Privacy policy
Last updated September 13, 2026
Operator
APEX is operated by Jack Bloom, an individual doing business as APEX, Tequesta, Florida, United States. Contact: [email protected].
What we collect
Account: email, name, username, date of birth (to confirm you are 18+; never shown on Social, Squad, or profiles if those exist), and the sign-in method you pick (email/password now; Google/X only if later enabled).
Training log: workouts, sets, meals, weigh-ins, check-ins, custom lifts and foods, photos you attach, and program settings.
Optional: Oura and Strava readings you connect, files you import, and comments or cheers you post on sessions (when those features exist).
Device: theme and similar choices stored on this device so the app feels like you left it.
How we use it
To run APEX — save your log, build programs, show progress, and (where you opt in) let people you follow see workouts you chose to share.
We do not sell your training or health data. We do not use meal photos or body scans for ads or to train a model beyond returning text to you.
Payments
Monthly memberships are billed by Stripe: Basic $9.99, Elite $16.99, and Max $29.99. Plans auto-renew until you cancel. Cancel in Account → Plan (Stripe customer portal). Paid features stay through the period you already paid for. We receive email, plan, status, and last4/brand if Stripe sends them. We do not store full card numbers. See stripe.com/privacy. Charges appear as APEX / Jack B or APEX - APP.
Processors
Photo reading is sent to xAI (Grok) so the model can return text from the photo. Photos leave our servers for that request. xAI’s use is to return that text, not to advertise to you. Other processors: Vercel (hosting), Cloudflare (security/CDN), Better Auth (login), Google and X (optional sign-in if enabled), Stripe (payments), Google Fonts (type), AgentMail ([email protected]), Oura and Strava only if you connect them.
Health data
Workouts, meals, weigh-ins, body scans, check-ins, and wearable readings are sensitive. Followers (when social exists) see custom and programmed sessions you log — never bodyweight, body fat, meals, or check-ins unless a feature you turn on clearly says otherwise. Workout photos follow hide-photos settings when present.
Health Breach Notification
APEX is not a HIPAA covered entity. We still treat workouts, meals, weigh-ins, photos, and wearable readings as sensitive. If unsecured personal health records are acquired by an unauthorized person, we will notify affected users and, where the FTC Health Breach Notification Rule or state law requires it, regulators, on the timelines those rules set.
Children
You must be 18 to create an account or subscribe. We do not knowingly collect data from anyone under 13. If we learn we have, we will delete it. Guest tools that log health or photos should not be used by minors.
California (CPRA)
If you are a California resident you can ask for: (1) the categories of personal information we collected, (2) a copy of the personal information we have, (3) deletion, (4) correction, and (5) to opt out of sale or sharing. We do not sell or share personal information for cross-context behavioral advertising. We do not use sensitive health or photo data to advertise. We will not deny the service, charge a different price, or give a lesser experience because you exercised these rights, except as the law allows. To make a request: Account deletion and export in Account (when present), or email [email protected] from the address on the account. We will verify it is you. An authorized agent may submit a request with proof of authority. We will not discriminate for exercising these rights. Do Not Sell or Share: we do not sell or share, so there is no extra opt-out switch. If that ever changes, a Do Not Sell or Share link will go in the footer.
Wearables
Connecting Oura or Strava (when available) sends us the tokens those apps issue and the latest readings we request. Revoke access in APEX and in that app to stop the pull. We keep imported rows until you delete them or disconnect with remove-imported.
Retention and deletion
We keep your log while the account is open. Sign out does not wipe the server copy. Deleting data from a screen removes that row. Account deletion works from Account when present. Backups linger about 30 days. A copy of your data or a full deletion: Account, or email [email protected].
Cookies
Essential cookies for login and security, including Cloudflare. No ad pixels. Cookie policy: /cookies.
Security
We use standard account security (hashed passwords; provider OAuth if enabled). No log is perfectly safe. Do not store secrets in workout notes.
Your choices
Change username, hide photos, disconnect wearables, and delete data inside the app when those controls exist. You can browse as a guest without an account; creating one requires agreeing to this policy and being 18.
APEX does not claim HIPAA.
If you are in the EEA/UK we currently do not offer the service there on purpose. If that changes, we will add GDPR terms before we take those users.
Contact
[email protected] — display name APEX.