← Back to home

Privacy Policy

Last updated: 5 August 2026

This Privacy Policy explains how the Strathlon mobile application (the "App") handles your information. We have designed Strathlon to keep your data on your device wherever possible. The App does not require an account or a login, and we do not run any advertising or third-party analytics SDKs.

In short: Your data lives on your iPhone. You don't need an account. Your training history is also backed up to your own private iCloud so it survives a new phone, and you can turn that off in the app. Apple Health access is permission-based: Strathlon reads the figures you permit and writes nothing back from your iPhone; if you use Strathlon on an Apple Watch, the watch app saves the workouts it records to Apple Health — that is the only thing Strathlon writes. By default those figures are not sent anywhere. The exception is the AI Coach: when you use it, your message, any food photo, and the profile and plan context it needs to answer about your programme — including your health & safety details — are sent to our AI provider to generate that response. Sections 4 and 5 list exactly what, and which switch governs it. Subscriptions are handled entirely by Apple. We don't sell your data, and we never use your health data for advertising.

1. Who we are (Data Controller)

The data controller is Chanaka Ekanayake trading as Strathlon, developer of Strathlon. You can contact us about privacy at support@strathlon.com.

2. No account needed

Strathlon does not require you to create an account, and we do not ask for your name purely to identify you (the name you optionally enter during setup is used only to personalise the App on your device). There is no email/password sign-up and no social login. Your subscription is identified to us only by the anonymous transaction identifier Apple assigns (see section 6). The one time we hold an email address is when you choose to give us one — sending a feature request (from the app, or from the form on this site), or joining the launch list on this site (see section 14).

3. What we collect, and why

The following is created and stored on your device and is not transmitted to us, except where this policy explicitly says otherwise:

DataWhyWhere it lives
Profile & setup (name, accent colour, age, gender, height, weight, goals, experience, training setup, food preferences, sports and schedules) To build and personalise your training plan and nutrition targets On device. The parts your coach needs to answer about your own programme are included in what is sent when you use an AI feature (see section 5)
Health & safety details you choose to enter (food allergies and supplements to avoid, injuries, pregnancy/breastfeeding, chronic conditions, medications, and the optional relationship-with-food and readiness questions) To keep your plan and your coach's advice safe for you — for example never proposing a food you're allergic to, and never putting you in a calorie deficit during pregnancy On device. Shared with the AI Coach so its advice is safe (see section 5). Not included in the default iCloud backup (see section 7)
Food logs, training history, weight and progress entries To power your tracker, charts and plan progression On device. A summary of where you are — today's totals and targets, your plan phase and your progress — is included in what is sent when you use an AI feature (see section 5)
In-app workout & body analytics (e.g. session and rest data, body-metric and sleep samples) To improve plan personalisation; you can opt out in the App On device (Apple SwiftData store), and backed up to your own private iCloud so it survives a new phone — you can turn that off in the App
Chat messages, food descriptions and food photos you send to the AI Coach To generate coaching answers, meal plans and calorie/macro analysis Sent to our AI processors (section 5); see retention in section 9
Apple subscription transaction identifier & anonymised usage/cost figures To verify your subscription and meter AI usage fairly On our Cloudflare Worker (section 6)

4. Apple Health (HealthKit)

With your permission, Strathlon reads data from Apple Health to personalise your plan and nutrition targets and to auto-fill your stats. Access is permission-based: Strathlon reads the figures you permit and writes nothing back from your iPhone; if you use Strathlon on an Apple Watch, the watch app saves the workouts it records to Apple Health — that is the only thing Strathlon writes. By default, Health data stays on your device and is not transmitted off it — the exceptions are the opt-in AI coaching described below, and the two separate cycle opt-ins in section 4A. The list below is a list of reads only — it sets out what the App asks permission to read from Apple Health, and nothing in it describes anything written back. Specifically, the App requests read access to:

Health data is never sold and never used for advertising. In line with Apple's requirements, data obtained through HealthKit is used only to provide and personalise the App's features on your device. It is not shared with third parties for advertising or marketing, and is not disclosed to data brokers.

Optional: sharing Health data with the AI Coach. By default, your Apple Health data is not sent to our AI provider. If you turn on "Share Health data with AI coaching" (off by default; offered once during onboarding and available any time in Settings → Privacy & your data), certain Health-derived figures — body weight, BMI/body-fat, calories burned, resting and active heart rate, heart-rate variability (HRV) and heart-rate recovery, respiratory rate, blood oxygen (SpO2), overnight wrist temperature, cardio-fitness (VO₂ max), recent workouts, your sleep in detail (including the deep/REM/core/awake breakdown, sleep efficiency and bed/wake times) and sleep-debt, and a derived "readiness" summary — may be sent to our AI provider (section 5) solely to generate your coaching and the AI Health Analyst's answers, and only when a feature you use needs them. If you have told the App you are on hormone therapy (an optional question — see below), that status is also covered by this same switch and is shared only when it is on, so the coach reasons from your actual logged data rather than a sex-typical baseline. This is never sold and never used for advertising, and you can turn it off at any time. Your reproductive/cycle information has its own separate controls and is not governed by this switch — see section 4A.

