Cadence

Privacy Policy

Cadence holds detailed information about your body, your training, your food, and your health. This page describes what is actually collected, where it goes, and what you can do about it.

Last updated: September 8, 2026

Draft, pending legal review

This document was drafted from the behaviour of the Cadence codebase and has not been reviewed by a lawyer. It is published so the app has a working policy in place. Sections marked [TODO:] still need real information filled in. Treat it as a description of current practice, not as finished legal advice.

The short version

  • Cadence stores health and fitness data you enter, plus Apple Health data you explicitly connect.
  • We do not sell your data, and we do not use it for advertising or ad targeting. That includes all Apple Health data.
  • The AI coach sends a summary of your current state, plus whatever data the tools it runs read on your behalf, to Anthropic, the company behind Claude. This is the most privacy-sensitive part of the product and section 5 explains it in detail.
  • Meal photos and label photos are sent to Anthropic for analysis and are not stored. Only the numbers extracted from them are kept.
  • Usage analytics are stored against a salted hash of your user ID, not your account. No IP address, no advertising identifier, no third-party analytics or tracking pixels.
  • There is no self-serve export or delete button yet. Email support@cadencemode.com and we will handle it. See section 10.

1. Who we are

Cadence is operated by [TODO: legal entity name], a sole proprietorship based in Saskatoon, Saskatchewan, Canada. For privacy questions, contact support@cadencemode.com.

There is no dedicated data protection officer. Privacy requests are handled directly by the operator.

  • Mailing address: [TODO: contact address in Saskatoon, SK]

2. What data Cadence collects

Everything below is data Cadence actually stores today. It is grouped by what it is, not by which screen it comes from.

Account and profile

  • Email address and password. Passwords are handled by our authentication provider and are stored hashed, never in plain text and never visible to us.
  • Name, and an approval status controlling whether you can sign in.
  • Birth date, biological sex, height, and weight unit preference. Birth date and sex are used to calculate your basal metabolic rate.
  • Timezone, training experience level, fitness and training goals, available equipment, and coaching style and personality preferences.
  • Dietary restrictions, food allergies, and food dislikes. Allergies are treated as a hard constraint on meal suggestions.
  • A list of current injuries or physical limitations, for example "lower back" or "right shoulder".
  • If you ask for access before you have an account, we keep the name, email address, and reason you submitted on the request form until the request is resolved.

Body measurements

  • Body weight entries with timestamps and optional notes.
  • Body fat percentage and weight targets recorded as part of a nutrition phase (a cut, bulk, or maintenance block), including its starting, target, and ending values and any notes you write about the outcome.
  • Bodyweight and height recorded during a fitness assessment.

Daily check-ins

  • Mood, energy level, sleep hours, sleep quality, stress level, and water intake, per day.
  • Free-text notes you add to a check-in.

Workout and training data

  • Completed workouts and cardio sessions, including duration, heart rate and calorie figures where available, and your notes.
  • Every logged set: exercise, weight, reps, and per-set notes, including live sets recorded during a session on the phone or watch.
  • Your programs and training blocks, including mesocycle position, periodization settings, deload history, and adaptations made to your plan.
  • Custom exercises, custom workout templates, template notes, and drafts created with the program builder.
  • Benchmark and fitness test results, movement screen scores including per-body-segment findings, and goals with progress.
  • Gym profiles, including the gym name and an optional address you enter, plus available barbells and plates.

Physio and pain

  • Physio and mobility sessions, including pain level before and after and free-text notes.
  • A safety flag raised when the symptom screen detects something that warrants caution. Only the resulting caution level and a message reference are stored. The specific symptoms you selected are not saved.

Nutrition and meals

  • Meal plans and the individual meals in them, including which meals you marked as eaten and when, plus ad-hoc food you log outside a plan.
  • Calorie and macronutrient targets, current nutrition phase, portion presets, and per-recipe adjustments you save.
  • Grocery lists, custom grocery items, freezer inventory, and meal-prep sessions.
  • A taste profile: cuisines you prefer, proteins you eat and avoid, cooking effort on weeknights and weekends, budget level, how many people you cook for, and free-text notes about your routine and your likes and dislikes.
  • Recipes you create or save, and which recipes you favourite.

