Privacy Policy

Effective Date: July 23, 2026
Last Updated: August 1, 2026

Autumn Creek Press, LLC ("Iridium," "we," "us," or "our") provides the Iridium mobile app, the website at https://iridium.fit, and related support and feedback services. This Privacy Policy explains the information these services process, why we use it, when service providers receive it, and the choices available to you.

Autumn Creek Press, LLC is responsible for the personal information described in this policy. The company's founder/manager serves as Interim Privacy Officer and, for Quebec, the Person in Charge of the Protection of Personal Information until replaced in writing. You can contact the Interim Privacy Officer at hello[at]iridium[dot]fit or at the mailing address below.

1. Scope

This policy applies to the Iridium mobile application, website, feedback and bug-reporting tools, and related communications (collectively, the "Services"). Different features use different information. For example, information needed to generate a workout is separate from app analytics described below and from optional website analytics.

Our separate Consumer Health Data Privacy Policy explains additional rights and practices for consumer health data, including rights available to residents of Washington and Nevada.

2. Information Processed by the Mobile App

Most fitness information is stored and processed on your device. Depending on the features you use, this can include your profile and goals; workout plans and history; exercises, sets, weights, repetitions, RPE, rest periods, notes, and personal records; gym and equipment details; nutrition and hydration entries; recovery information; custom instructions; AI conversations and memories; and photos, video, or audio you provide or authorize the app to use.

With your permission, Iridium can read from and write to Apple HealthKit to provide workout, nutrition, sleep, activity, body-measurement, and recovery features. You control HealthKit access through Apple's permission controls. We do not use HealthKit information or detailed health and fitness information for advertising.

iCloud synchronization and backups

If iCloud is available for Iridium, Apple's CloudKit can synchronize supported app records across your devices, and Apple's iCloud backup service can include eligible app data and settings. Apple processes that information under your Apple account and Apple's privacy practices. You control iCloud synchronization and device backups through Apple's settings. Apple controls what its device-backup systems include. An app-data export, Analytics ID reset, or backup setting does not delete optional analytics already received by Iridium.

Location and weather

With device permission, location can be used to provide local weather and recovery context. Apple WeatherKit processes the location needed to return weather conditions. When an AI feature uses weather-aware context, applicable location and weather context can also be sent with that AI request to the routing and model providers described below. You can revoke location access in Apple's Settings app.

Nutrition lookup services

When you search for a food or scan a barcode, the query or barcode and information needed to return nutrition results can be sent to Iridium's hosted food-search service or to Open Food Facts. Those services can also receive ordinary network information such as an IP address and request timestamps.

Optional External Data Sync

If you enable External Data Sync, Iridium uploads supported workout, nutrition, profile, settings, and training information to Iridium's server so that tools you authorize, including compatible MCP clients or third-party AI agents, can access that information using the sync credentials you configure. This is separate from the optional app analytics described below. Do not enable or connect External Data Sync unless you trust the client or agent that will receive access.

Optional app analytics

Iridium sends pseudonymous product analytics only after you affirmatively enable Help Improve Iridium. Your choice applies to that device and is stored as a versioned consent record. Analytics events use a randomly generated, persistent Analytics ID instead of your name or email. Because events associated with that ID can be connected over time, the data is pseudonymous, not anonymous.

When enabled, app analytics can include:

  • Profile categories: age bracket, gender, training goal, experience category, workout frequency, and how long you have used Iridium, when provided.
  • Workout activity: timestamps, duration, completion, source, exercise and block structure, planned and completed sets, weights, repetitions, RPE, rest, intensity, structured replacement-reason categories, personal records, and Apple Watch, timer, or voice-coach usage. These events do not include user-defined names, written feedback, or other free text.
  • Equipment context: structured equipment identifiers available for the workout. App analytics do not include the gym name, street address, or coordinates.
  • Feedback: a workout rating and predefined reason categories, but not written feedback or other free-text responses.
  • Nutrition usage: how you logged an item, meal category, a broad calorie range, and whether a barcode was present. These analytics events do not include the food name, brand, photo, or exact nutrition values.
  • Technical context: app version, platform, and event timestamps.

After an enabled analytics event is successfully recorded, Iridium may send an event-only administrator notice through Pushover. Onboarding-completed and food-logged notices contain only the event type. Workout-completed notices contain the duration rounded to the nearest minute and whether the source was AI generated, a template, or manually created. These notices do not include the Analytics ID, session ID, profile categories, exercise or food details, client timestamps, or free text.

Turning Help Improve Iridium off cancels analytics work in progress and stops new optional events. It does not delete information already received. Resetting the Analytics ID separates future events from the prior ID but does not delete earlier events. Contact the Interim Privacy Officer to request deletion.

3. AI Features

When you use an AI-powered feature, Iridium may transmit the information needed to perform your request. Depending on the feature, that can include your prompt, custom instructions, relevant workout, nutrition, recovery, or HealthKit-derived context, AI memories, and images, video frames, or voice input you submit. Iridium routes AI requests through AIProxy and, for many features, OpenRouter. OpenRouter can route a request to a selected downstream model provider, including providers such as OpenAI or Google. Voice generation can use ElevenLabs. The provider used can vary with the feature, selected model, and service availability.

