same safeguards: if you turn it on, what the section on the meal assistant lists - including your food notes, a recording you speak and your goal's body weight - is sent to OpenAI and processed in the United States, with no account id, name or email address. Turning the assistant off ends that transfer.
If you sign in with Apple or with Google, the sign-in itself is an exchange between your phone, that provider and our server, and the provider may handle it outside the European Union under its own terms - which is the same relationship you already have with the account you are signing in with. What crosses is what the sign-in is made of: the token your phone was given, the request to prove it, and, when you delete your account, the authorisation handed back to Apple. None of your training record, your body data or your photos is part of it, and it happens only on the sign-ins you choose.
On an iPhone, our server also sends Apple the attribution token the app was given when it was installed, and Apple may handle that exchange outside the European Union under its own terms. The token carries nothing from your account, and what comes back is only the Apple Ads campaign that led to the install, if any.
The steps the phone apps report for measuring our ads go to Meta Platforms Ireland Limited, which may transfer them to Meta Platforms, Inc. in the United States. Meta makes that transfer on the safeguards its own privacy policy sets out, which include adequacy decisions of the European Commission and its standard contractual clauses. What crosses is the list of steps and the technical details above, never your record.
A personal trainer you apply to may live anywhere, including outside the European Union. Your record stays stored in the EU either way; it is shown on your trainer's own device because you asked them to coach you, and only while they do. Ending the coaching ends it. A review you write is the same: it is stored in the EU and shown on the device of whoever reads the directory, wherever they are. A plan, guide or recipe you send a client as their trainer goes the other way, to that client's own device, wherever they live.
If you add a plan to Google Calendar, its name, times and notes go to Google, which may process them outside the European Union under its own terms. That is a transfer you make yourself by opening Google Calendar, one plan at a time; ProgressLoop does not send anything to Google.
If you share a workout photo to an Instagram story, or send it anywhere from the share sheet, the picture goes where you send it, and Instagram or that other service may process it outside the European Union under its own terms. That is a transfer you make yourself, from your phone; ProgressLoop sends nothing.
If you connect Google Calendar, our server sends the events described above to your Google account at your request, and Google may process them outside the European Union under the terms of that account. Disconnecting stops it.
How long we keep it
- Your account and everything in it - for as long as the account exists. Deleting it erases them, as described below.
- Progress photos - until you delete the photo, the check-in it belongs to, or the account. On an Android phone the app also keeps the photos taken on it, each as it came from the camera, in its own storage on that phone - where they stay after you sign out, and go at the latest when the account is deleted or the app is removed from the phone. They are never part of a phone backup.
- Workout motion you shared - until you switch sharing off or delete the account, either of which deletes all of it, and for at most 24 months in any case. The phone keeps its own copy of a recording for a week after it has been uploaded.
- Workout photos - never received by our server. Android may keep temporary sharing files in the app's cache until replaced or cleared. A card you saved or shared is wherever you put it, and stays there under your control.
- Readings from Health Connect - the ones that stay on your Android phone, for up to a year, until you sign out, delete the account or remove the app. What reached your daily entries is kept with them, as above.
- AI training reviews - one reading per week, replaced in place if you ask for it again, for as long as the account exists. Turning the feature off keeps the readings already made; asking us to erase them, or deleting the account, removes them. OpenAI's own copy of what was sent goes within 30 days.
- Meals, their pictures, your food notes, your food diary and the recipes you starred - until you delete them, or the account. Deleting a meal deletes its picture; a diary entry that came from it stays, with its own figures.
- The meal assistant - each request and the recipes it returned for one day, after which the words and recipes are cleared; the record of each call, which holds no words, for as long as the account exists. Turning the assistant off keeps both. OpenAI's own copy of what was sent goes within 30 days.
- Nutrition guides you write as a trainer - until you delete them, or the account.
- Coaching records - each application and coaching relationship, with the notes on it, for as long as both accounts exist, including after it was declined, withdrawn or ended. That is what lets each of you see what happened, and what the wait before applying to the same trainer again is measured from. Deleting either account removes it from both sides, and you can ask for an ended one to be erased.
