LEGAL
Privacy Policy
Last updated: August 6, 2026
Overview
Frontload is designed to keep your health data private by default. We do not run servers that store your personal data, and the developer has no ability to access what you log in the app.
Data Stored on Your Device
All health data you enter — your stack, protocols, injection logs, labs, nutrition, supplements, sleep, fitness, and profile — is stored on your device, not on any server we operate. Most of the time, nothing leaves your phone. A handful of features and services do require limited off-device communication; each is named below so you know exactly what is sent and when.
AI Coach
When you message the AI Coach, your message and a snapshot of your relevant health context (the data needed to answer your question) are sent to Anthropic’s API to generate a response. We do not log, store, or retain these messages on any server we control. Conversations are not used to train AI models under Anthropic’s current API terms. A per-install device identifier is included with each request so that rate limits can be enforced; this identifier is not tied to your name, email, or any other personal information.
Lab PDF Parsing & Photo Scanning
When you upload a lab PDF or scan a label or nutrition screenshot, the file is sent to Anthropic’s API for one-time extraction. The extracted data lands on your device. The original file is not retained on any server we control.
Knowledge Base Search
When you message the AI Coach, a short embedding of your query is generated by a third-party embedding service (Voyage AI) to find the most relevant entries from the curated knowledge base. The embedding service receives the text of your query only — not your full health context — and the result is used to route which reference entries are shown to the AI. No content is retained by the embedding service per its API terms.
Health Connect (Android)
On Android, the app can read selected data types from Google’s Health Connect — steps, distance, calories, heart rate, resting heart rate, heart rate variability, sleep stages, oxygen saturation, respiratory rate, weight, and basal metabolic rate. This data is read on demand and displayed in the app’s screens; it is also included in the AI Coach context only when you send a message that benefits from it. Health Connect data is not used for advertising or marketing, is never sold or shared with third parties for their own use, and only leaves your device through the AI Coach feature described above.
Subscription & Billing
If you subscribe to Frontload Pro, billing is handled by Apple’s App Store (on iOS) or Google Play Billing (on Android). Your subscription state — whether you are currently on a free trial, paid, or expired — is verified through RevenueCat, a third-party subscription management service. RevenueCat sees your platform subscription identifier, your current entitlement state, and the date your app last contacted it to check that state; it does not see your health data, your messages with the AI Coach, or anything you have logged in the app.
Feedback
If you submit feedback via the Send Feedback button, your message is delivered directly to the developer’s Workspace email inbox. Feedback may include the text you type, your email address (if provided), and any screenshots you attach. This data is used only to respond to your feedback and to fix the issue you’re reporting. It is not shared with third parties.
Crash Reporting
If the app crashes, anonymous crash data (the type of error, which file it occurred in, and the device’s OS version) is sent to Sentry to help us fix bugs. Crash reports do not contain your health data, your messages with the AI Coach, or anything you have logged — only technical details about what code path failed.
Anonymous first-run milestones
To find and fix where new users get stuck, we record a small, fixed set of anonymous milestones — for example, whether onboarding was completed, whether a first protocol was added, whether a first dose was logged, and whether the AI coach was opened. These are simple yes/no signals about reaching a step. They never include the contents of what you do — not the compounds or doses you log, not your labs, not anything you type to the coach. They’re tied only to the same anonymous per-install identifier described above (which resets if you reinstall), never linked to your name, email, or any personal information, never sold, and never shared with advertisers.
No third-party analytics
We use no third-party analytics or advertising SDKs — no Google Analytics, Firebase, Amplitude, or similar. The milestones above are our own minimal measurement. Apart from them and RevenueCat’s last-seen date (used only in aggregate, never to build a picture of an individual), we have no visibility into how you use the app.
No Advertising, No Data Sales
We do not run ads. We do not sell, share, or monetize your data in any form.
Data Deletion
You can delete your locally stored health data at any time by clearing the app’s data through your device settings, or by uninstalling the app. To request deletion of your subscription state held by RevenueCat, email feedback@stackeddd.app and we will request its removal. Crash reports held by Sentry expire automatically per its retention policy.
Children
This app is not intended for users under 18. We do not knowingly collect information from minors.
Changes to This Policy
We may update this policy as the app evolves. Material changes will be noted with an updated date at the top.
Contact
Questions about privacy? Email feedback@stackeddd.app or use the Send Feedback button in the app.