Privacy Policy
Last updated: September 24, 2026.
Who we are
MuscleBuddy ("MuscleBuddy", "we", "us", or "our") is operated by Garrett Makes It, LLC. This Privacy Policy explains how we collect, use, share, and protect personal information when you use the MuscleBuddy web application, progressive web app, and related services (the "Service"). For privacy questions or to exercise your rights, contact us at garrett@garrettmakesit.com.
By using the Service you agree to the practices described here. If you do not agree, do not use the Service.
MuscleBuddy is a direct-to-consumer wellness app, not a healthcare provider, health plan, or healthcare clearinghouse, so the Health Insurance Portability and Accountability Act (HIPAA) does not apply to how we handle your data. Instead, we protect your information under this Policy, the FTC Health Breach Notification Rule, and applicable state consumer-privacy laws (including the CCPA/CPRA and Washington’s My Health My Data Act) and, where applicable, the GDPR.
Information we collect
Account and profile data: name, email address, password (stored only as a salted hash by our authentication provider), date of birth or age, biological sex, height, weight, training goals, experience level, unit preferences, and a profile photo if you choose to add one.
Health and fitness data: this is the core of the Service and is highly sensitive. It includes weigh-ins and body-weight history, body measurements and symmetry data, progress photos, workout and exercise logs, recovery and sleep inputs, vital-sign readings (such as blood pressure and resting heart rate), bloodwork and lab-marker results, medical imaging studies and their readings, menstrual-cycle logs, rehab and return-to-training episodes, and supplement/compound stack details, including hormone and HRT/TRT protocols and routine prescription or over-the-counter medications, where you choose to record them.
Medical imaging: if you record an imaging study (a DEXA scan, an ultrasound, an echocardiogram, an MRI, a CT), we collect what you attach to it. That is the written report, any exported stills or clips, and, if you upload them, the DICOM files a hospital portal or a CD hands you. DICOM files are de-identified on our server before anything is stored: the patient name, date of birth, medical record number, accession number, institution, referring clinician, every identifier a scanner writes into the file, and every vendor-private field are removed against the DICOM PS3.15 Basic Application Level Confidentiality Profile, and the identifiers that link the file back to the hospital system that produced it are replaced with new ones that map to nothing. The file you upload is never stored in its original form: it exists only in memory for as long as it takes to strip it, and only the stripped copy is written. We refuse a file whose own header declares that patient details are printed into the picture itself, because that text cannot be removed reliably and storing it would keep the identifiers we just took out of the header.
Menstrual-cycle logging: if you track your cycle, we collect the start date of each period and its end date once you record one, the flow you note, the symptoms you tag, and any notes you write. We use it to time training and nutrition guidance around your cycle.
Rehab and return-to-training episodes: if you open a rehab episode, we collect which rehabilitation protocol you are following, the stage you are on, when you advanced through each stage and the readiness notes recorded at each advance, when the episode started and when it resolved, any notes you write, and the imaging study or compound protocol you link to it. If you have a coach, they can advance a stage; the only people who can are you and that coach.
Natural-status verification: if you apply for one, we collect the physique photos you submit with the application, and the reviewer handling your case also sees the lab report already attached to the bloodwork you logged. See "Third-party processors and sharing" for the AI passes a reviewer can run on both.
Workout videos: if you send a form-check video for review, record a Rep Coach clip while training, or record a posing clip while practising for a show, we collect the footage. A form-check video is reviewed by a person, an active coach of yours, and is never analyzed by any model. A Rep Coach clip is measured automatically for rep timing, and, only if you ask for one, a small number of still frames from it are sent for an AI cue pass; the clip itself is never sent. See "Third-party processors and sharing" and "Data retention" for how each is handled.
Upkeep and self-care data: appointments you schedule with a provider (type, provider name, date and time, location, and your notes); routine self-care cadences you track and their completion history (for example a dental or haircut cadence, a skin routine and the products in it, a logged wellness protocol such as sauna or cold-plunge sessions, or a habit you are trying to quit and its relapse history); your fasting windows, fasting schedule, and its reminders; any health conditions you declare, which adaptations for them you have turned on or off, and the changes the app has made to your program because of them; and, if you complete it, your periodic IIEF-5/SHIM sexual-health questionnaire responses.
Genetic data: if you choose to use the genetics feature, a curated set of genotype results for a small number of well-studied variants (see the Genetics page for the full list). If you upload a raw-DNA export (for example from 23andMe), it is parsed entirely on your device: the file itself is never uploaded or sent to us in any form, and only the curated results extracted from it are. You can also enter select genotypes yourself instead of uploading a file.
Nutrition data: food logs, macro and calorie targets, recipes, meal plans, pantry contents, and dietary restrictions.
