Private by design

Privacy
Policy

Your training data should help you train, not help someone else profile you. This policy explains what OPTAL processes, where it goes, and the controls available to you.

Effective August 10, 2026

Overview

OPTAL does not sell personal information, show third-party ads, use advertising networks, or track you across apps or websites. Workout and profile data is stored in the app's local database on your device, and while you are signed in it is also backed up to OPTAL's cloud database so you can restore it on a new or reset device. OPTAL uses Supabase to host that database and to authenticate your account.

Scope

OPTAL is operated by Connor Felice. This Privacy Policy describes how Connor Felice, operating as OPTAL ("OPTAL," "we," "us," or "our"), processes personal information when you use the OPTAL iOS app, the OPTAL website, or contact OPTAL. It does not govern services operated independently by Apple, Google, Supabase, or another third party.

By using OPTAL, you acknowledge the practices described in this policy. Where consent is required by law, OPTAL will request it separately.

Information OPTAL processes

Depending on the features you use, OPTAL processes the following categories:

  • Account information: your account identifier, sign-in provider, email address, and name or display name. Apple or Google provides permitted identity information when you choose that sign-in method. You may also add or edit your name and contact email in the app.
  • Google Sign-In technical information: when you choose Google Sign-In, Google's SDK may process your name, email address, phone number associated with the Google account, user identifier, IP-derived coarse location, device identifier, usage information, and other technical information for sign-in functionality, fraud prevention, security, and Google's limited analytics. OPTAL directly receives only the Google user identifier, email address, display name, and authentication tokens needed to sign you in.
  • Profile and fitness information: training goal and experience, unit preferences, selected strong or weak muscle groups, workouts, exercises, sets, repetitions, weight, effort, routines, schedules, and custom exercises. OPTAL does not collect bodyweight, height, or body measurements.
  • Calculated information: training recommendations and metrics such as estimated one-repetition maximum, stimulus, fatigue, overload, plateau, imbalance, progress, and similar insights calculated from your entries.
  • App settings: preferences such as appearance, units, default effort, tuning choices, onboarding status, and Live Activity state.
  • Authentication and security information: Supabase automatically records authentication events and related technical information such as the event time, account identifier, sign-in provider, IP address, user-agent information, and request or response metadata. This information supports authentication, rate limiting, abuse prevention, security auditing, and troubleshooting.
  • Diagnostic information: Apple may provide crash, hang, performance, and other diagnostic information under your device and App Store analytics settings. OPTAL also writes MetricKit diagnostics to the device's unified system log. OPTAL does not include an advertising, behavioral-analytics, or third-party crash-reporting SDK. Google Sign-In's limited analytics processing is described above.
  • Support communications: if you email OPTAL, we receive the address, message, attachments, and other information you choose to send.
  • Website technical information: website and hosting providers may process standard request information such as IP address, request time, browser type, and requested page to deliver and secure the site. The OPTAL landing and privacy pages do not include an advertising or behavioral analytics tracker.

OPTAL does not request permission to use iOS Location Services, contacts, camera, photo library, microphone, HealthKit data, or payment-card information in the current version. As described above, Google may estimate coarse location from an IP address when you use Google Sign-In.

How information is collected

Information comes directly from you when you create an account, complete your profile, log training, change settings, export or share content, or contact support. OPTAL also creates calculations from your entries on your device.

When you sign in, the selected provider supplies authentication credentials and permitted profile details. OPTAL sends the credentials needed to verify the sign-in to Supabase, which creates and maintains the OPTAL authentication record and session.

While you are signed in, the app uploads new and changed training, routine, custom exercise, and profile records to OPTAL's cloud database in the background so the backup stays current. Entries are written to the device first, so logging works with no network connection and uploads once one is available.

How information is used

OPTAL uses information only for the following purposes:

  • Provide the app: authenticate you, store workout history, build routines, calculate training insights, personalize units and recommendations, and support Live Activities, exports, and user-requested sharing.
  • Back up and restore: keep a copy of your training, routines, custom exercises, and profile in OPTAL's cloud database so it survives a lost, replaced, or reinstalled device, and restore it when you sign in again.
  • Protect and improve OPTAL: maintain account security, troubleshoot failures, respond to support requests, and understand reliability using diagnostics Apple makes available.
  • Comply with obligations: enforce applicable terms, protect rights and safety, prevent abuse or fraud, and comply with valid legal requirements.

