Beta
Privacy Policy
Last updated: 23 July 2026
IronMate is an AI training partner. To do that job we need to learn who you are, remember what you tell us, and process some of your inputs through AI services. This page explains exactly what data we collect, what we do with it, who else sees it, and how long we keep it.
If anything in this policy is unclear, write to hello@ironmate.ai and we'll explain or fix it.
1. What we collect
From your device
- Device identifier - a per-install UUID we mint locally on first launch. Not your phone's serial number. Resets if you reinstall.
- App version + build number so we can debug regressions.
From you, directly
- Waitlist signups - if you join the early-access waitlist on ironmate.ai, we keep the name and email you submit so we can email you when the beta opens. We don't share this list with anyone. We delete your row on request, and we stop holding it once you accept the beta invite and become a regular IronMate account.
- Onboarding answers - your mission, target physique, schedule, injuries or limitations, training context.
- Coach configuration - your chosen push style, tone, voice preference, check-in cadence, and any free-text context you provide.
- Optional starting photo - a single physique photo you may upload during onboarding so IronMate can read where you're starting from.
- Workouts you log - sets, weights, reps, mood, soreness flags, and any notes you record.
- Coach conversations - the text turns you exchange with IronMate inside the app.
From your usage
- Memory snippets - short text observations the coach extracts about what works for you, written into a memory store so future sessions are smarter. You see these. You can delete them.
- Crash reports + error logs - anonymous traces that help us fix bugs.
We do not collect: your contacts, your camera roll beyond the one photo you pick, your location, your health data, or anything from other apps on your phone.
2. Photo analysis - the special case
If you upload a starting photo during onboarding, here is exactly what happens:
- The image is sent over HTTPS to our backend in Ashburn, Virginia, USA.
- Our backend forwards the image to OpenAI for analysis by their GPT-4o vision model.
- OpenAI returns a structured text reading (observations, opportunities, strengths, and a one-sentence starting summary).
- The text reading is stored as a memory snippet on your IronMate account.
- The original photo is deleted from our servers within 60 seconds of the analysis returning. A background sweep also runs every 5 minutes to catch any orphan files.
- OpenAI does not retain your image for training; per their API terms (openai.com/policies/api-data-usage-policies), customer API content is not used to train their models and is retained for at most 30 days for abuse monitoring.
You can skip the photo step. The app works without it.
3. AI processors we use
IronMate doesn't run AI models on its own hardware. We use these third parties:
- DeepSeek (Hangzhou DeepSeek AI, Hangzhou, China) - the DeepSeek V4 Flash language model, reached via api.deepseek.com, generates coach replies and personalizes your training plan. Privacy policy.
- DeepInfra (USA) - runs the DeepSeek V3 model that detects when a conversation should update your training plan, and the BGE-M3 embeddings used to search your memory store by meaning. Privacy policy.
- OpenAI (San Francisco, USA) - vision models for photos only: GPT-4o reads your optional onboarding photo, and GPT-4o mini reads photos you attach in coach chat. Privacy policy.
- ElevenLabs (USA) - text-to-speech for the voice coach narration, and the optional end-of-workout voice debrief conversation. Privacy policy.
When the app calls one of these services, we send only what that service needs - the photo for vision, the relevant text for chat, the snippet text for embedding. We do not send your device ID or any other unrelated data to AI processors.
Voice. Voice coaching is live in the current build. Speech recognition for workout logging runs entirely on your device using Apple's speech frameworks; that audio never leaves your phone. When you ask the coach a question out loud, your words are transcribed on-device and sent to our servers as text only. The one case where voice audio leaves your device is the optional end-of-workout debrief: if you choose to talk through your session, that conversation streams audio to ElevenLabs while the debrief runs. Skip the debrief and no voice audio is sent anywhere.
4. Where your data lives
- On your device - the SwiftData store inside the IronMate app. Workouts, sessions, set logs, and your coach configuration live here.
- On our backend - a PostgreSQL database with pgvector, hosted on Hetzner servers in Ashburn, Virginia, USA. This holds your memory snippets, the structured photo reading (text only, not the photo), and a copy of your coach configuration so the API can answer turn-by-turn requests.
- With the AI processors above - only momentarily, per call.
All data in transit uses HTTPS with TLS 1.2 or higher. Database backups are encrypted at rest.
5. Retention
- Photo files: deleted within 60 seconds of analysis returning.
- Memory snippets, workout logs, coach conversations: retained for as long as your IronMate account exists.
- Crash reports + error logs: retained for up to 90 days, then auto-purged.
- When you delete your account: we delete your row from our database within 30 days. AI processors that briefly saw your data follow their own retention windows (max 30 days at OpenAI per the policy linked above).
6. Your rights
You can, at any time:
- Access - request a copy of everything we hold about you.
- Correct - update your onboarding answers, coach config, or memory snippets directly in the app.
- Delete - wipe your account and all associated data through the in-app "Reset Device Data" or "Delete Account" actions in Settings, or by emailing hello@ironmate.ai.
- Export - request a portable copy of your workout history and memory store in JSON format.
- Object - tell us you don't want a specific type of memory written about you.
Email hello@ironmate.ai with any of the above. We respond within 7 days.
If you're in the EU or UK, you have the same rights under GDPR. The legal basis for our processing is your consent (onboarding answers, photo upload) and contract performance (running the coach you signed up for).
If you're in California, you have the same rights under the CCPA. We do not sell or share your personal information.
7. Children
IronMate is not directed at children under 13 (under 16 in some EU jurisdictions). We do not knowingly collect data from anyone under those ages. If you believe a minor has signed up, email hello@ironmate.ai and we will delete the account.
8. Beta context
IronMate is currently in a TestFlight beta. The data practices above apply to beta testers exactly the same as to general-release users. If we change anything material between beta and general release, we will notify you in-app and update this policy with the new "Last updated" date.
9. Changes to this policy
If we change this policy, we update the "Last updated" date at the top. Material changes (new data we collect, new processors we use, new retention rules) are also surfaced in-app before they take effect.
10. Contact
Email hello@ironmate.ai for any privacy question or request. We answer.