Metal Strength ← Back to the app
Legal

Privacy Policy

Last updated: October 8, 2026

The short version: You can browse the exercise library, the training programs and the calculators without an account and without giving us anything. If you create an account, we store your email and the training, body and photo data you choose to save, so we can show you your own history. Progress photos are private to you. Premium is billed by PayPal on the website and by Google Play or Apple in the apps β€” we never see your card details. The website shows ads (Google AdSense) and uses cookies for sign-in, security, analytics and advertising; the apps carry no ads and no analytics trackers. We never sell your personal data, and you can delete your account and everything in it at any time. How we handle health data in particular is also set out, on its own, in our Consumer Health Data Privacy Policy.

1. Who we are

This Privacy Policy explains how Metal Strength ("we", "us", the "Service") handles personal data on the website at metalstrength.fit and in the Metal Strength apps for Android and iOS. Metal Strength is operated by an independent developer based in France, acting as the data controller for the purposes of the EU General Data Protection Regulation (GDPR). You can reach us at [email protected].

2. Information we collect

a. Account information

Creating an account is optional. If you sign up with email and password, we store your email address and authentication details. If you sign in with Google, we receive your name and email address from your Google account. If you sign in with Apple (in the iOS app), we receive the name and email address Apple shares β€” which may be a private relay address if you choose to hide your email. Accounts and sign-in are handled for us by Supabase (see section 8).

b. Profile and body data

So the app can pre-fill your workouts and calculators and adapt what it suggests, we store the profile you set up: sex, bodyweight, height, age, unit preference (kg / lb), and β€” if you answer the optional onboarding questions β€” your training goals, chosen sports, training experience level and where you train (gym or home).

Body measurements, the weigh-ins you log, body-fat estimates, workouts and progress photos can reveal information about your health, so we treat them as health data under Article 9 of the GDPR and store them only with your explicit consent, which you give with a tick box when you sign up (see section 9). For people in Washington, Nevada, Connecticut and other US states with consumer-health-data laws, the same data is "consumer health data"; our Consumer Health Data Privacy Policy sets out what we collect, why, who receives it and how to use your rights. We also store the date you gave that consent and confirmed you are 18 or older, so we can show that it was given.

c. Training data you save

When you are signed in and choose to save something, we store what you entered so we can build your history, charts and badges. This can include:

d. Friends

If you use Friends, we store a friend code generated for your account, an optional display name you choose (up to 24 characters), the connections you make β€” who asked whom, whether the request is pending or accepted, and when β€” and your sharing settings: whether you share your training at all, and which of the four results listed in section 3 you show. While sharing is on we also store your friend card: those results, worked out by your own app from your own history so that a friend's device never needs anything else. The card holds results only β€” never the weights, body measurements, sex, age or dates they were worked out from β€” and it is deleted when you switch sharing off. Your friend code cannot be used to look up your email address or your real name, and you are not searchable: another person can only reach you if you give them the code yourself. What a friend can and cannot see is set out in section 3.

e. Health-calculator saves

The inputs and results you choose to save from the macro and body-fat calculators β€” for example height, weight, age, activity level, calorie and macronutrient targets, and body-fat estimates.

f. Progress photos

If you use the progress-photo strip in Stats, the pictures you upload are stored in a private storage bucket, in a folder that only your account can read or write, together with the date you attach to each one. They are shown back to you through short-lived signed links. They are never public, never shared with other users, and never used for anything else. On mobile, adding a photo asks for camera or photo-library permission; you can decline and the rest of the app keeps working.

g. Record submissions

If you submit a lift for the community record board, we receive the video of the lift, the photo or video of the weight, the lift details and the contact details you enter. The files go to a private bucket that is not web-readable and are reviewed by us. If a record is accepted, only the record details you provided (such as the lift, the load and the name you chose) are published β€” never your raw files or your email.

h. Messages you send us

If you use the contact or "notify me" form, we collect the name, email address and message you submit so we can reply and (for the launch list) email you. These messages are delivered to us by email through Resend. The launch list is used only for what the form says β€” telling you when the app is out and about major updates β€” and we keep the date you joined as the record of your consent. Every email to it says who we are and lets you unsubscribe by replying "unsubscribe"; we then remove you within 10 days.

i. Technical & usage data

Like virtually all websites, our hosting and security providers automatically process limited technical data needed to deliver and protect the Service β€” for example your IP address, browser and device type, and request logs. Our bot-protection widget (Cloudflare Turnstile) also processes your IP and a token to tell humans from bots. We use this for security, abuse prevention, and to keep the Service running.

