PLAN Privacy Policy
Policy version: 0.6. This version number is the one the app records in your consent history.
Effective date: October 11, 2026. Version 0.6 adds email sign-in and describes optional verified friend discovery. Publishing this policy does not change older builds, announce TestFlight availability or enable features marked inactive below.
Who we are
PLAN is a workout planning and tracking app made by Lauture Labs LLC ("we", "us"). Contact for privacy questions, access and deletion requests: support@lauturelabs.com.
The short version
- PLAN works without an account. A guest's workout data stays on the phone; optional crash reports and usage statistics follow the choices below.
- If you sign in with Apple or a verified email address, PLAN can back up and sync your workouts to our server.
- PLAN does not track you across other companies' apps or websites, never reads your advertising identifier, does not sell your data, and does not use it for advertising.
- Your weight, body measurements, calories and any health data are never shown to friends. PLAN does not collect weight or body measurements at all.
- Crash reports and usage statistics are off until you choose Share. You can change your mind at any time in Profile, Privacy and permissions.
- Health, Motion and Fitness, Photos, camera, location and notifications are all optional. PLAN offers them in one setup step right after you set up your profile, and otherwise asks only when you use the feature that needs them. You can say no to any of them and still use PLAN. Tracking is informational, not a permission PLAN requests.
- Health readings, motion steps and Health-derived readiness stay on this iPhone. They are never sent to Supabase or DeepSeek, crash or usage services, or friends.
- If you sign in, you can join groups. Group members see your display name, avatar, the messages you send and whether you joined or finished a group workout. They never see your reps, loads, calories, Health values, steps or place.
- Optional verified contact discovery is not enabled in this candidate. Selected-contact invitations remain available without address-book permission. The separate discovery scope and activation holds are explained below.
- Accepting a friend challenge shares your display name, qualifying workout count and rank with its participants. You see the rules before joining. Challenges never share individual workout details or Health data.
- PLAN Coach plans workouts for you. Only after you explicitly allow remote planning, our server sends catalog exercises and non-Health training preferences to DeepSeek, a provider based in China, without your name, email or account id. Separately allowing workout history adds your own PLAN workout decisions. Both choices start off. Remote PLAN Coach never sees your Health values, including derived readiness, or weight, body measurements, calories, steps, location, photos or chat.
- You can delete your account and data inside the app.
What PLAN collects, and why
On your phone, always
PLAN stores your workout plans, sessions, set logs (exercises, reps and loads you enter), coins, stars, medals, settings, and your choices in Privacy and permissions on your phone. This is how the app works. If you use PLAN as a guest, this data never leaves your phone, except as described under "Crash reports" and "Usage statistics" if you opt in.
If you sign in with Apple
When you choose Sign in with Apple, Apple gives PLAN a stable identifier for you and, on the first sign in, the name on your Apple Account if you allow it. PLAN stores the identifier in your phone's secure Keychain. PLAN does not ask Apple for your email address. Apple's own privacy terms apply to what Apple processes.
When the server is turned on for your build, signing in creates a PLAN account on our server (hosted by Supabase) and links it to your Apple identifier. We use it to recognize you, keep your data private to you, and sync it between your sessions.
If you continue with email
You can create an account with an email and password, or request a sign-in code. Supabase manages your verified email identity, encrypted sessions and password authentication. Resend delivers confirmation, sign-in and password-reset codes from PLAN. Codes expire after ten minutes. Your email is not sent to Coach, friends or analytics, and signing in does not turn on contact discovery. Passwords and codes are never stored in workout records, logged by PLAN or shared with our analytics services. You can reset your password in the app. Deleting your PLAN account removes its managed sign-in identity and associated PLAN records; it does not recall delivered emails or erase your mailbox.
Data synced to our server when you are signed in
- Your profile: display name, avatar choice, units, weekly goal, and your friend-visibility settings.
- Your workout plans, workout sessions, exercises and set logs, and your rewards (coins, stars, medals and weekly progress).
- Your profile photo, if you add one.
- A place label for a workout, if you use "Tag where you trained".
- Your onboarding answers and your week plan (see "Onboarding answers and your week plan").
- Your groups, group memberships, chat messages, reports and blocks (see "Groups and chat").
- Your room invitations, challenges and challenge memberships (see "Workout rooms, invitations and challenges").
- Your PLAN Coach decision log and a log of coach runs. The history switch controls whether the coach can use the decision log and build learned memory; it does not stop account backup of decisions (see "PLAN Coach").
