Last updated August 2026. Operating entity: pending.
Sinter is a workout and nutrition planning app run by the operator of Sinter. This policy says what it collects, why, who else sees it, and how to get rid of it. It is written to be read, not to be survived.
Your training and food data lives on your device and works offline. If you sign in, a copy syncs to our server so your devices agree and nothing is lost with a phone. We do not sell it, we do not advertise against it, and there is no analytics or tracking code in the app at all. You can export everything at any time and delete everything at any time.
Sinter is local-first. Workouts, sets, food logs, body weight, your plans and your profile are written to your device’s local storage first and read from there. The app works fully offline, which is the point: a gym with no signal is still a gym.
An account holds your email address and an account identifier from our sign-in provider. Turning on sync also stores a copy of your Sinter data: workouts and sets, personal records, food and meal logs, macro targets, body weight and body-fat entries, your plans and cycles, your profiles, your subscription tier, and counts of how many AI generations and photo estimates you have used. If you turn on lock-screen rest alerts, we also hold a device push token registered through Apple or Google — there is no web push.
Sync is not end-to-end encrypted, and we would rather say so than imply otherwise. Your data travels over an encrypted connection and sits on our database provider’s encrypted storage, but we hold it in a form we can read. That is what lets the app merge two devices and build your targets from your own logged history. If you want none of it on our servers, do not turn on sync — the app is fully functional without it.
Body weight, body-fat estimates, height, sex, age and food intake are health-adjacent personal data, and we treat them as the most sensitive thing here. They are used to run the product and nothing else: to build and adjust your plan, to estimate your maintenance calories from your own logged history rather than a population average, and to show your trends back to you.
They are never sold, never shared for advertising, and never used to train anyone’s models. Sinter provides wellness and fitness information, not medical advice, and calorie and macro figures are estimates rather than clinical measurements.
By default, your plan is built on your device from the answers you give it — nothing about it leaves the phone. Tap “Generate with AI” instead and those same answers are sent once to our AI provider to produce the plan, and kept nowhere afterward.
A photo taken for an AI estimate is sent once to the same provider, used to produce the estimate, and never written to any store of ours. There is no photo library on our servers to breach or subpoena. You always confirm or edit the result before anything is logged.
Looking up a food — scanning a barcode or searching by name — goes through our own server to USDA FoodData Central first: it receives the barcode or the search text and nothing that identifies your account. If USDA has no answer, your device asks Open Food Facts directly and we do not see that request at all.
How-to videos are third-party videos on YouTube, played in YouTube’s own embedded player. Nothing at all is requested from YouTube — not even a thumbnail — until you tap play, so no data reaches Google unless you choose to watch.
Subscriptions are handled by Stripe, the App Store or Google Play. We never see or store your card number. Those providers process the payment and tell us only whether your subscription is active, and they keep their own records for their own tax and accounting obligations.
No advertising. No analytics or crash-reporting SDK. No attribution or cross-app tracking of any kind, and nothing that would require an app-tracking prompt. We do not sell or rent personal data, and we do not share it with data brokers. Barcodes are decoded on your device rather than uploaded.
A small number of providers handle data on our instructions and for no purpose of their own: Firebase Authentication for sign-in, Neon for the database, Vercel for hosting and the API, USDA FoodData Central for food lookups (it receives only the barcode or search text, never anything that identifies your account), Stripe for payments, and Google’s Generative Language API for photo estimates and plans you choose to generate with AI. Data is processed in the United States.
Synced data is kept while your account exists. Delete the account and it goes immediately — there is no waiting period and no retained copy. What that removes exactly, and how to ask for it if you cannot reach the app, is set out on .
Export is always available and always free, including after a subscription ends. Your own data is never held behind the paywall.
Sinter is a general-audience fitness app and is not directed at children under 13. Do not create an account for a child. If we learn that we hold data from one, we delete it.
If this policy changes in a way that affects what we collect or who sees it, we will say so in the app rather than quietly reposting the page.
Questions: support@sinter.fit