What this notice covers
This notice explains how Regimen Labs LLC handles information in the Regimen iPhone app and its supporting web service. Regimen is for adults age 18 and older.
Information Regimen handles
Account and device details
Regimen handles an account or installation identifier, display name and email when you sign in, time zone, app version, notification settings and token, device integrity signals, and technical request information such as an IP-derived rate-limit key.
Fitness, health, and profile details
Your intake can include age, sex, height, weight, body-fat entry, goals, experience, injuries, training limits, schedule, equipment, gym details, food restrictions, budget, and medication details you choose to provide, including GLP-1 cadence.
Content you add
Regimen stores the plan, workouts, sets, reps, loads, exercise changes, meals, macros, pantry items, bodyweight entries, coach conversations, and notes needed to provide the service. It also stores extracted results when you choose to analyze a receipt, food, machine, or gym.
Membership and product operation
Regimen handles subscription status and dates, paywall presentation and purchase outcomes, limited attribution information, and bounded product events used to operate and improve the app. Regimen does not receive your payment-card number from Apple.
Device permissions and uploads
- Apple Health: with permission, Regimen reads steps, body-mass samples, and qualifying workouts. The shipping app requests no Health write access. Regimen does not use Apple Health data for advertising or marketing.
- Speech: recognition runs on your device. Raw microphone audio is not uploaded. Text you submit after transcription is processed like text you type.
- Food barcodes: the barcode image is processed on your device. The barcode number is sent to nutrition lookup services.
- Chosen photos: receipt, equipment, and gym photos you choose are sent to an AI service for analysis. Regimen does not store the image bytes in its application database, but it can store the extracted result.
- Notifications: Regimen stores the Apple push token and your reminder choices when you enable notifications.
How Regimen uses information
Regimen uses this information to:
- create, run, and update your training and nutrition plan;
- show logged progress and keep changes tied to the correct account;
- answer coach requests and analyze content you choose to submit;
- provide reminders, membership access, support, exports, and deletion;
- protect the service, enforce limits, diagnose failures, and measure whether core product flows work; and
- meet legal, safety, accounting, and platform obligations.
AI processing
Regimen sends relevant request text and context through OpenRouter to a selected AI model provider. Depending on the task, that context can include profile details, injuries, food restrictions, medication cadence, recent logs, plan targets, notes, conversation history, and images you choose to submit.
AI-provider retention and training practices differ by provider and route. Regimen does not describe every AI request as anonymous or promise zero provider retention.
Services that process information
Regimen relies on the following services for specific jobs:
- Apple: App Store billing, StoreKit, HealthKit, push notifications, App Attest, and attribution;
- Clerk: sign-in and account identity;
- RevenueCat: purchase validation and membership entitlement status;
- Superwall: paywall delivery and pseudonymous paywall, device, and purchase-flow events;
- Vercel and Regimen's database provider: application hosting and storage;
- OpenRouter and selected model providers: AI requests and chosen-image analysis; and
- USDA FoodData Central and Open Food Facts: food and barcode nutrition lookup.
These services process information under their own terms and retention practices and can process it in countries where they operate. Regimen can also disclose information when required by law, to protect people or the service, or as part of a business transaction with appropriate safeguards.
Retention
Account content, plans, logs, membership status, and paywall records remain until you delete the account. Generation diagnostics, nutrition-coverage events, product events, and client-adoption receipts are kept for up to 90 days. Completed work receipts are kept for 30 days. Expired rate-limit records are kept for up to 7 days. Short-lived pending operational records and expired leases are kept for up to 1 day.
Account-deletion work remains until the supported provider action finishes; its completed operational receipt is kept for up to 30 days. Service-provider records and backups can follow different retention schedules. Some billing, security, de-identified abuse-prevention, or legally required records can remain after account deletion.
An account-detached device identifier and generation can remain until that device advances to its next local account state. This lets a lost account-deletion response finish without restoring the deleted account.
Your controls
- Review or revoke Apple Health, speech, photo, and notification permissions in iOS Settings.
- Use You → Account → Prepare data export to create a JSON export of Regimen account data.
- Use You → Account → Delete account to delete the account and account-linked data from Regimen's primary application database. Regimen also queues deletion work for its identity, membership, and paywall providers.
- Use Apple's subscription settings to cancel a membership. Deleting a Regimen account does not cancel an App Store subscription.
Depending on where you live, you can have additional rights to access, correct, delete, or restrict use of personal information. Regimen does not sell personal information or use it for third-party targeted advertising.
Security and changes
Regimen uses technical and organizational safeguards intended to protect information. No storage or transmission method is completely secure. This notice can change when the product or its providers change. The effective date above will change with it.
Contact
For a privacy question or request, email michaeldleon@proton.me.