- A record of your consent choices (what you chose, when, in which app and policy version), including that you accepted the group rules. Your choices about Apple Health, Motion and Fitness, Photos, notifications and iOS Contacts permission are recorded on your iPhone only and are not sent to our server. Discovery's separate matching/discoverability preferences are server records when that feature is enabled.
- If optional verified contact discovery is enabled: verified-identity tokens, masked phone/email values, verification dates, discovery preferences, temporary verification material and replay/abuse-prevention records described below. Matching lookup batches are processed, not stored as an address book or query history.
We use this data only to run PLAN for you: to show it back to you, sync it, calculate rewards, and support the group and challenge sharing you choose.
Onboarding answers and your week plan
After you set up your profile, PLAN asks a few optional questions: your goal, your experience, how many days a week you want to train, the areas you want to focus on and the equipment you have. You can skip any of them and change them later in Profile. PLAN does not ask about your weight, your body or weight goals. In the week planner you choose which workouts go on which days, and a reminder time for each day. These answers and your week plan are kept on your phone and, when you are signed in, synced to our server. They are used to suggest your week and to plan workouts with PLAN Coach.
Groups and chat
Groups need you to be signed in. You can create a group, or join one with an 8 character invite code or an invite link that someone shares with you. Anyone with the code can ask to join, so share it only with people you want in the group. The owner can change the code, remove members and delete the group.
What other members of your group see: your display name and avatar symbol, the plans you share with the group, when you joined or finished a group workout, and the messages and share cards you send. They never see your reps, loads, calories, Health values, steps or place.
Text messages contain up to 1000 characters. A workout share card shows only the plan title, exercise names, duration and the group plan it belongs to. Text and share cards are stored on Supabase until you delete them, their group or your account; the phone keeps a copy for quick opening.
You can separately choose or take one photo, review its group audience and explicitly tap Send photo. PLAN strips embedded camera/location metadata, validates and size-limits it, and uploads only that selection to a private message payload on Supabase. Current group members may explicitly open it; each open rechecks account/session, membership and blocks. No public image URL or persistent phone image cache is created. Message/group/sender-account deletion erases the payload; leaving ends access but does not recall a photo already sent. Reporting uses the restricted message/report mechanism, not a public photo copy. The beta limits images to 5 MB each, 10 sends per sender per UTC day, 25 MB retained per sender and 100 MB shared total; deleting stored bytes does not refund daily sends. A photo can contain personal information visible to its chosen audience. Private progress photos are never automatically shared here.
To keep groups safe, you can report a message (spam, harassment, inappropriate or other, with an optional note of up to 280 characters), block a member, leave a group and delete your own messages. The PLAN team reviews reports. When you block someone, their messages are hidden from you at once. When you leave a group, your membership is deleted and you stop receiving its messages.
Workout rooms, invitations and challenges
A group workout room uses the group's shared plan and chat. Its members can see who has joined, is ready or has finished. Your "Training" state is shown locally on your own iPhone, not broadcast to the room. Each person tracks their own workout; participants cannot see another person's logged sets, reps or loads. A nudge is an in-app invitation saved for one existing group member, not an iPhone push notification. The recipient can read the invitation and room it refers to; the sender receives confirmation when it is sent. You can dismiss it without joining.
Friend challenges are optional. The creator chooses most completed workouts over a set period, or first to a workout target before a deadline. Before accepting, you see the title, rules, time remaining and participant count. Acceptance shares your display name, qualifying workout count and rank with the challenge's active participants. Scores use server-confirmed completed sessions with a completed set, not calories, weight, load or Health data. Your friend-visibility and weekly-leaderboard settings do not hide a count you separately agree to share by joining a challenge. You can leave, report or block another participant. The creator can cancel the challenge. There are no payments or financial stakes.
Shared invitation links contain an invite code and, for a room, its room identifier. Anyone with a valid link can review and request to join, so share them only with intended friends. The PLAN invitation page has no analytics/advertising; its hosting provider receives the ordinary web request. Opening never automatically joins. If installing afterward, return to the original page/message and open PLAN, or explicitly paste its full link into the app. There is no silent clipboard read, fingerprinting or guaranteed automatic post-install restoration; a group code alone does not identify an exact room. Beta installation is offered only for a verified eligible external build, not an unavailable public App Store listing.
