Privacy Policy
Effective September 5, 2026
1. Who we are
Cragen ("Cragen," "we," "our") is a fitness logbook for iOS and Android. This Privacy Policy describes how the Cragen mobile app and cragen.app handle information.
Privacy questions: privacy@cragen.app.
2. The short version
- Your training data stays on your device by default. Workouts, programs, templates, body metrics, and preferences are stored locally unless you turn on optional iOS account backup or approve connected coaching for selected categories.
- Account backup is optional. If you sign in with Apple or passwordless email on iPhone and back up your account, Cragen uploads a backup snapshot of your logbook so it can be restored on another iPhone. Email sign-in on Android can own a coach connection but does not enable Android backup.
- Connected coaching is optional and approval-only. Private-pilot members choose a coach and approve exact permissions. Write requests are applied by the signed-in phone only after its safety checks pass; a queued request is not a saved change.
- Emails are purpose-limited. If you choose passwordless sign-in, WorkOS sends a single-use six-digit code that expires after ten minutes. Cragen does not store a password or log the code. If you contact us, we use your address and message only for that request.
- Health data flows in only. If you grant permission, we read steps, sleep, and body weight from Apple Health or Health Connect. We don't write back. Raw health samples are processed on device. If you approve Health summaries for a connected coach, Cragen sends only recent step, sleep, and body-weight summaries. Body metrics saved into Cragen may also be included in account backup or in connected-coaching context when you approve the relevant scope.
- No advertising trackers. Cragen contains no third-party advertising SDKs and does not engage in cross-app or cross-site tracking.
- Crash reports only. Anonymous crash reports help us fix bugs. They never contain your workouts, health data, or identifiers tied to you.
- You can leave at any time. Export your workouts as CSV, request a full account export, and delete your optional account backup from Settings → Account. Uninstalling the app removes local data from your device.
3. Information stored on your device by default
The following data is created and stored locally on your device, in the platform's standard storage (SQLite for structured data, SecureStore for preferences and keys). It is not transmitted to Cragen unless you choose optional iOS account backup or approve connected coaching for the categories shown to you.
- Workout logs — exercises, sets, reps, weight, RPE/RIR, notes, rest times, timestamps.
- Programs, templates, and program history.
- Body weight entries you enter manually, plus your unit and preference settings (e.g. default rest, units, theme).
- A per-device identifier generated locally on first launch. It is not derived from your name, email, phone, or external account. When you use passwordless email or account services, Cragen processes it with your account or email for app functionality and request security, so it is linked to the account or email in those flows.
4. Optional account and iOS backup
On iPhone, Sign in with Apple may provide Cragen with your shared email address or an Apple private-relay address. Cragen resolves the account through Apple's stable account identifier, not by matching email text. You may optionally add a verified regular email later as an alternate sign-in method for the same account. Adding one is never required to connect a coach.
If you choose passwordless email sign-in or add a regular email, WorkOS Magic Auth processes the email address plus request-security context, including IP address, user agent, and device identifier, to send and verify a single-use code. This passwordless email request/security processing is separate from connected-coach authorization. Cragen does not store an account password or log the code.
Cragen uses a stable internal user ID so programs, workouts, backups, and connected coaches are not owned by an email address or provider identifier.
On iPhone, either sign-in method can back up and restore your Cragen logbook. When enabled, Cragen may transmit a backup snapshot containing workouts, programs, templates, custom exercises, preferences, body metrics, saved coach notes, training preferences, reminder desired schedules, and account metadata such as your verified email and user ID. Local coaching command receipts and Undo preimages are not included.
Raw Apple HealthKit and Health Connect samples, health-permission state, and provider connection metadata are excluded from account backup and remain on the device that received them.
Account backup is not required to use the app. Passwordless email on Android can be used for account ownership and connected coaching, but Android account backup is not included in this release.
