English ↓
setpad 개인정보 처리방침
시행일: 2026년 9월 24일
주식회사 다락스튜디오(이하 "회사")는 운동 기록 앱 setpad(이하 "앱") 이용자의 개인정보를 「개인정보 보호법」에 따라 처리합니다. 이 방침은 앱이 어떤 정보를 기기 밖으로 보내는지, 누가 그것을 받는지, 얼마나 보관하는지를 사실 그대로 적습니다.
요약
- 운동 기록, 세트 메모, 식단은 기본적으로 이용자의 기기에 저장됩니다. 혼자 기록하는 데는 계정이 필요 없습니다.
- 앱을 켜면 무작위 기기 식별자를 회사 서버(싱가포르)로 보내 AI 요청용 임시 토큰을 받습니다.
- 문장 해석(기록 검색 질문, 한 줄 설정, 식단 글·사진의 열량 추정)은 앱이 처음 쓸 때 동의를 받은 뒤에만 회사 서버를 거쳐 DeepSeek(중국)의 AI가 처리합니다. 동의하지 않거나 설정에서 끄면 보내지 않습니다. 회사 서버는 그 내용을 저장하지 않습니다.
- 운동 이름 칸에 친 글이 음식인지 가리려고 회사 서버의 음식 표(식약처·USDA)에 같은 이름이 있는지 묻습니다. AI가 아니며, 친 글은 저장하지 않습니다.
- 로그인하면 이름(닉네임)과 로그인 식별자를 저장합니다. 이메일은 저장하지 않습니다.
- 도장 연결, 같이 하기(여럿이 한 기록을 실시간으로 같이 고치기), 기록 건네기, 공동 루틴을 쓰면 그 기록이 서버를 거쳐 도장이나 상대에게 전달됩니다.
- Apple 건강·헬스 커넥트에서 읽은 활동 칼로리와 심박수는 기기 밖으로 보내지 않습니다.
- 광고와 분석(애널리틱스) 도구를 쓰지 않습니다.
1. 처리하는 개인정보 항목
1-1. 앱을 켜면 보내는 정보 (로그인하지 않아도)
- 기기 식별자: 앱이 처음 켜질 때 만드는 무작위 값입니다. 앱을 켤 때마다 이 값을 서버에 보내 AI 요청용 임시 토큰(30일)을 받습니다. AI 해석 기능을 쓰면 이 값이 요청 횟수를 세는 이름표로 서버에 저장됩니다.
- 요청 횟수 집계: 과도한 요청을 막기 위해 날짜별 요청 횟수를 셉니다. 회사 데이터베이스에는 IP 주소를 저장하지 않고, 회사만 가진 비밀 키로 변환한 값으로 셉니다.
- 이용권 판매 여부 조회: 이용권을 파는지 확인하는 요청을 보냅니다. 개인정보는 담기지 않습니다.
- 원판(AI 사용량) 장부: 기록 질문에는 AI 사용량 단위인 원판이 듭니다. 지갑(기기 식별자, 로그인했으면 계정)마다 받은 원판과 쓴 원판을 서버에 적습니다. 쓴 양은 그 질문에 AI가 실제로 쓴 토큰 수로 계산합니다.
- 하루 원판: 하루에 세트를 10개 이상 기록하면 원판 1장을 받습니다. 이때 그날의 세트 수(숫자 하나)만 보냅니다. 기록 내용은 보내지 않습니다.
1-2. AI 해석을 위해 보내는 정보 (동의한 경우에만, 회사 서버는 저장하지 않음)
앱은 아래 기능을 처음 쓸 때 DeepSeek으로 무엇이 가는지 보여 주고 동의를 묻습니다. "나중에"를 고르거나 앱의 설정 → AI 도움 (DeepSeek)에서 끄면 아래 어느 것도 보내지 않으며, 친 글과 직접 적은 열량은 기기에 그대로 기록됩니다.
- 기록 검색 질문: 기록 검색창에 문장을 쳐서 제출하면 보냅니다(운동 이름만 치면 보내지 않습니다). 해석을 돕기 위해 이용자 기록의 운동 이름 목록(최대 60개)을 함께 보냅니다. 로그인해 있으면 계정으로, 아니면 기기 식별자로 요청합니다.
