Legal
Privacy Policy
Last updated: July 11, 2026
1. Scope
This Privacy Policy explains how myoxin collects, uses, stores, shares, and protects information when you use our website, mobile apps, coach features, messaging channels, health integrations, subscriptions, and related services (together, the "Services").
myoxin is a training, logging, analytics, and coaching product. It is not an emergency service and is not a substitute for medical care. If you do not agree with this Privacy Policy, do not use the Services.
2. Controller And Contact
Tim Wehnes is the controller for myoxin. Tim Wehnes is also the current operator for the app-store versions of the Services.
For privacy questions, rights requests, export requests, or deletion requests, contact:
We currently handle privacy requests through this email address.
3. Data We Collect
Account and identity data
- Email address, login identifiers, anonymous account identifiers, and authentication state.
- Name, username, or profile label you provide.
- Password and authentication credentials are handled by our authentication providers rather than shown in plain text to us.
Profile, onboarding, and fitness data
- Age, sex, units, bodyweight, optional body-fat, lifting and cardio experience, training goals, sports context, gym access, and similar profile fields.
- Workout sessions, exercise selections, set-level entries, templates, splits, schedules, favorites, custom exercises, lift profiles, and progress metrics.
- Daily check-ins and other self-reported wellness information such as sleep quality, stress, recovery, notes, and related training context you choose to enter.
Self-reported diet, stress, illness, and alcohol trackables
- Optional, self-reported lifestyle markers you enter directly in the app or tell the scientist coach in chat, not read from a wearable or health platform: daily calorie intake (with an optional protein figure), a lightweight diet-adherence rating, subjective stress, illness or sickness status (a severity level and, if you provide it, a date range), and alcohol intake. These are stored under your account as trackables and logged entries.
- We use these to personalize your coaching and, combined with your training data, to help our analytics tell real training effects apart from lifestyle factors like poor nutrition, elevated stress, illness, or alcohol intake. An illness entry may also be used to flag training sessions during that period so they are not misread as a decline in your normal training response.
- Logging any of these is optional: you can answer when the coach asks, log a value yourself, or ignore it entirely. You can delete an individual entry at any time, and deleting your account deletes all of them.
Health and activity data
- When you grant permission, myoxin may read data from Apple Health, HealthKit, Google Health Connect, or similar device-health sources.
- Depending on the permissions you approve, this can include steps, distance, calories, heart rate, resting heart rate, heart rate variability, respiratory rate, oxygen saturation, weight, body fat, nutrition, VO2 max, sleep data, and workout or activity records.
- We may copy synced health data into your myoxin account so it can be used for training context, recovery insights, analytics, and coach features you enable.
- On the first sync, myoxin may import up to the preceding 30 days of data covered by the permission you granted, including days before you created your myoxin account, so your initial recovery and trend baseline is not based on a single day. Later syncs normally use a shorter overlapping period.
- If you disconnect a health integration in the app, myoxin stops all future syncing immediately, and the health data already stored on your account is retained but excluded from all use: it is not used for personalized coaching, recovery insights, analytics, or model improvement, and the coach's context no longer includes it. If you reconnect, use of that data resumes. You can have the stored health data permanently deleted at any time, whether or not you have disconnected, by deleting your account or by making a deletion request as described in "Your Rights And Choices" and "Account Deletion And Data Deletion" below.
Coach, chat, and communication data
- In-app scientist conversations, prompts, replies, tool actions, conversation summaries, and persistent coach-memory notes derived from your usage.
- Feedback you submit about a scientist reply (for example, helpful/not helpful and an optional note), together with the exact assistant reply and the immediately preceding user message needed to review and replay that coaching scenario. We do not duplicate the whole conversation into the feedback record.
- If you link WhatsApp, we process your linked phone number, onboarding state, inbound and outbound message timing, and conversation content. Proactive WhatsApp sends occur only while WhatsApp's customer-service window is open. Outside that window, the update remains in your in-app Scientist chat and an enabled push may invite you to open it there; we do not hold a second WhatsApp copy to flush on an unrelated later reply.
- If supported messaging channels accept media, we may process voice notes, images, and attached content to generate transcripts, summaries, or coach responses, including by sending that media to third-party AI or processing providers we use for those features.
- If you choose to connect your own supported AI-provider API key (currently Google Gemini, Z.AI GLM, or xAI Grok) ("bring your own key"), we store that key in encrypted form and use it, instead of our own hosted key, to process your coaching requests. See "Your AI Key (Bring Your Own Key)" below for details.
Photos and voice notes you send the in-app coach
- You can optionally attach a photo (for example, of a machine, a whiteboard, a gym setup, or a form check) or a short voice note to an in-app scientist chat message. As of this writing, this in-app attachment feature supports images and voice-note audio only (no video yet).
