Ledger is a training log. It records the sessions you do, estimates how recovered each muscle group is, and can read sleep and recovery figures from a watch if you connect one. This policy explains what it holds, who else sees it, and how to get rid of it.
The short version: everything Ledger stores is there so the app can work for you. Nothing is sold. Nothing is used for advertising. Nobody tracks you across other apps or websites, and there is no analytics, crash-reporting, or attribution code in the app at all.
Who we are
Ledger is developed by Marwan Aljasmi (the "developer", "we"). For privacy questions, contact: contact@nexudo.tech
What Ledger collects
Your account
- Email address. This is your sign-in identity and the key that ties every other record to you.
- Display name and username, if you choose to set them. Both are optional.
- A user identifier issued when your account is created.
What you log
Everything you enter yourself, which is the substance of the app:
- Sessions, exercises, sets, weights, repetitions, and how hard each set felt.
- Training programs and schedules.
- Bodyweight and tape measurements, if you record them.
- Food and macronutrients, if you use the nutrition features.
- Sleep, if you type it in rather than reading it from a device.
Health and fitness data from other sources
Only if you turn these on:
- Apple Health. Ledger reads sleep only, and only after you grant access on Apple's own permission sheet. It is read-only: Ledger never writes anything back to Apple Health.
- WHOOP, if you connect it. Ledger requests three permissions and no others: recovery data (recovery score, heart rate variability, resting heart rate), sleep data (duration and start and end times), and offline access so the connection does not expire after an hour. Ledger does not request your WHOOP profile, workouts, cycles, or body measurements.
Your subscription
Apple's transaction identifier for your subscription and whether it is currently active.
Ledger never sees your card, bank details, or billing address. Payment is handled entirely by Apple.
What Ledger does not collect
Stated plainly, because what is absent matters as much as what is present:
- No location data, precise or coarse. Nothing in the app asks for it.
- No contacts, photos, or microphone access. The camera is used only to scan a barcode on food packaging; no image is stored and none leaves your device.
- No browsing history, search history, or diagnostics.
- No advertising identifiers, and no tracking of you across other companies' apps or websites.
- No analytics or crash-reporting SDK. There is none in the app.
Apple Health data, specifically
Where Ledger reads sleep from Apple Health, that data:
- is never used for advertising or marketing;
- is never sold, rented, or shared with data brokers;
- is never used for data mining or any purpose other than showing you your own recovery estimate;
- is not written to iCloud.
You can withdraw access at any time in the iOS Health app under Sharing. Ledger stops reading immediately. Sleep already imported remains until you delete your account, as described under Retention.
The AI coach
If you use the coach, your question and a summary of your current training context are sent to Mistral AI to generate the reply.
That context is a summary, not your raw records. It contains your recent sessions and your per-muscle recovery percentages, and because recovery is calculated partly from sleep, figures derived from Apple Health or WHOOP sleep can influence those numbers. It does not include your body measurements, your nutrition log, your email address, or your name.
If you would rather no training data reach a third party, do not use the coach. Every other part of Ledger works without it.
Ledger calls Mistral's standard API (the same product any paying developer uses, not Mistral's free consumer chat product). By Mistral's own published policy for that API, your prompts are never used to train their models, and inputs and outputs are retained for 30 rolling days for abuse monitoring, then deleted. Mistral also offers Zero Data Retention as a paid upgrade on its Scale plan for this kind of request, which would remove even that 30-day window; confirm with your account team whether that upgrade is active before treating this paragraph as final.
Who else processes your data
- Google Firebase: your email address and authentication, for sign-in
- Apple: subscription status and transaction identifiers, for billing through the App Store
- Mistral AI: coach questions and training context, only when you use the coach
- WHOOP: recovery and sleep data, only if you connect WHOOP
- Ledger's own servers: everything Ledger stores; self-hosted infrastructure, reached publicly through Cloudflare, for running the app's backend
If you are in a different country from where those servers are, your data is transferred there so the app can function.
How your data is protected
- Traffic between the app and Ledger's servers is encrypted in transit.
- Access tokens for connected providers such as WHOOP are encrypted at rest using AES-256-GCM. Ledger never stores your WHOOP password; it never has it.
- No employee routinely reads your training data.
No system is perfectly secure, and this policy does not promise one.
Retention and deletion
Read this section carefully, because it is the part people most often assume wrongly.
Disconnecting a provider keeps what has already been imported. If you disconnect WHOOP, Ledger stops fetching new data and deletes the stored access token, but the recovery and sleep figures already imported stay in your account and continue to inform your history. There is no per-provider erase.
Deleting your account is the only way to erase your data. It removes your account and the training records attached to it, including everything imported from Apple Health and WHOOP. It cannot be undone.
You can delete your account from within the app, under Profile, then Settings.
Some records may persist briefly in encrypted backups after deletion, and Apple retains its own transaction records independently of Ledger, under its own policy.
Your rights
Ledger provides two rights directly in the app, without needing to ask:
- A portable copy. Profile, Settings, export your data. It produces a file of your training records.
- Deletion. Profile, Settings, delete account.
Depending on where you live, you may have further rights over the data Ledger holds about you. If you are in the European Economic Area or UK, you have rights under the GDPR. If you are in California, you have rights under the CCPA. If you are in the UAE, you have rights under the Federal Decree-Law No. 45 of 2021 on Personal Data Protection (UAE PDPL). For anything beyond what the app gives you directly, write to contact@nexudo.tech and you will get an answer within 30 days.
Children
Ledger is not intended for anyone under 16, and it is not directed at children. Ledger does not knowingly collect data from anyone under that age. If you believe a child has created an account, write to contact@nexudo.tech and it will be removed.
Changes to this policy
If this policy changes materially, the date at the top changes and the app will tell you the next time you open it. Continuing to use Ledger after that means you accept the revised policy.
Contact
contact@nexudo.tech