Plain-language policy

Privacy without the fine-print fog.

Benchpresso works locally without an account. If you choose an optional account, a photo-free private cloud copy and approved Gym Buddy features are available—without ads, analytics, tracking, public profiles, or a social feed.

Effective 20 July 2026 Benchpresso 1.0 Owner: Finn Jaeger

Overview

The short version: you do not need an account or Internet connection to track workouts. If you choose an account in Settings, Benchpresso sends a photo-free private copy for synchronization and approved Gym Buddy features. Exercise photos stay on your device. Optional Apple Health or Health Connect access is separate, off by default, and does not send data read from your health store to Benchpresso.

This policy explains how the Benchpresso app and this release website handle information. The app is a private, offline-first workout tracker operated by Finn Jaeger.

Information stored on your device

Depending on how you use the app, Benchpresso may store:

  • exercises or machines you create;
  • workout dates, times, durations, lifted weights, repetition counts, completion state, and body-weight measurements you add;
  • reusable workout presets;
  • app settings;
  • optional photos you choose or take for an exercise or machine; and
  • temporary background images used while composing a workout card and generated workout-card PNGs retained temporarily for sharing.

This information is stored in Benchpresso’s application storage on your device. Exercise photos are processed locally to create an app-managed copy.

Information processed by the optional service

If you do not create an account, the app does not send your workout database to Benchpresso. If you create one, the service processes your email, username, display name, password for the immediate authentication or reset request, stored password hash, verification and reset-token hashes/state, sessions, a photo-free private copy of workout records, settings, and body-weight measurements, buddy relationships, sharing choices, and private leaderboard totals. Limited request and security metadata such as IP address, request time, route, and request identifier is processed to deliver and protect the service.

Passwords are transmitted over HTTPS only for signup, login, password reset, or confirmed account deletion, processed for that authentication request, and never retained or logged in raw form. The service stores only an Argon2id hash needed to verify a later password. Reset links are single-use and expiring; a successful reset revokes existing sessions.

Cloudflare provides DNS, reverse proxy, and private object storage; Resend delivers verification email; and the operator’s VPS/database provider runs the API and PostgreSQL. Benchpresso has no analytics, advertising, tracking, crash-report upload, or remote-content SDK and does not access contacts, location, microphone, or advertising ID. Apple Health or Health Connect is accessed only after you enable a specific optional Health control described below.

Store disclosures are checked against the signed production app and its dependencies before release. If the app’s behavior changes, this policy and the relevant store disclosures will be updated before that change is released.

Camera and photo access

Camera and photo access are optional and begin only when you choose to add or change an exercise photo, or choose a workout-card background. Exercise images are normalized into Benchpresso’s app-local storage. A workout-card background is used to render the card and is not added to the exercise library. Selected images are not uploaded to a Benchpresso service.

Your operating system controls permission prompts and may offer limited photo access. You can use the workout tracker without adding photos.

Optional Apple Health and Health Connect access

Health integration is off by default and does not require an account. Settings offers one checklist with four choices: read body weight, write body weight, export finished workouts, and read daily steps. After you confirm the checklist, Benchpresso requests the newly selected access in one batch, never at startup. HealthKit belongs only to the iPhone app; the Apple Watch companion does not use it. Android provides the same limited behavior through Health Connect.

Body-weight and daily-step data read from the platform is queried for the current Stats view and is not copied into Benchpresso’s database, export, cloud copy, Gym Buddy data, leaderboard, workout card, logs, or server requests. If both sources have body weight on one date, the measurement you saved in Benchpresso is shown. Daily steps are read-only and are not turned into distance, calories, a workout, goal, streak, health advice, or shared statistic.

When an enabled write is used, Benchpresso commits the body weight or finished workout locally first and then tries to write a copy to Apple Health or Health Connect. A workout copy contains its truthful time and duration, not invented calories, distance, heart rate, routes, or detailed sets. Stable record identifiers make manual retry update the Benchpresso-owned sample rather than duplicate it. A failed platform write never removes the local record, and there is no background retry queue.

