Legal
Privacy Policy
Last updated · June 2026
Our promise
Privacy is not a feature we added. It is the principle the whole system is built on: your workout data belongs to you, and only you.
- All processing happens on-site at your gym
- No images are ever stored
- Only anonymous movement is analysed, never an image
- You control all of your workout data
Contents
Information we collect
Your email and a username, plus your workout history. No images, ever.
Account information. When you create an account we collect your email address and the username you choose. That is it.
Workout data. We store your exercise history, including exercises performed, reps, sets, and estimated weights, linked to your account. It contains no biometric or identifying visual information.
What we do not collect. We never store or record images. Visual frames are read in real time to detect movement, then immediately discarded. We never perform facial recognition or collect biometric identifiers.
How we process data
Everything visual is handled on a device inside your gym and discarded in real time.
Our edge models process all visual data locally at each gym. Here is what happens:
- The gym's motion-capture feed streams to an on-premise edge device.
- Models read frames in real time to detect equipment and movement.
- Anonymous keypoints are extracted for exercise recognition.
- Only the workout summary, with no visual data, is sent to your app.
- Every frame is discarded immediately after it is read.
Data storage and security
Workout summaries are encrypted in transit and at rest.
Your workout summaries are encrypted with 256-bit AES and stored on secure servers. We follow industry-standard practices, including:
- Encrypted transmission (TLS 1.3)
- Encrypted storage at rest
- Regular security reviews
- Strict access controls
Your rights
Access, correct, export, or delete your data at any time.
- Access. Download all of your workout data whenever you like.
- Correction. Edit or delete any workout record.
- Deletion. Delete your account and everything tied to it.
- Portability. Export your data in standard formats.
Compliance
Built around GDPR, CCPA, and the Australian Privacy Principles.
atheo is designed to meet global privacy regulations including GDPR, CCPA, and the Australian Privacy Principles. Processing on-site means sensitive data never leaves the gym, which goes further than most regulations require.
Updates to this policy
We post changes here and update the date above.
We may update this policy from time to time. We will post the new version on this page and update the “Last updated” date.
Contact us
Questions about this policy or our data practices? Email privacy@atheo.ai.
See also our Terms of Service and how we keep things safe on the Security page.