SecondwindStrength for the decades ahead

Privacy policy

Privacy, in plain words.

Last updated: 14 August 2026

The short version: Sign in with Apple is required before purchase or restore and for custom Coach questions. Your programme and workout history stay on this phone. Secondwind has no advertising. Before the first custom Coach question is sent, Secondwind asks for permission to send the question and a short programme context to Kovus and Anthropic. Post-session Coach notes and the six quick answers stay on the device. Apple and RevenueCat process subscription information. We do not sell personal information or use it for advertising.

Who we are

Secondwind is developed by Josh Waller, trading as Kovus, in Perth, Western Australia. Contact josh@kovus.dev for privacy questions or requests.

Information stored on your device

Secondwind stores the information needed to run your programme locally, including:

Secondwind does not request your name or email from Apple and does not use a password. Apple and Supabase provide opaque identifiers for the linked service account. You can export the app data from Settings. Delete account and all data removes local app data and the linked service account as described below.

Custom Coach questions

The six quick answers shown in Coach and post-session Coach notes are built into the app and work offline. Before the first custom question leaves the device, Secondwind shows the data recipients, context and retention and asks you to choose Agree and send. Choosing Not now sends nothing. The choice is stored on this device, can be reset in Settings and will be requested again if the data, recipient, purpose or retention materially changes.

If you approve and send a custom question, Secondwind sends the following over an encrypted connection:

The request goes to a Kovus-operated Supabase Edge Function, which validates the non-anonymous Sign in with Apple session, checks the active RevenueCat entitlement and verifies App Attest when supported, and then sends the request to Anthropic's commercial API. Kovus stores a per-account burst counter, a daily counter keyed to the RevenueCat subscription, a daily counter keyed to a cryptographic hash of an attested installation, and a global token counter. App Attest registration stores the public key, Apple receipt, environment and signature counter needed to reject replayed requests. Kovus does not store the question in the Coach service database. Your copy of the conversation remains on your device.

Anthropic states that standard API inputs and outputs are automatically deleted from its backend within 30 days, subject to exceptions for services with different retention, agreed terms, usage-policy enforcement and legal requirements. Read Anthropic's commercial data retention information.

Do not include information that identifies you or another person in a Coach question. Coach is an optional programme-support feature, not medical advice.

Subscriptions and purchases

Before purchase or restore, Secondwind uses Sign in with Apple to create an opaque Supabase service account and identifies the RevenueCat customer with that opaque account identifier. This lets the App Store entitlement remain attached to the same private service identity across purchase, restore, transfer, reinstall and custom Coach checks. Secondwind does not request your name or email from Apple. RevenueCat does not receive your Secondwind programme, Coach messages or Apple Health data. Read RevenueCat's privacy policy and Apple's privacy policy.

RevenueCat also sends Kovus subscription lifecycle events so we can investigate entitlement and billing-delivery problems. Kovus stores the event identifier and type, app user identifier, product identifier, price and event timestamps, together with the event payload supplied by RevenueCat. These records do not contain payment-card details, your Secondwind programme, Coach messages or Apple Health data. Kovus does not receive your payment-card details.

Apple Health

If you enable Apple Health sync, Secondwind asks permission to save completed functional strength workouts. Secondwind does not upload Apple Health data to Kovus or Anthropic. A workout already saved to Apple Health is managed in the Health app and is not removed when you delete Secondwind's local app data.

Notifications

Session and renewal reminders are scheduled locally on your device. Secondwind does not use a push-notification server in version 1.

Apple Maps professional search

When you choose Find a pro nearby, Secondwind opens an Apple Maps search for the professional type you selected. Secondwind does not request location permission, receive your location or receive the resulting listings. Apple handles the search under its own privacy policy.

Analytics and diagnostics

Version 1 records a small set of product events only in the running app for development diagnostics. Those events are not transmitted to Kovus or an analytics provider in the release configuration.