This same opt-in powers the AI Health Analyst, which lets you ask the coach plain-English questions about your Health data — for example your sleep, resting heart rate or recovery — and shows a "readiness" summary. No new data is shared beyond the figures listed above, and none of your cycle dates, flow, symptoms or history are ever included (see section 4A).

Biological sex and hormone therapy. Strathlon asks for your biological sex as a required setup field. It is a calculation input, not a label: the metabolic-rate equations the App uses were derived separately for male and female bodies, and the App's minimum daily calorie floor is keyed to it. Like your age and height, it forms part of your basic profile and is included in the standard iCloud backup and in the context sent to the AI Coach, because the calorie model cannot be applied or explained without it. Strathlon separately asks an optional question about hormone therapy (testosterone, estrogen, or none / prefer not to say), asked of every user. Its only purpose is accuracy: where no measured body-fat percentage or lean mass is available, it adjusts the App's estimate of your body composition, which changes your calorie targets. It is treated as special-category health data: it is stored on your device, excluded from the iCloud backup unless you switch on the separate, off-by-default "Back up health & safety details", and shared with the AI Coach only under the "Share Health data with AI coaching" switch above. Setting it back to None in Profile & Settings → Body & stats deletes it everywhere the App holds it. It is never used for advertising, profiling or sale.

You can grant or revoke Health access at any time in iPhone Settings → Privacy & Security → Health → Strathlon. Declining only means you'll enter some values manually.

4A. Cycle data — what stays, and the two things that can leave

If you log your period in Apple Health, Strathlon can read it to add gentle, optional cycle-aware guidance. Cycle data is special-category data, so it is handled separately from everything in section 4, under its own off-by-default switches in Profile & Settings → Cycle-aware insights. It is not governed by the "Share Health data with AI coaching" switch. So that you can see exactly where the line falls:

Cycle dataDoes it leave your phone?
Your dates, flow, symptoms, cycle length and period history No. They are not sent to our AI provider, not included in any analytics, and not included in any iCloud backup
Your own export of your own data (Profile & Settings → Export my data) Yes, and deliberately. The export is a complete copy of your data, made by you, for you — so it includes your cycle dates and phases alongside everything else. The file is written on your phone and goes nowhere until you choose where to send it. If you would rather it did not include cycle data, turn cycle tracking off before exporting
Cycle-aware training guidance (the "train by feel today" suggestion on your Plan) No. It is worked out and shown on your device, and it does not change your programmed sets, reps or weights
A general phase word (for example "pre-menstrual") Only if you switch on "Share my cycle phase with the AI coach" (off by default). It is a single general word — never a date, a flow level, a symptom or your history
Your calorie target for the day, and a note saying it was deliberately adjusted Only if you switch on "Ease my targets in my pre-period week" (off by default). Your coach then sees the adjusted number like any other target, plus a note that it was deliberately adjusted — but not that your cycle is the reason, unless you have also switched on the phase share above. That note is deliberate: without it, the coach would read a higher target as a mistake or as overeating and correct you

Both switches are off by default and either can be turned off at any time.

5. AI processing (Anthropic & Cloudflare)

The AI Coach features — chat answers, AI meal plans, "describe-to-log", and photo calorie/macro analysis — are powered by a large language model. When you use these features, the App sends the relevant content to a Cloudflare Worker that we operate, which forwards it to Anthropic's Claude models to generate the response. What is sent depends on the feature and may include:

Health & safety details are always shared with the AI Coach. So that its advice is safe for you, the health & safety details you enter in the App are included with every AI Coach message: food allergies and supplements to avoid, whether you are pregnant or breastfeeding, any chronic conditions and medications you have entered, and any injuries. If you completed the optional relationship-with-food or fitness-readiness questions and something was flagged, the coach is told that a flag was raised — never your individual answers — so that it keeps its guidance gentle and conservative. Your dietary and religious food preferences (for example halal, kosher, vegetarian or vegan) are included for the same reason.

