Privacy Policy
Version 2026-09-11 · Effective September 11, 2026
1. Who we are and what this covers
Proxfit LLC, an Illinois limited liability company, operates the Proxfit mobile app and the proxfit.app website. This policy describes what we collect through the app, the website, and support, how we use it, who else processes it, how long we keep it, and what you can ask us to do.
Proxfit is currently offered in the United States only. If that changes, this policy will be updated before the change takes effect.
Contact us at privacy@proxfit.app.
2. What the website collects
The proxfit.app website does not run advertising pixels, product-analytics trackers, or cross-site trackers. Our hosting and network provider, Cloudflare, processes standard technical request data such as IP address and user agent in order to serve and protect the site.
If you submit the waitlist form, we collect the email address you enter, your consent to be contacted, and any campaign parameters in the link you arrived through. The form is protected by Cloudflare Turnstile, which checks that the submission is not automated; we receive the result of that check and do not store the Turnstile token. The check may complete without asking you to do anything. Cloudflare's handling of the data the check collects is set out in its Turnstile Privacy Addendum, at https://www.cloudflare.com/turnstile-privacy-policy/. Waitlist emails are sent through Resend.
3. What the app collects
Account and identity: your email address or Apple private-relay address, the identifier from your sign-in provider, and session and security metadata. Sign-in is handled by Clerk, and you can sign in with Apple or with Google.
Eligibility: your date of birth, used to enforce the 16+ minimum described in section 8.
Fitness profile: your goals, experience level, training schedule and availability, available equipment, and any sport or specialization preference.
Body information: height, weight and weight history, and the biological sex field used to select appropriate reference values.
Injury and pain information: the body region and side you report, a pain score, and recovery dates. This is what drives the exclusion and substitution of exercises.
Readiness check-ins: sleep, soreness, stress, and reported pain, used to adjust the intensity of a given day's session.
Workout data: your plans, sessions, completion status, sets, reps, loads, substitutions, and progress history.
Plan-generation records: the constrained inputs a plan was generated from and the decisions the planner made, kept so that a plan can be explained and audited.
Subscription state: your subscription product, entitlement, trial status, and the transaction identifiers we receive from Apple through RevenueCat.
Device and security data: internal user and device identifiers, IP address and request metadata, server logs, and audit records.
Support and requests: what you send us, and what we need to verify who you are.
We do not receive or store your payment card details. Apple handles payment.
With your permission, the app can read your height, weight, biological sex, and date of birth from Apple Health to prefill your profile. Proxfit does not write anything to Apple Health. You can decline this and enter the same information by hand, and you can withdraw the permission at any time in iOS Settings.
4. What we do with it
We use this information to create and secure your account and enforce eligibility; to generate, validate, and adapt your training plans; to apply equipment, injury, readiness, and progression constraints; to record your sessions and progress; to administer subscriptions, trials, and entitlements; to answer support and privacy requests; to detect abuse, secure our systems, debug problems, and respond to incidents; and to meet legal obligations.
We do not sell your personal information. We do not share it for cross-context behavioural advertising. We do not use your health, injury, readiness, body, or workout information for advertising of any kind. There is no advertising in Proxfit and no advertising or data-broker software in the app.
If that ever changes, we will update this policy and obtain any consent or offer any choice the law requires before the change takes effect.
5. Automated plan generation
Your training plan is produced by a deterministic optimization process that runs on Proxfit's own servers. In the current release no external AI provider is enabled, and your information is not sent to one.
The app is built so that an external AI service can be enabled for plan generation in future. If we enable one, it receives a constrained snapshot — training preferences, available equipment, the injury region, side and pain score you reported, sleep and soreness, limited workout history, and derived load information. That snapshot excludes your email address, your date of birth, your sign-in credentials, and our internal identifiers. Deterministic rules validate or reject whatever comes back before it reaches you. We will update this policy before enabling an external provider.
Plan generation does not make decisions that produce legal effects for you or anything similarly significant. You can change any input at any time, and you decide what to perform.
6. Who else processes your information
Clerk — authentication and identity. Receives your email or relay address, provider identity, and session data.
Apple — Sign in with Apple, the App Store, and payment. Apple acts on its own behalf for your Apple account and your purchase records.
Google — Google Sign-In, where you choose it.
RevenueCat — subscription and entitlement management. When you purchase a subscription, it receives an app user identifier and your entitlement, plan, and trial state, together with the transaction identifiers Apple provides.
Cloudflare — DNS, network protection, the tunnel that fronts our API, hosting for proxfit.app, and Turnstile on the waitlist form, which it covers by a separate Turnstile Privacy Addendum at https://www.cloudflare.com/turnstile-privacy-policy/. It also stores our database backups, which are encrypted before they are sent.
