Privacy Policy

Last updated September 2026

Draft — pending legal review. This document was drafted by the engineering team to describe what the app actually does. It has not been reviewed by a lawyer, and highlighted values below are still unresolved. It must be reviewed before App Store submission.

Sett is an AI workout coaching app for iOS. This policy explains what data Sett collects, why, who processes it on our behalf, and what control you have over it. It describes what the app actually does today — not what it might do later.

Sett is currently distributed through Apple TestFlight as a beta. Parts of the product are still being built, and this policy will change as they ship. Questions about anything here: support@sett.coach.

What we collect

Account and sign-in

You sign in with an email address and password, with Sign in with Apple, or with Google. We use Supabase for authentication; your password is handled by Supabase and is never stored by Sett, and account emails — such as password-reset codes — are sent through Supabase as well. We store your account identifier, your email address, and a display name you choose. If you use Sign in with Apple and select “Hide My Email,” Apple gives us a private relay address instead of your real one — and if Apple provides no email at all, your account simply has none on file. The name Apple returns on first authorisation may be saved to your profile; Apple only provides it once.

Fitness profile

During onboarding, and whenever you edit it later, we store: your fitness level, primary and secondary training goals, training days per week, typical session length, available equipment (including any gym profiles you name), exercise preferences, sex, age in whole years, height, and body weight. We also store injury notes you write in free text and a structured list of movements you have asked the coach to ease off.

Apple Health (optional, read-only, one time)

If you allow it during onboarding, Sett reads four values from Apple Health to pre-fill your profile: biological sex, date of birth, body mass, and height. These are read once to set sensible starting training loads, and everything stays editable afterwards. Your date of birth is converted to an age in whole years on your device — the raw date of birth is never sent to our servers. Sett does not write anything back to Apple Health, does not read your workouts, heart rate, sleep, or any other Health category, and does not sync in the background. There is no live integration with Whoop, Oura, or any other wearable.

Workout logs

Every workout creates a record: when it started and finished, its duration, the planned exercise list, and per set — weight, reps, RPE, duration or distance where relevant, whether it was a warm-up, when it was logged, and any free-text note you attach. We also store optional workout-level notes, an “overall feeling” note, and AI-generated post-workout debrief text.

Coach conversations

Your chat with the coach is stored verbatim: your messages, the coach’s replies, the structured content blocks it renders, and the tool calls it makes along with their arguments and results. We also store AI-written summaries of a session, used to keep long conversations coherent.

Coach memory

Sett runs a separate AI process at the end of a session that extracts durable facts about you so the coach remembers you between sessions. These fall into five categories with hard caps — physical (up to 8), preference (up to 8), goal (up to 4), milestone (up to 10), and observation (up to 5), roughly 35 facts in total. The “physical” category explicitly includes injuries, mobility issues, and physical limitations you mention in conversation. In practice that looks like “Right knee pain on squats — avoiding deep knee flexion for now,” “Hates burpees,” or “Run a 10K in 12 weeks.” Assume that health-relevant things you say to the coach may be extracted and retained.

Programs, progress, and derived data

We store training programs you enrol in or build, program change history, personal records, estimated strength baselines per exercise (some estimated from your sex, age, height, and weight), pinned lifts, muscle-group targets, and AI-generated monthly recaps. Recovery scores are calculated on the fly from recent training history and are not stored.

Diagnostic and usage data

We log metadata about every AI call made on your behalf: your user id, the session, the model, token counts, estimated cost, latency, which tools ran, whether it errored, and the app/API version. These logs do not contain the text of your messages or the coach’s replies. We also log app opens and product events (a user id, an event name, an app version, your device’s timezone — a coarse region signal, and the closest thing to location we store — and properties intended to be free of personal information). The Sett iOS app uses no third-party analytics SDK — no PostHog, Amplitude, Mixpanel, Segment, or Firebase Analytics — and shows no App Tracking Transparency prompt, because the app does not track you across other apps or websites. The Sett website is a separate surface with its own analytics — see “The website: analytics, anti-spam, and the waitlist” below.

Crash and error reports

We use Sentry to capture crashes and errors. Sett does not attach your identity to Sentry events — we do not send your user id, email, or name. Sentry does collect automatic breadcrumbs about what happened before an error, which can include which screens you visited and where you tapped. Screenshots and session replay are not enabled.

