← Whetstone
Privacy Policy
Last updated & effective: September 2026
Whetstone ("Whetstone", "we", "us", "our") is a personal coaching app for fitness, nutrition, daily planning, goals, finances, spirituality, and mindset. This Privacy Policy explains what we collect, why we collect it, how it is used and shared, and the rights and choices you have. It applies to the Whetstone iOS application (the "App") and our website and waitlist at our web domain (the "Site") — together, the "Services".
The short version.
- We do not sell your personal data, and we do not share it for targeted or cross-context behavioral advertising. We are not a data broker.
- There are no advertising SDKs in the App — no ad networks, no advertising identifiers, no cross-app tracking. We use one privacy-preserving product-analytics SDK, described in Section 3, that cannot identify you and never sees anything you type.
- Your data is used for one thing: running your coaching experience.
- Apple Health data is never used for advertising, never sold, and never shared except to provide the features you asked for.
- We do not use your personal data to train AI models, and our AI providers are contractually restricted from training on it under our API configuration.
- If you join a Challenge, some of what you post there is visible to other participants — see Section 9, which is the one place in this policy where your data is shared with other users rather than with a processor.
- You can delete your account and data at any time from Settings → Delete Account.
1. Information we collect
We collect the following categories of information. Sensitive categories are marked, because several laws (including the California CPRA and GDPR Article 9) give them extra protection — and so do we.
Information you provide
- Identifiers & account — email address, display / preferred name, and authentication credentials managed by Firebase Authentication (email/password, Google sign-in, Apple sign-in, or phone number). We never see or store your Google or Apple password.
- Phone number — if you choose to sign in with your phone number, we collect that number and Firebase Authentication sends you a one-time verification code by SMS. Your carrier's standard message and data rates may apply. The number is stored with your account as a sign-in identifier; we do not use it for marketing, and we never sell or share it.
- Demographic & body data (sensitive) — if you provide them: age, sex, height, weight, activity level, and fitness goals, used to compute calorie and macro targets.
- Health & fitness data (sensitive) — workouts you log (exercises, sets, weights), training preferences, sleep schedule, streaks, and wellness check-ins such as reflections and gratitude entries.
- Nutrition data (sensitive) — foods and meals you log, portion estimates, calorie/macro totals, dietary preferences, restrictions, and allergies.
- Meal photos — if you snap or attach a photo of food, the image is sent to our AI providers to identify the meal and estimate nutrition, and the resulting food entry is stored with your log. See "AI processing" below.
- Voice / spoken audio — if you use voice mode to talk to the coach, your speech is sent to Apple's speech-recognition service to produce a text transcript; the transcript is then processed like any other message you type. See Section 4.
- Religious & spiritual data (sensitive) — participation in faith features is optional. If you choose to share your religious affiliation or use prayer, reflection, or faith-based content, we store those preferences and entries to personalize the Spiritual section. You can use the entire rest of the App without disclosing any belief, and you can change or remove your faith setting at any time in Settings. Religious data is never used for advertising and never shared except as needed to generate the content you requested.
- Financial data (sensitive) — figures you choose to enter, such as income, expenses, savings balances, savings goals, and business planning details. Whetstone does not connect to your bank, and we never collect bank credentials, account numbers, or card numbers.
- Goals, schedule & planning data — goals and streaks, calendar events and routines you create in the App, and preferences used to plan your day (e.g., gym days, prayer times, business hours).
- Calendar data — if you connect a calendar, event titles, times, and busy/free status from your connected calendar(s), so the App can plan around your real commitments and create or move events on your behalf. See Section 5.
- Coach chat content — messages you send to the AI coach, by text or (transcribed) by voice. Be aware that free-text chat can contain anything you choose to type or say, including sensitive information (health conditions, beliefs, finances, mood). We treat all chat content with the protections described in this policy regardless of what it contains.
- Challenge / social content — if you create, join, or participate in a Challenge: your display name, your progress on shared goals, and any notes or photos you post as proof of activity. This category is shared with other people, not only with us — see Section 9.
- Waitlist information (Site) — if you join the waitlist, your email address and first name, stored in our Firebase database and used only to contact you about Whetstone availability and launch updates.
Information from Apple Health (HealthKit)
- With your explicit permission, we read your step count and walking/running distance to power your movement rings and activity insights. We do not write to Apple Health, and we do not read any other Health data types.
