Privacy Policy

Last updated: July 25, 2026

NEPSYN ("we", "our", "us") is a fitness tracking application and public website. This Privacy Policy explains how we collect, use, and protect information when you use our app or website.

1. Information We Collect

We collect the following types of information:

Most information is linked to your account because NEPSYN is an authenticated service. We do not sell this information, use it for advertising, collect an advertising ID, or track you across apps or websites owned by other companies.

2. How We Use Your Information

3. AI Features

Our AI coaching features use Anthropic's Claude API to process your requests. When you use AI features — including chat, program generation, exercise suggestions, or photo analysis — relevant context from your profile and workout history is sent to Anthropic for processing. Under Anthropic's standard commercial API policy, API inputs and outputs are deleted from its backend within 30 days, subject to its stated safety, legal, and contractual exceptions. Anthropic states that commercial API inputs and outputs are not used to train its models unless the customer explicitly opts in.

NEPSYN stores your AI chat messages and coaching memory with your account so the trainer can continue the conversation across sessions. You can delete saved AI chat history from the AI Trainer's clear-history control, and account deletion removes the associated AI chat history and coaching memory.

Automated features and scores. NEPSYN uses automated processing to generate AI coaching suggestions and to compute informational scores and estimates (such as recovery, strength, and TDEE/calorie figures) from the data you enter. These outputs are informational and are not medical advice, not a diagnosis, and not a substitute for a qualified professional. We do not use automated processing to make decisions that produce legal or similarly significant effects about you, and we do not use your data for automated advertising profiling. You remain in control: AI guidance and generated programs are suggestions you choose whether to follow.

4. Data Sharing

We do not sell your personal information. We do not display ads. We share data only in these limited circumstances:

5. Data Storage & Security

Your data is stored on secure servers hosted by Railway. All data is encrypted in transit using HTTPS/TLS. Passwords are hashed using bcrypt and are never stored in plain text. We implement industry-standard security measures to protect your information.

5-A. Cookies & Tracking Technologies

Our tracking is deliberately minimal. We do not use advertising cookies, do not collect advertising identifiers, and do not track you across other companies' apps or websites.

Website cookie. When you visit www.nepsyn.com, we set one first-party, pseudonymous cookie so we can count page visits and understand how prospective testers move through the site. It contains only a random identifier — not your name, email, or any account or health data:

Website analytics (cookieless). Our marketing pages also send anonymous page-view and page-leave events to PostHog using memory-only (cookieless) persistence, with element autocapture and session replay disabled. These events carry page path, referrer, coarse browser/device type, and a one-way keyed hash of your IP address — never account, health, message, or AI-prompt content.

In-app. The mobile app does not use browser cookies. It stores an authentication token on your device to keep you signed in, and — only if you enable notifications — an Expo push token.

Your choices. You can block or delete the nepsyn_vid cookie through your browser settings; the website will still work. We do not set the nepsyn_vid cookie on this Privacy Policy, the Terms of Service, or the account-deletion pages. If our hosting edge identifies your request as coming from the European Economic Area or United Kingdom, we do not set the nepsyn_vid cookie. A Do-Not-Track or Global Privacy Control signal received on the website is honored as an opt-out of the non-essential website analytics cookie.

6. Data Retention

We retain your data for as long as your account is active. Metadata-only authenticated API response aggregates and hashed release-adoption records are automatically deleted after 30 days. The public website visitor cookie lasts up to 180 days. Website page-view database records remain until they are operationally deleted, and coarse CTA events can remain in Railway service logs until those logs expire or are deleted under Railway's configured retention controls; NEPSYN does not currently promise a shorter automatic deletion interval for those anonymous website records. Saved AI chat history remains available until you clear it or delete your account. When you delete your account, NEPSYN immediately deletes or de-identifies associated records in its active database, coordinates supported account deletion with RevenueCat and Apple, and queues stored progress-photo cleanup. Limited provider records and backups may remain under provider retention controls, including up to 30 days where applicable. Support and bug-report copies stored in GitHub may be retained separately as needed to investigate, secure, and document the reported issue; the GitHub issue excludes reporter identity but can retain links to screenshots hosted on our servers. Service providers may retain limited records under their own legal, security, fraud-prevention, and backup requirements.