Selected-contact invitations
Apple's contact picker lets you choose one phone number or email address to prepare a room/challenge invitation. PLAN receives only that selection, temporarily, for the native Messages/Mail composer; you review the recipient/link and press Send yourself. Cancel sends nothing. This picker flow uploads no address book and does not infer that a selected contact uses PLAN. Manual links remain available independently of the optional discovery feature below.
Optional verified contact discovery (not enabled)
The discovery schema and API are installed at this candidate checkpoint; operator configuration is off and no active discovery collection has begun. Deployment is not feature activation. Provider, consent, security and disclosure gates must be reviewed before enabling it. The following describes the bounded feature if enabled, not current collection.
You can explicitly request a code to verify a US phone number or email. This is separate from Apple or email sign-in and does not merge accounts. Telnyx processes phone verification; Resend delivers email verification. Sending a code is not proof of ownership. Verification does not by itself enable either "Find friends using my contacts" or "Let contacts find me on PLAN"; these are separate choices, both off by default, and require the current group-rules consent. iOS Contacts permission is another separate choice and never enables either server preference.
After you enable matching and explicitly run Find friends, PLAN reads supported phone numbers and email addresses from contacts iOS permits. Full access permits a broader scan; limited access permits only your selected subset. Contact names are not fetched or uploaded. Normalized phone/email values go to Supabase in batches of at most 200 and are converted there into server-keyed matching tokens, not hashed on your phone before transmission. PLAN does not save these lookup batches as an address book or query history. Tokens are pseudonymous, not anonymous; scans and results are bounded and may be incomplete.
If you enable discoverability, eligible users checking your verified phone/email can receive your PLAN profile identifier and display name, subject to block rules. Your phone/email is not returned in matching results. No invitation, friendship or group membership is created automatically. Matching opt-out stops new matching requests on this iPhone; discoverability changes require server confirmation. Requests already transmitted or information others have seen cannot be recalled.
iOS Contacts status/history and the account-scoped local matching-off flag stay on this device without an address-book copy. Sign-out/backgrounding clear pending local discovery fields and results; sign-out does not delete server identities or withdraw server discoverability. Removing an identity and deleting an account have the distinct retention effects below. Provider-request handling remains a review hold before activation; the published delivery-provider terms are described below. PLAN makes no new provider contract or guaranteed-deletion promise.
PLAN Coach
PLAN Coach suggests workouts and fills your week. What it may see:
- The catalog ids of the exercises it can choose from, the muscle groups you picked, your equipment, your experience, your goal, the minutes you have and your days per week.
- Only after the separate Allow sharing with DeepSeek action: catalog candidates, selected body parts, equipment, training goal, experience, available time, training days and week dates. Viewing an explanation, Continue, completing setup or using a plan does not grant sharing.
- With remote planning also allowed and the separate default-off history switch on: your own PLAN workout decisions, including completed/skipped sessions, swaps, sets, reps, loads, effort ratings, edited targets, moved days, accepted/rejected suggestions and learned summaries. This is not HealthKit-derived data. Change either choice independently in Privacy and permissions.
Remote PLAN Coach (Supabase and DeepSeek) never sees your Health values, including derived readiness, or weight, body measurements, calories, steps, name, email, Apple identifier, location, photos, chat messages or groups. Health-derived readiness is used only on this iPhone by local planning, rules and validation to check suggestions and choose a lighter schedule; it is not disguised as a transmitted training constraint. Historical readiness-sharing consent cannot enable transmission.
Only after your current, explicit remote-planning permission, while signed in and online, the request goes from our server to DeepSeek, a provider based in China. The request does not include your name, email or account id. DeepSeek's API-specific retention and model-training protections for these requests have not yet been verified; we do not promise that it stores nothing or never uses requests for training. Its consumer privacy policy does not cover the personal data of our app's users sent through its API. When our server cannot answer, Apple Foundation Models can plan the workout on your iPhone without sending an additional request. A preceding server request may already have been transmitted. Otherwise PLAN's own rules on your iPhone plan it. Guests use only the iPhone options. These AI-generated suggestions may contain mistakes; review them before training. Whatever PLAN Coach suggests, you see it and can change it before you start.
Turning the history switch off prevents new coach requests from using your decision history or learned summary, even while that choice is still syncing. A request already sent may finish. Your decision log continues to sync with your account, but the coach cannot use it while the switch is off. "Delete coach history" in Privacy and permissions removes past coach decision events on this iPhone and, while signed in and connected, your decision history and learned summary from our server. Old decisions queued on another offline iPhone cannot recreate the erased server history. It does not delete workouts, plans, rewards or the coach's rate-limit run log. Deletion is not confirmed if the request fails; check your connection and retry. If the history switch stays on, PLAN Coach can learn from new decisions. We keep a log of coach runs (purpose, counts, how long it took and whether it worked) to limit how often it can be used and to fix problems.
