Privacy Policy
Incredible is built to be private. An Incredible account is optional, and the app works fully without one. There are no ads, no cross-app tracking, and we do not sell your data. For a short, plain summary of how your data is protected, see our security page.
Invite a friend and the monthly draw
If you use Invite a friend, our server keeps a ledger with a pseudonymous identifier for your phone (the App Attest key id, which does not identify you). While you are signed in, the ledger uses your account's identifier instead, which is linked to your account (your Apple user ID, email and name); after Delete Account the row keeps only that pseudonymous key. The ledger also holds your invite code, the code you entered if any, how many days the app was opened while an invite was pending (for a friend who joined through a challenge, the days their challenge progress went up and, after the first such day, also the days they opened the app), the time zone used to count those days, and the draw tickets you hold. The organizer reviews entries and keeps a record of ticket selections, announcements and shipping actions. We do not collect your date of birth. This is what makes the tickets and the avatars work. It is stored with Supabase in the EU (Stockholm). If you win the monthly draw and claim the prize, we ask for your name, postal address, country and email, keep them until the prize is marked as shipped, and delete them within the following 24 hours. Apart from those days of challenge progress, nothing from Apple Health enters this ledger. The rules of the program are at incredible-app.com/referral-rules.
If you allow notifications, our server stores your phone’s Apple push token to let you know when a friend uses your code, joins your challenge or cheers you. Apple receives the token and notification text, without invite codes, names or health data. You can turn notifications off in iPhone Settings. Delivery records are deleted after seven days, and unused push tokens after 90 days.
Who Is Responsible
Incredible is operated by Incredible AS, the controller for the personal data described here. Contact options are available at incredible-app.com/contact.
Data We Use
Incredible uses data you choose to provide or allow:
- Apple Health data, such as workouts, activity, heart rate, HRV, resting heart rate, sleep, respiratory rate, blood oxygen, temperature, body measurements, mobility, daylight, and related fitness metrics.
- Age and biological sex from Apple Health, when available, to calculate heart-rate zones.
- App data you create, such as workouts, routines, plans, exercise progress, optional check-ins, settings, imports, and preferences.
- Apple Watch workout and dashboard data when you use the Watch app.
- Messages, attachments, and the training summary that travel with each chat if you turn on the optional AI coach, as described in the AI Coach section.
- The coach reply, your last message to the coach, and any notes you write, when you rate a coach reply as unhelpful and send the feedback form.
- Location only for features that need sunrise and sunset times.
- Limited product analytics, such as app launches, onboarding completion, Health access requested or skipped, selected tabs, and general interaction events.
- Limited crash diagnostics, such as app version and build, device model and architecture, operating system version and build, crash type, and technical stack information.
- On our website, anything you type into the public request board, such as a bug report or a feature request and an email address if you choose to leave one, plus a random identifier stored in a cookie so your votes are counted once each.
Why We Use It
- App features: to provide daily training context, Fitness, Training Load, sleep, vitals, and workout insights.
- Sync: to keep supported app data available on your devices through private iCloud.
- AI coach: to answer your questions with replies grounded in your training data, if you turn the coach on.
- Payments: to process optional tips through Apple.
- Support: to answer requests you send us.
- Analytics: to understand basic product usage, improve reliability, and test the coach against feedback you send.
- Crash diagnostics: to find and fix crashes and watchdog terminations.
Legal Bases
For GDPR, we rely on:
- Contract: to provide app features you request.
- Consent and explicit consent: for Apple Health data, location, notifications, the AI coach, and optional permissions.
- Legitimate interests: for limited analytics, crash diagnostics, app security, and product improvement.
- Legal obligation: where we must keep records or respond to lawful requests.
You can withdraw consent in iOS Settings, Apple Health, or the app where available. Withdrawal does not affect processing that already happened while consent was active.
Apple Health
Apple Health data is read through HealthKit and processed on your devices to calculate Fitness, Training Load, sleep, vitals, and workout insights and to provide daily training context.
We do not send Apple Health data to analytics providers. If you turn on the optional AI coach and send it a message, a summary of your training and health data travels with that chat. If you explicitly join a Challenge, your agreed goal progress is also sent to our server, as described below. Neither feature shares this data until you choose to use it.
