Privacy Policy
Effective date: August 29, 2026
1. Who we are
Byrna (“Byrna,” “we,” “us,” or “our”) is a fitness and self-improvement iOS application operated by Aiden August Lindan Buck. This Privacy Policy explains what information we collect, how we use it, how long we keep it, how it is stored, and the choices and rights you have.
Byrna is intended for users in the United States and is available only to users who are 18 years of age or older. We do not direct Byrna to, or design it for use by, anyone under 18, and we do not knowingly permit anyone under 18 to create an account.
If you have questions about this policy or your privacy, contact us at buckaiden40@gmail.com.
2. Summary of our approach
We built Byrna to keep the most sensitive information about you off our servers:
- Your exact date of birth, your in-app display name, and all of your health and fitness data (workouts, nutrition, sleep, bodyweight, and similar) are stored on your device and synced only to your own private iCloud account. We do not store this data on our servers.
- If you choose to use an AI feature, the inputs that feature needs are transmitted to our AI provider for processing (see Section 4.5). Our proxy does not store the content of these requests.
- Our servers otherwise hold only what is needed to run your account, verify eligibility, process subscriptions, operate optional social features you choose to use, and keep the service safe.
- We use analytics on our website and in the app to understand usage. Our website analytics includes a service that receives IP and device data (see Section 5).
- We do not sell your personal information or share it for cross-context behavioral advertising, and we do not use it for third-party ad targeting.
This summary is for convenience only; the full policy below controls.
3. Sign-in and authentication
Byrna uses Sign in with Apple as its only sign-in method. We do not offer password-based accounts and we never collect or store passwords.
When you sign in, Apple provides us with a stable, pseudonymous Apple identifier for your account; an email address, which may be a private Apple relay address you can turn off at any time in your Apple settings; and your name, only the first time you authorize Byrna.
Processing during onboarding. Sign in with Apple establishes an authentication session before you tell us your age. Because of this, a minimal authentication record (the Apple identifier and email above) is created at sign-in, before we know whether you are eligible to use Byrna. We do not create a Byrna user profile at this point. If you then indicate you are under 18, we deny access, delete that authentication record, and never create a profile (see Sections 6 and 9). If you confirm you are 18 or older, this information is used to create your account.
4. Information we collect
4.1 Account information
Your Apple identifier, email address, and (if provided) name, plus a subscription identifier used for billing (see Section 8).
4.2 Age information
During onboarding you enter your date of birth. Your exact date of birth is stored only on your device and is not sent to our servers. Our servers receive only your birth year and a coarse age category, which we use to confirm you are eligible to use Byrna (18 or older).
4.3 Health and fitness data you create in the app
Workouts, sets, exercises, program days, food and supplement logs, bodyweight, and sleep entries. This data is stored on your device and synced to your own private iCloud (CloudKit) account. We do not store it on our servers, except that when you choose to use an AI feature the relevant inputs are transmitted for processing (Section 4.5), and when you choose to share a social summary the limited items in Section 7 are stored.
4.4 Information collected automatically when you connect to our services
When the app communicates with our servers and infrastructure providers, those providers automatically receive standard technical information, including your IP address, device and operating-system type, app version, and request timestamps. We use this to route requests, secure the service, prevent abuse, and diagnose problems. We do not use it to build advertising profiles.
4.5 AI features
Byrna includes optional AI-powered features. When you use one, the inputs that feature needs are sent from your device to our AI provider (Anthropic) through our server proxy (hosted on Railway), which returns a response to you. What is sent depends on the feature:
- Plan generation: your training profile — goal, experience, available equipment, training days and session length, listed injuries, sport, and your age and sex. Your age is sent as a number, not your date of birth.
- AI Coach: to provide tailored coaching, this feature transmits fitness and health information, including your profile and name, listed injuries, sleep data, nutrition targets, your current program, and your recent logged training (including per-set exercise, weight, and reps).
- Meal analysis: the food photo or text description you submit.
