Privacy Policy
Resistance is a strength-training log. To do its job it holds things that are genuinely personal: what you lift, what your body weighs, how you slept, what hurts, and whatever you tell Coach. This page says what we collect, what leaves our servers and to whom, how long it stays, and how to get it back or delete it. It describes what the product actually does today, not what we would like it to do.
Resistance is operated by Percival Labs LLC, a Texas limited liability company, which is the data controller for everything described here. Write to privacy@rezist.ai about any of it.
The companion page is the subprocessor list — every outside company that can touch your data, what they do, and what reaches them. It is dated, and we keep it current.
What we collect
Your account. Email address, display name, and your password stored as a scrypt hash — never in plain text. If you turn on two-factor authentication or a passkey, we store the credential material for it. Optionally: a public @handle, a bio, and a profile photo. We also record that you accepted our Terms and disclaimers, which version of them you saw, and when. Creating an account asks for your date of birth so we can check you are old enough; we keep the answer to that check, not the date.
Your training. The product itself — workouts, logged sessions, every set with its weight, reps, RPE and notes, personal records, body measurements, bodyweight, custom exercises, and routines (including routine-as-code YAML if you use it).
Health information you type. The daily readiness check-in (sleep, soreness, motivation, stress, plus a free-text note), and the injuries, pain and physical limitations you tell Coach about, which are kept in Coach's memory so it does not ask twice. Daily food totals, if you log them — calories, protein, carbs and fat, as four numbers you enter yourself. There is no food database and no meal parsing: we store the totals next to your training so Coach can read them alongside what you lifted. Also optional: birth year, height, and sex, which power calorie estimates and coaching context. This is health data and we treat it as such.
Data in your phone's health app stays on your device. On Apple Watch, workouts record heart rate and active energy through Apple Health, and finished sessions are written back to the Health app so they count toward your rings. On Android, finished sessions are written to Health Connect the same way, along with the calorie estimate for each one. To size that estimate for you rather than for an average person, Android reads your most recent weight back out of Health Connect when you have not logged one with us; it is used to work out the number and then dropped. None of it is uploaded — there is no heart rate, energy, step or sleep field anywhere in our database. From there it is your phone's: the Health app syncs to your own iCloud under Apple's terms, and Health Connect stays on the device and is read only by the apps you allow. This mirroring is on by default and can be switched off in Settings, and it only ever happens after your phone asks your permission.
Coach conversations and Coach memory. Your chat threads are stored on our server so they follow you between devices. Coach's memory is a single free-text profile it maintains about you — goals, equipment, constraints, injuries — which you can read and edit in the app.
Photos, in three different ways.
- Profile photo — you pick it. We save a fresh copy of just the picture (dropping whatever your camera recorded alongside it, including the location), under a random filename.
- A photo you send Coach — a machine, a form check. Our server makes a fresh copy of just the picture, so the location and time your camera recorded do not go anywhere. It rides one request to the AI provider and is not stored by us; only the text of the conversation is kept.
- Feedback screenshots — if you switch on evaluation mode in Settings, a feedback button appears. Tapping it automatically captures the screen you are on, before you have typed anything, and attaches that image to the report. There is no control to detach it; on a phone the only way to avoid sending it is to cancel the report, and on the web app it simply cannot be captured, so nothing is attached there. Whatever was on screen is in the image — measurements, notes, a Coach thread, your email address on the Settings screen. The separate contact form in Settings sends text only.
Identifiers. An account id, your optional public @handle, and — if you allow notifications — a push token for each install.
Purchases. Which plan you are on, whether it is active, when it renews, and the store's transaction id. Card numbers never reach our servers.
Diagnostics. Crash and error reports (message, stack trace, platform, release), and request timing. A feedback report also carries app version and build, OS version, device model, the screen you were on, and your sync state.
Dictation. When you dictate to Coach, the microphone is handled by your device's speech recognizer — Apple's on iOS, the browser's on the web. Depending on the device and browser, that audio may be processed on your device or sent to Apple or Google by the operating system. It never reaches us. Only the resulting text does, and only when you send the message.
