Privacy Policy
The policy that follows covers the Delta app, the Apple Watch app, this site and the trainer console. This box covers only what this website itself does, which is much less.
This site collects one thing: the email address you give us when you request early access. It is stored privately, used only to send your invite, and never shared or sold. The site sets no cookies and loads no third-party analytics or advertising scripts.
The interactive demo on the home page runs entirely in your browser. Nothing you do in it is recorded or transmitted.
Every email from Delta is written and sent by a person. Reply to any of them, the invite included, and ask for your address to be removed; it will be deleted.
Delta Privacy Policy
TMS Enterprises LLC | Effective Date: 2026-08-25
| Controller / operator | TMS Enterprises LLC |
| Scope | Delta iPhone app, Apple Watch app, website, and trainer console |
| Launch scope | United States |
| Privacy contact | privacy@deltafitness.app |
| General support | support@deltafitness.app |
1. Overview
This Privacy Policy explains how TMS Enterprises LLC (“TMS,” “Delta,” “we,” “us,” or “our”) collects, uses, stores, discloses, and otherwise processes personal information through the Delta iPhone application, Apple Watch companion application, website, trainer console, Coach, subscriptions, and related services.
Delta is designed to minimize sensitive server-side data. The full workout logbook, per-exercise workout detail, in-progress workout edits, and the health/body/readiness categories described below remain on the user’s device. Delta stores only the narrower server-side information needed for account, program/settings restoration, trainer-sharing, entitlement, and related service functions.
2. Information We Collect or Process
Account information
Delta’s server-side account information includes the athlete’s email address and display name. Athletes authenticate using email one-time codes. Trainers use separately provisioned email/password accounts. Age and optional sex are held on the athlete’s device rather than in Delta’s server-side account record; Delta is limited to users age 18 or older under the Terms.
Delta also stores limited account/program state used to operate the service and restore a user’s settings/program to a device, including program structure, settings, usage counts, and user-entered names for custom exercises and program days. These program/settings records are not used by trainer-facing server interfaces; trainer-facing functionality reads a separate structured record. Custom exercise names and program-day names may nevertheless be visible to a linked trainer as part of the training program.
Workout and training information
The athlete’s full workout logbook—including every set, weight, and repetition—is stored on the athlete’s device and is not stored on Delta’s servers. Per-exercise workout detail and in-progress workout edits are likewise device-only. Delta does not provide a server-side restore path for the full logbook. The user-initiated data export available in the app is the recovery mechanism for that local history.
Delta maintains a separate, narrower server-side trainer-facing session projection to support trainer visibility and related features. Those structured records contain date, exercise identifier, method, weight, and repetitions, and are not a copy of the full device logbook.
Body composition
Weight, body-fat percentage, skeletal muscle, lean mass, and related body-composition history are device-only and are not stored in Delta’s server database. If Coach is enabled, available body-composition information may be sent to the AI provider as disclosed in the Coach consent.
Readiness and physiological information
Raw and derived readiness/physiological data are device-only. This includes HealthKit-derived resting heart rate, heart-rate variability, respiratory rate, wrist temperature, sleep, as well as user-entered soreness, personal baselines, z-scores, dispersion/sample-count information, and readiness scores/bands. These data are not made available to trainers. If Coach is enabled, specified readiness context may be transmitted to the AI provider as described below.
Health notes and Coach history
Free-text health notes in the Coach profile are device-only. Coach conversation history and AI-generated post-workout insight text are also device-only. Health notes or other context may be transmitted to the AI provider when Coach is enabled, but Delta does not store those materials on its servers.
Website information
If you submit a website contact form, Delta may collect your name, email address, and free-text message. Please do not submit health or other sensitive information through the website contact form. Delta may also collect website/device/network information through analytics and advertising technologies described below.
3. Apple Health and Apple Watch
Delta requests HealthKit permissions only in response to user actions in health/readiness/workout features; it does not require HealthKit during general onboarding or to use Coach.