Our proxy passes these inputs to Anthropic to generate your response and does not store the content of your AI requests or responses; it records only aggregate, non-content usage metrics such as token counts used for cost control. Under Anthropic’s commercial terms, your inputs and outputs are not used to train Anthropic’s models; Anthropic may retain them for a limited period (up to 30 days by default) for safety and legal purposes before deleting them. We do not use this data for advertising, and we do not sell or share it. Because using an AI feature transmits the inputs described above, that information leaves your device by design when you choose to use the feature.
4.6 Optional social feature data
If you use Byrna’s optional social features, we store on our servers: your chosen public handle; your friend relationships; blocks and reports you create (including any reason you choose to include in a report); and a shareable activity summary (such as your Byrna Score, streak, and recent training volume) that you choose to share. We do not store your email or underlying health details in these social records beyond what is listed here.
4.7 Marketing sign-ups (website)
If you enter your email address on our website (usebyrna.com) to join a waitlist or receive updates, we store that email address (via Resend) to send you those communications. Our website uses two analytics services, Cloudflare Web Analytics and HeyCatch, described in Section 5. You can unsubscribe at any time using the link in any such email, or by contacting us at buckaiden40@gmail.com. Website email sign-ups are separate from app accounts.
4.8 Analytics and diagnostics
See Section 5.
5. Analytics
Website. Our website (usebyrna.com) uses Cloudflare Web Analytics to count page views and see which pages people visit. It is cookieless: it sets no cookies, stores nothing on your device, does not fingerprint you, and does not build a profile of you or follow you across other websites. Measurement is derived from a single page-view request and reported only in aggregate. We use it to see whether the site is working and what people read — not to identify you.
Our website also uses HeyCatch, a product-analytics service, to understand how people move through the site and where they get stuck. HeyCatch records site visits and sessions, interaction events such as clicks, taps and form submissions (not the contents of anything you type), and the IP address and device information of visitors. This is more than the aggregate counting that Cloudflare Web Analytics does, and unlike that service it may store an identifier on your device in order to recognise a single browsing session. We use it to improve the site. We do not sell this information, and we do not use it to make decisions about you.
If you would rather not be measured by either service, most browsers offer tracking protection or content blocking that will prevent them from loading, and the site works normally without them.
App. We use TelemetryDeck to understand aggregate, anonymous usage of the app so we can improve it. TelemetryDeck is a privacy-focused analytics service: it does not store IP addresses, it uses a hashed anonymous identifier that cannot be traced back to you, and it records location only at the country level. Along with each event, the service receives standard technical metadata such as device type, operating-system version, app version, and coarse locale, tied to that anonymous identifier. The events we send contain only categorical information (which feature was used, counts, and fixed labels) — we do not include your email, handle, name, or any free text you enter. We use this to see which features are used and where problems occur, not to identify you or track you across other apps or services.
6. Age requirement
Byrna is for adults. It is not intended for or directed to anyone under 18, and we do not knowingly permit anyone under 18 to create an account. During onboarding we ask for your date of birth; if you indicate you are under 18, we deny access and delete the authentication record created at sign-in (see Section 9). If we later learn that a user is under 18, we will terminate the account and delete associated server-side information. We do not collect precise geolocation from any user.
7. Optional social features
Byrna offers optional social features. If you use them:
- Handle. You choose a public handle. In search, it is the only identifier shown.
- Handle search. Other users can find you by your exact handle. Search results show your handle only — not your name — unless and until you become connected friends.
- Friend relationships. You can send and accept friend requests. Friend connections are visible only to the two users involved, and users you accept as friends can see the display name on your profile.
- Shareable summary. You may share a limited activity summary with friends you choose. Friends never have access to your underlying health, workout, or other personal data.
- Blocking and reporting. You can block or report other users at any time, and we review reports to keep the service safe.
8. Subscriptions and billing
Byrna offers paid subscriptions processed through Apple’s in-app purchase system and managed via our subscriptions provider, RevenueCat. We receive a subscription identifier and your entitlement status. We do not receive or store your payment card or financial-account details — those are handled entirely by Apple. Your use of subscriptions is also subject to Apple’s terms.
9. Data retention and deletion
Your account. We retain your account information for as long as your account is active.
