Privacy Policy

Last updated: April 24, 2026

Setster is an AI training partner. To coach you well it has to remember your training — which means it processes a fair amount of personal data. This policy explains what we collect, why, who we share it with, and how to get rid of it.

Data we collect

Account data. Email address, and (if you sign in with Apple or Google) the name and avatar provided by those identity providers.

Onboarding profile. Experience level, age, primary training goal, available equipment, days per week, session length, injuries, unit system, and any free-text notes you provide.

Training data. Every workout log you create — strength sets, cardio, check-ins, body metrics — along with the programs your coach generates, your personal records, goals, and chat history.

Chat attachments. Images you upload during chat (for example, form checks) are stored in AWS S3 and served via CloudFront (images.setster.app).

Health data (iOS, with your permission). If you grant access, Setster reads Apple Health data — workouts, sleep, heart-rate variability, active energy, and recovery metrics — to personalize coaching. Setster can also write workouts back to Apple Health. Health data stays on device except when explicitly sent to our servers for coaching context.

Payment data. We do not store credit-card numbers. Web subscriptions are processed by Stripe; iOS subscriptions by Apple. We store your subscription status, plan, and renewal date so the app can gate access correctly.

Analytics. We use PostHog and Google Analytics to track product usage (page views, feature clicks, conversion events). These tools use cookies and identifiers in line with their own privacy policies.

How we use your data

To run the coaching service. Your profile, training history, and recent messages are assembled into a context snapshot that is sent to the AI model with each request. This is how the coach “remembers” your history.

To improve the coach's memory. We use Mem0 to extract durable facts about your training (e.g. “prefers volume-first programming,” “shoulder sensitive to OHP”) so future conversations feel continuous.

To operate the product. Delivering notifications, billing you, preventing abuse, and debugging issues.

To improve the product. Aggregated analytics help us understand what works. We do not sell your data.

We do not use your data to train foundation models. Your messages are sent to OpenAI for inference only, under their API data-use terms (no training on API inputs).

Who we share data with

We use a small set of service providers, each with access only to what they need:

  • Supabase — authentication and database hosting
  • OpenAI — chat model inference (your messages and training context)
  • Mem0 — durable memory extraction
  • Stripe — web subscription billing
  • Apple — iOS subscription billing and receipt validation
  • Amazon Web Services (S3 + CloudFront) — image storage and delivery
  • PostHog and Google Analytics — product analytics
  • Vercel — web hosting

We only share data with law enforcement when required by valid legal process.

Data retention

We keep your data for as long as your account is active. If you delete your account, we permanently remove your profile, logs, programs, goals, and chat history within 30 days. Aggregated, anonymized analytics may be retained longer.

Backups are retained for up to 90 days and then purged on a rolling basis.

Your rights

You can access, correct, export, or delete your data at any time. Email support@setster.app from the address associated with your account and we'll act within 30 days.

If you are in the EEA, UK, or California, you have additional rights under GDPR / UK GDPR / CCPA — including the right to object to processing and to lodge a complaint with a supervisory authority.

You can opt out of analytics via your browser's Do Not Track setting or by disabling cookies. Mobile users can reset their advertising identifier in system settings.

Security

Data is encrypted in transit (TLS) and at rest. Access to production data is limited to a small number of engineers and logged. We'll notify affected users within 72 hours of becoming aware of a breach that risks your rights.

Children

Setster is intended for users 18 and over. We do not knowingly collect data from anyone under 13. If you believe a child has given us their information, contact us and we'll delete it.

International transfers

Setster is operated from the United States. If you use it from outside the US, your data will be transferred to and processed in the US and wherever our service providers operate. By using the service you consent to this transfer.

Changes to this policy

We'll update this page when our practices change and bump the “Last updated” date at the top. For material changes we'll notify you by email or in-app before they take effect.

Contact

Questions, access requests, or complaints: support@setster.app. See also our Terms of Service.