Open the app

Legal

Privacy policy

This policy explains what personal data ARMR. collects, why, who helps us process it, how long we keep it and the rights you have over it.

Last updated: 8 October 2026

1. Who we are

ARMR. is a fitness app available on the web at armr.app/app, and soon as iOS and Android apps that wrap the same app. The service is operated from the United Kingdom. ARMR. is the controller of the personal data described in this policy.

For anything to do with your data, email support@armr.app.

We handle personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. The short version

  • ARMR. is free. There are no payments, no adverts and no tracking or analytics SDKs.
  • We never sell your data, and we never share it for advertising.
  • Your weight, height and BMI are private to you and are never shown to anyone else.
  • You choose who sees each workout: Public, Friends or Only me.
  • You can delete your account at any time from inside the app. See Delete account.

3. What we collect

Account details

  • Your name, email address and username (handle).
  • Your password, which we store only as a salted PBKDF2 hash. We never store or see your actual password.
  • Optional: a bio and a profile photo.
  • Your private-account setting.

We use your email address to send account emails, such as confirming your email address and resetting your password. These are sent through Cloudflare’s email service from noreply@lannex.uk (this sending address may change). We do not send marketing emails.

Sign-in sessions

When you sign in, we create a session. On the web this is held in a secure, HttpOnly cookie; in the mobile apps a session token is stored on your device. On our server we store only a hash of the session token, never the token itself. Sessions last up to 60 days.

Training data

  • The programmes you choose and your progress through them.
  • Your workout history: title, duration, intensity score, recovery estimate, calories and average heart rate summaries.
  • Your daily checklist habits and your daily and weekly scores.

This app data is stored on your device and synced to your account so that it works across your devices.

Body check-ins

If you log body check-ins, we store your weight and height, and the app calculates your BMI from them. This information is private to you and is never shown to other users.

Food log (Fuel)

The foods and meals you log, their calories and macros, and the targets you set. See section 5 for how photo and barcode scanning work.

Social activity

Who you follow and who follows you, follow requests, workouts you share, kudos, comments, @mentions, chat board posts, direct messages (including photos, stickers, shared workouts and “train together” invites), and the notifications these create.

Uploaded images

Profile photos and photos you send in chat are stored in the app database and served through unguessable links.

Reports and blocks

If you report something, we store who made the report, the reason given and a copy of the reported content so our team can review it. If you block someone, we store that block so it can be enforced.

4. Heart rate and health data

Bluetooth heart-rate sensors

If you connect a Bluetooth heart-rate sensor, live readings are processed in the app during your workout. When the workout ends, a summary is saved with it in your synced app data: average and maximum heart rate, time in each heart-rate zone, and a simplified heart-rate trace (up to 120 points) used to draw the chart on your workout summary.

Apple Health and Health Connect (planned)

We plan to support Apple Health and Health Connect in the mobile apps. If and when you grant permission, the app will:

  • read only the data types you allow;
  • use that data only to show your own scores and stats;
  • never use it for advertising; and
  • never sell it.

Health data obtained from Apple Health is not shared with third parties.

Where information about your health counts as special category data under UK GDPR, we process it only with your explicit consent, which you give by choosing to connect a sensor or grant health permissions. You can withdraw that consent at any time by disconnecting the sensor or revoking the permission in your device settings.

5. Food log and scanning

Food photo scanning

When you scan a food photo, the photo is sent to an AI model which estimates the food and its macros. This is processed by Anthropic (Claude) or Cloudflare Workers AI. ARMR. does not store photos sent for scanning once the estimate has been returned.

Barcode scanning

When you scan a barcode, the barcode number is looked up in Open Food Facts, a public food database, directly from your device. Open Food Facts receives the barcode number and the technical details any website receives (such as your IP address); it does not receive your ARMR. account details.

