Privacy Policy

Effective Date: February 1, 2026 · Last Updated: February 1, 2026

Slate Fitness ("Slate," "we," "us," or "our") operates the Slate mobile application (the "App"). This Privacy Policy describes how we collect, use, disclose, and protect your information when you use the App. By accessing or using the App, you agree to this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access or use the App.

We encourage you to read this Privacy Policy carefully and contact us at support@slatefitness.app if you have any questions.


1. Information We Collect

We collect information in several ways depending on how you interact with the App. We categorize the data we collect as follows:

1.1 Account Information

When you create an account, we collect:

1.2 Workout and Fitness Data

When you use the App to track workouts, we collect:

1.3 Body and Biometric Data

If you choose to enter body statistics, we collect:

This data is entered voluntarily by you and is used solely to provide you with analytics and progress tracking within the App.

1.4 Health Data (Apple HealthKit)

With your explicit permission, the App may read from and write to Apple HealthKit. This may include workout data, step count, heart rate, and other health metrics supported by HealthKit.

Important: Data obtained from HealthKit is used solely to display health and fitness information within the App. We do not use HealthKit data for advertising, marketing, or sale to third parties. HealthKit data is not shared with any third party except as necessary to provide core App functionality to you, and only with your express consent. We do not use HealthKit data to build user profiles, serve advertisements, or for any purpose other than providing health and fitness features directly to you. This policy applies regardless of whether you continue to use the App.

1.5 Voice Data

The App offers voice-to-text exercise entry powered by Apple Speech Recognition. Voice processing occurs entirely on your device. Raw audio recordings are not transmitted to our servers.

The transcribed text output from on-device speech recognition may be sent to our servers solely for the purpose of matching your spoken input to exercises in our database. This transcribed text is processed in real time and is not stored persistently on our servers after the matching operation completes.

1.6 AI-Generated Content Data

When you use AI workout generation features, the App sends workout parameters to our servers, including muscle groups, workout duration, intensity preferences, and custom instructions you provide. These parameters are forwarded to a third-party AI service (xAI / Grok) to generate workout suggestions.

We do not send personal identifying information (such as your name, email address, or account identifiers) to the AI service. The AI service receives only the workout parameters necessary to generate a response. These parameters are processed transiently and are not stored on our servers after the response is returned. Data sent to the AI service is processed according to their privacy policy (see Section 3.1).

1.7 User-Generated Content

The App may allow you to create and share content, including:

1.8 Subscription and Transaction Data

We use RevenueCat to manage subscriptions. We collect:

We do not directly collect or store your payment card information. All payment processing is handled by Apple (App Store), Google (Google Play), and RevenueCat.

1.9 Device and Technical Data

We may collect:

We do not collect precise geolocation data. We do not access your contacts or phone call logs.

1.10 Push Notification Tokens

If you opt in to push notifications, we collect your device push notification token to send you workout reminders, social activity notifications, and other service-related communications.


2. How We Use Your Information

We use the information we collect for the following purposes:

We do not use your data for third-party advertising. We do not sell your personal information to any third party.


3. Data Sharing and Disclosure

We do not sell, rent, or trade your personal information. We may share your information only in the following limited circumstances:

3.1 Third-Party Service Providers

We use the following third-party services to operate the App:

ServicePurposeData SharedPrivacy Policy
SupabaseDatabase, authentication, file storageAccount data, workout data, body statssupabase.com/privacy
RevenueCatSubscription managementSubscription status, transaction IDsrevenuecat.com/privacy
CloudflareAPI hosting, exercise video deliveryWorkout parameters (for AI generation), exercise video requestscloudflare.com/privacypolicy
xAI (Grok)AI workout generationWorkout parameters only; no PIIx.ai/legal/privacy-policy
AppleSign-In, Speech Recognition, HealthKit, App StoreAuth tokens, on-device voice, health data (with permission)apple.com/privacy
GoogleGoogle Sign-In, Google Play (when available)Authentication tokenspolicies.google.com/privacy
SentryCrash reporting (when implemented)Device info, crash logssentry.io/privacy
FirebaseUsage analytics (when implemented)Anonymized usage eventsfirebase.google.com/support/privacy

Each third-party provider is bound by its own privacy policy and data processing terms. We select providers that maintain industry-standard security practices. Data shared with third-party AI services (xAI) is processed according to their privacy policy, including any retention or model improvement practices described therein.

