The short version of the privacy policy, as a table. Every row is something you switch on yourself; nothing here happens until you do.
Everything is stored in one Postgres database at Supabase, in the EU (eu-west-1, Ireland), where the database itself — not the app — enforces that you can only read your own rows.
| Source | What it takes | What it is for | Who else sees it | How to turn it off |
|---|---|---|---|---|
| Apple Health | Workouts with heart rate and distance, heart rate, heart-rate variability, resting heart rate, VO2 max, steps, body mass and sleep from your iPhone | The morning session, readiness, the debrief, your weight chart | Nobody. Health data is never sent to OpenAI, never used for advertising, never stored in iCloud | iPhone → Settings → Health → Data Access → Iron U. Read permission only: Iron U cannot write to Health |
| Strava (coming — not in this build) | Your activities and their heart-rate streams, once the connection exists | Time in zone, so the app can tell an easy session from a hard one | Strava will see that you connected | Nothing to turn off yet: the row in Data sources says "coming" and does nothing |
| Garmin, via your own Mac | Activities, sleep and daily metrics, pulled by a program that runs on your computer with your Garmin login | The same as above, with more detail than Health carries | Nobody. Your Garmin login stays on your own Mac and never reaches us | Stop running the program |
| Meal and drink photos | The photo, and the estimate made from it | A log of what you ate and drank. It is never a target and never sets a calorie deficit | The photo is sent to OpenAI for one request. It is not used to train models and is kept by OpenAI for up to 30 days for abuse checks | Do not photograph. Delete an entry and its photo is deleted too |
| AI (estimates, session sentence, coach) | The photo, or the numbers already calculated for one session, or your question with your recent training numbers | The estimate, one sentence under a debrief, an answer built from your own data | OpenAI, per request, under the terms above | Do not use those screens. Or add your own OpenAI key in Settings, and ours is never used |
| Weather | A latitude and longitude — nothing else, and only if a venue is on your account. This build has no way to set one, so a new account sends nothing | Heat warnings, and whether the sea is swimmable | Open-Meteo receives the coordinates with no name and no account | Nothing to turn off until a venue can be set |
| Notifications | The times you choose, and your average wake time if the app knows it | The morning line and the evening summary | Nobody. They are built and scheduled on your device by iOS; there is no push server | iPhone → Settings → Notifications, or Settings → Notifications in the app |
| Your account | Email address, password hash, profile, race, and the answers you type | Signing in, and building the plan | Nobody | Settings → Delete account |
Two things Iron U does not do
No advertising and no analytics. There is no advertising identifier, no tracking library and no analytics tool in the app or on the website. Nothing about you is sold or shared with an advertiser.
No health data for anything but your training. Apple's rules for HealthKit forbid using health and fitness data for advertising, marketing or data mining, and Iron U does not.
Deleting
One meal, one drink: delete it and the photo goes with it.
Everything: Settings → Delete account. Every row, every photo and the account itself, behind one confirmation, with no copy kept.