AI routing services and downstream providers can also process technical and network data, including an IP address and a device or app identifier, to deliver and authenticate requests, protect the service, provide functionality, and measure their service. This processing happens when you use an AI feature and is separate from Iridium's app analytics described above. Turning off Help Improve Iridium does not prevent processing needed to deliver an AI feature you choose to use.

We use these providers to deliver the feature you requested, not to place health-related ads. Do not include information in an AI prompt, image, video, or recording that is not needed for the feature.

4. Website Information

When you visit the website, our hosting and network providers process ordinary request information such as IP address, browser and device information, requested page, timestamps, referring page, and security or diagnostic logs. The website also uses storage that is needed for features you request, such as sign-in sessions, site access, and your analytics preference.

Optional website analytics

Google Analytics is off unless you select Allow analytics. If you allow it, we load Google Analytics only on a limited set of public marketing and educational pages, such as the home, blog, comparison, and screenshot pages. We do not intentionally load it on exercise library or exercise-detail pages, shared-gym links, legal pages, account or authentication pages, feedback and support administration, private administration tools, or API routes.

On allowed pages, Google Analytics can receive the page path (without the query string), page title, referring source, browser and device details, an analytics identifier, approximate region, and interaction or visit information. We disable Google Signals and advertising-personalization signals in our website tag configuration. Your choice is stored in your browser. You can change it at any time using Cookie Preferences in the website footer.

Separately, Iridium can keep first-party aggregate documentation counters, such as an article slug and view count or a yes/no helpfulness response. The application does not attach those aggregate records to a Feature Board account.

Shared gym links

If you create a shared gym link, the link itself contains an encoded copy of the gym identifier, name, address (if included), and equipment details. Encoding is not encryption. Anyone who receives the link can open it and may be able to decode that information, and hosting or browser infrastructure can process the URL. Do not publish or send a shared gym link if it contains an address or other information you do not want the recipient to have.

24-hour workout-sharing links

If you choose to share a workout, Iridium uploads a copy of the planned workout to create a temporary link. The copy includes the workout title and structure; exercise names; target-set details such as repetitions, weight, RPE, duration, intensity, distance, rest, and applicable set techniques; and the associated gym's name, address (if included), equipment, quantities, weight limits, and plate settings. It does not include completed-workout history, workout notes, nutrition or recovery information, HealthKit data, or your name, email address, or account identifier.

The workout payload is encrypted at rest on Iridium's server. The link's unguessable token acts as an access credential, so anyone who has the link can open and import the workout while it is active. The link expires 24 hours after it is created, and Iridium stops returning the workout through the link at that time. An expired encrypted record remains stored only until routine cleanup removes it, and backup copies can remain for the applicable backup cycle, but the expired link cannot be used to retrieve it. Expiration does not remove a copy that a recipient imported, saved, or forwarded while the link was active.

Share a workout link only with people you trust. Before sharing, review the workout and its associated gym, remove an address or identifying title you do not want others to receive, and avoid posting the link publicly.

5. Accounts, Feedback, and Support

If you use the Feature Board, bug reporter, or feedback tracker, we process the information you provide. This can include an email address, username, authentication and session records, votes, comments, feature requests, bug descriptions, follow-up messages, and attachments. Submissions from the app can also include app version, build number, device model, operating-system version, locale, time zone, screen identifier, recent diagnostic logs, chat context, and attachments. Some app report flows attach diagnostic or chat context automatically. Push-notification features can require an APNs device token and related device/app metadata.

We encrypt selected feedback-account and reporter email fields and use keyed hashes for lookup. Correspondence and operational records can separately contain email addresses and are protected through access controls and other safeguards rather than a promise that every stored copy uses field-level encryption. An email associated with a feature request is used for private submission tracking. We contact the submitter about that request only when they explicitly allow contact; older requests without a recorded choice are treated as not permitting contact. Reviewed feature-request titles and descriptions may be displayed publicly. Public feature comments are shown as "You" to their author and "Community member" to everyone else; names and email addresses are not displayed. Bug reports, unreviewed submission text, and administrative context are not intended for public display.

Feature comments are checked for spam, email addresses, phone numbers, and prohibited content, then sent to OpenRouter and a downstream safety model for moderation before publication. Bug reports can also be automatically triaged using OpenRouter and a downstream AI model. When an administrator prepares a feature request for public display, its private title and description can be sent to OpenRouter and a downstream AI model to suggest shorter public copy and remove likely identifying details. An administrator must review that draft before publication. The data sent for bug triage can include report text, device/app context, a limited portion of diagnostic logs or chat context, and screenshots. If an administrator starts an automated implementation, relevant report or feature-request text and attachment links can also be processed through OpenAI Codex on an administrator-controlled development machine and associated with a GitHub development workflow. Attachments are stored by Publitio and can be made available through provider-hosted URLs for review and processing. Treat an attachment URL as sensitive, and avoid submitting unnecessary personal or health information.

