Who we are
This policy covers the Ironi apps for iOS and Android and the Ironi website at ironi.brillness.com. Ironi is run by Brillness, the trading name of Nidhanshu Sharma, who controls the account data described here. Email ironi@brillness.com or use our contact page with any privacy question.
Account and profile data
- Required for an account: your email address and either a password, Google Sign-In, or Sign in with Apple. We store a password hash, not your plain password. Apple may provide a private relay address instead of your usual email address if you choose Hide My Email.
- Required during setup: your date of birth or age, gender, unit choice, training frequency, height, current weight, fitness goal, and workout plan choices. This information sets up the plan and body goal screens you ask for.
- Optional choices: your display name, target weight, goal pace, training blockers, theme, reminder time, timezone, language, RPE tracking, exercise increments, email report preference, and whether the Android Live Workout notification may show workout details on the lock screen.
- Account security: a Google account ID if you use Google Sign-In, an Apple user identifier if you use Sign in with Apple, a server-side Apple refresh token used for revocation, password reset token hashes, login timing, account creation date, and a random billing account binding ID.
- Android Live Workout device state: if you start an eligible gym workout in the Android app, Ironi links an app-generated installation ID and the Android platform to your account. The dedicated device record stores whether the Live Workout preview was shown, accepted, or declined, the decline count and prompt dates used for the 7-day and 14-day backoff, the last OS notification-permission state observed by the app, and a version number used to sync changes safely after offline use.
- Account notices: Ironi stores when your included AI access ends, whether you choose to upgrade, choose Not now, or close the notice, and when you first complete another free gym workout afterward. This keeps the one-time notice consistent across devices and measures whether people continue using the free tracker.
We use this information to create and secure your account, remember your settings, personalize measurements and plans, and restore your account on another device. Most profile fields stay on our servers until you change them or delete the account.
Ironi uses the Android Live Workout device record to show the preview and permission request at the right time for each installation. This record is separate from web push subscriptions and does not contain workout details.
Training and health information
Ironi stores the fitness information you enter. This includes workout plans, training days, exercises, sets, reps, weight, RPE, set duration, set distance, drop sets, workout times, notes, exercise preferences, progress, PRs, body-weight entries, weight goals, and optional post-workout difficulty feedback.
Ironi does not ask for or store pain, injury, or symptom information.
This information is needed when you choose to log a workout, track body weight, view reports, or use a personalized plan. Ironi uses it to save your history and calculate progress, streaks, comparisons, and recommendations.
Ironi does not read Apple Health or HealthKit, Health Connect, Google Fit, step counts, heart rate, or body sensor data. It does not diagnose medical conditions. Your workout, body, and cardio records can still be sensitive health and fitness information.
Location and cardio routes
GPS tracking is optional. Ironi asks for precise location only after you start a GPS run, walk, or ride. While that activity is recording, the app reads latitude, longitude, time, accuracy, and available altitude. It uses those points to calculate the route, distance, pace, splits, moving time, and elevation gain.
On iOS and Android, an active GPS activity can keep tracking while Ironi is in the background or the screen is locked. Tracking starts only after you start the activity. It stops when you finish or discard it. Ironi does not collect a continuous location history outside an active GPS activity. iOS shows its background location indicator while an activity is recording.
The device keeps recording points in local recovery storage so an interrupted activity can be restored. When you finish, Ironi uploads an encoded route and the activity totals to our server. A manual cardio entry does not use location and has no route.
Route maps load map data from a platform provider. The website uses OpenStreetMap, Android uses Google Maps, and iOS uses Apple MapKit. The provider can receive your IP address, device request details, and the map area needed for the view. While a GPS activity is recording, that area follows where you are. Ironi does not give the map provider your account profile or its stored route record. Apple, Google, and OpenStreetMap handle their own service data under their privacy terms.
Photos, microphone audio, and transcripts
Photo access on iOS is optional. Ironi uses Apple's system photo picker only after you choose a photo for a cardio share card. The app reads only the photo you selected, combines it with the share graphic on the device, and does not upload the selected photo or generated image to Ironi. When you choose Save to photos, iOS adds the generated image to your photo library. Share card image files can also remain temporarily in the app's temporary directory until iOS removes them or a later render replaces them.
Microphone access is optional. It starts only when you tap a voice button for set logging or Coach dictation. Each clip is limited to about 15 seconds.