5. Optional connected coaching
Consent disclosures: read and proposal permissions use connected-coaching-2026-09-01-v4; a new connection that requests any write permission uses the separate connected-coaching-2026-09-05-v5 consent.
If connected coaching is available, the primary path is prompt-only OAuth 2.0 Device Authorization. You create a one-time pairing invitation in the signed-in Cragen app. With code-consent prompts, selecting access and creating the prompt is your approval. Anyone who redeems that single-use, 30-minute code can receive exactly the selected permissions, so share it only with your chosen agent. No second confirmation is required. Older invitations still require approval in Cragen. No website, Apple credential, email code, account token, or durable bearer credential is required from you. The agent sends its registered agent client identity and HTTPS origin plus its requested scopes to Cragen; they must match the access selected for the code. WorkOS browser OAuth is a compatibility fallback for agents that cannot complete the device flow. It is not the primary path. WorkOS compatibility uses an opaque account ID and a non-contactable alias under coach-identity.cragen.app. WorkOS and the coach never receive your real or Apple private-relay sign-in email through coach authorization. Your sign-in email is not a coach scope, coach context, or coach API field. Cragen then honors only the scopes you approve:
- Programs —
programs.read: program structure, exercise targets, and optional RIR targets. - Training history —
training.read: completed normal-set facts from the preceding 26 weeks. - Profile —
profile.read: coaching-relevant profile details and goals. - Health summaries —
health_summary.read: bounded recent steps, sleep, and body-weight summaries, never raw provider records. - Current workout —
live_training.read: the active workout, including entered and unfinished sets, read-only. - Notes —
notes.read: bounded notes attached to records the coach can already read. - Program suggestions —
programs.propose: submit a program proposal for your review; it does not grant authority to apply that proposal. - Upcoming program workouts —
programs.write: change only unstarted upcoming sessions in the active program, never started workouts or training history. - Personal exercises —
exercises.create: add to your personal exercise library, not Cragen's shared catalog. - Coach notes —
coaching_notes.write: add attributed program or exercise notes and manage only notes created by that connection; your notes stay unchanged. - Training preferences —
training_preferences.write: change only equipment and training days per week, not account, units, body, health, or notification settings. - Training reminders —
reminders.write: manage only that connection's local reminders within the limits below.
The Training only preset is Programs, completed training, and program suggestions: programs.read, training.read, and programs.propose. It excludes Profile, Health summaries, Current workout, and Notes. Existing v4 grants keep only their original seven permissions; refresh cannot add write access. Full coaching context remains those seven read and proposal permissions and does not include automatic writes. Choose access is required to add any write permission.
A pairing invitation expires after 30 minutes. Its expired unclaimed, pending, denied, or cancelled record is deleted in the next bounded retention cleanup run; this is not an instant-deletion guarantee. Approved connections, their token records, and security-audit records follow their separate retention rules, including 90-day audit retention. We process the agent client identity, origin, requested scopes, approval or denial, and connection and security-audit records to create, protect, disconnect, or investigate that connection. After approval, the agent host receives a 10-minute access token and a rotating refresh token; the refresh token has a 30-day refresh lifetime. Pairing codes and tokens are credentials, are excluded from analytics and support exports, and are never added to coach context.
The coaching snapshot includes only categories you approve. It always excludes raw health-provider records, credentials, account tokens, provider identifiers, and unrelated workout history. Approved automated clients may use Cragen's machine-to-machine MCP endpoint, which applies the same identity, connection, scope, and account-isolation checks as the coaching REST API. The snapshot, agent prompt, and Cragen logs never include access and refresh tokens, and Cragen never forwards an external bearer credential to another service.
Every program proposal is immutable and becomes a separate inactive replacement draft only after you approve it on your phone. It never edits your current program, active schedule, workout in progress, or workout history. You decide later whether to activate the replacement.
