Back

Privacy Policy

What PerformOS collects, why, and who else can see it.

Last updated 2026-08-07

Who controls your data

Zuhair Ahmad is the data controller for information collected through PerformOS. Contact us at support@perform-os.me or Delhi, India.

What we collect

Account — email address, name and profile photo if you sign in with Google. Handled by our authentication provider; we never see your password.

Health and training data — age, sex, height, body weight, injuries, soreness, sleep, energy, training sessions and the loads you lift. This is sensitive personal data. We collect it because a plan built without it would be generic, and a plan built without your injuries could hurt you.

Usage — pages visited and features used, so we can find where the product is confusing.

Payment — handled entirely by our payment provider. We never see or store your card details. We record that a purchase happened, what it was for, and how many credits it granted.

Why we use it

  • To generate your training and nutrition plans.
  • To run the automated safety checks that keep a plan within your injury restrictions.
  • To adapt your plan when your soreness, sleep, adherence or schedule change.
  • To operate your account, process purchases and provide support.
  • To understand which parts of the product work, in aggregate.

AI processing

Generating a plan sends a summary of your profile — goals, injuries, available equipment, schedule and recent training — to our AI provider. It is used to produce your plan and returned to us.

We do not send your name, email address or any direct identifier. We use paid API tiers, on which the provider does not use submitted data to train their models.

Who else processes your data

We use these providers, and no others:

  • Clerk — authentication and account management
  • Neon — the PostgreSQL database holding your data
  • Google (Gemini API) — AI generation, as described above
  • Razorpay — payment processing
  • Render — application hosting
  • Upstash — caching and rate limiting; no personal data is stored
  • Sentry — error reporting, with personal data scrubbed
  • PostHog — product analytics

We do not sell your data. We do not share it for advertising. We share it with the providers above only to the extent they need it to do their job.

How long we keep it

For as long as your account exists. Delete your account and we remove your personal data within 30 days, except records we must keep for tax and accounting — purchase amounts and dates, which do not include health data.

Your rights

  • Access — export everything we hold about you, from your settings.
  • Correction — edit your profile at any time.
  • Deletion — delete your account and its data from your settings.
  • Objection and restriction — email us and we will explain your options.

We will not make you email us for something you should be able to do yourself. Export and deletion are both self-service.

Security

  • All traffic is encrypted in transit. Data is encrypted at rest by our database provider.
  • Card details never reach our servers.
  • Logs are scrubbed of health data, prompt content and identifiers.
  • Access to production data is limited to what operating the service requires.

Children

PerformOS is not for anyone under 16. If we learn we have collected data from someone under 16, we delete it.

Changes

If we change this policy materially we will tell you in the app before it takes effect. The date at the top always reflects the current version.

Contact

Privacy questions, or to exercise any right above: support@perform-os.me.