The coach run log also stores a limited request summary: selected muscle groups, equipment, experience, minutes, days and the number of candidate exercises. It does not store raw Health readings or your name, chat, photos or location. This account-level diagnostic and quota log remains until account deletion, even after coach-history deletion.
Exercise demo videos
Most demonstrations use individually reviewed MuscleWiki footage through an authenticated Supabase proxy. A visible demo may play automatically on a suitable connection, unless Reduce Motion is on; you can pause or use Play instead. Internet and a signed-in account are required for these videos. MuscleWiki receives an exercise/video request from our server, not your identity or Health data. Recently loaded clips may briefly reuse a bounded, revocable memory buffer without another provider request. Buffers expire within two minutes or earlier when access expires, and are cleared on backgrounding, account/session changes, consent changes or memory pressure. Vendor video bytes are not stored in the database, cloud storage or a persistent device cache; durable request limits bound provider quota use. Attribution and the full frame remain visible. Written cues, timers and logging work without video playback.
Exactly Sauna, EZ-Bar Skull Crusher and Full-Body Stretch use individually reviewed owned Higgsfield-generated clips bundled with PLAN, available offline and to guests; their depicted people are synthetic, not real instructors. The stretching clip is a short upper/lower-body preview, not a complete routine; follow the written hold durations and seven-minute timer. Owned generated originals are privately archived, never a fallback for other exercises. A successful generation is not proof of safe or professionally certified technique. These demonstrations are not medical advice or a substitute for qualified instruction.
Profile photo
You can choose a photo with the system photo picker or take one with the camera. The system photo picker runs outside PLAN, so PLAN does not get access to your photo library: it receives only the one photo you pick. PLAN asks for camera permission only when you tap "Take photo", and the camera is used only for that picture. PLAN shrinks the photo, removes hidden information such as location data stored in the file, and keeps it on your phone. If you are signed in, it is also stored in a private storage area on our server that only your account can read. You can remove your photo at any time. PLAN does not save the photo to your Photos library.
Location (optional, off by default)
If you turn on "Tag where you trained" and allow location access, PLAN takes one approximate location when you tag a workout. It rounds coordinates to about one kilometer, asks Apple's map service for a place name and saves that name and rounded coordinates with the private workout. Apple receives the rounded coordinates for lookup. Friends, crash/usage services and Coach do not receive your place. Turn it off or type a place yourself instead.
Gym search separately uses Apple Maps. Optional Nearby sends a one-shot device location to Apple's map service after permission; Apple processes search/location under its terms. Results are temporary and shown with their Apple map, not copied into a lasting gym database. To save a reminder, be at the gym, type your own label and explicitly review/confirm a device-measured coordinate. Saved gyms/settings stay on this iPhone outside sync/analytics. Foreground and background reminder choices start off: foreground requires When In Use and precise access; background separately requires Always location and notifications. iOS monitors saved regions, not continuous routes. Notification text is generic; delivery is best effort, including after force quit/restart. Disabling/removing a gym unregisters its region/reminders; sign-out/account change stops old-scope monitoring. Account deletion removes its local gyms. Gym data never goes to Coach, friends or our server automatically.
Apple Maps also receives the visible map area when PLAN shows a map preview, including the device-measured gym location you review before saving a reminder. This is separate from PLAN's device-local gym library. [Apple Maps privacy](https://www.apple.com/legal/privacy/data/en/apple-maps/) describes Apple's processing of searches and maps.
Apple Health (optional)
Connect Health separately for each PLAN account to use these features. Disconnecting stops PLAN's Health features without changing your iOS permission decisions. A new account starts disconnected; existing iOS permission may be reused without another system alert. Manage Apple's read/write permissions in Health or Settings.
If you allow it, PLAN saves each workout you finish to Apple Health, with its type (strength, cardio or flexibility), its start time and its end time. PLAN does not write calories, heart rate or any other measurement to Apple Health. PLAN can also read the active calories that Apple Health holds for the time of that workout, for example from an Apple Watch, and shows the figure on your workout summary labeled Health. When there is no such figure, the summary shows an estimate labeled est.