Write tools send an encrypted, account- and connection-bound request to your phone; queued is not applied. If the phone is offline or Cragen is not active, the request waits for the next authenticated active sync; background delivery is not guaranteed. A coach should report a change as saved only after Cragen returns an authenticated device receipt. A conflict, expiry, revoked connection, or device failure is not success.
The phone validates the current expected hash or version before a write. For an acknowledged change, it stores a device receipt and an Undo preimage. Undo uses compare-and-swap against the saved after-state and refuses to overwrite a later user edit or workout progress. Restoring an account backup clears the ability to Undo commands from before the restore. Acknowledged Undo preimages are kept for at most 30 days, the latest 100 acknowledged snapshots, and 20 MB shared with recovery state. Unacknowledged recovery preimages are never evicted; if a new Undo cannot fit, the phone rolls back the write instead of leaving a partial change. Cleanup runs the next time the app executes, not at a wall-clock deadline while it is closed. Completing Undo clears that preimage. The minimal local receipt identity remains until the account's normal local clear.
Training reminders are limited to seven saved reminders per connection and one enabled reminder per weekday. Times must be from 08:00 through 20:59 in the saved time zone. Scheduling requires notification permission already granted in system settings; Cragen does not request notification permission automatically in the background. Revoking a connection cancels only that connection's scheduled reminders.
When the agent requests current write state, Cragen exposes only scope-specific minimal encrypted write context: equipment and training days, that connection's coach notes, or that connection's reminders. Missing or stale context waits for the phone. Encrypted write context and encrypted server command request and receipt content are erased after 30 days. Minimal connection IDs, hashes, and status records may remain until account deletion.
Pending proposals expire after 14 days. Resolved proposal ciphertext is erased after 30 days, coaching audit events after 90 days, and a connection idle for more than 90 days is suspended. Disconnecting one coach revokes that coach, invalidates its tokens, and cancels its pending proposals. A shared server snapshot remains for other coaches you keep connected and is deleted when the final connection is revoked.
Your full account export includes your connected-coaching records but redacts credentials, hashes, and encrypted payloads. Deleting your account removes all server-side pairing invitation, connection, snapshot, proposal, authorization, token, staging, and audit records. Connected-coaching request bodies, credentials, identifiers, and training facts are stripped from Cragen logs and Sentry events.
6. Apple HealthKit (iOS)
If you grant Cragen permission via the iOS Health permission sheet, Cragen reads the following data from Apple Health to display trends and context inside the app:
- Daily step count
- Sleep sessions
- Body weight entries
HealthKit data is read-only. Cragen does not write to Apple Health and does not modify your Health data. Raw HealthKit provider records are processed on your device. If you connect a coach and approve Health summaries, Cragen derives and sends only bounded step, sleep, and body-weight summaries through the encrypted coaching service. Body weight values you save into your Cragen profile or history become Cragen records and may be included in optional account backup or an approved connected-coach scope.
You can revoke HealthKit access at any time in iOS Settings → Privacy & Security → Health → Cragen.
7. Health Connect (Android)
On Android, Cragen integrates with Health Connect using the same principles as our HealthKit integration. With your explicit permission, Cragen reads:
- Steps
- Sleep
- Weight
Raw Health Connect records are read-only and processed on-device. If you connect a coach and approve Health summaries, Cragen derives and sends only bounded step, sleep, and body-weight summaries through the encrypted coaching service. Body weight values you save into Cragen become Cragen records and may be included in optional account backup or an approved connected-coach scope. You can revoke access at any time from Health Connect's settings.
8. Crash reporting (Sentry)
Cragen uses Sentry to receive anonymous crash and error reports so we can fix bugs. Reports include technical context such as:
- Stack traces and the file/line where the error occurred
- Device model and operating system version
- App version and build number
- A randomly generated install identifier (not tied to you)
Crash reports do not include your workouts, programs, body weight, HealthKit/Health Connect data, name, email, phone number, IP-based location, or any other personally identifying information. Personally identifying scopes (PII fields, request bodies, breadcrumbs containing user input) are stripped before transmission.
