LEGAL · PRIVACY
Privacy Policy
How 8-fit handles your account, workouts, gym choices, and optional body information.
Updated September 15, 2026 · Private beta
Overview
This policy explains the information processed by the 8-fit iPhone app, its paired Apple Watch companion, and this website. 8-fit is currently a private, invite-only TestFlight beta.
We do not sell personal information, show targeted advertising, or use workout history to build advertising profiles.
Information we collect
Account and sign-in information
8-fit requires an account. Depending on the method you choose, Supabase Auth processes your email address, a provider account identifier, verification status, and sign-in records. Apple or Google may provide basic identity information authorized by you, such as an account identifier, email address, name, or avatar. 8-fit uses provider information for authentication and account security—not to access unrelated provider services.
For email sign-in, the app sends the password you enter to Supabase Auth over an encrypted connection. Supabase stores a password verifier. Your password is not stored in your player profile or workout records.
Player setup information
We store your optional character name, appearance selections, setup progress, training split, gym layout, and owned cosmetic items. Older accounts may retain a previously selected training-experience description; the current setup does not ask for one.
Workout and progression information
Completed workout records include workout and exercise names, equipment and optional machine brands, planned targets, logged sets, reps, load or bodyweight, timed activity, exercise notes, and dates and times. Some exercises also record assistance, hold duration, or carry distance. We store the workout’s training-split context and, where applicable, separate completion records used to track in-app progress.
When available, completed workouts retain a snapshot of body information used for strength-level calculations. Changing your current profile does not rewrite these historical snapshots. Strength levels are estimates for tracking personal progress.
Optional body information
You can choose to save weight, height, date of birth, and sex. Records can also include where a value came from, measurement dates, and update timestamps. Body information supports strength-level estimates; it is not inferred from your character’s appearance. You can skip this step and still plan and log workouts.
Local and synchronization information
The app keeps a user-specific offline cache on your device. It may include pending changes, synchronization timestamps, remote revisions, and recoverable error information needed to retry safely. Ordinary sign-out locks and hides this user-ID-partitioned cache but retains it for the next successful sign-in.
Unfinished workout details, draft notes, and rest-timer state are saved locally so you can resume. A limited active-workout and device marker synchronizes with your account; this does not transfer every unfinished workout detail between devices.
The app can display current exercise, set, load, timing, and character information in an iPhone Live Activity. The paired Apple Watch companion receives a limited view of workout or character progress. Information displayed on the Lock Screen is subject to your device settings.
A device-only remembered-account shortcut can retain your account identifier, optional email, sign-in method, character name, and appearance after sign-out. It does not contain a password or session tokens and requires a new sign-in. Forget this account removes the shortcut.
Photos you choose
For Social posts and photo avatars, the system photo picker lets you choose images to submit. Images are uploaded when you publish a post or save a photo-avatar change.
Information we intentionally do not request
Account setup does not ask for diagnoses or injury history. The app does not request your device’s address book, advertising identifiers, Google Drive files, or Google Calendar data. Optional access to recorded Apple Health data is described below. Exercise notes and support messages contain whatever you choose to enter, so avoid including information you do not want stored.
Website information
The website serves public information pages and a staff moderation console. Staff sign in through Supabase Auth, and server-side permissions control access to moderation information. We do not set advertising cookies or run product analytics on these pages. Cloudflare processes basic network request information, such as IP address and security-related request metadata, to deliver and protect the site.
Optional Apple Health
You choose whether to use Apple Health and control access through Apple’s permission screens. In the private Health profile, you can select categories such as activity, heart rate, sleep, workouts, body measurements, nutrition, symptoms, cycle records, mood, and medications, where supported. Individual medications use Apple’s separate selection sheet. Opening Show Route separately requests access to a recorded workout route, which can contain precise locations.
Health-profile readings, charts, source information, records, and routes are displayed temporarily on your device. They are not uploaded to your 8-fit account or shared through Social. Category and favorite choices are saved locally for the signed-in account. Selected data can refresh when you open or return to the app, refresh manually, or Health records change while the app is running; the Health profile does not register background delivery.
Body Information has a separate, optional import. Use Apple Health or Refresh from Apple Health requests available weight, height, date of birth, and biological sex and places them in an editable draft. Only values you confirm are saved locally and synchronized to your private account in Supabase, with their source and applicable measurement dates. These confirmed values may also become part of the historical workout snapshots described above. Viewing body measurements in the Health profile does not change your saved Body Information.
You can also choose Track Heart Rate for a workout using a compatible device, or Load Heart Rate to view available readings afterward. Tracking requests permission to read heart rate and workouts and to save a workout in Apple Health. The iPhone or paired Apple Watch records through HealthKit; heart-rate samples and trends are not uploaded to your 8-fit account or included in Social workout snapshots. Apple Health manages its own storage and synchronization.
You can skip these features, turn off Health categories in 8-fit, stop heart-rate tracking, or change permissions in Apple Health. Revoking access prevents future reads of those types; it does not delete Body Information you already confirmed and saved, or records in Apple Health. You can edit current Body Information or delete your 8-fit account as described below. Manage or delete Apple Health records separately in Apple Health.
