Legal
Privacy policy
What Stronge collects, what it deliberately does not, and what you can do about either.
01 Who we are and what this policy covers
Chutta Digital (Pty) Ltd (“Stronge”, “we”, “us”) makes the Stronge mobile app and this website. We are the responsible party under South Africa’s Protection of Personal Information Act, 2013 (POPIA) and the data controller under the UK and EU General Data Protection Regulation (GDPR) for the personal information described in this policy.
Our registered address is 213 Main Road, Three Anchor Bay, Cape Town, 8005. Our Information Officer is Reegan Alward, who can be reached at support@stronge.app.
This policy applies to the Stronge app on iOS and Android and to stronge.app. It explains what we collect, why, what we do not collect, who processes it on our behalf, how long we keep it, and the rights you have over it. Where this policy says “health data” it means information about your body and your training — your injury history, pain reports, body weight, biological sex, date of birth and workout summaries. POPIA calls this special personal information; GDPR calls it special category data. Both give it extra protection, and section 5 sets out the basis on which we handle it.
02 The personal information we collect
All of it is linked to your account. Stronge has no anonymous collection.
Information you give us
- Account details — your email address, your name, and the identifier your sign-in provider gives us if you use Sign in with Apple or Google.
- Your profile — date of birth, biological sex and body weight. These set your starting loads and your age eligibility; they are not optional, because prescribing load without them would be guessing.
- Injury history and status — what you are managing, what you have cleared, and the rehab stage you are at for each.
- Pain and soreness reports — the flags you raise on a movement and the soreness and energy ratings you give before a session.
- Training context — your sport, weekly volume, the equipment you have, your session-length range, your goals and any race date you add.
- Free text you write — notes on an exercise, notes for your physio, and any feedback you send us.
Information from Apple Health or Health Connect
Only if you grant that permission, and only these types. Stronge asks Apple Health for your workouts, your heart rate, your body weight, your date of birth and your biological sex. Health Connect on Android surfaces its own list of granted types.
What we then store is narrower than what we read. From your workouts we keep weekly summaries — session count, distance, duration and elevation — not individual activities. Your heart rate is handled differently and section 3 explains how. You can decline this permission entirely and enter your training by hand instead; the app works either way.
Information Stronge generates as you use it
- The sessions prescribed to you, what you completed, and the loads you logged.
- Workouts you pinned, exercises you swapped, and the progression events those earned.
- The engine’s own record of what it decided and why, which is what lets the app tell you the reason a given exercise is in your session.
If you join the waitlist on this website
You do not need an account to give us your email address on stronge.app. If you do, we store the address, which part of the site you submitted it from, and the country your request came from, so that we can tell you when Stronge opens and consider you for the Beta Team. It is held separately from the app’s database, and it is not health data. Ask us to remove it and we will.
If you use the contact form on this website
The name, email address and message you type are sent to a private messaging channel our team monitors, which is how we see and reply to it. This is an ordinary “get in touch” form: unless you choose to write about your health in the message itself, nothing you send here is health data. That channel is a processor for this purpose only, named again in section 9, and we do not control how long it retains a delivered message, so please do not put anything in the message you would not want sitting in a chat log indefinitely. Email support@stronge.app directly if that matters to you.
Information collected automatically
- Product usage events — which screens and features you use. This is off unless you turn it on, and it is linked to your account. We do not describe it as anonymous, because it is not.
- Crash and error messages — so we can fix what broke.
03 What we do not collect
These are commitments, not aspirations, and each is enforced in the code rather than by policy alone.
- Your location, and your GPS routes. Never read, never stored. Location is not in the set of data types Stronge requests from Apple Health, so there is nothing to store. Stronge knows you ran for 48 minutes. It does not know where.
- Your raw heart rate. Your heart-rate trace is read on your phone, reduced there to a single dimensionless effort ratio for the week, and only that number is sent to us. The trace itself never leaves the device.
- Advertising identifiers. No IDFA, no advertising SDKs, no third-party analytics SDKs. Apple’s App Tracking Transparency prompt does not apply to Stronge because we do not track in the sense it governs.
- Payment card details. Stronge does not process card data. If and when paid subscriptions launch, they run through Apple’s and Google’s in-app purchase systems and we never see the card.
- Your contacts, photos, microphone or calendar.
