Effective August 8, 2026
Privacy policy
Panthyr is operated by ebonis ehf., a company registered in Iceland (European Economic Area), which is the data controller for the personal data described here. This policy explains what the closed-beta fitness app and website collect, why we use it, and the choices you have.
Questions or privacy requests can be sent to hello@panthyr.ai.
Data we collect
- Account and profile. Your email address, display name, age, training experience, goals, available equipment, training availability, session length, and unit preference.
- Training. Workout plans, templates, completed workouts, exercises, sets, reps, weights, duration, distance, RPE, notes, feedback, and progress records.
- Nutrition. Meal names and times, calories, macros, nutrition goals, notes, and AI scan summaries. When you choose meal scanning, the selected photo is sent through our backend to OpenAI for a one-time estimate. Panthyr does not save the photo to its database or file storage. The editable nutrition draft you choose to save is stored with your account.
- Body measurements. Entries such as body weight, body-fat percentage, and measurements you choose to log.
- Coach data. Your coach conversations, generated workout or plan content, and the coach memory slots used to personalize future conversations. Memory slots are visible and removable in Settings.
- Diagnostics and product analytics. Sentry receives error reports, stack traces, app or browser details, performance data, and signed-in account identifiers where available. PostHog records limited in-app product interactions. On the website, browsing analytics set no cookies and use no persistent identifiers, and session recording is disabled — but if you join the waitlist we record that event against your email address, and if you sign in to the web dashboard, product events are linked to your account. Vercel Analytics measures website visits. We do not use ad networks or SDKs for cross-app advertising tracking.
How we use data
We use account and product data to authenticate you, provide workout and nutrition logging, personalize coaching, generate workouts, show progress, sync the features you turn on, support users, secure the service, diagnose failures, and improve the beta.
We do not sell personal data. We do not use health or fitness data for advertising or marketing, and we do not share it with data brokers.
Apple Health (HealthKit)
Apple Health access is optional and controlled through separate in-app switches and Apple's permission screen.
- We write: completed strength workouts, including their start and end times.
- We read: sleep and sleep stages, heart rate variability (HRV), resting heart rate, step count, and active energy burned. These reads happen only after your explicit opt-in and sync only while the app is in the foreground.
You can stop either integration at any time from Panthyr's Apple Health settings. You can also change or revoke Panthyr's system access in iOS Settings → Health → Data Access & Devices. Turning recovery reads off in Panthyr stops future syncs; changing the iOS permission controls Panthyr's access at the system level.
AI processing
Coach chat, workout generation, and meal-photo scans are processed by OpenAI through Panthyr's backend. We send the information needed for the request, which may include your message, relevant profile, training, nutrition, recovery, and coach-memory context, or the meal photo you selected.
Panthyr requests that OpenAI not store response state. Per OpenAI's API terms and data-use policies, API content is not used to train its models by default. OpenAI may retain content for the limited periods and purposes described in those policies, including abuse monitoring.
Service providers
We use a small set of providers to run Panthyr. They process data for us under their own security and privacy terms:
- Supabase — database and authentication.
- Railway — backend API hosting.
- Vercel — website hosting and website analytics.
- OpenAI — AI coach, workout generation, and meal-scan processing.
- Sentry — error and performance monitoring.
- PostHog — website and limited product analytics.
These providers are based in the United States or may host or process data there. For transfers from the EEA, we rely on the EU–US Data Privacy Framework where the provider is certified, and on the European Commission's Standard Contractual Clauses otherwise. You can ask for a copy of these safeguards or more details by emailing hello@panthyr.ai.
Legal bases and your rights
Because Panthyr is operated from the EEA, we describe our GDPR posture plainly. We process account data to perform our contract with you. Health-related data — your workouts, body measurements, nutrition logs, recovery metrics, and anything else that can reveal your health or fitness status — is special-category data under GDPR Article 9, and we process it only with your explicit consent: you provide it by actively choosing to log this data or enable a feature that collects it, and Apple Health reads additionally require their own opt-in toggles. We rely on legitimate interests, where permitted, for service security, reliability, diagnostics, and limited product analytics — never for health data.
You can ask to access, correct, export, or delete your personal data, or object to or restrict certain processing, by emailing hello@panthyr.ai. You can withdraw consent for health data at any time — by deleting individual entries, turning off Apple Health access, or deleting your account. Withdrawing consent does not affect processing that already occurred while consent was active. You also have the right to lodge a complaint with a data protection supervisory authority — in Iceland, where ebonis ehf. is established, that is Persónuvernd (www.personuvernd.is); you may equally contact the authority in your own EEA country.
Retention and deletion
Account and product data is generally kept while your account exists. In the app, use Settings → Danger Zone → Delete Account. This calls Panthyr's account-deletion service and removes your authentication account and linked database records, including your profile, workouts, nutrition logs, measurements, chats, coach memories, and synced health metrics.
If you created an exercise in the shared exercise catalog, its catalog entry may remain for other users, but the link to your account is removed. Diagnostic and analytics records follow the providers' retention settings, and limited records may be kept where needed for security, legal obligations, or resolving abuse. Email us for a manual deletion request or help removing identifiable provider records.
Closed beta and policy changes
Panthyr is currently in closed beta. Features and data practices may change as the product develops. If this policy changes, we will update the effective date above and post the revised policy here. Material changes will be highlighted in the app or through another appropriate notice.