Skip to content
iris Training coach
How it works Principles Privacy Pricing FAQ
How it works Principles Privacy Pricing FAQ
Language
English Türkçe
Appearance
Privacy policy Frequently asked questions

iris Privacy Policy

Last updated: 28 September 2026

iris creates personalised workout programmes from your photos and the information you provide, helps you record workouts, and supports progress tracking. This policy explains how personal data is processed through the iris iPhone and Apple Watch apps and the services that operate them.

Sending photos for analysis, storing workout data in the cloud, and connecting to Apple Health are separate processing activities. Their scope is explained below.

1. Who is responsible for your data?

BULVAR.CO LIMITED, based in the United Kingdom, is the controller responsible for personal data processed through iris. “We”, “us” and “iris” in this policy refer to that company.

  • Registered office and postal address: 61 Bridge Street, Kington, HR5 3DJ, United Kingdom.
  • Privacy requests and support: support@iriscore.app.
  • Alternative company contact: info@bulvar.co.uk.

iris is offered to people in different countries. Your rights under UK data protection law and, where applicable, the EU General Data Protection Regulation (GDPR), Türkiye’s Personal Data Protection Law No. 6698 (KVKK) and other mandatory local privacy laws are preserved.

This policy provides information. Reading it, downloading the app or continuing to use iris does not, by itself, constitute explicit consent.

2. What data do we collect, and where does it come from?

Account and sign-in information

If you register using email, your email address and authentication information are processed through Firebase Authentication. If you sign in with Apple or Google, we may receive the account identifier, email address and basic profile information provided by that service. If you use Apple’s Hide My Email option, we may receive a relay address instead of your personal address. We do not receive your Apple or Google password.

You can obtain your first assessment without registering an account. However, Firebase creates a pseudonymous technical user identifier to authenticate requests and apply usage limits. This does not make the data completely anonymous. When you register, that identifier and its associated data may become linked to your account.

Profile and training preferences

We process your declaration that you are at least 18, age, stated sex or choice not to specify it, height, weight, training goal, experience, endurance goal, weekly training frequency, session duration, equipment selection and language preference. We do not routinely request a date of birth or identity document to create your training profile.

Photos and assessment results

We process body photos you take in the app or select using the system photo picker, their front/side/back view information, and technical information needed for image processing. An assessment may infer relative muscle-group priorities, posture observations and the limitations of what can be assessed. These results and the resulting programme are associated with you.

A photo and the assessment derived from it are different data. Not keeping a permanent photo archive does not mean the resulting assessment is deleted.

Workout and progress records

We process your programme, exercises, sets, repetitions, weights, effort ratings, rest periods, workout dates and durations, completion status, weigh-ins, weekly check-ins and the reasons for programme adjustments.

If you request programme changes, we also process your selected changes and any explanation you enter. Do not include identity documents, contact details, medical records or other people’s information in free-text fields unless they are genuinely necessary for the relevant request.

Apple Health, Apple Watch and sensor data

When you enable the relevant connections and grant device permissions, we may process heart-rate readings, their times and source, workout information and active energy values. The iPhone app can read recent heart-rate data from Apple Health and may request workout access to operate compatible live sensor sessions. The Apple Watch app can read heart rate and active energy. A Bluetooth connection may also use the selected sensor’s name and connection identifier.

Heart-rate records and active energy values can become part of your workout history. They are not limited to a live display: they may be stored with the session on your device and through cloud synchronisation.

Technical information, diagnostics and feedback

Our services and infrastructure providers may process IP addresses, request times and outcomes, app and operating-system versions, technical device characteristics, installation identifiers, app-verification tokens, usage counters and crash/error information. This supports security, usage limits and troubleshooting.

The scope, disclosure version and time of your privacy choices are recorded with your account identifier. During account deletion, a temporary security lock prevents old sessions from recreating data; it contains the account identifier and operation times.

Earlier versions may have stored a deletion reason, note, app language and submission time as separate feedback. These records have no added account identifier or email address, but free text can still identify you. The new account-deletion flow does not request a reason or feedback.

