Beta
Privacy Policy
Last updated: 2 September 2026
IronMate is an AI training partner. To do that job we need to learn who you are, remember what you tell us, and process some of your inputs through AI services. This page explains exactly what data we collect, what we do with it, who else sees it, and how long we keep it.
If anything in this policy is unclear, write to hello@ironmate.ai and we'll explain or fix it.
1. What we collect
From your device
- Device identifier - a per-install UUID we mint locally on first launch. Not your phone's serial number. Resets if you reinstall.
- App version + build number so we can debug regressions.
From you, directly
- Waitlist signups - if you join the early-access waitlist on ironmate.ai, we keep the name, email, age range and gym experience you submit. We use them to email you when the beta opens and to decide which invite wave you belong in. We send you one confirmation email at signup and one when your wave opens, and nothing else. If you ask us to, we pass your details to Mailchimp so those emails are sent from there; Mailchimp is a US email provider and their privacy policy governs that copy. We don't share the list with anyone else. We delete your row on request, and we stop holding it once you accept the beta invite and become a regular IronMate account.
- Onboarding answers - your mission, target physique, schedule, injuries or limitations, training context.
- Coach configuration - your chosen push style, tone, voice preference, check-in cadence, and any free-text context you provide.
- Optional starting photo - a single physique photo you may upload during onboarding so IronMate can read where you're starting from.
- Workouts you log - sets, weights, reps, mood, soreness flags, and any notes you record.
- Coach conversations - the text turns you exchange with IronMate inside the app.
From your usage
- Memory snippets - short text observations the coach extracts about what works for you, written into a memory store so future sessions are smarter. You see these. You can delete them.
- Crash reports + error logs - anonymous traces that help us fix bugs.
Apple Health (optional)
If you connect Apple Health, and only with your permission, the app reads steps, active energy, exercise minutes, heart rate, resting heart rate, heart rate variability, sleep, VO2 max and workouts from Apple Health. The trends you see on the Health tab are built on your phone and stay there.
One summary row per day is sent to our server so your training partner can adjust your sessions: sleep minutes, heart rate variability, resting heart rate, steps, active energy, exercise minutes, VO2 max and a recovery read (ready, steady or low). It is stored with your account, deleted with it, and wiped by "Reset my data". You can stop your training partner from seeing it at any time in Settings, without disconnecting Apple Health.
IronMate writes the workouts you finish to Apple Health so they count alongside your other activity. We never sell health data and never use it for advertising. You can revoke access at any time in the iPhone Settings app under Health.
From the ironmate.ai website
- Google Analytics - the public ironmate.ai pages (home, privacy, terms, support) load Google Analytics 4, which records page views, approximate location from IP, device and browser type, and how you arrived at the site. We use it only to see how many people find the page and which pages they read. IP addresses are truncated by Google before storage, we have not enabled Google Signals or advertising features, and this data is never joined to your IronMate account.
- To opt out, use Google's browser opt-out add-on, or your browser's tracking protection. Nothing on the site is gated on analytics running.
We do not collect: your contacts, your camera roll beyond the one photo you pick, your location, or anything from other apps on your phone.
From the app, anonymously (Firebase Analytics)
The iOS app includes Google's Firebase Analytics so we can see which parts of IronMate people actually use - how many sessions get started, which screens are opened, where people drop out of onboarding. It records app opens, screen names, session length, app version, device model and OS version, and a country-level location derived from IP.
What it does not do: we do not collect the advertising identifier (IDFA), we do not run any advertising or ad measurement, and we do not use this data to track you across other companies' apps or websites. That is why IronMate never shows you the "Ask App Not to Track" prompt - there is nothing to ask about. Your workouts, coach conversations, memory snippets, photos and health data are never sent to Firebase; that data stays on the path described above.
The analytics identifier Firebase uses is per-install and resets when you delete and reinstall the app. It is not joined to your name or email.
2. Photo analysis - the special case
If you upload a starting photo during onboarding, here is exactly what happens:
- The image is sent over HTTPS to our backend in Ashburn, Virginia, USA.
- Our backend forwards the image to OpenAI for analysis by their GPT-4o vision model.
- OpenAI returns a structured text reading (observations, opportunities, strengths, and a one-sentence starting summary).
- The text reading is stored as a memory snippet on your IronMate account.
- The original photo is deleted from our servers within 60 seconds of the analysis returning. A background sweep also runs every 5 minutes to catch any orphan files.