What we do not collect

Sett does not collect your location (the closest thing we store is your device’s timezone, noted above), contacts, calendar, photos, precise advertising identifiers, payment card details, body-fat percentage, body measurements, or progress photos. There is no advertising, and no data is sold or shared for advertising.

How we use it

We use your data to run the product, and for essentially nothing else:

  • To authenticate you and keep you signed in.
  • To generate workouts and programs suited to your goals, equipment, experience, and stated injuries.
  • To power the AI coach, which needs your profile, coach memory, recent training history, and the current conversation to give relevant answers.
  • To track your progress, personal records, and recovery over time.
  • To diagnose crashes, errors, and performance problems.
  • To understand aggregate usage well enough to decide what to build next.
  • To contact you about your account if something needs your attention.

We do not sell your data, use it to serve advertising, or build advertising profiles.

Who processes your data

Sett is a small operation and relies on third-party infrastructure. These providers process data on our behalf, each for a specific purpose:

  • Supabase — authentication and the Postgres database. Effectively all of your first-party data lives here.
  • OpenAI — language model inference. This is the important one: when you talk to the coach, the content of that conversation is sent to OpenAI, along with the context the coach needs — your fitness profile (including injury notes), your coach memory, and a summary of recent training. The same applies to program generation, memory extraction, and monthly recaps. OpenAI’s handling of that data is governed by its own terms and policies. When you use the hands-free voice coach (currently in limited testing), OpenAI also receives your raw microphone audio — your actual voice, not only a transcript. See “Hands-free voice coaching” below.
  • Langfuse — AI observability, used to debug and improve coach quality. Conversation content, including your messages and the coach’s replies, is sent to Langfuse in production, with email addresses and phone-number-shaped strings automatically redacted first. Other free text — including anything you write about injuries or health — is transmitted as written. Langfuse receives your account’s internal identifier, never your email.
  • Sentry — crash and error reporting, as described above.
  • Render — hosting for the Sett API.
  • Vercel — hosting for this website and public share pages.
  • Google — on the website only, analytics (Google Analytics 4) and spam prevention on the waitlist form (reCAPTCHA). Google receives website interaction and coarse device data for these purposes and sets cookies. It does not receive any of your in-app data. See “The website: analytics, anti-spam, and the waitlist” below.
  • LiveKit — the real-time audio connection for the hands-free voice coach (currently in limited testing — see “Hands-free voice coaching” below). When you speak to the coach hands-free, your live microphone audio and the coach’s spoken reply are carried between your phone and our voice servers over LiveKit. It transports your raw audio. Used only during a hands-free voice session.
  • Cartesia — text-to-speech for the hands-free voice coach. It receives the coach’s written reply and returns the synthesised voice you hear. Cartesia receives the coach’s words, not your microphone audio. Used only during a hands-free voice session.
  • Apple and Google — sign-in providers, if you use them. They tell us you authenticated and give us an identifier and, where you permit it, an email address and name.

Our infrastructure is hosted in the United States. If you use Sett from outside the US, your data will be processed in the US.

The website: analytics, anti-spam, and the waitlist

The section above is about the Sett iOS app. The Sett website — the marketing pages and the public share pages — is a separate surface, and it uses a small number of Google services that the app does not. This subsection covers them.

Website analytics (Google Analytics 4)

The website uses Google Analytics 4 on both the marketing pages and the public share pages — the share-to-download path is the funnel we most want to understand. Google Analytics collects a pseudonymous client identifier, the page paths you visit, the referring site, coarse device and approximate (city-level) location, and interaction events, and it sets cookies to do so. Google acts as our processor for this.

It runs under Google Consent Mode, default-denied: until you accept the cookie banner, no analytics cookies are set and only cookieless, aggregate signals are sent. Accepting enables full measurement; declining keeps it cookieless.

Share pages are in scope, but the path we send to Google is normalised: a share URL such as /w/jane-push-day-AbC12… is reported to Google only as the generic /w/[slug], so a display name and share token are never sent to Google.

Your consent choice

Your analytics choice is stored on your device (a small sett_consent_v1 entry in your browser’s local storage) — not in a cookie and not on our servers. You can change it at any time: clearing your browser storage, or a future change to this policy, brings the banner back. The reCAPTCHA below is strictly-necessary anti-abuse and is not affected by this choice.

