ALDO COACH

Aldo — Privacy Policy

Last updated: September 3, 2026 · Version 3.3

This policy explains what Aldo collects, why, who else touches it, and what you can do about it. It covers the app and website at aldo-coach.app (the "Service"). Using the Service means you accept this policy, the Terms of Use, and the Health & Safety Notice and Waiver.

1. Who we are

Aldo is operated by River Lentil LLC, a California limited liability company ("we", "us"), based in California, United States. It is a single-member LLC with no staff — one person runs the Service day to day, and that person is the only human with administrative access to your data. Forming the LLC changed who is legally responsible for the Service; it did not change who operates it, who can see your data, or how your data is handled.

Contact: support@aldo-coach.app

2. Where we operate

The Service is offered to users in the United States, and data is stored and processed in the US by our providers. We do not target the Service to users outside the US, and this policy is not written to satisfy the EU/UK GDPR or other non-US data-protection regimes.

3. Information we collect

3.1 Account data

Your email address and password. Passwords are handled by our authentication provider (Supabase) and stored only as a secure hash — we never see or store your plaintext password. Confirming your account also triggers a one-line internal notification — your email address and the confirmation time — to a private Discord channel we use to know a new account was created (see section 6).

3.2 Profile data

What you enter in your profile: age, sex, bodyweight, sleep, and nutrition notes. This is optional and it is what lets the coach account for your situation. You can edit or clear it in the app.

3.3 Training data

The substance of the app: workouts, training programs, set logs, schedules and life-schedule entries, exercise library entries, coach notes, and any files you upload (such as a program PDF or a training-history spreadsheet).

3.4 Injury and pain data — health-adjacent, called out separately

This category deserves its own heading, so it is getting one.

If you use the injury and rehab features, we collect:

Two things you should understand about this data:

It is sent to Anthropic's API as coaching context. To generate rehab-oriented coaching, pain interpretation, or a return-to-activity suggestion, the relevant injury entries, statuses, and pain scores are included in the prompt sent to Anthropic's models — the same way your training data is. There is no way to receive injury-aware coaching without the coach seeing your injury information. If you do not want that, do not enter it; the rest of the app works without it.

It is not medical-record data held by a healthcare provider. We are not a doctor's office, a clinic, a hospital, or a health plan, and we are not a business associate of one. Your injury and pain data in Aldo is not a medical record, is not protected health information under HIPAA, and does not carry the legal protections that apply to records your physician or physical therapist holds. It is consumer data you typed into a fitness app. We treat it carefully — it is stored under the same access controls as the rest of your account data, and we do not sell it or use it for advertising — but you should decide what to enter with that distinction in mind. What the injury features can and cannot do for you clinically is covered in the Health & Safety Notice.

3.5 Apple Health data (iOS app only)

The iOS app can connect to Apple Health. It is opt-in and does nothing until you turn it on in Settings → Data & Backup → Apple Health (or from the Recovery strip at the top of the Workout tab), and each data type has its own switch you can turn off at any time.

If you connect it, Aldo reads:

If you leave the third switch on, Aldo writes:

Three things you should understand about this data:

It is stored on your device. The summaries Aldo derives from Apple Health live in local storage on your phone. They are deliberately excluded from your cloud backup, the account mirror, and data exports — on a new phone, Aldo re-reads them from Apple Health there.

It is sent to Anthropic's API as coaching context. Like your injury data, the sleep summary, the body-weight trend, the heart-rate range comparison (below / at / above your own norm) and the count of other-app workouts are included in the prompt sent to Anthropic's models when the coach plans or adjusts a session (see section 5). Only those derived summaries are sent — never raw Apple Health samples.

It is never used for advertising, marketing, or data mining, and it is never sold. Apple Health data is not shared with anyone other than the model processing described above, and is not used for any purpose beyond coaching you.

You can revoke access at any time in the Apple Health app → Sharing → Apps → Aldo, or by tapping DISCONNECT on the Apple Health card in Aldo. Disconnecting stops all reading and writing. Deleting the app removes the summaries stored on your device.

3.6 Coaching chat transcripts

Your conversations with the coach — your messages and the coach's responses — are stored so your threads persist across sessions and so the coach has continuity. They may include whatever you have chosen to tell it, including health details.

3.7 Usage and billing metadata

App version, feature usage counts, message counts and model-usage records used to operate rate limits and monitor cost. Billing metadata is a subscription status and, if you have ever subscribed, a Stripe customer reference — Stripe, not us, holds any card details. During the free beta no new charges are made and no new payment information is collected; if paid plans return, billing works as described in the Terms of Use.

3.8 Diagnostic data

Limited technical information used to keep the app working: performance and request diagnostics, and a small rolling diagnostic buffer stored on your device.

3.9 Diagnostics and product analytics (Sentry, PostHog)

When diagnostics are enabled, we use two additional processors to keep the app working and to understand, in aggregate, how it's used:

What's never sent, structurally, not just by policy. Every property on every event and every error report is checked before it leaves your device: only a boolean, a number, or a short enum-style tag (like a status code) is allowed through. Free text is dropped, not sent. That means your messages to the coach, the coach's replies, anything you type into a note or an injury entry, uploaded file content, and your health, injury, or pain data can never ride out through Sentry or PostHog — there is no code path that reads or forwards the substance of what you write or what the coach says. Page URLs and referrers are excluded too. Session recording and automatic click/DOM capture are both disabled — nothing about how you interact with the screen is recorded.