If you contact us about privacy or support, we process your contact details, request and the correspondence needed to respond.

3. Why do we process data, and on what legal grounds?

We collect data mainly electronically and automatically through your app inputs, uploads, workout records, permitted device connections, sign-in providers and technical service events. Requests and support enquiries may also be received electronically or in writing.

Under the UK GDPR and, where applicable, the EU GDPR, we rely on:

  • Performance of a contract, Article 6(1)(b): Creating and authenticating your account and providing the basic services you request, for data that is not special-category data.
  • Explicit consent, Articles 6(1)(a) and 9(2)(a): Health-related personalisation and the associated processing, sharing and storage that require consent. This includes health-related profile information, photo-derived assessments and heart-rate records. The purposes of cloud storage and third-party AI processing are explained in the consent information.
  • Legitimate interests, Article 6(1)(f): Necessary technical security, preventing misuse, applying usage limits and resolving errors, balanced against your rights. This is not used as a general basis for processing health data.
  • Legal obligations, Article 6(1)(c): Handling statutory requests and complying with binding legal requirements. Processing needed to establish or defend a legal claim is limited to the relevant data and requires the applicable additional condition if special-category data is involved.

Support and feedback processing relies on performance of the relevant service or our legitimate interest in resolving requests and improving service quality, as appropriate. We do not request unnecessary health information for those purposes. UK processing is also subject to the Data Protection Act 2018 and applicable amendments. A contract or legitimate interest alone is not sufficient to process special-category health data.

Where KVKK applies, the corresponding grounds are Article 5(2)(c) for contractual necessity; Article 6(3)(a) for explicit consent to health-data processing; Article 5(2)(f) for necessary, balanced legitimate interests; Article 5(2)(ç) for legal obligations; and Article 5(2)(e) for establishing, exercising or protecting a right. Processing special-category data for a legal obligation or claim also requires the relevant condition under Article 6.

You may withdraw consent to processing based on consent. Withdrawal does not affect the lawfulness of processing carried out beforehand. Declining photo or health-data processing may prevent you from using personalisation features that need that information. Apple Health, Bluetooth and notification permissions are needed only for their related features.

4. How do photos and AI processing work?

Image and pose checks that assess photo suitability take place on your device using Apple Vision where feasible. To create a programme or perform a reassessment, your selected photos and profile are sent over an encrypted connection to the iris server and then to the AI service. A reassessment may also include previous muscle-group priorities and groups that could not be assessed.

A programme-edit request sends relevant content from your current programme, profile and requested changes. It does not require resending your photos. In the current flow, raw heart-rate samples read from Apple Health are not included in programme-generation requests. They may nevertheless be stored in the cloud as part of your workout record.

AI provider: Google Gemini API. It receives the analysis photos, profile and relevant programme/change information described above. Google publishes the Gemini API terms.

The iris application server does not save analysis photos to a permanent photo archive or database and does not write photo contents to application logs. Photos are processed in temporary memory during the request flow. This is separate from the AI provider’s own retention and security logging. Leaving the analysis screen does not retrospectively withdraw a request that has already reached the server.

iris does not use your photos to train its own AI model. We do not use them for identity verification or facial recognition, or estimate age from images. Photos and health-related assessments remain personal data even when no facial-recognition system is used.

AI generates muscle-group priorities, observations and programme suggestions. Weekly progress information can also inform programme adjustments. This involves personalisation and profiling. Outputs are not medical diagnosis or treatment and may be inaccurate. You can correct your profile, request programme changes or stop using personalisation. iris does not use these assessments to make employment, credit, insurance-eligibility or similar legal decisions about you.

5. Who receives your data?

The following recipients may access data to the extent needed for the relevant service:

  • Google Firebase and Google Cloud: Authentication, cloud storage and synchronisation, server operation, app verification, usage-limit management and crash/error analysis through Firebase Crashlytics.
  • The AI provider identified in Section 4: Photo assessment, programme generation and requested programme changes.
  • Apple and your selected sign-in provider: Apple or Google sign-in and the operation of the relevant Apple device, Health and watch features.
  • Recipients you choose: If you share a workout card, the photo and workout information visible on it are transferred to the app or person you select. A photo selected for a share card is not sent for AI analysis for that purpose. Copying to the clipboard, saving to Photos and sharing to social media are separate actions you initiate.
  • Competent authorities and necessary professional advisers: Where necessary and proportionate to meet a binding legal obligation or protect a specific legal right.