- Plans and sessions a trainer put into your account - they are yours, and stay when the coaching ends or the trainer's account is deleted, until you delete them. A session on your schedule that came from a booking is the exception, below.
- Plans, guides and recipes a trainer sent you - kept while they are on your shelf, including after the coaching ends. Removing a plan takes it off your shelf and records that you removed it, which is what your trainer sees while they coach you; you can ask for a removed one to be erased. Your trainer can withdraw one, which deletes it for both of you, and deleting either account takes everything sent between you with it, pictures and PDFs included. A copy you added to your library, or a recipe you took into your meals, is yours, as above.
- Your schedule - each plan until you or your trainer delete it, or the account is deleted. A repeating plan is kept with its rule and the times deleted or moved out of it, and deleting it deletes the times moved out of it too. A plan written there by a confirmed session goes when that session is cancelled.
- Session bookings - kept with the account, including declined and cancelled ones, so each of you can see what happened, until the account is deleted. The time before a session last moved is kept with it; an ask for a new time goes once it is answered or withdrawn, or the session is cancelled. If the other person's account is deleted, a booking still pending or confirmed is cancelled, and a confirmed session is taken off the client's schedule.
- App feedback - until you delete your account, unless erased earlier following your request.
- Reviews - until the author changes or deletes one. A review is deleted with its author's account, which takes its stars out of the average, and every review of a trainer is deleted with the trainer's account.
- A trainer profile and session hours - until the account is deleted, or until the trainer changes the hours. Hiding the profile takes it out of the directory straight away.
- Sessions and sign-in tokens - tokens stop working when they expire or are revoked, including when you sign out. The session record, including the app platform, version and build, stays until the account is deleted.
- How you sign in - the identifier Apple or Google gives us for you, for as long as the account exists, because it is what gets you back in. The authorisation for Sign in with Apple is kept beside it and handed back to Apple when the account is deleted.
- Notification choices - for as long as the account exists. A registered phone - until you sign out on it, Apple or Google tells us its notification address no longer works, another account signs in on that phone, or the account is deleted.
- Your answers about optional emails, and the record of each change - for as long as the account exists. Turning a kind off keeps the record that you once had it on, because that record is what shows the emails were asked for. Both are deleted with the account, together with the code the emails' links carry.
- A note of each scheduled message sent - which summary, nudge, tip, survey, campaign or reminder went to which account, and for which week, quiet spell, session or campaign, so that none is sent twice: for 400 days, then deleted, and with the account if that comes first. The note that you were asked to review a trainer is the exception: it is kept for as long as the account exists, because it is the only thing that stops the same request being sent again.
- The surveys you were sent, and your answers - for as long as the account exists, and deleted with it. A survey can be answered, and an answer changed, for 30 days after it was sent; after that it stays as it was left.
- The record of the emails sent to you - for as long as the account exists, and deleted with it. An address that bounced or reported one of our emails as spam stays on our list of addresses not to write to, even after the account is deleted, because that entry is about the mailbox rather than the account.
- A Google Calendar connection - until you disconnect it or delete the account; either one deletes it and withdraws the permission Google gave us. The events already written stay in your Google account if you chose to keep them when disconnecting.
- The steps reported for measuring our ads - we keep no copy of what was sent. The phone keeps a note of which steps it has already reported for which account, until the app is deleted from it. Meta keeps what it received for as long as its own privacy policy says.
- The install your account was made on, and the campaign it came from - for as long as the account exists. An install nobody made an account on holds no name, address or account, only its random identifier, the kind of phone, the app version and the campaign, and is kept with no end date, as part of the count of installs.
- When you accepted the terms and this policy - for as long as the account exists.
- Technical server logs - a short rolling window, and longer only for a specific record needed to investigate abuse or a legal claim.