Animals you look after: if you add a pet, we collect what you tell us about it: its name, species, breed, size class, birthdate, weight, body condition score, whether it is neutered, its activity level, its height and body length, and any notes you write. We also record which members of your household co-own it, the preventive-care schedule you turn on for it (such as a flea preventive, a wellness exam or a weigh-in) with when each item was done and who ticked it off, and any spending you link to it in your expenses, such as a vet visit. The feeding, training and enclosure guidance shown for a pet is calculated from these details each time and is not stored separately. A pet is not a person, so none of this is treated as your health data. The details of a pet you own are included when you export your data, and are deleted with your account unless another owner still shares the pet.
Spending you track: if you use the cost features, we collect the expenses you log (their category, amount, currency, date, whether they repeat, and an optional vendor and note), which food, supplement, appointment or pet an expense is linked to, and the budgets you set.
Coaching and social data: messages with coaches and the AI coach, check-in submissions, challenge participation, leaderboard standing, social posts, and follow relationships.
Payment data: subscription tier, billing status, and transaction metadata. Full card numbers are handled by our payment processor and are never stored on our servers.
Device and usage data: IP address, browser and device type, app interactions, feature usage, crash and diagnostic logs, and data synced from connected devices (for example smart scales and wearables) that you choose to link.
How you found us: if you arrive from one of our ads, emails, or campaign links, the link carries campaign labels in its web address (the “utm” values you can see in the URL, and, on a paid ad, the click identifier the ad platform adds). If you then create an account, we record those labels against it once, so that we can tell which channel a signup came from using our own data rather than an advertising platform’s. We do not create or store any identifier for you before you have an account: nothing follows you around the site, and nothing is kept about a visit that does not end in a signup. Alongside the campaign labels we record the page you first landed on and the website that referred you (its domain only, never the full address). None of this is collected if you decline analytics and advertising cookies or send a Global Privacy Control signal, and the ad-platform click identifiers are recorded only if you actively accept those cookies.
Contacting us without an account: if you use the contact form on our website (musclebuddy.net/feedback), we collect what you write and, if you choose to give it, the email address you ask us to reply to. The address is optional, it is stored with your message, and it is used for one thing only: answering you about that message. It is never added to a mailing list, never used to advertise to you, and never matched against an account. Your IP address is processed at that moment to rate-limit the form and, where the challenge is deployed, by Cloudflare to check that you are a person; neither is stored with your message. What you write is scrubbed of anything resembling a secret before it is stored, and the message is filed as an issue in our private code repository the same way an in-app report is.
How we use your information
We use your information to: provide and operate the Service; generate training programs, macro targets, and reactive adjustments; power AI coaching, check-in analysis, and compound-interaction explanations; enable coaching relationships and the social layer; process subscriptions and payments; send transactional and (where permitted) marketing communications; maintain security and prevent abuse; comply with legal obligations; and improve the Service through aggregated, de-identified analytics.
We process special-category health data (bloodwork/lab results, supplement, compound, and hormone/HRT details, vital-sign readings, medications, appointments, self-care and fasting tracking, declared health conditions, symptom logs, menstrual-cycle logging, rehab and return-to-training episodes, medical imaging studies and readings, and sexual-health questionnaire responses) only on the basis of your explicit consent. Before you can first use any of these features, we present a dedicated consent screen, separate from the Terms/Privacy acceptance you gave at signup, that names the categories of health data involved. You can withdraw this consent at any time in Settings → Privacy & data; withdrawing stops any further collection of new health data but does not delete data you already recorded (you can request deletion separately: see "Your rights" below).
Genetic data is collected and used only on the basis of your separate, explicit consent under GDPR Article 9(2)(a): before any genotype can be stored, a dedicated consent screen on the Genetics page (Upkeep → Genetics) names what will be stored and how, distinct from the health-data consent above. We use it only to show you, next to your own bloodwork, caffeine, and symptom-log entries, what the current evidence associates a variant with; a genotype never changes a training program, a nutrition target, or any other recommendation the Service makes, and no coach or social surface ever sees it. Withdrawing consent or deleting your stored results (both available on the Genetics page) removes them immediately, not on a delay; see "Data retention" below for how long a database backup can still hold a deleted copy.
Leaderboards: your training-leaderboard participation is on by default, while the nutrition and health leaderboards are off unless you turn them on. A leaderboard shows your display name, your profile photo, and the single figure it ranks: a rank tier and score, or a total such as your training volume over the last 30 days, your all-time count of personal records, or your current logging streak. It never shows an individual workout, a lift, or any other entry you logged. Turning the training leaderboards off in Settings → Privacy & data takes you off all of them, and setting your profile visibility to Nobody takes you off every leaderboard as well as out of search.
