Horme privacy policy
Horme is an evidence-based training and nutrition app. This policy explains, in plain terms, what data the app handles and what it does — and does not do — with it.
This is an English translation of the Spanish original. If the two ever diverge, the Spanish version prevails.
Summary
- You can use Horme with no account (guest mode): your data stays on this device only and is not synced. If you prefer, you can create an account (email/password or Google) to sync across devices and avoid losing your data when you change phone — it is used solely to identify your devices, and we ask for nothing beyond the email address.
- The rest of your data (profile, workouts, meals, progress…) is stored on your own device. It only travels to a server if you turn on multi-device syncing, use “Fito included” (managed AI), or manually publish a summary in Coach space. All three are explained below.
- There are optional features, dormant until you use them, that involve communicating over the internet: the AI coach (Fito), food search, wearable imports, product metrics, and Coach space. Each is explained below, with detail on what leaves your device and where it goes.
- We use no third-party analytics, no advertising and no trackers of any kind.
- We do not sell your data or use it for advertising. Optional features send only what is strictly needed to answer — never your full profile or history: an AI coach question to the AI provider, a search term / barcode to Open Food Facts, or the summary you publish for a linked coach account.
Anonymous metrics to improve Horme (optional)
Under Settings → Privacy & data you may voluntarily enable “Help improve Horme”. It is off by default. If enabled, the app sends only totals of approved events to Horme's own server: app opens, completed onboarding, workouts started and completed, Cardio opens, custom exercises created, weekly adjustments applied or undone, and the number of technical errors; plus app version, platform and language.
The payload contains no account, user, installation or advertising identifier, and no names, detailed routes, exercises performed, meals, weight, health data, photos, location, Fito questions, or error text/stack. Counters are aggregated by day, version, platform and language and cannot reconstruct one person's activity. We use no analytics provider and do not share these metrics with third parties. You may switch it off at any time; doing so deletes the pending queue on your device.
Separately, during onboarding or on the same Settings screen you may join the “90-day improvement study”. It is also off by default. Joining creates a random code on your device that is neither your account nor a phone identifier. For no more than 90 days, the app sends that code, the start date, relative day number, version, platform, language, and counters for a closed list of actions: reviewing/completing onboarding, seeing the first action, opening the app, starting/completing a workout, logging a set or meal, opening Cardio or a tutorial, and applying/undoing a weekly adjustment.
The study can measure activation and D7/D30 retention, but sends no exact time and no content or value from an action: no account, profile, routine or exercise name, sets, reps, loads, foods, calories, weight, health, photos, location, questions, or error text. The server transforms the code before storing it and never joins it to your account. Consent expires after 90 days. Leaving sooner deletes the local copy and immediately requests deletion of every day associated with that code.
What the app stores, and where
Everything you enter (profile, weight, body measurements, sleep, training sessions, routines you create, personal records, achievements and progress photos) is stored first in your own device's local storage, using standard browser/WebView capabilities (localStorage and IndexedDB). Unless you enable an online feature described in this policy, none of it leaves your phone.
If you uninstall the app or clear its data from system settings, the local copy is permanently erased. If you had enabled syncing or created coach links, also use their deletion controls or delete your account to remove the remote copies.
Training notes, and what Horme understands from them
After a set or a session you can write a note in your own words: “shoulder twinge on the last set”, “the bench was taken”, “slept 4 hours”. Since August 2026 those notes no longer sit in a drawer: the app classifies them by topic, ties them to the exercise you wrote them on and turns them into concrete suggestions (swap the exercise, drop the load, move it earlier, open the pain screening or lengthen the rest).
That analysis happens entirely on your device. What reads the note is a word dictionary shipped inside the app, not an artificial-intelligence model: the text is not sent to any AI provider or any server merely because you wrote it or because the app interpreted it. Notes are stored alongside the rest of your training, so they only leave the phone if you turn on multi-device syncing. If at some point you are the one who pastes a note into Fito to ask about it, then it travels like any other question to the AI coach, and that section applies.
Progress photos
If you choose to use the progress-photos feature, the app asks for access to your device's camera or gallery solely to capture or pick that image. Photos are compressed and stored only on your device (IndexedDB); they are never uploaded to any server and never shared automatically. You can delete them individually at any time from within the app.
