Last updated: 7 August 2026.
What this policy covers
This policy covers the Bulk Coach iPhone app, companion web app and public website. It explains the information collected from athletes, the purposes for which it is used, the services that process it and the controls available in the product.
Information we collect
Account and identifiers. We collect the name and email address supplied through Sign in with Apple or email sign-in, authentication and athlete identifiers, account dates, time zone, locale, unit preference, privacy choices, device notification token and app settings.
Profile and safety context. We collect date of birth, self-declared gender, optional height and bodyweight, goal and event date, training experience, available days and session duration, equipment, injuries or limitations, previous barriers and any notes the athlete chooses to provide.
Training, coaching and other user content. We collect saved workouts and schedules, exercise and set history, weights, repetitions, effort ratings, personal records, workout notes, programme proposals and decisions, Coach conversations, feedback, check-ins and Coach memories approved by the athlete.
Purchases. We collect App Store product, entitlement, renewal, expiry, store and refund status so that paid features and Restore Purchases work. Apple processes the payment method; Bulk Coach does not receive payment-card or bank-account details.
Support communications. When someone uses website support chat, we collect the messages and contact details they choose to provide, together with the technical information needed to deliver the conversation.
Usage and diagnostics. We collect allowlisted product interactions, screen names, counts, durations, app and device metadata, error classes, crash information and performance information. These records may use the athlete identifier or an unlinked device identifier, according to the athlete’s analytics-linkage setting.
How we use information
We use this information to create and secure the account; provide workout logging, history, programmes, Coach and connected Health features; honour subscription access; deliver requested notifications; personalise units and training guidance; prevent unsafe or conflicting exercise suggestions; diagnose failures; measure feature use; respond to support, privacy and legal requests; and meet accounting and legal obligations.
Separate choices
Apple Health access and AI coaching are requested separately. Each can be declined or revoked without disabling workout logging. Photo-library, camera and notification access are requested only when the athlete uses a feature that needs them and can be changed in iOS Settings.
Apple Health
With permission, Bulk Coach reads weight, body fat percentage, lean body mass, height, waist circumference, resting heart rate, heart rate variability, steps, active energy, dietary energy, protein and workouts. It retains weekly aggregate summaries, not individual readings or a day-by-day Health history. The latest weekly bodyweight average may update the athlete profile.
Bulk Coach can write a completed workout’s start and end time to Apple Health. It does not invent or write active calories. Disconnecting Apple Health stops future reads, removes retained Health summaries and removes a profile weight supplied by Health. Completed workouts already written to Apple Health remain in the athlete’s Health store unless removed there by the athlete.
Health information is used only to provide health and fitness features. It is not used for advertising, marketing or sale to data brokers. A connected Health summary is sent for AI processing only when AI coaching is also allowed and Coach explicitly reads Health trends for a response.
External AI assistants and MCP
An athlete can connect a compatible AI client to Bulk Coach through Model Context Protocol (MCP). The connection is authenticated and bound to the signed-in athlete. The model cannot choose an athlete identifier, timestamp or idempotency key.
The external connection covers supported workout reads and writes behind one revocable external-assistants grant. It does not expose Apple Health summaries, individual readings or unrelated health data.
A connected external client and its provider process the data returned for the athlete's request under that provider's own terms and privacy policy. Bulk Coach does not treat an external client's copy as part of the athlete's Bulk Coach account. Athletes should connect only clients they trust and grant only the access needed for the task.
AI coaching and workout-photo imports
AI coaching is off until the athlete explicitly allows it. When allowed and relevant to a request, Bulk Coach sends profile details, workouts and training history, connected Apple Health summaries, Coach and check-in text, workout notes and approved Coach memories to OpenRouter. OpenRouter routes the request to an upstream model provider, which may include OpenAI, Anthropic, Google, xAI, DeepSeek, StepFun or MiniMax. Those services process the data to generate Coach chat, programmes, post-workout feedback, weekly check-ins and workout-photo extraction, and processing may occur in the United States.
Bulk Coach asks OpenRouter to route only to providers that do not use prompts to train their models. Provider processing and retention remain governed by the relevant provider terms. The athlete can decline before the first request or withdraw permission later in Profile; withdrawal stops active and future AI requests without disabling workout logging or other non-AI features.
When an athlete deliberately selects workout screenshots or training-book photos for import, compressed copies are uploaded to temporary Convex storage and made available to OpenRouter and its selected model provider for extraction. They are deleted after the extraction attempt finishes. Incomplete uploads are automatically removed within one hour. The extracted workout data is shown for review and is saved only after the athlete confirms it.
