Privacy policy

Effective 22 August 2026 · Developer contact: info@thruster.cloud

The short version

A training log is a health record. We treat it as one.

What we store

DataWhyKept
Email addressTo sign you inUntil you delete your account
Display name, avatar, gym nameTo show you to your boxUntil you delete your account
Workouts, results, sets, personal recordsThe logbook — the productUntil you delete them, or your account
Which movements you scaled, and what toYour Rx history, the “still scaling” list, and better coach programmingUntil you delete the result, or your account
Your chosen languageSo coach notes and scan results are written in it, including when no device is askingUntil you delete your account
Bodyweight, body fat, resting heart rateOptional; charts onlyUntil you delete them
Coach requests and generated workoutsRate limiting, cost attribution, and support when a workout comes out wrong12 months
Whiteboard transcriptions — the text read off a board, never the photoRate limiting, and support when a scan comes out wrong12 months
Ad impressions and clicksTo know whether the ad slots are worth showing12 months

What we deliberately do not store

Who can see what you scaled

Nobody but you. A box leaderboard shows a name, a score and whether the session was Rx — it is a projection built by our API, not a view of your rows. The per-movement breakdown, including anything you typed into “what did you do instead”, never leaves your own logbook.

What somebody scales is the most personal thing in a training log. It is the thing people are quietly embarrassed about, and it is exactly what would make the feature unusable if it were a scoreboard.

The AI coach

When you generate a workout we send Anthropic a structured brief: how long you have, the equipment you selected, your experience level, your recent workout titles and stimulus, and your one-rep maxes. That is what lets it prescribe real loads instead of "moderate".

When you scan a whiteboard, we send Anthropic the photograph so it can be read. Nothing else about you goes with it.

Warm-ups work the same way: we send Anthropic the workout you are about to do and your one-rep maxes, so it can pick loads that make sense for you.

We do not send your name, email, notes, bodyweight or injuries. Anthropic does not train models on data sent through the API.

Form check

Form check is the one feature that sends video, and the one feature that goes to a different company. When you record a movement and ask for feedback, we send Google the video — up to one minute — along with which movement you said it is, your experience level, and your best single on that movement. Nothing else about you goes with it.

The video is never kept. It goes first into a private area of our own storage — this is only how it gets to us, since it is far too large to send any other way — and from there to Google. It is deleted from both as soon as your feedback comes back, rather than left to expire on its own, and it is removed from your phone once it has been sent. It is never in our database, never visible to anyone else, and nothing keeps a copy.

Form check gives technique feedback, not medical advice. It does not diagnose injuries and it is not a substitute for a coach or a clinician who can see you in person.

Analytics

Optional, and off with one switch in the app (Me → Share anonymous usage data). We use PostHog, hosted in the United States. Events are counts, enums, booleans and durations — for example "a timer was started, mode EMOM", or "a paywall was viewed, source coach_quota".

Analytics carries no workout content and no name, and the switch in Me turns it off completely. Note that it is not the only thing hosted outside the EEA: the database itself runs in the United States (see "Where data lives" below), so turning analytics off reduces what is collected but does not keep your data on one side of the Atlantic.

Autocapture and session replay are disabled in the app's source code, not by a dashboard setting, because both would record screen contents — and on these screens that means your training data. Identity in analytics is your account UUID and nothing else.

Ads

The free tier shows ads through Google AdMob. In the EEA and UK you are asked for consent first. If you decline, AdMob serves non-personalised ads — the app still works and the slots still show something. We send AdMob no training data. Thruster Pro removes ads entirely.

Subscriptions

Handled by RevenueCat and your app store. We store which entitlement you hold and when it expires — never card details, which we never see.

Sharing

Your results are visible to other members of a box you joined, on leaderboards for workouts you both logged. Those leaderboards show your display name, avatar and score — never your notes, RPE or bodyweight. Leave the box and you leave the leaderboard.

Deleting your account

Me → Delete my account, in the app. It removes your profile and everything that hangs off it — results, sets, records, programs, bodyweight, coach history — by cascade, immediately. You can also request deletion without installing the app.

Deleting your account does not cancel a subscription. We cannot cancel an App Store or Google Play subscription on your behalf — cancel it in the store first.

Children

Thruster is not for under-13s and we do not knowingly collect their data.

Where data lives

Supabase (Postgres, United States), Anthropic (coach requests, warm-ups and whiteboard reading), Google (form-check video analysis only, deleted as soon as the feedback returns), PostHog (United States, analytics, optional), RevenueCat (subscription state), IONOS (delivers your sign-up confirmation and password-reset email; it sees your email address and nothing else).

Changes

Material changes get an in-app notice before they take effect. The effective date at the top of this page always reflects the current version.