What we do not collect. No location of any kind — not even a time zone. No contacts, no calendar, no browsing history, no files. No advertising identifiers. The app carries no advertising SDK and no third-party analytics SDK; any page-view count on this website is Cloudflare's cookieless aggregate measurement, which does not follow you to other sites. We do not sell your data, we do not share it with data brokers, and nothing here is used to track you across apps or websites.
What leaves our servers, and to whom
Your training data lives in a Postgres database on a server we run ourselves. Most of what you do never leaves it. What follows is the complete set of exceptions, and the subprocessor list names each company.
Coach, when it runs on our AI
Coach always runs on a model. When it runs on our key, that model is one we pay for, hosted by Google, and it takes no subscription for your data to go there. Using Coach at all means sending the data below; if you would rather it did not, do not use Coach — the rest of the app works without it. Two things reach an AI provider even if you never send Coach a message: the background summaries described next, and the lookups behind the exercise editor, further down.
What goes to Google when Coach answers on a model we pay for:
- your message and the rest of that conversation;
- Coach's memory verbatim — including the injuries, pain and limitations you have told it about;
- your display name, age derived from birth year, height, sex, latest bodyweight and its recent trend;
- the training data Coach reads to answer — sessions, sets, workouts, records, progress and body measurements, including the notes you wrote on a session or on an exercise in it;
- your readiness check-ins, including the free-text note, verbatim;
- the names of any exercises you made yourself, whether or not you have ever trained them;
- any photo you attached, at full size.
The notes you write on a session, before or after it, and on an individual exercise are part of that training history, so they go wherever it goes: any question Coach answers by reading your history sends them, whether or not you attach that session to a message. That is what lets Coach act on "left shoulder pinched on set 3, cut it short" rather than seeing only that a set got lighter, and it means free text you wrote about your body goes to a model as a matter of course. Each note is sent quoted and cut off at 120 characters. The notes on a measurement are held back and are not put in the prompt by us.
The first message in a conversation causes a second, smaller call to the same provider to write the thread's title, and a long thread is periodically summarised by one more. Same company, same key, different model.
Our production account with Google is on a paid, billing-enabled tier, which is what makes this true: your data is not used to train their models. We will not tell you it is never stored — providers retain input briefly for abuse monitoring, and that window is their fact to state, not ours.
Background summaries, which go to two providers at once
Coach writes a summary after each workout and a review each week. These run in the background, without you asking and without a subscription. They are also how we work out which model actually writes the better summary — so, by default, the same prompt is sent to two providers at the same time and both answers are kept side by side for us to compare.
The primary answer comes from OpenAI; the comparison answer comes from Google. Both receive the same content: the session's name and every set in it with weights, reps and how hard it felt, the notes you wrote on that session and on the exercises in it, up to four earlier sessions in the same detail, your entire all-time record table, the week's totals, and your readiness check-in including the note you wrote that day, verbatim. Both answers are stored alongside the summary, indefinitely, where an operator can read them to judge which model did better. You see only one of them in the app. This is the detail most likely to surprise you, which is why it is stated plainly rather than folded into a sentence about "service providers".
You can stop all of this: turn Summarize my workouts off under Settings → AI coach & memory, and no summary is written and nothing about your sessions is sent to either provider. Conversations with Coach are separate and are covered above.
Coach, when it runs on your own key
Running Coach on your own key is part of Resistance Pro. You supply a key for OpenAI, Anthropic, Google, or anything OpenAI-compatible you point us at. The same context described above is sent to the provider you chose, on your own account with them, under their terms.
That flips who is promising what, and it is worth being blunt about: on your own key, whether your data trains anyone's model depends on your plan with your provider — a consumer-tier key often carries weaker terms than a paid API tier. We cannot make that promise for you. Coach running on our key is the path where we control the billing tier and can. If you use your own key, read your provider's policy.
Your key itself is stored on your device — in the Keychain or Keystore on iOS and Android, and in browser local storage on the web app, which has no equivalent secure enclave. If you opt in to syncing the key across your devices, we store it encrypted with AES-256-GCM; the plaintext is never returned to any client, and we never use your key for anything you did not initiate.