- Backups - deleted data can survive in an isolated database backup until that backup is overwritten on its normal rotation, which takes 7 days. Photos are not backed up, so a deleted photo is gone at once. Backups are not used for anything else, and a restore re-applies the deletion.
- Correspondence - as long as it takes to answer, and after that only while it is relevant to a dispute or a legal obligation.
Cookies, and what this website stores
This website sets no cookies and stores nothing in your browser. It loads no fonts, no scripts and no images from anywhere else. The pages you read make no request to any server once they have arrived; the four pages a mailed link opens - the one that confirms your address, the one that sets a new password, the one where you choose which optional emails you get and the one where you answer our survey - send what you came to do to ProgressLoop's own server and to nobody else. The page of choices only reads them when it opens, and changes one only when you press its switch. The survey page records the score you clicked in the email, and a comment only when you send one. The page a notification email's button lands on, if the app does not open in its place, only tells you where to find it and asks for nothing. There is no consent banner because there is nothing to consent to.
The administration area at /admin is a private tool for whoever runs the service, not part of the public site. It keeps a sign-in token and a couple of interface preferences in the browser's own local storage. These are strictly necessary for it to work and are never used to observe anyone.
The iPhone app stores your sign-in token and your settings on your device, which is how it keeps you signed in between launches. Your iPhone Calendar sync settings, and which event it wrote for which plan, are kept there too. So is what Meta's SDK needs to measure our ads: the identifier it makes up for that installation, your answer to Apple's tracking prompt as iOS reports it, and which steps have already been sent, so none is sent twice. And the random identifier the app reports its install to our server under, until the app is removed. The watch app has no sign-in of its own: it is signed in by the phone handing it that token, and keeps it on the watch for the same reason. It then talks to our server itself, over the watch's own connection, and keeps a workout in progress on the watch until the server has it - the same sets, sent the same way, as the phone would send.
The Android app keeps the same things on your phone: your sign-in token, sealed with a key held in the phone's secure hardware, your settings, what phone calendar sync wrote, and what Meta's SDK needs, including which steps have already been sent, and the random identifier it reports its install under. It also keeps the Health Connect readings described above, the progress photos taken on the phone, a copy of your account's data so the app opens quickly, and what its home screen widgets show. Android's own backup and its transfer to a new phone are told to take none of it. The Wear OS app is signed in by the phone the same way the Apple Watch app is, keeps that token sealed on the watch, and keeps what it shows on its tile and watch faces, and anything not yet delivered to our server, on the watch.
Emails and notifications we send
Some emails the service needs, and they are not optional: confirming your address, a welcome once you have, resetting your password, a notice when your password changes, and replies to things you write in about. Those always come by email, whatever else you have chosen, because they are how you get into your own account.
An account made by signing in with Apple or Google needs none of those four. The address is already confirmed by the provider, so no confirmation is sent - unless the provider will not vouch for it, which is the one case where the link still goes - and there is no password here to reset or to tell you about. If you signed in with Apple and shared no address at all, nothing can be emailed to you: notifications on your phone are then the only way we reach you, and the messages below that would have fallen back to email cannot. An address cannot be added to such an account afterwards either, because the way into it is Apple rather than an address and a password of its own.
Everything else below can reach you as a notification instead. Under Settings, Notifications you choose, for each topic - an application answered, coaching ended, a plan from your trainer, session requests, session changes, and, if you coach, somebody applying to you - whether it comes by email, as a notification on your phone, or both. None of them can be switched off entirely, and until you choose, each comes as a notification. If no phone is registered to your account, or Apple or Google refuses to deliver to it, it is emailed instead. A notification carries what the email would: the other person's name, and any note, plan name or session time. Whether it shows on your lock screen is decided by your phone's notification settings.
The iPhone app asks iOS for permission to show notifications only when you ask it to - on the Notifications screen, or when you turn on a reminder. The Android app asks Android at those two moments too, and once more, at the first rest of the first workout you log, since on Android the workout in progress and its rest are shown as a notification; never when it opens. Each app tells our server the address Apple or Google gives it for your phone each time it opens, so that the choice you make later works at once. Without that permission a notification is delivered but not shown, and no email is sent in its place - so set a topic to email, or both, if you have turned notifications off on your phone. Signing out on a phone stops notifications to it.
