GRIT privacy notice

Privacy, without the fog.

The GRIT WOD Timer does not require an account. Workout and Apple Health information stays on your device. GRIT receives limited anonymous timer-use events and, only when you deliberately send feedback, the report details disclosed below.

Last updated 4 October 2026

The short version

  • No GRIT account or sign-in for the timer. GRIT Community, the optional invite-only service for gyms, uses an email sign-in and is described below.
  • No advertising, cross-app tracking or persistent analytics identifier.
  • Workout history and Apple Health data stay on your device.
  • Anonymous analytics count timer starts/completions, Gym Clock openings, timer type, UTC day, completed duration when accurately measured, and app/build version.
  • The WOD Recorder keeps your videos on your device. Nothing is uploaded unless you choose to send a video to your own YouTube channel.
  • Optional feedback sends only your report, optional reply email and optional disclosed diagnostics to GRIT.
  • Identifiable feedback is deleted within 90 days, or earlier on a verified request.

Information kept on your device

GRIT stores the information needed to run the app and remember your choices locally on your device. This can include timer settings, appearance and sound preferences, saved workout results, scores, notes, favourites, custom workouts, and recent workout history.

This app-local information is not linked to a GRIT account. The timer does not create user accounts; a GRIT Community sign-in, if you have one, does not upload this history.

Optional workout sharing

When you choose Send to a mate, GRIT uploads the workout name, description, the Notes saved with a library workout, and timer configuration to share.gritwod.app. This may include named intervals, workout blocks and prescribed repetitions or weights. It does not upload your recorded result, notes on a completed session, workout date, identity or Apple Health data. Please keep personal information out of workout names, descriptions and Notes you share.

Anyone with the link can open the shared definition and pass the link on. Shared links are not listed in a public directory. The recipient gets an independent copy in Saved; their changes and results are not sent back to the sender.

The service stores the definition, a random link identifier and creation day. It does not create an account or persistent device identifier, and shared definitions are not used for advertising or tracking. Cloudflare processes network information to deliver requests and enforce request limits; the sharing database does not store IP addresses and Worker request logging is disabled.

Links have no automatic expiry. Deleting the app or the local workout does not delete a hosted link or copies already imported by recipients. To request removal for privacy, content or abuse reasons, contact @gritwod on Instagram with the exact link. GRIT reviews the request before removing the hosted definition. Removal makes that link unavailable; it cannot recall messages or copies already saved by recipients.

GRIT Community (gyms)

GRIT Community is an optional, invite-only service that lets a gym publish its programming, timetable and news to its members, on the web at app.gritwod.app and in the gym features of the GRIT app. Unlike the timer, it needs an account. If you sign in, GRIT stores:

  • your email address and the display name you choose;
  • which gyms you belong to and your role in each (owner, coach or member);
  • for coaches and owners, what you publish to your gym: workouts, training cycles, the timetable, classes, closures, checklists, movements and news posts;
  • invitations a coach sends: the invitee's email address, name and role (an invitation link stops working after 72 hours);
  • your notification and display settings, and, for gym owners, the Community plan the gym is on.

Everything published to a gym is visible to that gym's members. Personal workout results are not uploaded to GRIT Community.

GRIT uses this information to sign you in, run the gym's pages and send the emails you ask for (sign-in codes and invitations). The lawful basis is providing the service you signed up for. It is not used for advertising or sold.

Service providers: the database and sign-in run on Supabase, hosted in the EU (Ireland); sign-in and invitation emails are sent through Resend, also in the EU (Ireland); the web app is delivered through Cloudflare. For security, the sign-in service keeps a log of sign-in events, which can include the IP address and browser used. Community subscriptions are bought through the App Store; Apple handles payment and GRIT does not receive card details.

A gym owner decides who is invited to their gym and what is published there. If you are a member and want something removed from a gym, ask the gym first; you can also contact GRIT.

Optional Apple Health access

If you grant permission, GRIT can read nearby Apple Health workouts to match one with a result you save. A match can include workout type, start and end times, duration, active energy, and an average heart-rate summary.

Health access is optional. GRIT does not write workouts or other information to Apple Health. A matched summary can be saved with your local GRIT workout history, but the current public app does not send that health information to the GRIT developer.

WOD Recorder and optional YouTube upload

The WOD Recorder films a workout with your camera and microphone and draws the timer, countdown cues, the GRIT watermark, the date and time, a random recording ID and any athlete, event, week or event-code text you typed into the picture. GRIT asks for camera and microphone access only when you open the recorder. Recordings, their overlay sidecar and the details you typed are stored only in GRIT’s own folder on your device and are excluded from device backups. They are not sent to the GRIT developer, to analytics, to the sharing service or to anyone else. Deleting a video in GRIT deletes GRIT’s copy; copies you saved to your camera roll or shared elsewhere are yours to manage.

Upload to YouTube is optional and happens only when you tap it. GRIT then asks you to sign in to your own Google account through Google’s standard sign-in screen and requests one permission: to upload videos to your YouTube channel (youtube.upload). GRIT does not see your Google password, does not read your channel, videos, subscribers, comments or any other Google data, and cannot delete or change videos it did not upload. The upload sends the video file and a title and description made from the recording details (athlete, event, week, event code, workout, recording date and time, recording ID and round chapters) directly from your device to YouTube; the video does not pass through any GRIT server. Videos are uploaded as Unlisted unless YouTube’s own rules set them to Private. Google’s sign-in token is kept in your device’s secure keychain and can be removed by signing out in GRIT or by revoking GRIT’s access at myaccount.google.com/permissions.

