Legal

Privacy Policy

Last updated: July 23, 2026 · Effective: July 23, 2026

How WISION collects, uses, and protects your personal information — written to be read, not skimmed past.

The short version

We collect only what the app needs to coach you: your name, date of birth, email, motion data from your device, and any photos you choose to upload. Your photos are private to your account — no other user can see them, and we do not publish, sell, or share them for advertising. We do not sell your personal information. You can export or delete your data at any time from the app or by emailing support@wisionapp.com.

This Privacy Policy explains how Pitch Labs LLC ("WISION", "we", "us") collects, uses, shares, and protects personal information when you use the WISION mobile application, website, and related services (together, the "Service"). It applies to all users worldwide, with additional region-specific terms in sections 12–15.

1. Information we collect

1.1 Information you give us

DataWhy we need itRequired?
NameTo personalize your account, coaching messages, and communications.Required
Date of birthTo confirm you meet our minimum age, and because age materially affects safe training load, recovery, and heart-rate guidance.Required
Email addressAccount creation, sign-in, security alerts, and service notices.Required
Training profileGoals, split, days per week, session length, target timeline, and optional metrics such as height, weight, or experience level, used to build and adapt your plan.Optional
PhotosTo generate your private progress projection and track visible change over time. See section 2.Optional
Support messagesTo answer your questions and investigate issues.Optional

1.2 Information collected automatically

1.3 Information from third parties

2. Your photos

Photos are the most sensitive thing you can share with us, so we hold them to a higher standard.

Face and biometric information

If a photo you upload includes your face, that image may be treated as biometric or sensitive information under laws such as the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, and Washington state law. We do not perform facial recognition and we do not create a faceprint, face-geometry scan, or other biometric identifier from your photos. Our analysis estimates body composition and proportions only. Where any processing would qualify as biometric under applicable law, we will obtain your separate written consent first and publish our retention and destruction schedule.

3. Motion and health data

With your permission, WISION reads motion and activity data from your device to detect workouts, estimate effort and volume, and adapt your plan. On iOS this uses the Motion & Fitness permission; on Android it uses the Physical Activity permission. You can revoke this at any time in your device settings — the app will keep working, but automatic workout tracking will stop.

Motion data, training history, body metrics, and photos may constitute health-related data under laws including the EU/UK GDPR (special category data), the California Consumer Privacy Act (sensitive personal information), and the Washington My Health My Data Act. We process this data only to deliver the Service to you, and we ask for your explicit consent where the law requires it.

HIPAA does not apply

WISION is a consumer fitness product, not a healthcare provider, health plan, or clearinghouse. We are not a HIPAA covered entity or business associate, and the data you give us is not protected health information under HIPAA. It is protected by this policy and by the consumer privacy laws described below.

4. AI projections and automated processing

WISION uses automated systems, including machine learning models, to generate training plans and to render a visual projection of potential future progress. These outputs are estimates, not predictions or guarantees, and they are not medical advice or a diagnosis. Results depend on genetics, adherence, nutrition, sleep, health status, and factors outside our control.

Automated processing here does not produce legal or similarly significant effects about you. Where you are in the EEA or UK, you have the right to request human review of any decision that does — contact us and a person will look at it.

We use aggregated and de-identified data to improve our models. Your photos are excluded from model training unless you opt in separately.

5. How we use your data

We will not use your personal information for a materially different purpose without telling you first and, where required, obtaining your consent.

6. Legal bases (EEA and UK users)

PurposeLegal basis
Providing the Service, managing your account, billingPerformance of a contract (Art. 6(1)(b))
Health-related data: motion data, body metrics, photosExplicit consent (Art. 9(2)(a)), withdrawable at any time
Security, fraud prevention, product improvement, analyticsLegitimate interests (Art. 6(1)(f)), balanced against your rights
Marketing communicationsConsent (Art. 6(1)(a))
Retaining records for tax, accounting, legal claimsLegal obligation (Art. 6(1)(c)) / legitimate interests

Withdrawing consent does not affect processing carried out before the withdrawal, but it will stop the related feature going forward.

7. When we share information

We share personal information only in these situations:

We never grant third parties independent rights to use your data for their own purposes.

8. We do not sell or share your data for advertising

We do not sell your personal information for money or other valuable consideration, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA and similar state laws. We have not done so in the preceding twelve months. We do not use your health, motion, or photo data for advertising or ad targeting under any circumstances.

