Privacy Policy
Momentum OS — AI Fitness · effective August 19, 2026
The short version
Momentum OS is local-first. Your workouts, meals, weigh-ins, momentum history and settings are stored in a database on your own device (IndexedDB). Your account exists so you can sign in anywhere and compete on the leaderboard. Leaderboards and the community only ever see aggregate stats — never your logs. If you sign in, a private cloud backup of your logs is kept so a lost phone doesn't mean a lost history (details below).
What stays on your device
Everything you log lives in a database on your phone: training logs, food logs, body weight, lifestyle entries, custom foods, recipes, XP and momentum history. If you are signed in, a copy of most of it is also snapshotted to your private cloud backup — see Cloud backup below for the exact list. Progress photos never leave your device — they are not in the backup and are not synced, and are sent to the AI solely at the moment you run a Weekly Progress Analysis. Deleting the app (or using Settings → Reset all local data) permanently removes the on-device copy.
Who can use Momentum
Momentum is for people aged 18 and over. We don't knowingly collect personal information from anyone under 18 — if you believe a minor has created an account, contact us using the address below and we'll delete it.
Your account
Creating an account (your email address) is part of getting set up. Leaderboards and the recipe community receive only: your display name, profile photo or spirit mark, friend code, weekly XP totals, momentum (day-streak) length, workout count, days-logged count, recipes you choose to share, and your votes. Recipes you like from the built-in library are recorded against your account so your Liked list follows you between devices; the like count shown on a recipe is public, but who liked it is not — nobody, including other users, can see which recipes you liked. The same applies to a free weekly recipe pick, which is stored so the recipe stays unlocked for you. Authentication is handled by Supabase via one-time email codes; we never see or store a password. Your meals, weights, and training details are never shown to other users or used for anything besides your own private backup, described next.
Cloud backup
While you're signed in, the app snapshots your local database — workouts, sets, meals, custom foods, saved recipes, meal plans, planned meals and grocery lists, weigh-ins, lifestyle entries, health metrics, cardio, programs and workout templates, supplements, goals, XP and momentum history, your app settings, and lab-report findings (never progress photos or lab-report files) — about once a day to a private backup file in our storage (Supabase). That file is readable only by your account, is used solely for the Restore feature in Settings → Data, and is never analyzed, shared, or used for any other purpose. Deleting your account deletes the backup.
Finding friends from contacts
If you tap "Find friends from contacts", the app reads your address book on the device and computes a one-way hash (SHA-256) of each email address. Only those hashes are sent — never names, phone numbers, or raw email addresses — and they are compared against the hashes of people who have claimed a username, then discarded. The matching lookup stores nothing. Your own email is stored as a hash on your profile so friends scanning their contacts can find you; you can stay unfindable by not claiming a username. This is entirely optional and Momentum works without it — Android will ask for Contacts permission the first time, and you can decline or revoke it in system settings.
Health integrations
If you connect Health Connect (Android) or Apple Health / HealthKit (iOS), Momentum reads only the data types you approve — steps, weight, body fat, resting heart rate, blood oxygen, respiratory rate, active calories, basal metabolic rate, sleep, and exercise sessions — to show trends and personalize your targets. Health data is stored in the on-device database and leaves your device only as part of your private cloud backup (above) or when you explicitly run an AI analysis. Data read from HealthKit is never used for advertising or marketing, never sold, never shared with data brokers, and never shared with third parties. Disconnect at any time in Settings → Integrations; erase it with Settings → Reset all local data plus deleting your account (which removes the backup).
Watch app
If you install Momentum on a paired Wear OS watch or Apple Watch, the watch keeps its own copy of your current plan — today's session, your saved workouts, your calorie and macro targets, and your most recent health readings — so it works with your phone out of range. During a session the watch reads your heart rate from its own sensor and records the exercises, sets, reps and weights you log, how long the session lasted, and the calories burned (measured on Apple Watch, estimated from your bodyweight on Wear OS). Finished sessions are sent to your phone, stored in the on-device database alongside everything else you log, and included in your private cloud backup if you are signed in. On Apple Watch, completed workouts are also saved to Apple Health. The watch app has no internet access of its own — it talks only to your phone. Heart rate is read only while a session is running, never in the background, and is never used for advertising or marketing, never sold, and never shared with third parties. Declining the heart-rate permission leaves the watch app fully usable; sessions simply record without it. Uninstall the watch app to erase its copy.
AI features
When you use AI meal logging, recipe ideas, grocery lists, or the coach, the text/photo you submit and a summary of relevant stats (e.g. macro targets, training volume) are sent to our server and forwarded to Anthropic's Claude API to generate the response. These requests are not used to identify you and are not sold or shared for advertising.
Subscriptions and payments
Momentum Pro is sold through the App Store and Google Play, and we use RevenueCat to keep track of whether a subscription is active. We never see or handle your card details — the store processes the payment and tells RevenueCat the result. RevenueCat receives your account id, and, so that a real person is identifiable if you ever need billing support, your display name and the email address on your account. It is a billing processor working on our behalf: it does not sell your data, and none of your training, food or health data is ever sent to it. Your purchase history stays tied to your account so a reinstall restores what you paid for.
Barcode lookups
Barcode numbers you enter are sent to the Open Food Facts public database to fetch nutrition data. No personal information accompanies the request.
What we don't do
No ads, no ad networks, no tracking or advertising SDKs, no selling of data, no third-party data brokers, and no profiling of you for anyone else's benefit. The only outside parties that receive anything at all are the ones named above — Supabase for your account and backup, Anthropic for the AI features you invoke, RevenueCat and the app stores for subscriptions, and Open Food Facts for barcode lookups — and each gets only what its job here needs.
Your choices
Sign out at any time in Settings — the app keeps working from your device's data. Erase all local data in Settings → Data. To delete your account and synced data, see the account deletion page or email us.
Contact
Questions or data requests: support@momentumstreak.com
© 2026 Momentum OS. This policy mirrors the in-app version at /privacy.