Legal
Privacy Policy
How Unbound AF handles personal and fitness-related information for the Unbound AF service.
Effective: August 14, 2026Last updated: August 19, 2026
1. Introduction
This Privacy Policy explains how UNBOUND AF (“Unbound AF,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you use the Unbound AF website and application at https://unboundaf.com (the “Service”).
Unbound AF is a fitness and wellness product. It is not a medical provider, and this Policy is not a HIPAA Notice of Privacy Practices. Unbound AF is not a covered entity under HIPAA.
Fitness, workout, body, readiness, and nutrition information may be treated as sensitive or “consumer health data” under some state laws. See also our separate Consumer Health Data Privacy Policy.
2. Information We Collect
We collect the following categories of information when you use the Service:
Account and identity information. Email address, password (handled by our authentication provider), display name, and—if you choose Google sign-in—authentication identifiers and profile details provided by Google through our authentication provider.
Fitness profile information. Profile display name, unit preference, timezone, optional avatar URL, and whether a profile is your authenticated profile or a managed profile in a household.
Onboarding and preference information. Information you provide during onboarding and similar setup flows, which may include training goals, sex, experience level, recent training, days and session length, equipment and location, estimated bodyweight and height, estimated lift numbers, limitations, disliked exercises, sleep and stress self-reports, adaptation preferences, and free-text goal or plan notes.
Workout and performance information. Programs and schedules, workout sessions, exercises and sets (including loads, repetitions, and reported RIR), session notes, readiness checks (such as sleep, energy, soreness, and affected areas), adaptation decisions, planned skips, and progress derived from your training history.
Nutrition and body information (where the feature is available to you). Food logs, saved meals, calorie and macro targets, Adaptive Intake inputs (which may include age in years, metabolic sex, height, weight, activity level, and pregnancy-related status where you provide it), bodyweight logs, food-database lookups (including barcode product identifiers you scan for nutrition logging), and related nutrition metadata.
When you scan a food barcode on a supported device, Unbound AF uses the decoded product identifier for authenticated USDA product lookup. On iOS, your device camera reads the barcode locally in the app. On Android, Google Play services Code Scanner provides the native scanner UI and on-device barcode processing; Unbound AF receives only the decoded digits. We do not store camera images or video. Decoded barcode identifiers may be cached on our servers to improve lookup performance.
Household information. Household membership, roles, invitations, managed profiles, and delegated Training or Nutrition permissions you grant or receive.
Subscription and payment information. Plan type, billing interval, trial and subscription status, and related billing metadata. Payment card details are collected and processed by Stripe; Unbound AF does not store full card numbers or CVCs.
Support and communications. Messages and optional screenshots you submit through feedback or support channels, and emails you send to us.
AI feature inputs and outputs (when used). Free-text notes you submit for optional interpretation (for example, a plan brief or regenerate note), small related preference enums, and the structured interpretation result we store for reliability and auditing.
Technical and product-event information. Basic technical information needed to operate the Service (such as authentication session data) and first-party product events (for example, that onboarding completed or a workout was logged). We do not use Google Analytics, Meta Pixel, or similar advertising trackers.
We do not currently collect date of birth, meal photos, or progress photos as product features.
3. How Information Is Collected
- Directly from you (account forms, onboarding, logging, settings, feedback)
- Generated from your activity in the Service (programs, adaptations, progress)
- From authentication providers (email/password via Supabase Auth; Google OAuth)
- From our payment processor (Stripe) for subscription status
- From authorized household members when you grant delegated access, or when someone manages a managed profile they control
- From third-party food data APIs when you search, scan a barcode, or add foods (USDA FoodData Central)
- From optional AI processing of text you submit for interpretation (via OpenRouter)
4. How Information Is Used
We use information to:
- Create and maintain accounts, profiles, and sessions
- Build and update training programs and schedules
- Log workouts and calculate progress and recommendations
- Provide nutrition logging and targets where enabled
- Operate household membership, invitations, managed profiles, and delegated access
- Process subscriptions, trials, renewals, and cancellations
- Authenticate users and protect the Service against abuse and fraud
- Provide customer support and troubleshoot issues
- Improve reliability and understand feature usage through first-party events
- Comply with law and enforce our Terms
We do not use your information for cross-context behavioral advertising, and we do not sell personal information or consumer health data.
5. Fitness and Consumer Health Information
Unbound AF processes fitness, body, readiness, and nutrition information so the Service can generate programs, track performance, and (where enabled) support nutrition goals. This information may qualify as sensitive personal information or consumer health data under certain laws.
