Last updated July 5, 2026
The short version: your account and fitness profile sync to our servers; your day-to-day logs stay on your device; contacts and location features are optional and engineered so raw contacts and raw location never leave your phone. No ads. No third-party trackers. Your data is never sold.
When you create an account we store your name, email address, and a salted scrypt hash of your password — we cannot see the password itself. Your sign-in session uses a token stored in the iOS Keychain on your device. We also store a one-way SHA-256 hash of your email so friends who already have your address can find you.
Your profile — age, gender, height, weight, activity level, goal, and unit preference — is stored on your device and synced to your account so it follows you to a new phone. It is used to compute calorie and protein targets and to personalize workouts.
Workout sessions, logged sets, food entries, saved ingredients and body-weight entries are stored on your device. If you connect live coaching, your workout summaries and sets are sent to our coaching server and are visible to the coach you chose, along with the messages you exchange.
If you scan a meal with the camera, the photo is sent over an encrypted connection to our nutrition-analysis server, which passes it to our AI provider (Anthropic) to estimate the food and macros. We do not store the photo on our servers, and our provider's commercial API terms do not permit using it to train models. Barcode scans send only the barcode number to the Open Food Facts public database — never a photo. Camera access is used only when you actively scan.
Finding friends from your contacts is optional and off until you turn it on. When you do:
Detecting that you are at a partner gym is optional and uses "While Using the App" location permission. Your location is compared against the partner-gym list on your device to pick the right gym layout. Your location is never transmitted to our servers, never stored, and never accessed in the background.
Partner gyms use equipment sensors and cameras that detect whether a machine is in use. That system counts machine occupancy only — the availability data you see in the app contains no identity, image, or biometric information about anyone.
If you use the OPT(ML) watch app, motion data used for automatic rep counting is processed on your watch and phone. Motion and health data is not sent to our servers.
No advertising, no third-party analytics SDKs in the app, no cross-app tracking, no data brokers, no selling or renting of personal data, ever. The app requests no permission until the feature that needs it is used, and every permission is optional.
Connections to our servers use encryption in transit. Passwords are stored only as salted scrypt hashes. Session tokens live in the iOS Keychain, not in app files. Contact matching and gym detection are designed so the sensitive raw data stays on your device.
Settings → Account → Delete Account inside the app permanently removes your account and all server-side data: profile, friendships, identifier hashes, workouts, coaching history and messages. Deleting the app removes all on-device data. You can also just sign out, which clears the device copy.
optml.app uses self-hosted, first-party interaction analytics (counts and timings only, no typed text) to improve the site, and a booking form if you request a demo. No third-party trackers are used here either.
OPT(ML) is not directed at children under 13, and we do not knowingly collect data from them.
If this policy changes materially we will tell you in the app before the change applies.
Questions or data requests: privacy@optml.app