Stone — Privacy Policy
Last updated: 2026-08-27. Policy version 2026-08-27.
Stone is a workout log and training assistant. This policy describes what Stone does and does not collect, where data lives, and the controls you have.
We've tried to write this in plain English. Where a paragraph intentionally has no marketing varnish, that's by design.
At a glance
- Your workouts live on your device, and back up to your private iCloud by default. iCloud Sync is on out of the box so your training is safe and consistent across your devices — that copy is in your iCloud, not Stone's servers. You can turn iCloud Sync off in Settings.
- Cloud AI is off until you turn it on. Nothing goes to Stone's backend or to its AI provider until you accept it in onboarding. Once it is on, real detail leaves your device on coaching calls: your recent sets with their weights and reps, your workout notes, the injuries and avoided movements you typed, and your Coach messages. Anything you dictate or photograph is sent to be transcribed or read. It is processed by Stone's backend on Cloudflare and then by xAI (Grok).
- Apple Health is off by default. Stone reads seven types and writes two. Heart rate and HRV are reduced on your device to a category like "recovered" or "run down" and never leave as numbers — but your body weight, and your biological sex, age and height, DO go to the cloud with Cloud AI on. Turning Apple Health off stops that.
- You can delete everything any time — local data, iCloud mirror, AI memory, and Stone's server-side rate-limit + safety counters — from Settings ▸ Privacy & Data ▸ Delete all my data.
What we collect — and where it lives
On your device, and mirrored to your private iCloud by default
- Your workouts (exercises, sets, weights, reps, durations, notes).
- Your training profile (when you fill it in).
- AI memories you've accepted (statements like "trains push days on Tuesday afternoons" — only if you opted into Cloud AI and accepted the proposal).
- AI request log — one row per cloud call (which retention policy applied, tokens, estimated cost). Stone keeps the newest 500 and deletes older ones automatically. This table is part of your iCloud sync, so those rows reach your other devices like the rest of your training data — they are not sent to us.
- Cached learned aliases (e.g. you corrected "incline db" to "Incline Dumbbell Press" and Stone remembers).
- Custom exercises you've added (when an entry doesn't exist in Stone's seed library and you save it).
- Your gyms and what Stone has learned at each — the gyms you've named, the exercises you've pinned there, a per-exercise count of how often you've trained each one at that gym, and any you've marked "not here." This is what makes each gym's suggestions adapt to the place; it's derived from your own training and never includes anything you didn't do.
- The coach's standing order — a short private plan it writes for itself over the next handful of sessions: what it's working toward, whether load should climb or ease off, and whether it has scheduled a lighter day. Written only if you opted into Cloud AI. It's kept because a coach that forgets its own plan every morning isn't coaching, and it's private in the sense that Stone never shows you the note verbatim — it's written as a reminder to itself, not as a message to you. It IS part of your data: it syncs to your iCloud, it's in your export, and "Delete all my data" removes it. Earlier versions are kept rather than overwritten so the reasoning behind a past change is still there when you look.
Because iCloud Sync is on by default, this same data is mirrored to your private CloudKit container under your iCloud account (turn it off in Settings to keep everything strictly on-device). Apple, not Stone, operates iCloud and applies its own iCloud privacy terms.
Apple Health (HealthKit) — when you turn it on
Apple Health integration is off by default. If you turn it on in Settings ▸ Apple Health, Stone can:
Read eight types: body mass, resting heart rate, heart rate variability (HRV), your heart rate during a workout, your workouts from any app, and your biological sex, date of birth and height.
What leaves the device differs by type, and the difference matters:
Workout heart rate is read only to show you the average and peak for a session you already logged. It stays on your device — it is not stored by Stone and never sent anywhere.
Resting heart rate and HRV are compared to your own baseline on your device and reduced to a category ("recovered", "run down"). The numbers themselves never leave.
Your body weight, and your sex, age and height, are sent to Stone's backend and on to xAI when Cloud AI is on, so the coaching can scale to you. Body weight goes as a short trend sentence ("steady around 82 kg") — that wording contains the number, so treat it as sent. Switching Apple Health off stops everything Apple Health supplied, including values Stone had already read. It does NOT stop a sex, age or height you typed yourself in Settings ▸ Preferences — that is your own input to the coach, not a Health reading, and it keeps being sent until you clear it there.
