OnlySets Privacy Policy
Last updated: August 20, 2026
OnlySets is operated by a sole trader. This Privacy Policy explains how we collect, use, store, share, and delete personal information when you use the OnlySets iOS app and its related services.
1. Information We Collect
Account and authentication information
When you create or use an account, we process your email address, display name, and account identifier. You may sign up or sign in with email and password, Sign in with Apple, or Google Sign-In. Authentication and password-credential handling are provided by Supabase Auth. OnlySets does not receive or have access to your plaintext password.
If you use Sign in with Apple, Apple may provide a private relay email address instead of your personal email address. We use that address in the same way as any other account email address. We also process the authentication information needed to maintain your signed-in session.
Profile, fitness, and preferences information
OnlySets processes the information you choose to provide or record in the app, including your display name; age and, where provided, date-of-birth information; sex or gender selection; height; current, starting, and target weight; weight and height units; timezone and language; fitness goals; activity and training level; workout type and frequency; and related app preferences, such as reminder and notification settings.
We also process fitness and activity information you create or use in OnlySets, including workout plans, scheduled workouts, exercises, sets, workout sessions, weight logs, water logs, meals, calorie and macronutrient information, and nutrition, water, and step targets. We may use this information to calculate targets, recommendations, progress or performance scores, streaks, recovery or progress summaries, and similar fitness features. These outputs are not medical diagnoses or medical advice.
Meal photos
You may optionally capture or attach a photo to a meal entry. Meal photos are stored in OnlySets’ Supabase Storage infrastructure and associated with the relevant meal record. The current implementation does not use AI or computer vision to analyse meal photos.
Device, notifications, and diagnostic information
If you grant notification permission, the app receives an Apple Push Notification service (APNs) device token. We send the token to our backend and store it so that we can deliver remote notifications through Apple APNs. We may also process your notification preferences and notification-delivery status. OnlySets does not collect or store your device name as part of notification registration.
OnlySets also offers local, on-device reminders. These are distinct from remote push notifications and can be managed in the app or in your device settings.
To maintain and improve the app, we process crash, error, and diagnostic information, such as technical error details, app version, device/app context, and limited internal identifiers used for troubleshooting. Diagnostic events may be associated with your pseudonymous OnlySets/Supabase account UUID. We use this information for stability, security, debugging, and service improvement—not advertising or marketing profiling.
2. Apple Health and HealthKit
With your permission, OnlySets requests read-only access to Apple Health step-count data. We use step-count information to display your steps and support step-related goals, progress, and fitness features. For premium subscribers, up to seven days of historical step-count data may be synced from Apple Health to OnlySets servers and stored for step-history, analytics, and trend functionality.
OnlySets does not write data to HealthKit and does not request HealthKit workout access. It does not read heart rate, sleep, medical records, or other HealthKit categories not described above. You can change or revoke HealthKit permission in iOS settings at any time.
3. How We Use Information
We use the information described above to:
- create, authenticate, and secure your account;
- provide and personalise the app’s workout, fitness, nutrition, progress, reminder, and subscription features;
- operate, maintain, troubleshoot, and improve OnlySets;
- deliver remote notifications when you have enabled them;
- process and verify subscription entitlements; and
- comply with applicable legal obligations and respond to lawful requests.
4. Subscriptions and Payments
OnlySets offers subscriptions through Apple In-App Purchases and StoreKit. Apple processes payment and billing information; OnlySets does not collect or store your card or other payment credentials.
We use RevenueCat to manage subscriptions and entitlements. Where applicable, RevenueCat associates subscription information with the OnlySets/Supabase account identifier. We process subscription, purchase, renewal, entitlement, and related status information so that we can provide subscription features. Our backend also processes RevenueCat webhook events to keep subscription status up to date.
Deleting an OnlySets account does not itself cancel an active Apple App Store subscription. You must manage or cancel Apple billing through Apple.
5. Service Providers
We use service providers that process information on our behalf to operate OnlySets:
- Supabase provides authentication, database, and storage infrastructure.
- Render hosts our backend and API services.
- Our production Redis provider supports caching and rate limiting where needed to operate the service.
- Sentry provides crash, error, and diagnostic monitoring.
- RevenueCat provides subscription and entitlement management.
- Apple provides Sign in with Apple, APNs, StoreKit/In-App Purchases, and HealthKit platform functionality when you choose to use those features.
- Google provides Google Sign-In when you choose that sign-in method.
These providers process information only as necessary to provide their services to us or as otherwise permitted by their own applicable terms and privacy documentation. We do not state specific provider retention periods or hosting regions where they have not been established.
Sentry is configured to limit diagnostic data: default PII collection is disabled, and request details, extras, modules, and most tags are removed before events are sent. Diagnostic reporting is not used for advertising or marketing profiling.
6. How We Store and Protect Information
We use access controls, authentication, encrypted connections, and other reasonable technical and organisational measures designed to protect information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Signed-in session credentials are stored on your device using iOS security mechanisms and are cleared when you log out. Some non-sensitive preferences and cached app state may remain on your device until you clear them or uninstall the app.
7. Data Retention, Deletion, and Export
Retention
We generally retain account and associated information while your account exists, and retain individual information until you delete it where the app offers that option. We do not apply an automatic inactive-account deletion period. Service providers may retain information in their own legitimate backups or systems in accordance with their practices; we do not promise a specific retention period where one has not been verified.
In-app deletion and data clearing
You can delete your account in the app’s account settings. You can also clear certain data, including workout history, calorie logs, and weight logs, without deleting your account.
When you delete your OnlySets account, we delete the account’s application and database data, including associated profile and fitness records, and delete the related Supabase Auth account. We also remove associated meal photos from storage as part of the account-deletion process. Notification tokens associated with the profile lifecycle are removed when the account is deleted. We delete the associated RevenueCat customer and remove the backend subscription projection as part of this process. As noted above, this does not cancel an active Apple App Store subscription.
Deletion from active application systems does not necessarily mean immediate deletion from every provider backup, system log, or record that a provider must retain for legitimate purposes. We do not make a specific promise about third-party backup or legal-retention periods.
Data export
OnlySets supports exporting workout, calorie, and weight data in machine-readable JSON and CSV formats. You can request help with other privacy or export requests using the contact details below.
8. Children’s Privacy and Age Requirement
OnlySets is intended for people aged 13 and older and is not a Kids Category app. The onboarding flow prevents a person who provides an age below 13 from completing onboarding. Because authentication can occur before that age gate, we do not make an absolute claim that no information can ever be processed during an attempted under-13 signup. If you believe that a child under 13 has provided information to OnlySets, please contact us so we can review the request.
9. Advertising, Tracking, and Sale of Information
OnlySets does not display third-party advertising, sell personal information, use the IDFA for advertising, perform cross-app or cross-site advertising tracking, or build marketing audiences from fitness information. We do not use your fitness information for advertising or marketing profiling.
10. Your Privacy Rights and Contact Us
Depending on where you live and applicable law, you may have rights to request access to, correction of, deletion of, restriction of, or portability of your personal information, and to object to certain processing. We will consider and respond to requests as required by applicable law. You may also have the right to complain to the relevant data-protection authority.
For privacy questions, data export requests, or requests about your information, contact us at onlygymcompany@gmail.com.