OrderedStrength

Privacy

OrderedStrength Privacy Policy

Last updated: 1 September 2026. This policy covers the OrderedStrength iPhone app. It does not cover any other service.

The short version

Your training lives on your phone. We have no account system, so we do not know who you are. Six things can leave your device, and one of them should not be there. Point 4 is a set-submission left over from an earlier server design: it sent the sets you log, it contradicted what the rest of this page promises, and it was removed from the code rather than kept and explained. It stops on your phone when you next update. It is written here because you should not have to find it in a network log.

What stays on your device

All of this is stored on your iPhone. Nothing here is sent to us except where points 1, 2 and 4 below say otherwise:

  • Your name, age, bodyweight, height and sex, if you enter them. Bodyweight is also read from Apple Health when you grant permission, so it can reach the app without you typing it.
  • Every set you log: exercise, weight, reps, and the reps you had left in reserve. Point 4 explains what happened to this one.
  • Any injury you record, and how you said it felt.
  • Everything the coach learns about you: your strength estimates, fatigue model, calibration and history.

If you delete the app, this goes with it. That is why the app offers a backup file you keep yourself.

Apple Health

Only if you grant permission, the app reads: heart rate variability, resting heart rate, heart rate, sleep analysis, active energy, step count, respiratory rate, body mass, your completed workouts, and walking, running, cycling and swimming distance. It writes completed workouts and active energy back to Health so they appear alongside your other activity.

Health data is used on your device to inform recovery and readiness. Raw Apple Health records never leave your phone. The one exception is point 2: if you turn Cloud Answers on, the training context sent with your question can include a line derived from that data, such as your sleep debt in hours, or how many days of heart-rate variability Jerry has seen. You can revoke access at any time in Apple Health, and the app keeps working without it.

The six things that can leave your device

1. Jerry's voice · on when the spoken coaching voice is on

To speak in a natural voice rather than the built-in system voice, the text of the sentence Jerry is about to say is sent to our server, which forwards it to Microsoft Azure to turn into audio. Jerry's lines are a bounded set of templates, and each distinct line is fetched once and then stored on your phone and replayed from there forever.

Be aware: a spoken line can contain numbers from your session, such as a weight or a rep count, because that is what the sentence says. It never contains your name, and no other part of your training log is sent. Turning the voice off stops this entirely.

2. Ask Jerry · OFF unless you turn it on

If you enable Cloud Answers, then when you ask Jerry a question in chat, your typed question and the relevant training context needed to answer it are sent to our server, which forwards them to Anthropic to compose the reply. This is off by default. With it off, Jerry answers from the on-device engine and nothing is sent.

3. A daily usage summary · on by default, and you can turn it off

Once a day the app can send a short summary so we can tell whether the app is actually helping people train. It is tied to a random identifier created on your device, never to your name, and it contains day-level values only:

  • which days you opened the app, and which days you trained;
  • how far you got in setup, and how long it took to log a first set;
  • whether you have seen or bought Pro;
  • whether you have seen the experiment explanation, and whether an experiment has started or finished;
  • whether you have copied or shared one of Jerry's sealed predictions;
  • how many times Jerry has greeted you back after a break;
  • how many times the app crashed;
  • which language you use, and which version of the app you are on.

It does not include your sets, your weights, your body data, or anything from Apple Health. You can switch it off in Profile / Data & Privacy, and switching it off stops it completely.

4. Your logged sets · removed from the code, gone the moment you update

This one does not happen any more. The code that did it is gone, nothing in the app reaches it, and no current version sends a set. If your phone is still on an older version it is still in that one until you update, which is why this section is here rather than deleted. It goes when the last version that had it does.

What it was: when you finished a freestyle workout, the app sent each set you logged to our server, the exercise, the weight, the reps, and the reserve you reported. It was tied to a random identifier created on your device and never to your name, and it was not sold, shared or used to advertise to you.

It was left over from an earlier design in which the coaching engine ran on a server, and it survived the move onto the phone. It contradicted the promise at the top of this page, so it was removed rather than kept and explained away, and it was removed rather than given a switch, because a switch would have meant defending it.

5. A push notification token · not yet, because Apple has not enabled it for this version

To send you a notification at all, Apple has to give the app a device token, and we have to know where to send it. When the app starts it registers with Apple and sends that token, along with the language your phone is set to, to our server. The token identifies a copy of the app on one device, not you: it carries no name, no email and nothing about your training, and Apple reissues it.

In the version you can install today, this does not happen. The app has no push entitlement from Apple, so the registration fails and no token is sent to anyone. It is written here because the code path exists and will start working the day notifications are provisioned, and you should read about it before it does rather than after.

This is the plumbing behind Jerry's notes about your recovery and your weekly report. If you never allow notifications, nothing is ever delivered to it.

6. A fingerprint of each sealed prediction · on, and it carries no identifier at all

Before a set, Jerry writes down what he expects of you and seals it: a SHA-256 taken over that prediction together with a 32 byte random number that never leaves your phone. That fingerprint, and nothing else, goes to our server, which publishes one combined root hash per day to a public repository. The commit date there comes from GitHub rather than from us, which is what turns "he wrote it before the set" from our word into something you can check.

Without the random number the fingerprint cannot be reversed or guessed, so it says nothing about the lift, the weight, the reps or you. It is the only thing this app sends with no identifier attached at all: no name, no email, no account, and not even the random install identifier that points 3 and 5 carry. There is nothing here that can be linked to a person, a device or a session.

This is live in the version you can install. When the app comes to the front it sends the fingerprints it has sealed and not yet seen published, and it keeps each one until it can see that fingerprint inside a published day. That is the only reason it re-sends: so that a prediction cannot go missing from the record without anyone noticing. The request carries no account, no install identifier and no headers of ours at all, which is what the paragraph above means literally rather than as a figure of speech.

What we never do

  • No advertising, and no advertising networks.
  • No third-party analytics or tracking SDKs. There are none in the app.
  • No tracking you across other apps or websites, and no Advertising Identifier.
  • No selling or sharing your information with data brokers.
  • No account, so no email list, and no profile of you held on our side.

Your controls

  • Back up everything and restore a backup, in Profile / Data & Privacy. The file is yours.
  • Delete All Training Data, in the same place. This is immediate and cannot be undone.
  • Turn off usage sharing, in the same place.
  • Turn off Cloud Answers, in Profile / Apple Health.
  • Revoke Apple Health access, in the Apple Health app.
  • Delete the app, which removes everything stored on the device.

Service providers

Where data does leave the device it passes through our own server and then to: Microsoft Azure (speech synthesis) and Anthropic (chat answers, only with Cloud Answers on). They process it to return the result and we do not authorise them to use it for their own purposes.

Children

OrderedStrength is a strength-training tool intended for adults. It is not directed at children under 13, and we do not knowingly collect information from them.

Changes

If what the app does with data changes, this page changes with it and the date above is updated. The page is written from the app's own source code so that it stays true rather than generic.

Contact

Questions about this policy, or about your data: [email protected]