Relm
TourFeaturesPricing
Get iPhone beta
← Back to home

Legal & privacy

Privacy Policy

Effective and last updated: 26 July 2026

Relm is an offline-first iOS training tracker. This policy explains, in practical terms, what information Relm handles, why it is handled, when it leaves your device, and how you can control it.

  • Local by defaultCore training data stays on your iPhone.
  • Optional cloud featuresBackup and social features require deliberate choices.
  • No data salesNo ads, tracking SDKs, or data-broker disclosures.
  • User controlExport and account-deletion tools are built into Settings.
Consumer health data notice

Relm handles fitness, nutrition, recovery, and Apple Health data. A separate notice explains the additional disclosures and rights that apply to consumer health data.

Read the health data notice

Contents

  1. Scope and operator
  2. Information we handle
  3. How and why we use information
  4. Apple Health and HealthKit
  5. Service providers and disclosures
  6. International transfers
  7. Retention and deletion
  8. Your privacy rights and choices
  9. Security
  10. Regional disclosures
  11. Children
  12. Changes and contact

1. Scope and operator

This policy applies to the Relm mobile application, getrelm.app, the beta waitlist, support communications, and any related service that links to this policy (together, the Services).

The Services are operated by Batu Ganioglu, doing business as Relm, an individual sole trader based in Massachusetts, United States (Relm, we, us, or our). Where applicable data-protection law uses the term, Batu Ganioglu is the controller of the personal data described in this policy.

Privacy contact: support@getrelm.app

2. Information we handle

The table below is a product-specific inventory. We do not collect the broad marketing, advertising, payment-card, or device-analytics categories commonly found in generic privacy-policy templates.

CategoryExamples and sourceWhere it is handled
Local training and wellness dataWorkouts, routines, programs, nutrition logs, recipes, bodyweight history and goals, personal records, custom exercises, and manual recovery check-ins that you enter or import.Stored on your device by default. It leaves the device only when you enable a feature described below or export it yourself.
Account and authentication dataA random account identifier; for a permanent account, your email address and authentication records. Sign in with Apple may provide an Apple relay email if you choose Hide My Email.Supabase processes account and authentication records. Relm does not request your Apple name and does not use passwords.
Optional cloud backupWorkouts, routines, saved programs, categories, nutrition entries and recipes, records, exercise library, bodyweight, goals, manual recovery check-ins, coaching output, and profile inputs such as sex, age in whole years, height, and activity level.Uploaded automatically after you create a permanent account. The current version has no backup on/off control separate from signing in. A random installation identifier is attached so backups from different devices can be distinguished.
Optional social dataHandle, display name, bio, profile photo, privacy setting, workout posts, captions, comments, replies, likes, follows, blocks, and abuse reports that you submit.Stored by Supabase. Visibility to other users depends on the feature and your profile setting, as explained under Social features.
Apple Health dataBodyweight, steps, workouts, sleep analysis, resting heart rate, heart-rate variability, and heart rate, only for the categories you authorize in iOS.Most stays on-device. Imported bodyweight enters cloud backup automatically if you sign in to a permanent account. See Apple Health and HealthKit.
Derived informationRecovery scores, training insights, and coaching suggestions calculated from information in the app.Recovery scores stay on-device and are excluded from backup. Coaching output may be included in backup.
Beta access, platform interest, and supportEmail address, signup time, source page, and anything you choose to include in a support message. Please do not send health information that is not needed to answer your request.Beta-access and Android-interest records are stored by Supabase; Resend delivers iOS beta invitations and relevant product updates. Android-interest submissions do not trigger an iOS TestFlight invitation. Support data is handled through our email provider.
Network, security, and service metadataIP address, request time, request route, authentication event, and similar connection metadata generated when a network feature is used. Waitlist IP addresses are converted to a one-way rate-limit key; the raw address is not retained in the waitlist table.Processed by the relevant hosting or infrastructure provider to deliver requests, prevent abuse, and secure the Services. Relm does not use this information for advertising or cross-service tracking.
Website interaction eventsA fixed event name, page path, signup source, and short UI context such as the opened FAQ or product-tour step. A source value can come from the page URL.Stored by Supabase on a rolling window of roughly 90 days to understand the beta-access funnel and improve getrelm.app. The request IP is used transiently for abuse rate limiting and is not written to the event table. Relm does not intentionally add an email address, account identifier, health data, advertising id, or cross-site identifier to an event. Because source values are limited to 64 characters but can be supplied through a URL, do not put personal or sensitive information in a source parameter. UI context is limited to 120 characters.

What stays on your device

Relm's core features work without a permanent account or cloud backup. Local data remains until you delete it, reset the app, or remove the app. You can create a JSON export from Settings; that file is generated on your device and goes only where you choose to send it.