For Readiness, the physiological inputs Delta reads—resting heart rate, HRV (SDNN), respiratory rate, Apple sleeping wrist temperature, and sleep analysis—come through HealthKit, even where Apple Watch was the originating measurement device. The only non-HealthKit readiness input is the athlete’s optional 0–10 soreness rating.
Delta’s Apple Watch companion separately reads live workout heart rate during a workout for on-watch display/Apple Health workout handling. That workout heart rate is not sent through the Watch-to-phone payload and is not used in Readiness or Coach.
With permission, Delta may write completed workout records to Apple Health. Deleting a Delta account does not delete workouts already written to Apple Health. Users can manage Health permissions and data using Apple’s controls.
4. Coach and AI Processing
Coach is optional and requires separate affirmative consent before Delta sends covered personal or health-related information to a production AI provider. The consent identifies the provider and the categories of information that may be sent. Consent is versioned and recorded. If the production provider changes, Delta will require renewed consent before sending the covered data to the new provider.
Depending on what is available, Coach context may include recent training, progression, sessions, lifts, readiness information, body composition, age, optional sex, health notes, soreness, and HealthKit-derived resting heart rate, HRV, respiratory rate, wrist temperature, and sleep. Readiness context may include the actual value, a personal baseline/mean, and standardized deviation context used by the feature.
Coach supports both user-initiated conversations and optional automatic post-workout summaries. Users may disable automatic summaries without disabling Coach.
Anthropic is Delta’s production AI provider under Anthropic’s standard commercial API terms; Delta does not use a zero-retention configuration and has no custom retention agreement. Under Anthropic’s current commercial privacy documentation, standard API inputs and outputs are retained for up to 30 days. Content flagged for usage-policy violations may be retained for up to 2 years, and trust-and-safety classification scores may be retained for up to 7 years. These periods may also be subject to legal obligations and Anthropic’s applicable terms.
Under Anthropic’s current commercial/API position, customer API inputs and outputs are not used to train Anthropic’s generative models by default. Delta will not use identifiable or reasonably linkable athlete health/training/Coach data to train generalized AI models. Delta may use appropriately de-identified or aggregated data for internal model development as described below.
5. Trainer Sharing
Delta shares athlete training data with a trainer only after the athlete affirmatively accepts a trainer-specific disclosure naming that trainer. Only one trainer may be actively connected at a time.
A connected trainer may see the athlete’s name and full trainer-visible workout history, including workouts logged before the trainer relationship began and future workouts while connected. This may include sessions, exercises, sets, repetitions, weights, personal records, and athlete-authored custom exercise names or program-day names used in the training program. Those names are user-entered free text and may therefore contain text chosen by the athlete.
Trainers never receive through Delta the athlete’s body-composition information, HealthKit/readiness data, soreness, health notes, Coach conversations, account email, or phone number.
When a relationship ends, the trainer’s platform access ends and pending proposals are voided. The Trainer Agreement requires the trainer to stop using and, where applicable, delete copies under the trainer’s control except where legally required to retain them.
6. Product Analytics in the App
Delta’s app analytics are intentionally narrow. They may include screen views, bucketed durations, result counts, fixed-enumeration filters, pick sources, friction events, and feature usage. They do not include workout values, body composition, Coach content, health notes, or free text.
Delta does not attach an account identifier or device identifier to these app-analytics events. Events may be grouped by an identifier lasting one app launch. Delta stores these analytics in its own database and does not use a third-party app analytics service for them.
A technical capability to capture exercise-search text exists but is disabled. Delta will not enable collection of search text without a new privacy/product review and any required disclosure or consent.
7. Website Analytics and Advertising
The Delta website may use Google Analytics 4 and advertising technologies from Google Ads, Reddit Ads, and potentially Meta to measure site use, attribute campaigns, optimize advertising, and support targeted advertising where permitted.
Delta will provide cookie/privacy preferences for non-essential website analytics and advertising technologies where required and will honor Global Privacy Control and other legally required universal opt-out mechanisms where applicable.