Everything else that leaves
- All of your traffic passes through Cloudflare. Cloudflare provides the DNS, the certificates and the tunnel that connects the internet to our server, for rezist.ai, app.rezist.ai and api.rezist.ai alike. Because it terminates the encrypted connection, it is technically able to see the contents of every request, not only the IP address, user agent and URL. That includes what you send at sign-in, your training data, and uploads. It is the single most privileged company on this page, and it is there for the same reason it is on most of the internet — we could not offer the service without a provider in that position. Some public pages on rezist.ai (a public profile, a shared program) are also assembled by Cloudflare at the edge.
- Email — verification links, password resets, two-factor codes and support replies are delivered by Amazon SES. When you send a feedback report or use the contact form, the notification carries your name, email address, account id and your message. Everything you email us, including anything sent to privacy@rezist.ai, lands in a Google (Gmail) mailbox.
- Push notifications — sent through Expo's push service, which relays to Apple's and Google's push systems. It receives the push token and the notification's title and body, which can contain text you wrote — a workout or club name — or another member's public @handle. It never contains a Coach summary or a comment's text.
- Profile photos and feedback screenshots — stored in a private Amazon S3 bucket in the United States, encrypted at rest, with no public access.
- Purchases — Apple and RevenueCat for in-app purchases, Stripe for web purchases. They receive your Resistance account id and the product and transaction ids. Card details go to Apple or Stripe directly and never pass through us.
- Errors — when something breaks unexpectedly, a report goes to Sentry. We attach no name, email or account id to it. Two caveats we would rather state than leave you to discover: the report includes the exact address that failed, which can contain an id or a public @handle, and a database failure carries the query that failed along with its values, which can include free text you wrote or your email address.
- App updates — the app checks Expo's update service at launch, which sees your IP address, platform and app version. Any app that updates itself does this.
- Making or editing your own exercise — while you type its name, our server searches YouTube for a form video and asks a model which of the results actually shows that movement. On a new exercise it also asks a model whether the library already has the movement under another name. The search carries the name and equipment you have typed; the model calls carry those and the kind of exercise it is (barbell, machine, cardio), and the duplicate check also carries the muscles you picked. Nothing else from your account goes with them, and the subprocessor list names the companies. The button on that screen that asks Coach to fill in the details is Coach, and sends what Coach sends.
- Exercise images and videos — the exercise library's demonstration images are served by GitHub and its form-video thumbnails by YouTube, loaded straight from your device when you open an exercise or the exercise picker. Those companies therefore see your IP address and which exercise you are looking at, and on the web they see any cookies you already have with them. There is currently no way to turn this off; if you would rather we proxied or bundled them, say so and we will.
- The API documentation page loads its viewer from the jsDelivr CDN, which sees your IP address if you open that page.
- Webhooks you set up yourself — if you configure one, we POST a small signed payload (a session id and a count of records set) to the URL you gave us, when you asked.
What other people can see
Your profile is private by default. Nothing about your training is visible to anyone else unless you turn something on:
- Making your profile public shows your @handle, display name, bio, photo, the month you joined, and your follower counts. Aggregate training stats appear only if you separately switch those on. Turning your profile private again takes effect on the very next request, including previously shared links to your photo.
- Publishing a workout or routine to the marketplace makes that content public, along with its rating and install count. If your profile is private, your name and handle are masked on the listing but the content is still public.
- Sharing an individual session, posting a comment, or writing a review makes that item visible to others. Blocks are honoured everywhere you are signed in; on public pages served to logged-out visitors there is no viewer to check a block against.
How long we keep things
- Your account and training data — until you delete it. Things you delete in the app are marked as deleted and stop appearing immediately; the row is cleared when the account is deleted.
- Coach conversations and memory — until you delete the thread or the account. Coach also keeps the previous version of its memory so a change can be undone, which means text you removed from it is retained for a while and is not visible to you.
- Feedback reports and their screenshots — until you delete your account. There is no automatic expiry for them today, and any operator with admin access can read them. If you want a specific report and its screenshot removed sooner, email us.