7. Your Rights

You have the right to:

California residents have additional rights described in Section 7-A, and Washington, Nevada, and Connecticut residents have consumer-health-data rights described in Section 7-B.

7-A. Your California Privacy Rights (CCPA/CPRA)

This section applies to California residents and supplements the rest of this Policy. In the preceding 12 months we have collected the following categories of personal information. We have not sold or "shared" (as CCPA/CPRA defines those terms) any personal information, and we do not do so.

Sensitive personal information. We use sensitive personal information only to provide and secure the service you request and for the purposes listed above — never to infer characteristics for advertising. Because we use it solely for these permitted purposes, the CPRA right to limit its use does not create additional restrictions, but you may still exercise the deletion and other rights below.

Your rights. You may: (1) know/access the personal information we hold about you; (2) delete it; (3) correct inaccurate information; (4) obtain a portable copy of your workout and nutrition data; and (5) opt out of sale/sharing — although we do not sell or share personal information, so there is nothing to opt out of.

How to exercise. Submit requests through in-app Account Settings or by emailing support@nepsyn.com with the subject "California Privacy Request." We verify requests against your account credentials and respond within the statutory timeframe. You may use an authorized agent.

Global Privacy Control. We treat a valid GPC browser signal on our website as a request to opt out of any sale/sharing (again, none occurs) and of non-essential website analytics.

Non-discrimination. We will not deny service, charge different prices, or provide a different quality of service because you exercised any of these rights.

Other US state privacy rights. If you reside in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another state with a comprehensive privacy law, you have similar rights to access, correct, delete, and obtain a portable copy of your personal data, and to opt out of targeted advertising, sale, and certain profiling (we do not engage in targeted advertising, sale, or decisions producing legal or similarly significant effects). Health data is treated as sensitive and processed only to provide the service. Contact support@nepsyn.com. If we deny a request, you may appeal by replying to our decision; if an appeal is denied you may contact your state Attorney General.

7-B. Consumer Health Data (Washington, Nevada & Connecticut Residents)

Some data you enter is "consumer health data" under Washington's My Health My Data Act, Nevada SB370, and Connecticut law. This section is our Consumer Health Data Privacy Policy and controls for that data.

What we collect. Body weight and measurements (including body-fat %), workout and exercise activity, nutrition intake, supplement and medication tracking, habit data, progress photos, and health-related facts you provide to or that our AI infers from your inputs (such as injuries or physical constraints).

Why, and with whom. We collect this data only to provide the fitness-tracking, progress-metric, and AI-coaching features you request. We share it only with the processors that make those features work — principally Anthropic (to generate AI coaching from the workout/profile context you submit) — and with hosting infrastructure. We do not sell consumer health data, and we do not require separate authorization to sell it because we never sell it.

Your rights. You may access your consumer health data, obtain a list of the third parties with which we have shared it, withdraw consent, and delete it (in-app account deletion removes it from our active systems). To exercise these rights, email support@nepsyn.com with the subject "Health Data Request."

Consent. We ask for your affirmative consent to the collection and processing of consumer health data when you create your account; that consent is recorded with a timestamp and the version of the terms you accepted, and you can withdraw it at any time by deleting the data or your account.

No geofencing. We do not use geofencing around any health-care facility.

8. Account Deletion

You can delete your account at any time from within the app (Profile → Account Settings → Delete Account) or by contacting us. When you delete your account, the following account data is permanently removed from our systems: workout history and logs, nutrition logs and meal data, body weight and measurement history, progress photos, habits and habit history, programs and templates, AI chat history and coaching memory, gym profiles, social connections and feed activity, push-token registration, badges and achievements, and profile information. The separate support and provider retention described above may still apply.

This action cannot be undone. Active subscriptions should be cancelled through the Google Play Store or Apple App Store before deleting your account.

9. Children's Privacy

NEPSYN is intended only for people who are at least 18 years old. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected data from someone under 18, we will delete it promptly.

9-A. Geographic Scope

NEPSYN is directed to and intended for residents of the United States. We do not offer the service to, or target, individuals in the European Economic Area or United Kingdom, and we do not knowingly process their personal data. If you are located in the EEA or UK, please do not use the app or submit personal data.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes through the app or by email. Continued use of the app after changes constitutes acceptance of the updated policy.

11. Contact Us

If you have questions about this Privacy Policy or your data, contact us at:

support@nepsyn.com