Delta maintains a strict boundary between website advertising systems and Delta health/training/app data. Delta does not send workout history, HealthKit/body/readiness information, Coach activity/content, health notes, or trainer-access data to advertising platforms or use those data for targeted advertising.
Contact-form email addresses are used to respond to the inquiry and are not automatically added to marketing lists or used for promotional marketing unless the user separately opts in.
8. How We Use Information
provide, secure, support, and operate Delta;
authenticate users and maintain accounts;
provide user-initiated data export and recovery of locally held training data through that export;
provide workout, progression, program, readiness, and trainer functionality;
provide Coach when the athlete has affirmatively enabled it;
manage subscriptions, entitlements, and payments;
respond to support requests and troubleshoot problems;
measure product and website performance;
prevent fraud, misuse, and security incidents;
comply with law and establish, exercise, or defend legal claims; and
use appropriately de-identified or aggregated information for internal analytics, research, product improvement, model/algorithm development, aggregate publications, and substantiated aggregate marketing claims.
9. Health-Data Purpose Limitations
Delta uses HealthKit-derived data, body-composition data, readiness information, soreness, and health notes only to provide the health/fitness functionality requested by the user, including Coach when separately enabled, and for security/legal compliance where necessary.
Delta does not sell health/training data, use it for advertising or targeted advertising, provide it to data brokers, or use it to determine eligibility for insurance, employment, credit, housing, or similar decisions.
If Delta later proposes a materially new health-data use that requires consent, Delta will obtain the required new affirmative consent before beginning that processing.
10. De-Identified and Aggregated Information
Delta may create and use information that has been appropriately de-identified or aggregated so it is no longer reasonably linkable to an individual, subject to applicable law and safeguards against re-identification.
Delta may use such information for internal analytics, research, product improvement, development/training/evaluation of Delta algorithms or AI/ML models, aggregate publication, and substantiated aggregate marketing claims. Delta will not sell, license, or provide athlete-derived de-identified datasets to third parties as a commercial data product and will not attempt to re-identify data treated as de-identified.
11. Service Providers and Recipients
Delta may disclose information to service providers only as reasonably necessary for the service they provide and subject to applicable contractual/legal restrictions. Current or anticipated categories include Supabase for backend infrastructure, Anthropic for production Coach processing, Apple for App Store/HealthKit services, Stripe for permitted web payments, and website analytics/advertising vendors described above.
Delta’s minimum standard for providers handling identifiable health or other sensitive information is that they process the data only for authorized services, do not sell or use it for advertising, maintain appropriate security, impose appropriate subprocessor obligations, assist with incidents/deletion where applicable, and follow the agreed retention arrangement. AI providers must also have a documented no-training/default-no-training position consistent with Delta’s representations.
OpenAI has been used for limited internal testing. Before any production routing of user data to OpenAI or another provider, Delta will complete a provider-specific privacy/consent review and update disclosures as required.
12. No Sale of App/Health Data; Website Advertising Choices
Delta does not sell health, workout, Coach, trainer, or app-use data and does not use those data for cross-context behavioral advertising. Website advertising technologies may constitute “sale,” “sharing,” or targeted advertising under some state privacy laws even when no money is exchanged. Delta will provide applicable notices, consent mechanisms, and opt-outs for website advertising activity.
13. Data Retention
Delta uses a purpose-based retention framework. Active account, limited program/settings restoration data, and trainer-sharing records are retained while needed to provide the account/service. The full workout logbook, per-exercise workout detail, in-progress workout edits, body composition, readiness/physiological data, health notes, Coach conversations, and AI-generated summaries are device-only and have no Delta server-retention period.
Properly de-identified or aggregated information may be retained subject to applicable law and Delta’s anti-reidentification commitments.
14. Account Deletion
When an athlete confirms deletion, Delta deletes or de-links active identifiable server-side data under Delta’s control, including profile data, trainer-facing session records, trainer relationships, entitlements, consents, proposals/overrides, and other account-linked application data, subject to limited legal/security retention.
