Privacy Policy — StrengthHub Online
Effective 4 September 2026 · Version 1.3 Melbourne, Victoria, Australia · ACN 701 872 666 · ABN 35 701 872 666 · info@strengthhubonline.com
StrengthHub Online is operated by STRENGTHHUB ONLINE PTY LTD ("StrengthHub", "we", "us" or "our"), an Australian private company. It is a fitness, training, nutrition and wellbeing service operated from Melbourne, Victoria, Australia. This Privacy Policy explains how we handle personal information through our mobile and web application, website, AI-powered Coach and related services (together, the "Service").
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and we treat these as binding commitments rather than aspirations. Because we handle health information from Victoria, we also apply the Health Records Act 2001 (Vic) and the Health Privacy Principles (HPPs).
Contact: info@strengthhubonline.com
Contents
- Scope and age requirement
- Personal information we collect
- How we collect information
- Why we collect, use and disclose information
- AI and automated processing
- Who we disclose information to
- Overseas processing and disclosure
- How we store and protect information
- How long we retain information
- Your choices and rights
- Privacy questions and complaints
- Direct communications
- Changes to this Policy
- Contact
1. Scope and age requirement
This Policy applies to personal information we collect or hold in connection with the Service. It does not replace the privacy policy of a third-party app, store or connected service.
The Service is intended for people aged 18 and over. We do not knowingly permit children to create accounts. If you believe a person under 18 has provided personal information, contact us so we can investigate and take appropriate action.
2. Personal information we collect
The information we collect depends on the features you use and the choices you make.
Account and identity information
- email address, account identifier and optional display name;
- date of birth and age-verification status;
- university, campus, residence, society or similar community affiliation, if a profile or community feature asks for it and you choose to provide it; and
- authentication and security information. Password credentials are processed by Firebase Authentication; we do not receive your readable password.
Fitness, health and profile information
- sex, height, weight, goal weight, goals, experience and motivation;
- training availability, preferred environment and equipment, exercises and training history;
- injuries, affected body regions, limitations, symptoms, pregnancy or postpartum answers, professional-clearance status and other pre-exercise screening responses;
- nutrition entries, dietary preferences, meal plans, food check-ins, calorie and macro estimates;
- habits, sleep, recovery, activity, streaks, progress and body metrics you choose to log; and
- information about medication, physical or mental health, eating concerns or other sensitive matters that you choose to provide in screening, notes or AI conversations.
Some of this is health information or other sensitive information. Where required, we ask for consent before collecting it. You do not have to provide optional information, but the Service may be unable to personalise guidance or safely provide a feature without it.
Workout, nutrition and activity records
We collect workouts, sessions, sets, repetitions, loads, exercise substitutions, activities, meals, recipes, habits, goals and progress entries you log or import.
Progress photos are intended to remain on your device unless you deliberately use a sharing or upload feature.
AI-feature information
If you use an AI feature, we may process:
- prompts, messages and AI responses;
- selected profile, goal, screening, training-history, recovery, habit and nutrition context relevant to the request;
- recent conversation context and any coach memories you choose to save;
- your feature consent, preferences and proposed-action responses; and
- limited safety classifications, usage counters and operational safety state used to apply safeguards and prevent abuse.
Coach conversations are not reviewed live by a person by default. Do not use the Coach as an emergency or confidential clinical service.
Community and user content
Community features such as usernames, streak leaderboards, friend groups, reactions, scoring reviews and reports are active. When you use them, we collect the profile, participation, reaction, appeal/report and related activity records needed to operate them. Content you choose to publish is visible to the audience identified in the feature, such as all leaderboard users or the members of a private friend group. Any feature explicitly labelled as a preview may still use example content and will say so in the app.
