Stone

Stone — AI Disclosure

Last updated: 2026-08-27. Policy version 2026-08-27.

What changed in this revision. The previous version was stamped 2026-06-17 and described Stone as it was then. Since then Stone gained a coach that talks to you in a running conversation, a notebook it keeps about your training, standing orders it writes for itself, a spoken rest cue, and dictation. None of that was disclosed here. This revision covers all of it.

This page describes Stone's Cloud AI system end-to-end so you know what to expect before you opt in. Stone also keeps an on-device record of every cloud call (the data shape, a retention note, and the policy version that applied), which you can clear any time.

When does AI run?

Stone is cloud-AI-first. The pipeline tries each tier in this order:

  1. Cloud AI (xAI Grok, reached through a privacy-preserving proxy). Every Quick Log save when Cloud AI is on in Settings. Also used to produce the Today recommendation, to answer Coach, and to propose entries on the Learned screen.
  2. On-device deterministic parser — the safety floor. Parses canonical inputs like Bench 185 x 8 with no network and no model. Always available; runs when Cloud AI is unavailable, offline, or your consent settings opt out of cloud.
  3. Apple Foundation Models — a live on-device AI tier on Apple-Intelligence-capable hardware, not a future plan. It does not run before the cloud: with Cloud AI on, tier 1 is tried first, and Foundation Models handles the parse when the cloud declines, fails or is switched off. On a supported device with Cloud AI off, this is what reads your note — locally, with no network call.

Manual confirmation surfaces only when even the deterministic floor produced an ambiguous result.

If you have Cloud AI turned off in Settings, every save skips straight to the on-device deterministic parser.

Which mode runs

Cloud AI uses xAI's Grok models through a privacy-preserving proxy, in two modes:

The "AI quality" setting (Balanced / Smarter) changes only how deeply your recommendation is reasoned — chat and parsing always use the fast mode. Same provider, same privacy posture, same retention, same per-request cost either way.

What gets sent

The exact bytes are pinned per call. Stone records the data shape of every cloud call on your device:

Your voice

This is the part the previous version of this page never mentioned, and it is the most sensitive thing Stone sends.

Your conversation with the coach

The notebook and standing orders

Who sees the data and how long they keep it

Hop Sees Retention
Your iPhone Everything — it's the source of truth. Until you delete it.
Privacy-preserving proxy (Cloudflare) The request, in transit only. Does not store the request body. Cloudflare retains only metadata (timestamps, status codes, byte counts) for cost and abuse monitoring.
xAI (Grok) The request body Stone sent. Per xAI's API policy: not used to train models by default; retained only for a limited period. See x.ai/legal.

When this policy version changes, each call's on-device record stays pinned to the version that applied when the call was made — your historical record doesn't get rewritten by a later xAI ToS change.

What gets returned

For Quick Log, a structured workout the deterministic parser couldn't produce on its own. For Recommendations, a session title, training load, duration, and rationale bullets. For Coach, a grounded plain-language answer, optionally with links back to specific workouts in your history. For Memories, candidates with evidence pointing back at specific workouts.

Stone runs a server-side safety validator over the Today recommendation, Quick Log parses, and anything Stone learns about you, before those reach your device. It filters:

What the validator does not cover.

It only reads English. Its patterns are English phrases, and nothing in Stone tells the coach which language to answer in — it answers in yours. So if you write to Stone in another language the replies come back in that language, and this deterministic filter does not apply to them. What still applies are the coaching rules written into the model's instructions, which are language-independent, and Stone's refusal to diagnose is part of those. But the belt-and-braces filter described above is an English-only backstop today, and you should know that rather than assume otherwise.

Conversational replies in Coach, and the weekly and post-workout recaps, also do not pass through it. Those are governed by the coaching rules written into the prompt, plus a separate acute red-flag detector on the chat route that forces a stop-training-and-seek-care reply when your message describes something that needs a clinician rather than a coach. That detector is English-only too.

When your input mentions pain or injury, the safety validator forces a more conservative training-load suggestion and inserts a safety note pointing you at a qualified clinician. Stone never tries to diagnose.

Your controls

What Stone will never do

Open questions / honest limits