- The photo or voice-note file you attach is uploaded to a private, access-controlled storage area tied to your account. We send it to Google (Gemini), the same AI provider used to generate coach responses, to produce a text understanding of it, a transcript for a voice note, a description for a photo, which becomes part of that conversation.
- The uploaded photo or voice-note file itself is automatically deleted within 48 hours of upload. The transcript or description generated from it is kept as part of your chat history, under the same retention as other scientist-chat data described in "Retention" below.
- Attaching a photo or voice note is entirely optional, message by message.
- Because you choose what to include in a photo or voice note, an attachment could incidentally show or mention another identifiable person (for example, someone else visible at the gym), or reveal health-related information about you or, incidentally, about someone else (for example, showing or describing an injury). You are responsible for only sharing attachments you have the right to share, and our Terms of Service ask you not to include another identifiable person's information, including their health information, without that person's consent. We do not review attachments to screen for this before they are sent.
- Where a photo or voice note you share reveals health-related information, about you or, incidentally, someone else, we treat that content as health data under this Policy, using the same explicit-consent basis described in "Legal Bases" below for other health information you choose to give us.
Subscription, payments, and entitlements
- Subscription status, entitlement state, product identifiers, purchase metadata, and management URLs returned by billing and subscription providers.
- We do not intentionally store full payment card numbers in the app.
Technical, device, and usage data
- IP address, browser type, device or platform details, app version, build details, device or other identifiers, push token status, and deep-link information.
- Error reports, crash logs, diagnostics, app interaction telemetry, sync status, permission state, notification preferences, and security or anti-abuse logs.
Local device storage
- Session state, pending deep links, workout-draft patches awaiting reconciliation, conversation IDs, local telemetry caches, and similar app-storage items used for reliability and limited offline recovery.
4. How We Collect Data
We collect data:
- Directly from you when you sign up, log workouts, chat with the coach, complete onboarding, link integrations, or contact us.
- Automatically from your device and app usage, including technical events, errors, permission states, and local storage behavior.
- From third-party services you choose to use, such as health platforms, subscription providers, identity providers, WhatsApp, email providers, analytics and crash-reporting providers, and app store billing platforms.
5. How We Use Data
We use data to:
- Provide the Services, including workout logging, templates, split scheduling, exercise search, progress analytics, subscriptions, and support.
- Operate the scientist coach, generate responses, maintain conversation continuity, store durable user context, and power coach actions you request.
- Read, sync, and analyze health or activity data that you choose to connect.
- Use self-reported diet, stress, illness, and alcohol trackables you provide to personalize coaching and to support confounder-adjustment in our training analytics, so we can better distinguish real training effects from lifestyle factors.
- Process a photo or voice note you choose to attach to a scientist-chat message to generate a transcript or description and use it to answer your question or inform the conversation.
- Send service communications, workout reminders, and linked-channel messages, including optional proactive messages where enabled.
- Review scientist feedback, reproduce the two-turn scenario that received feedback, improve coaching quality, and adapt the coach to preferences you explicitly express.
- Protect the Services, debug issues, monitor abuse, enforce limits, and keep records needed for audits, disputes, and incident response.
- Develop, train, evaluate, and improve our analytics and machine-learning models, including the models behind your progress predictions, cohort comparisons, and coaching, using your workout and training data in de-identified or aggregated form, so the product gets better for you and for other users over time.
- Where you connect Apple Health or Health Connect data and give the consent described in "Legal Bases," use that health and fitness data to power features you can see in the app, such as recovery-aware coaching and personalized predictions for your own account, and, in de-identified or aggregated form, to improve the accuracy of our coaching and prediction models for all users. We never use this data for advertising, and never share or sell it, as described below.
- Comply with law, enforce our Terms, and protect our rights, users, and business.
We do not sell personal data or personal and sensitive user data. We never sell, share, or transfer health or fitness data connected from Apple Health or Health Connect to advertisers, data brokers, information resellers, or any other third party for their own purposes, even in aggregated or anonymized form, and we never use synced health data for advertising or marketing.
6. Legal Bases
Depending on the feature you use and your location, our legal bases can include:
- Contract: to create and run your account, provide workout logging, templates, split scheduling, subscriptions, history, and the coaching features or messaging channels you ask us to provide.
- Legitimate interests: to secure, maintain, troubleshoot, improve, and defend the Services, prevent abuse, investigate incidents, and keep the product reliable.
