← BACK TO SETTINGS

Privacy Policy

Last updated 13 September 2026. FAILURE is operated by [OPERATOR NAME AND POSTAL ADDRESS — TO BE ADDED], the data controller for the information described here.

What is collected

Nearly everything FAILURE holds is health data, which UK GDPR treats as special category data. It is processed on the basis of your explicit consent, given when you create an account and when you connect Whoop.

  • · Your email address, and a password if you set one.
  • · Training: sessions, exercises, loads, reps, conditioning and your weekly schedule.
  • · Food and drink: meals, calories and macronutrients, sugar, alcohol, water, favourites and scanned barcodes.
  • · Body: bodyweight, measurements, estimated body composition and progress photos.
  • · Whoop, if you connect it: recovery score, heart rate variability, resting heart rate, sleep duration and performance, daily strain, step count and workouts.
  • · Messages you send to the in-app coach, and the recent data given to it as context.

There is no analytics, no tracking, no advertising and no profiling beyond the training and nutrition guidance the app exists to give you.

Where it is stored

A copy is kept on your device so the app works offline, and a copy is stored in a managed cloud database and file store hosted in the EU by Supabase, our processor. Every record is tied to your account and protected by row-level access rules, so no other user can read it. Progress and meal photos are held in a private bucket that only you can read; the files are not reachable by URL.

Third parties

  • · Meal and equipment photos, and coach messages are sent to a third-party AI provider (Google Gemini, via the Lovable AI gateway) to produce the estimate or the reply. The provider is not permitted to retain them for training and they are not stored by the gateway, but the image or text does leave our systems. If you would rather that did not happen, enter the food manually or scan the barcode instead of photographing it.
  • · Whoop data is read through the official Whoop API with your explicit consent, read-only, and never shared onward. Your Whoop access is held on our server, not on your device, and is revoked at Whoop when you disconnect or delete your account.
  • · Open Food Facts is queried for the product behind a barcode. Only the barcode is sent; nothing about you is included.

How long it is kept

For as long as your account exists. When you delete your account, the database rows, the stored photos, the Whoop token and the login itself are deleted immediately and the copy on your device is wiped. Deletion is permanent and cannot be undone. Backups held by our hosting provider roll off within 30 days.

Your rights

You can export everything the app holds about you from Settings, at any time, in a machine-readable file. You can delete your account and all associated data from Settings, behind a typed confirmation. You also have the right to correction, to restrict or object to processing, to withdraw consent (disconnect Whoop, or delete your account), and to complain to the Information Commissioner's Office at ico.org.uk.

Contact

ricardo.chamberlain24@gmail.com

[OPERATOR POSTAL ADDRESS TO BE ADDED. No data protection officer is appointed.]