If you use coaching, the other person is emailed each time an application is made, answered, or a coaching relationship ends - including when it ends because an account was deleted. Each email carries the name of the person who acted and any note they wrote, and never their email address.
If your trainer sends you a workout, a programme, a nutrition guide or a recipe, you are emailed that it arrived, with its name, their name and any note they wrote, and never their email address. Adding it, removing it or the trainer withdrawing it sends no email.
If you book sessions, the trainer is emailed when a client asks for one, and the client is emailed when the trainer confirms one, books one directly or declines one. When a client moves a request or asks to move a confirmed session, the trainer is emailed the new time; when the trainer moves a session or declines an ask to move it, the client is emailed the time it is now at. Withdrawing an ask sends no email. When either of you cancels, the other is emailed - including for each upcoming session cancelled because an account was deleted. Each carries when the session starts, the name of the person who acted and any note they wrote, and never their email address. Writing or changing a review sends no email.
Two reminders come on top of those, by notification or email as you chose for session changes and session requests. If you train with a trainer, you are reminded about a day before each confirmed session, with the trainer's name and the time in their time zone - unless the session was confirmed less than a day before it starts, since the confirmation has only just reached you. If you coach, you are reminded once a day while a coaching application or a session request has waited more than a day for your answer, with how many of each are waiting.
Three kinds of email are optional, and you get only the ones you ask for. They are separate from everything above, and each is its own choice:
- News and offers - what is new in ProgressLoop, and offers. Each one is written by our own staff and sent on a day they choose to everybody who has this kind turned on, a confirmed address and an account that is not suspended - sometimes only to trainers, or only to people who do not coach, and sometimes only to readers of one language. To send it we use your name, your address, your language and whether you have a trainer profile, and nothing about your training. Before one goes out, a test of it is sent only to the member of staff who wrote it.
- Tips and progress - a weekly summary of your training, a nudge after a quiet spell, and tips for your first steps. The weekly summary is written from figures in your own record for that week: the sessions you finished against your weekly target and whether you met it, the working sets you lifted, your average body weight and how far and which way it moved from the week before, whether the week was on track for your goal, and your average daily steps against your step target. A figure you recorded nothing for is left out rather than shown as zero, and no summary is sent for a week in which you recorded nothing at all. Your body weight is health data, so turning this kind on is also your explicit consent to it being put in an email to you. The nudge comes after a week in which you neither finished a workout nor opened the app, and once more after three weeks: to know when, we look at the last day you finished a workout and when the app was last used on any of your devices, which is recorded to within an hour, and the nudge itself says only how many days it has been. The first-steps tips come a day, three days and a week after you make your account, and each is skipped once you have done its step: to know that, we look at whether you have an active goal, any workout or programme, and any finished workout. If you coach, the weekly summary also covers your clients, as counts and never by name: how many you coached, how many trained and how many have gone quiet, the sessions you held, and the applications and session requests waiting for your answer.
- Feedback requests - now and then, how likely you are to recommend ProgressLoop, and, if you train with a trainer, a request to review them. The survey comes at most once every 90 days, and only once you have had your account for at least two weeks and finished at least three workouts: to know that, we look at when the account was made and count your finished workouts. The request to review a trainer comes once you have had three confirmed sessions with them that are over, while they still appear in the trainer directory, if they coach or have coached you and you have not reviewed them - and only once for each trainer, ever. It names the trainer, and nothing is recorded from it: a review, if you write one, is written in the app as before.
Every one of them is off until you turn it on. When you make an account, however you make it, you are offered three separate boxes, one for each, and none of them is ticked: tick any of them, all or none, and the account is made the same way. Afterwards you can turn each one on or off at any time in the app's settings. Using the app never depends on any of them.