- Consent: for optional health-platform connections, optional health-driven features, optional push permissions, non-essential analytics, optional self-reported lifestyle trackables (diet, diet adherence, stress, alcohol) where prior consent is required, and optional chat media (photos and voice notes) you choose to send the coach.
- Explicit consent for health data: where required by law for synced health data or other data concerning health that you choose to provide or connect for recovery, analytics, or coaching features, or to develop and improve our coaching and prediction models, including a self-reported illness or sickness entry, or a photo or voice note you attach that reveals health-related information, all of which we treat as health data.
- Legal obligation: to comply with applicable law, lawful requests, accounting duties, tax obligations, and rights-request handling where the law requires it.
If you choose to connect Apple Health, HealthKit, Google Health Connect, or similar sources, we rely on the permissions and consent flow for those features together with the choices you make inside myoxin. If you choose to use WhatsApp with myoxin, we process that channel data to provide the linked messaging feature you requested. Where available, you can manage non-essential analytics in your Profile.
You can withdraw consent going forward by revoking the relevant permission, disconnecting the integration, changing settings where available, or contacting us. Withdrawal does not affect past processing that was lawful when performed.
7. Sharing And Service Providers
We may share data with service providers and processors acting on our behalf, including providers in these categories:
- Authentication, hosting, database, storage, and infrastructure providers, including Supabase or equivalent providers.
- Email and communications providers, including ConvertKit and similar providers we may use to send product, account, or service emails.
- Subscription, billing, platform, and health-platform providers, including Apple, Google, and the relevant app stores or platform services.
- Messaging and communications providers for the WhatsApp coaching channel, if you use it. WhatsApp messages are processed by our messaging providers acting as service providers: Twilio Inc., and Meta Platforms Ireland Limited (which operates the WhatsApp Business Cloud API). Depending on the delivery path in use at the time, either or both may process your messages; once the older transport is fully decommissioned, only the remaining provider will.
- Analytics, crash-reporting, and diagnostics providers we use to operate and improve the Services.
- AI, model, and observability providers used for coach generation, media processing (including photos and voice notes you attach to an in-app chat message, and voice notes or images sent through a linked messaging channel), tracing, and system monitoring, including Google, Z.AI, xAI, and Langfuse. If you connect your own provider key, your coaching requests are processed by the selected provider under your own account and key instead of ours, as described in "Your AI Key (Bring Your Own Key)" below.
- Health-platform operators and identity providers when you choose to connect those services.
We may also disclose data if reasonably necessary to comply with law, enforce rights, prevent fraud or harm, complete a financing or business transfer, or protect users, the public, or the Services.
8. Your AI Key (Bring Your Own Key)
If your account uses the bring-your-own-key plan and you connect your own supported AI-provider key, currently Google AI (Gemini), Z.AI (GLM), or xAI (Grok), so myoxin can run the scientist coach under your account and quota with that provider, this section explains how that key is handled. Grandfathered legacy_hosted accounts use our hosted key. A bring-your-own-key account with no usable personal key does not fall back to our key: AI requests pause until the personal key is connected or restored.
- Your key is sent once, over an encrypted connection, to our backend, which checks that it works with the selected provider, then encrypts it (AES-256-GCM) and stores only the encrypted value. New ciphertext is additionally authenticated against your user ID, so moving it to another user's row cannot produce a usable key. The secret needed to decrypt it lives solely in our backend's server configuration. It is never stored in our database and never sent to any app, browser, or client.
- This is encryption at rest, not a zero-knowledge design. To place your coaching requests, our server must decrypt your key in memory for each request, use it to call the selected provider's API on your behalf, and then discard the decrypted value. Our server can technically access your key in order to use it for you. That is what makes the feature work.
- While a key is connected, the chat messages and training context you send to the coach are processed by the selected provider under your own provider account and are subject to that provider's API terms and practices, in addition to this Policy. Z.AI GLM and xAI Grok text requests do not receive attached image, audio, or video files through the current media-analysis path. xAI states that API user content is retained for up to 30 days by default unless zero-data-retention access applies. Those attachments remain supported only where the connected provider has an implemented media capability.
- After you save your key, the app never displays or reads the raw value back to you or to us. We do not log the key, attach it to diagnostics or tracing records, or share it with anyone else, and we do not charge you anything for using your own key.
- You can remove a connected key at any time from the app, which immediately erases the ciphertext and display preview from the active row (a non-secret tombstone may remain so the account cannot accidentally receive hosted-key fallback). You can also revoke the key directly with the selected provider at any time. This is your ultimate control because it invalidates the key everywhere, including with us.
- If your provider account is on a paid plan, a compromised key could be used to run up usage billed to your own provider account. We recommend setting up billing or budget alerts directly with your provider.