Third-party processors and sharing
We do not sell your personal information. We share it with the following categories of service providers ("processors") strictly to operate the Service, each bound by contractual data-protection obligations:
- Google (Sign in with Google): if you choose to sign in or sign up with Google, we share your account identity with Google as part of that OAuth exchange, and Google returns your name, email address, and profile photo to us to create or authenticate your account; we send Google no health, fitness, or nutrition data. "Sign in with Apple" and "Continue with Facebook" are built but not live in production, and neither is disclosed here as a recipient. The reason is that the app as shipped contacts no Apple or Facebook sign-in endpoint at all: those code paths are gated out of the build, so there is no exchange to describe. Where an integration’s code does ship and is held back only by a credential we have not issued, we disclose it below and mark it as not currently offered, because a configuration change alone would make it live. Either kind is only ever surfaced if we turn it on, at which point this Policy is updated first.
- Supabase: authentication, database hosting, and file/photo storage.
- Railway: hosting for our application server. Every request you make to the Service passes through it, and it holds our server logs; it keeps no copy of the database, and we do not log request bodies.
- Vercel: hosting and content delivery for the web app and marketing pages. It sees your IP address and request metadata; your training, nutrition, and health data are not sent through it.
- Cloudflare: bot and abuse protection on the public forms: sign-in, sign-up, password-reset, newsletter signup, and the contact form at musclebuddy.net/feedback. Its Turnstile challenge runs in your browser on those pages only and receives your IP address, user agent, and interaction signals to decide whether you are a person; we send it no account identifier and no health, fitness, or nutrition data.
- OpenFreeMap: map tiles for the Turf map. Your browser requests tiles directly from it, so it receives your IP address and the map area you are viewing; we send it no account identifier and no health, fitness, or nutrition data.
- Stripe: payment processing and subscription billing. We send your email address, subscription tier and billing status; full card numbers go to Stripe directly and never reach our servers. If you subscribe to a coach, a client’s subscription to a coach is created and managed at Stripe, and a coach who takes payments sets up a coach’s payout account details with Stripe through its own onboarding. A gym or studio that subscribes its members has a gym organisation’s billing contact held at Stripe for the same purpose. A referral credit you earn is applied to your Stripe balance so that Stripe discounts your next invoice. When you delete your account we ask Stripe to delete your Stripe customer record.
- Anthropic (Claude API): AI coaching, check-in analysis, compound-interaction explanations, plain-language summaries of your Lift Report, photo food logging, voice food logging, automated safety screening of profile photos, the optional Rep Coach form check, reading measurements off an uploaded imaging report, and the review passes run on a natural-status verification. Content you send to AI features is processed to generate responses: coaching questions you type to the AI coach and your check-in answers are sent when you use those features, the compounds in a stack are sent when you ask for an interaction explanation, and the figures in your Lift Report are sent when you ask for a plain-language summary of it. A profile photo you upload is additionally sent to Anthropic’s vision model to screen it for unsafe imagery before the photo becomes publicly visible. If you log a meal from a picture, a photo of a meal you log is sent to Anthropic’s vision model to draft the food entries; the draft is yours to edit and nothing is written to your log until you confirm it. If you log a meal by speaking it, your device transcribes what you said and the text of a meal you dictate is sent to Anthropic to draft the food entries; the recognition runs on your device, so the audio itself is never uploaded to us or to anyone else, and the draft is yours to edit with nothing written to your log until you confirm it. If you record a set with Rep Coach and then ask for a form check, a small number of still frames from a Rep Coach clip are sent to Anthropic’s vision model to generate coaching feedback; this happens only when you ask for it, never automatically, and the video itself is never sent. If you ask us to read the measurements off an imaging report, an imaging-report document or photo (an echo, DEXA, MRI, or similar report) is sent to Anthropic’s vision model to transcribe them; this happens only when you ask for it, and the extracted values are written unconfirmed until you accept them. If you submit a natural-status verification, then only once one of our reviewers opens your case, a lab report you attached to a bloodwork entry is sent to Anthropic’s vision model to compare against the marker values you typed, and at the strictest verification tier the physique photos in a natural-status verification are sent to it to describe what they show; neither pass decides anything, both are advisory to the human reviewer, and nothing is sent unless a reviewer opens the case.
- Open Food Facts: packaged-food nutrition lookups by scanned barcode; we send only the barcode you scan, never your account or personal information.
- USDA FoodData Central: packaged-food nutrition lookups by scanned barcode, used when Open Food Facts has no match; we send only the barcode you scan, never your account or personal information.
