CHEETAH
CHASE THE LIMIT

Cheetah Privacy Policy

Last updated: 2026-10-08

This Privacy Policy explains what information the Cheetah app ("Cheetah", "we", "us") collects, how we use it, and the choices you have. By using Cheetah you agree to this policy.

1. Information we collect

Account information. When you create an account we store your name, email address (or the identifier provided by Sign in with Apple or Google Sign-In), and your profile details. Your birthday is asked for at sign-up (or on first launch for older accounts). It is part of your profile, so it is stored with your account inside your encrypted synced profile (see "How information is stored and protected") and restored on every device you sign in on; it is used for heart-rate estimates and to check your age. Separately, our server records the date you turn 18, which is what the age rules below are enforced against. Gender, height, and weight are optional; if you enter them they are stored in the same encrypted synced profile.

Fitness content. The training plans, workout library and workout logs you create are stored with your account so they sync across your devices and come back if you reinstall the app or switch phones. A workout log holds what you recorded for that session: its name, date, distance, duration, notes, the exercises with their sets, reps, weight and distance, and — when available — that session's average and maximum heart rate, active calories and step count (see "Apple Health" below). Logs you made before this was introduced are uploaded once, the next time you open the app signed in.

Apple Health. If you connect Apple Health, we read workout sessions and vitals (heart rate, HRV, VO₂ max, respiratory rate, steps) so they appear automatically in the app. This data is used only to provide the app's features to you and is never used for advertising or marketing. The raw Health samples — your heart-rate readings over time, HRV, VO₂ max, resting heart rate, respiratory rate and the like — stay on your device and are not uploaded to our servers. What does leave your device, and only as part of your own account data: when you save a workout log, the per-session summary numbers stored on it (average and maximum heart rate, active calories, step count, distance and duration, any of which can come from Apple Health or your Apple Watch) are synced with that log, encrypted, so your history is restored on your other devices; and your single estimated maximum heart rate — one number, derived from your age and the average heart rates of workouts you've logged — is stored with your account so your training zones stay the same on every device you sign in on. If you turn on the optional "Activity" snapshot (see "Social features" below), the workouts it shows may include ones you imported from Apple Health, so their label, date, distance and duration can come from Apple Health (never their heart-rate, calorie, step or other Health values). Apple Health data is never sent to analytics or to our AI provider, never shown to other users beyond what's described for the Activity snapshot, and never sold or shared with third parties for any purpose.

On-device only. Your goals and weight history stay on your device and are not uploaded to our servers. (The one exception is the optional plan questionnaire at sign-up, described under "Usage analytics" below: which of its fixed choices you picked is recorded as a usage event.)

AI features (Anthropic). Cheetah's AI Coach and AI-powered imports use a third-party AI service: Anthropic, PBC, the maker of Claude. The first time you use one of these features, before anything is sent, the app shows a screen explaining what is sent and who receives it, and asks your permission. Nothing is sent to Anthropic unless you tap Allow. You can withdraw that permission at any time: open the menu on the Home tab, then Settings → AI Features and turn off "Allow cloud AI". From then on nothing is sent, and the app asks again before the next AI request. If your iPhone supports Apple Intelligence, many requests are handled entirely on your device and are not sent anywhere.

Exactly what is sent to Anthropic (only when you use one of these features and have allowed it):

Never sent to Anthropic: your name, email address, username, account or device identifiers, birthday or age, gender, height, weight, Apple Health data, heart-rate or other health values, workout logs, plans or library, location, and the original photos, videos or files. Requests go from the app to our server, which forwards them to Anthropic under our own account, so Anthropic does not receive your identity or your device's network address. Our server passes the content through without storing it; it records only how much AI usage your account has used, to enforce usage limits.

