Privacy Policy
Ghisa does not require an account and does not ask for your name, email address, phone number, or other direct personal identifiers. Alessandro Bortoluzzi is the data controller for the processing described below and can be reached at ghisa@bortoluzzi.dev.
Data that stays on your device
Your workouts, exercises, routines, coach conversations, and settings are stored on your device. Workout data syncs through your own private iCloud database, which only you can access; we have no server that receives your training log and no way to read your iCloud data. Coach memories are kept on your device only and are never synced. If you allow it, Ghisa reads from and writes to Apple Health; that data stays under Apple's control and is not sent to us.
The exceptions are described in the two sections that follow: the analytics we collect, and the information you send to the AI features.
Analytics
Ghisa uses PostHog for product analytics, on PostHog's EU Cloud, hosted in Frankfurt. PostHog acts as our processor and only processes this data on our instructions. We use it to understand how the app is used, to find broken flows, and to run feature flags that decide which version of a feature you see.
PostHog processes:
- A randomly generated identifier for your install. It is not your Apple ID, your email address, or your device's advertising identifier, and it is not shared with anyone else.
- Events describing what happens in the app: workouts started and ended, programs created, imports attempted, paywall and onboarding steps, coach usage, and errors, together with technical properties such as event timing and duration.
- Onboarding answers, converted to ranges before they leave your device. Age, height, and weight are recorded as brackets (for example "70–79 kg"), never as the exact numbers you entered.
- The text of the messages you send to the AI coach — see the next section.
- Technical metadata: app version, operating system version, device model, language, time zone, and your IP address, which PostHog uses to derive an approximate location (country and region) and does not use to build an advertising profile.
We do not record your screen, and session replay is switched off. Analytics runs on the legitimate interest of understanding and improving Ghisa. You can object to it at any time by writing to us, and we will delete the events associated with your install.
RevenueCat, our purchase provider, is given the same PostHog identifier so subscription events can be attributed to the same install.
AI coach and AI import
The AI coach is a chat feature. You can type a message, dictate it, or attach up to four photos. Speech dictated to the coach is transcribed by Apple on your device; only the resulting text is sent onward. The AI program import works the same way for the text, photo, PDF, or scan of a training program you choose to import.
When you send a message, the following leaves your device:
- The text of your message and any photos you attached.
- The parts of your training data the coach needs to answer you — workouts, exercises, statistics, and the notes it has saved as coach memories. The coach requests these while it composes a reply; it does not receive your whole log up front.
- For AI import, the file or text of the program you are importing, which is uploaded to OpenAI's file storage for the duration of the import.
That request travels through AIProxy, a proxy service that keeps our API credentials out of the app. AIProxy stores metadata about the request — IP address, status code, token counts, and the response body of failed requests — and does not store the content of your messages. From there the request reaches OpenAI, which generates the reply.
OpenAI processes this data as our processor under its data processing terms and does not use it to train its models. Because the coach keeps context across turns, conversations are stored on OpenAI's servers for at least 30 days before deletion, and OpenAI keeps abuse-monitoring logs for up to 30 days. AIProxy and OpenAI are based in the United States, so this involves a transfer outside the EEA and the UK, made under the standard contractual clauses in OpenAI's data processing addendum.
Messages sent to the coach are also recorded in our analytics. The text of each message you send is attached to the corresponding analytics event in PostHog, so that we can read conversations back and improve the coach — its answers, its prompts, and the features it needs. The coach's own replies are not sent to analytics; only counts, durations, which tools ran, and any thumbs up or down you give. Because you decide what to write, please do not include anything in a coach message that you would not want us to read: health conditions, injuries, real names, or contact details.
If you would rather this did not happen, do not use the coach, or write to us and we will delete the messages recorded for your install.
Purchases
Ghisa uses RevenueCat to manage in-app purchases, subscriptions, purchase validation, entitlements, purchase restoration, and refund-related processing. RevenueCat may process anonymous app user IDs, purchase history, subscription status, transaction information, and related technical metadata.
By using Ghisa and making in-app purchases, you consent to our sharing of data regarding your usage and consumption of purchased content with Apple, as necessary to help Apple make informed decisions regarding refund requests, in compliance with Apple's policies.
What we do not do
We do not sell your data, use it for advertising, or track you across other companies' apps and websites. We do not send RevenueCat your workout data or your coach conversations. Apart from the message text described above, we do not send your training log to our analytics.
How long we keep things
Data on your device stays until you delete it or remove the app. Analytics events, including recorded coach messages, are kept for as long as they remain useful for understanding how Ghisa is used, and are deleted when they no longer are or when you ask us to delete them. Data held by OpenAI, AIProxy, and RevenueCat follows those providers' own retention periods, described above where we know them.
Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to the processing of your personal data, and to complain to your local data protection authority. Because Ghisa has no account, we identify your data by the analytics identifier for your install; we may ask you for it, and you can find it by contacting us from the device in question. To exercise your rights or ask privacy questions, contact:
Alessandro Bortoluzzi ghisa@bortoluzzi.dev
We may update this Privacy Policy from time to time by posting a new version with an updated effective date.
Effective date: August 21, 2026