MyTrainerOSMyTrainerOS
Features Pricing Compare
Sign In Start Free Trial
Start Free Trial

Privacy Policy

Last updated: August 17, 2026

Summary of Changes — 17 August 2026

We updated this policy on 17 August 2026 so that it matches what the product actually does. The changes below add detail and correct two statements that were out of date. Nothing here removes a protection you had before.

  • Corrected — where wearable data comes from. We previously said wearable data reached us "via Terra API". It does not. Your phone reads the data from Apple Health or Google Health Connect and syncs it to us, and you may also connect WHOOP or Oura directly.
  • Corrected — what we store. We now say plainly that we store daily summaries of your wearable metrics on our servers. We do not store the raw second-by-second samples from your device.
  • Added — how your gym's payments, fees, member balance, and in-person purchases are handled, and who charges you.
  • Added — what we hold about gym staff (front-desk admins and trainers), including time-clock and pay-rate records.
  • Added — check-in codes, referral links, satisfaction surveys, and multi-factor recovery codes.
  • Added — that your gym may connect its own QuickBooks account, and what that sends.
  • Added — that when a gym changes its subscription plan, data is deactivated, never deleted.

Introduction

MyTrainerOS ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our fitness coaching platform, including our mobile application and website.

Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the application or website.

Information We Collect

Personal Information

We collect information that you provide directly to us when you:

  • Create an account (name, email address, password)
  • Complete your profile (age, gender, fitness goals, measurements)
  • Use our services (workout logs, nutrition entries, progress photos)
  • Communicate with us or your trainer
  • Make payments (processed securely through Stripe)

Health and Fitness Data

With your consent, we collect health and fitness data including:

  • Workout performance (exercises, sets, reps, weight lifted)
  • Nutrition, hydration, and wellness logs (food intake, macronutrients, calories, water, mood, energy, soreness, stress)
  • Body measurements, progress photos, and body-scan results if your gym offers scanning (for example Fit3D)
  • Exercise videos you submit for form review, and your coach's annotations on them
  • Wearable device data — resting heart rate, heart rate variability, sleep duration and stages, steps, and body composition

How Wearable Data Reaches Us, and What We Keep

This is important enough to state plainly.

  • Where it comes from. If you turn on health sync, the MyTrainerOS app reads your metrics on your own device from Apple Health (HealthKit) on iPhone or Google Health Connect on Android. You may also connect WHOOP or Oura directly, which authorizes us to fetch your data from that provider.
  • What we send to our servers. The app then syncs daily summary figures to our database — for example your resting heart rate for the day, your heart rate variability, how long you slept and in which stages, your step count, and body-composition figures if you have enabled that category. These daily summaries are stored on our servers.
  • What we do not send. We do not upload the raw underlying samples — the continuous readings your watch or ring records through the day. Those stay on your device and with the provider you got them from.
  • What we never show. We deliberately do not display calorie-burn estimates from wearables, because research shows consumer devices estimate them unreliably.
  • You choose the categories. Heart rate variability, sleep, steps, and body composition are each independently switchable, and body composition is off unless you turn it on.

Because we store health data on our servers, state consumer health-privacy laws — including the Washington My Health My Data Act — apply to us directly. Our Health Data Privacy Policy describes those obligations in full.

Payment, Fee, and Purchase Data

If you pay a gym or trainer through MyTrainerOS, we process:

  • Payment method details held securely by Stripe when you save a card on file with a gym or trainer — we never store your full card number
  • Appointment purchases, subscription and membership records, and session balances
  • Late-cancellation or no-show fees, where your gym has chosen to charge them, including fees your gym waives
  • In-person purchases of physical goods where your gym uses our point-of-sale features — receipts, items, returns
  • Your member ledger: the running record of what you have been charged, paid, owed, and credited at that gym

Gym Staff Data

If you work for a gym as a trainer or admin assistant, we also hold employment-related records on your employer's behalf: your role and permissions, your classification and pay rate at each facility as set by your employer, your time-clock entries including the location captured when you clock in at a geofenced facility, who recorded each entry, and any certifications you record. See the Staff Terms of Service.

Access, Referral, and Feedback Data

  • Check-in codes. If your gym issues you a kiosk check-in code, we store only a one-way cryptographic hash of it. The code itself cannot be read back or displayed by us or by your gym. Repeated incorrect attempts lock check-in temporarily.
  • Referral links. If you share a referral link, we count views of it, clicks on it, and sign-ups attributed to it, so your gym can credit you.
  • Satisfaction surveys. If your gym sends a one-question satisfaction survey, your score and any comment you add are visible to your gym.
  • Messages. Messages between you and your coach are stored so you both have a record. Your gym, as the coach's employer, can see them. We do not sell them and we do not use them for advertising.
  • Multi-factor recovery codes. If you enable multi-factor authentication, we store your recovery codes only as salted one-way hashes. Each code works once. Turning multi-factor authentication off ends all of your active sessions.