Both ride our own backend. Your device never contacts Sentry's or PostHog's servers directly; every report and event is proxied through our own API. Their servers never see your IP address making a direct request to them, and no separate third-party connection is made from your browser.

You can turn this off. Settings → Data & Backup → Sharing has a single toggle, Share error reports & anonymous usage — on by default — that governs both Sentry and PostHog together. Turning it off stops both immediately on your device — the app works exactly the same either way.

3.10 Calendar data

The app can connect to your calendar so the coach can see what's already on your schedule. It is opt-in and does nothing until you connect it, from the calendar sync card in Schedule (Program tab → Manage Schedule, or tap any day on the calendar), and you can disconnect at any time.

Two providers, depending on platform:

If you connect a calendar, for each event in the calendars you select Aldo reads:

Three things you should understand about this data:

It is stored, not just passed through. Unlike Apple Health data, a synced calendar event becomes an ordinary entry in your Schedule — on your device and in your account's cloud backup — exactly like one you typed in yourself. You can edit its category, mark its impact on training, add a note, or delete it there.

It is sent to Anthropic's API as coaching context. Event titles, dates, times, and categories in your Schedule — calendar-synced or hand-entered, the coach's context doesn't distinguish — are included in the prompt sent to Anthropic's models (see section 5) so the coach can plan around what's on your calendar. If you don't want an event's title reaching the coach, don't sync that calendar, or edit or delete the entry in Schedule once it appears.

The Google connection itself is stored server-side. Connecting Google Calendar stores a refresh token and the granted scope with our backend (Supabase) so we can fetch your events without asking you to sign in to Google every time; the token never reaches your device. Apple Calendar has no equivalent — it is on-device only, so there is no server-side token to store.

You can disconnect at any time with Disconnect in the calendar sync card. That stops Aldo from reading or syncing your calendar going forward; events already synced stay in your Schedule as ordinary entries, the same way disconnecting Apple Health doesn't erase what it already wrote (section 3.5). To also revoke Aldo's stored access to your Google account, remove Aldo from Google's connected apps — this invalidates the stored token — or delete your Aldo account, which removes it along with everything else. On iPhone, calendar access is controlled the same way as Apple Health: iOS Settings → Privacy & Security → Calendars → Aldo.

4. How we use your information

We do not sell your personal information, we do not share it for advertising or cross-context behavioral advertising, and we do not use your data to train AI models.

5. AI processing

Aldo is powered by large language models from Anthropic. To generate a response, the relevant parts of your data — profile, current and recent sessions, programs, notes, injury entries and pain scores, and the conversation — are sent to Anthropic's API through our backend.

Under Anthropic's API terms, data submitted through the API is not used to train its models. Anthropic processes it to return a response and retains it only as its terms and policies allow.

We send what the coach needs for the request at hand rather than your entire history, but assume that anything you enter in the app may be sent as coaching context.

6. Service providers and subprocessors

We share data only with providers that operate parts of the Service on our behalf:

Sentry and PostHog are being added at launch. We may add or change providers; when we do, we will update this list.

We may also disclose information if required by law, to enforce the Terms of Use, or to protect the safety of a person or the Service.

Outbound links are links, not embeds. When Aldo shows a "watch tutorial" button, or the coach includes a video or article link, the app is not loading that content inside itself. We do not embed third-party video players, so nothing about you is sent to YouTube, Google, or any other site until you tap the link and leave — and those sites set no cookies on you through us. Once you follow a link you are on their site, under their privacy policy, and we have no visibility into or control over what they collect.

7. Bug-report snapshots (opt-in)

When you file a bug report from inside the app, it is filed as an issue in a private GitHub repository that only the operator can see. The issue carries your report's description and basic diagnostic details, plus your account's opaque user id (never your email) so we can look you up if we need to follow up. You will also see a checkbox offering to attach a snapshot of your app data — training data, chat transcripts, and settings — so the bug can actually be reproduced.

How it works:

Ask at support@aldo-coach.app if you want a snapshot you submitted deleted.

8. Data retention

We keep your account and data for as long as your account is active.

When you delete your account, your data is removed from our active systems. Copies may persist for a limited period in encrypted backups and in provider logs (for example, hosting and error-monitoring logs) until they expire on their normal schedule. Bug-report snapshots expire with their signed URLs and are deleted on request.

Aggregate, de-identified usage counts that cannot be tied back to you may be retained.

9. Your choices and rights

California privacy rights. California residents have rights under the California Consumer Privacy Act (CCPA/CPRA), including rights to know, delete, correct, and limit the use of sensitive personal information, and the right not to be discriminated against for exercising them. We honor access and deletion requests sent to support@aldo-coach.app regardless of whether the statute applies to us at our current size. We do not sell or share personal information as those terms are defined by the CCPA.

10. Security

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach affects your data, we will notify you as required by law.

11. Children

The Service is for adults. You must be 18 or older to use it, and we do not knowingly create accounts for or collect personal information from anyone under 18. We do not knowingly collect any information from children under 13, consistent with COPPA.

If you believe someone under 18 has created an account, email support@aldo-coach.app and we will delete it and the associated data.

12. Changes to this policy

We may update this policy. When we do, we update the "Last updated" date and version number at the top. Material changes will also be announced in the app, and where they affect your agreement with us, you may be asked to re-accept the updated Terms of Use.

13. Contact

Questions about this policy, your data, or a deletion request: support@aldo-coach.app

Related documents: Terms of Use · Health & Safety Notice and Waiver