Every app in this category says it respects your privacy. Almost all of them mean they have a policy about what they do with data they can read. This is a list of what is on our server, which is a different kind of claim, and a checkable one.
What we cannot read: the contents of anything you log. Food, weights, sets, weigh-ins, measurements, photos, coach messages. Each row arrives as an AES-256-GCM ciphertext with its own initialisation vector and authentication tag, and the key that would open it is derived on your device from your password. The password never leaves the handset and neither does the key derived from it.
What we do hold, and you should know it: the wrapped data key itself, along with the salt and the key-derivation parameters needed to unwrap it given the right password. That is what makes account recovery across two of your own devices possible, and it is also exactly what an offline guessing attack would want. The protection is the cost of guessing, not the absence of the material.
Today that cost is PBKDF2-SHA256 at 210,000 iterations for 42 of the 43 password-wrapped accounts on the system. One account is on Argon2id at 19 MiB and two passes, which is the stronger scheme and the direction this is going; it is not yet rolled out, and saying "we use Argon2id" today would be true of one person. Twenty-one accounts also carry the same data key wrapped a second time under a recovery secret, derived with HKDF-SHA256.
What is not encrypted at all: your email address, your locale and units, which device sent a row, what type of thing it was, how many times it has been edited, whether it was deleted, three timestamps, and the length in bytes of each encrypted entry. That last one is the most interesting and the least obvious. Lengths on this server currently run from 0 to 8,647 bytes, and a long entry is a long entry whether or not anybody can read it.
So the honest sentence is narrower than the one most apps would write: we cannot read what you logged, we can see that you logged, when, from which phone, and roughly how much. We think the first half is the part that matters, and we are telling you the second half because a claim you cannot check is worth nothing.
A second limit, on a different key. Gym Buddies uses its own keypair, and accounts set up on the same device can end up sharing one — 19 accounts on the system hold 16 distinct buddy keys. That is a real gap between the architecture and the sentence "only you hold it", it is not the key that protects your log, and it is not yet fixed.
0 replies
No replies yet.