Last updated: July 20, 2026
This Privacy Policy describes how ISOBEAST (operated by Team ISOBEAST, "we," "us," or "our") handles your information when you use our mobile applications. By using ISOBEAST, you agree to the practices described below.
1. Data We Collect
We collect the minimum data required to operate the app:
- Email address — required for account creation and authentication. We never use it for marketing without your explicit opt-in.
- Fitness and training data — your logged workouts, sets, force measurements, hold durations, hook positions, routines, and progression targets. This is the core data the app exists to store on your behalf.
- Optional session notes — free-text notes you add to individual workouts. Stored alongside your workout records.
- Optional profile data — if you choose to enter them in the Profile screen: biological sex, birth year, height, and equipment type (ISO-BAR, Isomax, Isochain, or other). None of these fields are required to use the app. They are used solely to provide benchmark comparisons within the app.
- Optional in-app feedback — if you use the feedback feature, your message, feedback category, email address, account ID, app version, and device platform are sent to our support team. Used only to respond to your feedback.
- Crash and performance diagnostics — stack traces and performance metrics sent to Sentry when the app crashes or performs unexpectedly. These reports include your account's internal user ID (a random UUID assigned at account creation — not your email address), device model, OS version, and app version.
We do not collect your name, phone number, location, contacts, photos, or payment information.
2. How We Use It
Your data is used for the following purposes:
- App functionality — syncing your workouts and progression targets across your devices via your private cloud account.
- Account authentication — verifying your identity so only you can access your data.
- App stability — diagnosing crashes and performance issues so we can ship fixes quickly.
- Benchmark context — optional profile data (sex, birth year, height) is used to group your performance against comparable users within the app. It is not shared with third parties.
- Feedback response — when you submit in-app feedback, we use your email and message to respond to you directly.
- Optional Apple Health export — on iPhone, if you enable the integration, ISOBEAST writes the strength-workout category and logged workout time window to your Apple Health store. ISOBEAST does not read data from Apple Health.
We do not use your data for advertising, marketing profiling, or sale to third parties.
3. Sharing & Third-Party Processors
We work with the following processors to run the app. We have executed data processing agreements with each processor consistent with GDPR Article 28.
- Supabase — provides our cloud database and authentication infrastructure. Your fitness data, email, and optional profile data are stored on Supabase servers in the United States. Supabase does not access your data for its own purposes. Supabase Privacy Policy
- Sentry — receives crash and performance diagnostic reports. Reports contain device model, OS version, app version, stack traces, and your account's internal user ID (a random UUID — not your email address). Sentry does not receive your fitness data or optional profile data. Sentry Privacy Policy
- Resend — delivers transactional email on our behalf. When you submit in-app feedback or use the website contact form, Resend receives your email address and message content solely to forward it to our support inbox. Resend does not use this data for its own purposes. Resend Privacy Policy
- Cloudflare — hosts the API worker that processes feedback and contact form submissions. Cloudflare's infrastructure handles the network transit for these requests. IP addresses may be used transiently for rate limiting and are not retained beyond the request window. Cloudflare Privacy Policy
- Expo (EAS Update) — checks for over-the-air app updates each time the app launches. Expo receives your device platform, app version, and runtime version to determine whether an update is available. Expo does not receive your email address, fitness data, or optional profile data. Expo Privacy Policy
For transfers of personal data from the EU/EEA to US-based processors, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission. Each processor's applicable data processing agreement and transfer mechanism are available via the links above.
We do not share your data with data brokers, advertisers, or any other third parties. We have no advertising partners.
Apple Health: Apple Health export is optional and disabled until you choose to connect it. Exported workouts contain only the workout category and timing derived from your ISOBEAST sets; they do not contain force, hook position, heart rate, distance, calories, or session notes. Health data remains under your control in Apple Health and Apple Settings, and no data read from HealthKit is uploaded to ISOBEAST, Supabase, Sentry, or another processor.
4. In-App Purchases & Subscriptions
ISOBEAST offers an optional auto-renewable subscription, ISOBEAST Pro, which unlocks additional features. All payments are processed entirely by Apple through the App Store; we never receive or store your credit card or financial information.