If you record or log certain activity in Incredible, the app may write workouts, activity totals, and sleep entries back to Apple Health. You can change Health permissions or delete Health data in Apple Health or iOS Settings.
Challenges
Challenges are optional. You agree to share your chosen name and your challenge progress with the other participants by tapping Invite when you create a challenge, or Join when you accept one, after the app has told you what is shared. Vercel processes and Supabase in the EU stores a pseudonymous device identifier, your chosen display name, challenge membership and invitation code, shared goal and dates, capped daily or weekly progress and its total, consent and sync times, and cheers. Progress may count workout days, workouts, training time, distance, or daily steps, and in the weekly Incredible Challenge also active energy. Weight goals share only the percentage toward your own target. In a strength challenge, the heaviest weight you lift on the chosen exercise during the challenge is shared with the people in that challenge, as your progress. Raw workouts, routes, heart rate, individual workout dates, body weight readings and body weight targets are not uploaded for Challenges.
Participants in the same challenge see your name, progress, sync time and cheers. Anyone with the invitation link can see the creator’s name, goal, dates and participant count, but cannot see other participants or progress before joining. Workouts can finish syncing for 48 hours after the challenge ends. Challenges ended more than 365 days ago and profiles inactive for 365 days are removed on the next request to the service. You can delete your challenge data in Challenge options. Leaving removes your progress and cheers and stops sharing. Removing a past result from your history keeps other participants’ results. Creators can delete a challenge before starting it. Membership is linked to your installation, or to your account while you are signed in. Without an account, reinstalling may create a new identity.
If you allow notifications, Incredible can send you a notification through Apple’s push service when a friend joins your challenge or cheers you. That notification carries no names, codes or health data. Joining a friend’s challenge counts as using their invite code for Invite a friend and the monthly draw, which links your installation to theirs in the same way as entering the code, so you cannot enter a code afterwards.
If you join the weekly Incredible Challenge, your progress toward it is stored with the same pseudonymous challenge identity as your other challenges, without your name. In a week about active calories, that progress is your total active energy for the week. Other people see how many joined, how many reached the goal, and how many people stand at each point of the progress bar, with the lowest, middle and highest progress there. People who joined also see their own place, and the place and progress of the leader and of the members just ahead of and behind them. Nobody sees your name or anything else that identifies you.
Account
Signing in is optional, and the app works fully without it. You can sign in with Apple, or with a 6 digit code we send to your email.
If you sign in with Apple, we store Apple's user ID for you, your email address or the private relay address Apple gives us and whether it is a relay address, the name you give us, when the account was created and last changed, and which app installations you signed in on, with when each one was linked. Apple sends us your name only the first time you sign in. Incredible never sees your Apple password. We keep the email only to recognise your account when you write to us about it, for example to ask for a copy of your data or to delete it. We send email only when you ask for a sign in code.
If you sign in with email, the address you type is stored as your account's identifier and shown in Manage Account. We also store the name you give us, when the account was created and last changed, and which app installations you signed in on. The code is sent by Resend, our email provider, works only on the iPhone that asked for it, and expires after 10 minutes. We store each code only as a scrambled value that cannot be turned back into the code or your address, and delete it within 2 days. An email account is separate from an Apple account, even when both use the same address. Delete Account works the same way for both, with no Apple step for an email account.
Nothing is copied when you sign in. The challenges, challenge name, invite code, draw tickets and founder messages of the first iPhone you sign in on become your account's, and follow you to a reinstall or another iPhone. On a later iPhone you see your account's data while you are signed in, and that iPhone's own earlier data comes back when you sign out. This is also the groundwork for a friends list, which does not exist yet.
Delete Account, in Settings, deletes your account, your name and email, your challenges linked to it, and your messages to the founder, including what the first iPhone you signed in on did while signed out, and, for an account made with Apple, asks Apple to revoke the sign in. Your workouts and health data are not affected, because they stay on your iPhone. Your ticket rows in the Invite a friend ledger stay, under your pseudonymous identifier only, because other people's tickets and draws already reference them.
