PRIVACY
What we store, and who can reach it.
Apple Health (HealthKit)
XR Fit can read from and write to Apple Health on your iPhone and Apple Watch, with your permission. You grant or revoke each category yourself in the Health app, and XR Fit cannot read anything you have not allowed.
What we read: workouts, heart rate, resting heart rate, active energy, steps, walking/running distance, cycling distance, running speed, VO2 max, cycling FTP, body mass, body fat percentage, lean body mass, height, and sleep analysis.
What we write back: workouts you complete in XR Fit, along with their active energy and their walking/running, cycling or swimming distance.
Where it goes. Health data does not stay only on your phone. A completed workout — including the heart rate and calorie figures read from Apple Health — is stored on your XR account on our servers so it is available on your other devices and on the web. If you connect Strava and push a workout to it, those same heart-rate and calorie figures are sent to Strava through our servers.
What we do not do with it. XR Fit contains no advertising, analytics or tracking software, and your Health data is not used for advertising.
Camera and photos
XR Fit can read a workout written on paper, a whiteboard or a screen from a photo of it, and can work out what equipment a gym has from photos of the gym. You can take the photo with the camera or choose one you already have; scanning a gym uses photos you choose.
What we read: only the photos you hand over for that one job. Choosing an existing picture goes through Apple's own picker, which runs outside XR Fit and returns just what you selected, so the rest of your library is not visible to the app.
What we do with it. The photo is analysed by an AI model, which reads the written workout into an editable plan you review before anything is saved, or lists the equipment it can see so a session can be built around it. That analysis does not run on your phone.
Where it goes. The photo is sent to our servers inside the request and forwarded from there to the AI provider that performs the analysis — a company outside XR. We do not keep the image: it is not written to our file storage and it is not saved with your workout. What we record is that a request was made, and for which feature.
Motion (Apple Watch)
The XR Fit app on Apple Watch reads how the watch is moving in order to count your reps. The iPhone app does not read motion at all.
What we read: the watch's acceleration and orientation, sampled about fifty times a second while a set is running, and only while a set is running. XR Fit does not read your step count and does not use your watch's all-day activity data.
What we do with it. The watch turns that movement into your rep count and how fast the bar moved — a speed for each rep and an average for the set. The calculation happens on the watch as you lift.
Where it goes. The movement samples themselves are used to count the reps and then discarded; they are never stored. The results are kept: your reps, the per-rep speeds and the average bar speed are sent to your iPhone, saved with that set, and stored on your XR account on our servers along with the rest of the workout.
iCloud (your own Apple account)
XR Fit on iPhone keeps its training database in iCloud as well as on the device. That means a second copy of your training data sits in your own Apple account, separate from the copy on your XR account on our servers.
What syncs: the app's training database — your workouts and every set in them. That includes the heart-rate and calorie figures read from Apple Health and saved with a completed workout, and it includes the pain rating and the pain note you type against a set.
What it is for. The copy keeps your training history in step across the Apple devices signed in to your Apple account.
Where it goes. Into the private area iCloud gives an app for one person's own data, under your Apple account. It is held by Apple under your account rather than by us, we cannot read it, and it is covered by Apple's terms for iCloud rather than by this page.
AI coaching
When you use coaching, photo import or gym-equipment scanning in XR Fit, what you send goes to our server, and our server calls Anthropic using a key we own. Your device does not talk to Anthropic directly. We record that a call happened: which app, which feature, which AI provider and model, how many tokens, whether it succeeded, and a short error code if it did not. We keep it so we can see cost and reliability. That record contains no text you wrote. It is tied to your account, and no other account can read it.
And for coaching features that search our training library, we also store the question you asked, in full, linked to your account. We keep it to improve how well the library answers. It is not readable by you or by any other account — only our servers reach it. Like everything else we hold, it is not deleted or expired automatically today.
XR Fuel works differently. Its AI features run on your own key from Anthropic or OpenAI, which you add in the app. Your device sends those requests directly to the provider you chose, under your own account with them. They do not pass through our servers, and we do not record them. What that provider keeps is governed by your agreement with them.
XR Kitchen does not use AI.
XR Health does not use AI at all. Its coaching engine declares no network endpoints and needs no API key, and there is no network call anywhere in that feature. Nothing you enter in XR Health is sent to an AI provider.
We have not independently confirmed what Anthropic or Voyage AI retain of what they receive, or for how long.
Who else touches your data. For these features, the AI companies involved are:
- Anthropic — coaching, workout-photo import and gym-equipment scanning in XR Fit. Not XR Health, not XR Kitchen. (XR Fuel is different. Its AI features use your own key, directly with the provider you choose.)
- Voyage AI — makes our training library searchable. When a coaching feature searches that library, the question you asked is sent to Voyage to find matching material.
Errors and logs. Our server keeps three kinds of record when something happens, and they hold different things:
- The usage record for AI features (above). Account, app, feature, provider, model, token counts, success, and a short error code. No text you wrote.
- The question you asked a coaching feature that searches our library (above), in full. This is the one record where your own words are kept.
- Operational logs and error reports (Sentry). Before writing these, our server removes values stored under labels that look personal: email, phone, address, date of birth, tokens, passwords and other credentials.
We want to be exact about that last point’s limit. The filter works by label, not by content. It cannot recognise personal information inside free text. An error message raised by an underlying system is recorded as it arrives, so if such a message ever quoted something you entered, the filter would not remove it.
What we store
The training, nutrition, meal-planning and lab data you enter, and the account identity your sign-in provider gives us — an email address and a provider identifier. Two of the things you enter are about pain and injury, and are named here rather than left inside that general description: when you log a set you can record how much pain you felt, as a rating from 0 to 10, and a note about it in your own words; and your athlete profile holds a free-text description of injuries, niggles or movement restrictions that you write yourself. All of it is kept on your XR account, on our servers, not only on the phone or browser you entered it from. The pain rating and the pain note also sit in the iCloud copy of the training database described above; the profile description does not.
What we never see
Your password. Sign-in runs entirely through Apple or Google; we receive a token that confirms who you are, never a credential. There is no email-and-password path anywhere in the product.
Who can reach your records
You. Isolation is enforced at the database itself rather than by application code, so a query for another athlete's data does not return it even if a bug asks for it. This is a structural guarantee, not a policy promise.
What we do not do
We do not sell your data, and we do not share health or training records with advertisers. Your data is not used to build audience segments.
XR Health lab data specifically
Lab markers and adherence records entered into XR Health are treated as the most sensitive data in the system. XR Health does not provide medical advice, does not recommend protocols and does not surface doses.
