We collect only what the app needs to coach you: your name, date of birth, email, motion data from your device, and any photos you choose to upload. Your photos are private to your account — no other user can see them, and we do not publish, sell, or share them for advertising. We do not sell your personal information. You can export or delete your data at any time from the app or by emailing support@wisionapp.com.
This Privacy Policy explains how Pitch Labs LLC ("WISION", "we", "us") collects, uses, shares, and protects personal information when you use the WISION mobile application, website, and related services (together, the "Service"). It applies to all users worldwide, with additional region-specific terms in sections 12–15.
1. Information we collect
1.1 Information you give us
| Data | Why we need it | Required? |
|---|---|---|
| Name | To personalize your account, coaching messages, and communications. | Required |
| Date of birth | To confirm you meet our minimum age, and because age materially affects safe training load, recovery, and heart-rate guidance. | Required |
| Email address | Account creation, sign-in, security alerts, and service notices. | Required |
| Training profile | Goals, split, days per week, session length, target timeline, and optional metrics such as height, weight, or experience level, used to build and adapt your plan. | Optional |
| Photos | To generate your private progress projection and track visible change over time. See section 2. | Optional |
| Support messages | To answer your questions and investigate issues. | Optional |
1.2 Information collected automatically
- Motion and activity data from your device's accelerometer, gyroscope, pedometer, and activity-recognition APIs — steps, movement patterns, workout detection, and rep or set estimation. See section 3.
- Device and technical data — device model, operating system version, app version, language, time zone, crash logs, and diagnostic identifiers.
- Usage data — screens viewed, features used, workouts started and completed, and session timestamps.
- Approximate location derived from your IP address, used for security, fraud prevention, and regional content. We do not collect precise GPS location unless you explicitly enable a feature that requires it.
1.3 Information from third parties
- App stores (Apple App Store, Google Play) — purchase and subscription status. We never receive your full payment card details.
- Sign-in providers — if you use Sign in with Apple or Google, we receive your name and email (or a relay address) as permitted by that provider.
- Health platforms — if you connect Apple Health or Google Fit, we receive only the specific categories you authorize, and you may revoke access at any time in your device settings.
2. Your photos
Photos are the most sensitive thing you can share with us, so we hold them to a higher standard.
- Private to you. Photos you upload are visible only within your own account. They are never shown to other users, never made public, and never used in marketing, on our website, or in app store listings.
- Encrypted. Photos are encrypted in transit (TLS) and at rest, and stored separately from your profile data under access controls.
- Limited human access. Our staff do not browse user photos. Access is restricted to a small number of authorized personnel and only where strictly necessary — for example, to investigate a specific abuse report or a technical fault you have reported — and every access is logged.
- Not used to train models by default. We do not use your photos to train or improve our AI models unless you give separate, explicit, opt-in consent, which you may withdraw at any time.
- Deletable immediately. You can delete any photo from within the app. Deleted photos are removed from active systems promptly and purged from encrypted backups within [30–90] days.
- Not sold or disclosed for advertising. Ever.
If a photo you upload includes your face, that image may be treated as biometric or sensitive information under laws such as the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, and Washington state law. We do not perform facial recognition and we do not create a faceprint, face-geometry scan, or other biometric identifier from your photos. Our analysis estimates body composition and proportions only. Where any processing would qualify as biometric under applicable law, we will obtain your separate written consent first and publish our retention and destruction schedule.
3. Motion and health data
With your permission, WISION reads motion and activity data from your device to detect workouts, estimate effort and volume, and adapt your plan. On iOS this uses the Motion & Fitness permission; on Android it uses the Physical Activity permission. You can revoke this at any time in your device settings — the app will keep working, but automatic workout tracking will stop.
Motion data, training history, body metrics, and photos may constitute health-related data under laws including the EU/UK GDPR (special category data), the California Consumer Privacy Act (sensitive personal information), and the Washington My Health My Data Act. We process this data only to deliver the Service to you, and we ask for your explicit consent where the law requires it.
WISION is a consumer fitness product, not a healthcare provider, health plan, or clearinghouse. We are not a HIPAA covered entity or business associate, and the data you give us is not protected health information under HIPAA. It is protected by this policy and by the consumer privacy laws described below.