GRIT’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to upload the video you chose; it is never used for advertising, never sold, never shared with a third party and never used to build a profile of you. Once uploaded, the video is hosted by YouTube under your account and Google’s privacy policy.

Anonymous product analytics

GRIT sends limited product-interaction events to its dedicated service at analytics.gritwod.app: timer started, timer completed or Gym Clock opened; the fixed timer type; UTC calendar day; app version and build number; and, for a completed timer, scored elapsed seconds when GRIT can measure them accurately. Completed duration excludes count-in, cue transitions and paused time.

Each queued event has a one-time random UUID only so a network retry is not counted twice. It is not an account, device or installation identifier and is not reused across events. GRIT does not include a name, email, workout title or text, result, notes, Apple Health or HealthKit data, heart rate, calories, distance, location, contacts, advertising identifier, persistent device identifier, request headers or precise event time. The scored completed-timer duration described above is the only fitness-adjacent analytics value. The analytics are not linked to a person and are not used for tracking or advertising.

The analytics Worker does not read or store raw IP addresses. Cloudflare necessarily processes network connection information while delivering and protecting the request, but Worker observability is disabled for this dedicated service. Date-only retry receipts are deleted before 45 days. Daily aggregate event counts, completion-duration sums and sample counts contain no person or device identifier and may be retained longer for product planning and aggregate business insights.

Analytics infrastructure, database, secrets and policy are GRIT-only and separate from GRIT feedback, Section and every other product.

Optional feedback and support

When you choose to send a report or feature request, GRIT stores the report text and a delivery receipt. A reply email is optional. If you leave the diagnostics switch enabled, the report also includes only the GRIT app version and build, iOS version, device model, and most recently selected timer mode.

GRIT does not attach workout history, workout names, results, notes, Apple Health or HealthKit data, location, contacts, advertising identifiers, device identifiers, or unrelated device content. Please do not type sensitive or health information into the free-text report.

Reports are used for customer support and fault diagnosis. GRIT may retain longer-term de-identified aggregate counts of issue or feature-request categories for product planning. Those counts contain no report text, email, diagnostics, receipt reference, workout information, or stable identifier and provide no reasonable route back to a person.

Feedback goes only to GRIT's separate service at feedback.gritwod.app. GRIT feedback storage, email delivery, credentials and policies are kept separate from Section and every other product.

Abuse prevention and delivery

Cloudflare processes the network request, including its IP address, to deliver and protect the service. The GRIT intake does not store the raw IP address. It creates a GRIT-only keyed fingerprint limited to one UTC day to enforce a submission limit, then automatically deletes that fingerprint at expiry.

The owner notification contains only a feedback category and the protected GRIT inbox URL. It does not contain report text, reply email, diagnostics or the receipt reference.

Apple services

Apple provides the App Store, Apple Health permissions, and the system review prompt. Apple handles information for those services under its own terms and privacy policies. GRIT does not receive your Apple account credentials.

The GRIT website

The GRIT website is delivered through Cloudflare. Like other hosting providers, Cloudflare processes standard request information needed to deliver and protect a web page, such as an IP address, browser information, and request timing.

Marketing pages count page views and App Store link clicks through GRIT’s dedicated analytics service. The browser sends only a fixed page path, event type, a broad referring-site category or fixed campaign label. The service stores daily aggregate counts using its UTC calendar day. It does not store a visitor identifier, full referring URL, search terms, arbitrary URL parameters, precise event time or raw IP address. The counters use no cookies or browser storage and respect Global Privacy Control and Do Not Track when the browser exposes them. Fixed source/campaign labels may be carried in links between marketing pages; they do not identify a visitor. Counts are approximate events, not unique visitors or downloads.

These static legal pages do not create accounts, contain contact forms, set advertising cookies, or add client-side analytics. External services you choose to open from a link apply their own privacy terms.

Retention and deletion

App information remains on your device until you remove it or delete the app. GRIT does not hold a cloud account copy of your workout history or Apple Health data. Deleting GRIT does not delete the original workouts held by Apple Health.

Anonymous date-only analytics retry receipts are deleted before 45 days. Aggregate counts and duration totals cannot reasonably be traced back to a person, device or workout and may be kept longer for product planning.

Identifiable feedback content, an optional reply email, the delivery receipt, disclosed diagnostics and notification status are automatically deleted no later than 90 days after receipt. You can request earlier deletion using the receipt reference. If the report included a reply email, the same email is required to verify deletion. GRIT aims to complete a verified early-deletion request within 30 days and confirms completion without returning report content.

GRIT Community information is kept while your account exists. You can download a copy from Account → Export my data. To delete your Community account, email [email protected] from the address you sign in with; GRIT aims to complete a verified request within 30 days. A gym owner must hand over or delete their gym first. Workouts and posts you published to a gym stay with that gym unless you ask for them to be removed.

See the data-deletion instructions for the exact on-device and feedback-deletion steps.

Changes to this notice

This notice is updated before a public GRIT version begins a materially different data practice. Material changes will be dated on this page.

Privacy questions

GRIT WOD is operated by Andrew Dunn, trading as Handy Andy 3D. For a question about this notice, email [email protected] or contact the public GRIT WOD account at @gritwod on Instagram. Messages sent through Instagram are also handled under Meta's privacy controls.