Privacy Policy
Last updated: 2026-10-04
GainRace ("the app", "we") is a personal performance-tracking tool. This policy explains what data we collect, why, and how to remove it.
1. What we collect
- Account: email address, optional name, optional username (a public handle visible only to people you accept as friends), and a hashed password. If you sign in with Apple or Google, we store the provider's stable subject ID instead of a password.
- Profile: age, biological sex, height, weight, body-fat percentage (if you choose to log it), bedtime hour, and daily targets (protein, water, calories).
- Training and food preferences (optional): your goal (cut, maintain or bulk), where you train, lifting experience, session length, injuries, diet style, allergies, foods you avoid and cooking time. If you choose to answer, also whether you are pregnant or breastfeeding, have or had an eating disorder, or have diabetes or kidney disease. We use these only to tailor your training and meal plans, and a "yes" to any of those health questions turns meal plans off. You can change or clear every answer in Settings.
- Logs you create: hydration entries, caffeine/stimulant entries, food entries (with optional photos), training entries (exercise, sets, reps, weight), body weight history, and notes.
- Device: Expo push notification token (used to send reminders), app version, OS version, timezone.
- AI usage: your Pit Crew chat (kept until you start a new chat or delete your account), the Pit Crew training and meal plans built for you and the changes the chat makes to them, the daily-digest text the model generates for you, and a count of the AI camera scans you use (time and type only, not the photo) to apply your plan's limits.
- Purchases: your plan (Free, Plus or Pro), when it renews or ends, and which avatar packs you bought. We never receive your payment details; Apple handles payment.
We do not collect contacts, location, browsing history, advertising identifiers, or analytics events for behavioural advertising.
2. How we use it
- Compute your daily Form Score and surface it on the dashboard.
- Show your weekly leaderboard rank among friends you have accepted (Σ weight×reps).
- Generate your daily AI digest, build your Pit Crew training and meal plans, and answer and act on your Pit Crew chat messages, using your own recent data as context (30, 90 or 365 days depending on your plan).
- Send push reminders at times you have historically logged (only if you enable predictive nudges in Settings).
- Identify food and macronutrients from photos you upload to the nutrition estimator.
3. Third parties we share data with
We send the minimum data needed to each service to provide functionality. None of these parties use your data for advertising.
- Anthropic (Claude API) — receives your Pit Crew chat messages with your earlier messages in that chat, plus a summary of your profile, training and food preferences (including any health answers), and recent logs (the same summary is sent when a Pit Crew plan is built), and food-photo image bytes for the nutrition estimator, and body photos for the body-fat estimate. Photos are sent for the estimate only and are not stored by us. Anthropic's policy: anthropic.com/legal/privacy.
- RevenueCat — processes App Store purchase receipts for subscriptions and avatar packs, linked to your GainRace user ID (not your name or email). Policy: revenuecat.com/privacy.
- Supabase — managed Postgres host for your account row and all logs. Policy: supabase.com/privacy.
- Render — application hosting for the API server (Frankfurt, EU). Policy: render.com/privacy.
- USDA FoodData Central — receives the food name strings extracted from your photos so we can look up nutrition data. No personal identifiers are sent. Policy: usda.gov/privacy-policy.
- Expo — relays push notifications to Apple Push Notification service. Policy: expo.dev/privacy.
- Apple Push Notification service — delivers push notifications to iOS devices. Subject to Apple's privacy policy.
- Sign in with Apple / Google (if you choose to use them) — receives an authentication request and returns a stable user identifier and (first time only) your email. Subject to Apple's and Google's respective policies.
4. Retention
We keep your data for as long as your account is active. If you delete your account inside the app (Settings → Account → Delete account), all of the data listed in section 1 is removed from our database within 24 hours. Backups expire within 30 days. Anthropic, Supabase, and Render retain their own logs per their own policies — we cannot delete those on your behalf.
5. Your rights
You can:
- View and edit your profile at any time in the app (Settings → Profile & Targets).
- Delete your account permanently from inside the app (Settings → Account → Delete account).
- Request a copy of your data, request correction, or request erasure by emailing support@gainrace.com. We respond within 30 days under GDPR Article 12.
6. Children
The app is not directed to children under 13. We do not knowingly collect data from anyone under 13.
7. Security
Passwords are stored as bcrypt hashes (work factor 12). Data in transit is encrypted via HTTPS. Database access requires TLS. Refresh tokens are stored in iOS Keychain / Android Keystore on your device.
8. Changes
If we materially change this policy we will update the "Last updated" date at the top and, for substantive changes, surface a notice in-app at next sign-in.
9. Contact
Questions or data requests: support@gainrace.com.