If Apple tells us you withdrew consent or deleted your Apple Account, we delete your Incredible account the same way Delete Account does. If you turn relay email off or on, we update the stored email.
One iPhone installation belongs to one account for as long as that account exists. That keeps our fraud limits, such as the ticket cap, working the same way they do today.
Google Health
If you connect Google Health in Settings, Incredible reads your sleep, heart rate, resting heart rate, HRV, blood oxygen, breathing rate, skin temperature, steps, distance, energy, workouts, weight, body fat and VO2 max from the Google Health API and writes them into Apple Health on your device, under Incredible. That is how Fitbit and Pixel Watch data reaches the app. The connection is off until you turn it on.
You sign in on Google's own screen, and the access token stays in your device's keychain. The data goes from Google to your phone. None of it passes through our servers, and we never send it to analytics providers. Disconnecting revokes Incredible's access with Google, deletes the token, and removes everything the connection added to Apple Health.
Incredible's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
AI Coach
The AI coach is optional and off until you turn it on in the app. Nothing described here happens before that, and nothing is sent until you send a message.
When you chat, the app sends your message, any files or photos you attach, the recent conversation, and a summary of your training and health data, such as recent workouts, training load, sleep, readiness, your plan and goals, and body details like age, biological sex, and weight. While you are part-way through a strength workout, that summary also describes the session in front of you: the exercises, the sets you have logged, and the ones still to come. If answering needs more than the summary, the coach asks your phone for it, and that answer is sent too: individual workouts, exercise history, vitals, how a readiness score was reached, your plan, and your app settings. This goes to our server, which runs on Vercel in the European Union and passes it, through Vercel's AI gateway, to the provider serving the reply. Every such request runs under zero data retention: the gateway may only use providers under zero data retention agreements, currently Microsoft Azure serving OpenAI's model, and the request fails rather than falling back to any other route. Messages are also screened by OpenAI's moderation service for safety, which retains nothing under OpenAI's published retention table. The coach cannot browse the web.
The coach can also change things in the app, and it asks first every time. It can add a session to your schedule or move one, start, pause or end a training plan, create or change a goal or your race, adjust app settings, and change the workout you are in the middle of. Each of those arrives as a card that states exactly what will happen, and nothing changes until you tap to confirm. There are two deliberate exceptions, in opposite directions. Adding or skipping time on a running rest timer takes effect at once, because a countdown cannot wait to be confirmed. And the coach can never mark a set or a workout as done: what you have actually trained is yours to record. Changes are made on your phone and sync the way the rest of your data does.
The coach keeps a memory of useful facts it learns about your training so it can help you over time. That memory is stored on your device, not on our server and not with any other company. It travels with your messages to our server and the AI provider so the coach can read it, and neither of them stores it. After each reply the AI provider proposes what to add or change; your phone applies that and saves the result. You can switch memory off in the app at any time, and deleting it takes effect immediately because there is nowhere else to delete it from.
Conversations are stored on your device, not in a database of ours. Delete All Data in the app removes every chat and the coach's memory from your phone, and severs the random identifier your device uses so anything left cannot be connected to you. Because your chats and the coach's memory live in your phone's storage, they are included in your own device backups if you use them. Our server keeps short-lived technical logs, retained for about a day.
Nothing you write is used to train models, and nothing you write is kept: not by our server, not by the gateway, and not by the provider once the reply is written. The serving provider may process data in the United States; the Transfers section describes the safeguards.
You can rate a reply. Rating one down opens a form that asks what went wrong, and sending it shares that reply, your last message, and any notes you write with PostHog, our analytics provider, so we can test the coach against real failures. That text can contain training and health details, because that is what the coach writes about. Nothing is sent unless you tap Send on the form, a thumbs up sends no text at all, and deleting your chats does not remove feedback you have already sent.
Replies are generated by an AI model. They can be wrong, they are not medical advice, and they do not create legal effects or similarly significant decisions about you.