9. How long we keep your data

CategoryRetention
Account data (name, DOB, email)While your account is active, then deleted within [30–90] days of account deletion
PhotosUntil you delete them or delete your account; purged from backups within [30–90] days
Motion, workout, and training historyWhile your account is active; retained in de-identified aggregate form afterwards
Support correspondence[24] months
Billing and tax recordsAs required by law, typically [7] years
Security and access logs[12] months

We may retain limited information longer where necessary to comply with a legal obligation, resolve a dispute, or enforce our agreements.

10. Security

We use industry-standard safeguards including TLS encryption in transit, encryption at rest for photos and sensitive fields, role-based access controls, least-privilege internal access, audit logging, secure credential hashing, regular dependency patching, and periodic security review. We restrict employee access to personal data to those who need it to do their jobs.

No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant regulators within the timeframes required by law (for example, without undue delay and within 72 hours of becoming aware, where the GDPR applies).

11. Your rights and choices

Depending on where you live, you may have the right to:

How to exercise them: use the in-app privacy controls, or email support@wisionapp.com. We will verify your identity (usually by confirming control of your account email) and respond within 30 days, or 45 days where the CCPA applies, extendable once where permitted. You may use an authorized agent where the law allows; we may ask for proof of authorization.

If you are in the EEA or UK, you may also lodge a complaint with your local supervisory authority. We would appreciate the chance to address your concern first.

12. United States state privacy notices

California (CCPA/CPRA)

In the preceding twelve months we have collected the categories of personal information described in section 1, which map to these statutory categories: identifiers; customer records; characteristics of protected classifications (age); commercial information (subscription status); internet or network activity; sensory information (photos); inferences; and sensitive personal information (health and biometric-adjacent data). We collect it from you, your device, and the third parties listed in section 1.3, for the purposes in section 5, and disclose it for business purposes only to the recipients in section 7.

We do not sell or share personal information, and we do not use or disclose sensitive personal information for purposes beyond those permitted under CCPA §7027(m). You have the rights to know, delete, correct, and limit, as described in section 11. California residents may also request information under the "Shine the Light" law (Civ. Code §1798.83).

Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and other states

Residents of states with comprehensive privacy laws have rights to access, correct, delete, port, and opt out of targeted advertising, sale, and certain profiling. We process sensitive data (including health data) only with your consent where required. If we deny your request, you may appeal by replying to our decision email; we will respond within 45 days and tell you how to contact your Attorney General if you disagree.

Nevada

Nevada residents may submit a verified request not to sell covered information. We do not sell covered information.

13. Consumer health data (Washington, Nevada and similar laws)

This section serves as our Consumer Health Data Privacy Policy under the Washington My Health My Data Act and comparable laws.

We do not use a geofence around any healthcare facility for advertising, and we never will.

14. Children

WISION is not intended for children. You must be at least 16 years old to create an account (or the minimum digital-consent age in your country, if higher). We collect date of birth specifically to enforce this. Resistance training carries injury risk for developing bodies, and we do not offer youth programming.

We do not knowingly collect personal information from anyone under this age. If we learn that we have, we will delete the account and its data promptly. If you believe a minor has given us information, email support@wisionapp.com.

15. International transfers

We are based in [COUNTRY] and use service providers that may process data in the United States and elsewhere. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards — typically the European Commission's Standard Contractual Clauses together with the UK Addendum, plus supplementary technical measures such as encryption. You may request a copy of the relevant safeguards by emailing us.

16. Cookies and analytics

Our website uses strictly necessary cookies to function, and (where you consent) analytics cookies to understand aggregate usage. Our mobile app does not use advertising identifiers for tracking, and does not participate in cross-app tracking. On iOS we do not request App Tracking Transparency permission because we do not track you across other companies' apps or websites.

We honor Global Privacy Control (GPC) and other recognized opt-out preference signals where required by law. You can manage cookies in your browser settings.

17. Changes to this policy

We may update this policy as the Service evolves. If we make a material change — for example, collecting a new category of data or using it for a new purpose — we will notify you by email and in the app at least [30] days before it takes effect, and where the law requires, we will ask for your consent. The "Last updated" date at the top always reflects the current version, and we keep prior versions available on request.

18. Contact us

Pitch Labs LLC
United States
Email: support@wisionapp.com
Privacy requests: support@wisionapp.com