How Anthropic uses it. Anthropic processes this content only to produce the reply, workout or plan you asked for. Under Anthropic's commercial terms for API customers and its data processing agreement with us, Anthropic does not use this content to train its models, processes it only on our instructions, keeps it confidential and protects it with security measures that give it the same or equal protection described in this policy. Anthropic keeps request data only for a limited period, and longer only where needed to investigate a violation of its usage policies. Neither we nor Anthropic use AI content for advertising. See Anthropic's privacy policy.

AI response reports. If you report an AI response (for example as harmful, inaccurate, or offensive), we store the reported response, the message that produced it, the reason you selected and any detail you type, so our team can review it. Reports go to our server only, never to Anthropic, and are deleted when you delete your account. The photo, video, or spreadsheet file you import is processed on your device and deleted from it as soon as the import finishes or is cancelled. It is never uploaded to us or to anyone else, and we operate no file storage for user uploads.

AI safety check. Before a message is sent to the AI Coach, your device checks it for language indicating self-harm or an eating disorder. This check runs entirely on your device. If it matches, the message is not sent to our backend or to Anthropic at all — the app answers locally with crisis and professional-support resources. We record only an analytics event that a safety reply was shown (associated with your pseudonymous analytics identifier like any other event); we never record what you wrote or which words matched. The AI Coach is a training assistant, not a health or crisis service — see the Terms of Use.

Usage analytics & crash reports. We collect aggregated usage events (for example, "a workout was logged") through Firebase Analytics, and crash reports through Firebase Crashlytics, to understand how the app is used and to fix problems. Events carry only flags, counts and coarse categories — never your name, email, username, workout content, free text you type, or any health value. Alongside them we set a few coarse profile attributes: an age bracket (a range, never your birthday), whether you are Premium, your preferred weight and height units, whether you are signed in, and coarse usage ranges (for example how many workouts are in your library, as a range such as "6–20", and your library layout). We do not send your gender, height, weight or any body-metric band. If you answer the optional plan questionnaire when you create your account, we record which of its fixed choices you picked — for example "training for a race", "runner", "build muscle", "lose weight", "home" or "12 weeks" — and which ready-made plan it matched you to, so we can see which plans people want and improve them; never anything you type. When you are signed in, analytics are associated with a pseudonymous account identifier — a random ID, not your name or email — so one person using several devices is counted once; Firebase also uses an app-instance identifier to distinguish installs, and derives an approximate location (city and country) from the network address of each upload, which we use only for country-level usage reports. Crash reports contain technical crash data (device model, OS version, the code location of the crash) with web addresses stripped out. When you search for a username in Find Friends, we don't store your search, though our hosting provider's standard request logs briefly keep the request address (including the search text) without your account ID. Advertising storage and ad personalization are turned off in our analytics, we do not use the advertising identifier (IDFA), and this data is never used for advertising or to track you across other companies' apps or websites.

Social features. If you choose a username, it is public — any signed-in user can look it up. Your username, display name, and avatar choice (an illustrated icon you pick; we don't support photo uploads) are visible to other users when they search for you, view your profile, or see you in a followers/following list. Your follower and following counts are shown on your public profile; the identity of who follows you or who you follow is only ever shown to you, never to other users. Any workout you explicitly add to your "Public Workouts" catalog or feature in your "Top 5 Favorite Workouts" is public — visible to, and can be copied into their own library by, any signed-in user who views your profile or browses the Discover page. Your vitals, private workout library, logs, and plans stay private and are not made public by this feature, with one exception: if you turn on the optional "Activity" sharing toggle, a rolling snapshot of your current streak and your last 5 logged workouts is shown on your public profile until you turn the toggle back off. It is visible to any signed-in Cheetah user who views your profile, not only people you follow or who follow you. For each workout it includes the workout's label, date, a one-line summary, its distance and duration, and per-exercise details — exercise titles and their sets, reps, weight lifted, and distance. Distance and duration may come from a workout recorded in Apple Health. It never includes your notes, heart rate, calories, steps, or any other health data. We also store a notification record (e.g. "so-and-so followed you") when another user follows you or downloads one of your public workouts, which you can turn off in Settings; deleting your account removes your username, avatar, follows, public workouts, activity snapshot, and notification history from our servers. Public social features — choosing a username, following, publishing workouts, and Activity sharing — are not available to users under 18.

