GRIT privacy notice

Privacy, without the fog.

GRIT WOD Timer does not require an account. Workout and Apple Health information stays on your device. GRIT receives limited anonymous timer-use events and, only when you deliberately send feedback, the report details disclosed below.

Last updated 25 August 2026

The short version

  • No GRIT account or sign-in.
  • No advertising, cross-app tracking or persistent analytics identifier.
  • Workout history and Apple Health data stay on your device.
  • Anonymous analytics count timer starts/completions, Gym Clock openings, timer type, UTC day, completed duration when accurately measured, and app/build version.
  • Optional feedback sends only your report, optional reply email and optional disclosed diagnostics to GRIT.
  • Identifiable feedback is deleted within 90 days, or earlier on a verified request.

Information kept on your device

GRIT stores the information needed to run the app and remember your choices locally on your device. This can include timer settings, appearance and sound preferences, saved workout results, scores, notes, favourites, custom workouts, and recent workout history.

This app-local information is not linked to a GRIT account because GRIT does not create user accounts.

Optional Apple Health access

If you grant permission, GRIT can read nearby Apple Health workouts to match one with a result you save. A match can include workout type, start and end times, duration, active energy, and an average heart-rate summary.

Health access is optional. GRIT does not write workouts or other information to Apple Health. A matched summary can be saved with your local GRIT workout history, but the current public app does not send that health information to the GRIT developer.

Anonymous product analytics

GRIT sends limited product-interaction events to its dedicated service at analytics.gritwod.app: timer started, timer completed or Gym Clock opened; the fixed timer type; UTC calendar day; app version and build number; and, for a completed timer, scored elapsed seconds when GRIT can measure them accurately. Completed duration excludes count-in, cue transitions and paused time.

Each queued event has a one-time random UUID only so a network retry is not counted twice. It is not an account, device or installation identifier and is not reused across events. GRIT does not include a name, email, workout title or text, result, notes, Apple Health or HealthKit data, heart rate, calories, distance, location, contacts, advertising identifier, persistent device identifier, request headers or precise event time. The scored completed-timer duration described above is the only fitness-adjacent analytics value. The analytics are not linked to a person and are not used for tracking or advertising.

The analytics Worker does not read or store raw IP addresses. Cloudflare necessarily processes network connection information while delivering and protecting the request, but Worker observability is disabled for this dedicated service. Date-only retry receipts are deleted before 45 days. Daily aggregate event counts, completion-duration sums and sample counts contain no person or device identifier and may be retained longer for product planning and aggregate business insights.

Analytics infrastructure, database, secrets and policy are GRIT-only and separate from GRIT feedback, Section and every other product.

Optional feedback and support

When you choose to send a report or feature request, GRIT stores the report text and a delivery receipt. A reply email is optional. If you leave the diagnostics switch enabled, the report also includes only the GRIT app version and build, iOS version, device model, and most recently selected timer mode.

GRIT does not attach workout history, workout names, results, notes, Apple Health or HealthKit data, location, contacts, advertising identifiers, device identifiers, or unrelated device content. Please do not type sensitive or health information into the free-text report.

Reports are used for customer support and fault diagnosis. GRIT may retain longer-term de-identified aggregate counts of issue or feature-request categories for product planning. Those counts contain no report text, email, diagnostics, receipt reference, workout information, or stable identifier and provide no reasonable route back to a person.

Feedback goes only to GRIT's separate service at feedback.gritwod.app. GRIT feedback storage, email delivery, credentials and policies are kept separate from Section and every other product.

Abuse prevention and delivery

Cloudflare processes the network request, including its IP address, to deliver and protect the service. The GRIT intake does not store the raw IP address. It creates a GRIT-only keyed fingerprint limited to one UTC day to enforce a submission limit, then automatically deletes that fingerprint at expiry.

The owner notification contains only a feedback category and the protected GRIT inbox URL. It does not contain report text, reply email, diagnostics or the receipt reference.

Apple services

Apple provides the App Store, Apple Health permissions, and the system review prompt. Apple handles information for those services under its own terms and privacy policies. GRIT does not receive your Apple account credentials.

The GRIT website

The GRIT website is delivered through Cloudflare. Like other hosting providers, Cloudflare processes standard request information needed to deliver and protect a web page, such as an IP address, browser information, and request timing.

These static legal pages do not create accounts, contain contact forms, set advertising cookies, or add client-side analytics. External services you choose to open from a link apply their own privacy terms.

Retention and deletion

App information remains on your device until you remove it or delete the app. GRIT does not hold a cloud account copy of your workout history or Apple Health data. Deleting GRIT does not delete the original workouts held by Apple Health.

Anonymous date-only analytics retry receipts are deleted before 45 days. Aggregate counts and duration totals cannot reasonably be traced back to a person, device or workout and may be kept longer for product planning.

Identifiable feedback content, an optional reply email, the delivery receipt, disclosed diagnostics and notification status are automatically deleted no later than 90 days after receipt. You can request earlier deletion using the receipt reference. If the report included a reply email, the same email is required to verify deletion. GRIT aims to complete a verified early-deletion request within 30 days and confirms completion without returning report content.

See the data-deletion instructions for the exact on-device and feedback-deletion steps.

Changes to this notice

This notice is updated before a public GRIT version begins a materially different data practice. Material changes will be dated on this page.

Privacy questions

GRIT WOD is operated by Andrew Dunn, trading as Handy Andy 3D. For a question about this notice, contact the public GRIT WOD account at @gritwod on Instagram. Messages sent through Instagram are also handled under Meta's privacy controls.