PRIVACY POLICY
What Cited collects, and what it never touches.
Cited is a hypertrophy training app. It generates programs from cited research, records your workouts, and lets you read the studies behind every number it gives you.
This policy explains what the app collects, where it goes, and what it never touches. It is short because the app collects little.
The short version
- Your training data lives on your phone. Workouts, sets, weights, reps and effort ratings are stored locally and work with no network at all.
- Your bodyweight never leaves your device. It is not synced, not backed up by us, and not sent anywhere.
- If you sign in, your workouts and programs sync to our server so you do not lose them when you change phones. Signing in is optional.
- We send counts, never numbers. Our analytics record that you finished a workout of 24 sets. They never record what you lifted.
- We do not sell your data, run ads, or share anything with data brokers.
What the app stores on your device
Everything you log stays on your phone in a local database, and the app is fully usable without an account or a connection:
- Workouts, and the sets in them — exercise, weight, repetitions, and reps in reserve
- Programs you generate or build, and their history
- Bodyweight entries, if you record them
- Your settings: units, training experience, and what you told the app during onboarding
Deleting the app deletes all of it.
What syncs, and only if you sign in
Signing in is optional. The app works completely without an account; you would just lose your history if you lost your phone.
If you create an account, we store on our servers (Supabase, hosted in the United States):
- Your account identifier and email address
- The first and last name you enter when creating the account — used to greet you in the app and in the emails below, nothing else
- Your programs, and the workouts and sets logged against them
Your bodyweight entries are not among them. They stay on the device.
Access is restricted by row-level security, meaning the database itself enforces that your rows are readable only by your account.
Emails we send
If you have an account we send transactional email only: confirming your address when you sign up, resetting a password, confirming a change of address. These go through Resend, which receives your email address and name in order to deliver them. There is no newsletter and no marketing email.
Analytics
We use PostHog to understand how the app is used — where people get stuck, and whether the parts we built are the parts anyone opens.
We send counts, never values. workout_completed { setsLogged: 24 } is the shape of what we collect. The weight on the bar, your repetitions, your effort ratings and your bodyweight are deliberately excluded, and the app enforces that in code: property names matching training or personal data are stripped before anything is sent, and the check fails loudly in development.
Events are tied to a random identifier generated on your device. If you sign in, that identifier is linked to your account so a person is not counted twice.
You can turn analytics off. Profile → Privacy → Off stops every event, including the app-open and app-close events, and the choice is remembered on your device. Nothing else in the app changes.
Search text is kept only when a search finds nothing. A search that returns no results tells us which topic to write about next. A successful one is a record of something you wondered about, and is not ours to keep.
When the app talks to someone else
- PubMed (US National Library of Medicine). Searching the literature sends your search text to the NCBI E-utilities API so it can return results. Their privacy policy governs what they do with it.
- OpenAI. When you are signed in, searching our own evidence base sends your search text to our server, which asks OpenAI to turn it into a numerical representation used to find matching claims. OpenAI receives the text of the search and nothing about you; it is not used to train their models. Our server keeps a hashed form of the search and its numerical representation so repeat searches cost nothing, not the text itself. Signed out, search is keyword-only and never leaves your phone.
- Apple. Purchases and subscriptions are handled by Apple. We never see your payment details.
- RevenueCat. Validates your subscription receipt with Apple on our behalf and tells the app whether the subscription is active. It receives a purchase identifier, not a payment method.
What we never collect
- Payment card numbers or bank details — Apple handles payment and we never see it
- Contacts, photos, microphone, camera, or precise location
- Health data from Apple Health — the app does not connect to it
- Anything for advertising or sale to third parties
Notifications
The rest timer schedules a local notification so it can tell you when a rest period is over while the app is in the background. It is generated on your device and no push token or notification content is sent to us or anyone else.
Retention and deletion
Local data lives until you delete it in the app or delete the app itself.
If you have an account you can delete it yourself: Profile → Account → Delete account. That removes the account and everything backed up to it immediately and permanently. Data stored on your phone stays on your phone until you delete it in the app or delete the app. You can also contact us at the address below and we will do it for you. You do not need to give a reason.
Children
Cited is not directed at children under 13, and we do not knowingly collect data from them. Resistance training programmes for children should come from a coach, not an app.
Changes
If this policy changes in a way that affects what we collect, the app will say so rather than quietly updating a page nobody reads. The date at the top always reflects the current version.
Contact
Questions, deletion requests, or anything else about your data: support@citedlifting.com