Voice and Photo Data

When you use our AI-powered features, we collect:

  • Voice recordings (temporarily processed for workout and nutrition logging, not permanently stored)
  • Photos of meals (processed for food recognition, stored until you delete them)
  • AI chat conversations with your trainer's AI assistant

Automatically Collected Information

When you use MyTrainerOS, we automatically collect certain information including:

  • Device information (device type, operating system, unique identifiers)
  • Usage data (features accessed, time spent, interactions)
  • Location data (if you grant permission)
  • Log data (IP address, browser type, access times)

How We Use Your Information

We use the information we collect to:

  • Provide Services: Deliver our fitness coaching platform, process transactions, and send service-related communications
  • AI Features: Process voice commands, recognize food in photos, generate personalized coaching responses, and provide proactive interventions at optimal times (JITAI)
  • Personalization: Customize your experience, recommend workouts, and track your progress
  • Trainer-Client Relationships: Enable communication and data sharing between trainers and their clients
  • Improve Platform: Analyze usage patterns, identify bugs, and develop new features. AI models may be trained on anonymized, aggregated data to improve accuracy
  • Safety & Security: Protect against fraud, unauthorized access, and other security threats
  • Legal Compliance: Comply with applicable laws, regulations, and legal processes
  • Marketing: Send promotional emails about MyTrainerOS (you can opt out at any time)

Marketing From Your Gym, and the Line We Do Not Cross

MyTrainerOS gives gyms tools to contact their own members and prospects: email campaigns and newsletters, text messages, and lead-capture forms. Some gyms use all of them, some use none.

  • Your gym is the sender, not us. When you receive a campaign email or a text from your gym, your gym decided to send it, wrote or approved the content, and is responsible for it. We provide the software that delivers it.
  • Text messages require your consent. Your gym must capture your agreement before texting you marketing messages. You can review and change your text-message preferences at any time on the SMS preferences page, and you can reply STOP to opt out.
  • Email always carries an unsubscribe link. Unsubscribing stops marketing email from that gym. It does not stop messages you need — appointment confirmations, receipts, or a reply from your coach.
  • Your gym may draft marketing copy with AI. A person at your gym edits and approves it before it is sent. See our AI & Algorithmic Transparency Notice.

The line we do not cross: health and fitness data never enters marketing. We do not use your workouts, nutrition logs, wearable metrics, body measurements, wellness check-ins, readiness scores, or any figure derived from them to build marketing lists, to target or segment campaigns, to prioritise sales leads, or to select who receives a message. We do not sell health data and we do not use it for advertising. This is both our own rule and a condition of the Apple Health and Google Health Connect terms we operate under.

Information Sharing and Disclosure

We do not sell your personal information. We may share your information in the following circumstances:

With Your Trainer

If you are a client, your trainer can access your workout logs, nutrition data, measurements, progress photos, and other information you choose to share.

With Service Providers

We share information with third-party service providers who perform services on our behalf:

All the above categories exclude text messaging originator opt-in data and consent; this information won’t be shared with any third parties. This sentence is required verbatim by the carriers for Toll-Free Verification — see the Toll-Free Verification Onboarding Guide, “Legal Policies”. Do not reword it. SMS opt-in is a 1:1 agreement between you and us; it is never sold, shared, or transferred.

  • Supabase: Database and authentication services
  • Stripe: Payment processing (we do not store your full credit card information)
  • WHOOP and Oura: Wearable data, only for the accounts you choose to connect directly. Apple Health and Google Health Connect are not third parties in this sense — they are on-device system services your phone reads from, and we send nothing back to them.
  • Terra API: A legacy wearable aggregation layer. It is not how current health sync works and remains only for older connections.
  • Google Cloud Platform: AI backend hosting (LangGraph) and data processing
  • Anthropic (Claude AI): AI language model for coaching chat and text processing
  • Deepgram: Voice transcription for workout and nutrition logging
  • Passio AI: Food recognition from photos
  • Resend: Email delivery for CRM campaigns
  • Sentry: Error tracking and monitoring

Sharing Your Gym Chooses — Accounting Software

A gym may connect its own Intuit QuickBooks account to MyTrainerOS. When it does, that gym's transaction records — sales, payments, fees, and refunds — are sent to that gym's QuickBooks account as accounting journal entries, so the gym can keep its books.

