Privacy Policy
Last updated: 1 March 2026
Introduction
SHFT (“we”, “our”, “us”) is a strength training app operated by SHFT. This Privacy Policy explains how we collect, use, and protect your information when you use our mobile application and related services.
Information We Collect
We collect the following types of information:
- Account information — email address, hashed password, and authentication tokens.
- Onboarding profile — training goals, experience level, preferred split type, session duration, training frequency, and optional body metrics (age, bodyweight, lift numbers).
- Workout data — session logs, sets, reps, weights, and progression states generated as you train.
- Apple Health data — bodyweight, resting heart rate, and HRV, only when you explicitly grant access. We read but never write to Apple Health.
- Coach conversations — messages you send to and receive from the AI coach, stored to maintain conversation history.
- Analytics events — anonymous usage events (e.g. “session completed”, “coach message sent”) to improve the product.
- Subscription data — purchase receipts verified with Apple to manage your subscription status.
How We Use Your Information
- Generate personalised workout sessions based on your profile and history.
- Power the AI coach with context about your training to provide relevant advice.
- Track progression and trigger deloads, phase transitions, and streak tracking.
- Verify in-app purchases and manage subscription status.
- Analyse anonymous usage patterns to improve the app.
AI Coach & Third-Party Services
The AI coach feature sends your training context and messages to Anthropic's Claude API to generate responses. Anthropic processes this data according to their own privacy policy. We do not share your email, password, or personal identifiers with Anthropic — only the training context needed to generate coaching responses.
We use Apple's receipt verification service to validate in-app purchases. Receipt data is sent to Apple's servers for verification.
Data Storage & Security
Your data is stored on secure, encrypted servers. Passwords are hashed using bcrypt. API communication is encrypted via HTTPS. We use JWT tokens for authentication with appropriate expiration windows. We do not sell, rent, or share your personal data with third parties for marketing purposes.
Data Retention & Deletion
Your data is retained for as long as your account is active. You can delete your account at any time from the Profile screen in the app. Account deletion permanently removes all your data, including workout history, coach conversations, progression states, and profile information. This action is irreversible.
Your Rights
You have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Delete your account and all associated data.
- Withdraw consent for Apple Health access at any time via device settings.
To exercise any of these rights, contact us at privacy@dailyshft.app.
Children's Privacy
SHFT is not intended for children under 16. We do not knowingly collect personal information from children. If we become aware that a user is under 16, we will delete their account.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy in the app. Your continued use of SHFT after changes are posted constitutes acceptance of the revised policy.
Contact
If you have questions about this Privacy Policy, contact us at privacy@dailyshft.app.