One clarification, because the distinction matters and is easy to over-read. The heart-rate and location commitments above are specific to heart rate and location. They do not extend to everything else. Your date of birth, biological sex, body weight, injury history, pain reports and completed sessions are stored on our servers, because the engine that writes your plan runs there. Any statement that “your data stays on your device” would be untrue of those, and we do not make it.
04 Why we process your information, and on what basis
We process personal information for the purposes below and no others. POPIA requires that processing be lawful and minimal (sections 9 to 11); GDPR requires a lawful basis under Article 6, and a further condition under Article 9 for health data.
- To give you the service you signed up for — creating your account, authenticating you, writing and adapting your sessions, showing your progress and keeping your plan in step with your training. Basis: performance of our contract with you (POPIA s11(1)(b); GDPR Art 6(1)(b)).
- To handle your health data safely — your injury history, pain reports, body metrics and workout summaries drive which exercises you are given and, more importantly, which ones you are never given. Basis: your explicit consent (POPIA s27(1)(a); GDPR Art 6(1)(a) and Art 9(2)(a)). See section 5.
- To understand which features work — product usage events. Basis: your consent, given separately and off by default (POPIA s11(1)(a); GDPR Art 6(1)(a)).
- To improve the training engine — a separate, optional research use described in section 7. Basis: your separate explicit consent, off by default (POPIA s27(1)(a); GDPR Art 9(2)(a)).
- To keep the service secure and working — crash reports, abuse prevention, debugging. Basis: our legitimate interests in a functioning, secure product, balanced against your rights (GDPR Art 6(1)(f); POPIA s11(1)(f)).
- To meet legal obligations — where a law, regulator or valid court order requires it. Basis: legal obligation (GDPR Art 6(1)(c); POPIA s11(1)(c)).
We do not use your health data for advertising or marketing. We do not profile you for advertising at all.
05 Health data, and why we ask for consent
POPIA section 26 prohibits processing information about a person’s health unless a specific exception applies. GDPR Article 9 does the same. In both cases the exception we rely on is your explicit consent — POPIA s27(1)(a) and GDPR Art 9(2)(a).
That is why the consent to process your training and profile data is presented as a required consent at sign-up rather than buried in terms you scroll past. Stronge cannot function without it: an engine that does not know your injury history cannot avoid the movements that would aggravate it.
You can withdraw that consent at any time. Because it is the basis on which the whole service operates, withdrawing it means the app can no longer build your sessions — so the practical way to end all processing is to delete your account, which is one action inside the app and is covered in section 13. Withdrawing consent does not affect the lawfulness of anything we did before you withdrew it.
06 Your consents, and how to change them
Stronge keeps four separate consents rather than one blanket agreement. Each is recorded with a version and a timestamp, and every change is appended as a new record, so there is a full history of what you agreed to and when. You can view and change all four at any time under Settings → Privacy & data.
- Process my training and profile data. Required. Lets Stronge use your workouts, injury history, date of birth and biological sex to build and safely tailor your sessions.
- Read from Apple Health or Health Connect. Optional, and off until you grant it. Without it you enter your training manually.
- Share product usage data. Optional, off by default. Records which screens and features you use, linked to your account. Self-hosted, with no third-party analytics or advertising SDK involved. The entire app works with this off.
- Help improve the training engine. Optional, off by default, and described in section 7. Switching it off deletes everything already collected under it — that deletion happens in the database the moment you revoke, not on a queue.
07 How your plan is generated, and where AI is involved
The engine
Your sessions are produced automatically. A rules-based engine reads your profile, your injury status, your recent training load, your equipment and the time you have, and selects exercises and doses from a fixed library. It is deterministic: the same inputs produce the same plan. Hand-written clinical rules sit above everything else, so a movement that is contraindicated for an injury you have declared is never selected, whatever the rest of the engine would prefer.
This is automated processing, and we want to be plain about its limits. It is training decision support, not a decision that produces legal or similarly significant effects for you. You can swap any exercise, flag anything that hurts, change the session, or ignore it. You can also ask us how a decision was reached — see section 16.
Where a language model is used
A language model writes some of the text you read: session rationales, the weekly narrative, some notification copy, and the answers in Ask Stronge. It rewrites facts the engine has already established. It does not choose your exercises, and it is instructed never to introduce a number, exercise or claim that is not in the data supplied to it.
The model runs on our infrastructure provider’s own AI service, not on a separate outside AI company’s servers, so your data is not sent to a third-party AI vendor’s API. Request and response body logging is switched off at the gateway. The information we put in front of the model is your training context — session contents, exercise and focus-area names, your rehab stage, your recent load — and it does not include your name, email address or date of birth.