To keep competitive leaderboards fair, when you take part in leagues or groups we also keep a per-day record of the activity that determines your ranking. This includes, for each day, the daily wellness figures you log — your step count, hours of sleep, water intake and a nutrition-adherence score — along with how many workouts or other activities you logged, your training volume, any rest or streak-freeze days, and the time each was recorded. This record is used to calculate your leaderboard score on our servers (so rankings cannot be faked from a modified app) and to detect implausible activity; it is visible only to you, contains no body measurements, weight or health notes, and is retained only for the period needed for scoring before being automatically deleted. It is included when you download your data and removed when you delete your account. If you appeal a review decision, the note you write is kept with your community profile (and is in your data download); the anti-cheat and moderation details behind a review are not shown to you.
If you choose to claim a username and join the global streak leaderboard, your username, current and best streak, and ranking become visible to all users of the Service. Participation is optional — you only appear after you claim a username, and you can change your username at any time. We do not display your real name, location, or health measurements on the leaderboard; only your chosen username and streak figures are shown. Reactions you add to a friend group's activity are visible only to members of that group.
Connected-service information
If you connect a compatible on-device health service such as Apple Health (iOS) or Health Connect (Android), you grant permission on your device and we receive only the data categories you approve, which may include steps, sleep, activity or workout information. These on-device connections are being introduced with our native app builds and may not be available in every version of the Service.
You can disconnect a service at any time. This stops new collection through that connection but does not by itself delete information already imported.
Subscription and transaction information
If you subscribe, we collect or receive information needed to administer access, such as your email, payment-provider customer identifier, plan, subscription status, trial and renewal dates, transaction references and limited billing metadata. Stripe or the applicable app store processes payment-card details; we do not receive or store your full card number.
Device, notification and technical information
- a device push token, notification preferences and delivery status when notifications are enabled;
- app version, device/platform type, connectivity and general diagnostic or error information;
- security and service records such as authentication events, request timestamps, rate limits and logs; and
- internet protocol address and similar network information that hosting, security and service providers may process when you use an online service.
Usage analytics information
To understand how the Service is used and to improve it, we collect limited product-usage information: which screens and features you use and how long you actively use them; session start and end and foreground engaged time; your app version, platform, operating-system version and device type; whether key steps — such as signing up, starting or completing a workout, logging progress, opening a nutrition overview, messaging the Coach, viewing the subscription offer or starting a subscription — succeed or fail; and recoverable app errors and failed network requests used to monitor reliability.
This usage information is linked to your authenticated account identifier so we can remove it when you delete your account. It is not labelled with your name or email, and it deliberately excludes free text, notes, meal contents, body measurements, health values and the content of any message. We use it in aggregate to understand product usage and improve the Service, not to make decisions about an individual user. Where a version of the Service does not enable analytics, no such usage information is collected.
We do not use third-party advertising SDKs and do not track you across unrelated apps or websites for advertising.
3. How we collect information
We collect information:
- directly from you when you create an account, complete onboarding or screening, log activity, use AI, post content, contact us or change settings;
- automatically from your device and use of the Service where needed for operation, security and notifications;
- from payment providers and app stores when you subscribe;
- from a fitness or health service you choose to connect; and
- from another person only where they are authorised to provide it or where law permits.
If you provide information about another person, you must have authority to do so and must not submit more than is necessary.
4. Why we collect, use and disclose information
We use personal information to:
- create, authenticate, secure and support accounts;
- provide onboarding, screening, training, logging, nutrition, progress, community, reminder and connected-service features;
- personalise programs and guidance using the information you provide;
- provide AI responses, meal estimates, coach memory and safety controls where enabled;
- process subscriptions, confirm entitlements and support billing enquiries;
- communicate service, security, support and policy information;
- prevent abuse, enforce our Terms, investigate incidents and protect users and the Service;
- troubleshoot, maintain and improve reliability, accessibility and safety;
- comply with law and respond to lawful requests; and
- establish, exercise or defend legal claims.
We do not sell personal information. We do not use personal information for third-party targeted advertising.
We may use aggregated or de-identified information for analysis, planning, safety evaluation and improvement where it is no longer reasonably identifiable.
