← Whetstone
Privacy Policy
Last updated & effective: July 7, 2026
Whetstone ("Whetstone", "we", "us", "our") is a personal coaching app for fitness, nutrition, daily planning, goals, finances, spirituality, and mindset. This Privacy Policy explains what we collect, why we collect it, how it is used and shared, and the rights and choices you have. It applies to the Whetstone iOS application (the "App") and our website and waitlist at our web domain (the "Site") — together, the "Services".
The short version.
- We do not sell your personal data, and we do not share it for targeted or cross-context behavioral advertising. We are not a data broker.
- There are no third-party advertising or analytics SDKs in the App — no ad networks, no trackers, no advertising identifiers.
- Your data is used for one thing: running your coaching experience.
- Apple Health data is never used for advertising, never sold, and never shared except to provide the features you asked for.
- We do not use your personal data to train AI models, and our AI providers are contractually restricted from training on it under our API configuration.
- You can delete your account and data at any time from Settings → Delete Account.
1. Information we collect
We collect the following categories of information. Sensitive categories are marked, because several laws (including the California CPRA and GDPR Article 9) give them extra protection — and so do we.
Information you provide
- Identifiers & account — email address, display / preferred name, and authentication credentials managed by Firebase Authentication (email/password, Google sign-in, or Apple sign-in). We never see or store your Google or Apple password.
- Demographic & body data (sensitive) — if you provide them: age, sex, height, weight, activity level, and fitness goals, used to compute calorie and macro targets.
- Health & fitness data (sensitive) — workouts you log (exercises, sets, weights), training preferences, sleep schedule, streaks, and wellness check-ins such as reflections and gratitude entries.
- Nutrition data (sensitive) — foods and meals you log, portion estimates, calorie/macro totals, dietary preferences, restrictions, and allergies.
- Meal photos — if you snap or attach a photo of food, the image is sent to our AI providers to identify the meal and estimate nutrition, and the resulting food entry is stored with your log. See "AI processing" below.
- Religious & spiritual data (sensitive) — participation in faith features is optional. If you choose to share your religious affiliation or use prayer, reflection, or faith-based content, we store those preferences and entries to personalize the Spiritual section. You can use the entire rest of the App without disclosing any belief, and you can change or remove your faith setting at any time in Settings. Religious data is never used for advertising and never shared except as needed to generate the content you requested.
- Financial data (sensitive) — figures you choose to enter, such as income, expenses, savings balances, savings goals, and business planning details. Whetstone does not connect to your bank, and we never collect bank credentials, account numbers, or card numbers.
- Goals, schedule & planning data — goals and streaks, calendar events and routines you create in the App, and preferences used to plan your day (e.g., gym days, prayer times, business hours).
- Coach chat content — messages you send to the AI coach. Be aware that free-text chat can contain anything you choose to type, including sensitive information (health conditions, beliefs, finances, mood). We treat all chat content with the protections described in this policy regardless of what it contains.
- Waitlist information (Site) — if you join the waitlist, your email address and first name, stored in our Firebase database and used only to contact you about Whetstone availability and launch updates.
Information from Apple Health (HealthKit)
- With your explicit permission, we read your step count and walking/running distance to power your movement rings and activity insights. We do not write to Apple Health, and we do not read any other Health data types.
- You can revoke access at any time in iOS Settings → Privacy & Security → Health → Whetstone, and the App will continue to work without it.
Information collected automatically
- Device & technical data — basic device information needed to run the service (e.g., device model, OS version) and server logs (e.g., IP address, timestamps) generated when the App communicates with our backend, used for security, debugging, and abuse prevention.
- Usage of features — functional state the App needs to operate (e.g., which sections you've set up, streak counts). The App contains no third-party analytics, advertising, or tracking SDKs, and we do not collect advertising identifiers (IDFA), precise location, or your contacts.
Derived data (inferences)
- The Services generate personalized outputs from your inputs — e.g., calorie/macro targets, workout splits, day plans, goal timing suggestions, and coaching recommendations. These inferences are stored with your account and treated as your personal data.
2. Sources of information
We collect information (a) directly from you, (b) automatically when you use the Services, and (c) from Apple HealthKit with your permission. We do not purchase data about you from data brokers or enrich your profile from third-party sources.
3. How we use your information
- To provide the Services — logging food and workouts, planning your day, tracking goals and streaks, computing nutrition targets, managing your schedule, and syncing your data across your devices.
- To power AI coaching — generating coach replies, meal identification, plans, and recommendations (see "AI processing" below).
- To communicate with you — service messages about your account, and (for the waitlist) availability and launch updates. Every marketing-style email includes an unsubscribe option, which we honor.
- Reminders & notifications — local notifications on your device (e.g., streak or goal reminders) that you can disable in iOS Settings at any time.
- Security, integrity & legal compliance — protecting the Services against abuse, debugging, enforcing our Terms, and complying with law.