Your workout history from other apps informs what Stone recommends.
Write two types: finished workouts as HKWorkout records, and body-weight entries. Each is a separate opt-in toggle, off by default. Writes go straight to Apple Health via the on-device API and do not transit Stone's servers.
Deleting a workout in Stone also deletes the workout entry it wrote to Apple Health. Two things it does NOT delete: body weight entries Stone wrote, and anything at all under "Delete all my data" — that path never touches Apple Health. Remove those in the Health app.
Per Apple's HealthKit terms: Health and fitness data is processed by Stone solely in accordance with your consent, used only to provide and improve the app's functionality, and is not shared with any third party for advertising or data-broker purposes.
You can revoke any HealthKit permission at any time via the Health app → Sharing → Apps → Stone. When write permission is revoked, Stone surfaces a specific error if you try to log body weight through the in-app sheet, rather than silently failing.
Sent to Stone's backend only when you've opted in
- Your recent training in detail — up to 160 individual sets with their weights and reps, your workout names and notes, your goal and focus, the injuries and avoided movements you typed, your gym's equipment, your custom exercise names, and the patterns Stone has learned about you. This is not a summary.
- Your Coach messages, with the recent conversation for context.
- The coach's own notebook — short notes the model writes about your training, kept on your device and sent back up on later calls.
- When you dictate: the audio recording itself, so it can be transcribed. When you scan a workout: a copy of the photo, so it can be read. Neither is kept after the call.
- Your Apple Sign-in identity token, if you've signed in with Apple. Used only to verify your identity for elevated quotas; never stored beyond the lifetime of the request.
- A device-integrity check that proves the call came from a real Stone install on a real device. It is not your name, your email or a device serial number, and it is not shared with anyone — but it is stable for as long as the app is installed, so it does tie your calls together. Signing in with Apple adds your Apple subject identifier alongside it.
The request passes through Stone's own backend (hosted on Cloudflare) to its AI provider, xAI. Stone's backend passes requests through rather than keeping them, with three exceptions it does store:
- The automatic "learn from my training" pass — which runs at most once a day, after you finish a workout, open Today, launch the app, or overnight — stores its request for 24 hours so the result can be re-checked when it comes back.
- A five-minute cache of a scanned photo, so re-scanning the same image doesn't cost a second call.
- Any feedback note you write on an answer, kept 30 days. "Delete all my data" removes these.
Cloudflare additionally retains request metadata (timestamps, status codes, byte counts) to monitor cost and abuse, per its own gateway documentation.
Sent to xAI
xAI receives the model input and produces the response. As of the policy version stamped above:
- xAI does not use API requests to train its models by default.
- xAI retains API data only for a limited period under its own API policy.
- Stone embeds the policy version in effect on the day of each call, so historical AI Use entries continue to reflect the policy that applied at the time — not whatever xAI's policy says today.
xAI's terms apply directly to API data sent on Stone's behalf: see x.ai/legal.
Third-party processors
Stone uses the following third-party services to operate. Each processes data on Stone's behalf only for the purposes described.
| Processor | Purpose | Data they see | Their policy |
|---|---|---|---|
| Apple (iCloud + CloudKit) | Optional encrypted backup of your workouts | The same fields as your local store, if you turn on iCloud Sync. Encrypted in transit and at rest by Apple. | Apple Privacy |
| Apple (Sign in with Apple) | Optional sign-in for elevated cloud-AI quota | Your Apple ID's stable per-app subject identifier, optionally a relay email | Apple Sign in with Apple |
| Apple (device-integrity check) | Proves a cloud call came from a real Stone install | A non-correlatable cryptographic token — no personal identifier | Apple Developer Docs |
| Cloudflare | Hosts Stone's backend + routes AI calls | The request itself in transit, plus retained metadata (timestamps, status, byte counts). Most AI calls also pass through Cloudflare's AI Gateway. | Cloudflare Privacy |
| xAI | The AI models behind coaching, chat, parsing, dictation and photo reading | Everything listed under "Sent to Stone's backend" above — your training detail, your messages, and any audio or photo you send | xAI Legal |
We do not transfer your data to any party other than those listed above.
