Draft, under legal review
Privacy Policy
Last updated: 28 September 2026
This describes what Tartaris stores, why, and what you can do about it. It is written against what the app actually does; if you find something here that doesn't match the app, the app is the bug.
Tartaris is operated by the developer of Tartaris ("we", "us"). Contact: support@tartaris.app.
What we collect
Your account. An email address and a password, handled by Supabase Auth. We never see your password; it is stored hashed by Supabase and we cannot read it. If you turn on two-factor sign-in, Supabase also keeps the key your authenticator app uses, so it can check your codes.
What you log. Lifts, training blocks, training sessions, individual sets (weight, reps, RPE), per-day notes, cardio sessions, daily step counts, the kinds of training you said you do, food entries (brand, food name, weight in grams, calories and macros) and your daily nutrition targets. This is the app.
Apple Health, if you connect it. Tartaris reads four things from Apple Health and writes nothing to it:
- Daily step count, stored with us as one number per day, the same as a count you type in, so the steps ring works on your other devices.
- Sleep, resting heart rate and heart rate variability, used to show how this week's recovery compares with your normal. These are read on your iPhone each time and never leave it: they are not uploaded to us, not stored on your phone by Tartaris, and not sent to anyone.
Health data is never used for advertising or marketing, never sold, never shared with anyone outside the processors named below, and never stored in iCloud. You can turn any of it off at any time in the Health app (Sharing › Apps › Tartaris).
Photos and videos, only when you choose to send one. A profile picture and a profile banner, if you add them. Photos you add to a post (up to four). Photos or videos you attach to a direct message. Photos or short videos you post to show how an exercise is done. And meal photos you take or pick for a food estimate (see below), which are sent for the estimate and not stored by us. The camera is used only when you press a button to photograph a meal or scan a barcode.
What you share with other people, if you use the social features. Posts (a set, a training day or photos, with an optional caption), comments, likes, who you follow, and direct messages with the people you message. Routines you choose to publish, and the likes and saves you give other people's. Exercise demos you post. Exercises you create, only if you turn on Settings › Privacy & data › Share exercises I create (it is off unless you do).
Coaching, if you have a coach or are one. The coaching relationship itself, routines a coach assigns, and reviews of coaches written by their clients.
Your profile, if you make one. A username, an optional display name, picture, banner, bio and profile colour, whether your account is public or approval-only, the milestone badges you choose to show, and — only if you pick one — a scoring category used to calculate a pound-for-pound leaderboard score. A profile is optional. The app works fully without one; you simply won't appear on any leaderboard.
Your bodyweight, if you record it. Each reading is stored with the date you recorded it, so a pound-for-pound score can use what you weighed on the day of the lift rather than what you weigh now. Every reading is optional and every one can be deleted individually in the app.
Moderation records. Who you have blocked, and any reports you file.
Device settings. Weight unit, rest-timer length and theme are stored on your device only. They are not sent to us.
Notifications, if you turn them on. Your phone's push token (an address for sending notifications to that phone, which says nothing else about you), which kinds of notification you want, your quiet hours and your phone's time zone. A notification names who did something (for example "Sam sent you a message" or "Sam passed you on Squat") and never includes message text. The token is removed when you sign out, turn notifications off or delete your account.
We do not collect: location, contacts, your photo library (only the pictures you pick), any Apple Health data beyond what is listed above, advertising identifiers, or analytics of how you use the app. There is no third-party analytics SDK and no advertising SDK in the app.
Crash reports. When the app crashes or hits an error it cannot recover from, it sends a crash report to Sentry, our crash-reporting service, so we can find and fix the bug. A report holds the error and where in the code it happened, the app version, your phone's model and operating system version, and the app's last few requests to our server (which table or function, and whether it worked, but not what was asked for or sent). It does not hold your name, email, user id or IP address. Before it leaves your phone we remove anything that could carry your health readings, meals, food photos or message text: error text quoting your data, the search part of web addresses, file names and photo data, and the app's own log lines. No screenshots are taken and no record of what you tapped is kept.
What we do with it
Your training data exists so the app can show it back to you and compute your predicted PR-attempt date. Nothing more.
Food estimates. Nothing is sent for an estimate until you allow it: the first time, the app asks, and you can turn it off again in Settings › Privacy & data › AI food estimates. Once allowed, when you press "Estimate for me", the brand, food name and weight you typed are sent to Anthropic's Claude API to produce a calorie and macro estimate. When you photograph a meal instead, the pictures (at most two) and any note you add are sent the same way. Nothing else goes with either — not your name, not your email, not your training data. The estimate is returned to your phone; we do not keep the photos, and Anthropic does not use them to train its models. We count how many estimates each account asks for per day, to keep the service within its limits. If you'd rather not use it, type the numbers in yourself; the food log works either way.