The web and Android app hold the recording in memory for the live request. The iOS app records to a randomly named .m4a file in its temporary directory, reads the file into memory, and deletes the file before it uploads the audio bytes. It also deletes the file if you cancel or recording fails. Ironi sends the audio through its server to Groq Whisper for transcription and does not write the raw audio to its database. Groq receives the audio, its format, the selected app language, and a short gym vocabulary prompt. Groq's service rules control any provider-side logs or temporary copies.
Ironi returns the transcript to your device. For voice set logging, the transcript fills draft set fields and is not stored as a transcript by Ironi. Only the structured set values you confirm are saved. If the local parser needs help, the transcript may be sent through the AI provider chain in section 06. For Coach dictation, the transcript stays in the message draft until you send it. Once sent, it becomes part of the saved Coach chat.
Some browsers may also offer live speech recognition while you record. That browser or operating-system service may process the live speech under its own privacy terms. Ironi uses that live text only as a temporary on-screen preview.
AI processing
Ironi's current text-AI fallback order is Google Gemini, then Groq, then Cloudflare Workers AI. A request normally stops after one provider answers. If a provider fails, the same request may be sent to the next provider. Cloudflare Workers AI is only used for features that reply in plain text, such as Coach chat and AI reports. Voice transcription always uses Groq Whisper.
Depending on the feature, the AI input can contain:
- Workout exercises, sets, RPE, dates, duration, recent strength and cardio activity, progress, fitness goal, weekly training target, unit choice, local date, and coach memory for session reviews and Coach chat.
- Recent body-weight entries, target weight, and goal pace when you ask Coach about your body-weight goal.
- Cardio type, distance, pace, time, splits, elevation, notes, and recent training for cardio reviews. The encoded GPS route is not included in the cardio-review prompt.
- Age, height, current and target weight, fitness goal, goal pace, blockers, experience, equipment, and schedule choices for an AI workout plan.
- Your Coach messages, selected training context, saved feedback totals, and previous AI outputs.
- Training totals and patterns for weekly and monthly AI reports.
- For Trainer's Review, every exercise in the completed workout, today's logged sets, up to three earlier attempts for each exact exercise, the fitness goal, optional workout difficulty feedback, recent complete-week adherence, and code-approved options.
Ironi does not add your email address, password, raw microphone file, Google ID, Apple user identifier, or payment details to AI prompts. Avoid putting private information into a Coach message or workout note if it is not needed for training advice.
Saved Coach chats, Trainer's Review revisions, temporary actions, session and cardio reviews, AI reports, coach memory, AI feedback, and saved generated plans stay with your account until the account is deleted. Some of it you can remove sooner. Deleting a workout or cardio activity removes that item's review and its Trainer's Review records. Deleting a workout plan archives it, and the archived plan stays with your account until the account is deleted. You can delete a Coach conversation from the chat list, which permanently removes its stored messages. There is no separate control for coach memory, AI reports, or AI feedback. New chat starts a fresh conversation without erasing earlier ones. Deleting the account removes all of it. You can also email ironi@brillness.com to ask us to remove specific AI data. Weekly and monthly AI reports can be generated automatically from completed workouts and cardio activities. Turning off report emails stops the email, not the in-app report generation.
You can report an AI response or generated plan. Ironi stores the type of content, its account-owned reference, your reason, an optional comment, and the provider and model when available. The report does not copy the full AI response and is not automatically sent to an AI provider. It stays with your account until the account is deleted.
Analytics and diagnostics
Google Analytics is active on Ironi's public website pages, including this privacy page. It measures page views and sessions and can receive an IP-derived approximate location, browser and device details, and page interaction data. Ironi does not use this information for ads, and the main Svelte app shell does not load the Google Analytics script. The native iOS and Android apps open public pages in the system browser, so Google Analytics runs as part of the website visit rather than inside the native app.
Google Analytics runs in consent mode, and it stores nothing on your device in Europe. In the European Economic Area, the United Kingdom, and Switzerland, analytics storage is denied before the Google tag runs. Google Analytics sets no cookie there and reads no client ID, so it cannot recognize you on a later visit. That is why Ironi shows no cookie consent banner. Outside those countries, Google Analytics may set a first-party analytics cookie and read a client ID. Advertising storage is denied everywhere because Ironi runs no ads.
