1. Scope and contact

This Privacy Policy applies to Foom Athlete, Foom Coach, Second, the FOOM coach web service, and related support operations (together, the “Service”). FOOM is operated by Algorithmic Research Group, which is responsible for the processing described here. Questions and privacy requests may be sent to support@foom.fitness.

The Service is currently for adults 18 and older. We do not knowingly collect personal information through the Service from anyone under 18. If you believe a minor has used FOOM, contact us so we can investigate and delete the account.

2. Information we collect

CategoryExamplesWhy we use it
Account and contact Name, email address, account ID, authentication and account status Create and secure accounts, sign users in, connect invited users, and provide support
Coaching relationship Coach and athlete identifiers, invitation, relationship status, and profile details Connect the invited pair and enforce their access boundaries
Fitness and nutrition Age, sex, height, body weight, goals, nutrition targets, scheduled and completed sessions, exercises, sets, weight and repetition entries, meal descriptions, macro estimates, and progress records Provide workout planning, tracking, nutrition tools, and shared coaching progress
User content Workout and meal notes, meal descriptions, and meal photos Provide coaching records, meal logging, nutrition estimates, and progress views
Device and notification App bundle, a locally generated device identifier, APNs push token or browser push subscription, timezone preference, and notification delivery state Deliver account-linked notifications and manage each registered device
Subscription Stripe customer and subscription status, billing dates, and legacy Apple transaction identifiers where applicable Verify and provide paid coach access, prevent fraud, and respond to renewal or revocation events
Support Support correspondence, privacy requests, and the account or transaction identifiers needed to answer them Provide account, billing, technical, and privacy assistance
Service and security Request time, route, status or error code, coarse operational events, request ID, and account-linked notification delivery state Keep the Service reliable and secure, investigate incidents, and prevent misuse

We receive information directly from users, from a connected coach or athlete using the shared relationship, from the device and app, and from Stripe or legacy Apple billing for subscription status. We do not receive precise location, contacts, advertising identifiers, payment card details, or data from HealthKit through FOOM's backend services.

Second is a separate, local run recorder. It stores route coordinates, distance, start and end times, and duration on the user's iPhone or Apple Watch and does not send those records to FOOM servers. Paired devices may exchange completed runs and deletion markers directly through Apple's WatchConnectivity framework. We cannot access those records. With permission, the Watch app writes a completed workout to Apple Health but does not read Health data. Deleting a run removes Second's copy from paired devices; an Apple Health workout remains in Health until the user manages it there, and a local deletion marker prevents the paired device from restoring the route.

3. How we use information

  • provide authentication, invitations, coaching, workouts, nutrition estimates, notifications, subscriptions, and account deletion;
  • show shared coaching records only to the connected coach and athlete under the applicable relationship state;
  • protect accounts, prevent fraud and abuse, and secure the Service;
  • provide support, communicate about the Service, comply with law, and establish or defend legal claims; and
  • monitor service health using operational metadata that is designed not to contain meal descriptions, photos, tokens, or model output.

We do not sell personal information. We do not use personal information for cross-context behavioral advertising and do not track users across third-party apps or websites for advertising. We do not use health, fitness, nutrition, workout, nutrition, or photo data for advertising or marketing profiles.

4. AI meal estimation

Before the first AI meal request, Foom Athlete identifies Anthropic as the third-party AI provider, explains whether the selected meal photo or typed description will be shared and why, and asks the athlete for permission. Nothing is sent for AI processing unless the athlete chooses Allow AI estimate. Permission can be withdrawn later from the app’s Account screen, and nutrition can always be entered manually.

After permission is granted and the athlete actively requests a meal estimate, FOOM sends the submitted meal photo or text description, together with the minimum technical request needed to operate the feature, through a Cloudflare Worker to Anthropic. The AI service returns an estimated calorie and macronutrient result. Inputs and model output are not placed in FOOM’s worker logs. If the athlete saves the result, the meal record and any selected photo are stored with the coaching relationship and may be viewed by the connected coach.