PLAN can also read sleep, resting heart rate and heart rate variability from Apple Health for the last two weeks. Your iPhone computes a coarse readiness level (ready, steady or take it easy) for Home and local lighter-day suggestions. Readings and derived readiness are computed locally, not persisted or transmitted. PLAN asks to read nothing else from Apple Health. Workout-write authorization does not tell PLAN whether you allowed read access.
Health readings, motion steps and Health-derived readiness stay on this iPhone. They are never sent to Supabase or DeepSeek. PLAN does not persist these values, upload them to crash/usage services or friends, store them in iCloud, or use them for advertising/data mining. Old readiness-sharing choices do not authorize transmission. Change read/write access in the Health app. Deleting PLAN data does not remove workouts already saved in Health; remove them in the Health app. Deleting a PLAN account cannot reset an iOS permission decision.
Private progress photos
Choose or take a photo, review the full frame, then save it only on this iPhone. PLAN strips embedded location/camera metadata, size-limits it, uses protected account-separated files and excludes the library from device backup. Photos are not uploaded, AI-analyzed or automatically shared. Removing the app loses this library. Signing out hides it, never transfers it to another account. Account/data deletion removes the corresponding local library; a failed cleanup is reported and can be retried. Copies you exported elsewhere are not erased.
Steps (optional)
If you allow Motion and Fitness, PLAN reads today's step count from your iPhone's motion sensors and shows it as Steps today on Home. The count is read while Home is open. PLAN does not save it, send it anywhere, show it to friends or use it for rewards.
Tracking is not used
PLAN does not track you across other companies' apps and websites, never reads your advertising identifier, does not sell your data, does not show ads and does not share data with data brokers. It does not request App Tracking Transparency permission. The Privacy center can show the actual iOS status and historical choices without using them to enable tracking or analytics. Optional usage analytics uses a new random identifier each launch, regardless of that iOS status. A previous iOS decision is not reset when you delete a PLAN account.
PLAN's optional crash reports and usage analytics choices control its Sentry and PostHog services only. Apple's own sharing is managed in Settings, Privacy & Security, Analytics & Improvements. TestFlight separately collects beta crash logs and usage information automatically under [Apple's TestFlight privacy terms](https://www.apple.com/legal/privacy/data/en/test-flight/); PLAN's switches do not disable that collection. PLAN cannot present or reset Apple's analytics consent controls.
Saving a summary card to Photos (optional)
If you allow PLAN to add to your photos, the Save to Photos button on a workout summary saves one picture to your photo library. The card shows PLAN, the workout name, the date, the duration, how many exercises and sets you completed, and your coins. It does not show your weight, loads, calories, place or name. PLAN can only add pictures: it cannot see the photos you already have. Choosing a profile photo still uses the system photo picker and does not need this permission. Cards you save stay in your library if you delete your PLAN data.
Reminders (optional)
If you allow notifications, PLAN schedules a reminder on your iPhone on each day you have a workout planned, naming that plan, at the time you set for that day in the week planner (9:00 unless you change it). The reminders are made and delivered on your iPhone. PLAN does not use a server to send notifications and does not send marketing notifications. If you turn notifications off in iOS Settings, PLAN schedules none.
Friends
This beta has no seeded friends or activity. Its working social features are groups, workout rooms and challenges, described above. A separate friend activity feed and weekly friend leaderboard are not available yet. Their visibility preferences remain saved in Privacy and permissions for a future version; they do not change group messages or the workout counts you explicitly share by accepting a challenge. Your uploaded profile photo stays private to your account. Group members see your chosen avatar symbol and colour, not that photo; challenge standings show your display name and a generic symbol.
Crash reports (only if you choose Share)
If you choose Share, PLAN uses Sentry to send crash and error reports to help us fix bugs. A report contains technical details such as the app version, iOS version, device model, what the app was doing when it failed, and the error type, plus an identifier for this install of the app that cannot be tied to your name or account. PLAN is set up so that reports do not include your name, email, Apple identifier, account id, workout details, location, photos, or anything you typed. Reports are not tied to your account. They are kept only as long as needed to fix problems and improve the app, within Sentry's standard retention periods. If you say no, or turn it off later, PLAN sends no reports.