-
Change records — 90 days. We log every change made through the API so a
mistake can be traced. The entry records the action, the record it touched, the token
that acted, and which fields changed, by name — not what you put in
them. Editing a session's note stores that the note changed; it does not store the note.
Values are kept only for a short list of things like identifiers and status words, and
anything outside that list — every free-text field, every body metric — is stored as
[redacted]. No IP address, no user agent. Entries are deleted 90 days after they are written, by a sweep that runs hourly. You can read your own trail through the API. An operator can still deliberately read across accounts, and when they do, that read is itself written into the same log. - Some records still have no expiry job. Generated summaries, feedback reports, revoked API tokens and used sign-in links sit until the account is deleted. That is a gap we would rather name than paper over with a retention period we are not enforcing.
-
Server log lines — 90 days. Our API writes one line for every request:
the route in its general form (
GET /v1/sessions/:id, never the id), the status, how long it took, and a request id. No account id, no IP address, no email address, and nothing you typed. The lines are collected into a log store on our own hardware and deleted after 90 days. Other lines carry more than that, and we would rather name them: a background summary that gives up for good records the account id it was working on; an error your app reports carries its message, its stack trace and the screen you were on; when Coach changes its memory it writes down the one-line description of the change it made, which can be about an injury; a webhook of yours that cannot be reached at all has its address written down; when an AI provider fails, its own message is recorded, which can quote back part of what was sent to it; and a request that fails unexpectedly records the failure's message, which for a database failure carries the values in the query that failed — the same caveat as the error reports above. -
Failed requests at our front door — until that program is next
replaced. Requests reach our API through a separate program on the same machine, which
hands them on. It writes nothing about a request that works. When one cannot be handed
on at all — our API is restarting, or the connection drops — it writes a single line
about that one failure, and that line holds more than the one above: the exact address
that was asked for, ids and all, your IP address, your country, and the name your app or
browser gives for itself. Your sign-in token and any cookies are written as
REDACTEDin place of their values, and no account id or email address appears at all. These lines stay on that machine and are not gathered into the log store above. Nothing deletes them on a schedule: they go when that program is next updated or its settings change. We would rather say that than name a period we are not keeping to. - Counts and timings — 90 days. How many requests each route served and how long they took, kept as running totals with nothing in them that identifies anyone. The store holding them is also capped at 4 GB, so a busy stretch can push the oldest out sooner than 90 days.
- Where the time went on an AI call — 30 days. Every time we call a model — a Coach reply, a background summary, the two lookups behind the exercise editor — we record which steps ran, which of Coach's tools they used, and how long each one took. This carries no part of your message, nothing Coach read to answer it, and nothing that says whose turn it was. Kept on our own hardware and deleted after 30 days.
- Failed sign-ins — about two hours. Ten wrong passwords for the same address within fifteen minutes lock it for fifteen more. That count is a row in the database rather than something the server forgets when it restarts, and the address is stored as a one-way fingerprint, never in readable form. The row is deleted once an hour has passed with no further attempt, by a sweep that runs hourly. Rate limiting is a separate thing: it counts IP addresses in memory and never writes them to the database.
- Database backups — snapshots on a rotation, which means a deleted account can persist in a backup until that backup ages out.
Deleting your account
Three ways, all the same erasure: Settings → Account → Delete account in the app,
rezist.ai/delete-account in any browser, or
DELETE /v1/account. Each one asks you to confirm your password first. It then
runs immediately, in one transaction. There is no grace period and no way to undo it, so
export first if you want a copy.
It erases your profile, sessions, workouts, routines, exercises, measurements, readiness check-ins, records, Coach conversations and memory, preferences, devices and push tokens, webhooks, subscription records, feedback reports, your marketplace listings and reviews, and your social graph. Your profile photo and every feedback screenshot are deleted from object storage. Change records are erased by every route that names you — as the subject, as the entity, or by the token that acted — so the billing history a store webhook wrote about you goes too, even though no token of yours created it. Cached counts on other people's listings and clubs are corrected so your departure does not distort their numbers.
What does not vanish the instant you press the button:
- Stored images take up to 30 days to disappear completely. Our object storage keeps previous versions so an accidental deletion is recoverable. Your photo and screenshots are removed from view immediately and permanently purged within 30 days.