Barcode scans. When you scan or type a barcode, only the barcode number is sent to Open Food Facts, a free public food database, to look up the product's label. Nothing that identifies you goes with it.
Keeping the social features civil. Captions, comments, messages, reviews, usernames and display names are checked on your phone for offensive language before they are posted. Reports you file are reviewed by us.
Coaching payments. When a client pays a coach through Tartaris, or a coach pays for a coach subscription, the payment is handled by Stripe. Card and bank details go straight to Stripe and never reach us. We keep only what's needed to run coaching: Stripe's reference numbers, the amount, the plan and whether it's paid, and we share with Stripe the account details it needs to pay coaches and meet its legal checks.
Consumer health data. Training, body weight, food and recovery data count as consumer health data in some US states. How we collect, use and share it, and your rights over it, are set out in our Consumer Health Data Policy, which you agree to separately in the app.
We do not sell your data. We do not share it with advertisers. There are no ads in Tartaris.
Who can see your training data
By default, nobody but you. Every table is protected by Postgres Row Level Security policies keyed to your account, which means the database itself refuses to return another user's rows — this is not a filter applied in the app that could be bypassed.
The leaderboard shows your best lifts, and only for lifts you have logged: to people you have accepted as followers, or to every signed-in user if your account is public. It shows your username, your display name, your best set for that lift, and — if you entered a bodyweight — your pound-for-pound score. It never shows your email, your other lifts, your training history, or your food log.
Blocking someone removes both of you from each other's search results and leaderboards. The person blocked is not told.
The social and coaching features share only what they are for:
- Posts, including their photos, and the comments and likes on them, are visible to you and the audience your account allows: your accepted followers, or anyone signed in if your account is public.
- Direct messages and their attachments are visible only to the people in that conversation.
- Routines you publish, exercise demos you post and exercises you share are visible to every signed-in user, with your username, except people you have blocked or who have blocked you. Unpublishing a routine or deleting a demo takes it down.
- Your profile picture, username, display name, banner, bio and the badges you choose to show are visible to other signed-in users, so they can find you. A coach's public coach page shows their profile and rating to anyone, signed in or not.
- A coach you have accepted can read your training log (sessions and sets) and your body weight readings while the relationship is active, on the app and the coach website. Not your food log, not your steps or recovery. Ending the relationship ends their access.
- Reviews of coaches are readable by every signed-in user.
Where it is stored
On Supabase's infrastructure, hosted on AWS in the US East region. Supabase acts as our data processor. If you are in the EEA or UK, your data is therefore transferred to the United States.
The only other services that receive anything are Anthropic (the food estimates above), Open Food Facts (barcode numbers only), Stripe (coaching payments), Sentry (crash reports, as described above, kept for up to 90 days and stored in the United States) and, if you turn on notifications, Expo's push service with Apple or Google, which deliver them to your phone. Each receives only what is described here, and we use them only on terms that protect your data at least as well as this policy does.
How long we keep it
Until you delete it. Removing a set, a block or a food entry deletes it immediately. Deleting your account (Settings → Account → Delete account) removes your login and every row attached to it — training history, bodyweight readings, profile, follows, blocks, reports and food log — and every file you uploaded (pictures, post photos, exercise demos and message attachments), permanently and without a backup copy. We do not keep a shadow copy after deletion.
Your rights
Whatever jurisdiction you are in, the app gives you these directly rather than making you ask:
- See and export your data. Settings → Account → Export my data writes a JSON file of every row we hold about you.
- Correct it. Every logged value is editable in the app.
- Delete it. Settings → Account → Delete account, effective immediately.
- Restrict who sees you. Settings → Who can follow you.
If you are covered by the GDPR, UK GDPR, CCPA/CPRA or a similar law, these cover the substance of your access, portability, rectification, erasure and opt-out rights. For anything they don't cover, email us at the address above.
The website waitlist
If you join the waitlist on our website, we keep the email address you give and the date you gave it, and nothing else. We use it only to tell you when Tartaris is available, and we delete the list once the app has launched. To be taken off sooner, email us and we will remove it.
Children
Tartaris is not directed at children under 13, and we do not knowingly collect data from them. Sign-up asks for your birth month and year; the app checks it on your phone and does not send or keep it. If the answer is under 13, no account is created and sign-up stays closed on that phone. If you believe a child has created an account anyway, email us and we will delete it.
Changes
If this policy changes materially we will say so in the app before the change takes effect, and update the date at the top.