Usage statistics (only if you choose Share)
If you choose Share, PLAN uses PostHog to count which screens and steps people use and when something fails (for example a sync or sign in error), so we can improve the app. PLAN decides exactly which events can be sent; it sends no free text, names, emails, workout numbers, body data, locations or photos, and it does not record your screen. Events are tied only to a random identifier that PLAN creates on your phone, not to your name or account. The identifier is new each launch, regardless of the iOS tracking status. You can reset that identifier or turn statistics off at any time in Privacy and permissions; turning them off deletes the identifier from your phone. Events are kept only as long as needed to improve the app, within PostHog's standard retention periods.
What every service sees
Any time PLAN connects to a server, that server can see your phone's IP address and basic connection details, as with any internet service. We switch off IP-based location lookups in our analytics and ask our crash service not to store IP addresses.
TestFlight
If you are a beta tester, Apple's TestFlight automatically collects beta crash logs and usage information, plus feedback you choose to send, under Apple's terms. That is separate from PLAN's settings.
What PLAN does not do
- It does not track you across other companies' apps and websites, and it does not use or read your advertising identifier, regardless of the iOS tracking status.
- It does not sell, rent or share your personal data for advertising, and it does not use health or fitness data for marketing or data mining.
- It does not read your whole photo library. Apple's photo and contact pickers provide only an explicitly selected item. Optional contact discovery separately needs iOS Contacts permission to read allowed phone/email fields, not names; its lookup batches are not stored as an address book. Health reads are limited to active calories and the sleep/resting-heart-rate/heart-rate-variability readings described above.
- It does not use location without an explicit feature choice and permission. Background access is only for separately enabled saved-gym region reminders, never continuous route recording.
Who we share data with
We use these service providers to run PLAN. Their handling of data is governed by the agreements and terms applicable to their services; we do not make a blanket promise about every provider's independent uses:
| Provider | What for | What it receives |
|---|---|---|
| Supabase | Account, database and file storage; optional contact matching/verification when enabled | Your signed-in account data listed above; normalized matching phone/email values and account-bound verification material for the optional discovery feature |
| Telnyx | Optional US phone verification, not enabled in this candidate | Phone number, verification request and submitted code for checking, plus verification/profile identifiers; not your Apple or PLAN account identifier |
| Resend | Email account confirmation, sign-in and password-reset codes; optional discovery email verification is not enabled in this candidate | Recipient email and code message; optional discovery also uses a random delivery idempotency nonce and sends no Apple or PLAN account identifier |
| Sentry | Crash reports | Technical crash data, only if you opt in |
| PostHog | Usage statistics | Anonymous events, only if you opt in |
| DeepSeek | PLAN Coach requests (based in China) | The allow-listed request described under "PLAN Coach", without your name, email or account id, only when you are signed in; API-specific retention and model-training protections remain unverified |
| Higgsfield, MuscleWiki | Reviewed demonstrations | Higgsfield generates the three fixed owned demonstrations before release, without user data. MuscleWiki receives bounded exercise/video requests from our server, not user identity or Health data. No persistent vendor video copy is kept. |
| Apple | Sign in with Apple, TestFlight, map searches/previews/place lookup, system pickers/composers and device Contacts permission | As described above, including optional location sent for Apple Maps. Health, Motion and local notifications stay on-device. Contacts/Photos pickers provide explicit selections; full/limited device Contacts permission for optional discovery is separate and never enables matching by itself. |
We may also disclose information if the law requires it. We have not verified an API-specific agreement requiring DeepSeek to give our users' data the same protections described here. This is an unresolved release-review requirement, not evidence that the provider misuses data.
Resend processes verification emails under its [signup DPA](https://resend.com/legal/dpa). Its [published Pro retention policy](https://resend.com/security/gdpr) lists US storage, 30-day email/log retention, seven-day backups and deletion of remaining customer data within 90 days after terminating the Resend account—not after deleting a PLAN account. Earlier message removal requires provider support. These periods do not cover every independently controlled usage, billing, legal or compliance record. Provider-request handling must be verified before activation; five-minute codes are not a provider purge deadline. Removing PLAN-held records cannot recall messages or confirm provider-copy deletion; no blanket no-storage, no-training or equal-protection guarantee is implied.
Telnyx's [DPA](https://telnyx.com/legal/data-processing-addendum) is incorporated into its service agreement without further execution. It documents instructed processing, confidentiality, security and rights-request assistance. Its [privacy terms](https://telnyx.com/privacy-policy) describe independently controlled account/communications metadata for routing, billing, security, fraud prevention, service improvement and legal obligations; SMS content may be inspected for spam. Telnyx may also process Customer Content as an independent controller for service improvement; its DPA requires prior de-identification, pseudonymization or aggregation so the content does not identify us, our users or other individuals. Telecom carriers are not DPA subprocessors. The published terms establish no managed-Verify purge deadline or deletion triggered by removing a PLAN account. Agreement-termination deletion has legal-retention exceptions; carrier retention is not established here. This documented basis is not activation or legal certification.