5. AI and automated processing
The app includes an active AI Coach that uses Google's Gemini AI. AI systems can infer information from what you submit and can produce inaccurate results.
When you choose to use the member-facing AI Coach, your Coach messages, optional saved memories and relevant fitness or health context are processed to generate replies. An owner-only administrative question tool also uses Gemini to answer questions about an aggregate operational dashboard. It sends the owner's question and aggregate counts or trends, not member names, email addresses, messages or individual user rows. StrengthHub does not store that administrative question or answer.
Automated safety systems may block or redirect a request, limit feature use or display support information. These controls are designed to reduce risk; they do not make clinical diagnoses or decisions that have legal or similarly significant effects. A person is not monitoring each interaction in real time.
Long-term Coach memory is optional. Where available, you can pause it, inspect and delete individual memories, or clear them. You can withdraw Coach consent and delete the Coach workspace without deleting the rest of your account, subject to minimal records we must retain for security or law.
Google processes AI inputs and outputs under the terms and privacy commitments applicable to the service configuration we use. Do not submit information that is unnecessary for the feature.
6. Who we disclose information to
We disclose personal information only as reasonably necessary to:
- Google Firebase and Google Cloud, for authentication, database, hosting, storage, server functions and security;
- Google's Gemini services, for the owner-only aggregate administrative question tool and the AI Coach;
- Stripe (web checkout), RevenueCat (native app-store subscription management) or an applicable app store, for checkout, subscriptions, fraud prevention and payment support;
- Expo or another notification-delivery provider, if you enable remote notifications;
- the operating-system health platform you choose to connect on your device, such as Apple Health or Health Connect, to the extent needed to operate that connection;
- professional advisers, insurers, auditors or contractors bound by appropriate confidentiality obligations;
- a buyer, investor or successor in a genuine business transaction, subject to appropriate safeguards and notice where required;
- regulators, courts, law-enforcement bodies or other persons where required or authorised by law; and
- another person where you direct us or consent.
Community content is disclosed to the audience you select or that the feature clearly identifies. We do not sell personal information.
7. Overseas processing and disclosure
Our primary Firestore database and Cloud Functions are configured in Australian regions. The Firebase Storage bucket used for uploaded profile images is configured in the United States (US-EAST1). Some providers are global companies and may process, support or store information outside Australia.
Overseas recipients are likely to include providers in the United States. Depending on the provider, your location and its current infrastructure, information may also be processed in other countries described in that provider's published privacy or data-location materials.
Likely overseas processing includes Google AI and support systems, Stripe, RevenueCat, Expo and app stores. On-device health connections such as Apple Health and Health Connect are read locally on your device and are not, by themselves, disclosed by us overseas. Before a cross-border disclosure, we take reasonable steps required by applicable Australian privacy law, and we assess providers and contractual or technical safeguards appropriate to the information and service.
8. How we store and protect information
Cloud account and app data is primarily held using Firebase services. Some information is cached locally on your device to support performance and offline use.
We use safeguards appropriate to the nature of the information, including encrypted network connections, authentication, user-scoped access controls, restricted administrative access, service-provider controls, logging, rate limits and deletion processes.
No system is completely secure. You should use a unique password, protect your device and notify us if you suspect unauthorised access.
If a data breach is likely to cause serious harm and notification is required, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme.
9. How long we retain information
We retain account and app data while your account is active and for only as long afterwards as reasonably needed for the purposes described in this Policy, backup and security cycles, dispute resolution and legal obligations. Our Firestore point-in-time recovery history is seven days, and our daily Firestore backups are retained for seven days. Deleted user Storage objects are subject to a seven-day provider soft-delete window. Ordinary Google Cloud application and request logs are retained for 30 days; required audit logs are retained for 400 days. User-linked product analytics are scheduled to expire after 12 months (implemented as 365 days), notification-send audit records after 90 days and client-error records after 30 days. Firestore TTL deletion occurs asynchronously after the record's expiry timestamp. Account deletion removes linked records sooner.