Your training, body and photo data is information you knowingly enter and it is tied to your account. We use it to show you your own history, charts and progress, and we never sell it. The one case where any of it reaches another person is Friends β€” which is off until you switch it on, covers training only, and is described in section 3. You can delete any entry, any photo, or your whole account, at any time.

3. Sharing with other users (Friends)

Friends is the only feature that shows any of your data to another person. It is off by default: creating an account does not switch it on, adding somebody does not switch it on, and being added by somebody does not switch it on. Nothing is shared until you turn on "Show my training to friends" yourself.

Connecting to someone takes two deliberate steps by two different people:

What an accepted friend can see, and only while your sharing switch is on:

…and, of the four results below, only the ones you leave switched on:

You choose these in Friends (the gear beside the sharing switch) or in Settings → What friends see. All four start switched on once you turn sharing on, and each can be switched off on its own at any time.

What a friend can never see, whatever your settings:

This is enforced in our database, not merely in the app: the queries a friend's device is allowed to run can only return the results listed above, never dates, loads or body measurements, and they leave out every result you have switched off, so none of it can be requested even by a modified client. Turning the switch off, or removing the friend, stops the sharing immediately β€” either side can remove a connection at any time, without the other's agreement. Removing a friend deletes the connection record itself.

Sharing your training is entirely optional and the Service works fully without it. Because it is a choice you make about your own data, we rely on your consent for it (see section 9), and you can withdraw that consent at any time with the same switch.

4. What stays on your device

A lot of the app runs entirely in your browser or on your phone and never reaches our database:

5. Cookies & similar technologies

We use cookies and similar browser storage for a few distinct purposes:

Where the law requires it (for visitors in the EEA, UK and similar regions), non-essential cookies β€” including personalised advertising β€” are only used after you give consent through our cookie/consent message. You can change or withdraw your choice at any time, and you can also block or delete cookies in your browser settings. Full detail is in the Cookie Policy.

6. Advertising

The free tier of the website is supported by advertising, and a Premium subscription removes it. The Android and iOS apps show no ads at all, to free and Premium accounts alike.

One promise applies everywhere, and it does not change: your training data, your body measurements, your progress photos and your saved plans are never shared with any advertiser and never used to target ads. Advertisers receive no information about what you lift, what you weigh, or what you look like.

a. On the website

We use Google AdSense, a third-party advertising service provided by Google. As a result:

b. In the Android and iOS apps

The apps contain no advertising and no advertising SDK. They do not read, store or share your device's mobile advertising identifier (the Android Advertising ID or, on iOS, the Identifier for Advertisers), and they never show an App Tracking Transparency prompt, because there is nothing to track. If this ever changes, we will update this policy and ask for any consent the law requires before an ad is shown.

For more on how Google uses data when you use our website, see How Google uses information from sites or apps that use its services and the Google Privacy Policy.

7. Payments & subscriptions

Where you buy Premium determines who processes the payment:

In every case we never receive your full card or bank details. We store only what is needed to run your subscription: the biller, the subscription or transaction identifier, the plan, its status and its renewal dates, linked to your account. We keep transaction records for as long as accounting and tax law requires.

To meet consumer law we also keep three small records about your subscription: that you asked, at the website checkout, for Premium to start immediately (with the date); each renewal reminder we emailed you (date and renewal date); and, if you withdraw within 14 days, the withdrawal β€” your name and email as you confirmed them, the contract, when we received it, the amount refunded and the refund reference. We use your email address to send the confirmation of your subscription, the reminders and the acknowledgement of a withdrawal; these are part of your contract, not marketing.

