FLEX Privacy Policy

Effective September 22, 2026

FLEX is a workout tracking app for saving routines, workout history, body metrics, and optional AI-generated workout plans. This policy explains what data FLEX handles, why it is used, and how deletion works.

Data We Collect

How We Use Data

FLEX uses your data to authenticate your account, sync your workout history across devices, restore backups, display progress, import workout files, generate workout plans when you request AI assistance, and investigate bug reports you choose to submit.

Sync And Third-Party AI Sharing

When sync is enabled, your workout logs, routines, custom exercises, body metrics, and sync metadata are sent to the FLEX sync server. Before each AI generation or refinement request, FLEX asks for your permission to send your typed or dictated description, selected goals and training preferences, optional notes, and compact exercise catalog through a Supabase Edge Function to OpenRouter and its AI model providers, such as OpenAI. Refinements also include your current plan and requested changes. Canceling the permission prompt sends no AI request. Do not include sensitive medical information in your request. You can continue using the rest of FLEX without AI.

Direct Routine And Program Sharing

When you choose to share a routine or program, FLEX uses the exact email address or username you enter to find the recipient and delivers a copy with your sender identity. The copy contains the routine or program name, exercise definitions, and training targets. Personal notes, saved weights, workout history, body measurements, and private media URLs are excluded. FLEX stores delivery records, sharing usernames, and blocked-sender preferences. Recipients can keep independent copies they save to their own library, including after you change the original or delete your account. Deleted accounts' former usernames remain reserved without their account identifier to prevent impersonation.

Bug Reports And Email Delivery

When you report shared content, FLEX stores the shared copy, sender identity, your account identifier, report reason, and any details you choose to provide in a private moderation queue. Reports are accessible to authorized FLEX administrators, not to the reported user or other app users. Reporting also blocks the sender and hides the delivery. Associated reports are removed if either account is deleted. Moderation decisions and sharing suspensions are stored to enforce the community rules.

When you submit a bug report, FLEX sends the report message, optional images, your account email and user ID, app version, current app page, and basic device information through a Supabase Edge Function and Resend to FLEX support. This information identifies who submitted the report and allows support to reply. Images and report messages are not stored in the FLEX database; the database stores only limited submission and delivery metadata for rate limiting and operational reliability.

Optional Product Analytics

FLEX does not create an analytics identifier or collect product-analytics events unless you explicitly select Allow Analytics. If allowed, FLEX uses the analytics data listed above to understand feature use, diagnose product issues, and improve the app. FLEX does not use this information for advertising or to track you across other companies’ apps or websites. You can allow or decline at any time in Profile > Data & Privacy. Withdrawing consent stops future collection and removes the queued events and analytics identifier stored on that device. Analytics already received by FLEX is retained until account deletion or an applicable deletion request.

Payments And FLEX Pro

Apple processes iOS purchases, and RevenueCat processes subscription entitlement information for iOS and web purchases. FLEX receives entitlement and transaction status needed to unlock Pro, restore purchases, prevent fraud, and provide support. Payment providers handle payment credentials under their own privacy policies. Tester codes are stored as one-way hashes; FLEX records the account that redeemed a code and the resulting access expiration date.

Retention

Server sync and linked analytics data are retained while your account remains active. Local data remains on your device until you delete it, uninstall the app, clear browser storage, or delete your account from inside FLEX. Bug-report messages and images are retained in the support mailbox and by the email delivery provider as needed to investigate and respond to the report.

Account Deletion

You can delete your account in FLEX from Profile > Data & Privacy > Delete Account. Deletion removes your server user row, stored sync payload, active sessions, linked provider records, auth rate-limit records, AI usage records, linked analytics events and identifiers, RevenueCat customer profile when configured, and bug-report delivery metadata. The app also removes local workouts, body metrics, routines, templates, custom exercises, AI history, analytics identifiers, and profile preferences for the signed-in account on that device. Deleting a RevenueCat customer does not cancel an Apple subscription; manage or cancel the subscription in your Apple Account. Deleting an account does not automatically delete bug reports already delivered to the support mailbox.

Fitness And Health Notice

FLEX is for general fitness tracking and workout planning. Body metrics and AI-generated plans are not medical advice. Use your judgment and consult a qualified professional before making medical, injury, nutrition, or treatment decisions.

Security

FLEX uses HTTPS for hosted services, password hashing for password accounts, session tokens for authenticated requests, CORS allowlists, request size limits, and rate limits for authentication and AI usage. No internet-connected service can be guaranteed completely secure.

Contact

For privacy questions, support, or deletion help, contact support@duffyadams.com.