Message the founder is separate from the coach and works the same way as coach feedback: what you write, our reply, and technical details such as your app version, iOS version and an anonymous reference code travel to our server in Frankfurt and are stored in Stockholm until you delete the conversation in the app. The thread is stored under a pseudonymous identifier for your installation, or under your account while you are signed in. The founder reads it personally, and none of it is used to train anything. If you allow notifications, you get one when the founder replies. It only says that he replied: none of the conversation goes to Apple.
iCloud And Apple Watch
Supported app data can sync through Apple's private iCloud and CloudKit systems for your Apple ID. This may include routines, exercises, plans, completed strength sessions, progress, library organization, preferences, layouts, optional check-ins, and optional feature data.
This is separate from the optional Incredible account described above. If iCloud is unavailable or disabled, supported data stays local until sync is available again.
The iPhone and Apple Watch apps can exchange workout state, routines, daily summaries, Fitness, Training Load, sleep, and vital data using Apple's WatchConnectivity and HealthKit systems.
Imports And Exports
If you import workouts or routines from screenshots, the selected images are processed on device using Apple frameworks. Incredible stores the workout or exercise data you choose to save, not the screenshots.
Imported and exported files stay under your control. Anything you share outside the app is your choice.
Analytics
Incredible uses PostHog's EU-hosted analytics service for limited product analytics. We do not send Apple Health data, workouts, derived health and training insights, screenshots, names, email addresses, or account IDs to PostHog.
Coach feedback is the one exception, and you choose it: when you rate a coach reply as unhelpful and send the form, that reply, your last message, and your notes go to PostHog, and that text can contain training and health details. The AI Coach section describes it in full.
Chatting with the coach also records how the chat went, such as how long the reply took, how many tools it used, and what it cost to run. Those records never carry the text of a message or a reply.
Analytics is not used for advertising or tracking, and it is anonymous counts of which parts of the app get opened and whether they worked. If you want to object to this processing, contact us and we will handle it. The coach feedback form is separate: it only ever sends when you tap Send on it.
Our Website
The app and the website are separate. Nothing you record in the app reaches the website, and the website has no access to your Apple Health data. The one exception is a challenge invitation: its page and the picture shown with its link carry the creator’s chosen name and the goal.
The website carries a public request board where you can report a bug, ask for a feature, comment, and vote. What you write there is public. You can leave an email address so we can follow up, and leaving it is optional. Board content is stored by Supabase in Stockholm, inside the European Economic Area. To stop one person filing the same thing a hundred times we keep a one way scrambled form of your IP address, which we cannot turn back into an address, and a random identifier in a cookie so a vote counts once. That cookie exists to make the board work and nothing else. We also set a cookie to remember which language you are reading in.
The website uses Vercel Web Analytics for page view counts. It sets no advertising cookies, does not follow you to other sites, and does not store your IP address.
Crash Diagnostics
In production releases, Incredible uses Sentry's Germany data region to receive limited crash and watchdog diagnostics. These diagnostics help identify the part of the app that failed.
We configure the app not to send Apple Health data, workouts, derived health and training insights, names, email addresses, or account or user IDs to Sentry. We also disable network activity collection, including request and response bodies. We do not send source files, screenshots, view hierarchies, breadcrumbs, app logs, performance traces, or session replay. Sentry is also configured not to store IP addresses.
Two things beyond crashes. The app reports freezes, meaning the screen stopped responding for about three seconds or more. And once a day, the first time you open the app, it records whether overnight health updates arrived on time, with a technical log of when the system woke the app, how long it was given, and whether the device was locked. That log holds timings, battery level and outcomes. It holds no health values.
Crash and freeze diagnostics also reach PostHog, in the same anonymous form: what kind of crash, where in the app it happened, and how long a launch took.
Payments And Notifications
Optional tips are handled by Apple through StoreKit. Apple processes the payment and may share basic transaction status with the app. Incredible does not receive your payment card details.
If you allow notifications, Incredible may send local alerts such as a rest timer. These are generated on your device. Our server also sends a few notifications through Apple’s push service: when a friend uses your invite code, joins your challenge or cheers you, and when the founder replies to your message, as described above. We do not send marketing push notifications.