- OpenAI does not retain your image for training; per their API terms (openai.com/policies/api-data-usage-policies), customer API content is not used to train their models and is retained for at most 30 days for abuse monitoring.
You can skip the photo step. The app works without it.
3. AI processors we use
IronMate doesn't run AI models on its own hardware. We use these third parties:
- DeepSeek (Hangzhou DeepSeek AI, Hangzhou, China) - the DeepSeek V4 Flash language model, reached via api.deepseek.com, generates coach replies and personalizes your training plan. Privacy policy.
- DeepInfra (USA) - runs the DeepSeek V3 model that detects when a conversation should update your training plan, and the BGE-M3 embeddings used to search your memory store by meaning. Privacy policy.
- OpenAI (San Francisco, USA) - vision models for photos only: GPT-4o reads your optional onboarding photo, and GPT-4o mini reads photos you attach in coach chat. Privacy policy.
- ElevenLabs (USA) - text-to-speech for the voice coach narration, and the optional end-of-workout voice debrief conversation. Privacy policy.
When the app calls one of these services, we send only what that service needs - the photo for vision, the relevant text for chat, the snippet text for embedding. We do not send your device ID or any other unrelated data to AI processors.
Voice. Voice coaching is live in the current build. Speech recognition for workout logging runs entirely on your device using Apple's speech frameworks; that audio never leaves your phone. When you ask the coach a question out loud, your words are transcribed on-device and sent to our servers as text only. The one case where voice audio leaves your device is the optional end-of-workout debrief: if you choose to talk through your session, that conversation streams audio to ElevenLabs while the debrief runs. Skip the debrief and no voice audio is sent anywhere.
4. Where your data lives
- On your device - the SwiftData store inside the IronMate app. Workouts, sessions, set logs, and your coach configuration live here.
- On our backend - a PostgreSQL database with pgvector, hosted on Hetzner servers in Ashburn, Virginia, USA. This holds your memory snippets, the structured photo reading (text only, not the photo), and a copy of your coach configuration so the API can answer turn-by-turn requests.
- With the AI processors above - only momentarily, per call.
- With Google Analytics and Firebase - website usage data and anonymous in-app usage events, on Google's servers, under Google's own retention settings. No training, health, photo or conversation content goes to either.
- With Mailchimp - waitlist name, email, age range and gym experience only, if we have enabled the Mailchimp sync so that beta emails are sent from there.
All data in transit uses HTTPS with TLS 1.2 or higher. Database backups are encrypted at rest.
5. Retention
- Photo files: deleted within 60 seconds of analysis returning.
- Memory snippets, workout logs, coach conversations: retained for as long as your IronMate account exists.
- Crash reports + error logs: retained for up to 90 days, then auto-purged.
- When you delete your account: we delete your row from our database within 30 days. AI processors that briefly saw your data follow their own retention windows (max 30 days at OpenAI per the policy linked above).
6. Your rights
You can, at any time:
- Access - request a copy of everything we hold about you.
- Correct - update your onboarding answers, coach config, or memory snippets directly in the app.
- Delete - wipe your account and all associated data through the in-app "Reset Device Data" or "Delete Account" actions in Settings, or by emailing hello@ironmate.ai.
- Export - request a portable copy of your workout history and memory store in JSON format.
- Object - tell us you don't want a specific type of memory written about you.
Email hello@ironmate.ai with any of the above. We respond within 7 days.
If you're in the EU or UK, you have the same rights under GDPR. The legal basis for our processing is your consent (onboarding answers, photo upload) and contract performance (running the coach you signed up for).
If you're in California, you have the same rights under the CCPA. We do not sell or share your personal information.
7. Children
IronMate is not directed at children under 13 (under 16 in some EU jurisdictions). We do not knowingly collect data from anyone under those ages. If you believe a minor has signed up, email hello@ironmate.ai and we will delete the account.
8. Beta context
IronMate is currently in a TestFlight beta. The data practices above apply to beta testers exactly the same as to general-release users. If we change anything material between beta and general release, we will notify you in-app and update this policy with the new "Last updated" date.
9. Changes to this policy
If we change this policy, we update the "Last updated" date at the top. Material changes (new data we collect, new processors we use, new retention rules) are also surfaced in-app before they take effect.
10. Contact
Email hello@ironmate.ai for any privacy question or request. We answer.