← Dynos

Privacy Policy

Last updated 15 September 2026

The short version. Dynos stores your training and body data so the app can work for you. We do not sell it, we do not share it for advertising, and the app contains no advertising or analytics SDKs — only a crash reporter that is configured to never receive your personal or health data. Your workout plans are generated on your phone, not on a server. You can export everything as a CSV, and deleting your account really deletes it — including your profile photo. This summary is not a substitute for the detail below.

1. Who we are

Dynos is a strength-training app. This policy explains what we collect, why, how long we keep it, and what you can do about it. It covers both the Dynos mobile app and the dynos.fit website, which behave differently — see section 6.

The data controller is Dynos (dynos.fit). For any privacy question or request, contact support@dynos.fit.

2. What we collect in the app

Only what the product needs. There is no analytics or tracking SDK in the app and no hidden collection — the categories below are the complete list.

Account information

Account information
Email addressUsed to create and sign in to your account, and to send password resets.
Phone numberOnly if you choose to sign in by phone. Used to send a one-time code. We do not use it for marketing.
PasswordHandled entirely by our authentication provider and stored only as a salted hash. Dynos never sees or stores your plaintext password.

Health and fitness information

This is sensitive data, and in the UK/EU it is a special category of personal data. We collect it only because you enter it, and only to personalise your training. It is never used for advertising and never sold.

Health and fitness information
Body metricsHeight, weight, starting weight, body-fat percentage, resting heart rate, VO2max estimate, and any body measurements you record.
About youDate of birth, gender, display name, full name, and your profile photo if you add one.
Wellbeing inputsSleep hours, stress level, recovery quality, and activity level, where you provide them.
InjuriesAreas you tell us you are training around, so plans can avoid them.
Training preferencesGoal, experience level, training frequency, session duration, preferred days, available equipment, and training location.
Training historyWorkouts, exercises, sets, reps, weights, effort ratings (RPE/RIR), personal records, routines, goals, and derived weekly analytics such as volume and recovery ratio.
SettingsUnits, first day of week, timezone, locale, and notification and celebration preferences.

Diagnostics

When something goes wrong, the app records an error entry containing the error type, a stack trace, the app version, and the platform, so we can fix it. These entries are deliberately filtered: the app keeps an allow-list of which fields may be recorded, so your health fields, email, date of birth and profile-photo locations are stripped before an error is stored. Error entries are linked to your account so that deleting your account deletes them too, and are purged automatically after 90 days regardless.

The same filtered error summaries are also sent to Sentry, a crash-reporting service, together with the app version, operating system and device model, so we can see crashes as they happen across the beta. This is configured as narrowly as the tool allows: personal identifiers are switched off, no screenshots or screen contents are captured, no performance tracing runs, and every message is passed through the same redaction filter before it leaves your device. Sentry events are not linked to your account or email.

3. What we do not do

These are commitments about how the app is actually built:

  • No advertising. There are no ads in Dynos and no advertising identifiers are collected or shared.
  • No analytics or tracking SDKs in the app. The app ships with no analytics or attribution SDK. The only third-party SDK is the Sentry crash reporter described in section 2, which receives no personal or health data. (The website is different — see section 6.)
  • No selling or sharing of personal data. We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
  • No third-party AI processing. Dynos generates your suggested workouts on your own device. Your training and health data is not sent to any external AI or machine-learning provider to do it.
  • No font or asset calls to third parties. Fonts are bundled in the app, so opening Dynos does not reveal your IP address to a font host.
  • No push-notification server. Reminders are scheduled locally on your device.

4. How we use your data, and our legal bases

Purposes and legal bases
Run your accountTo authenticate you and keep your data available across your devices. Legal basis: performance of our contract with you.
Personalise trainingTo generate suggested workouts, track progress and personal records, and adapt volume around injuries and recovery. Legal basis: your explicit consent to process health data, which you give by entering it and can withdraw by deleting it or your account.
Keep the app workingTo diagnose crashes and sync failures. Legal basis: our legitimate interest in a reliable, secure product.
Security and abuse preventionTo protect accounts and prevent misuse. Legal basis: legitimate interest and legal obligation.

We do not use your data to make decisions with legal or similarly significant effects about you.

5. Where your data lives

Dynos is local-first. Your data is written to a database on your device first, which is why the app keeps working offline, and is then synchronised to our backend so it survives losing or changing phones.

Profile photos are stored in a private bucket that is not publicly readable. Access is scoped to the owning account and served through short-lived signed links.