Medication data (GLP-1)

This is the most sensitive category Cadence holds.

If you use the GLP-1 support feature, Cadence stores the medication name (for example Ozempic, Wegovy, Mounjaro), your current dose, when therapy started, your last dose escalation, your dosing day and time, your therapy goal, and any side-effect symptoms you report.

With your explicit consent, it also stores four medical history answers used purely for safety screening: whether you are pregnant or trying to conceive, a history of medullary thyroid cancer or MEN2, a history of pancreatitis, and a history of an eating disorder. The database physically refuses to store these answers unless a consent timestamp is present.

You can delete your GLP-1 data on its own, without deleting the rest of your account, from the app.

Chat and AI conversation history

  • Your chat sessions and every message in them, including what you wrote, what the coach replied, and a record of the tools the coach ran during the conversation.
  • AI memories: short facts the model extracts from your conversations so it does not forget them, categorised as injury, preference, struggle, breakthrough, coaching style, or life context. These are written by the model in its own words and are visible to it on later turns.

Data Cadence derives about you

  • Hidden wellness levels: a score from 1 to 5 for each wellness domain, used to calibrate coaching and filter content. These are deliberately not shown to you in the app, and a log of every change to them is kept with the reason and the signals behind it.
  • Statistical correlations between your behaviour and your outcomes (for example a relationship between sleep and next-day performance), including the strength, significance, lag, and a plain-language summary.
  • Readiness and recovery estimates derived from your recent health metrics, plus adaptations made to your plan and the reasons for them.
  • Questions the app asks you when it is uncertain, and the answers you give.

Usage analytics

Cadence records page views, feature use, and button clicks in its own database. Each event stores the event type, an event name, the page path, a small metadata object, and a timestamp. It is associated with a salted SHA-256 hash of your user ID, truncated to 16 characters, not with your account row. Your raw user ID, your IP address, and your user agent are not written to that table. If the hashing secret is missing in production, analytics writes are skipped entirely rather than falling back to a weaker identifier.

There is no third-party analytics service, no advertising SDK, and no tracking pixel in Cadence.

Notifications and device diagnostics

  • If you enable web push notifications, we store the push endpoint URL issued by your browser vendor, the public encryption keys for that subscription, the platform, and your browser user agent string.
  • A log of notifications sent to you, so the same one is not sent twice.
  • Watch diagnostics: when the Apple Watch app fails to sync or authenticate, the phone records the failure type, a technical detail, the app version and build, and timestamps, linked to your user ID. The watch cannot report its own failures, so this is how those bugs become visible.

Technical data

  • Your IP address is read from the request in order to rate-limit public endpoints. It is not written to any table.
  • Standard web server logs may temporarily contain request metadata.
  • Cadence uses cookies only for authentication and session management. There are no advertising or tracking cookies.

Administrative records

Actions taken by an administrator are written to an audit log, including a snapshot of the record before and after the change. Where an administrator edits user-related content, that snapshot can contain personal data.

A small amount of internal conversation logging exists for the operator's own developer account and one test account, and is restricted to those two addresses in code. It does not apply to other users.

3. Apple Health and HealthKit

Apple Health data is never used for advertising.

Cadence does not use Apple Health data, or data derived from it, for advertising, marketing, ad targeting, or any use-based data mining. It is not sold, rented, or shared with data brokers, and it is not disclosed to third parties except the infrastructure and AI providers listed in section 6, which process it only to deliver features you are using.

Connecting Apple Health is optional and off by default. Nothing is read until you turn it on and grant permission through iOS's own Health permission sheet, and you can revoke it at any time in the Health app under Sharing, without uninstalling Cadence.

What the iPhone app reads

The iPhone app requests read-only access to exactly 17 HealthKit types. It never writes to Apple Health.