AI description (optional): in the before/after comparison you can, if you want, ask for a general visual impression from the AI (AI coach) — only then are those 2 specific photos sent to the AI provider for analysis, in the same way as AI coach questions: directly with your own key, or — if you use Fito included with your account — via the Horme server, which forwards them to the provider without storing them (see “AI coach — Fito” below). It is a subjective impression in text, never a body-composition measurement, and nothing is ever sent unless you press that button.
AI coach — Fito (optional)
Fito, the AI assistant, is an optional feature that only acts when you use it. It can work in two ways, and in neither of them does Horme store your conversation:
- With your own API key (BYOK): in Settings you choose the provider — Gemini (Google), Claude (Anthropic), ChatGPT (OpenAI) or DeepSeek — and paste your key. Your question (and a short history) is sent straight from your device to that provider's API with your key: Horme plays no part and never sees or stores the conversation. The key is kept only on your device.
- Fito included (managed AI), when signed in: if you use an account, you can use Fito without obtaining or paying for a key. In this mode your question (and any photos you send for analysis, if you use it) travels from your device to a Horme server function (Firebase Cloud Functions) that verifies your session, counts your monthly usage, picks the model and forwards the request to the relevant AI provider — currently Google (Gemini), Anthropic (Claude), OpenAI or DeepSeek — which processes it and returns the answer. Horme acts only as an intermediary to authenticate you and allocate the quota: it does not store your conversation or your photos; the key for those providers belongs to Horme and you never see it.
International transfer: AI providers process your request on their own servers, which may sit outside your country and under their own privacy policy and jurisdiction. Google and Anthropic process data mainly in the United States, and DeepSeek in China. Only what is needed to answer is sent (your question, the conversation context and, if you enable the “Personal” option, a summary of your app data), never your full history. Fito is educational material and does not replace a professional.
Food search (optional)
In the meal diary you can search for foods by name or by scanning a barcode. That search term or code is sent to Open Food Facts, a free and open food-product database, to retrieve nutritional values. Your profile, your meal history and any other personal data are not sent — only the search term or barcode, at the moment you use it. You can also add foods entirely by hand, with no connection at all.
In the Advanced Nutrition Center you may voluntarily query Open Prices. Only after you press “Search prices” are the barcode and, if supplied, the currency sent. Your location, usual store, profile, receipt and history are not sent. Prices and structured receipts you save remain in Horme; the app does not publish proofs or images to Open Prices.
Voice dictation (optional)
Some screens (logging training sets or meals) let you dictate by voice instead of typing. If you use that feature, the app asks for microphone access and speech recognition is performed by your phone's operating system; Horme receives only the resulting text. The app does not record, store or transmit audio to any server. If you do not use dictation, the microphone is never accessed.
Notifications (optional)
Horme uses two kinds of notification, both optional:
- Local reminders (training, meals, hydration, morning check-in, end of fast): scheduled by your own phone from the configuration you choose in Settings. No data leaves the device and they work offline.
- Push notices (app news and content), which you can switch on or off in Settings. If you enable them, your phone obtains a device identifier (token) from Firebase Cloud Messaging, Google's notification service, and the app uses it to subscribe you to the general notice topics. That identifier points to the device, not to you: it is not linked to your account or to your training, nutrition or health data, and we do not use it to profile you or for advertising. Sends are general messages, identical for everyone — no personalised messages are sent based on your data.
If you turn push notices off in Settings, the app cancels the subscriptions and stops using that identifier. If you never turn them on, no token is ever obtained.
Wearables / Health Connect (optional)
If you connect Health Connect (Android) or Apple Health (iOS) from Settings, Horme can read what your watch or band has already recorded and store it locally, like the rest of your data. You can disconnect it at any time from Settings or revoke access in the system health settings.
Write access is separate, optional, and off by default. If enabled, Horme writes only data created in Horme: weight and active-calorie, distance, and heart-rate samples from a session. A local export ledger prevents duplicates; imported information is never written back and other apps' records are never modified.
This is the complete list of what the app asks to read, and what for. It asks for nothing else: the types not listed here (blood glucose, blood pressure, height, basal body temperature, basal metabolic rate, floors climbed, mindfulness) are deliberately removed from the app manifest, because no feature uses them.
- Steps and active and total calories: your real daily expenditure, which is what adjusts your nutrition targets.