Sharing
We share data only where needed to run the app:
- Apple provides HealthKit, iCloud, StoreKit, WatchConnectivity, location, and notification services, App Attest, which confirms your copy of the app is genuine before the coach will answer, and Sign in with Apple, if you choose to sign in.
- Resend sends the sign in code when you choose to sign in with email. It receives your email address, the code and the language of the email.
- PostHog receives limited product analytics, crash and freeze diagnostics, and the coach feedback you choose to send, as described above.
- Sentry receives limited crash diagnostics as described above.
- Vercel hosts the server that handles AI coach chats, with function execution in the European Union, and routes those chats to the AI provider through its AI gateway. Vercel also runs the Challenges service and the optional account service, hosts our website and counts its page views.
- Supabase stores what people post to the public request board on our website, the Invite a friend ledger, Challenges, and the optional account.
- OpenAI receives coach chats and their training summary to generate replies and to screen messages for safety.
We do not sell personal data, use health data for ads, or track you across other companies' apps or websites.
Transfers
Apple, PostHog, Sentry, Vercel, OpenAI, and Resend may process data in countries where they operate. We use PostHog's EU-hosted service for analytics, Sentry's Germany data region for crash diagnostics, Vercel's European Union region for the coach server, and Supabase's Stockholm region for the request board, the Invite a friend ledger and Challenges. OpenAI processes coach data in the United States. Resend sends sign in codes from its EU region and processes and stores what it handles in the United States. We have a data processing agreement with each of them. Coach data reaching OpenAI in the United States is covered by standard contractual clauses, with EEA data processed by OpenAI Ireland. Sign in emails reaching Resend in the United States are covered by the EU-U.S. Data Privacy Framework and standard contractual clauses.
Retention
- Device and private iCloud data stays until you delete it, turn off sync, remove the app, or Apple deletes it under your settings.
- Apple Health data is controlled in Apple Health.
- Analytics data is kept only as long as needed for product usage and reliability, then deleted or aggregated. PostHog's retention rules may also apply.
- Sentry retains crash diagnostics for 30 days under the current plan.
- Coach chats stay on your device until you delete them. Coach memories are kept until you delete them in the app. Reply requests run under zero data retention and are kept by no one. Server logs live for about a day.
- Coach feedback you send is kept for as long as it is useful for testing the coach, including as a saved test case so the same failure can be checked against later versions of the coach.
- Posts on the public request board stay until the request is closed and cleared, or until you ask us to remove yours.
- Support messages are kept as long as needed to answer you and keep a record of the request.
- If you sign in, your account is kept until you tap Delete Account, until Apple tells us the sign in was revoked or your Apple Account deleted, or on a verified request.
- Sign in codes are deleted from our database within 2 days. Resend keeps each sign in email, with your address and the code, for 30 days. The code stops working after 10 minutes.
Security
We limit what we collect, avoid sending health data to analytics or crash diagnostics services, and rely on Apple's device, HealthKit, iCloud, and StoreKit security for the Apple services used by the app. No system is perfect, but we keep the data flow small and protected.
Automated Insights
Incredible calculates Fitness, Training Load, sleep, vital, and workout insights and provides daily training context from the data you allow. The optional coach generates replies with an AI model. None of this creates legal effects or similarly significant decisions about you.
Your Rights
If GDPR applies to you, you may have the right to access, correct, delete, export, restrict, or object to processing of your personal data. You may also withdraw consent.
Some data is only on your device, in Apple Health, or in your private iCloud, so the most direct controls are in the app, Apple Health, iCloud, and iOS Settings. In the app: Share Usage Data under Settings turns product analytics off, and Delete All Data in the coach's settings erases every chat and everything the coach has learned, immediately, because all of it is held on your phone. If you signed in, Manage Account in Settings shows your name and email, and Delete Account there erases the account as described in the Account section above. The full record, including your Apple user ID if you signed in with Apple, when the account was created and changed, and which installations are linked, is available on request.
You can make a request at incredible-app.com/contact. We may need enough information to verify and handle it. You can also complain to your local data protection authority.
Children
Incredible is not designed for children. If you believe a child has provided personal data through the app, contact us.
Changes
We may update this policy as the app changes. If changes are meaningful, we will make them clear in the app or on our website.