4. AI projections and automated processing
WISION uses automated systems, including machine learning models, to generate training plans and to render a visual projection of potential future progress. These outputs are estimates, not predictions or guarantees, and they are not medical advice or a diagnosis. Results depend on genetics, adherence, nutrition, sleep, health status, and factors outside our control.
Automated processing here does not produce legal or similarly significant effects about you. Where you are in the EEA or UK, you have the right to request human review of any decision that does — contact us and a person will look at it.
We use aggregated and de-identified data to improve our models. Your photos are excluded from model training unless you opt in separately.
5. How we use your data
- Create and secure your account, and authenticate you.
- Build, adapt, and deliver your personalized training plan.
- Generate your private progress projections and track change over time.
- Detect and log workouts from motion data.
- Provide customer support and respond to your requests.
- Send service communications (security alerts, plan changes, billing notices). These are not marketing and you cannot opt out of them while you hold an account.
- Send marketing emails only where you have opted in, or where permitted by law. Every marketing email has a one-click unsubscribe.
- Monitor performance, debug crashes, and improve features.
- Prevent fraud and abuse, enforce our Terms of Service, and protect users.
- Comply with legal obligations and respond to lawful requests.
We will not use your personal information for a materially different purpose without telling you first and, where required, obtaining your consent.
6. Legal bases (EEA and UK users)
| Purpose | Legal basis |
|---|---|
| Providing the Service, managing your account, billing | Performance of a contract (Art. 6(1)(b)) |
| Health-related data: motion data, body metrics, photos | Explicit consent (Art. 9(2)(a)), withdrawable at any time |
| Security, fraud prevention, product improvement, analytics | Legitimate interests (Art. 6(1)(f)), balanced against your rights |
| Marketing communications | Consent (Art. 6(1)(a)) |
| Retaining records for tax, accounting, legal claims | Legal obligation (Art. 6(1)(c)) / legitimate interests |
Withdrawing consent does not affect processing carried out before the withdrawal, but it will stop the related feature going forward.
7. When we share information
We share personal information only in these situations:
- Service providers (processors) who work on our behalf under written contracts that limit them to our instructions — cloud hosting and storage, authentication, crash reporting and analytics, email delivery, payment and subscription management, and customer support tooling. A current list of sub-processors is available at [LINK TO SUB-PROCESSOR LIST] or on request.
- At your direction — for example if you connect a third-party health platform or choose to share a workout.
- Legal and safety — where we reasonably believe disclosure is required by law, or necessary to protect the rights, safety, or property of users, the public, or WISION. Where legally permitted, we will notify you before disclosing your data in response to a government or law-enforcement request.
- Corporate transactions — in a merger, acquisition, financing, or sale of assets. We will give you notice, and any successor will remain bound by this policy or provide comparable protection until you are notified of a change.
We never grant third parties independent rights to use your data for their own purposes.
8. We do not sell or share your data for advertising
We do not sell your personal information for money or other valuable consideration, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA and similar state laws. We have not done so in the preceding twelve months. We do not use your health, motion, or photo data for advertising or ad targeting under any circumstances.
9. How long we keep your data
| Category | Retention |
|---|---|
| Account data (name, DOB, email) | While your account is active, then deleted within [30–90] days of account deletion |
| Photos | Until you delete them or delete your account; purged from backups within [30–90] days |
| Motion, workout, and training history | While your account is active; retained in de-identified aggregate form afterwards |
| Support correspondence | [24] months |
| Billing and tax records | As required by law, typically [7] years |
| Security and access logs | [12] months |
We may retain limited information longer where necessary to comply with a legal obligation, resolve a dispute, or enforce our agreements.
10. Security
We use industry-standard safeguards including TLS encryption in transit, encryption at rest for photos and sensitive fields, role-based access controls, least-privilege internal access, audit logging, secure credential hashing, regular dependency patching, and periodic security review. We restrict employee access to personal data to those who need it to do their jobs.
No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant regulators within the timeframes required by law (for example, without undue delay and within 72 hours of becoming aware, where the GDPR applies).
11. Your rights and choices
Depending on where you live, you may have the right to:
- Access the personal information we hold about you and obtain a copy.
- Correct inaccurate or incomplete information.
- Delete your information, subject to legal exceptions.
- Port your data to another service in a structured, machine-readable format.