Data on our backend is protected by row-level security, so one account cannot read another’s rows even if a client misbehaves.

6. The website is different from the app

We want to be precise rather than flattering here. The app contains no analytics. The dynos.fit website currently does:

  • Google Analytics, to understand how people find and use the site. Advertising storage is disabled, so it is not used to build advertising profiles. If you are visiting from the EEA, the United Kingdom or Switzerland, analytics storage is switched off by default, so no analytics cookie is set and your visit is not measured.
  • Vercel Analytics, privacy-focused aggregate traffic measurement provided by our hosting platform.
  • If you join the waitlist, we store the email address you submit and send you a confirmation email.

There is no cookie banner because the site sets no analytics cookie where consent would be required. Vercel Analytics is cookieless and does not identify individual visitors.

7. Who else processes your data

We do not sell your data. We use a small number of service providers who process it on our instructions:

Service providers
SupabaseAuthentication, database, and file storage for the app. Processes your account and training data.
VercelHosts the dynos.fit website and provides its aggregate analytics.
Google AnalyticsWebsite usage analytics only. Not present in the app.
ResendDelivers our transactional email: sign-up confirmation, password reset, and the waitlist confirmation. Receives only your email address and the message.
SentryCrash reporting for the app. Receives filtered error summaries, app version and device/OS details — no account identifier, no health data, no screenshots (see section 2).
Google WorkspaceHosts the support@dynos.fit mailbox. Receives whatever you choose to send us.
AppleDistributes the app and processes any purchases under its own privacy policy.

We may also disclose data where legally required, or to protect the rights and safety of our users.

8. How long we keep it

We keep your account and training data for as long as your account exists, because the product’s value is your history. When you delete your account, deletion is immediate and permanent as described in section 9.

  • Diagnostic error entries are deleted automatically after 90 days, or immediately when you delete your account, whichever comes first. Sentry retains crash events for 90 days under its own retention settings.
  • Waitlist email addresses are kept until the app is generally available and you have been invited, or until you ask us to remove yours, whichever is sooner.
  • Backups. Our database provider may keep encrypted backups for a short rolling period, never longer than 7 days, for disaster recovery. Deleted data can persist in those backups for that period and is then gone.
  • Support email you send to support@dynos.fit is kept for as long as needed to resolve your request and for a reasonable period afterwards for reference.

9. Your rights and controls

Two of these are built into the app rather than being request-only:

  • Export. Profile → Export Data produces a CSV of your workout history on demand.
  • Deletion. Profile → Permanently Delete Account erases your training data, your profile, your profile photo, your diagnostic entries, and your login itself. It is not a soft delete or a deactivation, it is not recoverable, and we cannot restore it afterwards. Your local copy on the device is wiped in the same operation.

Depending on where you live, you may also have the right to access, correct, or port your data, to object to or restrict processing, to withdraw consent, and to complain to your local data protection authority. Most correction can be done directly in the app; for anything else, contact us at support@dynos.fit and we will respond within the period required by applicable law.

If you are in California, we do not sell or share your personal information as those terms are defined by the CCPA/CPRA, and we will not discriminate against you for exercising your rights.

10. Children

Dynos is not directed at children and is not intended for them. You must be 18 or older to create an account, which matches the minimum age in our Terms of Service. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.

11. International transfers

Our service providers may process data in countries other than yours, including the United States. Where required, transfers rely on appropriate safeguards such as the European Commission’s standard contractual clauses. Our database and file storage are hosted by Supabase in the United States (AWS us-east-1, Northern Virginia), the website is served by Vercel’s global network, and crash reports are processed by Sentry in the United States.

12. Security

We use encryption in transit, hashed passwords handled by our authentication provider, row-level security so accounts are isolated at the database level, private storage with signed access for photos, and filtering that keeps sensitive fields out of diagnostic logs. No system is perfectly secure, but we would rather tell you exactly what we do than claim more than we can support.

13. Changes to this policy

If we change how we handle your data we will update this page and its “last updated” date. For material changes affecting how we use health data, we will seek your consent again rather than relying on a silent update.

14. Contact

Questions, requests, or complaints: support@dynos.fit. We are based in the United States and have not appointed a representative in the EU or UK under Article 27 of the GDPR; you can still reach us at the address above and complain to your local supervisory authority.

This document describes Dynos’ actual data handling as built. It has not been reviewed by a lawyer, and it is not legal advice. Have counsel review it before you publish it or submit the app for review.