Privacy Policy
Effective July 30, 2026
This policy explains what Overload (“we”, “us”) collects when you use the iOS app and overloadai.app, why we collect it, and the controls available to you. We collect the data needed to run your training program. You can delete your account and cloud data in the app.
What we collect
- Account. When you sign in with Apple or Google we receive an account identifier and, unless you hide it, your email address. Sign in with Apple lets you use a private relay address.
- Training setup. Your onboarding answers: goal, experience level, schedule, available equipment, and any body areas you ask the plan to work around. We treat the work-around list as a training preference and use it to filter exercise selection.
- Training data. Your program, logged workouts and sets, personal records, and plan-edit history. Stored locally on your device first (offline-first) and synced to our backend (Supabase) so your history survives phone changes.
- Purchases. Subscription status via RevenueCat and Apple. Apple handles payment details.
- Usage analytics. Product events (e.g., onboarding steps completed, feature usage) via PostHog, tied to a pseudonymous identifier, to improve the app. No advertising trackers, no data brokers.
AI processing
AI coaching is optional and off until you affirmatively enable it. When enabled, our Supabase backend sends only the information relevant to your request to OpenAI: your training goal, experience, equipment, exercise preferences, work-around selections and, when applicable, your Coach message, workout plan, or logged sets. OpenAI processes this data to personalize plan structure, explanations, weekly reviews, and validated replanning proposals. Requests are configured with storage disabled. The deterministic Overload engine—not OpenAI—controls and validates sets and weights.
If you choose Not now, no training data is sent to OpenAI and Overload builds a standard deterministic program. You can enable or revoke AI processing at any time in the app under You → AI coaching data. After revocation, new training data and messages are not sent to OpenAI.
What we don't do
- We don't sell or rent your personal data.
- We don't run third-party ads or ad trackers.
- Version 1.0 does not access Apple Health. If we add an Apple Health integration later, we will ask for permission and update this policy before collecting or writing Health data.
Service providers
We use a small set of processors to run Overload: Supabase (database, auth, hosting of our API), RevenueCat (subscription status), PostHog (product analytics), Apple (payments, notifications), Cloudflare (this website), and OpenAI (optional AI plan structure and coaching text). Each receives only what it needs to do its job.
Retention and deletion
We keep your data while your account exists. Delete your account in the app (You → Delete account) to permanently remove your account and cloud training data; local data is removed with the app. You can also email support@overloadai.app and we'll delete it for you. Backups age out within 30 days.
Your rights
Depending on where you live (e.g., GDPR, CCPA), you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. Email us to exercise those rights.
Security
We encrypt data in transit, restrict access to production systems, and keep service credentials out of the app. No system can guarantee perfect security.
Children
Overload is not directed at children and requires users to be at least 16.
Changes
If we change this policy materially, we'll notify you in the app or by email before the change takes effect. The effective date above always reflects the current version.
Contact
Privacy questions or requests: support@overloadai.app.