Privacy Policy
Last updated 15 September 2026
The short version. Dynos stores your training and body data so the app can work for you. We do not sell it, we do not share it for advertising, and the app contains no advertising or analytics SDKs — only a crash reporter that is configured to never receive your personal or health data. Your workout plans are generated on your phone, not on a server. You can export everything as a CSV, and deleting your account really deletes it — including your profile photo. This summary is not a substitute for the detail below.
1. Who we are
Dynos is a strength-training app. This policy explains what we collect, why, how long we keep it, and what you can do about it. It covers both the Dynos mobile app and the dynos.fit website, which behave differently — see section 6.
The data controller is Dynos (dynos.fit). For any privacy question or request, contact support@dynos.fit.
2. What we collect in the app
Only what the product needs. There is no analytics or tracking SDK in the app and no hidden collection — the categories below are the complete list.
Account information
| Email address | Used to create and sign in to your account, and to send password resets. |
|---|---|
| Phone number | Only if you choose to sign in by phone. Used to send a one-time code. We do not use it for marketing. |
| Password | Handled entirely by our authentication provider and stored only as a salted hash. Dynos never sees or stores your plaintext password. |
Health and fitness information
This is sensitive data, and in the UK/EU it is a special category of personal data. We collect it only because you enter it, and only to personalise your training. It is never used for advertising and never sold.
| Body metrics | Height, weight, starting weight, body-fat percentage, resting heart rate, VO2max estimate, and any body measurements you record. |
|---|---|
| About you | Date of birth, gender, display name, full name, and your profile photo if you add one. |
| Wellbeing inputs | Sleep hours, stress level, recovery quality, and activity level, where you provide them. |
| Injuries | Areas you tell us you are training around, so plans can avoid them. |
| Training preferences | Goal, experience level, training frequency, session duration, preferred days, available equipment, and training location. |
| Training history | Workouts, exercises, sets, reps, weights, effort ratings (RPE/RIR), personal records, routines, goals, and derived weekly analytics such as volume and recovery ratio. |
| Settings | Units, first day of week, timezone, locale, and notification and celebration preferences. |
Diagnostics
When something goes wrong, the app records an error entry containing the error type, a stack trace, the app version, and the platform, so we can fix it. These entries are deliberately filtered: the app keeps an allow-list of which fields may be recorded, so your health fields, email, date of birth and profile-photo locations are stripped before an error is stored. Error entries are linked to your account so that deleting your account deletes them too, and are purged automatically after 90 days regardless.
The same filtered error summaries are also sent to Sentry, a crash-reporting service, together with the app version, operating system and device model, so we can see crashes as they happen across the beta. This is configured as narrowly as the tool allows: personal identifiers are switched off, no screenshots or screen contents are captured, no performance tracing runs, and every message is passed through the same redaction filter before it leaves your device. Sentry events are not linked to your account or email.
3. What we do not do
These are commitments about how the app is actually built:
- No advertising. There are no ads in Dynos and no advertising identifiers are collected or shared.
- No analytics or tracking SDKs in the app. The app ships with no analytics or attribution SDK. The only third-party SDK is the Sentry crash reporter described in section 2, which receives no personal or health data. (The website is different — see section 6.)
- No selling or sharing of personal data. We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
- No third-party AI processing. Dynos generates your suggested workouts on your own device. Your training and health data is not sent to any external AI or machine-learning provider to do it.
- No font or asset calls to third parties. Fonts are bundled in the app, so opening Dynos does not reveal your IP address to a font host.
- No push-notification server. Reminders are scheduled locally on your device.
4. How we use your data, and our legal bases
| Run your account | To authenticate you and keep your data available across your devices. Legal basis: performance of our contract with you. |
|---|---|
| Personalise training | To generate suggested workouts, track progress and personal records, and adapt volume around injuries and recovery. Legal basis: your explicit consent to process health data, which you give by entering it and can withdraw by deleting it or your account. |
| Keep the app working | To diagnose crashes and sync failures. Legal basis: our legitimate interest in a reliable, secure product. |
| Security and abuse prevention | To protect accounts and prevent misuse. Legal basis: legitimate interest and legal obligation. |
We do not use your data to make decisions with legal or similarly significant effects about you.