When you delete your account, our server immediately disables access, then removes the active Firebase authentication account and the user data we control. This includes profile images, user-linked product analytics, client-error records, user-targeted notification-send records, profiles, workouts, Coach data, community records and our subscription/entitlement copies. If a deletion step fails, the job stays in progress and is retried; it is not recorded as complete until the registered Firestore data, user Storage prefix and Auth record have been handled. This is subject to:
- up to seven days for deletion to propagate through Firestore recovery history, daily backups and Storage soft-delete copies;
- financial, transaction, fraud-prevention or other records that a law requires or reasonably allows us to retain (we restrict access to any such records and delete them when the required period ends);
- information held independently by a payment, app-store or connected-service provider; and
- a minimal deletion audit record containing an account identifier and timestamp, retained only for security, compliance and evidence that the request was completed.
The minimal deletion audit is restricted to the identifier, deletion phase and timestamps and is scheduled to expire 24 months (implemented as 730 days) after completion. An in-progress deletion job is not expired before the recovery sweeper finishes it. Provider-held records follow provider and legal periods: Stripe states that it generally keeps Business User personal data for five years or more after the relationship or last transaction; Apple states that App Store purchase data is kept for financial-reporting periods of at least ten years for most customers. RevenueCat and Google Play do not publish one fixed period applicable to every record. Expo push receipts are cleared after 24 hours, while a queued notification may remain with the downstream push service for up to four weeks. These provider records are not erased by StrengthHub account deletion.
Deleting your account does not cancel a paid subscription. Cancel it first from Settings ("Manage or cancel subscription"); if you have already deleted your account and can no longer sign in, contact us at info@strengthhubonline.com and we will cancel your subscription for you.
Where deletion is not required or reasonably possible, we may de-identify information. We periodically review retained information and delete or de-identify it when no longer reasonably required.
10. Your choices and rights
Subject to applicable law and reasonable verification, you may:
- access and correct personal information through the app or by contacting us;
- download available profile and log data from Settings > Download my data;
- delete your account from Settings or request deletion by email;
- control notifications through the app and device settings;
- connect or disconnect optional third-party services;
- control available Coach consent and memory settings; and
- withdraw consent to future collection or use where we rely on consent.
Withdrawing consent does not affect earlier lawful processing and may mean a feature cannot operate. Internal security logic, confidential information about others and information we are legally entitled or required to withhold may not appear in an export.
We will respond to access and correction requests within a reasonable period. If we refuse a request, we will explain why and available complaint options where required.
11. Privacy questions and complaints
To ask a question, make a request or complain about privacy, email info@strengthhubonline.com with enough detail for us to understand the issue. Do not send unnecessary health information or account passwords.
We will acknowledge and investigate a complaint and aim to respond within 30 days. We may ask you to verify your identity or provide further information. If more time is reasonably needed, we will tell you why and provide an updated timeframe.
If you are not satisfied after giving us a reasonable opportunity to respond, you may complain to the Office of the Australian Information Commissioner at www.oaic.gov.au or by calling 1300 363 992. For a complaint about health information handled in Victoria, you may also contact the Victorian Health Complaints Commissioner at hcc.vic.gov.au or on 1300 582 113. Other complaint rights may also apply.
12. Direct communications
We may send service, billing, safety and security messages needed to operate your account. If we send optional marketing communications, we will provide a way to unsubscribe. You may still receive essential non-marketing messages while your account is active.
13. Changes to this Policy
We may update this Policy when our practices, providers, features or legal obligations change. We will publish the new effective date and take reasonable steps to notify you of a material change before it takes effect where practicable.
This Policy is a notice about how information is handled; it does not reduce rights you have under applicable law.
14. Contact
STRENGTHHUB ONLINE PTY LTD (trading as StrengthHub Online) Main business location: VIC 3161, Australia ACN: 701 872 666 ABN: 35 701 872 666 Telephone: 0435 754 525 Email: info@strengthhubonline.com