Vigor Privacy Policy
Last updated: June 15, 2026
Vigor ("we," "us," or "the app") is a fitness and strength training app built by Zach Hicks. This policy explains what information Vigor collects, how it's used, and the choices you have. We've tried to write this in plain English — if anything is unclear, get in touch at the address at the bottom.
1. Information We Collect
Account information
When you create an account, we collect:
- Your email address (for sign-in and account recovery)
- A display name you choose
- A user ID generated by the sign-in service you use (Apple, Google, or email)
You can sign in with Apple, Google, or an email-and-password account. When you use Sign in with Apple or Google, those services handle authentication and only share the information you approve with us.
Workout and routine data
Vigor stores what you log in the app:
- Strength sessions: exercises performed, sets, reps, weights, durations, side (left/right for unilateral lifts), set tags (warmup, working, drop set, back-off, AMRAP), RPE (1–10), notes, and timestamps
- Per-exercise records: tested 1-rep max, longest holds, lifetime sets and sessions
- Routines you build or clone from program templates
- Equipment availability tags (My Gym / At Home) and other strength preferences
- Other workouts you log manually (cardio, mobility, etc.)
Health data
Vigor integrates with Apple HealthKit. With your permission:
- We write workouts to HealthKit so they count toward your Activity rings.
- We read workout data so the app can recognize sessions you've logged elsewhere.
HealthKit data is treated as a special category. We never use HealthKit data for advertising, never share it with third parties without your explicit consent, and don't transfer it off your device or our backend except as needed to provide the app's features (e.g., syncing a Champion-quality strength workout you started on your watch).
Social features
If you join or create a group in Vigor:
- Your display name and avatar are visible to other group members.
- Messages, shared routines, and reactions you post in a group are stored and shown to everyone in that group.
- Other members can see when you finish workouts you choose to share, including the workout type and basic stats.
You can leave any group at any time. Leaving a group removes you from future visibility, but messages you previously sent remain visible to members who already received them.
Device and diagnostic information
We do not collect analytics or behavioral usage events. The only device-level information that reaches our servers is what's strictly required to run the app — your authenticated user ID, the data you log, and standard request metadata (e.g., approximate timestamps) used by Firebase to process the request.
Apple Watch
When Vigor is paired with an Apple Watch, your routines, exercise records, and preferences sync between devices so you can run workouts on either. Workouts you finish on the watch are sent back to your iPhone, which writes them to our servers and HealthKit.
2. How We Use Your Information
We use the data above to:
- Provide the app's core features (logging, tracking progress, syncing across your devices)
- Run social features (groups, sharing, chat) when you opt into them
- Calculate stats (Champion qualification, personal records, Vigor score, muscle-group volume)
- Auto-prefill workout cards with your past performance or programmed targets
- Send notifications you've enabled (rest timer alerts, social activity, etc.)
- Comply with legal obligations
We do not sell your personal information to third parties, and we do not use HealthKit data for advertising or marketing.
3. Who Has Access to Your Data
Service providers
We use the following providers to run the app. Each is bound by their own privacy terms:
- Google Firebase (Authentication, Firestore database, Cloud Messaging, App Check) — stores your account, routines, sessions, exercise records, and group messages, and authenticates requests from the app.
- Apple iCloud / Sign in with Apple — handles authentication if you sign in with Apple.
- Google Sign-In — handles authentication if you sign in with Google.
- Apple HealthKit — on-device only; data never leaves your device through HealthKit.
- Apple Push Notification service — delivers notifications you've enabled.
Other people
- Members of groups you join can see anything you post in that group.
- Anyone you explicitly share a workout or routine with can see that workout or routine.
- Nobody outside the app can see your workouts unless you share them.
Legal requests
We may disclose information if required by law, court order, or to protect the safety, rights, or property of Vigor users.
4. Your Choices
Account deletion
You can delete your account at any time from Profile → Settings → Delete Account. Deleting your account:
- Permanently removes your routines, sessions, exercise records, profile, and group memberships from our servers.
- Removes your messages from groups where you can no longer be reached for deletion. Messages already delivered to other members' devices may persist there.
- Does not delete workouts already written to Apple HealthKit. To remove those, use the Health app on your iPhone.
Account deletions are processed immediately and cannot be reversed.
Exporting your data
You can export your strength training data as CSV or PDF from Profile → Export Strength Data. The export contains every session, set, and per-exercise record we have for you.
Notifications
You can turn off any notification category from Settings → Notifications → Vigor on your iPhone or Apple Watch.
HealthKit access
You can revoke Vigor's HealthKit permissions at any time from Settings → Health → Data Access & Devices → Vigor on your iPhone. Revoking access stops new reads and writes but doesn't remove data already shared.
5. Data Retention
We keep your account data for as long as your account is active. After you delete your account, data is removed from our active systems immediately. Backups containing your data are rotated out within 30 days.
6. Children
Vigor is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us and we will remove it.
7. International Users
Vigor is operated from the United States. If you access Vigor from outside the United States, your information will be transferred to, stored, and processed in the United States. By using Vigor you consent to that transfer.
8. Security
We use industry-standard measures to protect your data, including:
- TLS encryption for all data in transit
- Firebase's at-rest encryption for all stored data
- App Check to verify requests come from a legitimate copy of Vigor
- Sign in with Apple and Google to avoid handling passwords directly
No security measure is perfect. If you discover a vulnerability, please report it to the contact below before disclosing it publicly.
9. Changes to This Policy
We may update this policy as the app evolves. When we make material changes, we'll notify you in the app and update the "Last updated" date at the top. Continued use of Vigor after a change means you accept the updated policy.
10. Contact
If you have questions, concerns, or requests about your data or this policy, reach out:
Zach Hicks
Email: info@zachhicksapps.com