We do not use your information for third-party advertising, cross-app tracking, profiling that produces legal or similarly significant effects, or automated decisions of that kind.
4. AI processing
- Who processes it. AI features are powered by Anthropic (Claude models) and OpenAI via their commercial APIs. When you use AI features, relevant context is transmitted to them to generate a response — for example: your chat message, recent workouts, nutrition totals and targets, goals, schedule context, financial figures you've entered, spiritual preferences (if enabled), and meal photos you submit for identification.
- No training on your data. Under the commercial API terms we use, Anthropic and OpenAI do not use API inputs or outputs to train their models. We likewise do not use your personal data to train, fine-tune, or improve any large language model or other AI model, and we do not sell personal data for AI training.
- Limited provider retention. AI providers may retain API data briefly for trust-and-safety / abuse monitoring under their policies, after which it is deleted per their retention terms.
- Health data and AI. Health-related context is sent to AI providers solely to provide the coaching features you request — never for advertising, marketing, or data mining.
- AI output disclaimer. AI-generated content can be inaccurate or incomplete. Coaching output is general wellness information — it is not medical, mental-health, nutrition/dietetic, financial, investment, tax, legal, or religious professional advice. See our Terms of Service for the full disclaimers. Always consult a qualified professional before acting on health or financial decisions.
5. Apple HealthKit — required disclosures
- Data obtained through HealthKit is used only to provide health and fitness features you request in the App.
- HealthKit data is never used for advertising, marketing, or other use-based data mining; it is never sold to anyone, including advertisers, data brokers, or information resellers; and it is never shared with third parties without your explicit consent, and then only to provide the service you asked for.
- You control access at all times through the iOS Health permissions screen.
6. How we share information
We do not sell personal data, and we do not share it for targeted or cross-context behavioral advertising. We have not done so in the preceding 12 months. We share information only as follows:
- Service providers (processors) that run the Services on our behalf, under agreements limiting their use of your data:
- Google Firebase / Google Cloud — authentication (including Google Sign-In), database (Firestore), file storage, cloud functions, and website hosting. Your account and app data are stored here.
- Anthropic and OpenAI — AI processing as described in Section 4.
- Voyage AI and Pinecone — the coach's long-term memory. Snippets of your coaching context are turned into numerical embeddings by Voyage AI and stored/searched in a Pinecone vector index so the coach can recall relevant past details. This data is scoped to your account and used only to power your coaching.
- Apple — sign-in with Apple, App Store distribution, and (on-device) HealthKit and notifications.
- Food & nutrition database lookups — when you log or search for a food, the food name or barcode is sent to Spoonacular, the USDA FoodData Central database, and/or Open Food Facts to look up nutrition information. No account identifiers are attached to these lookups.
- Book cover lookups — when the Spiritual section shows book recommendations, the book's title is sent to Open Library / Google Books to fetch a cover image. No personal data is included in these requests.
- Legal & safety — if required by law, subpoena, or legal process; to enforce our Terms; or to protect the rights, safety, or property of you, us, or others.
- Business transfers — if we are involved in a merger, acquisition, financing, reorganization, or sale of assets, your information may be transferred as part of that transaction. This policy (or one at least as protective) will continue to apply, and we will notify you of material changes.
- Aggregated / de-identified data — we may use and share data that cannot reasonably identify you (e.g., overall usage statistics). We commit to maintaining such data in de-identified form and to never attempt to re-identify it.
We do not share your data with data brokers, ad networks, or analytics companies.
7. Cookies & website tracking
The Site is a static page with a waitlist form. It does not set advertising or analytics cookies and contains no third-party trackers or advertising pixels. Because we do not track visitors across sites, there is nothing to opt out of; where a browser sends a Global Privacy Control (GPC) or Do-Not-Track signal, our no-tracking practice already complies with it.
8. Your rights & choices
Depending on where you live, you may have some or all of the following rights, which we extend to all users regardless of location:
- Access / know — request a copy of the personal data we hold about you and information about how it is used and shared.
- Correction — most data can be corrected directly in the App; you may also ask us to correct inaccurate data.
- Deletion — delete your account and data in-app (Settings → Delete Account) or by contacting us.
- Portability — receive your data in a portable, machine-readable format.
- Opt out of sale / sharing / targeted advertising — we do not sell or share personal data for these purposes, so there is nothing to opt out of; if that ever changed, we would provide a clear opt-out first.
- Limit use of sensitive personal information — we already use sensitive data (health, religion, finances) only to provide the Services you request, which is the limited use contemplated by the CPRA.
- Opt out of profiling — we do not use your data for profiling in furtherance of decisions with legal or similarly significant effects.
- Non-discrimination — we will never discriminate against you for exercising your rights.
- Appeal — if we decline a request, you may appeal by replying to our decision; we will respond to appeals as required by your state's law, and you may also contact your state Attorney General.
