Subprocessors
A subprocessor is an outside company we use to run Resistance that can, in the course of doing its job, handle some of your data. This page names every one of them, what they do, and what actually reaches them. It is part of the privacy policy, which explains the flows in context.
Your training data is stored in a Postgres database on a server we run ourselves — not a managed cloud database. Aside from Cloudflare, which every request necessarily passes through on its way to us, most of what you do in Resistance is never handed to any company on this page.
When this changes. We update this page whenever a subprocessor is added, removed, or takes on a different job, and we date every change. If we add one that receives your personal data, we will say so here and — when the change is material — in the app or by email. Recording each change against the vendor it affects is deliberate: swapping the company behind a piece of infrastructure should be a line item you can check, not a policy rewrite you have to re-read.
AI providers
These receive data when you use Coach, when Coach writes a background summary after a workout, and when you make your own exercise. Everything else in Resistance — logging, history, charts, records, programs, the community — runs without them and sends them nothing.
-
Google
Training + health dataRuns the model behind Coach chat when Coach runs on our key, the model that titles and summarises a chat thread, and the comparison arm of the background summaries below. One such reply sends your message and conversation, Coach's memory verbatim (including injuries and limitations), your display name, age, height, sex, bodyweight and trend, the training data Coach reads to answer you — including the notes you wrote on a session or on an exercise in it — your readiness check-ins including the free-text note, and any photo you attached. It does not send the notes you write on a measurement. Our account is a paid API tier, so this data is not used to train Google's models.
-
OpenAI
Training + health dataRuns the primary model for background summaries — the review written after a workout and the weekly review, which run on every account. Receives the session's name and every set in it with weights, reps and effort, the notes you wrote on that session and on the exercises in it, up to four earlier sessions in the same detail, your entire all-time record table, weekly totals and per-muscle set counts, and your readiness check-in including that day's note, verbatim. By default the same prompt also goes to Google at the same time, so we can compare which model writes the better summary; both answers are stored with the summary indefinitely for our review, and you see one of them.
On the same key, also answers the two questions behind the exercise editor: which YouTube result actually demonstrates a movement, and whether the library already has that movement under another name. Those two calls carry the name, the kind of exercise and the equipment you have typed — and, for the duplicate check, the muscles you picked — alongside the candidate video titles or library entries they are choosing between. Nothing else from your account goes with them.
Infrastructure
-
Amazon Web Services
Photos and emailS3 stores your profile photo and any feedback screenshots, in a private bucket in the United States (US East, Ohio) with public access blocked and encryption at rest. SES delivers our outbound email — verification links, password resets, two-factor codes, support replies — so it handles your email address and the contents of those messages.
-
Cloudflare
All trafficDNS, TLS and CDN for rezist.ai, app.rezist.ai and api.rezist.ai; hosts this website and the web app's files; and carries the tunnel between the internet and our API server. Because it terminates the encrypted connection, it is in a position to see the contents of every request and response, not only the IP address, user agent and URL — sign-in, training data, uploads, all of it. It also renders the public profile and program pages on rezist.ai at the edge, and routes email sent to an @rezist.ai address. Any aggregate page-view count on this website comes from Cloudflare too.
-
Google (Gmail)
Email you send usThe mailbox behind our @rezist.ai addresses, including privacy@ and support@. Anything you email us — the message, attachments, your address and the headers that come with it — is delivered into a Google mailbox, as are the notifications we get when you file a feedback report or use the contact form. If you would rather not route a privacy request through Google, say so and we will arrange another channel.
-
YouTube search (Google)
Exercise namesWhen you make your own exercise, our server searches YouTube for a form video to suggest. The search text is the name and equipment you have typed plus the words "proper form tutorial", and the search is made from our server on our own key, so Google sees our address rather than yours. This is not the same thing as the thumbnails your device loads, further down.
-
Expo
Push and updatesDelivers push notifications, relaying them on to Apple's and Google's push systems: it receives your device's push token and the notification's title and body, which can carry text you wrote (a workout, club or challenge name) or another member's public @handle. Your device also contacts Expo directly to mint that token. Expo serves app updates as well, so at launch the app tells it the platform, version and — unavoidably — its IP address.
-
Sentry
Error reportsCollects crash and error reports so we can fix what breaks. Receives the error message, stack trace, release, platform and the exact address that failed. We attach no name, account id or email — but the failing address can contain an id or a public @handle, and a database error carries the query that failed together with its values, which can include free text you wrote or your email address. Reports are sent by our server, so Sentry sees our address rather than yours.
Payments
Card details never pass through our servers.
-
Apple
Purchase recordsHandles every subscription bought in the iOS app, and holds the payment relationship. We learn the product, the transaction id, and whether the subscription is active. (On iPhone, Apple also delivers your push notifications and stores your Health data — both covered above.)
-
RevenueCat
Purchase recordsValidates App Store receipts and tells our server what you are entitled to. Receives your Resistance account id together with the product and transaction ids.
-
Stripe
Purchase recordsHandles subscriptions bought on the web. You give Stripe your payment details directly, on their hosted checkout; we send them your Resistance account id so the subscription can be matched to it, and we receive the subscription's status and id.
Content your device loads directly
These are contacted by your browser or the app, not by our server, so they see your own IP address rather than ours. None of them receives your training data.
-
GitHub
Exercise imagesHosts the demonstration images for the built-in exercise library, which the app links to rather than copying. They load when you open an exercise or the exercise picker, so GitHub sees your IP address, your device's user agent, and the file name — which names the exercise you are looking at. There is no toggle for this today.
-
YouTube (Google)
Video thumbnailsSupplies the thumbnail images for form videos on some exercises, including any YouTube link you paste into an exercise you created. Loading a thumbnail tells YouTube your IP address and the video's id, which identifies the movement; in a browser it also sends whatever Google cookies you already have. Playing a video opens YouTube itself. There is no toggle for this today either. Finding a video to suggest in the first place is the separate server-side search above.
-
jsDelivr
Web page assetsA public CDN that serves the interactive viewer on our API documentation page. It sees your IP address if you open that page. No other page on rezist.ai loads anything from a third party.
Not subprocessors, but worth knowing
These receive data too — but at your instruction, or without passing through us.
-
The AI provider you choose yourself
Your own accountWith bring-your-own-key, Coach runs on OpenAI, Anthropic, Google, or any OpenAI-compatible endpoint you point us at — using your key, on your account, under your terms with them. They are your provider, not our subprocessor, which also means their training policy is the one that applies to your data.
-
Apple and Google speech recognition
Dictation audioWhen you dictate to Coach, your device's own speech recognizer handles the microphone. Depending on the device and browser, the audio may stay on the device or be sent to Apple or Google by the operating system. That is between you and your device — the audio never reaches us, and we only receive the text you choose to send.
-
Apple Health and Health Connect
Stays on deviceHeart rate and active energy recorded during an Apple Watch workout, and finished sessions written back to Health, live on your device and in your Health app. On Android the same finished sessions go to Health Connect, with their calorie estimate. None of it is uploaded to us. Once it is in Health it follows Apple's rules, including syncing to your own iCloud; Health Connect stays on the phone and is read only by the apps you allow. The mirroring is on by default and can be switched off in Settings; your phone asks your permission before the first write either way.
-
A webhook you configure
Your endpointIf you set one up, we send a small signed payload — a session id and a count of records set — to the URL you gave us. Where that goes is your choice.
Contact
Questions about anything on this page, or about a vendor we should be clearer about: privacy@rezist.ai. See also the privacy policy and the Terms of Service.