Anonymous and permanent accounts

On first launch, when the backend is available, Relm creates a random anonymous account so the installation has a stable service identity. The account has no name or email and cannot use cloud backup or social features. Infrastructure providers may still process ordinary network and authentication metadata when this account is created or refreshed.

You can deliberately upgrade to a permanent account with Sign in with Apple or an email magic link. A permanent account is required for backup and social features. Apple may let you share a relay address; Relm works normally with that address.

Cloud backup

A permanent account and its backup are optional. If you create a permanent account, backup begins automatically; the current version does not offer a separate backup toggle. Backup is transmitted using TLS and stored with account-level database access controls. Relm does not apply end-to-end or client-side encryption to backup contents, so the hosting provider's infrastructure can technically process them. Use Relm without a permanent account if that trade-off is not acceptable to you.

Social features

The social feed is optional, online-only, and requires a permanent account and acceptance of the Community Terms. A handle, display name, and bio are visible to signed-in Relm users. Workout posts may include the workout name, date, duration, set count, exercises and top set, personal records, and your caption. Comments, replies, likes, follows, and @mentions are also visible to the relevant users.

A private profile requires follow approval before another user can see its posts. Profile-photo files are stored at a public URL and may be viewed by anyone who has the direct link, even when the profile is private. Do not upload a photo you would not be willing to make public. You can block users and report content in the app.

External requests you initiate

  • Food search: the search words you type are sent to the USDA FoodData Central API, together with a Relm application key, as you use USDA search. Search words are sent to Open Food Facts only when you explicitly submit a packaged-food search. When you select an Open Food Facts result, its product barcode is sent to that service to retrieve serving size and micronutrient details. Relm does not attach your account identifier to either request, but both services necessarily receive ordinary network metadata such as your IP address. Open Food Facts is a non-profit operated from the European Union.
  • Exercise videos: a YouTube privacy-enhanced player loads only after you tap play. Google then receives your IP address, video request, and ordinary playback metadata under Google's privacy policy.
  • Subscriptions: Apple processes purchases through the App Store. Relm verifies entitlement on-device with StoreKit; we do not receive payment-card details or store transaction history in your Relm account.

3. How and why we use information

PurposeInformation usedUK/EEA legal basis, where applicable
Provide requested app, account, backup, and social featuresAccount data and the feature-specific data listed abovePerformance of our contract with you; consent where required for sensitive data
Connect Apple Health and process health or fitness informationOnly the Health categories you authorize and derived resultsConsent and, for special-category data, explicit consent
Send beta invitations and beta updatesWaitlist email and signup recordConsent
Measure the website signup flow, understand site use, prevent abuse, and improve the websiteWebsite event, page path, source, short UI context, and transient request metadataOur legitimate interests in operating, securing, and improving the website
Secure the Services, rate-limit abuse, moderate reports, and enforce termsNetwork, account, security-event, social, and report dataOur legitimate interests in protecting users and the Services; legal obligation where applicable
Respond to support or privacy requestsContact details, request contents, and proportionate verification dataPerformance of contract, legitimate interests, and legal obligation
Comply with law and establish, exercise, or defend legal claimsOnly information reasonably necessary for the matterLegal obligation or legitimate interests

Relm does not use personal information for targeted or cross-context behavioural advertising, data-broker enrichment, or automated decisions that produce legal or similarly significant effects. Recovery scores and coaching suggestions are product features, not legal, employment, insurance, credit, or healthcare decisions.

For cloud backup of health and fitness data, Relm relies on the deliberate permanent-sign-in action presented with the backup disclosure. For Apple Health, Relm relies on the per-category permission action presented by iOS. You may withhold either action and continue using Relm's core local features. Where applicable law requires explicit consent, those affirmative actions are the actions by which you express it.

4. Apple Health and HealthKit

Relm connects to Apple Health only if you choose to grant access. iOS provides a separate control for each category, and you can revoke access at any time in the Health app or iOS privacy settings.

  • Relm can read: bodyweight, steps, workouts, sleep analysis, resting heart rate, heart-rate variability, and heart rate.
  • Relm can write: bodyweight entries and workouts. Sleep and heart data are read-only.
  • On-device only: sleep, resting heart rate, heart-rate variability, heart rate, steps, and derived recovery scores are not uploaded.
  • Limited backup exception: bodyweight imported from Apple Health becomes part of your normal bodyweight history and is backed up automatically if you sign in to a permanent account.

HealthKit data is used only to provide health and fitness features you request, including steps, recovery insights, history import, and duplicate prevention when exporting. It is never sold or used for advertising, marketing, profiling, or use-based data mining, and is not disclosed to advertising platforms, data brokers, or information resellers. Relm does not use HealthKit background delivery and reads Health data only while the app is running.