Camera, photos, notifications and Live Activities
An athlete can optionally choose or take an image when creating a workout story. The selected image and generated story stay on the device: Bulk Coach does not upload or save either image. Sharing happens through the destination the athlete chooses on their iPhone. Photo-library access is also used for the workout-photo import described above.
If notifications are enabled, Bulk Coach stores an Expo push token linked to the athlete and sends it through Expo and Apple Push Notification service to announce completed Coach reviews or check-ins. Notification bodies contain no workout values or Health data. If Live Activities are enabled, active-workout status can appear on the Lock Screen and Dynamic Island. Bulk Coach does not request contacts, location or microphone access.
Analytics, error tracking and session replay
Public website analytics. The Bulk Coach marketing website uses Google Analytics 4 on public pages to measure page views, referrals, campaign attribution and general browser or device characteristics. Analytics storage is enabled automatically. Advertising storage, advertising user data, personalisation and Google Signals remain disabled. Calculator inputs, workout values, exercise names, Health data, support messages and other form values are not sent as analytics event properties.
Bulk Coach uses PostHog US Cloud for product analytics, error tracking and session replay. Custom analytics events receive structural information only: event names, counts, durations, screen names, app and device metadata, and error types. They do not receive weights, reps, body measurements, exercise names, session notes, onboarding answers, photo references, Health values, Coach text or other athlete free text. Permitted fields are declared per event and anything else is discarded before an event leaves the device.
Session replay records the visual interface and interactions for eligible sessions, so it may show information rendered on screen. Text entered into fields and images are masked. Console capture and network telemetry are disabled. Replay is a broader visual record than the allowlisted custom events described above.
Analytics starts after the signed-in account loads. It is linked to the athlete identifier by default. During onboarding and later in Profile, the athlete can choose unlinked analytics; this removes the account identifier and uses PostHog’s unlinked device identifier for future events and replay. This setting changes linkage rather than turning analytics collection off.
Services that process information
Bulk Coach uses Apple for Sign in with Apple, subscriptions, HealthKit, notifications and platform services; Clerk for account authentication and external-client OAuth; Convex for application data, file processing and server functions; OpenRouter and its selected upstream model provider for consented AI features; RevenueCat for subscription status and support-safe customer attributes; PostHog US Cloud for product analytics, replay and diagnostics; Google Analytics for public-website measurement; Chatwoot Cloud for website support chat; Expo and Apple Push Notification service for requested notifications; and Cloudflare for delivery and protection of the web services. Each service receives only the information needed for its role.
Bulk Coach does not sell personal information, use it for third-party advertising or combine it with third-party data to track athletes across other companies’ apps or websites.
Retention, deletion and security
Account, profile, training and Coach data is retained while the account is active. Temporary workout-import images use the shorter deletion periods described above. We use access controls, encrypted network connections, authenticated service boundaries and protected device storage appropriate to the data, but no online service can promise absolute security.
The app provides permanent account deletion from Profile. Deletion removes the authentication account, profile, training history, Coach data, retained Apple Health summaries, push-notification records, linked analytics person and processor customer records. Account access ends immediately; processor erasure may continue securely in the background. Workouts already saved to Apple Health and content deliberately shared to another app remain under the athlete’s control in those destinations.
Apple subscriptions and deletion
Deleting a Bulk Coach account does not cancel an Apple subscription. Apple billing is separate and can continue after the account is deleted. The app links to Apple’s subscription-management screen before deletion so the athlete can cancel future renewal, while still allowing immediate account deletion.
Purchase-record retention
After account deletion, Bulk Coach retains only an anonymised purchase-event receipt for up to seven years to meet UK accounting and tax record requirements. It contains a provider event identifier, event type and timestamps, but no Bulk Coach account identifier, contact details, receipt payload, price, training data or health data. Records may be kept longer where a tax enquiry or legal hold requires it. Apple settlement reports are retained separately under the company’s approved accounting process.
Your choices and rights
Athletes can withdraw AI permission, disconnect Apple Health, unlink product analytics, disable notifications or Live Activities, change camera and photo access in iOS Settings, and permanently delete the account. Contact the published support route to request access, correction, export, restriction, objection or deletion, or to raise a privacy concern. UK users may also complain to the UK Information Commissioner's Office.
We will update this policy when the product, processors or data practices materially change and will update the date shown above.