3.2 Social Features

When social features are available, certain information you choose to make public — such as your display name, profile information, workout posts, and comments — will be visible to other users. You control what you share through your privacy settings.

3.3 Legal Requirements

We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

3.4 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred to the acquiring entity. We will notify you of any such change in ownership or control of your personal information.


4. Data Storage and Security

4.1 Storage Location

Your data is stored on servers located in the United States, operated by our infrastructure provider, Supabase. Exercise demonstration videos are hosted on Cloudflare R2 (globally distributed).

4.2 Offline-First Architecture

The App is designed with an offline-first architecture. Your workout data is stored locally on your device and synchronized with our cloud servers when a network connection is available. You can use core features of the App without an internet connection.

4.3 Security Measures

We implement industry-standard security measures to protect your information, including:

While we strive to protect your information, no method of electronic storage or transmission is completely secure. We cannot guarantee absolute security.

4.4 Data Retention

We retain your personal information for as long as your account is active or as needed to provide you with the App's services. Specifically:

4.5 Data Breach Notification

In the event of a data breach that compromises the security, confidentiality, or integrity of your personal information, we will:


5. Your Rights and Choices

5.1 Access and Portability

You may access your workout data at any time within the App. The App provides a data export feature that allows you to download your data in JSON format, enabling data portability.

5.2 Correction

You may update or correct your personal information (display name, body stats, workout data) at any time through the App.

5.3 Deletion

You may delete your account and all associated data through the App's settings. Upon account deletion:

5.4 Push Notifications

You may opt out of push notifications at any time through your device's settings.

5.5 HealthKit Permissions

You may revoke the App's access to Apple HealthKit at any time through your device's Health app settings. Revoking access will prevent the App from reading or writing HealthKit data but will not delete data previously synced.

5.6 Data Import and Export

You may import and export your workout data in JSON format through the App's settings. This supports your right to data portability.


6. Rights for Users in the European Economic Area (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following additional rights under the General Data Protection Regulation (GDPR):

To exercise any of these rights, contact us at support@slatefitness.app. We will respond to your request within 30 days.

Legal Bases for Processing: Performance of a Contract, Consent, and Legitimate Interests.


7. Rights for California Residents (CCPA)

If you are a California resident, you have the following rights under the CCPA and CPRA:

To exercise your rights, contact us at support@slatefitness.app. We will respond within 45 days.

We do not sell personal information.


8. Children's Privacy

The App is not directed to children under the age of 13 (or under the age of 16 in the EEA). We do not knowingly collect personal information from children under these ages. If you believe a child has provided us with personal information, please contact us at support@slatefitness.app.


9. International Data Transfers

Your information may be transferred to, and processed in, the United States and other countries where our service providers operate. For users in the EEA, we rely on standard contractual clauses approved by the European Commission, where applicable.


10. Third-Party Links and Services

The App may contain links to third-party websites, services, or content that are not operated by us. This Privacy Policy does not apply to third-party services.


11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date and notify you through the App or via email.


12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us at:

Slate Fitness
Email: support@slatefitness.app

For GDPR-related inquiries, you may also contact your local data protection authority.


13. Additional Disclosures for Specific Features

13.1 AI-Powered Features

Our AI workout generation feature uses third-party artificial intelligence services to create workout suggestions based on parameters you provide. The AI service does not receive your name, email address, account information, workout history, or any other personally identifying information.

13.2 Voice Input

Voice input is processed using Apple's on-device Speech Recognition framework. Audio is processed locally on your device and is not transmitted to Slate's servers. The resulting transcribed text may be sent to our servers to match exercises and is not stored after the operation completes.

13.3 Share Cards and Social Sharing

When you create a workout share card, the image is generated locally on your device. We do not receive or store information about where you share your content.

13.4 Photo Attachments

Progress photos are stored in your account and are private by default. Photos are accessible only by you unless you explicitly choose to share them through social features.

13.5 Apple Watch

When the Apple Watch companion app is available, it will access workout data and health metrics in accordance with the permissions you grant. Data collected by the Apple Watch app is subject to this same Privacy Policy.