Privacy Policy
This policy says what Core Motion stores about you, why, who else sees it, and how to get rid of it. It describes what the app actually does — not a general template.
Who is responsible
Core Motion is the controller of the data described here. Write to support@core-motion.app about anything in this policy, including a request to access or delete your data.
What we store
Only what the app needs to do its job:
- Account: your email, your name, and — if you sign in with Google — the identifier Google gives us. Never your Google password.
- About you: sex, date of birth, height, weight, your goal and target weight, how long you have been training, your language and units.
- Training: your programme, every session, every set with its weight and reps, how hard it felt, your rests, your personal records, and any joints or movements you have told us to avoid, including what you wrote in your own words.
- Nutrition, if you use it: your meal plan, the meals you log, your calorie and macro targets, and any dietary restrictions you give us.
- Trackers: body weight, water, steps, and — if you take them — progress photos.
- Google Fit, only if you connect it: your daily step counts. We ask for read access to activity data and nothing else.
- The AI coach: your chat messages and the facts the coach remembers about you, so it does not ask the same thing every week.
- Operational records: when the account was last active, how much AI it has used (model, tokens, cost) and when a request was refused for hitting a limit. Anything you send us through feedback.
- Product analytics: which screens are opened and whether the app was launched as an installed app, tied to a random identifier for the browser rather than to your name; and, at signup, where you arrived from (a campaign tag in the link, or the site that referred you).
We do not collect your precise location, we do not read your contacts, and there is no advertising or tracking network in the app.
Why we are allowed to
For most of the above, because we cannot provide the service without it: a training app that does not remember your training is not a training app. That is the performance of our contract with you.
Your body metrics, your injuries and your progress photos are health data, which needs more than that — we process them on your explicit consent, given when you enter them, and you can withdraw it by deleting the data or the account.
Keeping the service secure and working — the usage records, the abuse limits, the error logs — is our legitimate interest.
Who else sees it
Nobody buys it, and it is not shared for advertising. It reaches these processors only, and only as far as each one needs:
- AI providers (Anthropic and/or OpenAI, depending on the feature): the relevant part of your training context — your programme, recent sessions, goal, limitations, and what you type in chat — is sent so the coach can answer. Progress photos and meal photos are sent when you ask for them to be analysed. These providers process the request on our behalf and do not use it to train their models.
- Google: sign-in, if you use it, and Google Fit, if you connect it.
- Our hosting provider, which runs the server and its backups.
- Email and push delivery, to send you a password reset or the reminders you have turned on.
- Error tracking, if enabled, which receives technical details of a crash.
Some of these are outside the EU. Where that is so, the transfer is covered by the European Commission's standard contractual clauses.
How long we keep it
Your account data stays while the account exists. When you delete the account it is disabled at once and everything it owns — training, nutrition, photos, chat, trackers — is erased 30 days later. The 30 days exist so a deletion made by mistake can be undone; sign in during that time to cancel it.
Product analytics events are deleted automatically after 60 days. Records of AI usage are kept longer, without the content of the request, because they are what our costs and limits are calculated from.
Your rights
You can see and correct most of your data directly in the app. Beyond that you have the right to a copy of it, to have it corrected or erased, to restrict or object to processing, and to withdraw a consent you gave. Write to us and we will answer.
Deleting the account is the quickest route and needs nobody's help: open your profile and delete it there.
If you think we have handled your data wrongly, you can complain to your national data protection authority.
Security
Traffic is encrypted in transit. Passwords are stored hashed, never in a form anyone can read, and any API key you are given is stored encrypted. Access to the production database is limited to the operator.
No system is perfectly secure. If a breach ever affects your data, we will tell you and the regulator as the law requires.
Children
The service is not intended for anyone under 16, and we do not knowingly keep data about them. If you believe a child has created an account, write to us and we will remove it.
Changes
If this policy changes in a way that affects you, we will tell you in the app before the change takes effect.
Questions: support@core-motion.app