  • Resting heart rate
  • Heart rate variability (SDNN)
  • Respiratory rate
  • Walking heart rate average
  • Cardio recovery (one-minute heart rate recovery)
  • VO2 max
  • Sleeping wrist temperature
  • Step count
  • Active energy burned
  • Exercise minutes
  • Walking speed
  • Walking step length
  • Walking asymmetry percentage
  • Walking double support percentage
  • Walking steadiness
  • Sleep analysis (REM, deep, core, awake, and time in bed)
  • Stand hours

Why each of those is read

Heart rate, heart rate variability, respiratory rate, sleeping wrist temperature, and sleep stages feed the recovery and readiness estimate that adjusts how hard the app asks you to train on a given day. Steps, active energy, exercise minutes, and stand hours give a picture of overall daily activity so training load is not counted in isolation. VO2 max and cardio recovery track cardiovascular fitness over time. The walking metrics (speed, step length, asymmetry, double support, steadiness) are gait quality signals used for movement and mobility work. Nothing here is used for any other purpose.

Data from Oura, Whoop, and other devices

Cadence reads from Apple Health, not from any device maker's service. If a third-party ring or strap writes heart rate variability, resting heart rate, respiratory rate, or sleep stages into Apple Health, Cadence will read those values the same way it reads Watch-recorded ones. We have no account with those companies, no API connection to them, and no ability to reach data they do not put into Apple Health.

What the Apple Watch app writes

The Apple Watch app does write to Apple Health, and only this: the workout itself, its active energy burned, and its walking or running distance. That is what gives you Activity ring credit for a workout recorded in Cadence. It reads workout-time metrics such as heart rate and distance while a session is running.

Where it goes

Health readings are summarised into one row per day and stored in your account in our database. The sync runs when you open the app, at most once every 30 minutes, and looks back over a rolling window of recent days. Health data is not sent to any advertising network, data broker, or analytics service. It is included in the context sent to our AI provider when you use an AI feature, as described next.

4. How your data is used

  • To run the features you are using: prescribing workouts, generating and adjusting meal plans, tracking progress, and calculating recovery, readiness, and nutrition targets.
  • To personalise coaching, including adjusting tone, difficulty, and content to your recorded level and preferences.
  • To send notifications and reminders you have enabled.
  • To keep the service secure and working: rate limiting, abuse prevention, debugging, and diagnosing sync failures.
  • To understand which features are used, in aggregate, using the pseudonymous analytics described above.
  • To communicate with you about your account, including invitations, approvals, and password resets.

Your data is not used to train AI models. See the next section.

Under Canadian law our basis for processing is your consent, given when you create an account and, for Apple Health, when you grant permission. If the GDPR applies to you, we rely on contract (providing the service you asked for), consent (for health data and for optional integrations), and legitimate interests (security and keeping the service working).

5. What is sent to our AI provider

Read this section if you read nothing else.

Cadence's AI coach runs on Claude, operated by Anthropic PBC. To answer you usefully it is given a substantial amount of your data, and it can also read and write more of it while it works.

Sent on every AI chat turn

Every message you send to the coach is transmitted to Anthropic along with a context block assembled from your account. That block contains:

  • Your profile basics: goals, experience level, equipment, dietary restrictions, allergies, injuries, and coaching style.
  • Your current state: today's date and timezone, your next scheduled session, sessions logged this week, your last workout and how long ago it was, your last check-in, your current weight and its recent trend, active goals and their progress, daily macro targets, your nutrition phase, your training phase and deload status, weekly training volume, and which muscle groups are over- or undertrained.
  • Your recent Apple Health summary and the recovery and readiness estimate derived from it.
  • Your hidden wellness levels and current wellness focus.
  • Up to 15 stored AI memories about you.
  • Your GLP-1 medication context and its safety guardrails, if you use that feature.
  • Statistical correlations found in your data, and any adaptation made to your plan today.
  • The recent history of the conversation you are in.
  • Nutrition context (current meal plan, recipes, phase) when the conversation is about food.

The coach can read and change your data

The coach has 79 tools available to it. Roughly half read your data and half write to it. Which tools are offered depends on what you are asking about, and results of any tool it runs are sent back to Anthropic as part of the same conversation.

Read tools can pull your workout, cardio, and physio history, live workout sessions, per-exercise progression and personal records, benchmark results, meal plans and recipes, grocery lists and freezer inventory, weight history, check-ins, goals, correlations, wellness levels, saved memories, earned cards, and your Apple Health metrics, sleep detail, and recovery status.

