Privacy policy
Last updated October 8, 2026.
Information Rytiva processes
Rytiva processes account identifiers, your name and email when supplied by an authentication provider, provider-neutral sign-in links, Rytiva device identifiers, purchase and entitlement records, authored workout plans, workout interactions and completion history, notes attached to sets, and limited HealthKit workout summaries such as duration and heart-rate statistics. Rytiva does not request or upload your full HealthKit history, payment-card data, advertising identifier, precise location, contacts, microphone, or photo library.
How information is used
We use this information for app functionality: authenticating you, delivering workouts between an authorized assistant and your Apple devices, maintaining history, providing requested training summaries and product interactions, enforcing paid capabilities, preventing replay, and completing export and deletion requests. Rytiva does not sell personal information, use it for targeted advertising, or track you across other companies’ apps and sites.
Service providers
Apple processes Sign in with Apple, HealthKit, StoreKit, subscription activity, and App Attest device verification for supported TestFlight access. Cloudflare operates the Worker, D1 database, KV authorization store, OAuth service, restore facilities, and minimized operational diagnostics. When enabled, Supabase processes email authentication and may use Resend to deliver transactional authentication email. Supported third-party AI assistants process the content you send and the account-owned tool results you authorize Rytiva to share with them. MuscleWiki provides exercise catalog and optional reference media. Each provider also processes ordinary security and network metadata under its own terms.
Third-party AI assistant connections
Choosing a coach or sharing a setup prompt does not itself grant access to your Rytiva account. Native coaching handoffs share a short text request, not workout JSON or recorded health values; any text you add is also sent to your selected destination. Separately, connecting an assistant through MCP requires explicit approval on Rytiva’s authorization page before sign-in can complete the connection. The page identifies the requesting client by its registered name and callback origin and explains its access. Client names are supplied by their registrants, not verified endorsements by Rytiva.
An authorized connection can retrieve your saved workout plans, exercise prescriptions, schedule, completion history, logged reps, resistance, timings and set notes, and synced session summaries. Those summaries may contain duration, heart rate, heart-rate zones and energy when recorded; they do not contain your full Apple Health history. The connection can also create, modify and schedule workouts using the capabilities available to your account. Rytiva sends requested tool results to that assistant’s service for use in your conversation. The recipient may process or retain your requests and results under its own privacy policy and controls. Declining a connection does not prevent phone-only workout use.
Retention and security records
Active account records remain until account deletion or a shorter feature-specific lifecycle. Account-linked analytics, if production ingestion is separately enabled, age out after 30 days. OAuth authorization state lasts 10 minutes. A deletion retry proof and encrypted Apple cleanup credential last at most 24 hours, the deletion receipt lasts 30 days, and keyed erasure markers last 31 days. Those records contain no raw account ID, email, or provider subject and protect against an account reappearing during Cloudflare D1 Time Travel, which can retain database recovery points for up to 30 days. Custom diagnostics use a fixed field allowlist and are sampled once at the Cloudflare head at five percent; code does not apply a second sample. They omit identifiers, email, URLs, queries, headers, IP/geolocation/user-agent values, workout or purchase content, provider payloads, exact durations, and raw errors. Cloudflare may retain its platform records according to the applicable plan and legal obligations.
TestFlight access verification
On supported iOS 27 or later devices, Rytiva uses Apple App Attest to verify an eligible TestFlight installation. Rytiva stores an account-bound public device key, replay counter, build and access-lease metadata until account deletion. Challenge and retry records last at most 24 hours. Raw attestations and Apple receipts are not retained. Access leases last at most six hours; older devices use managed tester grants. Account export includes access-lease metadata but excludes device security keys and replay controls.
Exercise reference media
Exercise data and videos provided by MuscleWiki.com. For verified mapped exercises, Rytiva sends only the catalog’s provider exercise ID from the Worker and obtains a short-lived media-only stream URL. Playback then connects directly to MuscleWiki and discloses the selected media plus ordinary request and network metadata, but does not send your Rytiva account identifier, email, workout log, or HealthKit data. Rytiva keeps the provider key on the Worker, does not log the signed stream URL, and does not download, persist, proxy, re-host, or shared-cache video bytes. Playback uses only transient in-memory buffering.
Your choices
You can revoke a connected device or assistant, remove Health access in iOS Settings, export a versioned copy of account-owned data, and request account deletion in Rytiva. Export omits authentication secrets, OAuth tokens/private properties, Supabase password/session/token data, Apple signed payloads, and security HMACs. Deletion requires recent proof from each linked identity provider and succeeds only after Supabase, Apple, and assistant authorization cleanup succeeds or the provider confirms the record is already absent. Deleting Rytiva does not cancel an App Store subscription; manage that separately with Apple. Content copied to an external assistant remains subject to that service’s controls.
Contact
Email support@rytiva.com with privacy questions or deletion requests.