Turning a Health choice off stops future attempts from Benchpresso. It does not revoke the operating-system permission or delete data already written to the health store. Later workout edits are exported only after a manual action; deleting the local workout does not delete an external copy. Erase all Benchpresso data resets the four app choices but cannot delete external Health data.

Benchpresso does not currently connect to Strava. Apple Health does not relay workouts written by third-party apps to Strava, and this release processes no Strava OAuth token, account data, or activity.

Device backup

Your operating system may include eligible Benchpresso application data in its device backup or device-transfer features when those features are enabled.

On iPhone, eligible app data may be included in an iCloud or computer device backup. On Android, workout records and settings may be included in system cloud backup; the intended configuration excludes exercise photos from Android cloud backup and may include them in supported device-to-device transfer.

These services are provided and controlled by Apple, Google, the device manufacturer, or your chosen backup provider under their own terms and privacy policies. Device backup is not live synchronization provided by Benchpresso. The app owner cannot guarantee backup timing, retention, quota, or successful restoration.

Exporting and importing data

Full export

You can choose to create a portable Benchpresso export containing your records, including body-weight measurements, and optional exercise photos. Benchpresso opens the operating system’s document picker or share sheet so you can select a destination. That destination may receive and retain the file under its own privacy policy.

Benchpresso exports are not currently promised to be encrypted by the app. Store them somewhere you trust and protect them as you would other personal files.

When you import a full export, the app validates it locally. Version 1 import replaces the Benchpresso data on that device only after creating and verifying a local rollback copy. That rollback copy may remain in app cache for up to seven days. Settings lets you open the system share sheet to save the rollback somewhere you control; closing the share sheet does not guarantee an external copy was saved. Portable import does not itself send that file to Benchpresso; if you are signed in, later cloud-copy reconciliation may upload the resulting photo-free local records.

Single-preset document

You can separately share a small preset document containing only its name, ordered exercise names and types, and optional strength or cardio suggestions. It never includes workout history, photos, completion state, or internal IDs.

Preset import is an additive path, not a full-data replacement. Benchpresso strictly validates the bounded document locally, shows explicit create or reuse choices for exercise identities, never silently matches or revives an exercise by name, and atomically creates only the reviewed identities and one preset. It does not alter workouts, history, photos, settings, or existing presets.

App-cache preset share files are reclaimed after 24 hours. Erase all Benchpresso data removes them immediately.

Optional cloud copy and Gym Buddies

The Benchpresso cloud copy is a bounded whole-data copy, not an exercise-photo backup and not Apple iCloud or Google Drive sync. SQLite on your device remains the app’s working source. If both device and server changed, Benchpresso asks before replacing anything; an offline error leaves local tracking usable.

You can request a Gym Buddy by exact email, exact @username, or a short-lived QR or deep link. Every request needs recipient approval. For each accepted buddy, aggregate statistics, finished workout history, and presets are separate sharing choices that start off. Leaderboards include only you and accepted buddies currently sharing stats with you; body-weight measurements are never included. There is no public directory, global ranking, feed, messaging, or comments.

Your chosen username and display name are shown to the people involved in a pending buddy request and to accepted buddies, including eligible leaderboard participants. Your verified email address is used for account delivery and exact-address invitations but is not returned in buddy or leaderboard data.

A buddy can import an individual shared workout or preset as a new local copy. Turning sharing off blocks future access but cannot recall a copy already imported. Imported buddy history is excluded from the recipient’s aggregate Stats, leaderboards, recent-performance suggestions, and re-sharing as their performance.

For delivery and abuse prevention, the API necessarily processes source IP address, request time, method, a token-redacted route, duration, random request ID, and errors. The application log does not contain raw IP address, email address, bearer token, account ID, request body, workout content, or object key. The in-memory abuse key is a process-secret pseudonym and expires after at most one idle hour; rotating application logs are limited to three 10 MiB files. Cloudflare and the VPS provider may retain their own delivery and security records under their terms.