How to exercise rights: use the in-app controls or email dillonkeating20@gmail.com with the subject "Privacy Request". We will verify your request using your account email and respond within 45 days (extendable by 45 days where permitted, with notice). You may use an authorized agent where your state's law allows; we will verify the agent's authority.
California (CCPA/CPRA) disclosure summary
| Category | Collected? | Disclosed to (service providers only) | Sold / shared for ads? |
| Identifiers (name, email) | Yes | Google Firebase | No |
| Sensitive PI — health & fitness, nutrition | Yes | Google Firebase; Anthropic/OpenAI (to generate output) | No |
| Sensitive PI — religious beliefs (optional) | Only if you opt in | Google Firebase; Anthropic/OpenAI (to generate output) | No |
| Sensitive PI — financial data you enter | Yes | Google Firebase; Anthropic/OpenAI (to generate output) | No |
| Photos (meal photos) | Yes | Anthropic/OpenAI (identification); Google Firebase (storage) | No |
| Audio, video, biometric identifiers | No | — | — |
| Precise geolocation | No | — | — |
| Internet activity / device logs | Limited (service logs) | Google Firebase | No |
| Inferences (plans, targets, recommendations) | Yes | Google Firebase | No |
European Economic Area, UK & Switzerland (GDPR)
- Legal bases: performance of our contract with you (providing the Services); your explicit consent for special-category data — health and fitness data, and religious or philosophical beliefs (Art. 9(2)(a)) — which you give when you enable those features and can withdraw at any time in Settings or by deleting the data; legitimate interests (service security, abuse prevention); and legal obligation.
- Your rights include access, rectification, erasure, restriction, portability, objection, withdrawal of consent (without affecting prior processing), and the right to lodge a complaint with your supervisory authority.
- Transfers: data is processed and stored in the United States. Where required, transfers rely on safeguards such as Standard Contractual Clauses and/or the EU–U.S. Data Privacy Framework as applicable to our providers.
9. Consumer health data (Washington, Nevada & similar laws)
Some of the data described above — such as nutrition logs, workouts, body measurements, and wellness check-ins — is "consumer health data" under laws like the Washington My Health My Data Act and Nevada SB 370. Our separate Consumer Health Data Privacy Policy describes the categories of health data we collect, our purposes, who receives it, and how to exercise your rights. In short: we collect only the health data needed for the features you use, we obtain your consent before collecting it, we never sell it, we don't share it except with the processors that run the Services, and we do not use geofencing around health facilities (or at all).
10. Data retention
- Account & app data (logs, goals, plans, chat context, preferences) — retained while your account is active, then deleted when you delete your account.
- Meal photos — used to identify the meal; the derived food entry is kept with your log, and images are not retained longer than needed for that purpose and your log history.
- Waitlist data — retained until launch communications conclude or you ask to be removed.
- Server logs — kept for a short period for security and debugging, then deleted or de-identified.
- We may retain limited information where required for legal, security, or fraud-prevention purposes, and de-identified data indefinitely.
11. Deletion & account controls
You can delete your account and associated data at any time in the App: Settings → Delete Account. This removes your account and your app data from our systems (subject to short backup cycles and legal retention requirements). You can also email us to request deletion. Other controls: revoke Apple Health access in iOS Settings; disable notifications in iOS Settings; change or remove your faith setting, body stats, financial figures, and other data directly in the App.
12. Security
We use reasonable administrative and technical safeguards appropriate to the sensitivity of the data: encryption in transit (TLS) and at rest in Google Cloud/Firebase, authentication-scoped access rules so your data is only readable by your account, and least-privilege access to production systems. No method of storage or transmission is 100% secure, and we cannot guarantee absolute security — please use a strong, unique password.
13. Breach notification
If a breach of security affecting your personal data occurs, we will notify you and applicable regulators as required by the laws that apply to you.
14. International users
The Services are operated from the United States, and your information is processed and stored in the U.S., where privacy laws may differ from those of your country. By using the Services you understand your information will be transferred to and processed in the U.S. as described in this policy.
15. Children
Whetstone is not directed to children under 13, and we do not knowingly collect personal data from children under 13 (or under the age required by your jurisdiction). If we learn we have collected such data, we will delete it promptly. If you believe a child has provided us data, contact us at the email below.
16. Third-party services & links
The Services may link to or interact with third-party services (e.g., Apple Health, Google sign-in, book listings). Those services are governed by their own privacy policies, which we encourage you to read. We are not responsible for the privacy practices of third parties.
17. Changes to this policy
We may update this policy from time to time. Material changes will be posted here with a new "last updated" date, and where required by law we will provide additional notice (e.g., in-app). Your continued use of the Services after changes take effect means you accept the updated policy.
18. Contact us
Privacy questions, requests, or appeals: dillonkeating20@gmail.com (subject: "Privacy Request").
Related: Consumer Health Data Privacy Policy · Terms of Service