Privacy Policy
Effective date: 25 May 2026 · Last updated: 13 September 2026
This policy explains what data the Overload mobile app
(the "App") collects, why, and how you control it. Overload is a fitness coach
app: workouts, nutrition, recovery and an AI coach. The data we handle
is the data you choose to log or connect.
Plain summary. Overload stores your account (email),
workouts, routines, meals, body stats, health data you choose to
connect, purchase records, and AI Coach conversations. We do not sell
your data and we do not run ads. We use PostHog for product analytics
and crash reports so we can fix bugs. You can delete your account at
any time from inside the app. It wipes your data.
1. Who we are
The App is operated by Sarthak Kumar
("we", "us"). Contact: support@tryoverload.app.
2. What we collect
Account data
- Email address and authentication identifiers (via Clerk, our auth provider).
- If you sign in with Apple or Google, we receive the identifiers those providers return — typically email + a stable user ID. We never receive your password.
Fitness data you log
- Workouts, exercises, sets, reps, weight, duration, notes.
- Routines you create.
- Meals you log: the text you type and the calories, protein, carbs and fat parsed from it.
- Body stats you choose to enter (weight, body fat, measurements, goal weight, unit preference).
- Onboarding answers you give: goal, experience, training days, age, sex, height, weight, target weight, and any injury notes or preferences.
Health data (optional)
- If you connect Apple Health or Health Connect, the App reads steps, sleep, resting heart rate, heart rate variability, active calories and bodyweight.
- We use this only to compute your readiness score and to let the Coach adjust your training. It is never used for advertising, never sold, and never shared except with the processors below that store it (Supabase) or that answer you (Anthropic, as a short summary inside a Coach request).
- The App never writes to Apple Health or Health Connect. You can disconnect at any time in your phone's Settings.
Purchases
- If you buy Overload Pro, Apple or Google processes the payment. We receive a purchase record (product, dates, status and an app user ID) through RevenueCat so we can unlock Pro on your account. We never see your card details.
AI Coach interactions
- The messages you send to the AI Coach and the responses returned.
- Coach prompts include a summary of your recent workouts so it can answer in context.
Usage analytics and diagnostics
- We use PostHog to record which screens you open and which buttons you tap, and to replay sessions so we can see where the app confused you or broke. Replays capture the screens as you saw them; sign-in fields are masked.
- App version, OS version, device model, crash reports and error logs, collected through PostHog and Expo.
- Bug reports you submit voluntarily through the Profile screen.
- This data is linked to your account ID. It is used only to improve the product and fix bugs, never for advertising, and never shared with ad networks.
We do not collect: location, contacts, photos, microphone, or advertising IDs. Health data is read only if you connect Apple Health or Health Connect.
3. How we use it
- To provide the app's features (track workouts, render analytics, answer Coach questions).
- To keep you signed in across devices.
- To unlock Overload Pro after you buy it.
- To investigate and fix bugs you report or that crash the app.
- To understand how the app is used and where it breaks.
- To improve the product over time.
We do not use your data for advertising, profiling, or sale
to third parties.
4. Who we share it with
We use the following processors. They handle data on our behalf under their own privacy commitments:
- Clerk — authentication (privacy policy).
- Supabase — database + storage (privacy policy).
- Anthropic — AI Coach inference, when you use the Coach (privacy policy). Anthropic does not train on customer API content.
- Voyage AI — embeddings used by the Coach for context retrieval (privacy policy).
- PostHog — product analytics, session replay and crash reporting (privacy policy).
- RevenueCat — in-app purchase records (privacy policy).
- FatSecret and Open Food Facts — nutrition database lookups for the foods you log. They receive the food name being searched, not your account (FatSecret privacy policy, Open Food Facts privacy policy).
- Apple Health / Google Health Connect — read only if you connect them, under Apple's and Google's health data rules.
- Expo (EAS) — over-the-air updates + crash diagnostics (privacy policy).
- Apple / Google — sign-in and app distribution.
We do not share or sell your data for advertising.
5. Where data is stored
Account + fitness data is stored in Supabase Postgres (region
us-east-1 (US East, Virginia)). Auth state is stored in
Clerk. AI Coach inference runs through Anthropic's API.
6. How long we keep it
- While your account exists, we keep your data.
- When you delete your account from inside the app (Profile → Delete Account), we wipe your Supabase rows and ask Clerk to delete your account. To have your PostHog analytics data deleted as well, email us and we will do it within 30 days. Purchase records stay with Apple, Google and RevenueCat for as long as their accounting rules require.
- Backups may persist briefly (up to 30 days) until they roll off.
7. Your rights
You can:
- Access — see your data inside the app at any time.
- Correct — edit any of it inside the app.
- Delete — Profile → Delete Account permanently removes your data.
- Export — email support@tryoverload.app and we will send your data within 30 days.
- Object / Restrict — email us; if you're in the EU/UK/California you have additional rights under GDPR / CCPA which we honor.
8. Security
Tokens are stored in the device's secure enclave (iOS Keychain /
Android Keystore). All network traffic uses HTTPS. Supabase
Row-Level-Security policies scope every row to your user ID so no
other user can read your data. We are a small team — no system is
perfect — and we will notify affected users in the event of a breach.
9. Children
Overload is not directed to children under 13 (or under 16 in the
EU/UK). We do not knowingly collect their data. If you believe a
child has signed up, email us and we will delete the account.
10. Changes
If we materially change this policy we will update the "Last updated"
date and notify users inside the app on next launch. Continued use
after changes constitutes acceptance.
11. Contact
Questions? support@tryoverload.app