5. Service providers and disclosures

We do not sell personal information, share it for targeted advertising, or disclose it to data brokers. Relm has no advertising, attribution, third-party analytics, or crash-reporting SDKs.

When a provider processes personal information on Relm's behalf, Relm uses service terms or contracts intended to limit processing to the described services and require protections applicable to the data. Independent services you contact directly through an app feature—such as USDA FoodData Central, Open Food Facts, or YouTube—process those requests under their own notices and terms. Relm remains responsible for selecting and overseeing processors as required by applicable law.

RecipientRoleInformation involved
SupabaseAuthentication, database, file storage, edge functions, and backend hostingAccount, backup, social, waitlist, moderation, and service metadata described above; primary project region is Oregon, United States
AppleSign in with Apple, HealthKit, and App Store billingInformation you direct Apple and Relm to exchange for the relevant feature
ResendEmail deliveryWaitlist email address and beta message; moderation notices contain report identifiers, reasons, and target identifiers, but not reported content
USDA FoodData CentralFood-search resultsSearch terms, application key, and ordinary network metadata
Open Food FactsFood-search results and product detailsSearch terms, the barcode of a product you select, and ordinary network metadata; operated from the European Union
Google / YouTubeExercise-video playback you initiateVideo request, IP address, and ordinary playback metadata
Cloudflaregetrelm.app hosting and support-email routingVisitor IP address and ordinary request metadata; support messages in transit. Forwarded support mail is delivered to a mailbox operated by its own provider, which also processes the message
Other Relm usersSocial featuresProfile and social content according to the feature and your settings

We may also disclose information when reasonably necessary to comply with applicable law or valid legal process; protect users, Relm, or others; investigate fraud or security incidents; or establish, exercise, or defend legal claims. We review requests for legal validity and limit disclosures to what is legally required where practicable.

If Relm is involved in a merger, financing, acquisition, reorganisation, or sale of assets, information may transfer as part of that transaction subject to this policy and applicable law. Where required, we will notify you before a materially different use takes effect and obtain consent for a new use when the law requires it.

6. International transfers

Relm is operated in the United States, and providers may process information in the United States and other countries where they operate. Those countries may have different data-protection laws from your country.

Where UK, EEA, or Swiss law requires a transfer mechanism, we rely on an applicable adequacy decision, contractual safeguards such as the relevant Standard Contractual Clauses, or another lawful mechanism. Email support@getrelm.app to request more information about applicable transfer safeguards.

When providing information is required

You are not required by law to provide personal information to Relm. Local information is needed to provide the app features you choose to use. An email address or eligible Apple sign-in credential is needed only if you choose a permanent account; an email address is also needed if you join the waitlist or ask for an email response. If you do not provide information needed for an optional feature, Relm cannot provide that feature.

7. Retention and deletion

DataRetention approach
On-device dataUntil you delete the relevant entry, reset Relm, or remove the app.
Installation identifierA randomly generated identifier remains on the device until the app is removed or its local storage is cleared. It can be linked to cloud backup rows while a permanent account exists and may be sent with a future permanent-account backup.
Account and backupFor the life of the account; each backup record is replaced by a newer version or deleted with the account.
Social contentUntil you delete the content or account, subject to limited safety, dispute, and legal records described below.
Abuse and enforcement recordsFor as long as reasonably necessary to investigate reports, prevent repeat abuse, enforce terms, resolve disputes, and meet legal obligations.
Beta access and platform interestUntil public launch, until the platform-interest record is no longer needed, or until you ask us to remove your entry, whichever comes first.
Service and security metadataFor the shortest period reasonably needed for delivery, security, debugging, abuse prevention, and provider or legal requirements.
Website interaction eventsRemoved by a periodic sweep once they are older than 90 days. The sweep runs as the site receives traffic, so a quiet period can delay a removal past that window.

Deleting your account in Settings removes the account and associated data from active Relm systems, including profiles, backups, posts, comments, likes, follows, blocks, and profile photos. We also attempt to revoke the Apple sign-in token tied to an Apple-linked account. The app explains how to revoke it in iOS if automatic revocation is not possible. When the backend is available, Relm then creates a fresh anonymous service identity so non-account app functions can continue.

Limited copies may remain temporarily in provider disaster-recovery backups until their normal rotation, isolated from ordinary use. We may retain the minimum record required for security, fraud prevention, dispute resolution, or legal compliance, and we will complete deletion from archived systems within any deadline imposed by applicable law. Account deletion does not remove a separate beta-access or platform-interest entry; email us to remove it.

Account deletion also erases the local user-data categories included in the deletion process, but it leaves the random installation identifier, app preferences, and the fact that onboarding was completed. It does not delete bodyweight or workout records previously written to Apple Health; you can manage those records in Apple Health. Removing the app deletes Relm's remaining local storage.