The app also measures how Ironi itself is used through PostHog. Requests go to Ironi's own domain first, and Ironi forwards them to PostHog's European servers. PostHog receives an event name, the screen name you moved to, counts such as how many sets a workout had, short labels such as whether a set was logged by hand or by voice, your platform and app version, your Ironi account ID, the request user agent, and the client IP address used to derive country and device properties. It does not receive your name, email address, weights, reps, distances, durations, body weight, exercise names, or GPS coordinates in the event body. There is no session recording, heatmap, or PostHog cookie. You can turn this off at any time under Profile, Settings, Share usage analytics, and the rest of the app keeps working.
The app sends limited, account-linked diagnostics to Ironi when a workout save fails or GPS setup has a problem. These records can include the failed API path, retry status and timing, online state, exercise and set numbers, cardio activity ID and type, platform, GPS accuracy, simulated-location flag, notification permission state, and error text. GPS diagnostics do not include latitude or longitude.
Ironi also records limited, account-linked events for the included-AI-access notice and Pro purchase flow. These events can record that the notice was shown, which action you chose, whether pricing opened, whether saving the choice failed, and whether that pricing journey led to a confirmed purchase. They do not include workout content or AI conversations. The current app sends these to PostHog with the rest of the usage analytics described above, so turning that setting off stops them too. Older installed app versions may still send them to Ironi directly.
Ironi also stores basic service activity, such as the last time an authenticated API was used and counts of successful AI actions for daily limits. Cloudflare can process request information, IP addresses, server errors, and application logs while hosting and protecting the service.
To limit spam and login abuse, Ironi temporarily stores request counters keyed by an IP address or an email address entered on an account form. A counter becomes eligible for cleanup after five matching rate-limit windows. The window depends on the action, and an old row can remain until a later limited request runs the cleanup.
There is no Firebase Analytics, Firebase Crashlytics, Sentry, advertising SDK, or social media tracking pixel in the current native iOS or Android app. Apple and Google may provide Brillness with platform crash, performance, and app analytics reports under their own terms and the device owner's sharing choices.
Notifications and email
- Training reminders are optional. Web reminders store a push endpoint and encryption keys. The browser or operating-system push service receives the encrypted notification. Expired endpoints are removed when the push service rejects them.
- Native reminders are displayed locally. The iOS and Android apps schedule reminders on the device after you enable notifications. Denying notification permission does not stop workout logging.
- iOS Live Activities are optional and local. If ActivityKit is enabled, Ironi can start a Live Activity when you begin a gym workout or GPS cardio activity. It can show exercise, set, weight, rep, distance, elapsed time, and pace information on the Lock Screen or Dynamic Island. It does not use a remote push token, and the Live Activity ends when the activity ends.
- You control gym workout details. You can hide exercise, set, weight, and rep details in Ironi's Settings. Ironi stores the choice in your account and applies the private state before publishing a workout Live Activity update.
- Cardio metrics follow iOS privacy settings. Ironi marks distance, time, and pace as privacy sensitive on the Lock Screen and Dynamic Island. iOS can redact those metrics according to the device's Lock Screen notification privacy settings.
- Account email is required for service messages. Resend receives your email address, name when used, and the email content for welcome messages, password resets, subscription notices, and other account messages.
- AI report email is optional and starts on by default. It can contain workout totals and AI report text. Turn it off in Profile without removing the in-app report.
- Contact messages are optional. If you use the public contact form, Resend and the Ironi support inbox receive your name, email, topic, and message.
Sign-in and billing
Google Sign-In is optional. Google handles the sign-in screen. Ironi receives a verified email address, name, and Google account ID. On the web, Ironi sends the one-time authorization code to Google's token service. On Android, the Google sign-in plugin returns an ID token for Ironi to verify.
Sign in with Apple is optional on iOS. Apple handles the sign-in screen. Ironi receives an Apple user identifier, an identity token, a one-time authorization code, and the name and verified email address that Apple makes available. Ironi sends the authorization code to Apple's token service and stores the returned refresh token on its server so it can revoke Apple access when the account is deleted. The refresh token is never sent back to the app or added to AI input.
Dodo Payments handles web subscriptions as the Merchant of Record. Ironi sends Dodo your email, optional name, billing country inferred from your IP country, selected plan, Ironi user ID in checkout metadata, and return URL. You enter card, billing, and tax details on Dodo's hosted checkout. Ironi does not receive your full card number.
Google Play Billing handles Android subscriptions. Ironi receives and stores the product, purchase token or subscription ID, status, renewal date, and a random account-binding ID. Ironi sends the purchase token and account-binding ID to the Google Play Developer API to verify and acknowledge the purchase. Ironi does not receive your full card number from Google Play.
