Privacy Policy

Effective: June 2, 2026

Yoke Fitness Services, LLC (“Yoke,” “we,” “us”) operates the Yoke mobile application and yokeyourgym.com web platform (collectively, the “Service”). This policy describes what data we collect, why we collect it, how it’s used, and the choices you have. We wrote it in plain language. If anything is unclear, email privacy@yokeyourgym.com.

1. Who’s the controller

Two parties are involved in any data you provide through the Service:

  • Your gym — the gym operator who invited you to use Yoke. They are the controller of your membership profile, workout history, and intake answers. They determine why and how your data is processed in the context of your training relationship.
  • Yoke— the technology provider. We process data on your gym’s behalf to deliver the Service. We are a controller for limited purposes (account security, fraud prevention, aggregate analytics) and a processor for everything else.

2. What we collect

Account & profile

  • Email address (sign-in identifier)
  • First and last name (optional)
  • Authentication method used (magic link, Apple, Google, Facebook)

Intake answers (onboarding)

  • Experience level, primary goal, days per week, bonus day preference
  • Sex, date of birth, height, weight (of these, only sex informs programming; the rest sit on your profile)
  • Timestamp of Terms of Service and Privacy Policy acceptance

Workout activity

  • Programs your gym has assigned to you
  • Sessions you start and complete, weights and reps you log, the rating you give a session
  • Substitutions you make mid-workout (which exercise you swapped, what you swapped to)

Health data (only if you opt in)

With your explicit permission, the app reads the following from Apple HealthKit (iOS) or Health Connect (Android):

  • Body weight
  • Resting heart rate
  • Sleep hours
  • Active energy expenditure
  • Step count

It writes back the completed workout itself (duration and estimated energy) so your Apple Watch / health activity gets credit. What we read is stored and shown back to you in the app, on your Progress screen. It is not used to build or change your workouts. We do not sell health data, share it with advertisers, or use it for anything other than showing it back to you.

Device & technical

  • App version, OS version, device model, locale, timezone
  • Firebase Cloud Messaging push token (only if you grant push permission)
  • Network metadata (IP address, request timestamps) used for security and rate limiting

Analytics

We use PostHog for product analytics. PostHog captures pseudonymous interaction events (screens viewed, features used) tied to a per-user ID. We do not capture sensitive form contents, the body of free-text fields, or any health data into the analytics stream.

3. How we use it

  • Operate the Service: authenticate you, deliver workouts, log sessions, send push notifications you opted into.
  • Build your weekly program: your intake answers, your gym’s equipment, and which exercises you were given in recent weeks, so the next week does not repeat them. Health data is not one of these inputs.
  • Communicate with you: transactional email for sign-in and account changes, optional product updates.
  • Improve the product: aggregate, pseudonymous analytics; never sold, never combined with health data.
  • Comply & secure: fraud prevention, abuse mitigation, legal requests, audit logs.

4. Legal basis (GDPR users)

Account, intake, and workout data are processed on the basis of the contract between you and your gym. Health data is processed on the basis of your explicit consent given when you granted HealthKit / Health Connect permissions. Withdrawing that consent (revoking the permission in iOS Settings or the Health Connect app) stops further reads immediately. Signals we already stored are deleted when you delete your account, or sooner on request.

5. Who we share data with

  • Your gym’s admin staff — see your membership profile, intake answers, programs, workout sessions and logs. They do not see your raw HealthKit / Health Connect samples. Aggregate trends only become visible to gym admins in future releases and only with separate notice.
  • Service providers (sub-processors) — Supabase (database, auth, storage), Vercel (web hosting and serverless functions), Anthropic (the LLM that generates your weekly program — receives equipment context and intake-derived parameters, not your health samples), Firebase Cloud Messaging (push delivery), Resend (transactional email), PostHog (product analytics), Sentry (error monitoring, optional).
  • Legal & safety — when compelled by valid legal process or to protect rights, property, or safety.

We do not sell your personal information. We do not share it with advertisers. We do not use it to train third-party AI models.

6. How long we keep it

  • Account & intake data — for the life of your account.
  • Workout history — retained by your gym for their training records.
  • Health signals: kept for a rolling 90 days so your Progress screen can show a trend, then aged out.
  • Analytics events — pseudonymous; 12 months.
  • Backups — up to 35 days beyond deletion in disaster-recovery snapshots.

7. Your rights

  • Access — request a copy of your data at support@yokeyourgym.com.
  • Correction — fix profile details in-app, or email us.
  • Deletion — delete your account from inside the app (Profile → Delete my account), or see Delete your account. This hard-deletes your health signals, intake answers and push tokens, deactivates your member record at your gym, and removes your authentication identity.
  • Portability — request an export at privacy@yokeyourgym.com.
  • Object / restrict / withdraw consent — revoke HealthKit / Health Connect or push permissions any time in OS settings.

8. California residents

Under the CCPA / CPRA you have additional rights including the right to know, the right to delete, the right to correct, the right to limit use of sensitive personal information, and the right to opt out of “sale” or “sharing.” We do not sell or share your personal information as those terms are defined in California law.

9. Children

Yoke is not directed to children under 13. We do not knowingly collect data from anyone under 13. If your gym onboards a youth program (13–17), parental consent is the gym’s responsibility under their own policies.

10. International transfers

Our infrastructure runs in the United States. If you access the Service from outside the US, your data is transferred to the US for processing under the safeguards our sub-processors maintain (SCCs where applicable).

11. Security

Data is encrypted in transit (TLS 1.2+) and at rest. Multi-tenancy is enforced at the database layer via Row-Level Security so one gym cannot see another’s members. Service-role credentials are never embedded in the mobile app. We disclose material security incidents to affected users without undue delay.

12. Changes

We’ll update this policy when the Service changes. If we make a material change, we’ll notify you in-app and by email before it takes effect.

13. Contact

Yoke Fitness Services, LLC
Privacy: privacy@yokeyourgym.com
Support: hello@yokeyourgym.com