  • This sharing is started by the gym, not by us. The gym controls its own QuickBooks account and what happens to the data once it arrives there.
  • No health or fitness data is sent to QuickBooks. Not workouts, not nutrition, not wearable metrics, not body measurements, not messages. Only the financial record of a transaction.
  • A gym that does not connect QuickBooks sends nothing there.

For Legal Reasons

We may disclose your information if required by law, court order, or governmental authority, or to protect our rights, property, or safety.

Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.

Data Security

We implement appropriate technical and organizational security measures to protect your personal information, including:

  • Encryption of data in transit (HTTPS/TLS) and at rest
  • Row-level security policies in our database
  • Regular security audits and penetration testing
  • Access controls and authentication requirements
  • Secure storage of progress photos with signed URLs

Specific Protections Worth Naming

  • Connected-account credentials are encrypted at rest. The access tokens that let us fetch your WHOOP or Oura data, or a gym's QuickBooks records, are stored encrypted with AES-256-GCM. Holding the database alone does not yield a usable token.
  • Row-level security throughout. Access rules are enforced in the database itself, not only in the app. You see your own records; a coach sees the members assigned to them; a gym sees its own gym.
  • Billing fields are not user-writable. The columns that record which subscription plan an account is on can be written only by our billing system reacting to a confirmed payment event. An account cannot promote itself to a higher plan by editing its own record.
  • Elevated database routines are scoped to the caller. Functions that run with elevated privileges are constrained to the specific account that invoked them, so an elevated routine cannot be used to reach another person's data.
  • Check-in codes and multi-factor recovery codes are stored only as one-way hashes. We cannot display them back to you or to your gym; a forgotten code is reissued, never recovered.

However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee its absolute security.

Your Rights and Choices

Depending on your location, you may have the following rights:

  • Access: Request a copy of your personal information
  • Correction: Update or correct inaccurate information
  • Deletion: Request deletion of your personal information
  • Data Portability: Request your data in a machine-readable format
  • Opt-Out: Unsubscribe from marketing emails
  • Withdraw Consent: Revoke consent for wearable data collection

To exercise these rights, please contact us at privacy@mytraineros.com. We will respond within 30 days.

Data Retention

We retain your personal information for as long as your account is active or as needed to provide services. If you delete your account:

  • Your profile and personal information will be deleted within 30 days
  • Workout and nutrition logs may be retained in anonymized form for analytics
  • Financial records will be retained as required by law (typically 7 years)
  • Backups containing your data will be deleted within 90 days

If Your Gym Changes Its Subscription Plan

Gym owners can move between our subscription plans, including moving down to a smaller one. If a gym moves to a plan that allows fewer members, locations, staff accounts, or less branding than it is currently using, the records over that limit are deactivated — they are not deleted.

  • Deactivated means hidden from day-to-day use and not counted against the plan. The underlying data stays in full.
  • If the gym moves back up to a larger plan, the same records are restored exactly as they were.
  • A staff member the owner had already suspended stays suspended through this cycle — moving up again does not quietly reinstate someone the owner had turned off.
  • A plan change by your gym is never, by itself, a reason your data is erased. Deletion happens when you delete your account or ask us to delete your data, as described above.

Children's Privacy

MyTrainerOS is not intended for anyone under 18 years of age. We do not knowingly collect personal information from anyone under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@mytraineros.com.

International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country. By using MyTrainerOS, you consent to the transfer of your information to the United States and other countries where we operate.

California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides you with specific rights regarding your personal information.

Your CCPA/CPRA Rights

As a California consumer, you have the right to:

  • Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you, the sources of collection, the business purposes, and the categories of third parties with whom we share it
  • Right to Delete: Request deletion of your personal information, subject to certain exceptions (e.g., legal obligations, ongoing transactions)
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt-Out of Sale/Sharing: We do not sell your personal information or share it for cross-context behavioral advertising
  • Right to Limit Use of Sensitive Personal Information: Direct us to limit the use and disclosure of your sensitive personal information to what is necessary to provide our services
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights

Categories of Personal Information Collected

In the preceding 12 months, we have collected the following categories of personal information:

  • Identifiers: Name, email address, IP address, device identifiers
  • Customer Records: Billing address, payment information (via Stripe)
  • Protected Characteristics: Age, gender (voluntarily provided for fitness customization)
  • Commercial Information: Transaction history, subscription records, session balances and member ledger entries, cancellation and no-show fees where a gym charges them, in-person retail purchases and returns, referral link attribution, satisfaction survey responses
  • Biometric Information: Body measurements, progress photos (voluntarily submitted)
  • Internet/Network Activity: Browsing history within the app, feature usage analytics
  • Geolocation Data: Approximate location (if permission granted)
  • Sensory Data: Voice recordings (temporarily processed, not stored), meal photos
  • Professional/Employment Information: Trainer and staff certifications, business information, role and permissions, employment classification and pay rate set by the employing gym, time-clock entries and the location captured at a geofenced clock-in
  • Health Information: Workout performance, nutrition logs, wearable data, wellness check-ins (classified as sensitive personal information under CPRA)
  • Inferences: Fitness level, readiness scores, churn risk scores, TDEE estimates

Sensitive Personal Information

We process the following categories of sensitive personal information solely to provide our fitness coaching services:

  • Health data (workout logs, nutrition, body measurements, wearable data)
  • Biometric data (progress photos; body-composition figures such as body-fat percentage from body scans, or from Apple Health or Google Health Connect if you turn that category on)
  • Precise geolocation (only if explicitly consented for gym check-in)

We do not use sensitive personal information for purposes beyond providing our services. You may limit the use of sensitive personal information at any time through Settings > Privacy & Consent.

Exercising Your Rights

To submit a verifiable consumer request, you may:

  • Use the in-app Privacy & Consent settings to manage or delete your data
  • Email us at privacy@mytraineros.com

We will verify your identity before processing your request and respond within 45 days. You may designate an authorized agent to submit requests on your behalf.

Data Retention Under CCPA/CPRA

We retain personal information only as long as necessary for the purposes described in this policy. For specific retention periods, see our Data Retention Policy. When your account is deleted, personal data is purged within 30 days, with a 72-hour cooling-off period during which you may cancel the deletion.

Health Data Privacy (MHMDA Compliance)

MyTrainerOS collects health and fitness data and stores it on our servers. That includes daily summaries of your wearable metrics. Because we store it rather than merely display it, we treat the Washington My Health My Data Act (MHMDA) and comparable state consumer health-privacy laws as applying to us directly, not as a possibility. We take additional precautions with all health-related data.

Health Data We Collect

With your explicit consent, we collect and process:

  • Workout performance metrics (exercises, sets, reps, weight, RPE)
  • Nutrition intake (food logs, macronutrient tracking, hydration)
  • Body measurements and composition estimates
  • Progress photos, body-scan results, and exercise videos submitted for form review
  • Wearable daily summaries (resting heart rate, HRV, sleep duration and stages, steps, body composition)
  • Wellness check-ins (mood, energy, soreness, stress)
  • Readiness and recovery scores

Scores and insights we calculate from the above are themselves health data, and we treat them that way.

How We Use Health Data

Health data is used exclusively to:

  • Provide personalized fitness coaching and workout recommendations
  • Generate AI coaching responses and proactive interventions
  • Calculate adaptive TDEE, readiness scores, and program effectiveness
  • Share with your assigned trainer for coaching purposes
  • Detect injury risk and provide safety alerts

We never sell health data. We do not use health data for advertising, employment decisions, or insurance underwriting.

Consent for Health Data

Collection and processing of health data requires your explicit, informed consent. You may:

  • Withdraw consent at any time through Settings > Privacy & Consent
  • Selectively consent to individual data categories (e.g., wearable data only)
  • Request a complete export of your health data
  • Request permanent deletion of all health data

Geofencing Restriction

We do not use geofencing technology to identify or track consumers seeking health-related services. Location data, when collected, is used solely for gym check-in features with explicit user consent.

For full details, see our dedicated Health Data Privacy Policy.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. Your continued use of MyTrainerOS after changes are posted constitutes acceptance of the updated Privacy Policy.

Contact Us

If you have questions or concerns about this Privacy Policy, please contact us:

  • Email: privacy@mytraineros.com
  • Website: https://app.mytraineros.com/contact
MyTrainerOS

Every tool your training business needs — programs, scheduling, payments, and messaging in one app, with AI that assists your coaching and never replaces it. You keep 100% of your sales revenue.

Product

  • All Features
  • Scheduling
  • AI Coaching
  • Nutrition
  • Workouts
  • Pricing
  • Compare

Resources

  • Help Center & Support
  • Docs
  • Blog
  • About
  • Contact
  • Switching from QuickCoach?

Legal

  • Privacy Policy
  • Terms of Service
  • Health Data Privacy (MHMDA)
  • Cookie Policy
  • Data Retention
  • Do Not Sell or Share My Info

Sign in by role

  • I'm a Trainer
  • I'm a Member
  • I'm an Admin Assistant

Built for the gym floor.Runs on the front desk.

© 2026 MyTrainerOS LLC. All rights reserved.