How we use information
- Authenticate you and protect your account.
- Create and restore your private player profile.
- Save your character, gym layout, training split, and optional body information.
- Synchronize workouts across authenticated devices.
- Rebuild progression and resume incomplete setup.
- Calculate strength-level estimates using workout history and available body information.
- Privately display the Apple Health data you select and support optional workout heart-rate tracking.
- Provide offline operation to a previously authenticated player.
- Detect errors, prevent duplicate workout records, and maintain service security.
- Respond to support, privacy, or account-deletion requests.
Service providers
8-fit uses service providers only for defined parts of the product:
- Supabase provides authentication, the Postgres account database, and protected server functions.
- Apple and Google provide optional sign-in methods. Apple also provides the optional Health permission system and TestFlight distribution. Each provider processes information under its own privacy terms.
- Resend delivers account verification and password-reset email for email/password accounts.
- Cloudflare provides DNS, security, and static website delivery.
When you test through TestFlight, Apple collects and shares beta usage information, crash logs, and feedback with the developer under its TestFlight information and privacy terms. Feedback and screenshots you submit may include personal information you choose to share.
These providers may process information in the countries where they operate. We do not authorize them to use 8-fit account or workout data for our own targeted advertising because 8-fit does not run targeted advertising.
Storage and security
Account-owned records are stored in Supabase and protected with row-level access controls intended to limit each authenticated player to their own data. App sessions are stored using the iOS Keychain. The device cache is partitioned by the Supabase user identifier, and network traffic uses encrypted connections.
These access controls separate players’ accounts. They do not prevent authorized service or database administrators from accessing stored information, including confirmed body information and workout notes. Those fields are not encrypted with a key held only by you.
No online service can promise absolute security. 8-fit limits the information it collects and keeps secret administrative credentials out of the app and public repository.
Your choices
- Edit optional player information and character choices in the app.
- Skip Body Information, enter it manually, or review an optional Apple Health import before saving.
- Choose Health categories for private display, turn them off, or change Apple Health permissions.
- Sign out to lock and hide the active account’s local store while retaining its offline copy for a later successful sign-in.
- Use Apple, Google, or email/password authentication where available.
- Revoke 8-fit access through Apple or Google’s account controls where available.
- Delete your 8-fit account from the authenticated app after a clear deletion confirmation.
Retention and deletion
We retain account, profile, and workout records while your account remains active so that progress can synchronize and be restored. This includes optional body information and historical workout snapshots. Successful in-app account deletion removes the Supabase Auth user and associated account records, then clears the app’s local account data. Limited security logs or provider backups may remain temporarily where required for security, recovery, fraud prevention, or legal compliance.
Unsynchronized information that never reached Supabase exists only in the local app cache. Permanent in-app account deletion or deleting the app removes that device-local cache; ordinary sign-out does not.
Changes and contact
We will update this page and its date when the product’s data practices materially change. Future paid membership, analytics, or additional categories of personal information will require an updated policy before those changes are released.
Send privacy and support requests to drewkloek@gmail.com. During the private beta, you can also use TestFlight feedback or the invitation or testing channel that provided access to 8-fit. See the support page for instructions.
Optional Social
When Social is enabled for your account, adults 18 and older can separately opt in, choose a username and public or private profile, follow others, and publish text, photos, workout summaries, or a snapshot of My Gym. We store the profile fields you submit, connections, selected shared content, likes, comments, notification preferences, and reports needed to operate these features.
Public content is visible to eligible signed-in 8-fit social users. Private profiles require approved followers. A comment shares its parent post’s audience, even if the commenter has a private profile. Review the audience before publishing. Social links open the app; the public app-opening pages do not display the shared post or private profile.
Workout sharing uses a separate snapshot. Set, rep, and weight details are optional. Private notes, body information, scoring context, Apple Health readings, heart rate, and exact private activity times are not automatically included. Gym snapshots include the appearance you publish, not private inventory history or live presence. People can retain screenshots or exported copies after access is revoked.
Supabase stores social records and photos. Automated moderation through Sightengine checks submitted text and images, including text in photos. Authorized reviewers can examine reported or held content and record moderation decisions. Optional push notifications use Firebase Cloud Messaging and Apple Push Notification service; device registration identifiers support delivery, without including private workout metrics in push previews. We do not use these features for targeted advertising.
You can delete posts, remove followers, block or mute people, change visibility, or deactivate Social without deleting your private workout history. Deleted content is hidden immediately while retryable cleanup removes stored copies, including media backups, with a target of 24 hours. Minimal moderation audit records are retained for 90 days; reported evidence is retained only as needed for an active review or appeal within that window. Media recovery copies are kept for seven days unless deleted sooner. Retired usernames remain reserved to reduce impersonation.
Account deletion includes social content and media. Cleanup must finish before account deletion is reported as complete. Operational backups can expire on their backup schedule, and deletion records are applied if a backup is restored. See the community rules and support options.