Omega — Privacy Policy
Last updated: September 30, 2026
Overview
Omega ("we," "our," or "the app") is a fitness tracking and AI coaching application. This privacy policy explains how we collect, use, and protect your information.
Information We Collect
Account Information
Name and email address obtained via third-party sign-in providers (Apple or Google). We do not collect or store passwords — authentication is handled entirely by your chosen sign-in provider.
Health & Fitness Data
- Apple HealthKit: Steps, heart rate, resting heart rate, HRV, body weight, body fat percentage, VO2 max, sleep duration, and workout data. This data is read with your explicit permission and used solely to display fitness metrics and personalize your training plans.
- Workout Logs: Exercise sets, weights, reps, duration, and RPE ratings you manually enter.
- Bluetooth Heart Rate: Live heart rate data from connected Bluetooth monitors during workouts.
Nutrition Data
- Food Log: Meals you log (foods, portions, calories and nutrients), your nutrition targets, and the body stats and goals you enter to calculate them.
- Meal Photos and Menus: When you log a meal from a photo or scan a menu, the image is sent to OpenAI to estimate the foods and portions. A small thumbnail of the photo is saved with the meal in your food log; the full-size photo is not kept on our servers.
- Barcodes: When you scan a packaged food, the barcode number is looked up in the USDA and Open Food Facts databases. Nothing else about you is sent with it.
Third-Party Import Data
- Workout activities imported from connected services (Strava, Garmin Connect, COROS, Fitbit, AllTrails, Strong).
- We access only the data types you explicitly authorize through each provider's OAuth flow.
AI Conversations
- Messages exchanged with the Omega AI coach are stored to maintain conversation history and improve plan recommendations.
- When you use the AI coach, the following data may be sent to OpenAI for processing: your conversation messages, fitness goals, experience level, available equipment, recent workout summaries (exercise names, sets, reps, weights), and auto-analyzed fitness benchmarks (estimated 1RMs, running paces, training volume). Refer to OpenAI's privacy policy for their data handling practices.
Analytics & Diagnostics
- Usage Analytics: With your consent, we collect anonymized usage events such as screens viewed, features used, workout sessions started/completed, and subscription actions. Analytics collection can be disabled at any time in Settings > Analytics.
- Device Diagnostics: When you submit a bug report, the report includes your device model, iOS version, app version, locale, and timezone to help us diagnose issues.
- Crash & Performance Data: Crash reports and performance traces are sent to Sentry, and anonymous usage signals to TelemetryDeck, to keep the app stable. They carry your device model, OS and app version and an anonymous identifier, not your workouts, meals or messages.
Subscription & Payment
- Subscription status is managed through Apple's StoreKit framework.
- Transaction identifiers are verified server-side to validate subscription status.
- We do not collect or store credit card numbers or payment details.
How We Use Your Data
- Display fitness metrics and track your progress over time
- Generate personalized workout plans based on your goals and current fitness level
- Analyze training history to detect benchmarks, personal records, and progression
- Sync data between the app and Apple Health
- Process AI coaching conversations
- Improve app stability and performance through crash and diagnostic data
- Understand aggregate usage patterns to improve the app (when analytics consent is given)
Data Storage & Security
- Authentication tokens are stored in the iOS Keychain
- Fitness data is stored locally on your device using SwiftData
- Backend data is stored in encrypted AWS DynamoDB tables
- All network communication uses HTTPS/TLS encryption
- Analytics logs are stored locally on device and uploaded to our servers only with your consent
Data Sharing
We do not sell, rent, or share your personal data with third parties for advertising purposes. Data is shared only:
- With OpenAI for AI coaching and meal analysis (conversation messages, fitness context and meal photos as described above)
- With Sentry and TelemetryDeck for crash reporting and anonymous usage signals
- With Apple for subscription management via StoreKit
- With third-party fitness services you explicitly connect (Strava, Garmin, etc.)
Your Rights
- Access: View all your data within the app
- Export: Export your workout and health data as CSV or JSON
- Delete: Delete your account in the app under Profile > Delete Account. This permanently deletes your account and everything stored for it on our servers (workouts, plans, meals, nutrition targets, health metrics, AI conversations, connected-service tokens and subscription records) and clears the data on your device. If you signed in with Apple, we also revoke Omega's access to your Apple ID. Deleting your account does not cancel an App Store subscription; cancel it in Settings > your name > Subscriptions.
- Disconnect: Revoke access to any connected third-party service at any time
- Opt-out of Analytics: Disable usage analytics at any time in Settings > Analytics
HealthKit Data
Omega does not use HealthKit data for advertising, marketing, or sale to third parties. HealthKit data is used exclusively for displaying your fitness metrics and personalizing workout recommendations within the app.
Children's Privacy
Omega is not intended for children under 13. We do not knowingly collect data from children under 13.
Changes to This Policy
We may update this policy periodically. Continued use of the app after changes constitutes acceptance of the updated policy.
Contact
For privacy questions or data requests, contact: privacy@omega-fitness.app