Stopping them takes one step, whichever way suits you: the link in every one of those emails, which opens a page on this website where you can turn any of the three off, or back on; your mail program's own unsubscribe button, where it shows one, which turns off the kind that email belongs to; or the app's settings. Reporting one of those emails as spam turns off all three. Turning one off takes effect at once and changes nothing else - the emails about your account and the messages described above carry on as before. Our staff can turn one off for you if you ask, but nobody here can turn one on for you: only you can.
The survey is answered on this website. It asks how likely you are to recommend ProgressLoop, from 0 to 10, and each number in the email is a link to a page here that records the one you clicked and offers a box for a comment, if you want to add one, of up to 1,000 characters. For 30 days after the survey was sent you can change the score, and add, change or clear the comment, from the same link. The links carry a random code instead of asking you to sign in. Your answer is kept with your account, and our staff read the answers, and the overall score they add up to, in the administration area, beside the account they belong to. It is used to understand how people find the app and what to improve; it is never published with your name and never used for advertising.
A record is kept of each answer - which kind, whether it was turned on or off, how, and when - because it is what shows that you asked for what we send. The page an email's link opens changes nothing when it loads, only when you press one of its switches, because some mail systems open every link in an email to check it before you do.
These emails go only to an address you have confirmed, and stop while an account is suspended. They are sent the same way as every other email from us, by Amazon's mail service in Amazon Web Services' Frankfurt region (eu-central-1), inside the European Union. No email marketing platform is involved, and your address is not given to anyone else to send them.
Every email we send is recorded, optional or not: what kind it was, the address it went to and when, and what Amazon's mail service reports about it afterwards - that it was delivered, bounced or reported as spam, and when it was opened and which of its links was followed. An open is noticed through a tiny image in the email, and a followed link because it passes through that service on the way; a link that carries a code of yours, such as one that resets a password or opens the survey, does not, and is never recorded. The record holds none of the email's words and is kept with the account, as set out under how long data is kept. An address that bounces for good, or that reports one of our emails as spam, is not written to again.
Your rights
Under the GDPR you have the right of access to your data, and the rights to have it corrected, erased, restricted or ported; to object to processing based on legitimate interest; and to withdraw consent at any time for anything based on it. Consent to an optional email is withdrawn in one step, as set out under the emails we send, and never needs a reason.
Withdrawing consent does not make earlier processing unlawful. The right to erasure is not absolute - data can be kept where the law requires it, or where it is needed to establish, exercise or defend a legal claim. Everything outside that is erased or irreversibly anonymised.
Two of them do not need us at all. Access and portability are built into the app: Settings will export your whole record whenever you ask, as JSON exactly as it is stored or as CSV with one file per table, and erasure is the account deletion below. Neither is rationed and neither asks a reason. The export is rows rather than pictures - it names your progress photos but does not contain them. For a copy of the photos themselves, write in and they will be sent to you. The export does not yet include your coaching records - applications, session bookings, reviews and plans a trainer sent - your schedule, or a trainer profile and its hours either; write in for a copy of those too.
To exercise any of the others, write to privacy@progressloop.eu. If you think your data has been handled wrongly you may complain to a supervisory authority - in Bulgaria that is the Commission for Personal Data Protection - or to the authority where you live, and you may also go to court.
Deleting your account
You can delete your account yourself, in the iPhone app or the Android app, under Settings, Delete account. You do not need the app for it: write to privacy@progressloop.eu from the address on the account, and it will be deleted for you. The page on deleting your account sets out both ways. Removing the app from your phone does not delete the account.
Deleting your account closes it irreversibly, at once: there is no waiting period in which it can be restored. Access ends immediately and active sessions are invalidated. Your training record, your body data, your progress photos, any AI training reviews, and your meals with their pictures, your food notes, your food diary, the recipes you starred and everything the meal assistant kept, and any workout motion you shared, are erased or irreversibly anonymised. Only data with a legal basis to survive is kept - and since there are no payments and no invoices, in practice that is very little. Copies in database backups go when those backups are overwritten, within 7 days. If the account was deleted for you at your request, our administration log keeps one line saying that the account, by its name or address, was deleted and when: it is the record that your request was carried out, and holds nothing else about you.