5. Where your data lives
Dynos is local-first. Your data is written to a database on your device first, which is why the app keeps working offline, and is then synchronised to our backend so it survives losing or changing phones.
Profile photos are stored in a private bucket that is not publicly readable. Access is scoped to the owning account and served through short-lived signed links.
Data on our backend is protected by row-level security, so one account cannot read another’s rows even if a client misbehaves.
6. The website is different from the app
We want to be precise rather than flattering here. The app contains no analytics. The dynos.fit website currently does:
- Google Analytics, to understand how people find and use the site. Advertising storage is disabled, so it is not used to build advertising profiles. If you are visiting from the EEA, the United Kingdom or Switzerland, analytics storage is switched off by default, so no analytics cookie is set and your visit is not measured.
- Vercel Analytics, privacy-focused aggregate traffic measurement provided by our hosting platform.
- If you join the waitlist, we store the email address you submit and send you a confirmation email.
There is no cookie banner because the site sets no analytics cookie where consent would be required. Vercel Analytics is cookieless and does not identify individual visitors.
8. How long we keep it
We keep your account and training data for as long as your account exists, because the product’s value is your history. When you delete your account, deletion is immediate and permanent as described in section 9.
- Diagnostic error entries are deleted automatically after 90 days, or immediately when you delete your account, whichever comes first. Sentry retains crash events for 90 days under its own retention settings.
- Waitlist email addresses are kept until the app is generally available and you have been invited, or until you ask us to remove yours, whichever is sooner.
- Backups. Our database provider may keep encrypted backups for a short rolling period, never longer than 7 days, for disaster recovery. Deleted data can persist in those backups for that period and is then gone.
- Support email you send to support@dynos.fit is kept for as long as needed to resolve your request and for a reasonable period afterwards for reference.
9. Your rights and controls
Two of these are built into the app rather than being request-only:
- Export. Profile → Export Data produces a CSV of your workout history on demand.
- Deletion. Profile → Permanently Delete Account erases your training data, your profile, your profile photo, your diagnostic entries, and your login itself. It is not a soft delete or a deactivation, it is not recoverable, and we cannot restore it afterwards. Your local copy on the device is wiped in the same operation.
Depending on where you live, you may also have the right to access, correct, or port your data, to object to or restrict processing, to withdraw consent, and to complain to your local data protection authority. Most correction can be done directly in the app; for anything else, contact us at support@dynos.fit and we will respond within the period required by applicable law.
If you are in California, we do not sell or share your personal information as those terms are defined by the CCPA/CPRA, and we will not discriminate against you for exercising your rights.
10. Children
Dynos is not directed at children and is not intended for them. You must be 18 or older to create an account, which matches the minimum age in our Terms of Service. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.
11. International transfers
Our service providers may process data in countries other than yours, including the United States. Where required, transfers rely on appropriate safeguards such as the European Commission’s standard contractual clauses. Our database and file storage are hosted by Supabase in the United States (AWS us-east-1, Northern Virginia), the website is served by Vercel’s global network, and crash reports are processed by Sentry in the United States.
12. Security
We use encryption in transit, hashed passwords handled by our authentication provider, row-level security so accounts are isolated at the database level, private storage with signed access for photos, and filtering that keeps sensitive fields out of diagnostic logs. No system is perfectly secure, but we would rather tell you exactly what we do than claim more than we can support.
13. Changes to this policy
If we change how we handle your data we will update this page and its “last updated” date. For material changes affecting how we use health data, we will seek your consent again rather than relying on a silent update.
14. Contact
Questions, requests, or complaints: support@dynos.fit. We are based in the United States and have not appointed a representative in the EU or UK under Article 27 of the GDPR; you can still reach us at the address above and complain to your local supervisory authority.
This document describes Dynos’ actual data handling as built. It has not been reviewed by a lawyer, and it is not legal advice. Have counsel review it before you publish it or submit the app for review.