Privacy Policy

Instrument — Lifting Log  ·  Effective August 5, 2026

Instrument is a workout logging app for iPhone, made by Jordan Francis. This policy explains exactly what the app records, what leaves your device, and how to get rid of it. There is no advertising, no analytics, no tracking, and nothing is sold or shared with third parties for their own purposes.

The short version

What the app stores on your device

If you never sign in, that is the whole story: the data stays in the app's own storage and is removed when you delete the app. It is included in your iPhone or iCloud device backup according to your own iOS backup settings, which we do not control or read.

What we receive when you sign in

Sign-in uses Sign in with Apple. We never see your Apple ID password. From Apple we receive:

Once you are signed in, the app uploads a copy of your training log, listed above, and keeps it in sync. We do not receive your name, contacts, photos, location, health records, HealthKit data, device advertising identifier, or any browsing activity — the app does not request any of those.

Why we hold it

Only to run the features you asked for: keeping your log backed up, restoring it on a new device, and answering questions about your own training. It is never used for advertising, profiling, credit or insurance decisions, resale, or training any machine-learning model.

Microphone and speech recognition

The microphone is used only while you are actively dictating a set or a question, and only after you grant permission. Speech is transcribed with Apple's on-device recognizer, so audio never leaves your iPhone and is never sent to Apple, to us, or to anyone else. Recordings are not saved — only the text you keep is stored, as part of your log. You can revoke microphone or speech access at any time in iOS Settings → Privacy & Security.

On-device intelligence

Session summaries, the “Ask” reports, and voice parsing use Apple's on-device Foundation Models through Apple Intelligence. These run locally on your device. Your training data is not transmitted to us or to any AI provider in order to produce them, and if Apple Intelligence is unavailable the app simply falls back to plain figures.

Connecting an AI assistant (optional)

If you tap “Get MCP URL”, the app generates a private link that gives read-only access to your own workout data. We store only a SHA-256 hash of its token, never the link itself.

Anything you paste that link into — Claude, ChatGPT, or any other client — can then read your training history, and that service's own privacy policy governs what it does with it. Treat the link like a password and only give it to services you trust. It is revoked when you sign out on the device that created it or delete your account.

Where it is stored, and who else touches it

Synced data is held in a Cloudflare D1 database, operated by Cloudflare, Inc. as our hosting provider and processed only on our instructions. Cloudflare does not use it for its own purposes. All traffic between the app and the server is encrypted in transit with HTTPS/TLS. Every database query is scoped to your own user identifier, so no account can read another's data. We use no other processors — no analytics vendor, no crash reporter, no advertising network, no email marketing tool.

How long it is kept

Synced data is kept until you delete it. There is no scheduled expiry, because a training log is only useful as a long record. Delete your account and it is removed from the live database immediately; residual copies in routine encrypted backups are purged within 30 days.

Deleting your data

Your rights

Wherever you live, you can ask us for a copy of the data we hold about you, ask us to correct it, or ask us to delete it. Depending on where you live — for example under the GDPR in the UK, EU and EEA, or under the CCPA/CPRA in California — you may also have the right to object to or restrict processing, to receive your data in a portable format, and to complain to your data protection authority. We do not sell personal information and do not share it for cross-context behavioural advertising, so there is nothing to opt out of. Email jordanmfrancis777@gmail.com and we will respond within 30 days. For users in the EU, EEA and UK, our lawful basis is performance of the contract you enter into by using the sync feature (Article 6(1)(b)) — nothing here relies on consent that you would later have to manage, other than the iOS microphone and speech permissions you can revoke in Settings.

Children

Instrument is not directed at children under 13 and we do not knowingly collect personal information from them. If you believe a child has created an account, email us and we will delete it.

International transfers

Our server runs on Cloudflare's global network and your data may be processed in the United States or other countries where Cloudflare operates. Transfers out of the UK, EU and EEA rely on Cloudflare's Standard Contractual Clauses.

Changes

If this policy changes materially, the effective date at the top changes and the updated version is published at this URL before the change takes effect. Continuing to use the app after that means you accept the update.

Contact

Jordan Francis, individual developer and data controller for Instrument
jordanmfrancis777@gmail.com