6. Purchases

Apple processes App Store purchases, payment credentials, billing, cancellations, and refund requests under Apple's terms and privacy practices. Iridium receives StoreKit transaction and entitlement information needed to unlock the subscription, such as the product, subscription status, and expiration or renewal state. We do not receive your full payment-card number.

7. How We Use Information

  • To operate, personalize, maintain, and secure the Services.
  • To provide workouts, nutrition tools, recovery insights, AI features, and subscriptions.
  • To process feedback, respond to support requests, and diagnose or fix problems.
  • To measure and improve the Services through optional app and website analytics when you choose to permit them.
  • To prevent abuse, enforce our terms, and comply with legal obligations.

8. Service Providers and Other Disclosures

We disclose information to service providers only as needed for the functions described above. Those providers include Apple for purchases, HealthKit, CloudKit, iCloud backup, WeatherKit, and notifications; Netlify for website hosting and workout-share routes; DigitalOcean for hosting and backup infrastructure used by analytics and External Data Sync services; Neon for database infrastructure, including encrypted workout-share payloads; Open Food Facts and Iridium's food-search service for nutrition lookup; Google Analytics for consented website measurement; AIProxy, OpenRouter, downstream model providers such as OpenAI and Google, and ElevenLabs for AI features; Publitio for media; Resend for email; OpenAI Codex and GitHub for administrator-initiated development workflows; and Pushover for notifications.

We may also disclose information when reasonably necessary to comply with law, protect users or the Services, investigate fraud or security issues, or complete a corporate transaction subject to appropriate safeguards. We do not sell personal information, and we do not use health-related data for advertising.

9. Your Choices and Privacy Rights

  • App analytics: use Settings → Privacy to turn Help Improve Iridium on or off and reset the Analytics ID.
  • Website analytics: use Cookie Preferences in the footer to allow or decline Google Analytics. Declining removes Google Analytics cookies that the website can access and prevents new website analytics from being sent by our tag.
  • HealthKit: review or revoke Iridium's permissions in Apple's Health or Settings apps.
  • Location and iCloud: review location access, iCloud synchronization, and device-backup choices in Apple's Settings app.
  • External Data Sync: enable it only when you want to make supported app data available to a compatible client or agent you authorize; disable connections you no longer use and contact us about server-held data requests.
  • In-app bug reports: a valid email address is required, is attached to the report, and may be used for follow-up. Contact the Interim Privacy Officer if you want a submitted report or associated email deleted.
  • Marketing email: use the unsubscribe link in an email where available.

Depending on where you live, you may have rights to request access to, correction of, deletion of, or a copy of personal information, or to object to or restrict certain processing. To make a request, contact hello[at]iridium[dot]fit. We may need to verify your request and may retain information where permitted or required by law.

If you are in Canada, you may request access to or correction of your personal information, withdraw consent subject to legal and contractual limits, and ask us to delete information that is no longer required or must otherwise be deleted. Quebec residents may also request eligible computerized personal information in a structured, commonly used technological format. We normally respond within 30 days. You may complain to the applicable federal or provincial privacy regulator.

A request to delete an Iridium or feedback account does not cancel an Apple subscription. Manage or cancel the subscription through Apple as described in our Terms of Use.

10. Retention and Security

We retain information for as long as reasonably necessary for the purposes described in this policy, including providing an active account or feature, resolving feedback, maintaining security and business records, and meeting legal obligations. Retention varies by record type and can include service-provider logs and backup cycles. When information is no longer needed, we take reasonable steps to delete or de-identify it, subject to technical and legal limits.

We use reasonable administrative and technical safeguards, including encryption in transit and encryption of selected stored identifiers. No system is completely secure, so please do not send information that is not needed for the feature or support request.

11. Age Requirement

The Services are not intended for anyone under 18, and people under 18 should not use them. If you believe a minor has used the Services or provided personal information, contact us so we can investigate and take appropriate action.

12. International and Cross-Border Processing

Iridium is based in the United States. We and our service providers can process information in the United States and in other countries where a provider or its subprocessors operate. Information processed outside Canada or your province may be accessible to courts, law-enforcement, or national-security authorities under local law. We are verifying the account region, contract, and current subprocessor countries for each provider rather than inferring them from a corporate address. Contact the Interim Privacy Officer for our current service-provider policies and the verified country information available for your data.

13. Browser Do Not Track and Cross-Site Collection

The website does not respond to browser Do Not Track signals. Hosting, security, and hosted-content providers receive ordinary request information to deliver and protect the site and can collect that information over time and across services under their own policies. Google Analytics loads only after you select Allow analytics and only on the permitted pages described above. We disable Google Signals and ad-personalization signals and do not use this information for targeted advertising.

14. Changes to This Policy

We may update this Privacy Policy as the Services or our practices change. We will post the updated policy here and revise the effective or last-updated date. When required by law, or when a change materially expands our collection, use, or disclosure of sensitive information, we will provide additional in-app or email notice and obtain consent before the new practice begins.

15. Contact the Interim Privacy Officer

Interim Privacy Officer
Autumn Creek Press, LLC
1203 W. Appaloosa Ln.
Lehi, UT 84043 USA
hello[at]iridium[dot]fit
https://iridium.fit