Data sharing and sale

Benchpresso does not sell personal data or share data for cross-context behavioral advertising. Optional service data is disclosed only to providers needed to operate it and to an approved buddy within the scopes you enable. The username/display-name visibility described above also applies while a buddy request is pending; the verified email address remains private.

Data may leave the app through operating-system backup or device-transfer behavior, when you deliberately choose a destination for a full export or single-preset document, when you deliberately share a generated workout-card image, when an enabled body-weight or workout write sends a copy to Apple Health or Health Connect, or through the optional private service described above.

Sharing a workout card

You can choose to render an image summarizing one finished workout. The card is generated on your device from that workout’s date, duration, aggregate metrics, and exercise names, using the fixed Benchpresso fallback or an optional background image you select.

Share image… uses the operating system’s share sheet and is the only workout-card sharing action. Benchpresso has no Meta/Instagram-specific handoff or posting API and cannot control what a receiving app retains after you choose it.

Only the generated PNG is handed off. The source background file, database, exercise photos, and portable export are not separately sent.

Retention and deletion

Benchpresso keeps app data on your device until you edit or delete records, erase all Benchpresso data, uninstall the app, or the operating system removes or restores application data.

Erase all Benchpresso data removes the app’s live database, app-managed photos, settings, generated workout-card cache, and temporary transfer files from that device and resets the app’s Health choices. It does not delete an optional account, cloud copy, operating-system Health permission, or sample/workout already written to Apple Health or Health Connect.

Delete account and cloud data is a separate signed-in, password-confirmed action. It revokes sessions and removes or schedules deletion of account metadata and private cloud objects while leaving this device’s SQLite records intact. Root-only operational database backups become eligible for cleanup after 14 full days and are normally removed by the next daily run, less than 16 days after creation. Host downtime or a failed cleanup can delay removal until recovery. Account deletion help is also available outside the app.

Neither action can remove copies you exported or shared, a buddy’s already imported copy, a receiving-app copy, an operating-system backup, or a copy written to Apple Health or Health Connect. Generated share PNGs are otherwise reclaimed from app cache after 24 hours. Uninstall and device-backup retention are controlled by your platform.

Deleting a used exercise from the library preserves its finished workout history and statistics. To remove those historical records, edit or delete the affected workouts, or erase all app data.

This website

The Benchpresso website code includes no analytics, tracking scripts, advertising, forms, cookies, remote fonts, or remotely loaded media. It does not run client-side JavaScript.

The hosting and network providers needed to deliver the site may necessarily process request information such as your IP address, browser headers, and security events under their own terms. Benchpresso does not use website delivery information for advertising or analytics. Website logs are separate from an optional app account and workout copy.

Security

Benchpresso uses the operating system’s sandbox and secure credential storage, HTTPS, Argon2id password hashing, hashed server session tokens, a non-public object bucket, and restricted service networks. No method can guarantee absolute security. Protect your device and export destinations.

Benchpresso does not claim end-to-end encryption from the service operator or separate app-level SQLite or export encryption.

Children’s privacy

Benchpresso is a general workout logging utility and is not directed to children. An optional account processes the information described above.

International use

The optional service runs on a European VPS. Its private R2 bucket was created with Cloudflare’s Western Europe (WEUR) location hint; a location hint is a placement preference, not a residency guarantee. Cloudflare, Resend, operating-system backup providers, and export or share destinations may process data in other locations under their own terms and lawful transfer mechanisms.

Changes to this policy

If Benchpresso adds behavior that changes how data is handled, the app owner will update this policy and relevant store disclosures before release of that change. The effective date at the top identifies the current version.

Contact

For privacy or support questions:

Finn Jaeger
Radenwisch 39
22457 Hamburg, Germany
finn@remoteroom.io