Grafana Cloud — server-side operational telemetry and metrics. It receives service and performance data, not your training, injury, or readiness content.
Resend — waitlist and transactional email delivery.
Doppler — secrets management for our deployment pipeline. It holds credentials, not your personal information.
Tailscale — private network access for our engineers to the systems that hold data.
All of these process data in the United States or in facilities their agreements permit. We may also disclose information to professional advisers, insurers, or authorities where the law permits or requires it, and to a party involved in a merger or acquisition, with appropriate safeguards.
The app itself installs no product-analytics, advertising, or crash-reporting software. Events the app records for its own use stay on your device and are not transmitted.
7. Where your data is held, and how it is protected
Proxfit's application servers and database run on hardware operated by Proxfit LLC in the United States, reached through a Cloudflare tunnel rather than being exposed directly to the internet. Connections are encrypted in transit with TLS.
We use access controls and audit logging, Clerk for authentication, and the operating system's secure storage for the authentication token held on your device. We take regular database backups; any copy kept outside our own hardware is encrypted with a public key before it leaves, and the private key needed to read it is not held on any server.
We do not apply application-level encryption to individual database fields, and our database is not hosted on a managed cloud provider with provider-managed encryption at rest. We say so plainly rather than implying protections we have not implemented. No system is completely secure.
8. Age
Proxfit is not directed to children and you must be at least 16 to use it. The app asks for your date of birth before it collects any fitness or health information, and our servers refuse to complete onboarding for anyone under 16.
Some users who are eligible will still be minors, aged 16 or 17. The app store or applicable law may separately require a parent or guardian's approval for a minor's download or purchase.
If we learn that someone under 16 has an account, we block it from completing onboarding, so it holds no fitness or health information, and we delete it. Subject to narrow legal and security exceptions, no such information is retained. A teen or a parent or guardian can contact privacy@proxfit.app. We verify such requests proportionately, and we will not disclose account information simply because someone says they are a parent.
9. How long we keep it
Account, profile, fitness, injury, readiness, workout, and plan-generation records: for as long as your account exists. When you request deletion, the account is deactivated immediately and the data is permanently deleted after a 30-day grace period, which exists so that a deletion made by mistake can be undone.
Records of which version of these documents you accepted, and security audit records: retained for two years after the account is deleted, because they are the proof that the account existed and consented. These are not deleted on request.
Waitlist email addresses: until six months after launch, or earlier if you ask.
Subscription and store records: for the period Apple and RevenueCat retain them, and for any period we are legally required to keep financial records.
Server logs and operational telemetry: short retention periods set per system.
Backups: deleted data can persist in an encrypted backup until that backup rotates out, within 30 days. Backups are not used for ordinary processing and are restored only to recover from a failure.
10. Your rights
You can ask us to give you a copy of your data, correct it, delete it, or stop a particular use of it. If you live in California, you have the rights described in the CCPA as amended by the CPRA, including the right to know, to delete, to correct, to limit the use of sensitive personal information, and not to be treated differently for exercising them. Residents of other US states with comprehensive privacy laws have comparable rights.
You can delete your account yourself from Settings in the app, without contacting us. For anything else, email privacy@proxfit.app.
We verify requests proportionately — usually by requiring you to be signed in, or by a one-time link to your account email. A request made by an authorized agent, a parent, or a guardian may need more verification. We aim to respond within 30 days; applicable law controls where it sets a different period.
If we decline a request, we will tell you why, and you may appeal by replying to our response.
11. Sensitive information
The injury, pain, readiness, body, and workout information you give us may count as sensitive personal information or as consumer health data under some US state laws, even though Proxfit is not a healthcare provider and is not subject to HIPAA.
We treat it accordingly: it is used only to generate and adapt your training, it is never used for advertising, it is not sold or shared, it is excluded from the content sent to our operational telemetry, and it is deleted with the rest of your account.
12. Changes to this policy
Each published version of this policy carries a version identifier and an effective date, and the version you accepted is recorded against your account. When we make a material change we will ask you to accept the new version before you continue using Proxfit.
We will not reduce your rights retroactively.
13. Contact
Proxfit LLC, Illinois, United States.
Privacy questions and requests: privacy@proxfit.app Support: support@proxfit.app
About this version
This document is version privacy-2026-09-11, effective September 11, 2026. It was prepared by Proxfit LLC and has not been reviewed by an attorney. We publish it because the service cannot operate without a published privacy policy, and we expect to revise it after legal review; a revision will be published as a new version and you will be asked to accept it.