8. Your privacy rights and choices

Depending on where you live, you may have rights to confirm whether we process your personal data; access, correct, delete, or obtain a portable copy of it; restrict or object to processing; withdraw consent; appeal a refusal; and receive information about recipients. You will not be discriminated against for exercising a privacy right. These rights can have exceptions under applicable law.

  • Export: create a JSON export of Relm data stored locally on that device or a workout CSV in Settings. These local exports do not necessarily include account metadata, server-only records, or information held by an independent third party. Email Relm to request a complete access or portable copy where applicable law provides that right.
  • Delete: delete your active account and the associated Relm server data and local user-data categories in Settings, subject to the limits in Section 7.
  • Apple Health: change or revoke category permissions in the Health app or iOS settings.
  • Backup: use Relm without a permanent account if you do not want a cloud copy. Signing out stops future backup activity from that device but does not delete an existing permanent account or its cloud rows; use in-app account deletion or contact Relm to request removal. The current version has no backup toggle independent from sign-in.
  • Waitlist: email us to withdraw and delete the signup.
  • Other requests: email support@getrelm.app with the subject “Privacy Request.”
Your right to object

Where we rely on legitimate interests, you may object to that processing. You may also object at any time to direct marketing; Relm does not use app data for direct marketing.

We may ask for information reasonably necessary to verify that the request concerns you. Verification information is used only for that purpose. You may use an authorised agent where the law permits; we may request proof of authority and direct verification from you. We will respond within the period required by applicable law. If we deny a request, you may appeal by replying with “Privacy Appeal”; we will explain our decision and available regulator complaint options.

If you withdraw consent, the withdrawal applies going forward and does not affect processing that was lawful before withdrawal. A feature may stop working if its necessary data is deleted or permission is withdrawn.

9. Security

We use safeguards designed for the nature of the information handled, including TLS in transit, database row-level access controls, scoped service credentials, rate limits, data-size and type constraints, and account deletion tools. Relm does not store account passwords. Access to operational systems is limited to what is needed to operate and secure them.

No storage or transmission method is completely secure, and we cannot guarantee absolute security. If a qualifying incident occurs, we will investigate and provide notices to affected people, regulators, and others as required by applicable breach-notification law.

10. Regional disclosures

United States

We do not sell personal information; share it for targeted or cross-context behavioural advertising; or use it for profiling that produces legal or similarly significant effects. We have not done so in the preceding 12 months. Therefore there is no sale, targeted-ad, or profiling opt-out for us to apply. Where a legally binding browser preference signal applies to a covered practice, we will honour it as required.

For state-law classification purposes, the categories handled in the preceding 12 months may include identifiers; customer-record information; age and sex; internet or network activity; visual information that you upload; inferences such as recovery or coaching output; and sensitive personal data including account credentials and health or fitness information. We do not collect government IDs, payment-card numbers, precise geolocation, biometric identifiers used to identify you, professional history, or education records.

The sources, purposes, retention criteria, and recipients for those categories are described in Sections 2, 3, 5, and 7. California and other eligible state residents may use the methods in Section 8 to exercise applicable rights. Relm operates exclusively online; the designated request method issupport@getrelm.app.

Washington consumers should also read our separate Consumer Health Data Privacy Policy.

UK, EEA, and Switzerland

The legal bases used for each purpose are listed in Section 3. You may exercise the applicable access, correction, erasure, restriction, objection, portability, and consent-withdrawal rights described in Section 8. You may also complain to the data-protection authority where you live, work, or believe an infringement occurred.

UK residents may contact the Information Commissioner's Office. EEA residents can find their authority through the European Data Protection Board. Swiss residents may contact the Federal Data Protection and Information Commissioner.

Canada, Australia, New Zealand, and other regions

We will consider requests and complaints under the privacy law that applies where you live. In Canada, Australia, and New Zealand this may include access and correction rights and the right to complain to the relevant privacy regulator. Use the request process in Section 8 so we can identify the law and response period that applies to you.

11. Children

Relm is not directed to children under 13, and we do not knowingly collect personal information from them. If the law where you live sets a higher minimum age for a child to consent to these Services, a parent or guardian must provide any consent the law requires. If you believe a child has provided personal information without valid permission, email support@getrelm.app so we can investigate and delete it where required.

12. Changes and contact

We may update this policy to reflect product, provider, or legal changes. The effective date at the top identifies the current version. If a change materially expands how we use personal information, we will provide additional notice and obtain consent where required before the new use takes effect.

Questions, complaints, or privacy requests

Batu Ganioglu, doing business as Relm
Massachusetts, United States

support@getrelm.app
Relm

Made for people who train

ProductProduct tourMove to RelmBeta updatesGet beta access
Help & legalSupportPrivacyHealth data privacyTerms

© 2026 Relm