ReInvent / Reference
Privacy Policy
Last updated 2026-09-30
This page is the authoritative copy. The app shows the same text, and the
official PDF is the document of record — all three are
generated from one source and carry version ad5484c3.
ReInvent is a fitness, nutrition, and habit app operated by Sean McKeen (“we”, “us”). It is built local-first: your training, food, and habit data lives on your device. This policy explains the small set of data that leaves it, who we share it with, how it is protected, and the controls you have. Questions or privacy requests: [email protected].
What we collect
- Account details: your email address, your name, and a password (stored only as a salted hash by our authentication provider). These create and secure your account.
- Your content, when cross-device sync is enabled: food log entries, custom foods and saved meals, workouts, routines, personal records, habits, body-weight entries, points, goal settings, and profile details you enter (height, age, sex, body-fat estimate). This includes the sports sessions you log and their details — the kind of session, how long it lasted and how hard it felt, rounds and what happened in them, the techniques and notes in your technique notebook, your rank history, competition results, climbs and grades, swim sets, match scores, and the summary and route of a recording (see Location).
- Health & fitness data: the workout, sports, nutrition, and body-metric information above is fitness data; any Apple Health data you choose to connect is covered under Apple Health below.
- Cycle data, if you use it: period days, flow, and any symptoms you log stay on the device you logged them on. They are never uploaded to our servers, never synced between your devices, never included in analytics, never visible to anyone you share progress with, and never used to change any recommendation the app makes. You can delete all of it at any time from Settings → Cycle, which removes it immediately and permanently from that device.
- Photos: progress photos you attach to a workout are stored on your device and, when sync is enabled, backed up to a private storage bucket only your authenticated account can reach (via short-lived signed links). Photos of nutrition labels or meals are processed on your device only and are never uploaded.
- Analytics and diagnostics, only if you opt in: product-usage events (for example, “a widget was added”) and — a separate toggle you turn on by itself — basic error signals that help us fix problems (for example, that a scan failed, or that an Apple Health sync did not complete: a short reason code, never the image, the food, or anything you typed). These are OFF by default, contain no names, food text, notes, locations, or free-form input, and are never linked to your account or to any lasting device or advertising identifier. Each analytics session uses a random id that resets after about an hour, and events go straight to our analytics provider — never through an ad network or a tracking pixel. As with any internet request, the connection itself shows that provider your IP address. You choose this in Settings → Privacy & Data.
- Approximate location, only if you turn it on: if you enable Nearby restaurants, the app asks your phone for your position, immediately rounds it to a roughly five-kilometre square, and sends only that square to find chain restaurants in the area. It is off until you turn it on, it is only ever used while you have that screen open, and it is never stored — not on your device, not on our servers. See Location below.
- Precise location, only while you record: if you start recording a run, walk, hike or ride, the app uses your precise position for as long as that recording is running, so it can measure distance and draw the route. It is never used at any other time, and the route is kept only with the session you saved. See Location below.
- Purchases, if you buy a paid plan: which plan you bought, when, and the transaction identifier the store gives us. Our subscription provider receives your account identifier so the plan unlocks on every device you sign in on. We never see or store your card details — Apple and Google handle the payment itself.
- Feedback you send us: if you use the feedback form, we receive what you wrote, the category you chose, and your app version, kept with your account so we can reply to you in the app. It is free text and we do read it, so please leave out anything you would rather we did not see.
- A notification token, if you turn reminders on: the push token your phone’s operating system issues for this installation, kept with your account so a reminder can reach the right device, and passed to our delivery provider with the text of the notification. It identifies the installation rather than you, it changes if you reinstall, and turning notifications off removes it.
Apart from the location described above — a rounded area for nearby restaurants, and the route of a recording you start — we do not collect your location. We never collect your contacts, advertising identifiers, or biometric identifiers, and we do not track you across other apps or websites.
Apple Health
Every Health connection is opt-in, per data type, and off by default. Depending on what you enable, ReInvent reads weight, steps, sleep (including sleep stages, where your device records them), water logged in other apps, heart-rate variability, resting heart rate, respiratory rate, one-time profile details (height, age, sex), workouts recorded by other apps or your Apple Watch (the kind of activity, when it started and ended, and its distance), and — only if you enable it separately — the period days you log in Health. Workouts read from Health join your history as sessions, so if cross-device sync is enabled they are backed up like any other workout; ReInvent never writes them back to Health, and a workout you delete in ReInvent is never brought in again. Cycle data read from Health is read-only, joins the device-local cycle log described above, is never uploaded or synced, and never changes any recommendation. ReInvent writes nutrition, water, weigh-ins you log, and workouts — the kind of activity, its start and end time and, for distance sports, the distance — and, only if you turn it on separately, the route of a session you recorded. Each toggle requests only its own permission, and turning one on never enables another.
Heart-rate variability, resting heart rate and respiratory rate are read purely as context you can look at beside your training. They are shown only against your own recent range, are never combined into a score or a readiness figure, and never affect anything the app calculates — including muscle freshness, which is worked out from your logged sets alone.
