Privacy Policy
RandWOD generates CrossFit workouts and records how you perform them. That means we handle data about your training — some of it health data. This page says plainly what we collect, what we do with it, and what we will never do with it.
01 · Who we are
RandWOD is operated by Zifang Liu, an independent developer. For anything in this policy, contact [email protected].
02 · What we collect
- Account data. When you sign in (Google, Apple, or an email link) we store your email address, display name, and an optional avatar.
- Training data. Workouts you run and the results you log: movements, reps, loads, times, scores, RPE, and personal records.
- Health data (with your permission). On Apple Watch the app reads heart rate and writes workouts through Apple HealthKit, only after you grant access in iOS. Heart-rate summaries (for example, average and peak for a session) are stored with the session they belong to.
- Motion sensor data (opt-in). If you take part in movement-recognition capture sessions, the watch records motion-sensor (IMU) data for those sessions only.
- Community content. Workouts or results you explicitly share are stored with the display name you chose.
We do not collect your location, contacts, photos, or advertising identifiers. The marketing site sets no tracking cookies and runs no analytics.
03 · How we use it
- To run the product: generate workouts, keep your history, detect personal records, sync between your phone and watch, and chart your training.
- To power community features you choose to use: content you share is visible to other users under your display name; nothing is shared unless you share it.
- To improve on-device movement recognition, using only opt-in capture sessions.
04 · What we never do
- We do not sell your data. To anyone, in any form.
- We do not show ads and do not share data with advertisers or data brokers.
- Health data is never used for marketing and never shared with third parties, consistent with Apple's HealthKit rules.
05 · Where it lives
Data is stored in Google Firebase (Authentication, Cloud Firestore, Cloud Storage), which processes it on our behalf under Google's data-processing terms. Transport is encrypted (TLS); access is restricted to your authenticated account by per-user security rules.
06 · API access you create
If you mint a personal access token in the developer portal, that token grants read-only access to your own data. We store only a hash of it; the plaintext is shown once, to you. Revoke tokens any time from the same page.
07 · Retention and deletion
Your data is kept while your account exists. Delete your account in the app — or email [email protected] — and your account record, training history, health-data summaries, sensor captures, and tokens are deleted. Shared community content is removed with it.
08 · Your rights
You can request a copy of your data, correct it, or have it deleted by contacting [email protected]. If you are in a jurisdiction with specific privacy rights (for example the EU/EEA, UK, or California), those rights apply and we honour them.
09 · Children
RandWOD is not directed at children under 16, and we do not knowingly collect their data.
10 · Changes
If this policy changes materially we will update the date at the top and note the change in the app. The current version always lives at this URL.