AI estimates may be inaccurate and are not medical advice. An athlete may enter nutrition information manually instead of using AI estimation.

5. When information is disclosed

  • Connected users. The connected coach and athlete can see the shared coaching records that the Service makes available to their relationship.
  • Service providers. We use providers for authentication, databases, storage, realtime delivery, web and edge hosting, AI meal estimation, push notifications, and subscription processing. Current core providers include Supabase, Cloudflare, Anthropic, infrastructure hosting providers, Stripe, and Apple.
  • Safety and legal needs. We may disclose information when reasonably necessary to protect a person, investigate misuse, comply with valid legal process, enforce our agreements, or establish or defend legal claims.
  • Business change. Information may transfer as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to this Policy and applicable law.

Providers may process only the information needed for their assigned service. We require providers handling personal information for us to use reasonable safeguards and protections consistent with this Policy and applicable law, and not to use it for their own advertising. Stripe processes web payments. Apple independently processes legacy App Store transactions under Apple’s privacy terms.

6. Retention

InformationTypical retention rule
Account, relationship, workout, meal, and stored photo dataWhile needed to provide the account and shared coaching history, until the applicable account is deleted, subject to the exceptions below. Archived relationships remain read-only until deletion.
Push registrationsUntil sign-out, invalidation, device deregistration, or account deletion.
AI quota recordsA rolling operational window; routine quota consumption removes entries older than the prior UTC day.
Notification delivery and operational logsOnly as long as needed for delivery, reliability, security, and incident investigation under the production retention schedule.
Historical pre-release messaging recordsFOOM no longer offers in-app messaging. Any records created during pre-release testing are unavailable in the current product and retained only until applicable account deletion or controlled cleanup, subject to backup and legal exceptions.
Second run historyStored only on the user's devices until an individual run is deleted or Second is removed. Local deletion markers remain to prevent paired-device restoration. FOOM does not receive or retain the route history.
Subscription and transaction recordsAs needed to provide entitlement, prevent fraud, reconcile Stripe and legacy Apple events, and meet tax, accounting, or legal obligations.
BackupsDeleted information may persist temporarily in protected backups until those backups expire under the provider’s rotation schedule; it is isolated from normal product use.

Retention may be shorter when a user deletes content or an account, and longer where law, a dispute, fraud prevention, or a documented safety need requires it. We delete or de-identify information when its retention purpose ends.

7. Account deletion and choices

Both apps provide an in-app account deletion flow under account settings. It requires recent authentication, the current password, and explicit confirmation. Account deletion removes the Auth account, account-linked database aggregates, device registrations, stored meal photos, and any historical pre-release messaging objects owned by the relationship. The process is designed to be safely retried if a provider is temporarily unavailable.

Deleting a coach account cancels its Stripe subscription before deleting account data. Any legacy App Store subscription must be canceled separately in Apple's subscription settings. You may also decline push-notification permission, delete individual meal entries where offered, use manual nutrition entry instead of AI estimation, withdraw AI meal-analysis permission from the athlete Account screen, leave or end a relationship, or contact us to request access, correction, deletion, or another privacy right available where you live. We may verify identity before completing a request.

In Second, delete an individual run from its detail screen. Removing Second from both paired devices removes its remaining local run history. Workouts already saved to Apple Health are controlled separately in the Health app.

8. Security and international processing

We use access controls, private storage, signed media URLs, encrypted transport, tenant-scoped database rules, server-side authorization, secret management, and operational monitoring designed to protect information. No system is completely secure, so we cannot guarantee absolute security. Information may be processed in the United States and other places where our providers operate, with safeguards required by applicable law.

9. Changes and requests

We may update this Policy as the Service or law changes. We will post the updated date and provide additional notice when required. For questions, complaints, or privacy requests, email support@foom.fitness. Include the email on the account and do not send passwords, authentication tokens, or unnecessary health information.