8. Services we use (data processors)

We rely on a small number of trusted third parties to run the Service. Each processes data only as needed to provide their function and under their own privacy policy:

We do not sell your personal data. Our typefaces are self-hosted, so loading a page does not send your IP address to a font provider.

9. Legal bases for processing (GDPR)

10. How long we keep your data

11. Your rights

Under the GDPR you have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to withdraw consent at any time. If you live in France, you can also leave instructions about what should happen to your data after your death. You also have the right to lodge a complaint with your data protection authority β€” in France, the CNIL.

Getting a copy of your data

You do not have to ask us. Open Dashboard → Settings → Your data and choose Download my data. You get a single archive β€” downloaded straight to your device, or emailed to the address on your account β€” containing a complete .json file of every record we hold for you, the same training as .csv spreadsheets, and your progress photos. The .csv uses a column layout other fitness apps can import, so you can take your training elsewhere. One emailed copy per day; we keep no copy of the archive after sending it.

The export covers all of your data, whatever your plan β€” including anything older than the 90 days a free account sees in the app. If you have more photos than fit in one archive, the email says how many were left out; write to us and we will send the rest. For anything else β€” correction, restriction, objection, withdrawing consent β€” write to [email protected]. We answer within one month.

Bringing data in from another app

Settings → Your data → Import from another app reads an export file you have already downloaded from another fitness app and turns it into workouts in your history. We never connect to another service on your behalf and never ask for your credentials there β€” you choose a file, your device reads it, and you see exactly what would be added before anything is written. We do not keep the file.

12. Deleting your data

You can delete individual items β€” a saved workout, a session, a lift, a progress photo β€” from your dashboard at any time. To delete your entire account and all associated data, open Dashboard → Settings → Delete account (available on both the website and the apps). Deletion is immediate and irreversible. If you prefer, email [email protected] from your account address and we will remove it for you. Full instructions, including what is deleted and what we must keep, are on the account deletion page.

13. International data transfers

Some of our providers (such as Google, Apple, Cloudflare, Supabase, RevenueCat, Microsoft and Resend) may process data on servers outside the European Economic Area. Where that happens, the transfer is covered by an appropriate safeguard under Chapter V of the GDPR: the EU–US Data Privacy Framework where the US provider is certified under it, and in every case the European Commission's Standard Contractual Clauses in that provider's data processing agreement. The same safeguards cover transfers from the UK (the UK Extension to the Data Privacy Framework and the UK Addendum to the Standard Contractual Clauses) and from Switzerland. We have assessed these transfers, taking into account the kind of data and the provider's technical measures (encryption in transit and at rest). You can ask us for a copy of the safeguards at [email protected].

14. Minors

Metal Strength is for adults (18 and over) and is not directed to children or teenagers. Sign-up asks for your age and does not accept an age under 18, and every account confirms it is 18 or older. We do not knowingly collect personal data from anyone under 18. If an account's saved age is under 18, the app blocks it until the age is corrected or the account is deleted.

If you believe someone under 18 has given us personal data, email [email protected] and we will delete the account and its data. The apps show no ads.

15. Mobile applications

The Metal Strength apps for Android and iOS offer the same account and the same features as the website, and this policy covers them. When you sign in, the data described in section 2 is stored in our database and storage (Supabase) so your history is available across your devices β€” and exactly as on the website, calculator inputs are only sent to us when you choose to save them.

The apps support native Google sign-in (and Sign in with Apple on iOS), and Premium is purchased through the platform store as described in section 7. The apps show no advertising, do not use your device's advertising identifier (section 6) and contain no analytics trackers. Device permissions are requested only when a feature needs them β€” camera and photo access for progress photos, record submissions and scanning a friend's QR code, notifications for the rest timer, and access to Health Connect or Apple Health (below) β€” and can be refused. Apple and Google may independently collect technical information through the App Store and Google Play under their own privacy policies.