This is not controlled by the "Share Health data with AI coaching" switch, which governs Apple Health measurements only — the figures listed in section 4. We have deliberately chosen to share these details rather than withhold them: a coach that does not know about a nut allergy, a pregnancy or a heart medication can give advice that is unsafe. You can review the full list in the App at Profile & Settings → App settings → Privacy & your data → "What your AI coach can see", and you can change or remove any of these details at any time in your profile.

These details are sent to generate that answer only. They are never sold, never used for advertising and are not used to train AI models. To keep follow-up questions fast, our AI provider briefly caches the background context we send (a few minutes); beyond that, our processors apply only their own limited operational retention as described in section 9. We keep no long-term store of your messages. Your cycle dates, flow, symptoms and history are never included. The only cycle-derived things that can ever be included are the two named in section 4A, and only under their own off-by-default switches.

We use the following processors for this feature:

These providers process your content to deliver the feature you requested. Your AI requests are not used to train models under our API arrangement, and we do not attach your name or contact details to them.

Spoken coaching (optional, your own OpenAI key)

Strathlon can speak a set of short coaching cues out loud during a workout — "Paused.", "Resuming.", "All sets done.", and so on. Generating that audio is off unless you supply your own OpenAI API key and start the one-time download; there is no Strathlon-provided key for it, so if you never enter one, nothing is ever sent to OpenAI.

What is sent is our own fixed list of coaching phrases — the same list for every user, compiled into the app — together with your API key as the credential. Nothing about you goes with it: no name, no weight, no training, no food, no health data, and nothing you have typed. The audio is then stored on your device, so playing it during a workout makes no further request.

6. Subscriptions (Apple)

Strathlon's premium AI features require an auto-renewing subscription, purchased through Apple's App Store using Apple's StoreKit. Apple processes the payment — we never see or store your card or payment details.

To confirm you're entitled to the AI features, the App sends the Apple-signed subscription transaction (a cryptographic token) to our Cloudflare Worker, which verifies it directly with Apple's App Store Server API. The Worker keeps a record keyed to the anonymous Apple original transaction identifier in order to apply daily fair-use limits and to log anonymised AI usage and cost (token counts and estimated cost). This identifier is not your name, email or Apple ID, and is not combined with any directly identifying information by us.

7. Where your data is stored

The large majority of your data — profile, food and training logs, progress, and in-app analytics — is stored on your device and is included in your normal device and iCloud device backups (which are controlled by Apple, not us). The only data on our servers is the subscription/usage record described in section 6, plus the transient AI request content described in section 5.

Strathlon's own iCloud backup (your private iCloud, never our servers).

Separately from Apple's device backup, the App can copy some of your data to your own private iCloud account so it is restored if you reinstall or change phone. The backup itself never goes to a Strathlon server and the AI Coach is never given access to it (some of the same information may separately be sent to the coach from your device — see sections 4 and 5). It is split across several switches in Profile & Settings → App settings → Privacy & your data:

SwitchDefaultWhat it covers
iCloud backup On Basic details (name, age, sex, height), weight, daily totals, goals, training setup, plan progress, your saved foods, auto-add rules, saved meal plans, schedule changes and holiday breaks, and your food preferences — including any dietary or religious food preference you have set, such as halal, kosher, vegetarian or vegan
Back up health & safety details Off Allergies and supplements to avoid, injuries, body composition and fitness figures (resting heart rate, VO2 max), pregnancy/breastfeeding, chronic conditions and medications, and your answers to the optional relationship-with-food and readiness questions. While this is off, none of these — including your allergies — are copied to iCloud, and you will be asked to re-enter them after a reinstall
Sync progress photos to iCloud Off Your progress photos
Back up training data to iCloud On Weigh-ins and lifting history

Your reproductive/cycle data is never included in any of these. You can turn any switch off at any time; turning one off also removes that data from your iCloud backup.

8. No advertising, no third-party trackers

Strathlon contains no advertising and no third-party advertising or analytics SDKs (for example, no Facebook SDK, Google Analytics, or similar). We do not track you across apps or websites, and we do not sell or share your personal data for advertising.

9. Retention

On-device data remains until you delete it, reset the App, or delete the App. The AI request content sent to our processors is used to generate your response and is subject to those providers' own limited operational retention (for example, short-term abuse-prevention retention); we do not maintain our own long-term store of your messages or photos. The anonymised subscription/usage records are retained for fair-use enforcement, accounting and fraud prevention.

10. Legal basis (UK GDPR)

For users in the UK and EEA, we rely on the following legal bases under the UK GDPR / GDPR:

11. Your rights

Because Strathlon doesn't require an account, most of your data is in your own hands: you can view, edit, or delete it directly in the App, and deleting the App removes the on-device data. Where we hold data (the anonymised subscription/usage record), you have the right to request access, correction, or deletion, and to object to or restrict processing. Note that we may be unable to link a request to a specific record without the relevant Apple transaction identifier. To exercise your rights, contact support@strathlon.com. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) or your local supervisory authority.

