Privacy Policy
Version 4 · 28 August 2026 · Русский
Stele keeps your training on your phone. There is no account to create, no server of ours to sign in to, and no copy of your data on our side. We do not collect, receive, sell or share your personal data, because it never reaches us.
This document spells that out in full, because both app stores require a policy that lists what is collected, how it is used, who it is shared with and how it is deleted — even when the answer is nothing.
Who we are
Stele is made by an independent developer based in the Republic of Belarus. Questions about this policy, or about your data: support@getstele.app.
What the app records, and where it stays
The app records what you enter: training programs, workouts, sets, reps and weights, body weight, recovery marks, session notes and your settings. All of it is written to storage on your own device by the app itself. None of it is transmitted to us, and we have no way to read it.
What the app never collects
No name, email address or phone number. No contacts. No location, precise or approximate. No photos. No advertising identifier, device fingerprint, or identifier tied to your phone or to you. (The AI feature sends a random identifier the app makes up for this installation — see below.) No crash reports. No usage statistics, analytics or behavioural data. The app contains no analytics, advertising or tracking components of any kind.
Health data
With your permission the app reads two kinds of health data — dietary energy, so the Body screen can show what you have eaten beside your training, and body weight, so weigh-ins recorded elsewhere appear in your trend. It writes back only the weigh-ins you type into the app, so your other apps show the same number. On iPhone this is Apple Health; on Android it is Health Connect.
Health data is read on the device, used only to draw the screens just described, and is never transmitted to us, never shared with anyone, and never used for advertising, profiling or any purpose other than showing you your own figures. You can withdraw the permission at any moment in your phone's settings, and the app keeps working without it.
When anything leaves your device, and what
Two features send anything at all, both optional and both off until you use them: composing a program with AI, and WHOOP sync. Everything else described above stays on your phone. Both go through a small server of ours, which exists so that no key has to be shipped inside the app, where it could be read out.
Composing a program with AI
If you ask the app to write or convert a training program, what you typed in that conversation — and any file you attach to it, such as a coach's plan — is sent to our server and passed on to Anthropic, which runs the model that answers. Your training answers from the first-run questions travel with it, because a program is written from them: how long you have trained, what you are training for, and the year you were born if you gave one. A random identifier for this installation goes too, and is used for one thing: counting how many conversations the installation has had this month. It is not linked to you, is not an advertising or device identifier, and is generated by the app itself.
What is *not* sent: your training history, your sets and weights, your body weight, your recovery marks and your notes. None of that is part of the conversation.
Our server keeps no copy of the conversation. It holds only that monthly count against the random identifier. Anthropic processes the request under its own terms and privacy policy as our processor, and does not use it to train models. If you never use this feature, nothing is ever sent.
WHOOP
WHOOP sync is off unless you turn it on. There are two ways to connect, and they differ in what passes through us.
With the **Connect WHOOP** button, the sign-in code your phone receives is sent to our server, which exchanges it with WHOOP for access tokens and hands them back. It has to be done there rather than in the app because the exchange needs a secret that cannot safely live inside a shipped app. Our server keeps no copy of that code or of your tokens; they are stored on your device.
If instead you register an application in your own WHOOP developer account and paste its Client ID and Secret into the app, your phone talks to WHOOP directly and nothing passes through us at all.
Either way, the credentials and tokens are stored only on your device, are deliberately excluded from the app's own backup file, and what comes back is your recovery score, stored on your device like everything else. WHOOP is a separate company and your use of it is governed by WHOOP's own terms and privacy policy.
Files you export
The app can write a Markdown report and a JSON archive of everything it holds. Where they go is your choice: the app's own folder, or a folder you pick — including one that syncs to a service such as iCloud Drive or Google Drive. If you pick such a folder, that service handles the file under its own privacy policy. We never see these files.
Sharing with third parties
We share nothing, because we hold nothing. Nothing is sold, rented or disclosed to advertisers, data brokers or analytics providers. The only parties involved at all are Apple and Google, who distribute the app and collect their own data under their own policies; Anthropic, and only if you use the AI feature; WHOOP, and only if you connect it; and a cloud storage provider, and only if you choose a folder that syncs to one. Each acts under its own privacy policy, offering protection at least equal to this one.
How long it is kept, and how to delete it
We keep nothing, so we have nothing to retain or to delete. What you enter stays on your device until you delete it in the app or delete the app itself — removing the app removes everything it stored. Files you exported stay where you put them and are yours to delete. Health and notification permissions are revoked in your phone's settings. WHOOP is disconnected with the Disconnect button on the WHOOP screen, which erases the stored credentials and tokens from the device.
Security
Your data sits in the app's private storage, protected by the operating system's sandbox and by your device passcode and disk encryption. The WHOOP connection uses HTTPS. No storage or transmission is perfectly secure — but nothing of yours is held anywhere we control.
Children
The app is not directed at children under 13, or under the minimum age set by the law where you live. We do not knowingly collect personal data from anyone, of any age.
Legal basis for processing
Where the GDPR applies: the app processes what you enter on the basis of your consent, given by using it, and it processes nothing anywhere else. Health data is a special category under Article 9 and is handled only with the explicit consent you give through your phone's own Health permission prompt — only on the device, and only to draw your own figures back to you. You can withdraw that consent at any time in your phone's settings, and the app keeps working without it.
International transfers
None on our side, because nothing reaches us. If you connect WHOOP, your phone sends your request to WHOOP's servers wherever those are; if you choose a folder that syncs to a cloud service, that provider stores the file wherever it stores files. Both act under their own policies and their own transfer safeguards.
Your rights
Data that never leaves your device stays under your control. Where the GDPR, the Republic of Belarus's personal data law or a comparable law gives you rights of access, correction, deletion or portability, those rights are met inside the app: everything is on screen, editable, exportable from the Export tab, and removable by deleting the data or the app. If you believe we hold something about you, write to us and we will confirm that we do not. You also have the right to complain to a supervisory authority — in the EEA or the UK, your national data-protection authority; in Belarus, the National Centre for Personal Data Protection.
California
We do not collect, sell or share personal information as the CCPA uses those words, we do not use it for cross-context behavioural advertising, and we offer no financial incentive for data. A request to know or to delete has nothing to answer, because we hold nothing.
Changes
If this policy changes in a way that matters, the app shows the new version and asks you to accept it again. The version and date are at the top of this document.
Contact
support@getstele.app