- Sleep: hours and quality, for the Recovery screen.
- Heart rate and resting heart rate: they reconstruct the heart rate and zones of a session even when you did not have the watch app open.
- Heart rate variability (HRV), respiratory rate, oxygen saturation (SpO₂) and body temperature (on iPhone, wrist temperature while you sleep): the overnight signals behind your readiness to train.
- VO₂ max (Android only): it feeds in as a cardiorespiratory capacity point when your watch estimates it.
- Weight and body fat percentage: the body-composition series in Progress, without typing it twice.
- Exercise sessions and distance: they import the cardio you recorded on the watch — type, duration and kilometres — so the training-load model also sees what was not lifting. Added in August 2026 along with cardio import from the watch.
None of this leaves your device just by being read: it is stored in the local database, and only travels if you turn on multi-device syncing, described further down.
Recording outdoor activities with GPS (optional)
The Cardio tab lets you record a run, walk or ride, measuring distance, pace, elevation and route. This feature is optional and stays off until you tap “Record activity with GPS”; until then the app never accesses your location.
- Only during a session you start. In the installed app, Horme runs a visible location activity —a permanent notification on Android and the blue background-location indicator on iPhone— so the trace continues when the screen is locked. You can pause or stop it from the app or system controls; it never starts by itself outside a session.
- Your route is never synced. The track is stored in your phone's local storage (
IndexedDB) and is never synced to any server, not even if you have multi-device sync enabled. It gets the same strict treatment as menstrual cycle data, and for the same reason: a GPS track pinpoints your front door to within a few metres. - What does sync (if you enable sync) is the session summary — activity type, date, minutes, kilometres and average pace — like any other workout. Never the coordinates.
- The map background is optional and ships turned off. By default your route is drawn inside the app from your own points, with nothing downloaded and your position sent to no one. If you turn it on in Settings → Maps — which also requires you to paste your own provider key — the app asks the provider you choose (Mapbox or Stadia Maps) for the map imagery of the area you are looking at. In that case that area does reach that provider: it is requested as “tiles” of a fixed worldwide grid, roughly neighbourhood-sized, without your route, without your individual coordinates and without any account data. You can turn it off at any time and the full route still displays, offline included.
- Advanced enhancements are optional and ship turned off. If you enable them in Settings → Maps and then tap “Enhance route” inside a specific activity, the visible, sampled part of that trace is sent to the active provider to snap it to paths and correct elevation; Stadia Maps can also return attributes such as surface type. This never happens in the background or merely by opening an activity. The result is stored only in the same local storage and can be deleted separately.
- Exporting to GPX, TCX or FIT is your call, file by file. The export is an explicit action and is trimmed by your configured privacy distance. You can also import GPX; it stays on the device like a recorded activity.
- Included maps. Besides pasting your own key, Horme can serve the map background using a temporary credential issued by its server once you are signed in, so you do not have to register with a provider. That changes who pays for the tile, not who sees it: the server only issues the credential — the request it receives carries neither your position nor the area — and your phone still asks Mapbox or Stadia Maps for the imagery directly. This mode ships inside the app but is switched off; while it is, the map background only works with your own key.
- You can delete the GPS track of a single session from its detail view and keep the workout, or delete both. You can also revoke the location permission in your system settings at any time; the rest of the app keeps working.
Menstrual cycle (optional)
Horme can adjust your training and nutrition according to the phase of your menstrual cycle. This feature is off by default and only switches on if you record your first date — it is never enabled automatically based on the sex set in your profile.
This data is especially sensitive and therefore gets the strictest treatment in the whole app: it is stored only on your device and is never synced to any server, not even if you have multi-device syncing enabled. It is not shared with anyone and not used for any other purpose. It would only leave your device if you yourself perform a manual export from Settings, into a file you control. You can turn tracking off and delete its data whenever you want.
Your account
The account is optional: you can use Horme in guest mode (without registering), in which case your data stays only on this device and syncing is disabled. If you create an account with email and password, or sign in with Google, that account lives in the app's Firebase project and identifies your devices and, only when you use Coach space, the two participating accounts — on its own it sends no profile, workouts or meals anywhere. If you start as a guest and later create an account, your progress is preserved. You can change your password, sign out, or delete your account and all its data at any time from the Account screen.