We never sell or share Health data, never use it for advertising, marketing, or data mining, and never disclose it to third parties. Health-derived data is used only to show your own trends inside the app. Steps, sleep, heart-rate variability, resting heart rate and respiratory rate stay on your device and are never sent to our servers. Weigh-ins imported from Health join your in-app body-weight log, so if cross-device sync is enabled they are backed up to your account like any other body-weight entry; leave sync off (or the weight connection off) to keep them on-device only.
Location
Off by default. Everything in ReInvent works without it, and we never ask for your location until you use a feature that needs it. There are two such features, and they work very differently.
Nearby restaurants (approximate)
There are two separate steps, and both are yours:
- You turn Nearby restaurants on in Settings → Privacy & Data.
- Only then does your phone ask whether to allow location access. You can say no, and the rest of the app is unaffected.
What actually leaves your device. Your phone gives the app a position. Before anything is sent anywhere, the app rounds it down to a grid square of about five kilometres across and sends that square — not your position. We ask for coarse accuracy for this feature, and we round it regardless. Your device then works out the real distances to each restaurant itself, so the precise number never travels.
Who sees it. The square is passed through our own server to OpenStreetMap, a public map database, to look up which chain restaurants are in that area. It goes server-to-server with no name, no email, no account, and no device identifier attached. OpenStreetMap sees a request for an area; it does not see you.
The map, and how it differs. The Near me screen shows a map, and this is the one part that does not go through our server. To draw the map your device asks Apple Maps (on iPhone) or Google Maps (on Android) for the imagery directly, the way any app showing a map does. That request comes from your device, so Apple or Google sees your IP address and which area you are looking at — and because the map opens centred on you, that area indicates roughly where you are. We do not send them your position, and they do not receive your name, account, or anything you have logged. If you would rather not, the restaurant list works without the map and the chain menus work with location off entirely.
What we keep. Nothing. The restaurant location is not written to your device’s database, is not part of cross-device sync, is never included in analytics, is never attached to anything you log, and is never used for advertising. It exists for the length of one lookup and then it is gone.
Recording a run, walk, hike or ride (precise)
Only while a recording you started is running. Nothing is recorded until you press start. The first time, your phone asks whether to allow location access while using the app; ReInvent never asks for “Always” access. While the recording runs — including with your screen locked — your phone shows that an app is using location (the blue location indicator on iPhone, a persistent notification on Android), and the moment you finish or discard the recording, location use stops.
What stays on your device. While you record, each position is written only to the app’s encrypted local database on your phone. If you discard the recording, it is deleted.
What is kept when you save it. The session keeps a summary — distance, time, splits, elevation, your fastest efforts, and a simplified line of the route for its map. Before that line is saved, every point within a set distance of where you started and where you finished is removed from it (200 metres unless you change it in Settings → Privacy & Data, where you can also choose a wider distance or none), so the saved summary does not point at your front door. The full recorded route is kept separately so your own route map and splits stay accurate.
If sync is on. The summary is backed up with your other workouts, and the full route is stored as a file in a private storage area that only your authenticated account can reach, the same way progress photos are. If sync is off, both stay on your device.
Who sees it. No one else. Your route is never shared with other users unless you choose to share it, never included in analytics, never sold, and never used for advertising. When you open a session’s map, your device asks Apple Maps or Google Maps for the imagery of the area on screen, exactly as described for the Near me map above: they see your IP address and that area, and receive nothing you logged.
Deleting it. Deleting a session deletes its summary and its route file, on every device. Deleting your account deletes all of them.
Turning it off. Simply don’t record — or revoke location access in your phone’s settings. Recording is never started for you.
Where your data lives
Everything is stored on your device first, in a local database. If sync is enabled, your content is also stored with our backend provider (Supabase) under row-level security, so only your authenticated account can read or write it.
Food-database lookups (search, barcode) send only the search text or barcode number to our food-data service — never your log, identity, photos, location, or Health data. Label and meal scanning runs entirely on your device.
Who we share data with
We do not sell your personal information and we share it only with the service providers needed to run the app, each acting on our behalf:
- Supabase (authentication, database, file storage) — stores your account and synced content, including workout progress photos and the route files of sessions you recorded, in the United States.
- Aptabase (analytics) — receives only the opt-in usage events described above, in the United States. It never receives your name, email, logs, location, or any identifier that persists beyond the hourly session id.
- USDA FoodData Central and Open Food Facts (food databases) — receive only the food search text or barcode number you look up, forwarded server-to-server with no user identity attached.
- OpenStreetMap (map data for the optional nearby-restaurant lookup) — receives only a rounded, roughly five-kilometre area, forwarded server-to-server with no name, account, or device identifier attached. Only when you have turned that feature on.
- RevenueCat (subscription and purchase management) — receives your account identifier and your purchase history (which plan, when, and the store transaction id), in the United States, so a plan you bought unlocks on every device you sign in on.
- Expo (push notification delivery) — if you turn on notifications, receives your device push token and the text of the notification we ask it to deliver.