- Object to or restrict processing based on legitimate interests.
- Withdraw consent at any time, including for health data and photo-based features.
- Opt out of sale, sharing, or targeted advertising (we do not do any of these).
- Not be discriminated against for exercising any of these rights. We will not deny service, charge different prices, or provide a lower quality of service because you exercised a privacy right.
How to exercise them: use the in-app privacy controls, or email support@wisionapp.com. We will verify your identity (usually by confirming control of your account email) and respond within 30 days, or 45 days where the CCPA applies, extendable once where permitted. You may use an authorized agent where the law allows; we may ask for proof of authorization.
If you are in the EEA or UK, you may also lodge a complaint with your local supervisory authority. We would appreciate the chance to address your concern first.
12. United States state privacy notices
California (CCPA/CPRA)
In the preceding twelve months we have collected the categories of personal information described in section 1, which map to these statutory categories: identifiers; customer records; characteristics of protected classifications (age); commercial information (subscription status); internet or network activity; sensory information (photos); inferences; and sensitive personal information (health and biometric-adjacent data). We collect it from you, your device, and the third parties listed in section 1.3, for the purposes in section 5, and disclose it for business purposes only to the recipients in section 7.
We do not sell or share personal information, and we do not use or disclose sensitive personal information for purposes beyond those permitted under CCPA §7027(m). You have the rights to know, delete, correct, and limit, as described in section 11. California residents may also request information under the "Shine the Light" law (Civ. Code §1798.83).
Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and other states
Residents of states with comprehensive privacy laws have rights to access, correct, delete, port, and opt out of targeted advertising, sale, and certain profiling. We process sensitive data (including health data) only with your consent where required. If we deny your request, you may appeal by replying to our decision email; we will respond within 45 days and tell you how to contact your Attorney General if you disagree.
Nevada
Nevada residents may submit a verified request not to sell covered information. We do not sell covered information.
13. Consumer health data (Washington, Nevada and similar laws)
This section serves as our Consumer Health Data Privacy Policy under the Washington My Health My Data Act and comparable laws.
- What we collect: motion and activity data, workout history, body metrics you provide, fitness goals, and photos you upload — as described in sections 1–3.
- Why: solely to provide the training and progress features you asked for.
- Who we share it with: only the processors in section 7, under contract, and only to run the Service. We do not sell consumer health data, and any sale would require your separate signed authorization.
- Your rights: to confirm whether we collect, share, or sell your consumer health data; to access it; to withdraw consent; and to have it deleted — including from our backups and, where applicable, by directing our processors to delete it.
- How to exercise: email support@wisionapp.com with the subject "Health Data Request". We respond within 45 days.
We do not use a geofence around any healthcare facility for advertising, and we never will.
14. Children
WISION is not intended for children. You must be at least 16 years old to create an account (or the minimum digital-consent age in your country, if higher). We collect date of birth specifically to enforce this. Resistance training carries injury risk for developing bodies, and we do not offer youth programming.
We do not knowingly collect personal information from anyone under this age. If we learn that we have, we will delete the account and its data promptly. If you believe a minor has given us information, email support@wisionapp.com.
15. International transfers
We are based in [COUNTRY] and use service providers that may process data in the United States and elsewhere. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards — typically the European Commission's Standard Contractual Clauses together with the UK Addendum, plus supplementary technical measures such as encryption. You may request a copy of the relevant safeguards by emailing us.
16. Cookies and analytics
Our website uses strictly necessary cookies to function, and (where you consent) analytics cookies to understand aggregate usage. Our mobile app does not use advertising identifiers for tracking, and does not participate in cross-app tracking. On iOS we do not request App Tracking Transparency permission because we do not track you across other companies' apps or websites.
We honor Global Privacy Control (GPC) and other recognized opt-out preference signals where required by law. You can manage cookies in your browser settings.
17. Changes to this policy
We may update this policy as the Service evolves. If we make a material change — for example, collecting a new category of data or using it for a new purpose — we will notify you by email and in the app at least [30] days before it takes effect, and where the law requires, we will ask for your consent. The "Last updated" date at the top always reflects the current version, and we keep prior versions available on request.
18. Contact us
Pitch Labs LLC
United States
Email: support@wisionapp.com
Privacy requests: support@wisionapp.com