9. International Transfers
We may process or transfer data in countries other than your own. Where required, we rely on contractual, technical, and organizational safeguards intended to protect transferred data, including standard contractual clauses or similar approved mechanisms.
10. Retention
We keep data for as long as reasonably necessary for the purposes described above, including to operate the Services, maintain account continuity, enforce rights, resolve disputes, recover from incidents, and comply with law.
- Account, profile, workout, analytics, coach, and synced health data are generally retained while your account remains active and until deletion is requested or required.
- Synced health data specifically: disconnecting a health integration does not delete the health data already stored on your account. It stops future syncing and excludes the stored data from all use (coaching, analytics, and model improvement) until you reconnect, at which point use resumes. The stored health data is permanently deleted only when you delete your account or make a deletion request, not merely by disconnecting.
- Scientist feedback and its minimal two-turn replay snapshot are retained while your account remains active so feedback can be reviewed and scenarios can be reproduced; account deletion removes them with the underlying account/conversation, subject to ordinary backup and legal exceptions.
- A photo or voice note you attach to an in-app chat message is automatically deleted within 48 hours of upload; the transcript or description generated from it is kept as part of your chat history under the coach-data retention described above.
- Notification tokens, linked-channel state, and subscription metadata may be retained while active and for a reasonable period afterward for fraud prevention, support, entitlement, or audit purposes.
- Operational logs, diagnostics, summaries, and backups may remain for a limited additional period after deletion or account closure.
- Local device storage remains on your device until cleared by the app, overwritten, removed by you, or deleted when you uninstall the app.
If we no longer need data, we may delete it, anonymize it, or de-identify it. If law requires a longer retention period, we may keep the minimum data necessary for that purpose.
11. Security
We use administrative, contractual, technical, and organizational measures intended to protect data, including encrypted transport, access controls, scoped database policies, and provider security features. No system is perfectly secure, and we cannot guarantee that unauthorized access, disclosure, alteration, or destruction will never occur.
12. Your Rights And Choices
Depending on your location, you may have rights to access, correct, export, restrict, object to, or delete your personal data, and to withdraw consent where processing depends on consent.
- You can disconnect a health integration in the app, or revoke health permissions in your device settings, to stop future syncing; either way, previously stored health data is retained but excluded from use rather than deleted, and reconnecting restores use of it. To have stored health data permanently deleted, delete your account or make a deletion request.
- You can unlink WhatsApp, turn off push preferences where available, and manage subscriptions through the relevant billing tools.
- You can delete an individual self-reported trackable entry (diet, stress, illness, or alcohol) at any time in the app, in addition to full account deletion.
- A photo or voice note you send the coach is deleted automatically within 48 hours; you can also contact us to ask for an attachment or its associated chat to be removed sooner.
- You can turn optional analytics on or off in the Profile where that setting is available.
- You can request access, correction, export, restriction, objection, or deletion by contacting us at the email above.
For now, we handle these requests manually by email. Where the law gives you a portability right, we may provide a structured electronic export by email or another reasonable electronic method after identity verification.
We may require identity verification before fulfilling requests, and we may deny or limit a request where permitted by law, security needs, or the rights of others.
13. Account Deletion And Data Deletion
You can initiate account deletion from within the app. If you cannot access the app, you can also contact info@myoxin.ai or use any public delete-account page we make available.
When an account deletion is processed, we may delete or de-identify the data associated with that account, including workout history, profile data, self-reported trackables (diet, stress, illness, and alcohol logs), health-sync data we copied into the Services, chat history, scientist-feedback replay records, chat media attachments (photos and voice notes) and their derived transcripts or descriptions, WhatsApp link state, and notification records, except to the extent we need to keep limited data for backups, fraud prevention, disputes, billing, tax, security, legal compliance, or technical recovery.
Disconnecting an integration or uninstalling the app does not by itself guarantee deletion of server-side account data. For health integrations specifically, disconnecting stops future syncing and excludes the already-stored health data from use, but does not delete it; deletion happens only through account deletion or a deletion request.
14. Children
The Services are not directed to children and are not intended for anyone under 18 unless allowed under applicable law with appropriate consent and supervision. If you believe a child has provided personal data to us improperly, contact us so we can review and take appropriate action.
15. Changes To This Policy
We may update this Privacy Policy at any time. The updated version will apply when posted, unless law requires additional notice or consent. If a change is materially adverse or legally significant, we may also notify you by email, in-app notice, store listing update, or other reasonable means.
16. Contact
Privacy, deletion, and data-rights requests:
If applicable law gives you the right to complain to a supervisory authority, you may do so in the jurisdiction where you live, work, or where the alleged issue occurred.