- Google (Places API): gym and metro-area location search. When you search for a gym to check in at, or set your home metro area, the text you type is sent to Google to return matching places. When you ask the Turf map to find gyms in the area you are looking at, the coordinates of the map area you ask to search are sent instead, so Google can return the places inside it. We send no account identifier and no health, fitness, or nutrition data.
- GitHub: bug reports, feature ideas and questions, whether you send them from inside the app or from the contact form at musclebuddy.net/feedback. When you submit one, the report is filed as an issue in our private code repository, including your display name (or, if you have not set one, your email address) so we can follow up. From the signed-out form it carries instead the reply address you chose to give, and nothing identifying you at all if you left it blank. Alongside what you wrote, the issue carries the page you were on, your browser’s user agent and window size, the app version, and the recent console output from your browser, because a bug report without them is rarely reproducible. All of it is automatically scrubbed first: the report text and the console output of secrets and other people’s email addresses, and the page address of its query parameters, its fragment, and any identifier or single-use link token in its path, so what is filed is the route you were on rather than the link you followed to it.
- Resend: transactional and marketing email delivery. Resend receives your email address and the full message body of every email we send you: the welcome email when you sign up; appointment reminders naming the provider or appointment type; fasting reminders and their plan detail; workout-day reminders naming the session; weekly and monthly recaps with your training highlights; payment and billing notices; account deletion and removal notices; coach referral summaries; the newsletter and onboarding drip mail you opted into; re-engagement and win-back mail; and the notification emails you turn on. Reminder, recap, and re-engagement mail is sent only where you have turned that channel on or opted in, and you can turn any of it off in Settings → Notifications; the sending choice is yours, but where a message does go out, its whole body passes through Resend. Resend also receives your email address alone when we add or remove you from the newsletter list, and a crew invite you send to someone by email: the address you enter, your display name and the name of the crew. It is never sent your photos, your uploads, or the underlying training, nutrition, and health records themselves.
- Google Analytics: aggregated, privacy-conscious usage analytics. We also import the GA4 "sign_up" conversion event into Google Ads so we can measure which ads produced a signup, which makes Google an advertising recipient too: it receives the fact that a signup occurred, never your email address, name, or any health, fitness, or nutrition data. Under the CCPA/CPRA this conversion import may count as "sharing" personal information for cross-context behavioral advertising; the cookie banner is your opt-out, and it runs only if you opt in. We do not run Google remarketing, display, or app-install advertising, and Google never receives your consumer health data for any advertising purpose.
- Microsoft Clarity: usage analytics including anonymized session replay and click/scroll heatmaps, used to understand and improve the Service's usability. All page text and form input content is masked from recordings by default, given the sensitivity of the health and fitness data the Service handles. Clarity also records the address of the page you are on, and masking does not cover addresses, so it does not run at all on the health and upkeep pages: nothing is recorded, and no page address is sent, while you are anywhere under Health, Upkeep, Compounds, Stack, Recovery or Phases. Reaching one of those pages stops recording for the rest of that visit.
- Meta (Facebook) Pixel: advertising measurement. It records that a page view, signup, subscription purchase, trial start or cancellation happened, and the amount of a purchase, so we can measure which ads bring people to the Service. The pixel reads the address of the page you are on itself, so it sends nothing at all while you are anywhere under Health, Upkeep, Compounds, Stack, Recovery or Phases, or on a page whose address carries a record identifier or a single-use link token; its own automatic page views and automatic events are switched off, so nothing it sends bypasses that check. The page view and signup are recorded by the pixel in your browser; the purchase, trial-start and cancellation events are reported by our server when Stripe tells it what happened to a subscription, and each carries the amount and currency where money moved and, on a cancellation, whether the subscription was still in a trial. A server-sent event also carries the browser user agent recorded when the ad click was claimed, which Meta requires for a website-sourced conversion, and the address of the page the event is reported for. That address is always one of a few fixed routes on our own site, never a page you navigated to and never carrying a query string, and it is what lets Meta recognise a server-sent event and the pixel’s own event as the same one rather than counting it twice. A purchase also carries a label naming which of our revenue streams it belongs to (a coach subscription or a gym organisation’s subscription). A purchase or cancellation made for a gym or studio is reported against the organisation owner who paid for it, and hiring a coach is reported against the client who paid, so an event may describe a subscription bought on behalf of other people rather than your own. Every one of those server-sent events is keyed on the advertising click identifier stored when you arrived from an ad, which exists only if you granted advertising consent without Global Privacy Control, so a member who declined advertising produces no send at all; withdrawing that consent erases the stored identifier and the user agent with it. We send no email address, name, or any health, fitness, or nutrition data to Meta. Under the CCPA/CPRA this use of an advertising pixel may count as "sharing" personal information for cross-context behavioral advertising; the cookie banner is your opt-out, and the pixel never loads unless you opt in.
