← Back to Lockout
Privacy Policy for Lockout
Last Updated: March 14, 2026
Lockout is committed to protecting your privacy. This Privacy Policy explains how we handle your information when you use our mobile application, including the optional Community features.
1. Data We Collect and How We Use It
Lockout's training journal is designed as a "local-first" app. Your private training data stays on your device. When you choose to use the Community features, certain data is stored in Apple's iCloud (CloudKit) — see Section 2.
- Fitness & Health Data: We store your workout logs, exercise sets, weights, body measurements, and progress photos. This data is used solely to provide you with tracking and analytics features within the App. It is stored on your device only — we have no private servers and no copy of your data, unless you explicitly choose to share a workout to the Community feed.
- Apple Health (HealthKit) Data: If you grant permission, Lockout reads data from Apple's HealthKit database (specifically heart rate, active energy/calories, resting heart rate, and heart rate variability) to calculate and display workout performance, heart rate zones, and recovery metrics. We also write your completed workout duration and logged body weight entries back to HealthKit if you choose. All HealthKit data remains entirely on your device and is never sent to external servers, shared with advertisers, or used for profiling.
- Purchase Information: We use Apple's StoreKit to manage subscriptions and tips. When you make a purchase, Apple verifies the transaction and shares your subscription status with us so we can unlock Pro features. We never see your name, payment card details, or billing information.
2. Community Features (CloudKit)
The Community tab is entirely optional. You only enter the Community by creating a community profile (username, display name, optional bio, optional bodyweight, optional avatar). If you never create a profile, none of the data described in this section is collected.
When you do opt in, Community data is stored in Apple's CloudKit public database — Apple's iCloud infrastructure, accessed through your Apple ID. We do not operate any private servers; we do not see, copy, or process this data outside of what Apple's CloudKit APIs return to your device when other community members request it.
- Profile data: Your chosen username, display name, bio, avatar selection, and bodyweight (if you set it). This is visible to other Lockout users.
- Shared workouts & posts: Any workout, text note, poll, or weekly recap you explicitly share. Includes the workout title, caption, exercise list, top weights, and duration. Visible to your followers (or to anyone if your profile is open).
- Photos: Photos you attach to posts or use as your avatar are stored as CloudKit assets. Photos are compressed (max 1080px, ~250 KB) before upload.
- Social interactions: Likes, comments, comment likes, replies, follows, follow requests, poll votes, post ratings, "trained with" tags, and saved posts.
- Direct Messages: 1:1 messages you send to another lifter are stored in CloudKit and visible to you and the recipient. We do not have access to read your message contents.
- Push notification subscriptions: If you allow notifications, CloudKit may send you pushes for likes, comments, follow requests, ratings, and new messages. You can disable per-type pushes in the Community → Notification Settings sheet, or globally in iOS Settings.
- Reports: If you report a post or comment, the report (target ID, reason, and your CloudKit user ID) is stored so the Lockout team can review it. Reports are used solely for moderation under Apple's user-generated content requirements.
- Blocked / muted users: Your block and mute lists are stored locally on your device and apply to the Community feed across all your devices signed into the same iCloud account.
You can stop using the Community at any time. Deleting your community profile from CloudKit will remove your profile record, though previously sent messages may remain visible to recipients (the same way deleting an iMessage account works).
3. iCloud Drive Backup
If you enable iCloud Drive auto-backup (Pro feature), a snapshot of your local training data is written to your own iCloud Drive folder after each completed workout. This backup lives in your personal iCloud — we never access it. You can delete it at any time from the Files app.
4. Advertising (AdMob)
Lockout shows banner advertisements to users on the free tier using Google AdMob.
- To show ads, Google may collect and use device identifiers (such as the IDFA) to personalize your ad experience.
- Upon your first launch, you will be asked for permission to "Track" via the App Tracking Transparency (ATT) prompt. You can opt-out at any time in your iPhone's Settings.
- If you upgrade to Lockout Pro, all advertising and tracking related to AdMob are disabled.
5. Data Storage and Security
- On-Device: Your private training data is stored locally in a secure database on your iPhone. We have no servers that receive or store it.
- CloudKit (Community only): Community data lives in Apple's iCloud, accessed via your Apple ID. Apple's privacy and security practices govern that storage.
- No Third-Party Sales: We never sell your fitness data, community posts, messages, photos, or any personal information to third parties.
- No Analytics Tracking: We do not use third-party analytics (like Google Analytics, Firebase, Mixpanel, etc.) to track your behavior inside the App.
- End-to-end: Apple's CloudKit transport is encrypted in transit. Direct Messages are stored in Apple's iCloud public database scoped to the participant pair — Apple may technically access this storage, but we do not.
6. Your Rights and Control
- Data Export: You can export all your local training data as JSON or CSV at any time from the in-app Backup screen.
- Data Deletion (Local): Delete the App from your device to remove all local training data.
- Data Deletion (Community): Use the in-app delete actions to remove individual posts, comments, or your entire community profile. Removing your community profile clears your username, bio, bodyweight, and avatar from CloudKit.
- Block & Mute: Manage your block list from Community → your profile menu → Blocked Users, or from Settings. Blocking is local; the blocked user is not notified.
- Notification Preferences: Toggle pushes per type (likes, comments, follows, requests, ratings, PRs) in Community → Notification Settings.
- Permissions: Revoke permissions for Notifications, Photo Library, Tracking, or HealthKit at any time via the iOS Settings app.
7. Changes to This Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date.
8. Contact Us
If you have any questions about this Privacy Policy, please contact us at: gymbuddy.lockout@gmail.com