OPTAL's automated calculations are fitness and training information. They are not medical advice, diagnosis, or treatment.

Storage and service providers

  • Your device: the app stores training, profile, settings, and calculated data locally using Apple platform storage, and it remains fully usable with no network connection. Sign-in credentials and sessions use Keychain-backed storage.
  • Apple: Sign in with Apple authenticates users who select it. Apple also provides the App Store, operating-system diagnostics, widgets, Live Activities, and related platform services. OPTAL does not store workout entries or training inferences in iCloud or CloudKit, and Apple does not receive them. See Apple's Privacy Policy.
  • Supabase: OPTAL uses Supabase to host OPTAL's cloud database and authentication service. It stores your account record, your profile, and the backup copy of your training data, and it receives the authentication credentials and related technical request information needed for sign-in, session management, security controls, account deletion, and authentication audit logs. Supabase acts as OPTAL's service provider and processes this information on OPTAL's behalf. See the Supabase Privacy Policy.
  • Google: Google Sign-In authenticates users who select it and provides OPTAL the account identifier, email address, profile name, and authentication tokens permitted by the user and Google account settings. The bundled Google Sign-In SDK also declares processing of phone number, IP-derived coarse location, device identifier, usage information, and other technical data for app functionality, fraud prevention, security, and limited analytics. OPTAL does not receive a phone number or precise location from Google Sign-In. See the Google Privacy Policy.
  • Cloudflare and support providers: Cloudflare hosts and secures the public OPTAL website and processes standard website request information needed to deliver it. Email providers process information needed to deliver support messages. See Cloudflare's Privacy Policy.

OPTAL requires service providers that process personal information on its behalf to protect it consistently with this policy and applicable law. Their own services are also governed by their privacy terms. Providers may process information in the United States or other countries where they operate.

Sharing and disclosure

OPTAL does not sell personal information, share it with data brokers, use it for cross-app tracking, or disclose it for targeted advertising.

Information is disclosed only to the service providers described above to operate OPTAL, to a destination you select when you export or share content, when reasonably necessary to protect OPTAL or others, in response to valid legal process, or as part of a merger, financing, acquisition, reorganization, or sale of assets subject to appropriate protections.

Retention and deletion

Training and profile information stays in the app's local database, and in OPTAL's cloud backup, until it is deleted. Removing the app deletes its local database but does not delete the cloud backup or the authentication record held by Supabase. Signing in again on another device restores your training from that backup.

Delete Local Data in Settings > Account removes this account's workouts, routines, and custom exercises from OPTAL's cloud database first and from the device second. Your account, profile, and settings are kept, so the account stays usable. If the cloud deletion cannot be confirmed, the app reports the failure and leaves your data in place rather than telling you it is gone.

Delete Account in Settings > Account first asks OPTAL's backend to permanently delete the Supabase authentication account and attempts to disconnect or revoke supported sign-in provider access. Deleting that account also deletes the training, routines, profile, and other account-scoped rows held in OPTAL's cloud database. After the backend confirms deletion, the app removes the profile and account-scoped data from the local database, clears the stored app credential, and signs you out. Provider revocation may require separate action in your Apple or Google account settings. If the backend cannot confirm deletion, the app keeps you signed in and preserves local data so you can retry.

OPTAL and its providers may retain support communications and limited security, audit-log, or backup information while reasonably needed to maintain security, resolve disputes, comply with legal obligations, or complete normal backup rotation.