9. Emails and support requests
If you email us for support or privacy questions, your email client sends your email address and message to Cragen. We use that information only to reply to your request. We do not sell it, add it to advertising audiences, or link it to your on-device training history.
You can ask us to delete support or privacy emails by writing to privacy@cragen.app.
10. App Tracking Transparency (iOS)
Cragen does not track you across apps or websites and does not present the App Tracking Transparency prompt. Our iOS privacy manifest (PrivacyInfo.xcprivacy) declares no tracking domains. The complete Apple collected-data declaration is below.
| Apple category | Linked to you | Tracking | Purpose |
|---|---|---|---|
| Email Address | Yes | No | App Functionality |
| Name | Yes | No | App Functionality |
| User ID | Yes | No | App Functionality |
| Device ID | Yes | No | App Functionality |
| Other User Content | Yes | No | App Functionality |
| Product Interaction | Yes | No | App Functionality |
| Fitness | Yes | No | App Functionality |
| Health | Yes | No | App Functionality |
| Crash Data | No | No | App Functionality |
| Performance Data | No | No | App Functionality |
Email Address, Name, User ID, Device ID, Other User Content, Product Interaction, Fitness, and Health are linked to you. Crash Data and Performance Data are not linked to you. Every category is non-tracking and has the sole purpose App Functionality.
The Health category covers body metrics saved as Cragen records and bounded derived Health summaries used only when you enable an optional feature and approve the relevant access. Raw Apple HealthKit and Health Connect provider records stay on your device and are not collected.
11. Data we do NOT collect
To be explicit, Cragen does not collect:
- Your phone number or postal address
- Your raw Apple HealthKit or Health Connect samples
- Your contacts or precise location
- Photos, unless you deliberately upload an optional progress photo; uploaded progress photos are encrypted at rest and deleted with your account.
- Advertising identifiers (IDFA / GAID)
- Raw card numbers or account credentials of any kind
12. Your controls
- Export. Export your workout history as CSV from Settings → Export workouts (CSV) at any time. If you have a cloud account, you can request a full account export from Cragen.
- Delete local data. Uninstalling the app removes locally stored Cragen data from that device, including the per-device identifier.
- Delete account and server data. Deleting your account from Settings → Account → Delete Account removes your Cragen account, optional server backup, and connected-coaching records.
- Health permissions. Revoke HealthKit / Health Connect access at any time in your OS settings. Cragen will detect the change on next launch.
- Connected coaching. Review or decline proposals in Cragen and disconnect an individual coach at any time. Disconnecting does not delete your local training data.
- Crash reporting. If you do not want Cragen to send anonymous crash reports, contact privacy@cragen.app and we will document the opt-out steps for your version.
13. Children
Cragen is not directed to children under 13 and we do not knowingly collect data from children under 13. The app is rated 4+ on the App Store.
14. Security
Because Cragen is local-first, the main defenses for local data are your device's lock screen, OS-level encryption, and device backup settings. Optional account backup is transmitted over HTTPS and stored on Cragen systems so it can be restored after sign-in. We recommend keeping your device passcode/Face ID/Touch ID enabled and your OS up to date.
15. International users
If you enable optional account backup, your backup data may be processed where Cragen's hosting providers operate. Anonymous crash reports may be processed by Sentry on infrastructure located in the United States and the European Union. If you connect a coach, WorkOS and Cragen's hosting providers may process the connection and minimized coaching records where they operate. This international processing is limited to the optional services you choose and the purposes described above.
16. Changes to this policy
We may update this policy as the product evolves — for example, when we ship new integrations or change how crash reporting works. Material changes will be reflected here with an updated effective date. Continued use of Cragen after the effective date constitutes acceptance of the revised policy.
17. Contact
Privacy questions or requests: privacy@cragen.app.
General support: support@cragen.app.