- You can revoke access at any time in iOS Settings → Privacy & Security → Health → Whetstone, and the App will continue to work without it.
Information collected automatically
- Device & technical data — basic device information needed to run the service (e.g., device model, OS version) and server logs (e.g., IP address, timestamps) generated when the App communicates with our backend, used for security, debugging, and abuse prevention.
- Product analytics — we use Firebase Analytics, configured specifically to protect your privacy: it cannot read your device's advertising identifier (we link the "without ad ID" variant of the SDK), we explicitly deny ad storage, ad-personalization, and ad-user-data collection, and we never call the function that would tie events to your account. What it records is limited to a fixed list of product events (e.g., which section you opened, which coach tool ran, whether you completed onboarding) and a few banded, non-identifying properties (e.g., an age range, a training-frequency range) — the code that sends analytics events is written so that it is structurally impossible to include a chat message, a food name, a goal title, or any other free-text content you typed. See Section 3.
- The App contains no advertising or cross-app tracking SDKs, and we do not collect advertising identifiers (IDFA), precise location, or your contacts.
Derived data (inferences)
- The Services generate personalized outputs from your inputs — e.g., calorie/macro targets, workout splits, day plans, goal timing suggestions, and coaching recommendations. These inferences are stored with your account and treated as your personal data.
2. Sources of information
We collect information (a) directly from you, (b) automatically when you use the Services, (c) from Apple HealthKit with your permission, (d) from a calendar provider you connect (Apple, Google, or Outlook) with your permission, (e) from your device's microphone when you use voice mode, and (f) from other Challenge participants when you view content they've posted to a Challenge you're also in. We do not purchase data about you from data brokers or enrich your profile from third-party sources.
3. How we use your information
- To provide the Services — logging food and workouts, planning your day, syncing your calendar, tracking goals and streaks, computing nutrition targets, managing your schedule, running Challenges, and syncing your data across your devices.
- To power AI coaching — generating coach replies, meal identification, plans, and recommendations, whether you typed or spoke to the coach (see "AI processing" below).
- To communicate with you — service messages about your account, and (for the waitlist) availability and launch updates. Every marketing-style email includes an unsubscribe option, which we honor.
- Reminders & notifications — local notifications on your device (e.g., streak or goal reminders) that you can disable in iOS Settings at any time.
- Product analytics — understanding which features are used and where people drop off during onboarding, using the privacy-preserving analytics described in Section 1, so we can decide what to build or fix next. This is never used to identify you individually, to advertise to you, or to make any decision that affects you.
- Security, integrity & legal compliance — protecting the Services against abuse, debugging, enforcing our Terms, and complying with law.
We do not use your information for third-party advertising, cross-app tracking, profiling that produces legal or similarly significant effects, or automated decisions of that kind.
4. AI processing, including voice
- Who processes it. AI features are powered by Anthropic (Claude models) and OpenAI via their commercial APIs. When you use AI features, relevant context is transmitted to them to generate a response — for example: your chat message (typed or transcribed from voice), recent workouts, nutrition totals and targets, goals, schedule and calendar context, financial figures you've entered, spiritual preferences (if enabled), and meal photos you submit for identification.
- Voice mode specifically. When you talk to the coach, your spoken audio is sent to Apple's speech-recognition service to be converted into text — for anything other than a short, fully on-device dictation, this means your voice leaves your device to be transcribed. Only the resulting text (not the audio recording) is then sent onward to Anthropic/OpenAI as described above. The coach's spoken replies are generated entirely on your device using Apple's speech-synthesis system and are never sent anywhere. You can revoke microphone and speech-recognition access at any time in iOS Settings → Privacy & Security, and use text chat instead.
- No training on your data. Under the commercial API terms we use, Anthropic and OpenAI do not use API inputs or outputs to train their models. We likewise do not use your personal data to train, fine-tune, or improve any large language model or other AI model, and we do not sell personal data for AI training.
- Limited provider retention. AI providers may retain API data briefly for trust-and-safety / abuse monitoring under their policies, after which it is deleted per their retention terms. Apple's speech-recognition service processes audio to produce a transcript under Apple's own privacy terms, which we do not control.
- Health data and AI. Health-related context is sent to AI providers solely to provide the coaching features you request — never for advertising, marketing, or data mining.
- AI output disclaimer. AI-generated content can be inaccurate or incomplete. Coaching output is general wellness information — it is not medical, mental-health, nutrition/dietetic, financial, investment, tax, legal, or religious professional advice, and it is not delivered by a human being. See our Terms of Service for the full disclaimers. Always consult a qualified professional before acting on health or financial decisions.