Apple Health and Health Connect. If you allow it, the apps write each workout you finish to your phone's own health store β€” Health Connect on Android, Apple Health on iOS β€” so it counts towards your activity there. What is written is limited to the workout itself: its type, start and end time, title, and the active calories the app estimates for it. Sets, reps, weights, exercises and notes are not written.

If you also allow it, from the "Calories today" card on the Home screen, the apps read three of today's totals from the health store: your steps, your active calories and your total calories burned (on iOS: steps, active energy and resting energy). They are used only to show today's calories on the Home screen, are read again each time that screen is shown, and are held in the app's memory on your phone: they are never uploaded to our servers or stored, and never shared with third parties, sold, or used for advertising. Nothing from before today is read, nothing is read in the background, and no individual health record is read β€” only the day's totals.

Two more things can be read, and unlike the day's totals they are kept, so each has its own switch in Settings → Phone health app, off until you turn it on:

Nothing read from the health store is shared with third parties, sold, or used for advertising. You can turn any of these permissions off, and delete what was written, at any time in Health Connect or the Health app, and turn the switches off in the app.

Developer API. Premium members can create personal access tokens to read their own data through our API (metalstrength.fit/developers). Whoever holds a token can read that account's workouts and body data, so keep tokens private. We store only a one-way hash of each token, its name, and when it was created, last used and revoked. You can revoke a token at any time in the app.

16. Your rights in the United States

This section applies to residents of US states with a consumer privacy law (including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Hampshire, New Jersey, Nebraska, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island). We give the rights below to every US user, whether or not a law requires us to. Consumer health data β€” which covers most of what the app stores β€” also has its own Consumer Health Data Privacy Policy (Washington, Nevada, Connecticut and similar laws).

What we collect, and why (notice at collection)

We do not collect precise geolocation. We keep each category for the period set out in section 10. The sources are you, your device, and β€” if you sign in with them β€” Google or Apple.

We do not sell your data. Website ads may count as "sharing"

We do not sell personal information for money, and we never sell or share your health, training, body or photo data with anyone. The one thing some state laws may treat as a "sale", "sharing" or "targeted advertising" is the website's Google AdSense ads, which can use cookies to personalise ads (section 6). The apps show no ads at all. You can opt out of it on our Do Not Sell or Share My Personal Information page. We also honour the Global Privacy Control (GPC) signal: a browser that sends it is treated as opted out automatically, with nothing else to do. We do not use your personal information for profiling that produces legal or similarly significant effects, and we do not knowingly sell or share the personal information of anyone under 18 (the Service is for adults only). We do not disclose personal information to third parties for their own direct marketing (California Civil Code Β§1798.83).

Your rights

How to make a request. Use the tools in the app, or email [email protected] from the address on your account (that is how we verify it is you; if you write from another address we may ask you to confirm from the account address). An authorised agent may make a request for you with your signed permission, and we may ask you to confirm it directly. We answer within 45 days; if we need longer (up to 45 more days) we tell you why.

Appeals. If we decline your request, in whole or in part, you can appeal by replying to our answer with the word "Appeal". We answer an appeal within 45 days (60 days where your state allows it), explaining our decision. If the appeal is denied, you may contact your state Attorney General.

17. No biometric data

We do not collect biometric identifiers or biometric information. Progress photos and record videos are stored as ordinary pictures and videos for you (or, for a submitted record, for our review) to look at: we do not analyse them to detect or recognise a face, measure the body, or build any template of face, hand or body geometry, and no feature of the Service does so on your device either. Scanning a friend's QR code reads the code only. If that ever changes, we will tell you first, publish how long such data is kept, and ask for your written consent before collecting any.

18. Security

We use reputable providers and security measures to protect your information: database row-level security so an account can only ever read its own rows, private storage buckets scoped to your user folder with short-lived signed links for your photos, encrypted connections, and bot protection. No method of transmission or storage is completely secure, but we work to keep your data safe.

19. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected here with a new "Last updated" date above.

20. Contact

Questions about this Privacy Policy or your data? Email [email protected].