TautFit

Privacy Policy

Last updated 30 July 2026

TautFit is a training app for iPhone and Apple Watch. It is operated by Qi Design Studios Pte Ltd, 60 Paya Lebar Road, #06-28 Paya Lebar Square, Singapore 409051 (“we”, “us”). This policy explains exactly what the app collects, where it goes, and what control you have over it. It is written to be read, not to be survived.

The short version. Your training data lives on your iPhone. It is only copied to our server if you sign in, and then only so your own devices stay in sync. We do not sell your data, we do not use it for advertising, we have no advertising or analytics SDKs in the app, and we never use Apple Health data for anything except the features you turned on.

  1. What we collect
  2. Apple Health data
  3. The AI coach
  4. Why we process it
  5. Who we share it with
  6. How long we keep it
  7. Your rights and controls
  8. Security
  9. Children
  10. International transfers
  11. Changes
  12. Contact

1. What we collect

Stored on your device

TautFit is local-first. Everything you log is written to a database on your iPhone and the app works fully offline. This includes your sessions and the sets, reps, weights, RPE, distances, durations and notes inside them; the exercises and nicknames you have taught it; your body measurements; goals; injury and constraint flags; programs; and your app settings.

If you never sign in, that is where it stops. Nothing on this list leaves your phone except through Apple's own iPhone backup, if you have iCloud Backup enabled, or a CSV file you export yourself.

Sent to our server if you sign in

Signing in is optional and is only required for cross-device sync, for a Pro subscription, and for the coach after your first few messages. When you sign in with Apple we receive and store:

What we do not collect

We have no advertising identifiers, no third-party analytics or attribution SDKs, no location tracking, and no crash-reporting service that ships your data to a vendor. We do not track you across apps or websites, and we do not build a profile of you for any purpose other than running the features you are using.

2. Apple Health data

We never use Apple Health data for advertising or marketing, never sell or share it with data brokers, and never disclose it to third parties. It is used only to power the features described here, inside your own account.

Health access is entirely optional and you can revoke it at any time in iOS Settings.

Imported workouts become normal session entries, which means they are covered by the sync described above if you are signed in. If you would rather Health data never leave your phone, do not sign in, or turn off Health import in the app's Health settings.

3. The AI coach

Three features send text to our server, which runs a language model on Cloudflare Workers AI:

We do not store your coach conversations on our server, and the model provider does not use this input to train models. Resolved exercise phrases are cached so the app gets faster and cheaper with use. The numbers you log are never sent to a language model for interpretation — weights and reps are parsed by a deterministic grammar on your device, precisely so a model can never invent one.

4. Why we process it

WhatPurposeLegal basis (UK/EU)
Training data on device Running the app you installed Performance of a contract
Sync copy on our server Keeping your devices in step and giving you a recoverable copy Performance of a contract
Apple Health data Import and write-back features you enabled Explicit consent (iOS permission prompt)
Account identifier and email Authentication, support, and account recovery Performance of a contract
Subscription state and usage counters Enforcing free limits and unlocking Pro Performance of a contract
Bug reports Fixing what you told us is broken Legitimate interests

5. Who we share it with

We do not sell your data and we have no advertising partners. Data reaches exactly three other parties, each doing a job we could not do ourselves:

6. How long we keep it

7. Your rights and controls

Regardless of where you live, TautFit gives you these directly in the app:

If you are in the UK, EU, or a similar jurisdiction, you also have the right to access, correct, port, restrict, or object to our processing of your data, and to complain to your local data protection authority. If you are a California resident, you have the right to know, delete, correct, and to opt out of “sale” or “sharing” — we do neither, so there is nothing to opt out of. Write to privacy@tautfit.com and we will respond within 30 days.

8. Security

All traffic between the app and our server uses TLS. Your identity is verified against Apple's published signing keys on every request, and subscription receipts are verified against Apple's certificate chain rather than trusted as sent. Sync data is stored in a database that partitions rows by account, and is only readable with a valid session for that account. No system is perfectly secure, but if a breach affects your data we will tell you and the relevant regulator as required by law.

9. Children

TautFit is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has provided us with data, contact us and we will delete it.

10. International transfers

Our infrastructure runs on Cloudflare's global network, so your data may be processed in countries other than your own, including the United States. Where required, these transfers rely on Standard Contractual Clauses or an equivalent safeguard.

11. Changes

If we change this policy we will update the date at the top, and for material changes we will tell you in the app before the change takes effect. We will never retroactively broaden how we use data you have already given us without asking you first.

12. Contact

privacy@tautfit.com
Qi Design Studios Pte Ltd
60 Paya Lebar Road, #06-28 Paya Lebar Square,
Singapore 409051