Write tools can start, log, edit, and finish workouts, add, remove, and swap exercises in a session, log cardio and physio sessions with pain levels, add to and remove from your meal plan, mark meals eaten, generate a week of meals, log food and weight, record a daily check-in, set and update goals, change your wellness focus, level, and coaching style, and create, update, or delete the memories it keeps about you.

In other words, asking the coach a question can change records in your account. Review what it does.

Photos and file uploads

When you photograph a meal or a nutrition label, or attach an image or PDF to a chat or to the program builder, the file is sent to Anthropic to be read. Cadence does not store the file. There is no image storage in the product at all. Only the text or numbers extracted from it are saved, for example the estimated foods and macros for a meal. Meal photo analysis is limited to 25 analyses per day per account.

Other AI features

The same provider is used for recipe generation, weekly meal plan selection, nutrition estimation, taste-profile interviews, exercise substitution, daily and post-workout insights, live coaching cues on the watch, and the background job that extracts memories from your chat history. Each sends only the context relevant to that task.

One separate AI service, Google Gemini, is used by an internal administrative tool that extracts exercise information from public YouTube videos to build the exercise library. It receives no user data.

What Anthropic does with it

Cadence calls Anthropic through its commercial API. [TODO: Confirm and link the specific Anthropic commercial terms and data retention policy in force for your API account, including their stated position on not training on API inputs] We do not consent to your data being used to train models, and we do not do so ourselves.

If you do not want this

AI features are the core of Cadence, so there is no way to use the coach without your context being sent. You can avoid it by not using the chat, photo analysis, or AI meal planning features. Logging, tracking, and viewing your own data do not send anything to Anthropic.

6. Who we share data with

We do not sell personal information, and we do not share it for cross-context behavioural advertising. Data goes to the following service providers only so they can help operate Cadence.

Supabase

Authentication and the Postgres database. Everything Cadence stores lives here, including all of section 2. Supabase infrastructure runs on Amazon Web Services. [TODO: Confirm the Supabase project region and state where the data is physically stored]

Anthropic

The AI provider behind the coach and every AI feature. Receives what section 5 describes.

Hosting

The Cadence web application runs on a dedicated server we manage. [TODO: hosting provider name and the country the server is located in]

Email

Account emails (invitations, password resets, email confirmations) are sent through our authentication provider's email delivery. [TODO: If a separate SMTP or email service is configured for production, name it here]

Push notification services

If you enable notifications, the push message is delivered through the push service operated by your browser or device vendor (for example Apple, Google, or Mozilla). Message content is encrypted in transit to your device, but those services necessarily see that a message was sent to your subscription.

Apple

Distribution of the iOS app is through Apple's App Store and TestFlight, and the Apple Watch app interacts with HealthKit on your device. Apple's own privacy policy governs what Apple collects through those channels.

Error monitoring

Sentry is integrated in the codebase but is not currently active: no Sentry connection string is configured in production, so no error reports leave the server. If it is switched on later, it is configured not to attach IP addresses, cookies, or request headers, and its session replay is set to mask all text and block all media. This page will be updated before that changes.

Other disclosures

  • We may disclose data where required by law, or to protect the rights, safety, or property of users or the public.
  • If the service is ever sold or transferred, your data may transfer with it. You would be notified before that happens and would be able to delete your account first.

7. Where your data is stored

Cadence is operated from Canada, but its infrastructure and AI providers process data outside Canada, primarily in the United States. By using Cadence you understand that your information, including health information, is transferred to and processed in other countries, where it may be accessible to courts, law enforcement, and national security authorities under the laws of those countries.

[TODO: Confirm the exact processing locations for the database, hosting, and AI provider so this section can name countries instead of generalising]

8. How your data is protected

Described plainly, without claiming certifications we do not have. Cadence has no SOC 2 audit, no ISO certification, and is not a HIPAA covered entity. HIPAA does not apply to a consumer wellness app of this kind, and we do not claim it does.