- Apple Maps (iPhone) and Google Maps (Android) — draw the maps on the Near me screen and on a recorded session. These are requests your device makes directly rather than through our server, so they see your IP address and the area shown on screen. They receive no name, account, route, or logged data from us, and nothing at all unless you open one of those maps.
- Apple and Google — distribute the app and process the payment for any paid plan. We never receive your card details. Apple Health data is exchanged only on your device under your control.
We may also disclose information if required by law, to protect our rights or users, or as part of a business transfer — in which case this policy continues to apply.
How your data is protected
- In transit: all traffic between the app and our servers is encrypted over HTTPS, with App Transport Security enforced (no cleartext connections).
- At rest on your mobile device: data written to the local database — including positions captured during a recording — is sealed with AES-256-GCM encryption using a device-only key held in the iOS Keychain / Android Keystore. On iOS this sits on top of an app-declared file-protection class; on Android it sits on top of the device-wide encryption Android applies to app storage. The key never leaves your device and is not stored on our servers.
- On the web version of ReInvent, local data relies on your browser’s built-in storage isolation and is not additionally encrypted at rest. The web version cannot record routes.
- If a security incident affects health or account information we hold about you, we will tell you — and, where the law requires it, the U.S. Federal Trade Commission — without unreasonable delay, within the time the FTC’s Health Breach Notification Rule (16 CFR Part 318) allows. The notice will say what happened, which kinds of information were involved, and what you can do about it.
No security measure is perfect; we cannot guarantee absolute security, but we work to protect your data in line with its sensitivity.
Your rights and choices
- You can access and correct your account and profile data directly in the app, and export your workouts, food log, and weight history as CSV files at any time (Settings → Privacy & Data).
- You can delete your account and its synced data at any time (Settings → Delete account), as described below, and delete any single session and its route from its own screen.
- You can turn analytics and Nearby restaurants on or off, and choose how much of the start and finish is removed from saved routes, at any time in Settings → Privacy & Data, and each Apple Health connection separately in Settings → Apple Health. Each of these is a per-device choice and each is off until you make it. Location for recording is used only when you start a recording.
- Depending on where you live (for example, under the EU/UK GDPR or the California CCPA/CPRA), you may have additional rights to access, correct, delete, or receive a portable copy of your personal data, and to object to or restrict certain processing. We honor these rights and do not discriminate against you for exercising them.
- We do not sell your personal information, and we do not “share” it for cross-context behavioral advertising — there are no advertising or tracking partners to opt out of, so there is no “Do Not Sell or Share” step to take. Because we run no advertising and no cross-site tracking, an opt-out preference signal such as Global Privacy Control has nothing here to act on; we do not currently read one.
To make any request, email [email protected]; we may need to verify your identity via your account.
International data transfers
Our providers store and process data in the United States. If you use ReInvent from outside the U.S., your information will be transferred to and processed there, which may have different data-protection laws than your country. By using the app you understand this transfer.
What we never do
No ads, no advertising SDKs, no cross-app tracking, and no selling of data — to anyone, ever. We do not use your data to train AI models, and nothing you log is sent to an artificial-intelligence service. Your coaching hints and insights are computed on your device from your own data.
Separately, and so this is not misread: much of the written exercise content in the catalog — descriptions, coaching cues, common mistakes, benefits and limitations — was drafted by an AI model while the app was being built. That happened on our side, before the content shipped, and involved none of your data. The Health & Fitness Disclaimer explains what that means for how to read it.
Retention and deletion
Your data is kept for as long as your account exists. When you delete your account (Settings → Delete account), we permanently remove your account and all synced data — workouts and sports sessions (including recorded routes), food log, body metrics, habits, points, settings, and progress photos — from our servers, and clear local data from the device. The removal is immediate, not scheduled.
Deleting your account does not cancel a paid membership. A subscription is billed by Apple or Google, and only you can cancel it, in your store account settings — we have no way to do it for you. So that nobody is charged for an account that no longer exists, the app asks you to cancel first and takes you to the right screen.
Two things outlive a deleted account, and these are all of them:
- A record that the deletion happened. We keep the date, whether it completed, a one-way cryptographic hash of your email address — not the address itself — and a note of which version of these documents you had agreed to. It exists so we can confirm we honored your request if you or a regulator later ask, and so we can answer someone who writes to us after deleting. It contains nothing you logged in the app.
- A published community exercise. If you submitted an exercise to the shared community catalog and it was approved and published, that catalog entry is de-identified and remains available to other users after your account is deleted.
You can export your workouts, food log, and weight history as CSV before deleting (note: CSV export covers those three data sets, not every item in your account).
Children
ReInvent is not directed to children under 13 (or the minimum age in your region), and we do not knowingly collect personal data from them. When you create an account we ask for your date of birth to check that you meet that minimum. We do not store it — it is used for the check and discarded; all we keep is the fact that you confirmed you meet the minimum age, and when. If you believe a child has provided us data, contact us at [email protected] and we will delete it.
Changes and contact
If this policy changes materially, we will update the date above and note the change in the app. For any question or privacy request, contact Sean McKeen at [email protected].