We do not sell your personal data. We do not use health data, photos or workout history to target advertising or give them to advertisers. We do not track your activity across apps and websites for advertising. Technical diagnostic and security processing is separate and limited to the purposes described in this policy.

Once you share content with another service, that service’s processing is governed by its own privacy terms. iris cannot automatically delete content you have shared elsewhere.

6. International processing and transfers

iris is operated by a UK company and uses Google Cloud/Firebase and AI infrastructure. Data may be processed outside your country, including by recipients outside Türkiye, the United Kingdom or the European Economic Area. An application server in Europe does not mean that all authentication, database, diagnostic and AI processing occurs only in Europe.

Transfers subject to UK or EU restrictions require the relevant adequacy arrangement or appropriate safeguard. Transfers subject to KVKK must separately meet Article 9 requirements. Consent to processing health data does not automatically satisfy every requirement for ongoing international transfers.

You can contact us using Section 1 to obtain information about safeguards applicable to your data or a copy of the relevant document with protected information redacted.

7. Device, cloud and Apple Health records

Your programme and workout history are stored on your device. When cloud synchronisation is enabled, your profile, photo-derived assessment and programme, completed sessions, weigh-ins and check-ins are sent to Firebase. A synchronised session includes heart-rate samples and active energy where available. The original analysis photos are not part of this training-data synchronisation.

Cloud synchronisation is off by default and requires your separate choice. If you enable it, records may be backed up under a technical user identifier before registration. Turn it off in Settings → Privacy choices to stop new uploads and request deletion of the cloud training copy. If a connection problem prevents completion, the app explains this and asks you to retry. Local records remain separately.

You can also withdraw health-data or AI consent on that screen. Withdrawing health consent stops new workout processing, sensor connections and associated transfers. Use account deletion to remove existing local records. Other devices receive the withdrawal when they reconnect.

If you use Apple Watch, your programme, session records and necessary profile/preferences are transferred between your paired devices. When disconnected, records may remain on the device and transfer after it reconnects.

If you enable saving to Apple Health and grant the relevant write permissions, completed workouts, permitted heart-rate records and active energy values may be written to Apple Health. Apple Health or the device system may also create its own records during sensor use. Turning off saving to Apple Health does not delete existing records or automatically stop iris’s own workout history or cloud storage.

You can change camera, Bluetooth, notification and Health permissions in your device settings. Revoking Health access does not automatically delete information previously transferred to iris.

8. How long do we keep data?

Retention depends on the service requiring the data, your account and feature use, deletion requests and applicable legal obligations.

  • Analysis photos: The iris application server does not create a permanent archive. iris does not delete originals in your photo library.
  • Profile, assessments, programmes and progress: Retained to provide history and programme continuity until you delete the relevant records or the service relationship ends and retention is no longer necessary.
  • Authentication records: Retained until the sign-in account is deleted. Under Firebase’s published terms, removal of the associated authentication information from active and backup systems can take up to 180 days after account deletion is initiated. Authentication IP logs have separate provider retention periods.
  • Crash records: Firebase Crashlytics retains crash traces and associated identifiers for 90 days before beginning removal from active and backup systems. This is not a general retention period for all iris data.
  • Consent and deletion-operation records: Account-linked consent records are removed during account deletion. A completed deletion’s security lock becomes eligible for automatic expiry after 24 hours; asynchronous infrastructure cleanup may take additional time. An incomplete deletion remains locked until it can safely complete.

If a specific legal obligation or dispute requires longer retention, only the necessary data is retained for that purpose with restricted access. This exception is not used to retain all data indefinitely.