The research use, if you opt in
If you turn on “Help improve the training engine”, we keep a copy of your sessions and how they went, under a random identifier, with your age and weight recorded in broad bands rather than as exact values, and with your name, exact date of birth and free-text notes excluded by construction.
We describe this data as pseudonymised, not anonymised. That is a deliberate choice of word: pseudonymised data remains personal information under both POPIA and GDPR and keeps the full set of protections in this policy. We will not call it anonymous unless and until we can demonstrate that it is.
08 The lab report
Stronge can render your pain history, injury and rehab state, exercise log and weekly load into a PDF intended for a physiotherapist or clinician.
That document is composed on your device, from information the app already holds and you can already see. Nothing is uploaded to us to produce it, and no recipient is pre-set — the file is handed to your phone’s share sheet and where it goes next is your instruction, not ours. It is not a disclosure by us and we have no record of who you sent it to.
The report states on its face that its contents are self-reported and are not a clinical record, so that a clinician reading it does not mistake it for a validated measurement.
09 Who else processes your information
We use service providers to run Stronge. They are operators under POPIA and processors under GDPR, which means they act only on our documented instructions and never for their own purposes. They are not recipients we have shared your data with in any commercial sense.
- Cloud hosting, authentication and database. Your data is stored in our hosting provider’s London region.
- Content delivery and AI processing. Delivery of this website and the waitlist store behind it, delivery of exercise demo videos and images, and the AI text generation described in section 7.
- Apple and Google — sign-in, and app distribution. If paid subscriptions launch, their in-app purchase systems handle payment; we never receive card details.
- A private messaging channel — only if you use the contact form on this website. Your name, email and message are delivered there so our team can reply. That provider is based in the United States, so this is the one processor in this section that sits outside the UK; nothing else on this list involves a US transfer.
Beyond these, your information is not given to anyone. In particular there are no third-party analytics SDKs, no advertising networks, and no data brokers in the app or on this site.
10 We never sell your information
We do not sell your personal information, and we do not trade or barter it. We have never done so.
We do not share it with insurers, medical schemes, employers or advertisers, and we will not — this is not a limitation of our current business model, it is a commitment about the product.
We would disclose information only where we are legally compelled to: a valid court order, a legal obligation, or to establish or defend a legal claim. Where the law permits us to tell you that this has happened, we will.
If Stronge is ever acquired or merged, your information could transfer to the acquiring entity as part of that transaction. It would remain subject to this policy, and we would tell you before it changed hands.
11 Where your information is stored, and cross-border transfers
Your data is stored in the United Kingdom, in our hosting provider’s London region, encrypted in transit and at rest.
If you are in South Africa. This is a cross-border transfer under POPIA section 72. It is permitted because the United Kingdom, through the UK GDPR and the Data Protection Act 2018, subjects the recipient to a law that upholds principles for the lawful processing of personal information substantially similar to POPIA’s, including provisions on onward transfer.
If you are in the UK or the EEA. Your data is processed within the UK. The European Commission renewed its adequacy decision for the United Kingdom on 19 December 2025, running to 27 December 2031, so transfers from the EEA require no additional safeguards.
One exception worth naming. The AI text generation in section 7 runs on a global content delivery network, so that specific request may be processed outside the UK. It carries your training context and no direct identifiers, and gateway body logging is off.
A second exception. If you use the contact form on stronge.app, that message is delivered to a United States-based messaging provider, as described in section 9. This is the only place on this site or in the app where a US transfer of directly identifying information (your name and email address) happens by design, and it happens only because you chose to send that message.
12 How long we keep your information
We keep personal information only as long as the purpose it was collected for requires — POPIA section 14 and GDPR Article 5(1)(e).
- Your account and training history — for as long as your account exists. Your history is the thing that makes the plan get better, so we do not prune it while you are using Stronge.
- Product usage events — deleted after 180 days.
- The engine’s raw input snapshots — cleared after 90 days. The record of what the engine decided is kept, because it is what lets the app explain itself; the underlying health signals behind that decision are erased once support and debugging no longer need them.
- Exercise swap events — deleted after 365 days.
- Research data, if you opted in — kept while that consent stands, and deleted immediately when you withdraw it.
- Data exports you generate — the download link is short-lived and the file is swept automatically.
- A waitlist entry — until Stronge opens to you and you either create an account or ask us to remove it.
