Fulcrum — Privacy Policy
Last updated: 12 August 2026
Fulcrum is a personal fitness coaching app. This policy describes what the app does with your information. It is short because the app does little with it: there is no account, no analytics, no advertising, and no server of ours anywhere in the picture.
What the app stores, and where
Your health log stays on your device. Weights, body fat, sleep, heart data, and your lifts are stored in a local database on the device that recorded them. This part of the log is not stored in iCloud, because Apple's rules rightly forbid putting HealthKit data there.
Your conversation with the coach syncs through your own iCloud account — messages, the coach's notes, and facts the coach has remembered about you. So does what you told the coach about a day: the meals and totals you logged in your own words. This uses Apple's private CloudKit database, which means it lives in your iCloud account, is governed by Apple's privacy terms, and is not accessible to the developer of this app. If you are not signed in to iCloud, it simply stays on the device.
Any API key you enter stays in the Keychain on your devices, synced by iCloud Keychain if you have that enabled. Keys are never transmitted to the developer.
Apple Health
With your permission, Fulcrum reads steps, active energy, exercise minutes, heart rate variability, resting heart rate, respiratory rate, blood oxygen, sleeping wrist temperature, sleep, body mass, body fat percentage, dietary caffeine, alcoholic drinks, and workouts, so your dashboard fills in without you typing them.
With your permission, it writes back only what you told it: nutrition you logged in conversation (calories, protein, carbohydrates, fat) and alcoholic drinks. It never writes back anything it read from Health, and it does not write your body weight.
Health data is never used for advertising or marketing, never sold, and never shared with third parties for their own purposes. It is never stored in iCloud.
What is sent off your device, and when
Fulcrum has no backend of its own. What leaves the device depends on which coach you choose in Settings:
- Apple (the free option) — replies are generated by Apple Intelligence on your device. No third party is involved and nothing is sent anywhere.
- Fulcrum (the paid option) — replies are generated by Google's Gemini models, reached through Google's Firebase AI Logic. When you use it, your messages, any photo you send, a summary of your recent log, and — during a live voice session — your microphone audio, are sent to Google to produce the reply. Google's privacy policy and terms govern that processing. Your name, email, and account identity are not sent, because the app has none. Along with each request, Firebase App Check sends a token from Apple's App Attest that proves the request came from a genuine copy of this app; it does not identify you.
- USDA FoodData Central — optional. If you supply a USDA API key, the name of a food the coach is unsure about (for example “greek yogurt”) is sent to the U.S. Department of Agriculture's public food database to look up its composition. Nothing about you is sent with it: no identifier, no portion, no log, no account. Without a key this never happens and the coach estimates instead.
- Apple WeatherKit — the app requests weather for your approximate location so the coach can tell a skipped run in a storm from a skipped run on a mild day. Location is used for this request and is not stored.
Speech depends on which mode you are in. When the coach reads a written reply aloud, the voice is synthesised on your device and nothing is sent for it. In a live voice conversation with the paid coach, it is the same Google session both ways: your microphone audio goes up, and the voice you hear is generated by Google and streamed back. The running transcription you see while you talk is always produced on your device.
Photos you send to the coach are stored on your device, and are sent to Google only if you are using the paid coach. They are not uploaded anywhere else.
Moving your log between your own devices happens directly, over your own network — the app finds your other device with Bonjour and sends the log straight across, encrypted with a key only your devices hold. It does not pass through any server, ours or anyone else's.
What the developer receives
Nothing. There is no analytics, no crash reporting, no telemetry, and no account system. The developer cannot see your log, your conversation, your photos, or your keys.
Your control
- Delete conversations at any time from the coach screen's menu, or Settings → Usage & data.
- Export everything as one complete JSON file: Settings → Usage & data.
- Revoke Health access in Apple's Health app → Profile → Privacy & Security → Apps.
- Remove any API key in Settings; this deletes it from the Keychain.
- Switch coaches at any time in Settings. Choosing the Apple coach stops anything being sent to Google.
- Delete the app to remove the local health log entirely. Conversation data in your iCloud account can be removed from iOS Settings → your name → iCloud → Manage Storage.
Children
Fulcrum is not directed at children under 13 and does not knowingly collect information from them.
Medical disclaimer
Fulcrum is a coaching and logging tool, not a medical device. Nothing it says is medical advice. Talk to a doctor about anything that concerns you.
Changes
If this policy changes, the date at the top changes with it.
Contact
Questions about this policy: info@atemkraft.dev