- Anything you emailed us stays in our mailbox. Support threads, contact messages and the notifications we get about your feedback reports are not part of the account record and are not swept by deleting it. Ask and we will delete them too.
- A change record someone else caused can still mention your old @handle — for instance if a club owner removed you. The erasure follows your account id, not the handle, and the handle itself is released for anyone to take when you go. Those entries expire on the same 90-day clock as the rest.
- Backups. A snapshot taken before you deleted your account still contains it, until that snapshot ages out of the rotation.
If you cannot sign in at all, email privacy@rezist.ai from your account's address and we will delete the account for you.
Exporting your data
Settings → Account → Export, or GET /v1/account/export with a scoped token,
gives you a JSON file. Export is not behind a plan. It contains your profile, custom
exercises, workouts and their exercises and sets, routines, sessions and every performed
set, measurements and readiness check-ins, personal records, and Coach's current memory
notes.
It is the training record, not the whole account. It does not currently include your Coach conversations, generated summaries, the previous version of Coach's memory, feedback reports, registered devices, webhooks, subscription records, saved preferences, routine-as-code documents, your profile photo file, your passkey and two-factor enrolment, your API tokens, change records, or your social and marketplace data (follows, comments, listings, reviews, collections, clubs, challenges). Sessions you have archived are also left out, though everything else archived is included. We would rather say that than call it complete. If you want any of the omitted parts, email privacy@rezist.ai and we will assemble them for you.
Your rights
You can see and correct almost everything from inside the app: your profile and
demographics, every logged session, your measurements, Coach's memory, and your privacy
settings. Export and deletion are self-service, above. You can also pull your own change
records — every action taken on your account, and by which token — from
GET /v1/audit.
Depending on where you live you may also have the right to obtain a copy of your data, to have it corrected or erased, to restrict or object to how we use it, and to complain to your data protection authority. Email privacy@rezist.ai and we will respond within 30 days. We will not charge you for it and we will not treat you differently for asking.
We process your data to provide the service you asked for, to keep it secure and prevent abuse, and to meet our legal obligations. Where consent is the basis — notifications, dictation, Apple Health, a public profile — you give it by turning the feature on, and you can withdraw it by turning it off.
Security
Everything travels over HTTPS. Passwords are scrypt-hashed. Two-factor secrets and synced AI provider keys are encrypted with AES-256-GCM. API tokens are scoped, so a token minted for one job cannot do another. Stored photos and screenshots live in a private bucket with public access blocked and encryption at rest. You can add two-factor authentication or a passkey in Settings, and we recommend it. No system is perfectly secure; if we ever discover a breach affecting your data we will tell you and the relevant authority as quickly as we can establish the facts.
Age
Resistance is for people 13 and over, or the minimum age of digital consent where you live, whichever is higher. We ask for your date of birth when you create an account, and you cannot finish signing up without it — if the date puts you under the minimum, the account is refused.
We do not keep that date. It is checked at the moment you sign up, and all we record is that the check passed and when. The birth year on your profile is a separate, optional thing you add yourself to sharpen calorie estimates and coaching, and you can change or remove it at any time.
We cannot tell where you are, so we cannot check the second half of the rule — if your country sets a higher age than 13, meeting it is on you. We do not knowingly collect data from children. If you believe a child has an account, email privacy@rezist.ai and we will delete it.
Where your data is
Resistance is operated from the United States, and your data is stored there. If you use it from elsewhere — including the EU or the UK — your data is transferred to and processed in the United States, and by the providers on the subprocessor list, which operate globally. Where the law requires a transfer mechanism, we rely on the standard contractual clauses incorporated into those providers' terms.
Changes
When we add, remove or change a subprocessor, the change lands on the subprocessor list with its date. That is deliberate: which company runs a given piece of infrastructure should be a line item you can check, not a policy rewrite you have to re-read. When we make a material change to this policy, or add a subprocessor that receives your personal data, we will tell you in the app or by email.
Contact
Privacy questions, requests, or a correction to something on this page: privacy@rezist.ai. See also the subprocessor list and the Terms of Service.