Privacy policy
Last updated September 1, 2026.
Information Rytiva processes
Rytiva processes account identifiers, your name and email when supplied by an authentication provider, provider-neutral sign-in links, Rytiva device identifiers, purchase and entitlement records, authored workout plans, workout interactions and completion history, notes attached to sets, and limited HealthKit workout summaries such as duration and heart-rate statistics. Rytiva does not request or upload your full HealthKit history, payment-card data, advertising identifier, precise location, contacts, microphone, or photo library.
How information is used
We use this information for app functionality: authenticating you, delivering workouts between an authorized assistant and your Apple devices, maintaining history, providing requested training summaries and product interactions, enforcing paid capabilities, preventing replay, and completing export and deletion requests. Rytiva does not sell personal information, use it for targeted advertising, or track you across other companies’ apps and sites.
Service providers
Apple processes Sign in with Apple, HealthKit, StoreKit, and subscription activity. Cloudflare operates the Worker, D1 database, KV authorization store, OAuth service, restore facilities, and minimized operational diagnostics. When enabled, Supabase processes email authentication and may use Resend to deliver transactional authentication email. User-authorized ChatGPT and Claude connectors process the workout content requested through those services. MuscleWiki provides exercise catalog and optional reference media. Each provider also processes ordinary security and network metadata under its own terms.
Retention and security records
Active account records remain until account deletion or a shorter feature-specific lifecycle. Account-linked analytics, if production ingestion is separately enabled, age out after 30 days. OAuth authorization state lasts 10 minutes. A deletion retry proof and encrypted Apple cleanup credential last at most 24 hours, the deletion receipt lasts 30 days, and keyed erasure markers last 31 days. Those records contain no raw account ID, email, or provider subject and protect against an account reappearing during Cloudflare D1 Time Travel, which can retain database recovery points for up to 30 days. Custom diagnostics use a fixed field allowlist and are sampled once at the Cloudflare head at five percent; code does not apply a second sample. They omit identifiers, email, URLs, queries, headers, IP/geolocation/user-agent values, workout or purchase content, provider payloads, exact durations, and raw errors. Cloudflare may retain its platform records according to the applicable plan and legal obligations.
Exercise reference media
Exercise data and videos provided by MuscleWiki.com. For verified mapped exercises, Rytiva sends only the catalog’s provider exercise ID from the Worker and obtains a short-lived media-only stream URL. Playback then connects directly to MuscleWiki and discloses the selected media plus ordinary request and network metadata, but does not send your Rytiva account identifier, email, workout log, or HealthKit data. Rytiva keeps the provider key on the Worker, does not log the signed stream URL, and does not download, persist, proxy, re-host, or shared-cache video bytes. Playback uses only transient in-memory buffering.
Your choices
You can revoke a connected device or assistant, remove Health access in iOS Settings, export a versioned copy of account-owned data, and request account deletion in Rytiva. Export omits authentication secrets, OAuth tokens/private properties, Supabase password/session/token data, Apple signed payloads, and security HMACs. Deletion requires recent proof from each linked identity provider and succeeds only after Supabase, Apple, and assistant authorization cleanup succeeds or the provider confirms the record is already absent. Deleting Rytiva does not cancel an App Store subscription; manage that separately with Apple. Content copied to an external assistant remains subject to that service’s controls.
Contact
Email lfauset@gmail.com with privacy questions or deletion requests.