Unbound AF does not provide medical diagnosis or treatment. Metrics and targets are fitness/wellness estimates, not clinical measurements. For additional detail, see the Consumer Health Data Privacy Policy.
7. Payment Information
Paid plans are billed through Stripe on the web. Stripe collects and processes payment credentials. Unbound AF stores subscription and entitlement metadata needed to provide access; it does not store full payment card numbers or CVCs.
Google Play Billing and Apple App Store billing are not currently offered for Unbound AF.
8. Household Privacy
Being in a household does not automatically give other members access to an adult’s training or nutrition data. Access to another person’s fitness information requires ownership of that profile, a managed-profile relationship with an explicit manage grant, or a delegated Training/Nutrition permission you grant.
Household owners and admins can manage household operations (such as invites and managed profiles) without automatically viewing another adult’s private fitness data. You should understand what you grant when you share access, and you can revoke delegated grants in the product where available.
9. Children and Managed Profiles
Authenticated Unbound AF accounts are intended for adults. The Service may allow an adult household member to create a managed profile for someone in their care (for example, a teen or dependent) without a separate login for that managed profile.
We do not knowingly market Unbound AF as a child-directed service under COPPA. Nutrition Adaptive Intake currently requires a self-reported age of at least 13 years, and automatic adult energy targeting is limited for younger ages in product logic. We do not collect date of birth as a dedicated field.
If you believe we have collected information in a way that is inappropriate for a child, contact support@unboundaf.com.
10. Retention
We retain account, profile, training, nutrition, household, billing, support, and security-related information while your account is active and as needed to provide the Service, resolve disputes, enforce agreements, and meet legal and accounting obligations.
Unbound AF does not currently publish fixed automated deletion schedules for every data category. Backups and operational logs may persist for a limited period after changes. When you request deletion, we will process the request as described below, subject to legally required retention (for example, certain billing records).
11. Account and Data Deletion
Signed-in users may initiate self-service deletion of their Unbound AF account and associated personal data from our account deletion page. If you cannot access your account, you may contact support@unboundaf.com for support.
When deletion is scheduled, future subscription renewal is canceled. If paid or trial access remains, the deletion effective date is set to the end of that applicable access period; otherwise the request may become due immediately. You may cancel a scheduled deletion before processing begins, but canceling the deletion request does not restart subscription renewal. The automated deletion processor checks due requests every five minutes; retries or operational failures may make completion take longer.
If a household owner has another eligible account-holder in the household, the owner must select a successor before scheduling deletion. Ownership transfers when deletion becomes effective, but the departing owner's payment method and subscription do not transfer. If the departing owner is the household's sole account-holder, the household and managed profiles or data that exist only under it are removed as part of deletion. Other household members' personal accounts and data are not deleted merely because another member deletes their account.
We delete or de-identify personal data we control as part of the deletion process, except where information must be retained for legal, security, accounting, fraud-prevention, or billing reasons. Limited backups, operational logs, and de-identified lifecycle records may persist according to applicable retention requirements.
12. Security
We use reasonable administrative, technical, and organizational safeguards, including:
- HTTPS encryption in transit
- Supabase authentication for account access
- PostgreSQL Row Level Security and server-side authorization for tenant and profile access
- Capability-scoped access for delegated Training and Nutrition permissions
No method of transmission or storage is completely secure. We do not claim military-grade encryption, end-to-end encryption of all product data, or certification of Unbound AF itself under SOC 2 or HIPAA.
13. Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of personal information, and to appeal certain decisions. Unbound AF also voluntarily supports reasonable requests to access, correct, or delete personal information even where a specific statute may not apply.
California residents: we do not sell personal information or share it for cross-context behavioral advertising as those terms are commonly used under the CCPA/CPRA. You may still contact us to exercise available rights.
To exercise rights, email support@unboundaf.com or use the deletion request page. We may need to verify your identity before fulfilling a request. We will not discriminate against you for exercising privacy rights.
14. Health Breach Notification
Unbound AF is a consumer fitness application that stores identifiable fitness and related health-adjacent information. The FTC Health Breach Notification Rule may apply to certain non-HIPAA health apps. If we experience a breach of unsecured identifiable health information covered by applicable law, we will provide notifications as required.
15. International Users
The Service is operated for use in the United States. If you access it from elsewhere, you understand that information may be processed in the United States.
16. Changes to This Policy
We may update this Privacy Policy from time to time. We will revise the “Last updated” date and, when changes are material, take additional reasonable steps to notify you.
17. Contact
Privacy and support requests: support@unboundaf.com
Related pages: Terms of Service · Consumer Health Data Privacy Policy · Delete account request