- A contact form message — we don’t set a retention period on the private channel it lands in. Don’t put anything in it you wouldn’t want kept indefinitely.
These sweeps run on a schedule, not on request. When you delete your account, everything goes at once — see section 13.
13 Getting your data out, and deleting it
Both are in the app, under Settings → Privacy & data. Neither requires you to email us and wait.
Export. Stronge produces a machine-readable file containing the personal information we hold about you across every table that holds it, and gives you a private, short-lived link to download it. This is your right of access and your right to portability in one action.
Deletion. Deleting your account removes your data from every table that holds it — profile, injuries, sessions, completions, notes, consents, usage events, research data, all of it — and revokes the sign-in token if you used Sign in with Apple. It is not a flag on a row or a soft delete. It cannot be undone, and we cannot restore an account afterwards.
Where the law requires us to keep a specific record despite a deletion request, we will keep only that record, only for as long as required, and we will tell you what it is.
14 Security
Your information is encrypted in transit and at rest. Database access is governed by row-level security, so your rows are readable only by your authenticated account — this is enforced by the database itself rather than by application code that could be bypassed. Access to production by us is limited to the people who need it.
The absence of third-party analytics and advertising SDKs is itself a security property: the smaller the number of parties holding your health data, the smaller the number of ways it can leak.
No system is perfectly secure and we will not claim otherwise. Keep your account credentials to yourself, and tell us at support@stronge.app if you think your account has been compromised.
15 If there is a security breach
If personal information is accessed or acquired by an unauthorised person, we will notify the Information Regulator of South Africa and affected users as soon as reasonably possible, as POPIA section 22 requires. Where UK or EU GDPR applies we will notify the relevant supervisory authority within 72 hours of becoming aware, and notify you directly where the breach is likely to result in a high risk to your rights.
Notification will describe what happened, what information was involved, what we have done about it, and what you can do.
16 Your rights
Under POPIA (sections 23 to 25) and GDPR (Articles 15 to 22) you have the right to:
- Know what we hold and get a copy of it — the in-app export does this immediately.
- Have it corrected if it is inaccurate, and completed if it is incomplete. Most of it you can edit directly in the app.
- Have it deleted — the in-app account deletion does this.
- Take it with you in a structured, commonly used, machine-readable format.
- Object to processing based on our legitimate interests, and to withdraw any consent you have given.
- Ask us to restrict processing while a dispute about accuracy or lawfulness is resolved.
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Section 7 explains why we do not consider your training plan to be such a decision — but you can always ask us how a plan was arrived at, and you can override any part of it.
- Complain to a regulator — see section 20.
To exercise a right that is not already a button in the app, email support@stronge.app. We will respond within 30 days, and will tell you if we need longer and why. We may need to verify your identity before acting, and we will not ask for more information than that verification needs. Exercising any of these rights is free, and we will not treat you differently for it.
17 Age
Stronge is for adults. You must be 18 or older to create an account. This is enforced at sign-up and again in the database, which rejects a date of birth implying an age under 18. The threshold reflects POPIA section 34, which restricts the processing of children’s personal information.
We do not knowingly collect information from anyone under 18. If we learn that we have, we will delete it. If you believe a minor has created an account, tell us at support@stronge.app.
18 Stronge is not medical advice
Stronge is strength and conditioning software that adapts to your training load. It is not a medical device. It does not diagnose, treat, or claim to prevent disease or injury, and nothing in it is a substitute for advice from a qualified healthcare professional.
Your injury history drives exercise selection — which movements you are given and which you are never given. It is not a clinical assessment. If you are injured or in pain, see a physiotherapist or a doctor. Stronge is built to work alongside them, not instead of them.
19 Changes to this policy
We will update this policy when what we do changes. The effective date at the top of the page always reflects the current version.
If a change is material — a new category of information, a new purpose, or a new processor — we will tell you in the app or by email before it takes effect, and where the change requires your consent we will ask for it rather than assume it from your continued use.
20 Contact and complaints
For anything in this policy, to exercise a right, or to raise a concern, email our Information Officer at support@stronge.app. We would genuinely rather hear from you first and put something right.
You also have the right to complain to a regulator directly, and you do not have to come to us first.
- South Africa — the Information Regulator, inforegulator.org.za.
- United Kingdom — the Information Commissioner’s Office, ico.org.uk.
- EEA — the supervisory authority in the country where you live or work.