What we do not collect
- We do not collect your name, email, phone number, or location unless you explicitly type one of them into a workout note.
- We do not collect HealthKit data unless you turn on Apple Health in Settings. With it on, your heart-rate and HRV numbers stay on your device (only a category leaves), but your body weight and your sex, age and height are sent on cloud calls. See the HealthKit section.
- We never ask for your contacts or your calendar.
- We do not read your email address. Sign in with Apple is requested with name scope only.
- We do not advertise. We do not have third-party trackers.
- We do not sell, rent, or share your personal data with any third party for advertising, data-broker, or "sale" purposes (CCPA-defined).
Automated decision-making
Stone's Cloud AI generates recommended workout sessions and parses your freeform Quick Log notes. These are decisions made by an automated system (xAI Grok via Stone's backend).
- These decisions do not have legal or similarly significant effects on you (they're workout suggestions).
- You can turn Cloud AI off in Settings ▸ Cloud AI at any time, in which case Stone falls back to its on-device deterministic recommender and parser.
- Every cloud call is recorded in Settings ▸ Privacy & Data ▸ AI use with the provider, the shape of data sent, the retention policy that applied at the time, and the response status. You can audit which inputs produced which outputs.
- While Cloud AI is on, Stone also keeps the full text of each call — what it sent about you and what came back — in a rolling log on your device. This is what makes it possible to work out why the coach said something, which was previously impossible to answer after the fact. That log is device-only: it is never synced to iCloud, never included in a backup, and never sent anywhere. It covers roughly the last two to three weeks and then overwrites itself. Turning Cloud AI off stops it being written; Forget AI memories and Delete all my data both erase it.
Data retention
| Data | Where stored | Retention |
|---|---|---|
| Workouts, training profile, custom exercises | Your device (+ optional iCloud mirror) | Until you delete them via Settings ▸ Privacy or by deleting the app |
| Your gyms + what Stone learned at each (pins, per-gym training counts, "not here" marks) | Your device (+ optional iCloud mirror) | Until you delete the gym, tap Start fresh in My Gym, or Delete all my data |
| AI memories | Your device (+ optional iCloud mirror) | Until you tap Forget AI memories or Delete all my data |
| AI request audit log | Your device | Until you tap Forget AI memories or Delete all my data |
| AI call log — the full text of what Stone sent to the AI about you and what came back | Your device only. Never synced to iCloud, never backed up, never sent anywhere. | A rolling window of roughly two to three weeks, then automatically overwritten. Cleared immediately by Forget AI memories, Delete all my data, or Clear AI call log |
| Quick Log learned aliases | Your device | Until you tap Delete all my data |
| Proxy metadata (never the request body) | Cloudflare | Per Cloudflare's gateway retention defaults |
| xAI inference data | xAI | A limited period per xAI's API policy at the time of the call |
| Feedback notes you write on an AI answer | Stone's backend | 30 days, or until you tap Delete all my data |
| The automatic "learn from my training" request | Stone's backend | 24 hours |
| A scanned photo, for de-duplication | Stone's backend | 5 minutes |
| Device-integrity record | Stone's backend | Until you tap Delete all my data, which clears the server-side record |
| Sign in with Apple subject identifier | Stone's backend (only if you signed in) | Until you sign out + tap Delete all my data |
Sign in with Apple
Sign in with Apple is optional. If you sign in:
- Apple gives Stone a stable per-app identifier (Apple's "subject" claim). We use it to switch your cloud-AI quota from the per-device anonymous limit to a higher per-account limit.
- Apple may send a relay email address to Stone if you chose "Hide My Email". Stone currently has no email server so the address is not used. If we ever add account features that send email, we will say so before turning them on.
If you sign out of Sign in with Apple inside Stone, the credential is removed from this device. Apple's record of the sign-in stays under your iCloud account settings — Apple, not Stone, controls that.