We use RevenueCat to manage subscriptions and validate purchase receipts. RevenueCat receives a random app-specific user identifier and the purchase/receipt details needed to determine your subscription status. It does not receive your email address, payment card details, or fitness data. RevenueCat Privacy Policy
Subscriptions renew automatically at the price shown at purchase until cancelled. You can manage or cancel your subscription at any time in your Apple ID account settings.
5. Analytics & Crash Reporting
ISOBEAST does not currently include product analytics SDKs (such as Mixpanel, Amplitude, or Firebase Analytics). We do not track screen views, button taps, or session durations for behavioral analytics.
Crash diagnostics via Sentry are used solely to maintain app stability. Sentry reports include your account's internal user ID (a random UUID assigned at account creation) to help us correlate crashes across sessions. Your email address is never sent to Sentry.
6. Legal Basis for Processing (EU/EEA)
If you are located in the EU or EEA, the legal basis for processing your personal data under GDPR Article 6 is:
- Contractual necessity (Art. 6(1)(b)) — fitness and training data, email address, and account authentication are required to provide the service you signed up for.
- Legitimate interests (Art. 6(1)(f)) — crash diagnostics via Sentry, to maintain app stability. Our interest in fixing crashes does not override your privacy rights; Sentry data is limited to technical diagnostics and your internal user ID.
- Consent (Art. 6(1)(a)) — optional profile data (sex, birth year, height, equipment), in-app feedback, and Apple Health export. You provide or enable these voluntarily. You can stop future Apple Health exports in Profile and manage Health access and previously exported workouts through Apple Health or Apple Settings.
7. Children's Privacy
ISOBEAST is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, please contact us or email [email protected] and we will delete the account promptly.
8. Your Rights
You have the right to access, correct, export, or delete the personal data we hold about you. EU/EEA residents have additional rights under the GDPR as described below.
- Access: request a copy of the personal data we hold about you.
- Rectification: ask us to correct inaccurate data.
- Data portability (export): receive your data in a machine-readable format.
- Erasure (deletion): request deletion of your account and all associated data. Account deletion removes your profile, all workout history, routines, progression targets, personal records, and optional profile data. This action is permanent and cannot be undone.
- Restriction of processing: ask us to suspend processing of your data while a dispute is resolved.
- Right to object: where we process data based on legitimate interests (e.g., crash diagnostics), you can object and we will assess whether our interests override yours.
- Complaint: EU/EEA residents may lodge a complaint with a data protection supervisory authority in their country of residence.
To exercise any of these rights, submit a request via the contact form including the email address associated with your account. We will respond within one calendar month of receipt. For complex or multiple requests, we may extend this by up to two additional months and will notify you of any extension.
Data retention: fitness logs and optional profile data are kept for the lifetime of your account. Sentry crash data is retained for 90 days per Sentry's standard policy. Feedback messages forwarded via Resend are retained in our support inbox until manually deleted.
Data breach notification: in the event of a personal data breach likely to result in a high risk to your rights, we will notify you by email within 72 hours of becoming aware of the breach.
9. Changes to This Policy
We may update this policy when we add new features or processors that affect data handling. Material changes (for example, adding a new third-party SDK that collects data) will be communicated in the app's release notes and reflected in the "Last updated" date at the top of this page.
Continued use of ISOBEAST after a policy update constitutes your acceptance of the changes.
10. Contact & Data Controller
A Data Protection Officer (DPO) is not currently designated. Under
GDPR Article 37, a DPO is required only where: (a) processing is
carried out by a public authority; (b) core activities consist of
large-scale systematic monitoring of individuals; or (c) core
activities consist of large-scale processing of special category data.
None of these conditions currently apply to ISOBEAST. If the user base
grows to a scale where condition (b) or (c) is triggered, or if
features involving explicit medical data or systematic behavioural
tracking are introduced, this policy will be updated and a DPO
appointed accordingly.
Questions about this policy or your data: