Tack Back to Tack ↗

YOUR TRAINING. YOUR PRIVACY.

Privacy policy.

Last updated
Applies to the Tack iPhone app, web app, and supporting services.

The short version

Your workout history and settings are stored on your device. Cloud coaching and optional direct wearable connections also process information through our service providers.

We do not sell personal information or use health data for advertising. You do not need a Tack account. Apple Health access, wearable connections, and notifications are optional.

1. Information we use and why

Notes and messages may contain sensitive information you enter. Please avoid including information that is not needed for your training.

2. Apple Health and connected wearables

Apple Health

With permission, Tack reads supported sleep, heart rate, resting heart rate, heart-rate variability (HRV), steps, active energy, and workout information. Summaries and baselines help estimate readiness and adapt training. Tack does not write data to Apple Health.

Health summaries are stored locally. Share with coach controls whether explicit recovery measurements and source-specific scores are included in cloud requests. Readiness and adapted recommendations may still reflect health information when that setting is off; see AI coaching below.

Oura and WHOOP

Where enabled, you can connect Oura or WHOOP through the provider’s authorization screen. Tack does not receive your provider password. Our backend exchanges your permission for access and refresh tokens, which it stores encrypted to maintain the connection. A random installation credential links your device to its server connection.

Authorized recovery, sleep, and activity information passes through our backend during sync. This can include Oura Readiness or WHOOP Recovery and Strain, HRV, resting heart rate, sleep duration, and workout summaries. The current summary is saved on your device; we do not maintain a separate server-side health-history database.

Direct connections sync on request and periodically when you return to Tack, not continuously while the app is closed. You choose one recovery source for readiness. Garmin direct connection is not currently enabled. Supported measurements shared by other apps through Apple Health follow the Apple Health path above.

Health information is used for training and recovery features, not advertising, data brokerage, or unrelated profiling. Connecting a provider does not enable the separate Share with coach setting.

3. AI coaching and third-party processing

The cloud coach uses Anthropic’s Claude API through a backend hosted on Netlify. Requests may occur when you message the coach or when Tack generates or refreshes a daily coach note.

Context can include your profile, current check-in, readiness score, recommended workout and rationale, plan adjustments, active and recently completed workouts, logged sets, notes, reflections, progress totals, recent conversation, and the coach’s saved memory summary.

With Share with coach enabled, the selected recovery source’s measurements and scores are also included. Turning it off excludes those explicit source fields, but does not remove health-derived information already reflected in readiness, recommendations, session records, saved coach memory, or messages you type. It does not delete previous requests.

We do not maintain a server-side conversation database. Anthropic processes content to generate replies and may retain it under its commercial API policies. Its published standard is deletion of API inputs and outputs within 30 days, subject to exceptions for safety, legal requirements, or agreed arrangements. Commercial API content is not used for model training by default. See Anthropic’s retention policy and training policy.

When cloud access is unavailable, Tack can provide built-in local guidance. Tack is a fitness planning tool, not a medical service or emergency monitoring system.

4. Notifications, exports, and external content

iPhone Calendar: on iOS 17 or later, you can approve adding the next eight weeks of planned workouts directly to your default calendar. Tack requests write-only calendar permission, not access to read your existing events. Calendar events include workout titles, dates, durations, general notes, and an optional alert—not your readiness scores or health measurements. They may sync through your calendar account (such as iCloud). Tack keeps a local record of dates it added to prevent repeat additions on this installation; it cannot detect calendar edits or deletions. This is a one-time copy, not live synchronization. Manage saved events in Calendar; disabling Tack reminders or deleting Tack does not remove them.

Notifications: optional iPhone reminders are scheduled locally from your selected times, plan, check-ins, and completed workouts. No push-notification service receives health data for these reminders. Alerts contain general encouragement rather than health measurements or exercise details. iPhone notification and Focus settings control presentation.

Backups: you choose where to save or share an export. Backup files can contain profile, workouts, conversations, and saved health summaries; treat them as sensitive. Direct wearable authorization credentials are excluded. Calendar exports contain planned training events. Copies you save elsewhere follow that destination’s policies and are not removed when you delete Tack.

External services: Netlify hosts the web app, backend, and connection storage. App fonts can load from Google Fonts. Exercise guides may load YouTube thumbnails or embedded videos; playing a demonstration can open YouTube. These services receive technical request information, such as IP address, and apply their own policies. See Netlify’s privacy policy and Google’s privacy policy.

Tack does not include advertising or analytics SDKs or request your contacts, photos, or precise location.

5. Storage, security, and deletion

Device records: local data remains until removed with the app or browser’s site storage. Deleting an iPhone app differs from offloading it, which can preserve data. Exported copies and device backups may remain separately.

Wearable connections: encrypted tokens and connection/sync information remain on the server until you disconnect. While online, use Profile → Connected devices → your provider → Disconnect. This removes the server connection and current local summary and attempts to revoke provider access. If revocation fails, revoke Tack in the provider’s settings too.

Disconnecting does not erase earlier readiness history, workouts, or coach content. Deleting Tack alone does not remove server connection records or revoke provider access. Disconnect first, or contact us for help. Without the original installation, we may need more information to securely locate a connection.

Operational records: installation-linked counters and timestamps support rate limits. A counter’s reset time does not guarantee deletion of its stored record. Provider logs and API content follow the applicable provider retention arrangements.

Production backend requests use HTTPS, and wearable tokens are encrypted at rest by Tack. Local records rely on your device’s protections. No system is completely secure. Service providers may process information in countries other than your own.

6. Your choices and privacy requests

We may request information needed to verify and locate your request and will handle it as required by applicable law. Please do not email passwords, tokens, or unnecessary health details.

7. Children and policy updates

Tack is not directed at children under 13. If you believe a child has provided information through Tack, contact us so we can investigate and address it.

We may update this policy as the app changes. The date above identifies the latest version. Material changes requiring additional notice or permission will be addressed before the relevant new use.

Questions about your data?

Contact Tack about this policy or a privacy request:

info@trainwithtack.com