Privacy Policy

Last updated: August 14, 2026. Operated by Steadfast Fitness Collective LLC, a Colorado limited liability company (“Steadfast,” “we,” “us”).

1. Information we collect

  • Account & profile: name, email, password (hashed), profile photo, and preferences.
  • Health & fitness data: workouts, personal records, goals, journal entries, readiness, and — if you connect a wearable (Apple Health, Health Connect, Oura, Polar, etc.) — recovery, HRV, sleep, heart rate, and body-composition metrics. Some of this is sensitive/special-category health data.
  • Optional cycle tracking: menstrual-cycle data, only if you enable it.
  • Payments: subscription and order details. We never see or store card numbers: a membership bought in the iOS app is billed by Apple and we receive only the transaction identifier, and card-billed memberships are processed by Stripe.
  • Library searches: what you search for in The Library, stored with your account and sorted into topics (for example Supplements, Recovery, Nutrition, Equipment). We use the aggregate to decide which sponsors and partners to bring to the collective. Because a wellness search can reveal a health interest, we treat these as health data under section 4.
  • Things you write and post: community posts and reactions, podcast comments, goals, direct messages with a coach, in-app feedback, and reports you file about content or another member.
  • Photos you upload: your profile photo and any photos you add to an event gallery.
  • What a coach writes about you: if you work with a coach, their session notes about your training. If you contacted us before joining, we may hold an enquiry record with your name, email, phone, and notes of the conversation.
  • Usage & device data: app interactions, and limited diagnostics for reliability and security. This includes a push notification token for each device you allow notifications on — a per-device identifier we keep until you ask us to remove it.

2. How we use your data

  • To provide the app: training, tracking, coaching, community, and commerce.
  • To personalize guidance, including the AI concierge, using only your own authorized data.
  • To process payments and memberships.
  • To decide which sponsors and partners to approach, using Library search topics in aggregate. Sponsors receive topic-level interest, never your name, email, or individual searches, and we do not sell your personal information.
  • To secure the service, prevent abuse, and meet legal obligations.

3. Service providers (data processors)

We share data only as needed with vetted processors under contract:

  • Apple — billing for memberships purchased in the iOS app.
  • Stripe — card billing for memberships set up that way.
  • Anthropic (Claude) — powers the AI concierge. Relevant data may be sent to generate responses. We require a data-processing agreement, do not permit training on your data, and retain AI conversations for no more than 12 months.
  • Cloudflare Stream — video hosting and delivery.
  • Sentry — error monitoring and session replay. A replay is a reconstruction of what happened on screen during a session. We record a small sample of sessions (about 1 in 100) and any session that hits an error, with all text masked and all images and video blocked, so the replay shows the shape of the screen rather than its contents.
  • Hosting and database infrastructure providers.

We do not sell your personal information.

4. Health data

Health and wearable data — including the Library searches described above — is used to power your training and recovery features and is never shared with other members without your action. You control wearable connections and cycle tracking and can disconnect or disable them at any time in Settings.

5. Your rights & choices

  • Access & export: download a copy of your data from Settings → Privacy.
  • Deletion: permanently delete your account and associated data from Settings → Privacy.
  • Correction & objection: update your profile, or contact us for other requests.
  • Depending on your location, you may have GDPR (EU/UK) or CCPA (California) rights; we honor verified requests.

6. Data retention

We keep your data while your account is active and delete or anonymize it after account deletion, except where retention is legally required (e.g., transaction records).

7. Security

We use encryption in transit, hashed passwords, role-based access controls, and security headers. No system is perfectly secure; please use a strong, unique password.

8. Children

Steadfast is not directed to children. You must be at least 16 years old (or the age of digital consent in your country) to use the service.

9. Changes

We will post updates here and adjust the “Last updated” date. Material changes will be notified in-app.

10. Contact

Questions or requests: privacy@steadfastfitnesscollective.com.