- TikTok Pixel: advertising measurement. It records that a page view, signup, subscription purchase, trial start or cancellation happened, and the amount of a purchase, so we can measure which ads bring people to the Service. The pixel reads the address of the page you are on itself, so it sends nothing at all while you are anywhere under Health, Upkeep, Compounds, Stack, Recovery or Phases, or on a page whose address carries a record identifier or a single-use link token; its own automatic page views and automatic events are switched off, so nothing it sends bypasses that check. The page view and signup are recorded by the pixel in your browser; the purchase, trial-start and cancellation events are reported by our server when Stripe tells it what happened to a subscription, and each carries the amount and currency where money moved and, on a cancellation, whether the subscription was still in a trial. A server-sent event also carries the browser user agent recorded when the ad click was claimed, and the address of the page the event is reported for. That address is always one of a few fixed routes on our own site, never a page you navigated to and never carrying a query string. A purchase also carries a label naming which of our revenue streams it belongs to (a coach subscription or a gym organisation’s subscription). A purchase or cancellation made for a gym or studio is reported against the organisation owner who paid for it, and hiring a coach is reported against the client who paid, so an event may describe a subscription bought on behalf of other people rather than your own. Every one of those server-sent events is keyed on the advertising click identifier stored when you arrived from an ad, which exists only if you granted advertising consent without Global Privacy Control, so a member who declined advertising produces no send at all; withdrawing that consent erases the stored identifier and the user agent with it. We send no email address, name, or any health, fitness, or nutrition data to TikTok. Under the CCPA/CPRA this use of an advertising pixel may count as "sharing" personal information for cross-context behavioral advertising; the cookie banner is your opt-out, and the pixel never loads unless you opt in.
- Sentry: crash and error diagnostics used to find and fix bugs. Events are configured to omit default personal information, and request data (headers, cookies, body) is stripped server-side before transmission; Sentry session-replay recording is not enabled.
- Withings: if you connect a Withings device (an optional integration you initiate), we exchange OAuth tokens with Withings and read the biometric readings you authorize, such as body-weight and heart-rate data, to sync them into the Service; you can disconnect the integration at any time, which revokes our access.
- Whoop: if you connect a Whoop strap (an optional integration you initiate), we exchange OAuth tokens with Whoop and read the biometric readings you authorize, such as strain, recovery, heart-rate variability, resting heart rate, and sleep data, to sync them into the Service; you can disconnect the integration at any time, which revokes our access.
- Oura: if you connect an Oura ring (an optional integration you initiate), we exchange OAuth tokens with Oura and read the biometric readings you authorize, such as sleep, readiness, heart-rate variability, resting heart rate, and (if you grant the scope) workout and activity data, to sync them into the Service; you can disconnect the integration at any time, which revokes our access.
- Polar: if you connect a Polar device (an optional integration you initiate), we exchange OAuth tokens with Polar and read the biometric readings you authorize, such as training sessions, heart-rate, and sleep data, to sync them into the Service; you can disconnect the integration at any time, which revokes our access. This integration is not currently offered: we have not provisioned Polar credentials, so the option to connect shows "Coming soon" and no exchange can be started. What is described above is what happens once we turn it on, and this Policy is updated before that.
- Google Health: if you connect a Google Health source (an optional integration you initiate), we exchange OAuth tokens with Google and read the biometric readings you authorize, such as resting heart rate, heart-rate variability, sleep, and activity data synced from Fitbit, Pixel Watch, and other Google Health sources, to sync them into the Service; you can disconnect the integration at any time, which revokes our access. This integration is not currently offered: we have not provisioned Google Health credentials, so the option to connect shows "Coming soon" and no exchange can be started. What is described above is what happens once we turn it on, and this Policy is updated before that.
- Apple (Push Notification service): delivery of push notifications to Safari when you turn on notifications for the web app there. Apple receives your browser push endpoint and the encrypted notification: the notification is encrypted so that only your browser can read it, so Apple sees when it was sent and how long to hold it, but not what it says. Our iPhone and iPad app sends no push notifications at all, so Apple receives no device push token and no notification content from it; if we ever turn that on, Apple would receive your device’s push token and the notification content it must deliver, and this Policy is updated before that. Apple receives nothing if you do not turn on notifications in Safari.
- Google (Firebase Cloud Messaging): delivery of push notifications to Chrome and the other browsers that use Google’s push service (such as Opera, Samsung Internet, Brave and Vivaldi) when you turn on notifications for the web app there. Google receives your browser push endpoint and the encrypted notification, which it cannot read. Our Android app sends no push notifications at all, so Google receives no device push token and no notification content from it; if we ever turn that on, Google would receive your device’s push token and the notification content it must deliver, and this Policy is updated before that. Google receives nothing if you do not turn on notifications in one of those browsers.