Deleting the account in the Android app also clears it from that phone: the Health Connect readings it kept, the progress photos taken on it, your reminders, what its widgets show, and the watch's sign-in. On any other phone or watch still signed in, the app stops working for the account the next time it reaches our server.
If you coach or are coached, deleting the account also ends every one of those relationships and erases the record of them from both sides, and each person you were actively coaching, or being coached by, is emailed that it has ended. A trainer profile leaves the directory. Plans and sessions you put into a client's account as their trainer belong to that client and stay with them, except a session that came from a booking, which goes as described next. A plan, guide or recipe you sent that is still on a client's shelf is not in their account, and goes with yours, as do your own guides; a copy they had already added, or a recipe they took into their meals, stays. Deletion cannot reach a copy a trainer made outside the app.
Your schedule and your session bookings are deleted with the account. A session still pending or confirmed with somebody else is cancelled on their side, and a confirmed one is taken off the client's schedule. Every review you wrote is deleted, taking its stars out of that trainer's average, and if you are a trainer, every review of you is deleted too. Your notification choices and registered phones are deleted, so are your answers about optional emails and the record of them, the surveys you were sent with your answers to them, and the record of the emails sent to you, and so is the record of the install the account was made on and the campaign it came from. If you signed in with Apple, the authorisation it gave us is handed back to Apple, which ends ProgressLoop's place in the list of apps you have used your Apple ID with. If you connected Google Calendar, the ProgressLoop calendar in your Google account is deleted and the permission Google gave us is withdrawn. Deletion cannot reach a copy of a plan you added to a calendar one at a time, or the events phone calendar sync wrote on your phone, which belong to that calendar - turn the sync off and choose to remove them first if you want them gone. Nor can it reach the workouts the watch wrote into Apple Health, which belong to Apple Health on your device and stay there, readable by any app you have allowed to read your workouts, until you delete them in the Health app. Nor can it reach the sessions your Android phone wrote into Health Connect from your Wear OS watch, which stay in Health Connect until you delete them there.
Children
ProgressLoop is not intended for children. It is meant for adults who train, and an account should be created only by someone aged 16 or over - or older, where the country you live in sets a higher age for consenting to online services. No account is knowingly created for a child. If you believe one has been, write in and it will be deleted.
Automated decisions
No decision producing legal effects or similarly significantly affecting you is made by automated means. The app does suggest a load to try on your next set, calculated from what you lifted in earlier sessions, leaving out any you marked as a lighter day - that is a suggestion you can ignore or overwrite, it changes nothing on its own, and it is not a decision about you in the sense the law means. The same holds for an AI training review, if you turn them on: it is automated analysis of your own training figures and workout and day notes that produces a reading and nothing else. No setting changes because of it, no load is altered, and no access is granted or withdrawn. A recipe from the meal assistant, and the calories and macros estimated for it, are suggestions of the same kind: nothing is saved or changed until you choose to. Sorting or filtering the trainer directory by rating is ordering by the average of the stars reviewers gave, and not a decision about any trainer.
Security and incidents
Connections are encrypted, passwords are hashed, progress photos sit in a private store reachable only through short-lived signed addresses, the permission to write to a connected Google Calendar is stored encrypted, a trainer's access to a client is checked against a live coaching relationship on every request, administrative access is restricted and separate from user accounts, and every administrative change is recorded in an audit trail. No internet service can promise absolute security.
If a personal data breach happens, the risk is assessed and the supervisory authority and the people affected are notified where the GDPR requires it.
Changes to this policy
This policy may be updated when the app, its providers or the law change. The new version and its date are published here. For a change that materially affects your rights or what you would reasonably expect, notice is given in advance, and where new consent is needed it is asked for rather than assumed.
Getting in touch
Any question about this policy, any request about your data, and any objection goes to privacy@progressloop.eu. See also the Terms of Use.