Your information
Privacy at baseline.
Your workouts, your choices, and how we handle your information.
Effective date: 28 September 2026.
Baseline and your information
Baseline is operated by Xuan Loc Le. It helps you record workouts, maintain a training commitment, and participate in its fitness community. This policy describes the iOS app, its connected services, Baseline Plus subscriptions, and our support and privacy website.
Privacy contact: 24m2space@gmail.com, attention Xuan Loc Le. You can contact us about your information, an export or deletion request, or a privacy concern.
Information you provide and information created by using Baseline
- Account and profile. Connected features create a persistent guest account. We store its account identifier, public alias, and any display name, biography, avatar, Sigil customization or gym affiliation you provide. The guest credential is stored in this device's Keychain. The current app does not provide account linking or recovery on another device. Losing the credential may mean losing access to that Social identity; an export is not a login backup.
- Training and health-related information. Workouts are saved on your device. Connected features also send private workout evidence and training schedules to Baseline's servers under your account, including exercises, sets, repetitions, loads, timing and training commitments. User-entered body weight and other inputs can form part of saved workout records. Local settings and recovery archives may contain additional training preferences. Baseline does not currently read Apple Health or HealthKit data.
- Community content and relationships. We store posts, comments, reactions, follows, blocks, hidden posts, profile and gym information, and photos you choose to upload. Reports and gym-ownership claims include information you submit to help us review them. Following relationships are an in-app social graph; the app does not request your iPhone address book.
- Private messages. We store message content, attachments and shared content, sender and conversation information, reactions, delivery information and read receipts. These are used to deliver messaging and support safety and account-management features. Messages are stored by our service and are not end-to-end encrypted.
- Activity and searches. We store account-linked feed impressions, reading time, opened posts and reactions to rank the feed and remember interactions. Some searches, including Board searches, are retained with pagination records. Exercise-catalog search and selected-file processing can happen locally.
- Subscriptions. Apple processes App Store payments. RevenueCat receives purchase and subscription information and your Baseline account identifier to verify purchases, restore access, provide Baseline Plus entitlements and support subscription reporting and analytics. Baseline does not receive your payment-card or bank-account details from this purchase flow.
- Notifications and technical information. If you enable private-message alerts, we register an Apple push-notification token associated with your account. Requests to our services also involve network information. Our backend uses a hashed IP address for guest-registration rate limits and records error categories and request identifiers to diagnose service failures. Hosting providers process request and operational information as part of running the service.
- Support requests. If you email us, we receive your email address and the information you include so we can respond. Send only information needed for your request. Our support and privacy website has no analytics scripts, web forms or cookies set by Baseline; its hosting provider processes network requests to deliver and protect the pages.
How we use information
We use information to provide and restore workouts, synchronize records for the same identity, calculate training progress and commitments, display profiles and community content, deliver messages and optional notifications, personalize the feed, administer purchases, prevent abuse, handle reports and support requests, and maintain the service. RevenueCat also provides subscription analytics.
Baseline does not contain advertising features or use an advertising identifier. We do not combine your information with other companies' data for advertising, or share it with data brokers.
Safety and content review
We check submitted text against automated safety rules. New media attachments are held privately for review by an authorized human reviewer before they can appear in profiles, posts or messages. This includes attachments intended for private messages. Reviewers can access submitted attachments and report details to decide whether content can be shared or needs to be removed. We keep review decisions and account-restriction records to operate these safety features. We do not send content to an external AI moderation service.
You can report posts, comments, private messages and profiles, and block other members. Content may be withheld or removed, and accounts may be restricted, when they violate our community rules. The support page explains how to report a concern.
What other people can see
Every Social account has a global Board entry. Other people can see its public alias, Sigil and commitment status. Profiles, gym affiliations, and content you publish may also be visible to other people. Post visibility follows the audience available for that post. Private workout records and user-entered body weight are not themselves displayed on the Board.
Automatic workout sharing requires your confirmation before the first automatic post. The app offers automatic sharing, but holds workout summaries privately until you choose to allow it for the current account. After you agree, completed workouts can create public summary posts, including exercise names, set count, duration and available workout totals. You can choose to keep workouts private or turn automatic sharing off in Settings. Turning it off cancels pending automatic posts; it does not remove posts already published or stop private training synchronization. A manually shared post can also include a workout summary. Consider the contents and audience before sharing.
Messages are available to the people in the conversation and are processed by the service to provide messaging and safety features. People who receive or view content may retain their own copies, such as screenshots or exports.
Service providers and permissions
Baseline uses Cloudflare services to run its backend, databases, media storage, queues and realtime features. It uses Apple for App Store purchases and optional push delivery, and RevenueCat for subscription processing and analytics. These providers process information needed for those functions. Their own privacy policies also describe their services: Apple, Cloudflare, and RevenueCat.
Photo and file selection use iOS pickers. Only the items you select are made available to those features. Camera access is requested for scanning profile codes; there is no continuous location access or address-book permission in the current app. You can control camera and notification permissions in iOS Settings. Your chosen gym associates your profile with its locality and helps personalize your feed with content from that gym. This can reveal your approximate locality even though the app does not use GPS or determine your precise device location.
Keeping, exporting and deleting information
Local workouts remain on your device independently of the Social account. Settings provides workout archive tools. Social's Privacy & Data screen provides an account export, including available Social records and original uploaded media. Exports may contain private information; you control where you save or share them.
Account profiles, private synchronized training records and community content are retained to provide the features you use until you change or delete them, or delete the account. Temporary search/feed pagination records and recent feed-interaction records have expiry rules and are removed by scheduled cleanup. Cleanup retries can delay removal; an expiry rule is not a guarantee that every provider copy disappears at that instant.
To delete the Social account, open Privacy & Data → Delete Account and confirm. If the app says confirmation is pending, retry the saved request rather than assuming deletion has finished. After confirmed deletion, the service revokes the guest credential, removes the Board entry and private server training records, removes account relationships and push registrations, clears profile details, and redacts published text and messages. Uploaded-media cleanup may complete asynchronously after access has been removed.
Some deletion receipts, record identifiers and moderation-related information remain after account deletion and currently have no automatic expiry. These records support confirming deletion, preventing replayed requests and reviewing safety incidents. Public gym entries may also remain after the creator's account is deleted. Deletion does not remove copies that other people saved, or automatically remove Apple/RevenueCat purchase records, provider operational logs and backups. Contact the privacy address if you need help with information that remains.
Deleting a Social account does not delete workouts saved on this device, erase copies you exported elsewhere, or cancel an App Store subscription. Manage or cancel a subscription through Apple. Apple and RevenueCat purchase records are separate from Baseline's Social-account deletion operation.
Changes and contact
We will update this policy and its date when the described practices change. For questions, access or correction requests, or help with deletion, email 24m2space@gmail.com. We may need information to verify that a request concerns your account. Never send a guest credential, password or verification code. Send a private workout archive only if it is needed for your request and you intend to share it.