Secondwind keeps up to 20 bounded crash and error diagnostics on your device so a support reference can be investigated. Email-like strings and long token-like values are redacted from the saved message, and the log records context-key names rather than their values. The diagnostics are not sent automatically. Export my data includes the saved diagnostics and recent errors still held by the running app.

When a production release is supplied with the complete Sentry configuration, sanitised JavaScript error messages and stacks, app version, operating-system and device diagnostics may be sent to Sentry for reliability support. Remote error messages and stacks redact email-like strings and long token-like values before sending and are length-bounded. Remote context is limited to the support reference and bounded, redacted operational labels. Sentry breadcrumbs and native crash handling are disabled. Default personal-information collection, tracing, screenshots and view hierarchy are disabled.

Where service data is processed

The Secondwind Supabase database is configured in Sydney, Australia. RevenueCat stores customer data in the United States and may use service providers in other jurisdictions. A custom Coach question is processed by Anthropic and its service providers and may be processed outside Australia under Anthropic's commercial terms and data-processing arrangements. Overseas providers can be subject to the laws of the countries in which they operate.

Retention and deletion

Local information remains until you delete it in Settings or remove the app. Delete account and all data clears Secondwind's SQLite records, persisted app state, local Coach history, crash diagnostics and reminder schedules. If a linked service account exists, the same action deletes the Supabase Auth account, integrity challenge rate-limit bucket, App Attest challenges and key record, Coach request claims, account burst counter and linked RevenueCat webhook event copies before clearing the local session.

To let an interrupted deletion finish safely, Kovus retains a bounded deletion receipt containing a SHA-256 hash of the app-generated random request identifier, the opaque Supabase account identifier, whether Apple authorisation was revoked, and its creation and expiry times. It is accessible only to the server's service role and expires for retry after seven days. A scheduled daily purge removes expired receipts. If server deletion cannot complete, the app keeps the local session or uses that bounded receipt so you can retry. Apple and RevenueCat purchase records remain subject to their own retention and account controls, and deleting Secondwind does not cancel a subscription.

Kovus keeps Coach subscription, attested-installation and global rate-limit counters for up to 31 days. The subscription counter is keyed to RevenueCat's subscription identifier rather than the deleted Secondwind account so reinstalling or changing app accounts does not reset a paid allowance. Kovus keeps RevenueCat subscription event copies for up to 24 months unless they are deleted through the in-app account deletion flow. Apple, RevenueCat and Anthropic also retain information under their own legal and operational obligations.

Access, correction and privacy complaints

Email josh@kovus.dev to ask what personal information Kovus holds about you, request correction or deletion, or make a privacy complaint. We may need account or purchase context to locate a server record. We will acknowledge a complaint and respond within 30 days. If you are not satisfied, you may contact the Office of the Australian Information Commissioner.

European Economic Area, United Kingdom and Switzerland

Kovus is the controller of the personal information described in this policy. Onboarding joint considerations and pre-exercise screening answers are health-related information. Secondwind asks for explicit consent to that screening and asks for separate explicit consent before that context is included in a custom Coach question that leaves the device.

Subject to applicable conditions and exceptions, you may have rights to access, correct, erase, restrict or object to processing, and receive a portable copy of your information. Export my data and Delete account and all data are available in Settings and remain available when a subscription is paused. Email us for a request you cannot complete in the app. We will respond within 30 days.

A custom Coach question is sent from your device to a Kovus-operated Supabase Edge Function in Sydney and then to Anthropic's commercial API in the United States. The specific transfer safeguard and any requirement for a formal EU or UK representative must be confirmed before distribution is enabled in those regions.

Security

Custom Coach requests use encrypted HTTPS connections. No system can be guaranteed completely secure. Keep identifying, medical and highly sensitive information out of Coach questions.

Children

Secondwind is designed as a strength-training app for adults. It is not directed to children and does not knowingly collect a child's personal information.

Changes and contact

We may update this policy when the app or its service providers change. The current version and update date will remain on this page. Email josh@kovus.dev with a question or request.

Read the terms of service or visit Secondwind support.