Multi-device syncing (optional)
If you additionally enable syncing from Settings, your profile, workouts, measurements, sleep, meals, achievements and other app data (except progress photos, which stay on the device) are also stored in Firestore, protected by security rules that only allow your own account to read or write that document. Coach space, described next, does not open that document: it stores a separate, much smaller summary. Without syncing, your full training and nutrition data stays on the device.
Coach space (optional)
With an account, you can create a private link to another Horme account through a random, one-use code valid for 7 days. The server stores only a cryptographic transformation of the code, not the readable code. Horme does not search for coaches by email, does not make your profile public, and does not verify professional qualifications or credentials.
The athlete separately chooses which areas to allow: training, progress, nutrition, and recovery. Nothing is published automatically: even after the link is accepted, the athlete must tap “Update summary now”. The summary covers no more than 14 days (7 for nutrition) and contains only aggregates and a short list. It does not contain the sync document, per-set load or reps, exact weight, food names, photos, location, menstrual-cycle data, or Fito conversations.
The summary, both accounts' visible labels, up to 30 comments, up to 20 program proposals, and up to 12 partner sessions are encrypted in transit and stored in Firestore. The app only returns them to the two linked accounts. A proposal contains a label, rationale, goal, days, minutes, equipment, and priorities, but not the athlete's history. A coach may propose a version but cannot activate it, change the plan, or write to the athlete's logs: the program is generated on the athlete's device and is activated only when the athlete accepts it. Partner sessions share a date, name, and invited/ready/completed states, never location. Either party may immediately delete the link and all these data. Deleting the account inside the app also removes all its links.
Purchases and subscriptions (optional)
Horme charges nothing today, so none of what follows is happening yet. It is described in advance because the mechanism already ships inside the app and we want you to know what it will do the day it is switched on.
If you ever buy a subscription, payment is processed entirely by the store (Google Play or the App Store). Horme never sees or receives your card details, your billing name or your address. The store only tells us whether the subscription is active.
To determine whether you have access, the app uses RevenueCat (RevenueCat, Inc., USA), an intermediary that validates the store receipt. What is sent to it is:
- An anonymous identifier that RevenueCat generates on your device. Horme does not pass it your account: that identifier contains neither your email, nor your name, nor your Horme identifier.
- The purchase receipt issued by the store, plus technical data about the device and the app version.
Nothing is sent about your training, nutrition, health, measurements or photos. See RevenueCat's privacy policy.
If you never buy anything, this section does not affect you: with no purchase there is no receipt to validate.
Exporting, importing and deleting your data
From Settings you can:
- Export all your data (photos included) to a file you control and store wherever you like.
- Import a previously exported file to restore your data.
- Erase everything, permanently and immediately.
Permissions the app requests
- Camera / gallery: to add a progress photo or scan a barcode when logging a meal. Optional, never required to use the rest of the app.
- Microphone: only if you use voice dictation to log sets or meals. Recognition is done by the operating system; Horme receives only the text and never records or transmits audio. Optional.
- Storage: to save and read your own data and exports within the device.
- Internet: in guest mode the app works entirely offline. It is only needed to create an account or sign in (if you choose to) and for the optional features described above (AI coach, food search, wearables, syncing, and Coach space).
- Notifications: for the local reminders (training, meals, hydration…) scheduled by your own phone, and — if you enable it in Settings — for push notices, which use a Firebase Cloud Messaging device identifier not linked to your account or your data. Both optional; see the “Notifications” section above.
- Location (only if you record an activity): to measure distance, pace and route during a session you explicitly start. The installed app keeps it active behind a persistent system indicator when the screen is locked. The route is never synced. Optional.
- Health data: read access if you connect wearables, and first-party write access only if you enable the separate switch. Types and purposes are listed above. Optional and revocable.
Horme does not request access to your contacts. Location is used only during the GPS cardio recording described above and remains visible through a permanent system indicator.
Minors
Horme is not specifically aimed at minors and does not knowingly collect data from minors beyond the email address, in the event an account is created (optional). The rest of your data stays on the device unless you voluntarily enable multi-device syncing or publish a summary in Coach space, described above.
Changes to this policy
If this policy changes (for example, if optional online features are added in future), this same page will be updated with a new “last updated” date before those features become available.
Contact
For any question about this policy, write to: Somatryx.dev@gmail.com