Apple's App Store handles iOS subscriptions. Ironi sends a random account binding ID with the purchase and receives an Apple-signed transaction. Ironi verifies the signature and stores the product ID, original subscription ID, status, entitlement and renewal state, and Apple event dates needed to grant, renew, cancel, refund, and restore Pro access. Ironi does not receive your payment card or bank details from Apple.
Deleting Ironi does not cancel a subscription. Manage an App Store subscription in App Store subscriptions. Cancel Google Play in Google Play subscriptions. For Dodo, open Manage subscription in Ironi before deleting the account, or use the management link in your Dodo receipt.
Who receives data
Ironi does not sell personal data, share it for targeted advertising, or show ads. These outside services receive data for the specific jobs below:
- Apple: optional Sign in with Apple, App Store purchases, MapKit map data, and platform analytics or diagnostics that a device owner chooses to share.
- Cloudflare: app hosting, network security, server logs, delivery, and Workers AI.
- Neon: the PostgreSQL database that stores Ironi account data in the Singapore region. Neon may use listed infrastructure subprocessors to provide that database.
- Google: optional Sign-In, Gemini AI, Google Play Billing, Android Vitals, Google Maps on Android, and Analytics on public website pages.
- PostHog: in-app product analytics hosted in the European Union. It receives account-linked usage events, the request user agent, and the client IP address, but no health or contact fields in the event body.
- Groq: Whisper voice transcription and fallback text-AI processing.
- Resend: sending and delivering account, report, and contact email.
- Dodo Payments: hosted web checkout, subscription management, tax, fraud checks, refunds, and payment records.
- OpenStreetMap Foundation: map tiles shown behind saved cardio routes on the web.
- Your browser or operating-system push service: delivery of web push notifications after you enable them.
These services handle data under their own terms and may use subprocessors. They may process data in countries outside yours. We may also disclose information when law requires it, to protect users and the service, or during a business transfer with proper safeguards.
Storage, cookies, and security
All app and API traffic uses HTTPS. Passwords are hashed with bcrypt. Logins use signed tokens. Password-reset tokens are stored as hashes, work once, and become unusable after 60 minutes. Public account-deletion tokens are also stored as hashes and expire after 30 minutes. Ironi data is not end-to-end encrypted because the server must read it to provide reports, exports, and AI features.
On the website, Ironi uses local storage and IndexedDB for the login token, cached profile, theme and language, active workout, unsent workout queue, Coach chat cache, offline workout snapshot, cardio recovery points, and feature preferences. The web service worker also caches public app files for offline launch.
On Android, the login token is stored in encrypted preferences backed by Android Keystore when that service is available. The app stores cached account and screen data, offline write queues, workout snapshots, cardio recovery points, and downloaded exercise artwork in private app files. It stores the unfinished onboarding draft, analytics identifier, Live Workout state, and small device preferences in private app preferences.
On iOS, the login token is stored in Keychain. The app stores the cached account, offline write queue, workout snapshots, cardio recovery points, and downloaded exercise artwork in files inside its app container. It stores small device preferences and an unfinished onboarding draft in UserDefaults. Temporary voice and share image files are stored in the system temporary directory as described above. Deleting the app removes its local container, while Keychain behavior remains subject to iOS and the user's device settings.
Ironi's own server sets no cookies. Outside Europe, Google Analytics can set the first-party cookies _ga and _ga_N9VFZMQ1Y7 on public website pages. In the European Economic Area, the United Kingdom, and Switzerland it sets neither. Ironi does not use advertising cookies anywhere.
The sign-in page loads Google's Identity Services script only after you choose to sign in with Google. Google can then set its own cookies under Google's terms. Clearing the app's storage or browser data removes device copies and may sign you out.
Data retention
- Account, profile, notice, workout, body, cardio, AI, preference, and diagnostic records: kept while the account is open, then deleted with the account.
- Sign in with Apple token: the refresh token is kept on Ironi's server while the Apple-linked account is open. A later successful Apple sign-in can replace it. Account deletion removes it from Ironi and then uses the captured token for the revocation request described in section 13.
- Voice audio: not stored in the Ironi database. The iOS
.m4ais deleted after it is read and before upload, or when the recording is cancelled or fails. Audio bytes are held for the live transcription request. Provider-side handling follows Groq's service terms. - Push subscriptions: kept until you turn off web reminders, delete the account, or the push service reports that the endpoint expired.