6. What other people can see

  • Your profile. Your name, username, bio and profile photo are visible to other signed-in users.
  • Private accounts. If your account is private, you approve each follower, and you are left out of the global leaderboard.
  • Workouts. Each workout can be Public, Friends (people you follow who also follow you) or Only me. “Only me” workouts are never sent to the shared feed on our server.
  • Kudos, comments and @mentions are visible to people who can see the workout they are on.
  • Leaderboards show scores from accounts that are not private.
  • Chat boards are public and visible to all signed-in users.
  • Direct messages can be exchanged only between friends and are visible to the people in the conversation. During a “train together” workout, your live progress is shared with the friend you are training with.
  • Body check-ins (weight, height, BMI) are never shown to anyone else.

The ARMR. team may view reported content when reviewing a report.

7. Why we use your data

UK GDPR requires us to have a lawful basis for each use of your data.

What we doLawful basis
Create and run your account, sign you in, sync your data across devices, and provide the training, food and social features you useContract (providing the service you asked for)
Send account emails such as email confirmation and password resetsContract
Process heart-rate and other health dataExplicit consent
Analyse food photos you choose to scanContract (you ask us to provide the estimate)
Review reports, enforce blocks, remove content and suspend accounts that break the rulesLegitimate interests (keeping the community safe)
Keep the service secure and prevent abuseLegitimate interests
Keep records where the law requires us toLegal obligation

We do not use your data for advertising, profiling for marketing, or automated decisions that have legal or similarly significant effects on you.

8. Service providers

We use a small number of providers to run ARMR. They process data on our behalf and only for the purposes below.

  • Cloudflare: hosting, database, realtime messaging, sending account emails, and Workers AI (food photo analysis).
  • Anthropic: food photo analysis using Claude.
  • Google Fonts: our fonts are loaded from Google, which receives your IP address when the fonts are requested.
  • jsDelivr: a content delivery network that serves the barcode scanner library, which receives your IP address when the library is loaded.

Open Food Facts receives barcode lookups made from your device, as described in section 5.

We do not sell or rent your personal data to anyone. We may disclose data if the law requires it, or to protect the safety of our users or others.

9. International transfers

Some of our providers may process data outside the UK, for example in the United States. Where this happens, we rely on appropriate safeguards recognised under UK law, such as the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the UK–US data bridge where the provider is certified.

10. Cookies and device storage

The only cookie ARMR. sets is the sign-in session cookie on the web. It is strictly necessary for signing in, so it does not need your consent. We do not use advertising or tracking cookies.

The app also stores your app data and preferences in your browser’s or device’s local storage. This makes the app fast and lets it work offline. You can clear it at any time through your browser or device settings; your synced data stays in your account.

11. How long we keep data

  • While your account exists, we keep your data so the app works for you.
  • When you delete your account, we immediately and permanently delete your profile, workouts, comments, kudos, messages you sent, photos, synced app data, notifications, follows and sessions from the live database.
  • Backups of the database may keep copies for up to 30 days before they are overwritten.
  • Moderation records (reports) may be kept for up to 12 months for safety reasons.
  • Food photos sent for scanning are not stored by ARMR. once the estimate has been returned.

12. Security

All traffic is encrypted in transit. Passwords are stored only as salted PBKDF2 hashes, and only a hash of each session token is stored on our server. Uploaded images are served through unguessable links. No system is perfectly secure, so please use a strong, unique password and keep your devices secure.

13. Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data. You can edit most profile details yourself in the app.
  • Delete your data. You can delete your account in the app, or ask us to do it.
  • Portability: receive your data in a commonly used, machine-readable format.
  • Object to or restrict certain processing.
  • Withdraw consent at any time, where we rely on consent. This does not affect processing already carried out.

To use any of these rights, email support@armr.app from the email address on your account. We will respond within one month. We may need to confirm your identity before acting on a request.

14. Age limit

You must be 16 or older to use ARMR. We do not knowingly collect data from anyone under 16. If you believe someone under 16 has an account, please tell us at support@armr.app and we will delete it.

15. Changes to this policy

We may update this policy as the app changes, for example when the mobile apps or health integrations launch. We will update the date at the top of this page and, for significant changes, tell you in the app or by email.

16. Contact and complaints

Questions, requests or concerns: support@armr.app.

If you are unhappy with how we have handled your data, you can complain to the Information Commissioner’s Office (ICO), the UK data protection regulator, at ico.org.uk. We would appreciate the chance to sort things out first, so please contact us before going to the ICO.