Features How It Works About Pricing Corporate Log In
Your Data. Your Rules.

Privacy Built In.

Your inner work is sacred. Some things should never leave your phone — and in Edwin Strong, they don't. Here is exactly what we collect, what we don't, and who can see what.

Last updated April 9, 2026

The Privacy Pledge

Stays On Your Phone.
Always.

Private by design, not by promise. The following data is stored only on your device and never uploaded to any server — not ours, not Edwin's, not Apple's. If you delete the app, this data is gone with it. If our database were compromised tomorrow, none of this would be in it.

01What We Collect

For your account to work across devices and for Edwin to personalize your programming, these pieces of information are saved to our secure servers:

02How We Use It

We will never sell, rent, or share your personal information with third parties for marketing purposes. Period.

03Security

Cloud data is stored in Supabase with industry-standard encryption — TLS in transit, AES-256 at rest. We use Row Level Security policies at the database level, which means one user physically cannot query another user's data, even if they tried. Each row is locked at the database to the user who created it.

Form check videos are stored in encrypted storage accessible only to Edwin Grant for coaching feedback.

04Who Can See What

You
Everything you've created. Full access, any time, forever.
Edwin Grant
(Your Coach)
Only your onboarding answers, subscription status, form check videos you submitted, and progress photos you shared. Never your journal. Never your gratitude. Never your workout history or HRV.
Admin Team
Only enough information to provide you support — subscription status and account info. Never your private reflections or health data.
Other Members
Only what you explicitly post in the Community.
Third Parties
Nothing. Ever. We don't sell data. We don't rent data. We don't share data with advertisers.

05Camera & Gym Scanner

The AI Gym Scanner uses your device camera to detect gym equipment and personalize your workout. Images are processed to identify equipment types and then discarded. We do not store, share, or retain camera images after processing.

06Third-Party Services

07Your Rights

At any time you can:

To exercise any of these rights, email hello@edwinstrong.com and we'll handle it within 30 days.

08Children's Privacy

Edwin Strong is not intended for users under 16 years of age. We do not knowingly collect data from children.

09Changes to This Policy

We may update this policy from time to time. When we do, we'll update the "Last updated" date at the top and — for significant changes — notify you through the app or via email.

10International Data Transfers

Edwin Strong is based in the United States. If you access the Service from outside the US, your information is transferred to and processed in the US.

For EU, UK, EEA, and Swiss users: We rely on the European Commission's Standard Contractual Clauses (SCCs) — Module 4 (controller-to-processor) — and supplementary technical measures (encryption in transit and at rest, Row Level Security at the database) to ensure adequate protections for data transferred outside the EEA.

Your health metrics — HRV, sleep, recovery, workout logs — remain on your device by architecture and are NOT transferred to our servers. Only operational data (account info, billing, support) is processed in the US.

11Subprocessors

A current list of our third-party data processors, the data they handle, their region, and the transfer mechanism in place is maintained at edwinstrong.com/subprocessors and updated within 30 days of any material change, per GDPR Art. 28.

EU/UK members may subscribe to subprocessor change notifications by emailing privacy@edwinstrong.com with subject line "Subprocessor list — subscribe."

12Contact & EU/UK Data Protection

Privacy Team: privacy@edwinstrong.com · response within 30 days

For EU, UK, EEA, and Swiss users:

13EU/UK Rights & Legal Basis

Legal Basis for Processing (GDPR Art. 6):

Your GDPR / UK DPA Rights:

To exercise any of these rights, email dpo@edwinstrong.com with your request. We respond within 30 days. You also retain the right to lodge a complaint with your local data protection authority.

QUESTIONS ABOUT YOUR DATA?

Email us any time. We respond within 24 hours.

Contact Edwin Strong