Privacy Policy

Last updated: 2026-06-01

1. Overview

This policy explains what information Quill (the “Service”) collects, how we use it, and the choices you have. We collect only what we need to generate your workouts, track your training, and run your account.

2. Information we collect

Account details: your name, email address, and a password (stored only as a salted hash — we never store your plaintext password).

Health and fitness profile: information you provide such as your goals, listed injuries or limitations, available equipment, and body-weight history. Some of this is sensitive health-related data, and you choose what to share.

Training data: the workouts, exercises, sets, reps, weights, and notes you generate or log in the app.

Trainer conversations: the messages you exchange with the in-app AI trainer.

Optional API key: if you add your own OpenAI API key, it is stored encrypted (AES-256-GCM) and is never sent back to your browser.

Notifications: if you enable reminders, your push-subscription details and notification preferences.

Technical data: basic information needed to operate the Service, such as your authenticated session.

3. How we use your information

We use your information to authenticate you, generate personalized workouts, track your training history, power the AI trainer, send reminders you opt into, and keep the Service secure and working.

We do not sell your personal information, and we do not use your data for advertising.

4. AI processing and third parties

Workout generation and the AI trainer are powered by third-party AI providers (such as OpenAI). To produce a response, relevant inputs — for example your profile, training context, and the messages you send — are transmitted to that provider for processing and returned to you.

Your use of AI features is also subject to the provider's own terms and privacy practices. Avoid sharing information with the AI trainer that you would not want processed by a third-party provider.

We rely on infrastructure providers (such as hosting and database services) to operate the Service. They process data only to provide those services to us.

5. Cookies and sessions

We use a cookie to keep you signed in. It is required for the Service to function and is not used for tracking or advertising.

6. How we protect your information

Passwords are hashed, any stored API key is encrypted at rest, and access to your data is scoped to your authenticated account. No method of storage or transmission is perfectly secure, but we take reasonable measures to protect your information.

7. Data retention and deletion

We keep your information for as long as your account is active. You can request deletion of your account and associated data by contacting us; we will delete it except where we are required to retain certain records by law.

8. Your choices

You can view and update your profile and settings in the app, turn notifications on or off, remove a stored API key, and request access to or deletion of your data. Depending on where you live, you may have additional rights over your personal information.

9. Children

Quill is intended for users who are at least 18 years old (or the age of majority where they live). We do not knowingly collect personal information from children.

10. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the date below and, where appropriate, notify you in the app.

11. Contact

Questions about this policy, or requests regarding your data, can be sent to [email protected].

See also our Terms & Disclaimer.

← Back to sign up