Lonexa.
← Lonexa

Privacy Policy — Steady Increment

Last updated: 27 August 2026

Steady Increment is published by Lonexa LLC (Kentucky, United States).

This policy describes what the app stores, what leaves your device, and what never does. It is written to be read rather than to be defensible, because the architecture is genuinely simple: the app is local-first, and most of it never touches a server at all.


The short version

Where it lives
Everything you log — workouts, sets, cardio, plans, gyms, body metricsOn your device, in a database only this app can read
The same data, if you create an accountAlso on our server, so a second device can see it
Progress photosOn your device only. Never uploaded, under any circumstances.
What the AI features seeTraining numbers only — see Artificial intelligence below
Crash reportsSent to Sentry when something breaks. No IP address, no account, nothing you logged
Which screens you openOnly if you turn it on. Off by default; a count per screen per day, never what you logged

You do not need an account to use this app. Logging a workout has never required one and never will. An account exists for one reason: so the same data appears on a second device.


What we collect, and why

Data you enter

Workouts, sets, weights, reps, cardio sessions, plans, gyms and their equipment, bodyweight, body-fat percentage, tape measurements and readiness check-ins.

All of it is stored locally on your device. The app reads every screen from that local copy, which is why it works with no signal.

Data from Health Connect (Android)

If you grant permission, the app reads sleep, steps, heart rate, bodyweight and body-fat percentage from Health Connect, and writes completed workouts back to it.

Account data

If you create an account, we store your email address and an authentication token. Passwords are handled by our authentication provider and are never stored by us in a form we can read.

Crash reports

If the app crashes or hits an error it could not handle, a report is sent to Sentry, our crash-reporting provider, so we can find and fix it. A report contains the error, the stack trace, and the app and device version.

Usage counts — off unless you turn them on

You can choose to share which screens you open, under Usage in Settings. It is off by default and nothing is recorded until you switch it on.

What is recorded is a count per screen per day — for example, "coach: 3 times on 29 August". That is the whole of it. Specifically:

Settings shows you exactly what has been recorded on your device before any of it is uploaded, and Forget what has been recorded deletes it.

We use this to answer one question — which features are worth building on — and nothing else.

Advertising

We do not collect advertising identifiers, and there is no advertising in the app.

We have never sold personal data and will not. We do not share it with advertisers or data brokers.


What leaves your device

Nothing you have logged, unless one of these three things is true. Crash reports are separate and are covered above — they carry no logged data.

1. You created an account (sync)

Your logged data is uploaded to our server so your other device — or your partner, if you have linked accounts — can see it. Row-level security means one account cannot read another's rows; this is enforced by the database, not by the app.

These sync: workouts, sets, cardio sessions, plans, gyms, equipment, exercise preferences, readiness check-ins, body metrics, goals, settings — and the usage counts described above, but only if you switched them on.

These never sync, by design:

2. You linked accounts with a partner

Partners share plans, workouts and sets. Partners do not share body metrics, progress photos or AI spending. Either person can unlink at any time.

3. You used an AI feature

See below.


Artificial intelligence

AI features are optional and are off unless you use them.

When you use one, the app sends a small context — training numbers relevant to the question — to our server, which forwards it to Anthropic (our AI provider) and returns the answer. Our server holds the API key so it is never in the app.

The context never contains:

This is enforced in code at the point every request is built, not by instructions in a prompt, and it is covered by automated tests that fail the build if a restricted field is ever added to a request.

Anthropic processes these requests on our behalf. We do not use your data to train any model, and our agreement with Anthropic does not permit them to either.

Every AI feature has a deterministic fallback. If you switch AI off, or have no signal, or exceed the monthly budget, the app still answers — from the local engine — and always tells you which answer you are looking at.


Children

Steady Increment is not directed at children and we do not knowingly collect data from anyone under 13 (or the equivalent minimum age in your jurisdiction).


How long we keep it

Local data stays on your device until you delete it.

Synced data stays on our server until you delete it or close your account.

Settings → Data → Reset everything deletes both. It purges the server copy first and refuses to run at all if it cannot reach the server, precisely so it cannot leave you with a device wiped and a server copy waiting to come back.

Deleting the app removes all local data including progress photos. If you had an account, delete the account first — Account and sync → Delete your account — or email us afterwards, so the server copy goes too. Uninstalling on its own does not remove anything from our server.


Your rights

Depending on where you live you may have the right to access, correct, export, delete, or restrict processing of your personal data, and to object to it.

Three of these you can exercise without contacting anybody:

Those last two are different actions and the difference matters: a reset is for starting over, and deleting your account is for leaving. The training log on your own phone survives an account deletion — it is often the only copy — and Reset everything is what removes that.

For anything else, email the address below. We will respond within 30 days.

If you are in the EEA or UK, the lawful basis for processing is performance of a contract (providing the app you asked for) and, for the AI features and Health Connect access, your consent — which you can withdraw at any time by turning them off.


Security

Data in transit is encrypted with TLS. Data on our server is encrypted at rest and access is restricted by row-level security policies enforced by the database. Data on your device is protected by your device's own encryption and app sandboxing.

No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you and any required regulator without undue delay.


Changes

If this policy changes materially, the app will say so before the change takes effect rather than quietly updating a page nobody revisits.


Contact

Lonexa LLC support@lonexa.ai