Privacy

Last updated 15 September 2026

https://gethector.app/privacy

Hector is a daily lift log and a weekly training planner. Apple Health is the record.

We don’t put your name or email in the product database. Identity is the Firebase Auth UID. Sign-in identity stays with Apple, Google, or Microsoft.

The product database holds only Auth UID, workout sessions, workout sets, subscription entitlements, your Eat Now nutrition profile, your training profile (including your screening answers), and the weekly plans we generate for you.

Weight, height, and date of birth stay in Apple Health on the device. They are never copied to our servers. Age is shown from that date of birth only.

Training plans and screening

To build a weekly plan we store a training profile: the kinds of training you want to do, how many days a week you want to train and how long a session should be, your experience level, the equipment you have, the classes you attend and how often, any movements you have asked us to avoid, and the date and version of the terms you accepted, plus whether you confirmed you are 18 or older.

Before your first plan we ask seven yes/no screening questions about your health. Those answers are health information. They are stored with the rest of your training profile in our product database under your Firebase Auth UID, and they are used for one thing: capping how hard a plan is allowed to be. They are never used for advertising or analytics, they are never sold. The answers themselves are never sent to any AI service; the exercise-selection request carries only a yes/no flag saying the plan is capped, which those answers set. Deleting your account removes them.

Apple Health

On your device the app reads steps, active energy, workouts, weight, height, and date of birth from Apple Health to show your day and your progress calendar (up to a year of workout days). None of that is sent anywhere; only the workout summaries described next leave the device.

When we build a plan we read the workouts Apple Health recorded in the seven days before that week, and send their date, kind, and length to our planning service so the week accounts for what you already did.

We write workouts back to Apple Health for the sessions you log or finish in the app: strength, HIIT, cycling, running, rowing, and walking. We do not write weight, height, or date of birth back, and those three never leave your device.

Location

Eat Now’s nearby-restaurant search uses your location on the device, through Apple Maps, only while you use that screen. Eat Now does not store or send your location.

Separately, each plan request includes your device’s time zone so the week starts on the right day; it is not stored with the plan.

Analytics

To see where people get stuck between signing in and subscribing, the app sends a small fixed set of usage events to Google Analytics: sign-in completed, Apple Health permission granted or denied, trial started, session logged or discarded, paywall viewed, subscription started or completed (with the plan name, monthly or annual), and account frozen. Nothing else is sent. There are no screen-by-screen or tap-by-tap events.

Each event carries a random identifier the app makes up once per install, plus your Firebase Auth UID so the events for one account line up. It never carries your name, email, weight, height, date of birth, screening answers, location, or anything else from Apple Health. We do not use the advertising identifier, and we ask Google not to personalize ads from this data.

Google processes this data for us and keeps it for two months, after which it is deleted. Deleting your account does not pull back events already sent; they expire on that same two-month schedule. The random install identifier goes away when the app is removed.

AI-assisted exercise selection

A rules engine we wrote decides how much you do — the sessions in your week, how long each one is, and its sets, reps, and effort — from published physical activity guidelines. Anthropic’s Claude API then picks which exercises from our own catalog fill the slots the rules engine already created. It cannot add, remove, or change a session, and it can only choose exercises we offered it.

What we send with that request: the training goals you chose (for example, add muscle or increase cardio), your experience level, the shape of each session the rules engine has already fixed, the candidate exercises from our catalog for each block (their ids, names, muscle groups, and tags) and the ids of exercises already placed that day, which kinds of classes you attend and how often, the exercise ids you were given recently, the Monday date of the week being planned, and a single yes/no flag saying whether the plan is capped.

The reply contains the chosen exercise ids and one short sentence per session explaining the session, which the app shows you as written.

What we never send: your screening answers, the movements you asked us to avoid, your equipment, your name, your email, or your Auth UID.

We keep the request and the reply in our own logs for 90 days so we can review what was chosen, then they are deleted. The request and reply are stored under a random request id rather than your account id. A separate operational log line records which request id belonged to your account, so we can join the two if we need to investigate a plan you report.

Deleting your account

Settings → Delete account removes your sign-in (if that step fails because you signed in long ago, the app asks you to sign in again and choose Delete account once more), your workout sessions and sets, your training profile and screening answers, your nutrition profile, and your weekly plans from our systems, and clears the same records from the app on your device. It cannot be undone.

Workouts already written to Apple Health stay in Apple Health. Delete them in the Health app if you want them gone.

Hector is not a medical device and makes no health claims.

Support: support@gethector.app. That is also the in-app Feedback button.