- Mozilla (Firefox push service): delivery of push notifications to Firefox when you turn on notifications for the web app there. Mozilla receives your browser push endpoint and the encrypted notification, which it cannot read, along with when it was sent and how long to hold it; it receives nothing if you do not turn on notifications in Firefox.
- Microsoft (Windows Push Notification Services): delivery of push notifications to Microsoft Edge when you turn on notifications for the web app there. Microsoft receives your browser push endpoint and the encrypted notification, which it cannot read, along with when it was sent and how long to hold it; it receives nothing if you do not turn on notifications in Edge.
Apps you connect: MuscleBuddy is one of a small family of apps from the same company (the "Life OS" apps). You can connect one of them to your MuscleBuddy account. Each is a separate service with its own privacy policy, and it receives your data as its own controller, not as our processor. Nothing is shared until you approve the connection and each kind of data it asks for, one at a time, and you can disconnect it at any time in Settings → Connected accounts, which stops any further sharing at once; what it already received is then held under its own privacy policy. • AdventureOS: trip and outdoor-adventure planning. With your approval it can read your daily recovery score, so it can show how ready you are for a trip day; your calorie and macro targets for a day, so it can size food and pack weight (targets only, never what you ate); and your pets’ species, breed and size, so it can size gear for them. Your recovery score is health data, and AdventureOS only ever learns the reason behind a low score (illness, injury or sleep debt) if you separately allow that too. It never receives a logged workout, bloodwork, a compound or your pets’ health details. • NetWorthy: personal finance and budgeting. With your approval, NetWorthy would receive your training and gear spend as expenses and your gym equipment as tracked assets, and, only with a separate health-data consent, what you spend on therapy, medication, lab tests and supplements (the spending, never the health records themselves). This connection is not currently offered: we have not set up NetWorthy access, so the option to connect cannot be started. What is described above is what happens once we turn it on, and this Policy is updated before that.
Google Analytics (including the Google Ads conversion import), Microsoft Clarity, the Meta Pixel, and the TikTok Pixel only run after you grant analytics and advertising consent in the cookie banner, and never run if you have Global Privacy Control enabled. You can withdraw that consent at any time from the same banner (reachable from "Cookie preferences" in the footer).
Genetic data: your genotype results are encrypted before they are ever written to our database, so Supabase, our database host, stores only ciphertext it cannot read; the decryption key is held only in our application environment, never in the database. No processor is ever sent your results in a readable form, and none receives them for any purpose of its own; we decrypt them only to display them back to you on the Genetics page.
Coaches: if you enter a coaching relationship, the coaches you authorize can access your data through granular scopes that you grant and can revoke; you see exactly which scopes a coach is requesting before you accept them. The training and nutrition scopes share your programs, logged workouts, and nutrition data, including your form-check videos and Rep Coach clips; the check-in scope shares your check-in submissions. Two scopes cover special-category health data and are shared only if you explicitly grant them: the health scope lets a coach view your detailed health records (bloodwork and lab-marker values, vital-sign readings, body measurements, and an alert when a recent marker falls outside the expected range) and any special-category check-in fields (such as mood, stress, or libido); the compounds scope lets a coach view your supplement and compound stack, including doses. A coach you have not granted a given scope sees none of the data under it. Data ownership stays with you, and a coach loses all access when the relationship ends. There is no scope that shares genetic data: no coach can ever see your genotype results, regardless of which scopes you grant. The same is true of your Upkeep data: appointments, medications, self-care cadences, fasting tracking, declared health conditions, and sexual-health questionnaire responses are not shared with a coach under any scope.
We may also disclose information to comply with law, enforce our Terms, protect rights and safety, or in connection with a merger, acquisition, or asset sale (subject to this Policy).
Data retention
We retain personal information for as long as your account is active and as needed to provide the Service. Specifically:
- Account, profile, training, nutrition, health, and Upkeep data (appointments, medications, self-care cadences, fasting tracking, declared health conditions, and sexual-health questionnaire responses): retained while your account is active, and deleted or de-identified within 30 days of account closure, except for the records named below that deliberately survive closure.
- Genetic data: retained only for as long as your genetic-data consent stands; withdrawing it or deleting your results (both available on the Genetics page) removes them from our live database immediately, not within 30 days. The rolling backup-purge cycle below still applies to whatever backup already held them.
- Sign-ins that never become an account: if you sign up and never confirm your email, or confirm it and never open the Service, we hold a sign-in record (your email address, and when it was created and last used) with no account behind it. It is deleted 30 days after it was last used.
- Backups containing personal data: purged on a rolling cycle, within 30 days.
- Billing and transaction records: retained for 7 years to meet U.S. tax, accounting, and audit obligations.
- Security audit logs (coach/admin/billing actions): retained 2 years on a legitimate-interest basis for security and fraud prevention, then deleted. They record who did what to whose data, so they deliberately survive account closure and run their full 2-year window from the action rather than from the closure. Deleting the trail of an account that then closes itself is the abuse the trail exists to record.
- Email suppression list: if our email provider tells us that an address permanently bounced or that one of our messages was reported as spam, we record that address so we stop sending to it. We keep that record on a legitimate-interest basis (not sending to an address that has already refused, and protecting the reputation of the domain we send from), and it deliberately survives account closure, because deleting it would start mail flowing again to a mailbox that had told us to stop. It holds the address, the reason, and the date. It is deleted after 3 years.
- Account erasure records: when an account is erased, we keep a record that the erasure happened. It holds a one-way hash of the erased account id, the reason for the erasure, and the date, and nothing else. The hash is computed under a key we hold outside this database, so the record identifies no one and cannot be used to reconstruct anything about the account. It deliberately survives the erasure it records, and any later erasure request, under GDPR Article 17(3)(b) and (e): it is the only evidence that a request was honoured, and destroying it would leave us unable to demonstrate the compliance the law requires us to demonstrate. It is deleted after 7 years.
- Form-check videos: no separate retention window; deleted along with the rest of your account data, within 30 days of account closure, or immediately if you delete one yourself.
- Rep Coach clips: deleted 30 days after you record them, unless you pin one to keep it. You can delete any of them yourself at any time.
- Posing clips: deleted 90 days after you record them, or 30 days after the show you linked one to, whichever is later, unless you pin one to keep it. The window follows the show because the point of a posing clip is comparing one week of prep to another, and a flat window would delete the earlier clip mid-prep. You can delete any of them yourself at any time.
- Natural-status verification photos: the photos you submit with an application are deleted 30 days after a decision on it. The case record itself stays, and notes that photos were submitted and later deleted, so an appeal or an audit can still tell what the decision was made on.
- Signup attribution (the campaign labels described in “Information we collect”): retained while your account is active and deleted with the rest of your account data, within 30 days of account closure. It is written once when the account is created and never updated afterwards. If you later withdraw analytics and advertising consent, the ad-platform click identifiers held against your account are deleted at that point; the campaign labels, which are our own and not an advertising platform’s, are kept.
- Accounts we remove: if we remove your account (for example, for a breach of our Terms), we suspend it and email you first. For 14 days after that email you can still sign in to download your data export, and the account is then erased as described above. We may erase an account at once instead where keeping it for 14 days would put someone at risk; you are emailed either way.
- De-identified or aggregated data that can no longer be linked to you: may be retained indefinitely. This includes a de-identified copy of an erased account’s training, nutrition, and bodyweight history, which we keep to improve the Service. It holds no name, contact details, account identifier, calendar dates (only days counted from signup), free text, photos or videos, location, or health records such as bloodwork, medications, or compounds, and it is never kept for an account erased because its holder was under the minimum age.
We keep data longer than the periods above only where required by law or where reasonably necessary to resolve disputes or prevent fraud (a legal hold).
Your rights
Subject to applicable law, you have the right to: access the personal information we hold about you; export your data in a portable format; correct inaccurate data; delete your account and associated personal data; object to or restrict certain processing; and withdraw consent for processing that relies on it. Depending on your jurisdiction (for example the EEA/UK under GDPR, or California under the CCPA/CPRA) you may have additional rights, including the right to lodge a complaint with your local data-protection authority.
Under the CCPA/CPRA, we use sensitive personal information (including health data) only to provide the services you've requested (the permitted-purpose exemption under Cal. Civ. Code §1798.121(a)), so we do not present a separate "Limit the Use of My Sensitive Personal Information" opt-out. Your access, correction, and deletion rights over that data remain fully available through the channels described in this section.
To exercise any of these rights, email garrett@garrettmakesit.com. We will respond within the timeframe required by applicable law.
Washington Consumer Health Data Rights
We collect "consumer health data" as defined by Washington's My Health My Data Act (RCW 19.373), including bloodwork results, medical imaging studies and the files attached to them, compound/HRT/PCT cycle tracking, vital signs, biometric/device data, genetic/genotype data, medications, appointments, self-care and fasting tracking, declared health conditions, sexual-health questionnaire responses, and workout videos, to power the Service's coaching and health-tracking features.
We do not sell consumer health data, and we do not use geofencing to target advertising around health facilities.