- 한 줄 설정: "벤치 80kg 100개 채우기"처럼 숫자가 든 줄을 운동 이름 칸에 치면, 그 문장과 비슷한 운동 이름 목록을 보냅니다. AI는 그 줄이 운동인지 음식인지도 가립니다.
- 식단 글: AI 도움에 동의했으면, 열량을 적지 않은 끼니는 열량을 추정하기 위해 자동으로 보냅니다.
- 식단 사진: 이용자가 촬영하거나 고른 사진을 1024px로 줄이고 촬영 정보(위치, 기기, 촬영 시각)를 떼어 보냅니다. 연결한 도장과 끼니 종류(아침·점심 등)가 함께 갑니다. 사진은 회사 서버에 저장하지 않으며, 처리하는 동안 앱의 임시 폴더에 남을 수 있고 운영체제가 정리합니다. 추정 결과(음식 이름, 열량)만 기록에 남습니다.
1-2-1. 음식 표 조회 (AI 아님, 저장하지 않음)
- 운동 이름 칸에 친 줄이 운동으로 보이지 않으면, 그 글(최대 200자)을 회사 서버로 보내 음식 표(식약처 식품영양성분 DB·USDA FoodData Central)에 같은 이름이 있는지 확인합니다. AI 도움 동의와 상관없이 동작하며, 친 글은 저장하지 않고 요청 횟수만 셉니다.
1-3. 로그인할 때
- 로그인 식별자: Apple 또는 Google이 알려 주는 계정 고유번호. Apple 로그인은 이메일을 요청하지 않습니다. Google 로그인 토큰에는 이메일이 들어 있을 수 있지만, 회사 서버는 계정 고유번호만 읽고 이메일을 저장하지 않습니다.
- 이름(닉네임): Apple·Google 계정에 등록된 이름을 그대로 씁니다(최대 20자). 이름을 받지 못하면 "도전자"로 정합니다. 지금은 앱에서 바꿀 수 없으며, 연결한 도장과 함께 운동하는 상대가 이 이름을 봅니다.
- Apple 로그인 연결 정보: 탈퇴할 때 Apple에 로그인 연결 해지를 요청하기 위한 토큰.
- 로그인해도 개인 기록은 서버에 백업되지 않습니다.
1-4. 이용권을 구매할 때
- 스토어가 발급한 구매 번호(Google Play 월 이용권은 구매 토큰), 상품, 만료일, 영수증을 확인한 기록. 카드 번호 등 결제 수단 정보는 받지 않습니다(결제는 Apple·Google이 처리).
1-5. 이용자가 선택한 기능을 쓸 때
- 도장 연결: 연결한 도장에서 한 운동의 시작 시각, 운동 이름, 무게, 횟수, 완료 여부(세트 메모는 보내지 않음. 빈 기록도 출석으로 보냄), 기록에 남긴 끼니(날짜, 끼니 종류, 글, 음식 이름, 양, 열량 — 열량이 없어도 보냄), 회원 신청, PT 예약.
- 같이 하기: 최대 6명이 실시간으로 같이 고치는 한 기록(운동 이름, 세트, 세트 메모, 그 세트를 적은 사람의 이름), 지금 고치는 자리와 치고 있는 글(최대 80자 — 상대 화면에 커서로 보입니다), 각자 공유하는 운동 기록, 같이 쓰는 타이머 설정(제목, 박자, 타바타 구간), 이름.
- 기록 건네기: 상대를 대신해 적은 기록과, 이용자가 붙인 상대의 이름.
- 공동 루틴: 루틴 제목, 예정일, 종목, 세트 수, 각자의 목표(무게, 횟수, 메모). 로그인해 있으면 초대하기 전의 초안도 서버에 저장됩니다.
- iPhone 근접 초대: 초대 토큰과 제목이 Apple의 SharePlay를 거쳐 상대 기기로 전달됩니다.
1-6. 기기에 저장하는 정보
- 운동 기록, 세트 메모, 식단, 같이 하기에서 받은 상대 기록의 사본, 설정, 로그인 토큰(앱 전용 저장공간의 파일), 기록 검색에 쓴 질문과 그 해석 결과.
