Last updated: September 22, 2026
WTF ("the app," "we," "us," or "our") is a personal fitness app for iOS. The app and its backend are operated by the team behind jerhud.com. If you have questions about this policy or your data, you can reach us at jeremy@jerhud.com.
When you create an account, we collect your email address and a password (or, if you sign up with Apple or Google, the user identifier those services give us). If you use Apple's "Hide My Email" relay, we receive the relayed address rather than your real one — that's fine, the app works the same way. We use this to identify you, let you sign in, and send you essential emails like sign-in links, password resets, and account verification.
Inside the app you can answer questions about your fitness goals, experience level, equipment access, training schedule, age, and weight. All of this is optional except your goal and experience level, and you can skip the rest entirely. We use whatever you provide to generate a workout plan that fits you. If you skip everything, we give you a generic beginner plan instead — the app still works.
As you use WTF, you log workouts (which exercises, how many sets, reps, and weight), nutrition (foods, calories, macros), body stats (weight, measurements), and meal plans. We store this so the app can show you your history, calculate your streak, generate progress charts, and adjust future plans. This data belongs to you. You can view it, edit it, and delete it any time from inside the app.
For outdoor walks, we also store the GPS coordinates of your route so you can review the walk on a map afterward. Route data is tied to your account and is never shared, sold, or used for any purpose other than showing you your own walks.
With your permission, WTF reads data from Apple Health — including body weight, body fat, height, age, biological sex, steps, active energy, heart rate, resting heart rate, sleep, and mindful sessions — to personalize your calorie targets, workout recommendations, and progress tracking. With your permission, WTF also writes data you log in the app — workouts, food and nutrition, water, body weight, and mindfulness sessions — back to Apple Health.
Apple Health data is stored on your device. We never sell it, use it for advertising, or share it for cross-app tracking.
When you use AI features (such as the AI Goal Coach, AI meal suggestions, or the AI Workout Generator), some information — which may include Health-derived values such as your current weight — is sent to our servers and to our AI provider (Google Gemini) solely to generate your personalized result. WTF does not store this data as part of that request, and it is not used for advertising.
You can turn Apple Health access on or off at any time in the app's settings or in the iOS Health app.
When you use an AI feature, we send the information that feature needs to a third-party AI provider (currently Google, via its Gemini generative-AI service) to generate your result. Specifically: "Snap a dish" sends a food photo and returns an estimated recipe and nutrition breakdown; "Scan a recipe" sends a photo of a written recipe and returns structured recipe text; AI coaching and eat-out suggestions send relevant context (your goals, macros remaining) and return text suggestions. We only send the specific photo or text needed for the feature you're using. Requests are associated with an internal account identifier, not your name or email. The provider processes this on our behalf and, under our agreement with them, does not use it to train their models. We don't use your data to train models either. Results are generated for you and are not shared with anyone else.
If you take progress photos in the app, the photos themselves stay on your device. We do not upload your progress photos to our servers. We only store metadata — the date a photo was taken — so the app can list your photos in order.
Food and recipe photos you take specifically to use an AI feature ("Snap a dish" or "Scan a recipe") are different: those are sent to our AI provider to generate your result, as described above. They are not used for advertising or to train any model, and are not retained beyond generating and returning your result. Either way, we don't access your broader photo library — only the specific photo you take or choose for a feature.
When the app talks to our servers, we receive standard technical information: your IP address, the date and time of the request, and basic device details (iOS version, app version). We use this to make sure the app works, debug problems, and protect against abuse like spam sign-up attempts.
When the app crashes, we receive a technical report describing what went wrong (which screen, which line of code, the iOS version). These reports are processed through Firebase Crashlytics and are used only to fix bugs. They do not include your workouts, food, or body measurement data.
We use PostHog to track basic, anonymous usage patterns — things like which screens get used most, where people drop off in onboarding, and whether new features are being adopted. We deliberately exclude your health, food, and body measurement data from analytics. What you weigh, what you eat, and what you've measured stays out of these reports.
We use your data only for these purposes:
We do not use your data to build advertising profiles, train AI models, or for any purpose unrelated to running WTF.
We do not sell your personal information. Ever. We don't share it with advertisers or data brokers. We do, however, work with a small number of service providers who help us run the app:
These providers are bound by their own contracts and privacy policies, and they only receive the information they need to do their specific job. We may also share information if we are legally required to (subpoena, court order, etc.) or if we need to defend our rights or protect someone from harm — but those situations are rare and we resist overbroad requests.
Your data is stored on servers located in the United States, and we operate out of Arizona. If you use WTF from outside the US, your information will be transferred to and processed in the US, which may have different privacy laws than your country.
We keep your account and the data you've logged for as long as your account is active. If you delete your account, we delete your personal information from our active systems within 30 days. Some information may persist briefly in encrypted backups for an additional period before being overwritten on the normal backup rotation. Anonymous, aggregated information (such as "10,000 workouts were logged this month") may be retained indefinitely for our internal metrics.
If your account has been inactive for two years and we've made reasonable attempts to contact you, we may delete it.
California residents have additional rights, including the right to know what personal information we have about you, the right to request deletion, the right to correct inaccurate information, and the right not to be discriminated against for exercising these rights. To make a request, email jeremy@jerhud.com with the subject "California Privacy Request." We do not sell personal information, so the "do not sell" right is satisfied by default.
You have rights under the GDPR including access, correction, deletion, restriction, portability, and the right to object to processing. Our legal basis for processing your data is the contract you enter into when you create an account, plus your consent for optional things (like optional questionnaire answers and the AI features you choose to use). You can withdraw consent at any time by deleting the relevant data or your account. To make a GDPR request, email jeremy@jerhud.com. You also have the right to lodge a complaint with your local data protection authority.
We protect your account with industry-standard practices: passwords are hashed (never stored in plain text), connections to our backend are encrypted via HTTPS, sessions use signed tokens with expiration, and the database server is firewalled and access-controlled. We rate-limit login attempts and account-related actions to prevent abuse. No system is perfectly secure, and we can't promise against all attacks, but we treat your data with care.
If we ever discover a breach affecting your data, we'll notify affected users without unreasonable delay and provide details about what happened and what we're doing about it.
WTF is not intended for children under 13 (or under 16 in the EEA / UK). We do not knowingly collect information from children under these ages. If you are a parent and believe we have collected information from your child, contact us at jeremy@jerhud.com and we will delete it.
WTF is not a medical device, and the information you log (weight, body measurements, nutrition, workouts) is not protected health information under HIPAA. We do not have a covered relationship with you under that law. If you need medically-protected fitness or nutrition tracking, please use a HIPAA-compliant tool — WTF is not it.
AI-generated suggestions — recipes, nutrition estimates, and coaching — are for general informational purposes only and are not medical, dietary, or professional advice. They can be inaccurate, so please consult a qualified professional before making medical or dietary decisions.
We may update this policy from time to time. When we make material changes, we'll update the "last updated" date at the top of this page and notify you in the app (and by email if the change is significant). Continuing to use WTF after a change means you accept the updated policy. If you don't, you can delete your account.
Questions, requests, or concerns? Email jeremy@jerhud.com. We aim to respond within 5 business days.