We do advertise the Service on third-party platforms. That advertising never uses your consumer health data: we do not share it with, or use it to build audiences on, any advertising platform, and we do not target ads based on it. Our advertising tags and imports are the Meta Pixel, the TikTok Pixel, and the Google Ads conversion import described in "How we share information," which record page views, the fact that a signup occurred, and the fact and amount of a subscription purchase, trial start or cancellation, never bloodwork, compound or HRT/PCT cycles, vital signs, biometric or device readings, body measurements, or any other health, fitness, or nutrition data. None of them runs at all unless you opt in through the cookie banner, and we do not run Google remarketing or display advertising.
You have the right to: confirm whether we are processing your consumer health data; access it (see "Export my data" in Privacy & data settings); withdraw consent to its processing (see "Health data consent" in Privacy & data settings) and have the underlying data deleted (see "Delete my health data" in Privacy & data settings), including instructing our processors to delete it; we will complete deletion within 30 days and confirm within 45 days; and appeal a denied rights request by contacting us at the address in "Contact us," with a response within 45 days.
These rights, and the settings controls named above, apply to your own MuscleBuddy account. They are not available on the public demo, which runs on shared accounts that belong to no one. See "Demo accounts" below before entering anything about yourself there.
This section serves as our designated "Consumer Health Data Privacy Policy" under RCW 19.373.
Demo accounts
We publish a public demo of the Service. It signs you straight in to a pre-built account so you can look around without registering.
The demo accounts are SHARED. There is one per demo track, every visitor is signed in to the same one, and there is no separate identity for you inside it. Anything you type there is visible to the next visitor, and to us. Do not enter anything real about yourself on the demo: in particular, do not enter real bloodwork, medications, measurements, photographs, or anything else about your health.
Because a demo account belongs to no one, we cannot tell one visitor’s entries from another’s. That has a consequence we would rather state plainly than leave you to discover: the self-serve export, consent-withdrawal and deletion controls described elsewhere in this Policy are switched off on the demo, and we cannot honour an individual access or deletion request for something typed there, because we have no way to identify which entries were yours and deleting them would erase other visitors’ entries too.
What we do instead is clear the demo accounts wholesale. Entries made on a demo account are deleted when the account is next reset, which happens on a recurring schedule rather than immediately. If you have entered something on the demo that you want removed sooner, contact us at garrett@garrettmakesit.com and we will reset that demo account, which deletes every entry on it.
The demo is not a place to keep anything. Creating your own account is the only way to have data that is yours, private to you, exportable, and deletable on request.
Children’s Privacy (COPPA)
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13 without verifiable parental consent, we will delete it promptly. Where the Service itself learns it, deletion is immediate and automatic: if you tell us at signup or during onboarding that you are under the minimum age, we do not simply refuse the account, we delete it and everything on it in the same moment, including the email address, name and photograph collected before your age was known. If you believe a child under 13 has provided us personal information, contact us at garrett@garrettmakesit.com.
For users in the European Economic Area and the United Kingdom, the minimum age to use the Service without parental consent under GDPR rules on a child’s consent (GDPR-K) is 16. Accordingly, we require all users to be at least 16 years old, and we enforce a minimum age of 16 at signup. Certain features, for example the compounds and hormone/HRT module, concern subject matter intended for adults and may require you to be at least 18 to access them.
Security
We use industry-standard technical and organizational measures, including encryption in transit, access controls, and hashed credentials, to protect your information. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential.
If you believe you have found a security vulnerability in the Service, report it to garrett@garrettmakesit.com rather than disclosing it publicly. Include enough detail to reproduce the issue. We will acknowledge receipt, investigate in good faith, and will not pursue legal action against a report made in good faith that avoids privacy violations, data destruction, and service disruption. This is also published as `/.well-known/security.txt` per RFC 9116.
International transfers
Your information may be processed in countries other than where you live, including by the processors listed above. For users in the EEA, the UK, and Switzerland, personal data may be transferred to the United States and other countries where we or our processors operate. Such transfers rely on the EU Standard Contractual Clauses (SCCs) and, for the UK, the UK International Data Transfer Addendum, and on the EU–U.S. Data Privacy Framework where a processor is certified. Our processors are contractually bound to provide a level of protection equivalent to the protections in your home jurisdiction.
Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or by email. The "Last updated" date above indicates when this Policy was last revised. Continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
Contact us
Questions about this Privacy Policy or our data practices? Contact Garrett Makes It, LLC at garrett@garrettmakesit.com or by phone at (386) 243-4263. This Policy is governed by the laws of the State of Florida, United States.
This Policy is provided for general information and does not constitute legal advice; for questions about your own specific situation, please consult your own qualified professional.
Read the Terms of Service too
Our Terms of Service cover eligibility, the health disclaimer, subscriptions, and your responsibilities when using MuscleBuddy.