Local workout history is not automatically erased by account deletion. Delta will provide a separate local-data erasure control. Workouts previously written to Apple Health remain in Apple Health. Previously transmitted Coach data may remain with the AI provider for its applicable retention period.
Deleted data may persist temporarily in protected infrastructure backups until those backups expire. Such backup copies are not used operationally and, if restoration is required for disaster recovery, deletion obligations will be re-applied as appropriate.
Subscriptions controlled by Delta will be cancelled as part of account deletion. Where an Apple-managed subscription cannot be cancelled by Delta, the deletion flow will provide the appropriate Apple cancellation path. De-identified/aggregated information and narrow legal/support records may remain where permitted by law.
15. Data Rights and Requests
Depending on where you live, you may have rights to access, correct, delete, obtain a portable copy of, or opt out of certain processing of personal information. Submit requests to privacy@deltafitness.app or through authenticated in-product controls where available.
Delta will generally verify a request through the authenticated account or control of the account email rather than requiring government identification. Authorized-agent requests are supported where required by law, subject to verification of authority. A user may appeal a denied request by replying to the decision or contacting the same privacy address.
Delta intends to provide a machine-readable export including JSON and workout-history CSV. Some information may be withheld where permitted or required by law, such as another person’s data or security-sensitive information.
16. Consumer Health Data
Delta treats its nationwide U.S. privacy baseline as including the highest reasonably applicable consumer-health-data protections. The consolidated disclosures in this Policy are intended to address applicable consumer-health obligations, including requirements that may arise under Washington, Nevada, Connecticut, and other state laws.
Where a law requires separate consent, authorization, notice, or a specific state procedure that cannot be satisfied through this consolidated Policy and Delta’s feature-specific consents, Delta will implement the required state-specific mechanism.
17. Security and Health Breach Response
Delta uses administrative, technical, and organizational safeguards intended to protect personal information, including TLS in transit, provider encryption at rest, account-scoped access controls, and least-privilege practices. Delta does not promise that security incidents or data loss can never occur.
Delta treats the FTC Health Breach Notification Rule as applicable to the Service and maintains an incident-response process addressing unauthorized acquisitions or disclosures of identifiable health information and required notices to users, the FTC, regulators, or media. Public notice will be provided as required by applicable law rather than by an artificially fixed contractual deadline.
18. Government and Legal Requests
Delta may disclose information when reasonably necessary to comply with valid legal process or law, protect users or Delta from fraud/security threats, or establish, exercise, or defend legal claims. Delta will limit disclosures to what is legally required or reasonably necessary.
As an operational policy, Delta intends to notify affected users before disclosing their data in response to government or law-enforcement process unless legally prohibited or an emergency makes notice inappropriate.
19. Children
Delta is for users 18 and older. Delta does not knowingly provide accounts to or collect personal information from users under 18. If Delta learns that an account belongs to a minor, it may terminate the account and delete the associated information as appropriate.
20. United States and International Users
Delta is offered in the United States. Server infrastructure is maintained in a U.S. region, but Delta does not promise permanent U.S.-only data residency.
Delta is not currently offered as a service in the EU/EEA or United Kingdom. Before making the Delta service available there, TMS intends to complete a dedicated international privacy review. Incidental international website visitors may receive cookie/privacy controls as required.
21. Business Transactions
Personal information may be disclosed or transferred in connection with a merger, acquisition, financing, reorganization, sale of the Delta business/assets, or transfer to an affiliate or successor, subject to applicable law and appropriate notice if privacy practices materially change.
22. Changes to This Policy
Delta may update this Policy. Ordinary changes may be communicated by updating the effective date. Material changes receive conspicuous notice where appropriate. Changes involving a materially new health-data purpose or AI-provider disclosure that requires consent will not rely solely on a revised Policy; Delta will obtain any required new affirmative consent. Delta archives policy versions.
23. Contact
TMS Enterprises LLC 16192 Coastal Highway, Lewes, Delaware 19958, Sussex County Privacy and data-rights requests: privacy@deltafitness.app General support: support@deltafitness.app Legal notices: legal@deltafitness.app