  • Traffic to Cadence is encrypted in transit with HTTPS. Data at rest is encrypted by our database provider.
  • Application queries run as your signed-in user, and every table in the database has PostgreSQL row-level securityenabled, with policies scoping rows to their owner. This means a query that forgets to filter by user still cannot return another user's rows.
  • A smaller set of server-side jobs (background crons, analytics writes, administrative functions) uses a privileged key that bypasses row-level security. Those paths are server-only and the key is never exposed to a browser or to the mobile app.
  • Accounts require approval before they can be used, which is enforced in the application and in database policy.
  • Sensitive endpoints are rate-limited, security headers and a content security policy are set on every response, and user input passed to the AI is screened for prompt injection.
  • The GLP-1 medical history fields cannot physically be written without a stored consent timestamp. That is a database constraint, not just an application check.

No system is completely secure. Cadence is built and maintained by one person, and we cannot guarantee that your data will never be accessed improperly. Use a unique password, and tell us at support@cadencemode.com if you suspect your account has been compromised.

9. How long data is kept

Cadence keeps your data for as long as your account exists. There is no automatic deletion schedule and no automated purge of old records. Training history, check-ins, chat transcripts, and health metrics accumulate indefinitely, because the product is built around long-range trends in them.

When an account is deleted, records linked to it are removed from the database by cascading deletion. Backups taken by our database provider may retain copies for a limited period afterwards. Analytics events, which carry only a salted hash and no account link, and administrative audit records are retained for operational integrity.

Access requests from people who never became users are kept until the request is resolved, and can be deleted on request.

10. Your rights and how to use them

Being straight with you about what exists today.

Cadence does notcurrently have a self-serve "download my data" or "delete my account" button. Those requests are handled manually by the operator. Building self-serve export and deletion is on the roadmap, and this page will be updated when they ship.

You have the right to ask for a copy of the personal information we hold about you, to have inaccurate information corrected, to have your data deleted, to withdraw consent, and to complain to a regulator.

What you can do in the app right now

  • View and edit most of your profile, preferences, goals, and logged data directly in Settings and throughout the app.
  • Delete individual records: workouts, meals, weight entries, check-ins, custom programs, and recipes.
  • Delete your GLP-1 medication data on its own, without affecting the rest of your account.
  • Disconnect Apple Health at any time from the iOS Health app under Sharing. Data already synced stays until you ask for it to be deleted.
  • Turn notifications off, which removes your push subscription.

What requires an email

Email support@cadencemode.com from the address on your account for any of the following, and we will confirm and act on it within 30 days, the window Canadian privacy law requires:

  • A full export of the data held about you.
  • Deletion of your account and the data linked to it.
  • Correction of information you cannot edit yourself.
  • Changing the email address on your account.
  • Deletion of an access request you submitted.

If you are in Canada

Cadence is subject to the Personal Information Protection and Electronic Documents Act (PIPEDA). If you are not satisfied with how we handle a request, you can complain to the Office of the Privacy Commissioner of Canada.

If you are in the EEA or UK

Where the GDPR or UK GDPR applies, you also have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your local supervisory authority. Health data is a special category of personal data and we process it on the basis of your explicit consent, which you can withdraw at any time by contacting us or deleting your account. We have not appointed an EU or UK representative. [TODO: Take advice on whether an Article 27 representative is required for your user base]

If you are in California

Under the CCPA and CPRA you have the right to know what personal information is collected and how it is used, to request deletion and correction, and to not be discriminated against for exercising those rights. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. California residents can use the same email address above. Health data collected here may constitute sensitive personal information, and we use it only to provide the service you requested.

11. Children

Cadence is not intended for children and we do not knowingly collect personal information from anyone under [TODO: minimum age, keep consistent with the Terms of Service] years of age. If you believe a child has created an account, contact support@cadencemode.com and we will delete it.

12. Cadence is not medical care

Cadence is a general wellness and fitness product. It is not a medical device, it does not diagnose or treat any condition, and the health information it stores is not a medical record held by a healthcare provider. Nothing in the app is medical advice. See the Terms of Service for the full health disclaimer.

13. Changes to this policy

We will update this page when what Cadence does with data changes. The "last updated" date at the top always reflects the current version. For changes that materially affect how your health data is used or shared, we will notify you in the app or by email before they take effect.

14. Contact

Privacy questions, data requests, and complaints go to support@cadencemode.com. We read every one.

  • Legal entity: [TODO: legal entity name]
  • Mailing address: [TODO: contact address in Saskatoon, SK]
  • Email: support@cadencemode.com