Avatar items, purchases & gifts. Avatar items you unlock, purchase, or receive are recorded with your account so they follow you across devices. Purchases are processed by Apple (we never see your payment details); we store only which items your account owns. If you gift an item to a follower, we record who sent the gift, and the recipient sees your username in their gift notification.

Blocking & reports. If you block another user, we store that block so it can be enforced (the blocked user is not told they were blocked). If you report a user or a workout, we store your report — the reporter, the reported account or workout, the reason you selected, and any detail you type — and review it. Reports are retained as a moderation record even after the reported account is deleted.

Share links. When you share a workout as a link, the app uploads a copy of that workout — its name and its exercises, including each exercise's details, target heart rate, distance, weight and any notes you wrote on it — to our servers and gives you a short link to it. Long links that carried the whole workout inside them were being cut off by messaging apps, which is why the copy is stored. Anyone who has the link can view that workout and add it to their own Cheetah library, with or without a Cheetah account, so only send it to people you want to see it. The link identifies the workout, not you: the page and the app show the shared workout only, never your name, username or account. Links are random and are not listed, searchable or shown on your profile. The copy is a snapshot of the workout at the moment you shared it — later edits to your workout don't change it (sharing the edited workout makes a new link), and sharing the same unchanged workout again reuses its existing link. The stored copy is encrypted at rest and is kept until you delete your account; we keep at most your 2,000 most recent links, removing the oldest beyond that. Links shared from older versions of the app carry the workout inside the link itself and are not stored on our servers. A shared workout never includes your workout logs, heart-rate history or any Apple Health data.

2. How we use information

We do not sell your personal information, and we do not use your data to track you across other companies' apps or websites.

3. How information is stored and protected

Account information and synced content — your plans, workout library, workout logs (including any heart-rate, calorie and step values on them) and profile (including your birthday) — and the workouts you share as links are encrypted in transit (TLS) and encrypted at rest on our servers (AES-256-GCM, with a key held on our servers). On-device data is protected by your device's security.

4. Third parties

5. Data retention & deletion

You can permanently delete your account at any time in the app: open the menu on the Home tab, then Settings → Account → Delete Account. This deletes your account, synced content (plans, workout library, workout logs and profile), username, avatar choice, follow relationships, featured and public workouts, workouts you shared as links (those links stop working), activity snapshot, block list, avatar item ownership records, AI-response reports you filed, and notification history from our servers; revokes Cheetah's Sign in with Apple tokens with Apple if you signed in with Apple; and erases the account's data stored on your device. Two things survive deletion: pseudonymous analytics events (keyed to the random account identifier described above, never your name or email, and never used for advertising); and abuse reports filed about your account, which are kept as a moderation record. Purchase and billing records are held by Apple under Apple's own policies; our own records of avatar-item purchases are kept for accounting with your account ID removed.

6. Children

You must be at least 13 years old to create a Cheetah account; if the birthday you enter shows you are younger, no account is created (and an existing account is deleted). Accounts of users under 18 cannot use public social features — choosing a username, following others, publishing workouts, or sharing Activity — though they can still browse and download public workouts. Your birthday is stored in your encrypted synced profile; the age rules are enforced against the date you turn 18, which our server records separately. Cheetah is not directed to children under 13, and we do not knowingly collect their data.

7. Your rights

Depending on your region, you may have rights to access, correct, or delete your personal data. Account deletion in the app fulfills the deletion right; for other requests, contact us.

8. Changes

We may update this policy; material changes will be reflected by the "Last updated" date above.

9. Contact

Questions? Email info@thearkcompany.co or visit our support page.

Home · Terms of Use · Support · © 2026 Cheetah