Privacy Policy
Last updated: April 14, 2026
Overview
Muscle Man ("the app", "we", "us") is built by Divv Ventures and is operated by Divv Saxena. This Privacy Policy explains what data we collect, how we use it, and your rights around that data. We take your privacy seriously — we collect only what is necessary to make the app work.
Data We Collect
Account Information
When you sign in with Apple, we receive a unique Apple User ID and, optionally, your email address (which Apple may anonymise). We use this solely to identify your account and associate your workout data with it.
Workout Data
We store the workouts you log — exercise names, weights, reps, and dates. This data is stored in Supabase (a PostgreSQL database hosted on AWS in the US) and is protected by Row Level Security, meaning only you can access your own data.
Device & Usage Data
We do not collect analytics, crash reports, or device identifiers beyond what Apple's App Store provides to all developers (aggregate download counts, etc.). We do not use any third-party analytics SDKs.
How We Use Your Data
- ✓To store and display your workout history
- ✓To sync data across sessions and devices signed into the same Apple ID
- ✓To identify your account when you sign in
We do not sell your data. We do not share your data with advertisers. We do not use your data for any purpose beyond operating the app. We do not sell personal information as defined by the California Consumer Privacy Act (CCPA).
Third-Party Services
Supabase— We use Supabase to store your workout data. Supabase is hosted on AWS (US East region). You can review Supabase's privacy policy at supabase.com/privacy.
Apple Sign In — Authentication is handled entirely by Apple. We never see your Apple password. Apple's privacy policy applies to the sign-in process.
Offline Storage
When your device has no internet connection, unsynced workout data (sets you have logged) is temporarily stored locally on your device in an encrypted file. This data is automatically uploaded to our servers and deleted from local storage once a connection is restored. We do not access this local data for any purpose other than syncing it to your account.
Data Security
All data transmitted between the app and our servers is encrypted in transit using HTTPS/TLS. Your workout data is stored in a database protected by Row Level Security (RLS), which ensures that only your authenticated account can read or modify your data. No other user or third party can access your workout records.
Data Retention
Your data is retained as long as you have an account. If you delete your account from within the app (Settings → Delete Account), all your workout data is permanently deleted from our database immediately. This action cannot be undone.
Your Rights
- ✓Access: You can view all your workout data inside the app at any time.
- ✓Deletion: You can delete your account and all associated data from Settings → Delete Account.
- ✓Portability: Contact us if you'd like an export of your data.
- ✓Correction: You can edit or delete any logged set directly in the app.
Children's Privacy
Muscle Man is not directed at children under 13. We do not knowingly collect data from anyone under 13 years of age.
Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page will reflect any changes. Continued use of the app after changes means you accept the updated policy. For material changes, we will make reasonable efforts to notify you.
Terms of Service
This Privacy Policy is incorporated into and subject to our Terms of Service. By using the App, you agree to both documents.
Governing Law
This Privacy Policy is governed by the laws of India. Any disputes relating to privacy will be subject to the jurisdiction described in our Terms of Service.
Contact
Questions about this policy? Reach us at: hello@divvsaxena.com