- 이 파일들은 기기 설정에 따라 iCloud 기기 백업 또는 Android 자동 백업에 포함될 수 있습니다.
2. 건강 데이터 (Apple 건강 / 헬스 커넥트)
이용자가 권한을 허용한 경우에만 다음을 주고받습니다.
| 종류 | 쓰기·읽기 | 쓰는 곳 |
| 운동 | 쓰기 | 기록을 마치면 그 운동을 운동 세션으로 남깁니다. 기록 제목과 활동 칼로리가 함께 들어갑니다. |
| 활동 칼로리 | 읽기 | 운동한 시간 동안 워치가 잰 활동 칼로리를 그 기록에 붙입니다. 잰 것이 없으면 칼로리를 표시하지 않습니다. |
| 심박수 | 읽기 | 타바타 타이머의 휴식 중 심박이 그 라운드의 최고치보다 25bpm 내려오면 휴식을 끝내고 다음 라운드 시작을 알립니다. 쉬는 동안 타이머에 현재 심박과 목표가 보입니다. iPhone에서는 운동 기록을 마친 뒤부터 워치가 심박을 기록할 때 앱이 깨어나 값을 읽고, 전달 지연을 재기 위해 기기 안의 로그에 남깁니다. |
- 건강 앱에서 읽은 값은 회사 서버나 제3자에게 보내지 않으며, 광고·마케팅에 쓰지 않습니다.
- iOS 26.1 이상에서 경보를 허용하면, 심박으로 휴식이 끝날 때 시스템 경보가 울리고 짝지은 Apple Watch로 전달됩니다. 경보에는 건강 데이터가 담기지 않습니다.
- 권한은 언제든 끌 수 있습니다. iPhone: 설정 → 개인정보 보호 및 보안 → 건강 → setpad. Android: 헬스 커넥트 → 앱 권한 → setpad.
3. 수집 방법
이용자가 앱에 직접 입력하거나 기능을 실행할 때 앱이 보냅니다. 로그인 정보는 Apple·Google 로그인 과정에서, 구매 정보는 스토어 결제 과정에서 받습니다.
4. 처리 목적
- 문장 해석, 식단 열량 추정 등 앱 기능 제공
- 회원 식별, 이용권 확인과 복원
- 도장 연결, 같이 하기, 기록 건네기, 공동 루틴 등 이용자가 선택한 공유 기능 제공
- 과도한 요청 방지와 서비스 안정 운영
5. 보유 및 이용 기간
| 정보 | 보유 기간 |
| AI 해석 요청(질문, 문장, 식단 글·사진) | 회사 서버는 저장하지 않습니다. 응답을 만든 즉시 버립니다. |
| 계정(로그인 식별자, 이름), 이용권, 도장에 보낸 운동·끼니·예약·회원 신청, 내가 만든 공동 루틴과 내 목표, 내가 건넨 기록 | 회원 탈퇴 시 삭제합니다. |
| Apple 로그인 연결 정보 | 로그인해 있는 동안 보관합니다. 탈퇴하면 즉시 Apple에 해지를 요청하고, 요청이 실패하면 암호화해 두었다가 다시 요청하며, Apple이 확인하면 삭제합니다. |
| 같이 하기 기록 | 같이 고친 기록과 커서 정보는 같이 하기가 끝나면 삭제합니다. 도중에 나가면 내가 공유한 기록 사본은 바로 삭제하고, 같이 고친 기록에 남긴 내 세트는 그 같이 하기가 끝날 때 삭제합니다. 아무도 끝내지 않으면 탈퇴할 때까지 남습니다. |
| 음식 표 조회 | 친 글은 저장하지 않습니다. 날짜별 요청 횟수만 셉니다. |
| 건넨 기록의 링크 | 마지막으로 고친 때부터 7일 동안 열립니다. 링크를 가진 사람은 누구나 그 기록과 보낸 사람의 이름을 볼 수 있습니다. |
| 요청 횟수 집계 | 기기 식별자·변환한 IP 값별 날짜 집계로, 탈퇴와 무관하게 남습니다. |
| 원판 장부 | 계정 지갑은 탈퇴 시 삭제합니다. 기기 지갑은 남습니다. |
| 기기의 기록 | 이용자가 지우거나 앱을 삭제할 때까지 기기에 남습니다. 회원 탈퇴로는 지워지지 않습니다. |
탈퇴해도 다음은 남습니다: 도장의 결제 장부와 변경 이력(이름을 뗀 채로), 다른 사람의 공동 루틴에 이용자가 고친 내용, 다른 사람이 이용자를 위해 적어 건넨 기록, 다른 사람이 연 같이 하기에서 같이 고친 기록에 남긴 이용자의 세트(적은 사람 이름 포함, 그 같이 하기가 끝날 때까지). 도장의 관장·트레이너는 도장을 정리한 뒤에 탈퇴할 수 있습니다. 도장이 직접 입력하는 회원 정보(메모, 체성분, 이용권, 결제)는 도장이 관리하며 이 방침의 범위 밖입니다.