How long we keep data
- On your phone: until you delete it or delete the app. (Items kept in your Keychain can survive deleting the app; "Delete account and data" removes them.)
- On our server: while your account exists, subject to the separate lifetimes and abuse/quota exceptions below. When you delete your account, we delete your account-linked data as described below.
- Chat messages and share cards: until you delete them, the group is deleted or your account is deleted.
- Workout room invitations and challenge records: while the related group, room or challenge exists. Leaving a challenge ends access but keeps its membership record; deleting your account removes your memberships and invitations, and challenges you created.
- PLAN Coach history and summary: until you tap "Delete coach history" or delete your account. Turning the switch off stops reads but keeps the rows until you delete them.
- PLAN Coach run log: with your account, and deleted when you delete your account.
- Requests already sent to DeepSeek: its API-specific retention period is unverified. Deleting PLAN-held account data or coach history does not establish that previously transmitted provider-held copies have been deleted.
- MuscleWiki playback bytes: bounded, revocable memory buffers within the same authorized account's foreground session. Dismissal revokes that view's playback access, but buffers may briefly remain for reuse. Buffers expire within two minutes or earlier when access expires; expiry, backgrounding, sign-out, account/session invalidation (including same-account session changes), consent changes or memory pressure revoke and clear them. No vendor video bytes are stored on disk or in a persistent device cache, database, cloud storage or CDN. The three fixed owned demonstrations and intro resources: part of the installed app, removed with it.
- Private progress photos and saved gyms: only on this iPhone until corresponding deletion or removal of the app. Gym opt-out stops monitoring; sign-out/account changes isolate local data.
- Crash reports and usage statistics: only if you chose Share, and kept only as long as needed to fix problems and improve the app, within the providers' standard retention periods. These are anonymous and are not tied to your account, so they are not deleted when you delete your account; resetting or removing the identifier on your phone breaks any link to your device.
- Your consent history is stored with your account on our server and is deleted when you delete your account. Choices about Apple Health, Motion and Fitness, Photos, notifications and iOS Contacts permission are kept on your iPhone only and are erased with the corresponding app/account data. Discovery's separate server preferences remain until account deletion; iOS permission decisions themselves are not reset by PLAN deletion.
- Optional discovery verification: a code is valid for at most five minutes, not a promise to purge personal information within five minutes. Successfully committed terminal transitions, including completed verification, cancellation, failure finalization or identity removal, clear the raw delivery target, code hash and provider verification/message identifier. Expired material is otherwise scrubbed only by a later successfully committed authorized discovery operation, not a timed job. Masked delivery values and profile identifiers become eligible for further scrubbing after one day under that same lazy condition; without such an operation, material can remain longer.
- Optional discovery identities/replay records: verified-identity tokens, masked values and verification dates remain until identity removal or account deletion. Removing an identity does not delete its challenge/replay row: owner/session bindings, keyed identity token, operation/state/time/provider/reservation metadata remain until account deletion to prevent replay. Account deletion removes discovery preferences, identities and challenge/replay rows.
- Optional discovery abuse/quota records: pseudonymous daily counters are eligible for removal when their UTC day is more than 32 days old, only on a later successfully committed authorized operation. They can survive account deletion. Aggregate monthly quota/spend records also survive account deletion; erasure does not refund admitted verification costs. Provider-held verification/message records have no PLAN-guaranteed retention or deletion deadline.
Your choices and rights
Open Profile, Privacy and permissions to see and change, at any time:
- Apple Health, Motion and Fitness, Photos, camera, location, notifications, crash reports, usage statistics, remote planning, optional workout history and friend-visibility choices, with benefits/scopes/status. Tracking is informational only, showing the actual iOS status and historical records. iOS Contacts permission/history and separate matching/discoverability controls belong to optional discovery, currently not enabled. Health-derived readiness has no remote-sharing switch; older history entries are inactive.
- "Delete coach history", which removes past coach decision events on this iPhone and, while signed in and connected, your PLAN Coach decision history and learned summary from our server. Workouts, plans, rewards and rate-limit run records stay.