Your choices and rights

  • Review and correct: review or edit your name, email, profile, and training information in the app.
  • Export: export training data from Settings and choose whether and where to share it.
  • Delete: use Delete Account in Settings > Account to delete your OPTAL authentication account and account-scoped app data. Contact OPTAL if you need help or want to make an additional privacy request.
  • Backup: see the state of your cloud backup, and when it last completed, in Settings under Backup. Delete Local Data and Delete Account both remove the cloud copy.
  • Provider access: manage or revoke Sign in with Apple or Google access through the applicable account provider. Revoking provider access may prevent future sign-in but does not itself delete the OPTAL authentication record.
  • Diagnostics: manage sharing of device analytics with developers in iOS Settings under Privacy & Security > Analytics & Improvements.

Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, objection, or an appeal concerning personal information controlled by OPTAL. Email to make a request. OPTAL may verify your identity before acting and will not discriminate against you for exercising a privacy right.

Washington consumer health data

This section supplements the rest of this policy for Washington consumers. OPTAL treats identifiable training inputs and the fitness or bodily-function inferences produced from them as consumer health data for purposes of this section.

Categories and purposes. Training inputs include your training goal and experience, selected strong or weak muscle groups, workouts, exercises, sets, repetitions, weight, effort, routines, schedules, and custom exercises. OPTAL collects these entries directly from you to provide the logging, history, routine, backup and restore, export, and sharing features you request. Inferred training information includes estimated one-repetition maximum, stimulus, fatigue, readiness, overload, plateau, imbalance, progress, and recommendations calculated by the app from your entries. OPTAL creates these inferences to provide the training-analysis features you request.

Sources. Consumer health data comes from information you enter in OPTAL and calculations OPTAL performs from those entries. The current version does not obtain health data from HealthKit, a wearable, a medical provider, or another health-data service.

Sharing. The categories shared are the training inputs and inferred training information described above. OPTAL discloses them to Supabase, which hosts OPTAL's cloud database and stores the backup copy as OPTAL's service provider, for the backup and restore purpose described in this policy. OPTAL also discloses them to a destination you select when you direct an export or share action. OPTAL does not share consumer health data with affiliates and does not sell it. Apple, Google, and Cloudflare do not receive workout entries or inferred training information as part of the roles described in this policy.

Your Washington rights. You may ask OPTAL to confirm whether it is collecting, sharing, or selling your consumer health data; access that data and obtain a list of applicable third parties and affiliates; withdraw consent; or delete the data. Email with “Washington consumer health request” in the subject. You do not need to create a new account, but OPTAL may request information reasonably necessary to authenticate you. Withdrawing consent may prevent OPTAL from providing features that require the affected information.

OPTAL will respond without undue delay and within 45 days after receiving a request. OPTAL may extend that period once by up to 45 additional days when reasonably necessary and will explain the extension during the initial period. Verified deletion requests will be applied to OPTAL's records, and OPTAL will notify applicable processors, contractors, and other third parties as required. Deletion from archived or backup systems may be delayed for up to six months where Washington law permits, and the affected data will not be used during that delay except as permitted by law.

If OPTAL refuses a request, you may appeal by emailing with “Washington privacy appeal” in the subject. OPTAL will respond to the appeal in writing within 45 days. If the appeal is denied, you may submit a complaint through the Washington Attorney General's consumer complaint process.

OPTAL uses consumer health data only for the purposes disclosed above and as needed to provide features you request. Before collecting an additional category or using consumer health data for an additional purpose, OPTAL will update this policy and obtain affirmative consent when Washington law requires it.

Security

OPTAL uses reasonable administrative and technical safeguards designed to protect information, including the iOS app sandbox, Keychain-backed credential storage, encrypted network connections, and the access controls provided by Apple and Supabase. Every table in OPTAL's cloud database enforces row-level security tied to the signed-in account, so one account's training data is not readable or writable by another. No method of storage or transmission is completely secure, so absolute security cannot be guaranteed.

Children

OPTAL is not directed to children under 13, and OPTAL does not knowingly collect personal information from a child under 13. If you believe a child has provided personal information, email so it can be reviewed and deleted as appropriate.

Changes to this policy

This policy may change as OPTAL evolves or legal requirements change. The effective date will be updated when the policy changes. If a change materially affects how personal information is used, OPTAL will provide additional notice when appropriate and obtain consent when required by law.

Contact

OPTAL is operated by Connor Felice. Questions, privacy requests, and complaints can be sent to .