Account deletion. You can delete your account from within the app at any time. Deletion removes your Byrna account and the server-side data associated with it and revokes the Sign in with Apple authorization, except for limited records we retain for safety, security, or legal purposes — such as the pseudonymous audit records described in Section 10. Your on-device and iCloud data (including your exact date of birth, display name, and health and fitness data) lives in your own iCloud account and is under your control — deleting your Byrna account does not delete that data from your device or iCloud. You can remove it by deleting the app and, if you wish, removing Byrna data from your iCloud settings.
Denied and incomplete registrations. If you are denied access for being under 18, or you sign in but do not complete onboarding, we delete the authentication record created at sign-in. You may also contact us at buckaiden40@gmail.com to request deletion of any such record.
Compliance audit records. We keep a limited, append-only audit record of key account events (see Section 10). These records are retained for up to 24 months — a period tied to the resolution of safety disputes and App Store and legal look-back windows — are stored separately, and may persist after account deletion under a safety and legal retention basis. They reference a pseudonymous identifier (which is still personal information, not anonymous data) and do not contain your name, email, exact date of birth, or exact age.
10. Compliance audit records
We maintain a limited, append-only audit log of significant account events (for example: account creation, eligibility determination, friend requests, blocks, reports, and account deletion). These records reference a pseudonymous user identifier and, where relevant, only a coarse category or a fixed action label for a moderation event. They never contain your exact date of birth, exact age, email, Apple identifier, or name. We use these records solely to demonstrate that our safety and eligibility controls operate as intended and to meet our legal and safety obligations.
11. How your information is stored and protected
Your exact date of birth, your in-app display name, and all of your health, workout, nutrition, sleep, and bodyweight data remain on your device and in your own private iCloud (CloudKit) account; we do not store them on our servers. Server-side data (account information, birth year and age category, handle, and any social-feature data) is stored with our hosting provider, Supabase.
We use industry-standard technical and organizational measures to protect your information, including encryption of data in transit (TLS) and access controls limiting who can reach server-side data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and any regulators as required by applicable law.
12. How we use information
We use the information described above to: create and operate your account and provide the app’s features; confirm eligibility (18 or older); process subscriptions and manage entitlements; provide AI-powered features you choose to use (Section 4.5); enable optional social features you choose to use; keep the service safe, including handling blocks, reports, and abuse throttling; maintain a limited compliance audit record of key account events (Section 10); send you website communications you signed up for, and let you unsubscribe; and diagnose problems and improve the app.
13. How we share information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only with the service providers listed in Section 14, who process it on our behalf, and where required by law or to protect the rights and safety of our users and the public.
14. Service providers we use
- Apple — Sign in with Apple, in-app purchases, and iCloud/CloudKit storage.
- Supabase — server-side database and authentication.
- Railway — hosting for our server/proxy infrastructure, including the AI proxy.
- Anthropic — AI provider that powers optional AI features (Section 4.5).
- Cloudflare — content delivery, security, and hosting for our website, plus cookieless website analytics (Section 5).
- HeyCatch — product analytics for our website, including IP and device data (Section 5).
- RevenueCat — subscription management.
- Resend — delivery of website/marketing emails you sign up for.
- TelemetryDeck — privacy-focused analytics (Section 5).
15. Your rights and choices
You can delete your account in the app at any time, and you can unsubscribe from website emails using the link in any such email. As a matter of practice, we honor requests from any user to access, correct, or delete the personal information we hold about them. Depending on where you live, you may also have additional rights under your state’s privacy law, including rights to obtain a copy of your information or to opt out of certain processing. To exercise any of these, contact us at buckaiden40@gmail.com. We will not discriminate against you for exercising your rights.
16. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will post the updated version with a new effective date and, where appropriate, provide additional notice in the app. Your continued use of Byrna after an update means you accept the updated policy.
17. Governing law and contact
This Privacy Policy is governed by the laws of the State of Hawaii, United States, without regard to its conflict-of-laws rules.
Aiden August Lindan Buck — buckaiden40@gmail.com
Effective date: August 29, 2026