- Android Live Workout device records: kept while the account is open and automatically deleted with it. Successful account deletion clears the local consent copy and pending sync for that account on the device where deletion finishes. The install-level ID remains only on the device until you clear app storage or remove the app.
- Password-reset records: become unusable after 60 minutes or after use, and are removed when the account is deleted.
- Account-deletion links: expire after 30 minutes. A new link replaces the earlier link, and account deletion removes the token record.
- Abuse-prevention counters: become eligible for automatic cleanup after five matching rate-limit windows. They can remain until a later limited request runs the cleanup. Account deletion removes the account's password-reset and deletion-request email counters. Unrelated IP and general form counters expire through normal cleanup.
- Device caches: kept until the app clears them, you clear app storage, or the saved item is uploaded or discarded. Successful account deletion clears Ironi account storage and the local cardio recovery database on that device.
- Google Analytics: event-level retention follows the setting in Ironi's Google Analytics property. Google may keep aggregated reports and service records under its own terms.
- Email and support correspondence: Resend, receiving mail providers, and the support inbox may retain delivery records and message content. Ask us to delete support correspondence when it is no longer needed, unless law or an active dispute requires it.
If you had a paid subscription, Ironi keeps only the provider, external subscription ID, product ID, status, cancellation flag, and billing dates after account deletion. This detached record has no Ironi user ID, email, name, workout, health, location, profile, or AI content. It is kept for accounting, tax, refunds, chargebacks, and audits until the start of the ninth financial year after deletion, then removed by a scheduled cleanup. Apple, Google, and Dodo keep their own legally required payment records under their policies.
Ironi also keeps a one-way hash of the deleted account's email address. It is a keyed hash, so the address cannot be read back from it or looked up by anyone without our server key, and nothing is stored beside it except the date. It exists for one reason: every new account gets a small number of free AI uses, and without this record the same address could delete and sign up again to collect them over and over. A new signup whose address matches simply starts with those free AI uses already used. Signing up is never blocked, nothing else in Ironi reads this record, and it is never used to identify you, to contact you, or for anything besides that one check.
Export, correction, and deletion
You can edit profile settings in Ironi. Profile also offers:
- Workout CSV: a spreadsheet of logged workout sets.
- Account JSON: your profile and settings, splits, workout sessions, set logs with RPE and tempo, saved gym-session coach notes, cardio activities, body-weight entries, per-exercise weight increments, and your weekly and monthly AI reports.
The current self-service export does not include cardio route maps, Coach chat history, Trainer question and answer history, coach memory, feedback and content reports you sent about AI output, diagnostic logs, account notices, Android Live Workout device records, authentication credentials, or billing records. Email ironi@brillness.com for a broader access request.
Delete the account in Profile, or use the public account deletion page if you cannot sign in. The public page emails a 30-minute verification link to the account address. Confirming it deletes the account right away. Permanent deletion removes the account and its profile, authentication, workouts, sets, body weights, cardio routes, plans, preferences, AI chats, reports and safety reports, coach data, diagnostics, push subscriptions, Android Live Workout device records, and reset records. The old login stops working, and the same email can create a new account later. Only the detached billing record and the one-way email hash described in section 12 remain. That new account starts with its free AI uses already used, because they are given once per person rather than once per signup.
For a Sign in with Apple account, Ironi permanently deletes the account first and then asks Apple's revocation endpoint to invalidate the stored refresh token. The Ironi deletion still succeeds if Apple rejects the revocation request, the request cannot reach Apple, or a legacy account has no stored refresh token. When deletion is completed in the iOS app and automatic revocation does not succeed, the app tells you that the account was deleted and asks you to remove Ironi manually in your Apple Account's Sign in with Apple settings.
Depending on where you live, you may also have rights to access, correct, restrict, object to, or receive a portable copy of personal data. Email us to use those rights. We may ask you to verify the account first.
Children
Ironi is not made for children. You must be at least 13 years old to make an account. If you think a child under 13 has one, tell us and we'll delete it.
Changes to this policy
We will update the date at the top when this policy changes. If a change materially affects how Ironi uses sensitive data, we will also give notice in the app or by email when appropriate.
Contact
Email ironi@brillness.com for privacy questions or data requests. You can also use the contact page or the public account deletion page. Please write "privacy request" in the subject so we can route it correctly.