6. 개인정보의 제3자 제공
회사는 이용자의 개인정보를 제3자에게 판매하거나 제공하지 않습니다. 다만 이용자가 직접 선택한 다음 기능에서는 그 상대가 정보를 봅니다.
- 연결한 도장(관장·트레이너): 이름, 도장에서 한 운동 기록, 기록에 남긴 끼니, 예약.
- 같이 하기·기록 건네기·공동 루틴의 상대: 이름과 이용자가 공유한 기록.
7. 개인정보 처리의 위탁
| 수탁자 | 위탁 업무 | 처리하는 정보 |
| DeepSeek (Hangzhou DeepSeek Artificial Intelligence Co., Ltd.) | 문장 해석, 식단 열량 추정(AI) — 이용자가 동의한 경우에만. 트레이너 모드 보고서의 문장 | 기록 검색 질문과 운동 이름 목록, 한 줄 설정 문장과 비슷한 운동 이름 목록, 식단 글, 식단 사진. 트레이너 보고서는 도장 이름, 재등록 안내 문구, 건수, 회원별 사유(예: "3일 뒤 만료")와 상품명·가격만 보냅니다(회원 이름·연락처·식별자는 보내지 않음). 요청에는 이용자를 가리키는 값(계정, 기기 식별자)을 싣지 않습니다. |
| Railway | 서버와 데이터베이스 호스팅 | 기기 식별자, 요청 횟수, 원판 장부, 계정, 이용권, 공유 기록, 그리고 서버를 지나기만 하는 AI 요청 내용 |
| Apple Inc. | Apple 로그인, App Store 결제 확인, SharePlay 근접 초대, 경보의 워치 전달 | 로그인 식별자, 구매 기록, 초대 토큰 |
| Google LLC | Google 로그인, Google Play 결제 확인 | 로그인 식별자, 구매 기록 |
8. 개인정보의 국외 이전
| 받는 자 | 국가 | 이전 항목 | 이전 일시와 방법 | 목적·보유 기간 |
| DeepSeek | 중국 | 7장의 AI 처리 정보 | 해당 기능을 쓸 때마다, 암호화된 통신(HTTPS)으로 | 응답 생성. 보유는 DeepSeek의 방침에 따릅니다. |
| Railway | 싱가포르(서버 위치) | 7장의 Railway 처리 정보 | 앱이 서버와 통신할 때, 암호화된 통신(HTTPS)으로 | 서비스 제공. 5장의 기간 동안. |
AI 도움에 동의하지 않거나 설정에서 끄면 앱은 DeepSeek으로 가는 요청을 보내지 않습니다. 다만 앱은 켤 때마다 기기 식별자를 회사 서버(싱가포르)로 보내고, 운동 이름 칸에 친 줄은 음식 표 조회(1-2-1)를 위해 회사 서버로 갈 수 있으며, 도장에 연결한 기록은 도장으로, 같이 하기의 기록은 상대에게 전송됩니다.
9. 만 14세 미만 아동
앱은 만 14세 미만 아동을 대상으로 하지 않으며, 아동의 개인정보를 의도적으로 수집하지 않습니다. 알게 된 경우 지체 없이 삭제합니다.
10. 안전성 확보 조치
- 앱과 서버 사이의 모든 통신은 암호화(HTTPS)합니다.