12. Children

Strathlon has a minimum age of 16, and we recommend it for ages 18 and over. Onboarding blocks anyone who indicates they are under 16, and for users aged 16 or 17 the App never sets a weight-loss target or calorie deficit — it keeps their calories at a healthy maintenance level. We do not knowingly collect data from anyone under 16. If you believe someone under 16 has used the App, please contact us so we can help.

13. Camera & photos

Strathlon requests access to your camera and photo library only so you can take or choose a food photo to analyse. A photo you select for analysis is sent to our AI processors (section 5) to estimate calories and macros. We do not access your photo library for any other purpose.

14. Email addresses you give us

There are two, and only two, places where you can choose to give us an email address. They are stored separately, in different records, and are used for different things.

14.1 Launch notification list (website)

If you register your interest on our website ("register your interest" / "Notify me"), we store: your email address, the time you signed up, which page you signed up on, and the exact consent text you agreed to. We use this for a single purpose: to send you one email announcing Strathlon's launch on the App Store. It is never shared with anyone else and never used for any other marketing.

The lawful basis is your consent, which you can withdraw at any time. The list is deleted no later than 60 days after the App Store launch. To be removed sooner, use the unsubscribe link in any email we send, or contact support@strathlon.com.

14.2 Feature requests and bug reports (in the App, or on our website form)

When you send us a feature request or bug report, the email field is optional — you can submit without it. If you do give one, it is stored with that submission, alongside the request itself: what you wrote (its type, title and description), the time you sent it, and whether it came from the App or the website form. Submissions from the App also carry a short technical note — the App version and build, your iOS version and your device model — and a random per-install identifier generated on your device, used only to rate-limit and de-duplicate submissions. That identifier is not your name, your email or your Apple ID, and there is no account for it to be attached to.

We use the email address for one thing: to reply to you about that request. It is not added to the launch list in 14.1, not used for marketing, and not shown publicly. Our public roadmap lists only items we choose to publish, and shows only a title and a short summary for each; it does not show your email address or any other contact detail.

The lawful basis is our legitimate interest in receiving, triaging and responding to product feedback. Unlike the launch list, feature requests have no automatic deletion schedule: we keep them while the request is still relevant to the product, so we can see what was asked for and why. To have your submission or your email address removed from it, contact support@strathlon.com.

15. Website cookies and visit measurement

Our website sets one cookie, and only if you vote on the public roadmap. It is described immediately below. Nothing else on the site sets a cookie, and the App sets none at all. We use no advertising cookies, no third-party analytics cookies, and no cross-site tracking of any kind.

The roadmap voting cookie (st_voter). The first time you vote on a feature request, we set a first-party cookie so that the next vote you cast is recognised as coming from the same browser. It contains a randomly generated identifier and a signature proving we issued it — nothing else. It is not derived from your name, your email, your IP address or anything you have told us, and it is not linked to any Strathlon account. Its only purpose is to keep voting fair: one browser, one vote per item, without making you create an account.

It lasts one year, is marked HttpOnly so scripts on the page cannot read it, Secure so it is only ever sent over HTTPS, and SameSite=Lax so it is not sent from other websites. It is set only on strathlon.com. Because it identifies a browser rather than a person, we cannot use it to work out who you are. If you never vote, it is never set; clearing your browser's cookies removes it, and your existing votes stay counted but your browser will be treated as new if you vote again. Our lawful basis is our legitimate interest in preventing repeat voting from distorting the roadmap.

Visit measurement, which uses no cookies. On our website only — not in the App — we count arrivals so we can tell whether people are finding our guides. This uses no cookies, no third-party analytics service, and nothing that can identify you. When a page loads, we record the page you arrived on, the time, the hostname of the site that linked you (for example "google.com" or "chatgpt.com"), and the country your request reached us from.

We deliberately do not store your IP address, any identifier, your browser's user-agent string, or the address of the referring page — only its bare hostname, because a full referring address can contain search terms and other personal details. We only record the page you arrive on, not where you go next, so there is no browsing trail to reconstruct. The data is processed by Cloudflare on our behalf and never leaves it. Our lawful basis is our legitimate interest in understanding how our website is found; because nothing identifies you, there is nothing for us to link back to a person.

16. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by the "Last updated" date above and, where appropriate, highlighted in the App.

17. Contact

Questions about this policy or your data? Email support@strathlon.com.

Terms of Use · Support · Home