Privacy Policy
Last updated: 2026-08-01
This Privacy Policy explains how Menlore ("we", "us") collects, uses, and protects information when you use the Menlore app or website.
Who we are
Menlore is a software platform that helps personal trainers manage clients and helps clients track workouts and progress. Contact: menlore.app@gmail.com.
What we collect
We collect only what's needed to run the service:
- Account info - your email address and password, your name and (for trainers) your business name.
- Health & training data - your workout logs, body measurements (weight, waist, stomach), progress photos you upload, daily checklist responses, activity logs, the food and water you log, and any nutrition or program information your trainer assigns to you. This is sensitive personal data and we treat it accordingly.
- Wearable and health-app data - only if you connect one. If you connect WHOOP, we import your recovery, strain, sleep, heart-rate and weight readings. If you allow Apple Health on iOS, we read your steps, energy burned, resting heart rate, sleep and weight, and we write your workouts, weigh-ins, meals and water back into Apple Health on your own device. You can disconnect either at any time in Profile → Connected devices.
- Messages and attachments - the messages you exchange with your trainer inside Menlore, including any photo, video or voice note you send.
- Usage data - basic technical information your browser sends (IP address, device type, last sign-in time), plus product analytics as described below.
- Product analytics - we measure how people move through Menlore so we can fix what is broken and see what is worth building. Two things are recorded. First, one random identifier stored in your browser on menlore.com and app.menlore.com, used to count how many people reach the site, click through, and finish signing up. It expires after 180 days, is reset when you sign out, and is never shared or matched against anything outside Menlore. Second, if you are signed in, each recorded action also carries your account identifier - so we hold a record of which product features you opened and when, kept for 180 days and readable by Menlore staff. What we record is that something happened, never what the data was: no weight, body measurement, photo, calorie or macro figure, workout, wearable reading, message, name or email is ever included in analytics, and analytics is never linked to your health or training data. You can turn all of this off in Settings -> Preferences -> Product analytics, and we honour Global Privacy Control and Do Not Track automatically.
- Payment status - for trainers paying for Menlore, we record whether your account is paid, pending, overdue, or free, and the date your current payment covers up to. We do not store credit card details - payment is handled directly via bank transfer for now.
We do not collect: precise location, contacts, advertising identifiers, or browsing history outside Menlore.
Why we collect it
- To provide the service (let you log in, save your data, sync across devices).
- To allow trainers to view their own clients' progress (only their own - never another trainer's clients).
- To identify and fix bugs.
- To process payments and keep tax records.
We never sell your data. We never share it with advertisers.
Where it's stored
Your data is stored on Supabase servers, currently in the Tokyo, Japan (ap-northeast-1) region. This is a cross-border transfer for users outside Japan. Supabase is a US-based provider with appropriate data protection commitments. We may move the database to a UAE region in the future for users in the Middle East - we will notify you if that happens.
Service providers we use
We rely on a small number of companies to run Menlore. They process data on our behalf under their own terms, and none of them may use it for advertising:
- Supabase - hosting, accounts, database and file storage (see "Where it's stored" above).
- Sentry - crash and error reports, so we can find and fix bugs.
- Apple and Google - delivering push notifications to your device.
- Open Food Facts - when you search for a food or scan a barcode, that search term or barcode is sent to Open Food Facts (a free, open food database) to look the product up. Nothing that identifies you is sent with it.
- WHOOP - only if you choose to connect a WHOOP account.
- Anthropic - powers the AI features your trainer can run for you, such as drafting your program or summarising your progress. When your trainer runs one, the relevant training and nutrition figures are sent to produce the response. Under Anthropic's API terms that content is not used to train their models.
Who can see your data
- You - full access to your own data via the app.
- Your trainer - if you are a client and accepted an invite from a trainer, that specific trainer can see your workout logs, body stats, nutrition and water logs, and program data. They cannot see your password.
- Your trainer's organization - if your trainer belongs to a gym or studio that manages them inside Menlore, that organization's manager can see your training and nutrition records alongside your trainer, so the gym can keep supporting you if your trainer changes. If your trainer is independent, no organization can see anything.
- Us (the Menlore team) - only as needed for support, debugging, or to comply with the law. We do not browse user data routinely.
- Every Menlore user, for foods you add to the shared library - when you add a food manually and leave "Add to the food library" switched on, that food's name, brand and macros are saved to a library everyone using Menlore can search. The row records your user id so a wrong entry can be traced and corrected; your name, email and your own food diary are never shown with it. Switch the toggle off to keep a food to yourself, or email us to have one removed.
- Nobody else.
How long we keep it
We keep your data for as long as your account is active. If you delete your account or ask us to, we delete your personal data within 30 days (some information may persist in encrypted backups for up to 90 days, after which it is permanently removed).
Your rights
Under the UAE Personal Data Protection Law and similar laws elsewhere, you have the right to:
- Access the personal data we hold about you.
- Correct any data that is wrong.
- Delete your data ("right to be forgotten").
- Withdraw consent at any time.
- Object to certain uses of your data.
- Receive a copy of your data in a portable format.
You can delete your account and personal data yourself at any time, directly in the app: open Settings → Delete Account. To exercise any other rights, email us at menlore.app@gmail.com. We respond within 30 days.
Cookies and local storage
Menlore uses your browser's localStorage and IndexedDB to keep your data available offline and to remember you between sessions. The same storage is used on the marketing site at menlore.com, which holds one random analytics identifier and nothing else. We do not use cookies for advertising or third-party tracking, and no third party receives any of it. Clearing your browser storage will sign you out and remove your offline cache, but your cloud data remains intact.
Children
Menlore is not intended for users under 18. By using Menlore you confirm that you are 18 or older.
Changes
We may update this policy as the service evolves. If we make material changes we'll notify you by email and require you to re-accept the updated policy on next sign-in.
Contact
Questions or requests: menlore.app@gmail.com.