5. Calendar integration
Whetstone supports connecting a calendar so the coach can plan around your real schedule. Apple Calendar is available today; Google Calendar and Outlook Calendar are supported and rolling out to users. This section applies to any calendar you connect, whichever provider it is.
- What we access. With your permission, we read event titles, start/end times, and busy/free status from your connected calendar(s), and we create, update, or delete events — including a dedicated "Whetstone" calendar we create for coach-generated plans, and, where you've granted access, events on your own calendars.
- Why. Solely to plan your day around your real commitments and to let the coach create or adjust events at your request. We do not use calendar data for advertising, and we do not analyze the content of unrelated meetings beyond what's needed to know you're busy at that time.
- Where it's used. Calendar-derived information (e.g., a recurring commitment's title and time) may be included as context sent to our AI providers (Section 4) so the coach can plan around it, and is stored with your account so it can sync across your devices.
- Google Calendar — Limited Use disclosure. Whetstone's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google Calendar data for advertising, we do not allow humans to read it except as needed for security, legal compliance, or with your consent, and we do not sell it or transfer it to third parties except as described in this policy.
- Revoking access. Disconnect a calendar at any time in Settings → Calendars, or revoke access directly from your Apple, Google, or Microsoft account settings. Disconnecting stops future sync; events already created stay on your calendar and in our systems until you delete them or your account.
- Token storage. If you connect Google or Outlook, we store the access/refresh tokens needed to sync on our backend, scoped to your account and never readable by any client app directly — only our servers can use them, and only to sync your calendar.
6. Apple HealthKit — required disclosures
- Data obtained through HealthKit is used only to provide health and fitness features you request in the App.
- HealthKit data is never used for advertising, marketing, or other use-based data mining; it is never sold to anyone, including advertisers, data brokers, or information resellers; and it is never shared with third parties without your explicit consent, and then only to provide the service you asked for.
- You control access at all times through the iOS Health permissions screen.
7. How we share information
We do not sell personal data, and we do not share it for targeted or cross-context behavioral advertising. We have not done so in the preceding 12 months. Other than Section 9 (Challenges, where you choose to share with other users), we share information only as follows:
- Service providers (processors) that run the Services on our behalf, under agreements limiting their use of your data:
- Google Firebase / Google Cloud — authentication (including Google Sign-In), database (Firestore), file storage, cloud functions, website hosting, and the privacy-preserving product analytics described in Section 1. Your account and app data are stored here.
- Anthropic and OpenAI — AI processing as described in Section 4.
- Apple — sign-in with Apple, App Store distribution, Apple Calendar sync, on-device HealthKit and notifications, and (for voice mode) speech recognition and speech synthesis.
- Google and Microsoft — if you connect Google Calendar or Outlook Calendar, as described in Section 5.
- Voyage AI and Pinecone — the coach's long-term memory. Snippets of your coaching context are turned into numerical embeddings by Voyage AI and stored/searched in a Pinecone vector index so the coach can recall relevant past details. This data is scoped to your account and used only to power your coaching.
- Food & nutrition database lookups — when you log or search for a food, the food name or barcode is sent to Spoonacular, the USDA FoodData Central database, and/or Open Food Facts to look up nutrition information. No account identifiers are attached to these lookups.
- Book & meal photo lookups — when the Spiritual section shows book recommendations, the book's title is sent to Open Library / Google Books to fetch a cover image. When a meal plan needs a photo, the meal's name is sent to Unsplash to fetch stock photography. No personal data is included in either kind of request.
- Legal & safety — if required by law, subpoena, or legal process; to enforce our Terms; or to protect the rights, safety, or property of you, us, or others.
- Business transfers — if we are involved in a merger, acquisition, financing, reorganization, or sale of assets, your information may be transferred as part of that transaction. This policy (or one at least as protective) will continue to apply, and we will notify you of material changes.
- Aggregated / de-identified data — we may use and share data that cannot reasonably identify you (e.g., overall usage statistics). We commit to maintaining such data in de-identified form and to never attempt to re-identify it.
We do not share your data with data brokers or ad networks.
8. Cookies & website tracking
The Site is a static page with a waitlist form. It does not set advertising or analytics cookies and contains no third-party trackers or advertising pixels. Because we do not track visitors across sites, there is nothing to opt out of; where a browser sends a Global Privacy Control (GPC) or Do-Not-Track signal, our no-tracking practice already complies with it.