Your rights and controls
Stone gives you direct in-app controls for every right described below. You don't need to email us to exercise them — but if you prefer, see "Data requests" below.
Rights under GDPR (EU users)
- Right to access (Article 15) — Settings ▸ Privacy ▸ Export your data produces a complete copy in JSON. CSV and Markdown are convenience formats and carry your workouts and sets only.
- Right to rectification (Article 16) — Edit any workout or AI memory directly in the app.
- Right to erasure (Article 17, "right to be forgotten") — Settings ▸ Privacy & Data ▸ Delete all my data (three-step confirmation; local + iCloud mirror + server-side counters).
- Right to restrict processing (Article 18) — Toggle Cloud AI off; toggle iCloud Sync off; revoke HealthKit in Health app.
- Right to data portability (Article 20) — The Export above produces JSON suitable for re-import elsewhere.
- Right to object (Article 21) — Cloud AI is opt-in; you can withdraw consent any time via Settings ▸ Cloud AI.
- Right not to be subject to automated decision-making (Article 22) — See the "Automated decision-making" section above.
Rights under CCPA / CPRA (California users)
- Right to know — Settings ▸ Privacy & Data ▸ AI use and Settings ▸ Privacy ▸ Export your data show every cloud call + every category of data collected.
- Right to delete — Settings ▸ Privacy & Data ▸ Delete all my data.
- Right to correct — Edit any workout or AI memory in-app.
- Right to opt-out of sale or sharing — Stone never sells or shares personal data with third parties for "sale" or "sharing" as those terms are defined under CCPA. No action needed.
- Right to limit use of sensitive PI — All cloud-AI processing of training data is gated behind the Settings ▸ Cloud AI toggle, which is opt-in. HealthKit reads + writes are separately gated.
Concrete controls
Settings ▸ Cloud AI — toggle cloud AI on or off. Off is the default until you grant consent at onboarding.
Settings ▸ Apple Health — toggle HealthKit reads + a separate toggle for workout writes. Both default off.
Settings ▸ Sync ▸ iCloud Sync — toggle CloudKit sync. Turning it off keeps the existing iCloud data; Stone just stops mirroring new changes until you turn it back on.
Settings ▸ Privacy ▸ Export your data — JSON is the complete copy of everything Stone stores about you: your workouts and sets, body weight, exercise notes, gyms, templates, your conversations with Stone, the AI memories it has learned, the coach's own notebook, the recommendations it made and the reasoning it gave, and the AI request audit log with the policy version pinned per row. CSV and Markdown are convenience formats covering your workouts and sets only.
The JSON file is not redacted. It contains your notes and your chat with Stone word for word, so treat it the way you'd treat a copy of your journal.
Settings ▸ Privacy ▸ Forget AI memories only — removes the audit log + AI memories. Your workouts stay.
Settings ▸ Privacy & Data ▸ Delete all my data — three-step confirmation (review → confirm → type "Delete my Stone data"), then a full local + CloudKit + server-side wipe.
Settings ▸ Privacy & Data ▸ AI use — read-only audit log of every cloud call with the provider, data shape sent, retention copy, and policy version.
Data requests
For data-subject requests not covered by the in-app controls (rare — the in-app controls already give you everything in your local, iCloud, and server-side data), use the contact method in Settings ▸ About (see Contact below).
Changes to this policy
We'll update the version stamp at the top of this file when this document changes. Each AI request audit row preserves the policy version that applied at the time of that request, so historical data stays interpretable even after the live policy moves. Material changes that broaden what we collect or send to third parties will also be surfaced as an in-app notice on next launch.
Children
Stone is not directed to children under 13 within the meaning of the Children's Online Privacy Protection Act (COPPA). If you believe we have inadvertently collected information from a child, contact us and we will delete it.
Governing law
This policy and your use of Stone are governed by the laws of the State of California, United States, without regard to conflict-of-laws principles. EU users retain the rights described in the "Rights under GDPR" section regardless of governing-law choice.
Contact
During the TestFlight beta, reach the developer through TestFlight feedback — the reply-to on your TestFlight invite reaches us directly. A dedicated privacy contact address ships with the public release and will appear in Settings ▸ About and on the App Store listing.