Privacy Policy
Last updated 7 September 2026
The short version
Compound stores your name, your email address, and what you record — the sets you log, the weights you lift, the meals you enter, the habits you tick and the fasts you run. There is no analytics, no advertising and no tracking. Nothing is sold, and nothing is shared with anyone for their own purposes.
To write your training plan and to read a photo of a meal, the app sends what it needs to Anthropic's model API. That is the one place your information goes to be worked on rather than only stored, and there is a section on it below.
You can delete your account and everything attached to it from inside the app, at any time, without asking anyone.
Who is responsible
The app and this server are run by Stewart Christensen, an individual developer, who is the data controller for the purposes of the UK GDPR and the EU GDPR. Contact: stewart@growthengines.us.
What is collected
Given when you create an account. The name is what the app greets you by and the letter it draws as your avatar; the email address is what you sign in with.
Never stored as you typed it. It is hashed with scrypt, and only the hash is kept — the original cannot be recovered from it, by us or by anyone who obtained the database.
Your sex, year of birth, height, weight and goal weight; how many days a week you train, for how long, where, and around which injuries. The plan is built from these, and the calorie and protein figures are worked out from them.
The weeks written for you, the sessions you finished, the weight and reps logged against every movement, how each set felt, your own notes on a movement, and the workouts you built and saved. This is the point of the app.
Meals you record — a name, calories, protein, carbohydrate, fat, and a barcode where you scanned one — and any fast you start, with its target and when it ended. Photographs of meals are not kept; see the section on the model below.
Your habit checklists and what you tick off them, how the morning and evening felt, body weights you enter, and the days you marked as rest.
The wording of a request you make of the coach — 'more legs', 'shorter sessions' — is kept so the next week still knows about it, along with the plan changes it produced and the reasons written for them.
Staying signed in needs a token on your phone. The server stores only a SHA-256 hash of that token, so a copy of the database does not hand anyone a working session.
The model, and what it is sent
Compound uses Anthropic's model API for four things: writing or rewriting a week, building a workout you asked for in words, reading a photograph or a description of a meal, and the short observation that sometimes appears on the Today screen.
Your training history, the profile figures above, the movements available to you, and the words you typed. Your name and your email address are not sent.
The photograph you took, or the words you typed, and nothing else — no profile, no history and no account details. The photograph is sent, read, and not stored: what is kept is the name and the numbers it came back with.
Anthropic processes this on our behalf to answer that one request. Under Anthropic's commercial terms, input and output from the API are not used to train their models. If you would rather none of this happened, everything except the meal photograph has a manual path: weeks are written by the app's own engine when you do not ask for a rewrite, workouts can be built by hand, and a meal can be typed in.
What is not collected
No analytics or telemetry of any kind — the app contains no analytics SDK, and none of your usage is measured or reported. No advertising identifiers and no ad networks. No location. No contacts. No microphone: the button with a microphone on it opens a text field. The app does not track you across other companies' apps or websites, and holds no data that could be used to.
Camera and photographs
The camera is used for two things, both of which you start: scanning a barcode on food packaging, and photographing a meal. You may pick an existing photograph from your library instead.
A meal photograph is sent to the model to be read and is not written to our database or kept on our server afterwards. A barcode is looked up against Open Food Facts, a public food database, directly from your phone — that request carries the barcode and your device's IP address, and nothing about your account.
Apple Health
The app can write to Apple Health and read one value from it, and only if you agree when iOS asks. Health is optional — decline it and everything else in the app works exactly as before.
When you finish a session the app saves it as a traditional strength training workout, with a start, an end and an estimated calorie burn, so it closes your Fitness rings. Health has no data type for a set or a rep, so what you lifted stays in this app.
If Health already knows your body weight, the app reads the most recent value to make the calorie estimate less of a guess. It is used on your phone, in that calculation, and nothing else. It is never sent to our server and never seen by anyone else.
Nothing read from Health is used for advertising, marketing or any kind of data mining, and it is never sold or shared. You can withdraw access at any time in the iPhone's Settings → Privacy & Security → Health, and the app carries on without it.
Why it is held
To run your account and to show your training back to you on every device you sign in on. Under the GDPR the lawful basis is performance of a contract — you asked for an account that remembers your training, and this is what remembering it requires. There is no secondary use.
Who else touches it
Three services process data on our behalf, and only to do the job named:
Hosts the server the app talks to, and carries the request traffic between your phone and the database.
The hosted Postgres database where accounts, training and meals are stored, encrypted in transit.
Reads what is described in the section above, to answer that one request, and returns a plan or a set of nutrition figures.
Exercise demonstration clips are served from our own server, so watching one tells nobody else anything. Nothing is sold. Nothing is handed to advertisers, data brokers, or anyone else for their own purposes.
How long it is kept
Until you delete it. Your account and everything in it are held for as long as the account exists, because an account that forgot your training would be of no use. Delete the account and it goes immediately — see below.
Deleting your account
In the app: tap your initial in the top right, then Account → Delete account. You confirm with your password, and the account is removed along with every week, logged set, meal, habit tick, fast, note and session attached to it. The deletion runs against the database at once and cannot be undone.
If you would rather not do it in the app, email stewart@growthengines.us from your account's address and it will be done for you.
Your rights
If you are in the UK, the EU, or a US state with a privacy statute, you have the right to see the data held about you, to correct it, to have it deleted, and to receive a copy in a portable form. The delete right is built into the app. For the others, email stewart@growthengines.us and expect a reply within 30 days. You may also complain to your data protection authority — in the UK, the Information Commissioner's Office.
Security
Traffic between the app and the server is HTTPS only. Passwords are hashed with scrypt and session tokens are stored only as hashes. Sign-in and sign-up attempts are rate limited. No system is perfect, and this one is run by one person — the design above is meant to limit what a breach could expose rather than to promise there will never be one.
Children
Compound is a weight training app intended for adults. It is not directed at children, and accounts are not knowingly created for anyone under 13. If you believe a child has created one, email the address above and it will be deleted.
Changes
If this policy changes in a way that affects what is collected or who it goes to, the date at the top changes and account holders are told before it takes effect.
Contact
stewart@growthengines.us — for privacy questions, data requests, or anything else about the app.