- 회사 데이터베이스에는 IP 주소를 저장하지 않고, 회사만 가진 비밀 키로 변환한 값만 씁니다. 구매 확인에 쓴 값은 해시로 저장합니다(Google Play 월 이용권은 구매 토큰을 그대로 저장합니다).
- 개인정보에 접근할 수 있는 사람을 최소한으로 제한합니다.
11. 자동 수집 장치
앱은 쿠키, 광고 식별자, 분석(애널리틱스)·광고 도구를 쓰지 않습니다.
12. 이용자의 권리와 행사 방법
- 회원 탈퇴: 앱의 설정 → 회원 탈퇴. 5장에 적은 대로 서버의 계정과 기록이 삭제됩니다. 기기의 기록은 앱을 삭제하면 지워집니다.
- 열람, 정정, 삭제, 처리 정지 요청은 아래 연락처로 하실 수 있으며, 회사는 지체 없이 조치합니다.
- 건강 데이터 권한은 2장의 방법으로 언제든 끌 수 있습니다.
- AI 도움(DeepSeek) 동의는 앱의 설정 → AI 도움 (DeepSeek)에서 언제든 끄거나 다시 켤 수 있습니다.
13. 개인정보 보호책임자
14. 권익침해 구제 방법
15. 처리방침의 변경
변경 내용은 시행 7일 전부터 이 페이지로 고지합니다. 이용자의 권리에 중대한 영향을 미치는 변경은 30일 전부터 고지합니다.
16. 문의
hello@darak.studio · darak.studio
주식회사 다락스튜디오 (Darak Studio Inc.)
setpad Privacy Policy
Effective: September 24, 2026
Darak Studio Inc. ("we") processes personal information of users of the workout log app setpad ("the app") under the Personal Information Protection Act of Korea. This policy states plainly what leaves your device, who receives it and how long it is kept.
Summary
- Workouts, set notes and meals are stored on your device by default. No account is needed to log on your own.
- When the app starts, it sends a random device identifier to our server (Singapore) to get a temporary token for AI requests.
- Sentence interpretation (record search questions, one-line setup, calorie estimates from meal text or photos) goes through our server to DeepSeek (China) only after you consent the first time the app needs it. If you decline or turn it off in Settings, nothing is sent. Our server does not store it.
- To tell whether a line typed in the exercise-name field is a food, the app asks our server whether the food table (Korean MFDS, USDA) has that exact name. This is not AI, and the text is not stored.
- If you sign in, we store your name (nickname) and a sign-in identifier. We do not store your email.
- If you connect a gym or use Together (editing one record live with others), record handoff or shared routines, those records go through our server to the gym or the other people.
- Active calories and heart rate read from Apple Health or Health Connect never leave your device.
- No advertising or analytics tools are used.
1. Information we process
1-1. Sent when the app starts (even without signing in)
- Device identifier: a random value created on first launch. Each time the app starts it is sent to our server to obtain a temporary 30-day token for AI requests. If you use an AI feature, it is stored as the label under which requests are counted.
- Request counts: to prevent abuse we count requests per day. Our database stores no IP addresses; we count by a value derived with a secret key only we hold.
- Subscription availability check: a request asking whether passes are on sale. It carries no personal information.
- Plate ledger: record questions use "plates", setpad's unit of AI usage. For each wallet (the device identifier, or your account when signed in) the server records plates received and spent; the amount spent is computed from the tokens the AI actually used for that question.
- Daily plate: logging 10 or more sets in a day earns one plate; the app sends only that day's set count (one number), not your records.
1-2. Sent for AI interpretation (only with your consent; not stored on our server)
The first time you use one of these features, the app shows what goes to DeepSeek and asks for your consent. If you choose "Not now" or turn it off in the app's Settings → AI help (DeepSeek), none of the following is sent, and what you type and the calories you enter are still logged on your device.
- Record search questions: a sentence you submit in the record search box (typing only an exercise name sends nothing). Up to 60 exercise names from your records are sent with it to help interpretation. Requests go under your account when signed in, otherwise under the device identifier.
- One-line setup: a line with numbers typed in the exercise-name field, such as "bench 80kg, fill 100 reps in total", with a list of similar exercise names. The AI also tells whether the line is an exercise or a food.