- Where the iPhone has switched a permission off, PLAN links you to PLAN's page in iOS Settings, where you can change it.
You can also:
- Delete your account and data. In Profile, Account, choose "Delete account and data". For a signed-in account, PLAN deletes your account, profile photo, consent history and synced data from our server, including the groups you own, your group memberships, your messages, your reports, your onboarding answers, your week plan and your PLAN Coach history and memory, and erases the app's data on your phone. As a guest, it erases the data on your phone. It also cancels the reminders PLAN scheduled. It does not remove workouts PLAN saved to Apple Health or cards you saved to Photos; you can remove those in the Health app and in Photos. If your phone is offline, deletion of a signed-in account needs a connection. For an Apple account, PLAN first asks you to authorize Apple again and ends PLAN's Sign in with Apple link before deleting your server account. The fresh authorization does not request your name or email. If this authorization or Apple's token revocation fails, deletion does not proceed; you can retry from Account.
- Optional discovery deletion. Confirmed account deletion also removes your discovery identities, preferences and challenge/replay rows and the corresponding local Contacts history/matching-off flag. Pseudonymous abuse counters and aggregate quota/spend records have the exceptions stated above. Removing one verified identity is not account deletion; turning a discovery choice off does not erase stored identities. Sign-out is not erasure. Previously sent provider requests/messages cannot be recalled, and PLAN deletion does not confirm provider-held-copy deletion.
- Ask us for a copy or correction of your data: contact support@lauturelabs.com.
- Withdraw consent for Apple Health, Motion and Fitness, Photos, notifications, crash reports, usage statistics, location, camera, remote planning or optional Coach history at any time, as above. Revoking sharing prevents new requests but cannot recall one already transmitted.
- Optional discovery controls. When enabled, change matching and discoverability separately or remove a verified identity. Revoking iOS Contacts access stops new permitted scans, not server discoverability; turn that server choice off and obtain confirmation separately. Failed server changes/deletion are not confirmed and can be retried. Manual selected-contact invitations remain available without discovery permission.
Depending on where you live, you may have more rights, including to access, correct, delete or move your data and to appeal a decision. Contact us at support@lauturelabs.com to use them.
Health information
PLAN is a workout tracker, not a medical service. Workout information is shared only through the explicit choices above, never sent to crash/usage services or used for advertising/data mining. PLAN does not collect weight or body measurements. Health readings, steps and derived readiness stay on the iPhone; no Health value reaches remote Coach, Supabase or DeepSeek. Calories are read for a summary and sleep/heart readings for local readiness, without persistence. Local readiness changes are not sent as disguised training preferences. Any future change to server Health scope would require a new policy and explicit permission first.
Security
Data is sent over encrypted connections. Your Apple identifier is kept in the iOS Keychain; Supabase also holds the Apple identity needed to authenticate your account. Your profile photo is kept in a private storage area. Row level security limits private workout data to your own account and shared group and challenge data to the authorized participants described above. No system is perfectly secure; if there is a security incident that affects your information we will notify you and regulators as required by law.
Children
PLAN is not directed to children under 13 and we do not knowingly collect data from them.
Changes to this policy
Version 0.6 adds optional verified email sign-in, confirmation, sign-in codes and password recovery. The matching manifest declares email, phone and contacts for account and opt-in friend-discovery functionality, never advertising or tracking. Service availability does not by itself turn on discovery or authorize a contacts scan.
We change the policy version and record choices against it. Version 0.2 added optional device permissions; 0.3 added groups/chat/Coach/demos/local readiness/onboarding/week planning. Published build-5 version 0.4 describes rooms, invitations, challenges, bundled demos and Coach-history deletion, including an obsolete readiness-sharing option that no longer authorizes any transmission. Version 0.5, effective October 10, 2026 for the matching next-build scope, keeps all derived Health local, adds affirmative non-Health remote permission, protected local progress photos, explicit private chat images, selected-contact invitations, optional local gym reminders and licensed streaming with three fixed owned demonstration exceptions. It also describes supplementary verified contact discovery as not enabled, names its proposed Telnyx/Resend processing and distinguishes code validity from lazy data cleanup and deletion exceptions. Publication does not activate inactive features, change immutable build 5's prior 0.4 disclosure or announce a new TestFlight build. Changes affecting previously supplied data are explained and reconsented where required.
Contact
Lauture Labs LLC, 2108 N St, Sacramento, CA 95816-5712, support@lauturelabs.com.