“Do Not Track” signals

Some browsers can send a “Do Not Track” or Global Privacy Control signal. There is no settled standard for honouring these, and the website does not currently respond to them. The consent banner above is the control that works here: until you accept it, analytics runs cookieless.

Spam prevention (Google reCAPTCHA)

The waitlist form uses Google reCAPTCHA v3 to keep spam and bots off the list. It runs invisibly: to score whether a submission is human, Google receives interaction and device signals from your browser and sets cookies for this purpose. We treat this as necessary anti-abuse (a legitimate interest), so — unlike analytics — it runs whether or not you accept the analytics cookie banner. Your use of reCAPTCHA is subject to Google’s Privacy Policy and Terms of Service.

The email waitlist

If you join the waitlist, we store the email address you enter together with basic funnel metadata: the page that referred you, any campaign (UTM) parameters, the normalised path you signed up on, and your browser’s user-agent string. This is kept in our Supabase database and is not sold or shared. We use it for one thing — to email you an invite when a spot opens. There is no newsletter. To be removed from the list, email support@sett.coach.

Cookies and local storage the website uses

NameSet byPurposeLifespan
_gaGoogle AnalyticsDistinguishes visitors (analytics)2 years
_ga_<id>Google AnalyticsPersists analytics session state2 years
sett_consent_v1 (local storage)This websiteRemembers your analytics-cookie choiceUntil you clear browser storage
_GRECAPTCHAGoogleBot/abuse detection on the waitlist form~6 months

Hands-free voice coaching

Sett offers a hands-free voice coach — currently in limited testing with a small number of accounts: you talk to the coach out loud and it talks back, without typing. This is a different data flow from typing, and it is worth being precise about, because it means your actual voice audio leaves your phone.

First, the distinction that matters. When you use on-device dictation to type a message — the microphone button on the chat input — your speech is transcribed by iOS on your device, and only the resulting text is sent to us. Your audio never leaves the phone. The hands-free voice coach described here is not that: to hold a spoken conversation, your raw microphone audio is streamed off your device.

When you speak to the coach hands-free:

  • Your microphone audio is streamed off your device in real time, over a live audio connection provided by LiveKit, to our voice servers.
  • That audio is sent to OpenAI, which converts your speech to text. This is your raw audio — your real voice — not just a transcript.
  • The transcript of what you said is then handled exactly like a typed message to the coach: it is stored in your conversation history, it goes to OpenAI’s language model together with your profile, coach memory, and recent training history for context, and — as with typed chat — conversation content is sent to Langfuse for debugging. Everything in “Who processes your data” and “A note on health-adjacent data” applies equally to what you say out loud, and health-relevant things you say aloud can be extracted into a persistent coach memory fact just as they can when you type them.
  • The coach’s spoken reply is produced by a separate text-to-speech provider, Cartesia, which receives the coach’s written reply and returns audio. Cartesia receives the coach’s words, not your microphone audio.

Sett does not store your audio — no recording is kept on our servers; what persists with us is the transcript, as part of your coach conversation. But we cannot guarantee that the providers above do not retain your audio. Each processes it under its own terms and retention policies, and Sett does not currently have a zero-retention arrangement covering this audio. Deleting your Sett account removes your data from our database but does not, on its own, purge any copies held by LiveKit, OpenAI, or Cartesia. If you would prefer something not to be processed this way, do not say it to the voice coach.

Hands-free voice is in limited testing and is enabled for a small number of accounts. If it is not enabled for your account, none of the above applies to you and no audio leaves your device for it.

A note on health-adjacent data

Sett is a fitness app, not a medical app, and is not a covered entity under HIPAA. But some of what you give it is genuinely sensitive: your sex, age, height, weight, injuries, and whatever you tell the coach about how your body is doing. Three things follow, and we would rather you know them up front:

  • That information is sent to OpenAI as part of coaching, because the coach cannot avoid a bad exercise for your knee unless it knows about your knee.
  • Health-relevant statements you make in conversation can be extracted into a persistent coach memory fact.
  • Conversation content is sent to Langfuse for debugging, and the automatic redaction there covers emails and phone numbers only — not free-text health details.

If you would prefer a health detail not to be processed this way, do not put it in the app.

Public share links

Sett lets you share a workout via a link. Treat this as publishing, not as sending.

