← Back to IRON WELL

Privacy Policy

Last updated: February 2026

1. Information We Collect

When you use IRON WELL, we collect the following information to generate your personalized fitness protocols:

  • Basic profile data (name, age, gender, height, weight)
  • Fitness goals and preferences
  • Medical conditions (for safety screening only)
  • Google account information (email, display name) when you sign in
  • Phone number (optional, for trainer contact purposes)

2. How We Use Your Data

  • Generate intelligently powered diet, training, and protocol plans
  • Calculate biometric data (BMI, BMR, TDEE) for accurate plans
  • Track your credit balance and plan history
  • Improve our smart generation quality

3. Third-Party Services

We use the following third-party services:

  • Google Firebase — Authentication, database, and hosting
  • OpenAI — Intelligent plan generation (your data is sent to OpenAI's API for processing)
  • Google Sheets — Optional backup of generated plans for business records

4. Device Identification & Rate Limiting

To prevent abuse and ensure fair access to our services, we use the following technical measures:

  • Canvas Fingerprinting — We generate a unique, anonymous device identifier using the HTML5 Canvas API. This creates a hash based on your device's rendering characteristics. No personal information is collected through this process; it is used solely to identify unique sessions and prevent abuse of our free credit system.
  • Rate Limiting — We use Upstash Redis to track and limit API request rates per IP address. This data is stored temporarily (60-second windows) and is automatically deleted.
  • Local Storage — Generated plans are cached in your browser's local storage for quick access. This data never leaves your device and can be cleared through your browser settings.

5. Data Storage & Security

Your data is stored securely in Google Firebase with encryption at rest and in transit. We use strict Firestore security rules to ensure you can only access your own data. Admin access is restricted to authorized personnel only.

6. Data Sharing

We do not sell, rent, or share your personal data with third parties for marketing purposes. Data is only shared with the third-party services listed above for the purposes of providing our service.

7. Your Rights

You have the right to:

  • Access the data we hold about you
  • Request deletion of your account and associated data
  • Withdraw consent for data processing at any time

8. Contact

For privacy inquiries or data deletion requests, contact us at aswini77554@gmail.com.