Champ
Privacy Policy
Effective 2 August 2026 · Version 1.3
Champ is an AI fitness coach. It reads your health data from Apple Health and holds a running conversation with you about your training — so this page is a plain account of what happens to that data.
The short version
- Champ reads a specific list of Apple Health types, only with your permission, and never writes anything back.
- Your conversations — including photos and PDFs you attach — are stored and sent to an AI provider to generate each reply. They routinely contain health information.
- No advertising, no analytics, no trackers. The app contains no third-party code at all.
- Your data is never sold or shared with data brokers, and never used for advertising or to train AI models.
- Delete your account in the app and everything Champ holds goes, including everything the coach remembered.
Who is responsible
Guy Aluk, an individual developer, is the data controller under UK and EU GDPR. Contact: contact@champ.fitness.
What Champ collects
Account
Champ uses Sign in with Apple and has no password of its own. It stores your name and email — if you chose Hide My Email, that is Apple's relay address and Champ never sees your real one. It also stores your time zone, locale, week start, check-in time, and a record of each sign-in session (its expiry, IP address and device user-agent).
Health data from Apple Health
With your explicit permission, and only the categories you allow, Champ reads: steps, active energy, exercise minutes, walking and running distance, heart-rate variability, resting heart rate, VO₂ max, body weight, body fat, lean mass, sleep analysis with its stages, workouts, and the heart rate recorded during them.
Read access only. Champ never asks to write to Health and never writes a sample. It backfills roughly 90 days when you first connect, and receives new data in the background. iOS does not tell apps which read permissions were granted, so the Health app is the place to see and change them.
What you tell Champ about yourself
Before your first conversation the app asks four things on a short form: your first name, date of birth, gender and height. They are what lets the coach size training and nutrition to you rather than to an average, and they are held in the same coaching memory described below and treated as health data. Your age is worked out from the date whenever it is needed rather than stored as a number of its own.
Your conversations, and what the coach remembers
Everything you send is stored: your messages, the coach's replies, and any images or PDFs you attach. So is anything you log by hand — workouts, meals, body measurements, injuries or illness.
To behave like a coach rather than a stranger each morning, Champ also keeps a persistent memory: a profile of your goals and constraints, observations drawn from your conversations, the plans it writes, and a searchable index of past messages. That memory is derived from your health data and is treated as health data.
Device, and access requests
If you enable notifications, Champ stores the push token iOS issues for your device — purely so the coach can reach you. It is not an advertising identifier, it cannot be used to recognise you in any other app, and it is deleted with your account. Server logs record operational events — timing, errors, internal identifiers — for running the service.
The app also reports its own crashes and errors to Champ's own servers, so a bug that only happens on your phone is fixable. These reports are built from Apple's own MetricKit — there is still no third-party crash-reporting code in the app — and they describe the shape of a failure only: what kind of error, which screen or request, your iOS and app version, and your device model. Never your messages, never a health figure, never anything you typed. They are kept for 30 days and then deleted.
The form on champ.fitness collects one thing: an email address, emailed to the operator so he can invite you to the beta. It exists before you have an account, so deleting an account later does not remove it — ask and it will be.
Why, and on what legal basis
All of it serves one purpose: running the coaching service you signed up for. There is no secondary use.
- Explicit consent (Art. 9(2)(a)) for health data — your Apple Health data, your conversations about your body, and the coach's memory. Withdraw it by revoking Health access or deleting your account.
- Performance of a contract (Art. 6(1)(b)) for your account, sign-in and settings.
- Legitimate interests (Art. 6(1)(f)) for keeping the service secure and working — logging, backups, abuse prevention.
Who else sees it
These providers process data on Champ's instructions. None may use it for their own purposes.
| Provider | What it receives | Where |
|---|---|---|
| Microsoft Azure hosting |
Everything Champ stores. | Poland (EU) |
| Azure OpenAI the coach's model |
Your conversation, attachments, the coach's memory, and the health figures given as context. This contains health data. | Stored in Poland; processed worldwide |
| OpenRouter standby model route |
The same, if the primary provider is ever unavailable. | United States |
| Langfuse agent monitoring |
A trace of each coaching run — your message, the coach's reply, the steps it took and how long they took. This contains health data. Used only to diagnose the coach misbehaving. | Germany (EU) |
| Apple sign-in and push |
Your sign-in identity; your device token; and the text of each notification, which previews what the coach wrote. | Apple's infrastructure |
| Resend operational alerts |
Notifications to the operator that something has broken. Error types and counts only — never your data. | United States |
| Resend access-request form |
Only the email address you typed into the form. Never health data. | United States |
On the AI provider. Microsoft states that prompts and responses are not available to OpenAI and are not used to train any models. Two things are worth knowing anyway: the models run on a global deployment, so a request may be processed in any geography even though stored data stays in the EU; and the API Champ uses keeps its own copy of the conversation in Champ's Azure resource, which account deletion does not reach (see below). Content flagged by Microsoft's abuse monitoring may also be reviewed — for EEA services, by reviewers in the EEA. Details: Microsoft, OpenRouter.
What Champ never does
- Sell or rent your data, or share it with data brokers or ad networks.
- Use health data for advertising or marketing, or disclose it for advertising or data mining — also a condition of Apple's HealthKit rules, which Champ follows.
- Use your data to train AI models, its own or anyone else's.
- Ship analytics, attribution, crash-reporting or advertising SDKs. The app has no third-party code of any kind — the crash reports described above are built from Apple's own framework and go to Champ's servers, nobody else's.
- Read any Health category beyond the list above.
Where it lives, and for how long
Champ's servers, database and backups are in Microsoft Azure's Poland Central region. Data is kept while your account exists — a coach with no history is not a coach. Encrypted backups roll on a 14-day window, so anything you delete ages out of them within 14 days.
Three things sit outside that database: the conversation copy held by the AI provider, any abuse-monitoring records Microsoft keeps under its own retention, and an access request if you sent one. None is removed by deleting your account — ask and they will be.
If you are in the EEA or UK, note that model processing, the standby route, Apple's push infrastructure and Resend can each involve processing outside your region, covered by the providers' standard contractual clauses.
Security
Traffic is encrypted with TLS; the database and its backups are encrypted at rest; production access is restricted to the operator over key-based channels. Every query is scoped to one account, enforced by an automated test suite that blocks a release if it fails. If a breach affects your data you will be notified, and the relevant authority informed, as the law requires.
Your rights
In the app: change or revoke Health access in the iOS Health app; turn off notifications in iOS Settings; or delete your account (Settings → Delete account), which immediately and irreversibly removes your identity, everything you logged, your plans, your device tokens, your entire conversation and everything the coach remembered, and revokes the Apple grant.
By request: you may access, correct, export, restrict or object to processing, and withdraw consent. Write to contact@champ.fitness — a reply within 30 days, no charge. In the EEA or UK you may also complain to your local data protection authority.
Children
Champ is not directed at anyone under 16 and accounts should not be created for them. If you believe a child has one, write to contact@champ.fitness and it will be deleted.
Changes
The version and date at the top change with this page. Any change that materially affects how your health data is handled will be announced in the app first.