Privacy Policy

Effective: June 2, 2026

Yoke Fitness Services, LLC (“Yoke,” “we,” “us”) operates the Yoke mobile application and yokeyourgym.com web platform (collectively, the “Service”). This policy describes what data we collect, why we collect it, how it’s used, and the choices you have. We wrote it in plain language. If anything is unclear, email privacy@yokeyourgym.com.

1. Who’s the controller

Two parties are involved in any data you provide through the Service:

  • Your gym — the gym operator who invited you to use Yoke. They are the controller of your membership profile, workout history, and intake answers. They determine why and how your data is processed in the context of your training relationship.
  • Yoke— the technology provider. We process data on your gym’s behalf to deliver the Service. We are a controller for limited purposes (account security, fraud prevention, aggregate analytics) and a processor for everything else.

2. What we collect

Account & profile

  • Email address (sign-in identifier)
  • First and last name (optional)
  • Authentication method used (magic link, Apple, Google, Facebook)

Intake answers (onboarding)

  • Experience level, primary goal, days per week, bonus day preference
  • Sex, date of birth, height, weight (used to personalize programming)
  • Timestamp of Terms of Service and Privacy Policy acceptance

Workout activity

  • Programs your gym has assigned to you
  • Sessions you start and complete, weights and reps you log, the rating you give a session
  • Substitutions you make mid-workout (which exercise you swapped, what you swapped to)

Health data (only if you opt in)

With your explicit permission, the app reads the following from Apple HealthKit (iOS) or Health Connect (Android):

  • Body weight
  • Resting heart rate
  • Sleep hours
  • Active energy expenditure
  • Step count

It writes back the completed workout itself (duration and estimated energy) so your Apple Watch / health activity gets credit. We use the data we read to personalize the next week’s program. We do not sell health data, share it with advertisers, or use it for anything other than program personalization and showing it back to you.

Device & technical

  • App version, OS version, device model, locale, timezone
  • Firebase Cloud Messaging push token (only if you grant push permission)
  • Network metadata (IP address, request timestamps) used for security and rate limiting

Analytics

We use PostHog for product analytics. PostHog captures pseudonymous interaction events (screens viewed, features used) tied to a per-user ID. We do not capture sensitive form contents, the body of free-text fields, or any health data into the analytics stream.

3. How we use it

  • Operate the Service — authenticate you, deliver workouts, log sessions, send push notifications you opted into.
  • Personalize programming — feed your intake answers and (if opted-in) health signals into the weekly program generator.
  • Communicate with you — transactional email for sign-in and account changes, optional product updates.
  • Improve the product — aggregate, pseudonymous analytics; never sold, never combined with health data.
  • Comply & secure — fraud prevention, abuse mitigation, legal requests, audit logs.

4. Legal basis (GDPR users)

Account, intake, and workout data are processed on the basis of the contract between you and your gym. Health data is processed on the basis of your explicit consent given when you granted HealthKit / Health Connect permissions. Withdrawing that consent (revoking the permission in iOS Settings or the Health Connect app) stops further reads immediately; previously stored signals can be deleted from inside the app.

5. Who we share data with

  • Your gym’s admin staff — see your membership profile, intake answers, programs, workout sessions and logs. They do not see your raw HealthKit / Health Connect samples. Aggregate trends only become visible to gym admins in future releases and only with separate notice.
  • Service providers (sub-processors) — Supabase (database, auth, storage), Vercel (web hosting and serverless functions), Anthropic (the LLM that generates your weekly program — receives equipment context and intake-derived parameters, not your health samples), Firebase Cloud Messaging (push delivery), Resend (transactional email), PostHog (product analytics), Sentry (error monitoring, optional).
  • Legal & safety — when compelled by valid legal process or to protect rights, property, or safety.

We do not sell your personal information. We do not share it with advertisers. We do not use it to train third-party AI models.

6. How long we keep it

  • Account & intake data — for the life of your account.
  • Workout history — retained by your gym for their training records.
  • Health signals — kept only as long as needed to feed the next program (rolling 90 days), then aged out.
  • Analytics events — pseudonymous; 12 months.
  • Backups — up to 35 days beyond deletion in disaster-recovery snapshots.

7. Your rights

  • Access — download a copy of your data via in-app Settings → Privacy.
  • Correction — fix profile details in-app, or email us.
  • Deletion — delete your account from inside the app (Settings → Delete account). This hard-deletes your health signals and push tokens, deactivates your member record at your gym, and removes your authentication identity.
  • Portability — request an export at privacy@yokeyourgym.com.
  • Object / restrict / withdraw consent — revoke HealthKit / Health Connect or push permissions any time in OS settings.

8. California residents

Under the CCPA / CPRA you have additional rights including the right to know, the right to delete, the right to correct, the right to limit use of sensitive personal information, and the right to opt out of “sale” or “sharing.” We do not sell or share your personal information as those terms are defined in California law.

9. Children

Yoke is not directed to children under 13. We do not knowingly collect data from anyone under 13. If your gym onboards a youth program (13–17), parental consent is the gym’s responsibility under their own policies.

10. International transfers

Our infrastructure runs in the United States. If you access the Service from outside the US, your data is transferred to the US for processing under the safeguards our sub-processors maintain (SCCs where applicable).

11. Security

Data is encrypted in transit (TLS 1.2+) and at rest. Multi-tenancy is enforced at the database layer via Row-Level Security so one gym cannot see another’s members. Service-role credentials are never embedded in the mobile app. We disclose material security incidents to affected users without undue delay.

12. Changes

We’ll update this policy when the Service changes. If we make a material change, we’ll notify you in-app and by email before it takes effect.

13. Contact

Yoke Fitness Services, LLC
Privacy: privacy@yokeyourgym.com
Support: hello@yokeyourgym.com