- Meal text: if you consented to AI help, meals logged without calories are sent automatically for an estimate.
- Meal photos you take or pick, resized to 1024px with capture details (location, device, time) removed, together with the connected gym and the meal type (breakfast, lunch…). Photos are not stored on our server; they may stay briefly in the app's temporary folder, which the operating system clears. Only the estimate (food names, calories) is kept in your record.
1-2-1. Food table lookup (not AI, not stored)
- When a line typed in the exercise-name field does not look like an exercise, the text (up to 200 characters) is sent to our server to check whether the food table (Korean MFDS food composition database, USDA FoodData Central) has that exact name. This works regardless of AI-help consent; the text is not stored, only request counts.
1-3. When you sign in
- Sign-in identifier from Apple or Google. Sign in with Apple does not request your email. A Google sign-in token may contain your email, but our server reads only the account identifier and does not store the email.
- Name (nickname): the name registered on your Apple or Google account, up to 20 characters ("도전자", "Challenger", if none). It cannot be changed in the app yet; connected gyms and people you work out with see it.
- Apple sign-in token used to revoke the sign-in when you delete your account.
- Signing in does not back up your personal records to our server.
1-4. When you buy a pass
- The store's purchase number (for Google Play monthly passes, the purchase token), product, expiry and a record that the receipt was verified. We never receive card or payment details; Apple and Google process payment.
1-5. Features you choose to use
- Gym connection: for workouts at that gym, start time, exercise names, weights, reps and completion (set notes are not sent; an empty record is sent as attendance); meals you record (date, meal type, text, food names, amount, calories — sent even without calories); membership requests; PT bookings.
- Together: the one record up to 6 people edit live (exercise names, sets, set notes, and the name of whoever wrote each set), where you are editing and the text you are typing (up to 80 characters, shown to the others as a cursor), the workout record each person shares, shared timer settings (title, tempo, Tabata intervals) and your name.
- Record handoff: the record you wrote for someone else and the name you gave them.
- Shared routines: title, planned date, exercises, set counts and each person's targets (weight, reps, notes). While signed in, drafts are stored on the server even before you invite anyone.
- iPhone nearby invite: an invite token and title are passed to the other device through Apple SharePlay.
1-6. Stored on the device
- Workouts, set notes, meals, copies of a partner's shared record, settings, the sign-in token (a file in the app's own storage), and record-search questions with their interpretations. Depending on your device settings these files may be included in iCloud device backup or Android auto backup.
2. Health data (Apple Health / Health Connect)
Only with your permission:
| Type | Access | Use |
| Workouts | Write | When you finish a record it is saved as a workout session, with the record title and active calories. |
| Active calories | Read | Active calories your watch measured during the workout are added to that record; if nothing was measured, no calories are shown. |
| Heart rate | Read | During a Tabata rest, once your heart rate is 25 bpm below that round's peak, the rest ends and the next round is signalled. While resting the timer shows your current and target heart rate. On iPhone, after you finish a record, the app wakes when your watch records heart rate, reads it, and writes it to an on-device log to measure delivery delay. |
- Values read from your health app are never sent to our server or any third party and are not used for advertising or marketing.
- On iOS 26.1 or later, if you allow alarms, a system alarm sounds when heart rate ends a rest and is forwarded to your paired Apple Watch. The alarm contains no health data.
- You can turn these off at any time: iPhone Settings → Privacy & Security → Health → setpad; Android: Health Connect → App permissions → setpad.
3. How we collect
The app sends information when you enter it or use a feature. Sign-in information comes through Apple or Google sign-in, and purchase information through store payment.