When you create a share link we mint a random token and store a snapshot of the workout — its name, and for each exercise the name, target sets and reps, rest periods, grouping, and any exercise notes — together with your display name. Anyone with the link can open that page at any time with no sign-in required.

  • The page shows your display name (or a generic label if you have not set one). It does not show your email, account id, logged weights, session results, or any body or profile data.
  • The link has no expiry. It works indefinitely.
  • There is currently no way to revoke or delete a share link from within the app. Email support@sett.coach and we will delete it. Deleting your account also deletes all of your share links.
  • Share pages are excluded from search engines (they are served with a noindex directive), so they should not appear in search results. They are still public to anyone holding the link, and link previews in messaging apps will show the workout name and your display name.
  • Anyone holding the link can copy the workout into their own Sett account.

Only share a workout if you are comfortable with your display name and that workout’s contents being visible to anyone who gets the link.

Retention

We keep your data for as long as your account exists. There is no automatic expiry on conversations, workouts, coach memory, or the diagnostic logs described above — no automated deletion job runs today, so data stays until you delete it or delete your account.

One detail worth stating plainly: if you delete an individual coach memory fact, Sett records that deletion so the coach does not re-learn the same fact, and that record retains the original text of the deleted fact. If you need a memory fact’s text erased entirely rather than suppressed, email support@sett.coach.

Data held by our processors is retained under their own policies and schedules. Deleting your Sett account removes your data from our database but does not, on its own, purge copies held by OpenAI, Langfuse, or Sentry.

Your choices and controls

Delete your account

You can delete your account yourself, in the app: Profile → Settings → Account → Delete account. You will be asked to confirm twice. This is immediate, permanent, and not recoverable. It removes your database record and every row attached to it — profile, gym profiles, coach memory and suppressions, body metrics, workouts and every logged set, chat sessions and messages, programs and program history, personal records, strength baselines, exercise preferences, recommendations, monthly recaps, share links, and your telemetry rows — and deletes your authentication record with Supabase. There is no backup copy we can restore from.

Two limits worth stating plainly. If you joined the email waitlist, that list is keyed by the email address itself, not by your account, so deleting your account does not remove you from it — email support@sett.coach and we will take you off. And deletion removes your data from our database; copies already held by our processors — OpenAI, Langfuse, Sentry, and our hosting providers’ logs — are not purged by it, and age out under each provider’s own retention policies, as described under “Retention.”

Edit your profile and memory

You can change your fitness profile at any time in Settings. The Profile tab’s “What Zutroy knows about you” panel lists every coach memory fact and lets you remove any of them.

Manage sign-in

Settings → Sign-in methods shows how you sign in (Apple, Google, or email and password) and lets you add a password to a social-only account. Connecting an additional Apple or Google login to an existing account is not available yet; until it is, your account keeps the sign-in method you created it with. You can reset your password from the login screen.

Apple Health

You can revoke Sett’s Health read permission at any time in the iOS Settings app. Sett only ever reads, never writes.

Data export

Sett does not currently offer a self-serve data export. Email support@sett.coach and we will put a copy together manually.

Other requests

Depending on where you live, you may have rights to access, correct, delete, or restrict processing of your personal data. There is no automated portal for these — email support@sett.coach and we will handle it directly.

Children

Sett is not intended for children. You must be at least 18 years old to create an account. Sett does not knowingly collect personal information from anyone under that age. If you believe a child has created an account, email support@sett.coach and we will delete it.

Security

Data is transmitted over encrypted connections and stored in Supabase’s managed Postgres with row-level security, so queries are scoped to the authenticated user. Access to production systems is limited, but it exists: a small internal admin dashboard, restricted to an allowlist of operators, is used for support and operations. Through it, staff can look up an account’s details (including its email address), usage and AI-cost figures, and limited conversation context such as the opening message of a coach session. Staff access is not currently audit-logged. No system is perfectly secure, and we cannot guarantee that a determined attacker will never succeed — but we will tell you promptly if we learn that your data was exposed.

Changes to this policy

Sett is early and actively changing. We will update this policy when what the app does changes, and update the date at the top. For a change that materially affects how your data is handled, we will make an effort to notify you in the app or by email rather than quietly editing this page.

Contact

Questions, requests, complaints, or a share link you want taken down: support@sett.coach.