9. Social features — Challenges
This is the one part of Whetstone where your data is shared with other users, not just with us or our processors. Read this section before posting anything to a Challenge.
- What's visible, and to whom. If you create, join, or are invited to a Challenge, your display name, your progress and score on that Challenge's goals, and any notes or photos you post as proof of activity are visible to anyone who has that Challenge's invite code, QR code, or link — not only the specific people you invited or who invited you.
- Health-adjacent data can appear here. Depending on the Challenge's goals, your posted activity can include figures like calories logged, workouts completed, steps, or focus/meditation minutes — the same categories described as sensitive elsewhere in this policy, but here shared with other people at your choice, not with a processor. See our Consumer Health Data Privacy Policy for how this fits our health-data practices.
- We do not vet other participants. Anyone with a Challenge's invite code or link can potentially view it. Do not post sensitive personal information, precise location, or anything you wouldn't want a stranger to see.
- Removing content. Leaving a Challenge stops future sharing but does not retroactively delete what you already posted to it; contact us to request removal of specific content.
- Challenges have no in-app messaging between participants — the only shared surface is the progress leaderboard and the activity/proof log described above.
10. Your rights & choices
Depending on where you live, you may have some or all of the following rights, which we extend to all users regardless of location:
- Access / know — request a copy of the personal data we hold about you and information about how it is used and shared.
- Correction — most data can be corrected directly in the App; you may also ask us to correct inaccurate data.
- Deletion — delete your account and data in-app (Settings → Delete Account) or by contacting us.
- Portability — receive your data in a portable, machine-readable format.
- Opt out of sale / sharing / targeted advertising — we do not sell or share personal data for these purposes, so there is nothing to opt out of; if that ever changed, we would provide a clear opt-out first.
- Limit use of sensitive personal information — we already use sensitive data (health, religion, finances) only to provide the Services you request, which is the limited use contemplated by the CPRA.
- Opt out of profiling — we do not use your data for profiling in furtherance of decisions with legal or similarly significant effects.
- Non-discrimination — we will never discriminate against you for exercising your rights.
- Appeal — if we decline a request, you may appeal by replying to our decision; we will respond to appeals as required by your state's law, and you may also contact your state Attorney General.
How to exercise rights: use the in-app controls or email dillonkeating20@gmail.com with the subject "Privacy Request". We will verify your request using your account email and respond within 45 days (extendable by 45 days where permitted, with notice). You may use an authorized agent where your state's law allows; we will verify the agent's authority.
California (CCPA/CPRA) disclosure summary
| Category | Collected? | Disclosed to (service providers only, unless noted) | Sold / shared for ads? |
| Identifiers (name, email, phone number) | Yes | Google Firebase | No |
| Sensitive PI — health & fitness, nutrition | Yes | Google Firebase; Anthropic/OpenAI (to generate output); other Challenge participants if you post it there | No |
| Sensitive PI — religious beliefs (optional) | Only if you opt in | Google Firebase; Anthropic/OpenAI (to generate output) | No |
| Sensitive PI — financial data you enter | Yes | Google Firebase; Anthropic/OpenAI (to generate output) | No |
| Photos (meal photos, Challenge proof photos) | Yes | Anthropic/OpenAI (meal identification); Google Firebase (storage); other Challenge participants for photos you post there | No |
| Calendar data (if connected) | Only if you connect a calendar | Google Firebase; Apple/Google/Microsoft (the provider you connect); Anthropic/OpenAI (planning context) | No |
| Voice / audio (if you use voice mode) | Only if you use voice mode | Apple (speech recognition only; only the resulting text goes to Anthropic/OpenAI) | No |
| Audio, video, biometric identifiers | No | — | — |
| Precise geolocation | No | — | — |
| Internet activity / device logs | Limited (service logs, privacy-preserving product analytics — see Section 1) | Google Firebase | No |
| Inferences (plans, targets, recommendations) | Yes | Google Firebase | No |
European Economic Area, UK & Switzerland (GDPR)
- Legal bases: performance of our contract with you (providing the Services); your explicit consent for special-category data — health and fitness data, and religious or philosophical beliefs (Art. 9(2)(a)) — which you give when you enable those features and can withdraw at any time in Settings or by deleting the data; legitimate interests (service security, abuse prevention, product analytics as described in Section 1); and legal obligation.