4. Purposes
- Providing app features such as sentence interpretation and meal calorie estimates
- Identifying members and checking or restoring passes
- Providing the sharing features you choose (gym connection, Together, handoff, shared routines)
- Preventing abuse and keeping the service stable
5. Retention
| Information | Retention |
| AI requests (questions, sentences, meal text and photos) | Not stored on our server; discarded as soon as the answer is produced. |
| Account (identifier, name), passes, workouts/meals/bookings/requests sent to a gym, shared routines you created and your targets, records you handed off | Deleted when you delete your account. |
| Apple sign-in token | Kept while you are signed in. On account deletion we immediately ask Apple to revoke it; if that fails, it is kept encrypted and requested again, and deleted once Apple confirms. |
| Together records | The jointly edited record and cursor information are deleted when the session ends. If you leave early, the copy of your record you shared is deleted at once, and your sets in the jointly edited record are deleted when that session ends. If nobody ends it, kept until account deletion. |
| Food table lookups | The text is not stored; only daily request counts. |
| Handoff links | Open for 7 days from the last edit. Anyone with the link can see the record and the sender's name. |
| Request counts | Daily counts per device identifier or derived IP value; kept regardless of account deletion. |
| Plate ledger | Account wallets are deleted with the account; device wallets remain. |
| Records on the device | Stay until you delete them or the app. Deleting your account does not erase them. |
After account deletion these remain: a gym's payment ledger and change history (with your name removed), edits you made to someone else's shared routine, records someone else wrote and handed to you, and your sets (with your name as their writer) in a record edited together in a session someone else started, until that session ends. Gym owners and trainers can delete their account after closing out their gym. Member information entered by a gym itself (notes, body composition, passes, payments) is managed by that gym and outside this policy.
6. Sharing with third parties
We do not sell or provide your personal information to third parties. When you choose a feature, the people involved see the relevant information: a connected gym (owner, trainers) sees your name, workouts at that gym, meals you record and bookings; Together, handoff and shared-routine partners see your name and the records you share.
7. Processors
| Processor | Task | Information |
| DeepSeek (Hangzhou DeepSeek Artificial Intelligence Co., Ltd.) | Sentence interpretation and meal calorie estimates (AI), only with your consent; wording of trainer-mode reports | Record search questions and exercise names, one-line setup sentences with similar exercise names, meal text, meal photos. Trainer reports send only the gym name, the renewal offer text, counts, a reason per member (e.g. "expires in 3 days") and product names and prices (no member names, contacts or identifiers). Requests carry no value that identifies you (account or device identifier). |
| Railway | Server and database hosting | Device identifier, request counts, plate ledger, account, passes, shared records, and AI request content passing through |
| Apple Inc. | Sign in with Apple, App Store purchase verification, SharePlay nearby invite, forwarding alarms to Apple Watch | Sign-in identifier, purchase records, invite token |
| Google LLC | Google sign-in, Google Play purchase verification | Sign-in identifier, purchase records |
8. International transfers
| Recipient | Country | Items | When and how | Purpose and retention |
| DeepSeek | China | AI items in section 7 | Each time you use the feature, over an encrypted connection (HTTPS) | Producing the answer; retention follows DeepSeek's policy. |
| Railway | Singapore (server location) | Railway items in section 7 | Whenever the app talks to the server, over HTTPS | Providing the service, for the periods in section 5. |
If you decline AI help or turn it off in Settings, the app sends no request to DeepSeek. The app still sends its device identifier to our server (Singapore) whenever it starts, lines typed in the exercise-name field may go to our server for the food table lookup (1-2-1), gym-connected records go to the gym, and Together records go to the other people.
9. Children
The app is not directed to children under 14 and we do not knowingly collect their personal information. If we learn of it, we delete it without delay.
10. Security
- All traffic between the app and our server is encrypted (HTTPS).
- Our database stores no IP addresses, only values derived with a secret key we hold. Values used to verify purchases are stored as hashes (for Google Play monthly passes, the purchase token is stored as is).
- Access to personal information is limited to the minimum number of people.
11. Automatic collection
The app uses no cookies, advertising identifiers, analytics or advertising tools.
12. Your rights
- Delete your account in the app: Settings → Delete account. Your account and records on our server are deleted as described in section 5. Records on the device are removed when you delete the app.
- You can ask to access, correct, delete or stop processing your information at the contact below; we act without delay.
- Health data permissions can be turned off at any time as described in section 2.
- Consent to AI help (DeepSeek) can be turned off or on again at any time in the app: Settings → AI help (DeepSeek).
13. Privacy officer
14. Remedies
15. Changes
Changes are announced on this page 7 days before they take effect, or 30 days before for changes that significantly affect your rights.
16. Contact
hello@darak.studio · darak.studio
Darak Studio Inc.