9. Deletion, correction and controls

You can update your profile in the app’s account screen and delete individual sessions from your history. Deleting a session does not automatically undo adjustments that the session previously contributed to your programme.

Start deletion under Settings → Account or Privacy choices. You are asked to verify control of the same account using your sign-in method. For Sign in with Apple, revocation of the Apple connection is included. No reason is required.

Deletion covers your Firebase sign-in account, device profile/programme/workout records, app-managed cloud training copies, account-linked consent records and usage counters. Failed server cleanup is not presented as completed deletion: check your connection and retry. A paired watch may need to reconnect to remove its copy. The temporary security lock and provider cleanup periods in Section 8 still apply. Independent feedback from older versions has no account identifier and cannot automatically be matched to your account; contact us using Section 1 about a note containing personal information.

Apple Health records, your photo library, exported share cards and content sent to other apps are separate copies. General in-app data deletion does not automatically remove all of them. Manage these copies through the relevant service. Uninstalling iris or signing out is not a request to delete your server-side account or cloud data.

10. Your privacy rights

Under UK or EU GDPR, where the relevant conditions are met, you can request access to your data, correction, erasure, restriction of processing and data portability. You can object to processing based on legitimate interests, withdraw consent and complain to the competent supervisory authority. In the UK, this is the Information Commissioner’s Office (ICO). In the EEA, you may contact the relevant local data protection authority.

Where KVKK applies, you can learn whether your data is processed; request information about processing, its purpose and whether it is used accordingly; learn the domestic or overseas recipients; request correction of incomplete or inaccurate information; request deletion or destruction when the legal conditions are met; and request notification of correction/deletion to recipients. You can object to an adverse result produced solely through automated analysis and seek compensation for damage caused by unlawful processing. Complaints to Türkiye’s Personal Data Protection Board are subject to the applicable preliminary application requirements and deadlines.

US state or other local laws may provide additional rights, including information about data categories and recipients, access/copies, correction, deletion, stopping certain processing or sharing, requests through an authorised agent, and an appeal if a request is refused. To appeal, contact the same address with the subject “Privacy request appeal”. We do not sell personal data, including health data, or share it for cross-context behavioural advertising. We do not discriminate against you for exercising legal rights; we explain where stopping processing affects a feature that needs the data. This policy does not limit stronger protections under applicable local law.

Send requests through the contact channels in Section 1. A formal KVKK application must follow the applicable statutory procedures. Using the email address registered to your account helps us verify the request. We may request necessary, proportionate verification to avoid disclosing your data to someone else. Do not send your password.

We respond to KVKK requests as soon as possible and within 30 days. UK/EU GDPR requests are generally answered within one month; if a permitted extension is needed, we explain its duration and reason. Requests under other laws are handled within the applicable statutory period. Requests are generally free, subject only to exceptions permitted by applicable law.

11. Security and age restrictions

We use measures including encrypted transmission, account authentication, app verification and user-based access controls. Workout files on the phone use operating-system file-protection features. We apply data minimisation to avoid adding photo or health contents to diagnostic logs. No system can guarantee absolute security; any required breach notifications are made under applicable law.

iris is for people aged 18 or older. Age screening relies on your declaration. People who declare that they are under 18 are not offered photo analysis or workout programmes. Contact us using Section 1 if you believe a child’s personal data has been submitted, so we can investigate and take appropriate deletion action.

12. Changes to this policy

We update this policy and its date when our processing practices change. Changes materially affecting data use, sharing or your rights will also be brought to your attention through an appropriate channel. If new processing requires explicit consent, we request it separately; a policy update or continued use of iris does not substitute for consent.

Back to top
iris

Assess → train → adjust.

  • Privacy policy
  • FAQ
  • Support · support@iriscore.app
  • Türkçe

This site sets no cookies. Visits are counted with Cloudflare Web Analytics, which uses no cookies and doesn’t follow you across sites.

iris is made by BULVAR.CO LIMITED, United Kingdom.

iris is a training app, not a medical device. Apple, Apple Watch, iPhone and App Store are trademarks of Apple Inc.

© 2026 BULVAR.CO LIMITED