- Your rights include access, rectification, erasure, restriction, portability, objection, withdrawal of consent (without affecting prior processing), and the right to lodge a complaint with your supervisory authority.
- Transfers: data is processed and stored in the United States. Where required, transfers rely on safeguards such as Standard Contractual Clauses and/or the EU–U.S. Data Privacy Framework as applicable to our providers.
11. Consumer health data (Washington, Nevada & similar laws)
Some of the data described above — such as nutrition logs, workouts, body measurements, and wellness check-ins — is "consumer health data" under laws like the Washington My Health My Data Act and Nevada SB 370. Our separate Consumer Health Data Privacy Policy describes the categories of health data we collect, our purposes, who receives it (including, if you choose to use Challenges, other participants), and how to exercise your rights. In short: we collect only the health data needed for the features you use, we obtain your consent before collecting it, we never sell it, we don't share it with processors beyond those that run the Services, we do share it with other users only where you choose to post it to a Challenge, and we do not use geofencing around health facilities (or at all).
12. Data retention
- Account & app data (logs, goals, plans, chat context, preferences, calendar sync state) — retained while your account is active, then deleted when you delete your account.
- Meal photos — used to identify the meal; the derived food entry is kept with your log, and images are not retained longer than needed for that purpose and your log history.
- Calendar tokens & mirrored events — retained while a calendar stays connected; deleted when you disconnect it or delete your account.
- Voice audio — processed by Apple's speech-recognition service to produce a transcript; we do not separately store the audio recording, only the resulting transcript, which is retained like any other chat message.
- Challenge content — retained for as long as the Challenge exists, or until you or we remove it; see Section 9 on why leaving a Challenge doesn't retroactively delete what you already posted.
- Waitlist data — retained until launch communications conclude or you ask to be removed.
- Server logs — kept for a short period for security and debugging, then deleted or de-identified.
- We may retain limited information where required for legal, security, or fraud-prevention purposes, and de-identified data indefinitely.
13. Deletion & account controls
You can delete your account and associated data at any time in the App: Settings → Delete Account. This removes your account and your app data from our systems (subject to short backup cycles and legal retention requirements). You can also email us to request deletion. Other controls: disconnect a calendar or revoke Apple Health access in Settings / iOS Settings; disable notifications in iOS Settings; revoke microphone/speech-recognition access to stop using voice mode; leave a Challenge to stop sharing new activity to it (see Section 9 for what doesn't retroactively delete); change or remove your faith setting, body stats, financial figures, and other data directly in the App.
14. Security
We use reasonable administrative and technical safeguards appropriate to the sensitivity of the data: encryption in transit (TLS) and at rest in Google Cloud/Firebase, authentication-scoped access rules so your data is only readable by your account, and least-privilege access to production systems. No method of storage or transmission is 100% secure, and we cannot guarantee absolute security — please use a strong, unique password.
15. Breach notification
If a breach of security affecting your personal data occurs, we will notify you and applicable regulators as required by the laws that apply to you.
16. International users
The Services are operated from the United States, and your information is processed and stored in the U.S., where privacy laws may differ from those of your country. By using the Services you understand your information will be transferred to and processed in the U.S. as described in this policy.
17. Children
Whetstone is not directed to children under 13, and we do not knowingly collect personal data from children under 13 (or under the age required by your jurisdiction). If we learn we have collected such data, we will delete it promptly. Challenges are not intended for use by children and rely on you and other participants being old enough to use the App under our Terms. If you believe a child has provided us data, including through a Challenge, contact us at the email below.
18. Third-party services & links
The Services may link to or interact with third-party services (e.g., Apple Health, Apple/Google/Microsoft Calendar, Apple's speech recognition, Google sign-in, book listings, Unsplash). Those services are governed by their own privacy policies, which we encourage you to read. We are not responsible for the privacy practices of third parties.
19. Changes to this policy
We may update this policy from time to time. Material changes will be posted here with a new "last updated" date, and where required by law we will provide additional notice (e.g., in-app). If we intend to use previously collected data in a new way, or start collecting a new type of data through a connected service such as Google Calendar, we will update this policy first and, where required, ask for your renewed consent. Your continued use of the Services after changes take effect means you accept the updated policy.
20. Contact us
Privacy questions, requests, or appeals: dillonkeating20@gmail.com (subject: "Privacy Request").
Related: Consumer Health Data Privacy Policy · Terms of Service