OpenSet

Privacy Policy

Effective date: 27 September 2026

OpenSet is operated by M3E Brands LLC, an Arizona limited liability company ("OpenSet," "we," "us," or "our"). This policy explains how we collect, use, disclose, retain, and protect personal information through the OpenSet mobile app, our website, and related support services.

OpenSet is for adults in the United States: you must be at least 18 years old to use it. Our Terms of Use explain the other eligibility requirements. This policy describes our information practices; reading or accepting it does not replace a separate consent where one is required.

1. Key points

2. Information we collect and where it comes from

Account and profile information. When you create an account, we collect your email address, your first and last name, and the information needed to sign you in. Supabase provides sign-in. Your password is used only to sign you in; never send it to us in a support request.

You may also add a profile photo, a short bio, a gender selection, a training goal, your experience level, how you heard about OpenSet, a home gym, and a temporary visiting gym. First and last names are required to register; the rest is optional. We also keep your settings, including sharing, messaging, and notification preferences.

Your gender selection chooses which default avatar illustration represents you, so other people may be able to infer it. Training goal and experience level personalize the app. How you heard about us helps us understand how people find OpenSet.

We do not ask for your date of birth. Our Terms of Use, which you agree to when you create an account, require you to be 18 or older.

Training and related health information. We collect what you log, including:

We use these records to work out statistics such as volume, progress, personal records, and strength relative to bodyweight. The records and those statistics can be personal or consumer health data. OpenSet does not read from or write to Apple Health or any other health platform.

Social content, messages, and safety information. We collect posts, photos, captions, questions, comments, replies, reactions, kudos, follows, group memberships, and the audience you choose when you share a workout or statistic.

For direct messages, we store the message text, who is in the conversation, when messages were sent, how far each person has read, your messaging preferences, and message requests. Section 5 explains who can access messages and how deletion works.

When someone reports content or an account, we collect the report, anything submitted with it, and the content or conduct reported. We keep block and mute preferences and the records needed to handle reports. So information about you can come from another member, for example through a message, a post, or a report.

Support, requests, and gym suggestions. When you contact us, we collect your contact details, what you write, and what we need to respond, including information used to verify a privacy request. Gym suggestions can include a gym's name, city, state, and your notes. Please don't send more sensitive information than your request needs.

Imported workout history. If you ask us to import history from another app, we receive the file you upload and details of the request. Export files can contain workouts, dates, notes, measurements, and other information from the other app. A person at OpenSet opens and reads your file by hand and adds the supported records to your account; we do not use an automated importer yet.

While doing your import, we also learn how that app lays out its exports, so we can build an automated importer later. It is a second use of your file, so here is exactly what it means:

Only upload information you are entitled to share, and remove anything unrelated where you can. Import files are kept in restricted, non-public storage. Imported workouts are added as "only you", so they don't appear to your gym or your followers unless you share them. You're told when an import is done or rejected through an in-app notification, a push notification if you allow them, and usually an email from our support address. You can withdraw a pending import from the same screen, which deletes the file. Contact us to remove records that were already imported.

Technical and subscription information. We and our providers process what's needed to deliver, secure, and fix the service. This includes your account ID, device and app information (model, operating-system and app version), IP addresses handled by our providers when your device connects, timestamps, app activity, error reports, and push notification tokens. Section 6 explains analytics and notifications.

Apple processes subscription payments. RevenueCat tells us whether your subscription is active. We receive the product, transaction, and subscription status; we never receive your payment card number.

3. How we use information

We use information to:

We don't use message content to build advertising profiles, and we don't use your fitness data for anything outside these purposes without asking where the law requires it.

4. What other people can see

Profiles and gym membership. Your display name, avatar, bio, and badges can appear on your profile and next to your activity. Your last name is shown by default unless you turn it off in Settings. Your gym or group memberships can be visible through profiles, member lists, or shared activity, depending on the group and your settings. Being in a gym's group doesn't mean OpenSet has checked that someone trains there.

Your surname (when hidden), training goal, experience level, and how you heard about us are visible only to you. Your gender selection is never shown as a label, but other members' apps receive it because it chooses the default avatar they display.

Private mode takes you out of member search and limits your profile page. It does not hide posts, comments, group member lists, or other activity that has its own audience. People can see follow relationships through activity; the app doesn't show other people's full follower and following lists.

Posts, workouts, and Discover. Check the audience each time you share. Depending on the feature, you can share to a gym or group, to your followers, or keep it to yourself ("only you"). The sharing control may start on your home gym.

For groups that allow it, "Also show in Discover" makes content visible to OpenSet members outside that group, and it starts switched on. Check both the group and the Discover switch before you share. A group's audience includes people who join later.

When one post is shared to several groups, each group has its own comments. Reaction totals include everyone, but names are shown only to people who share a group with the person who reacted, and Settings lets you stay out of reaction-name lists.

Your weigh-ins and height are never shown to other members. But a statistic, goal, workout, or post you choose to share can contain a measurement or let someone work it out; for example, a strength-to-bodyweight ratio next to a lifted weight can reveal roughly what you weigh. Deleting the underlying record doesn't remove something you already shared.

Photos and copies. Profile, group, and post photos are stored so that anyone with a photo's web address can open it, including people who are signed out or blocked. Nobody can list or browse the photos; they would need the address. Viewers can copy or pass that address on, and blocking someone doesn't revoke it.

Photos are only for content you share. You can't attach a photo to a post or workout kept to "only you", and a workout with a photo can't be changed to "only you".

When you delete a post or workout, replace your profile photo, or replace a group photo, we delete the old image from our storage. A copy can keep being served from a delivery cache for up to about an hour. When you delete your account, we delete every photo and file you uploaded; if that can't be completed, your account is not deleted and you're asked to try again. Copies other people have already saved are outside our control. Uploaded photos may be reviewed after they are published, so a photo can appear before a moderator sees it.

Gym activity and live visibility. Gym pages can show totals such as workouts in progress, workouts finished, and weight moved. They don't show names, but in a small or quiet gym someone might work out who contributed.

Separately, you can choose to be shown as training right now so members of your gym can cheer you on. You're asked each time unless you choose to remember "Show me", which then applies to later workouts until you change it in the live-visibility setting. Your gym and the times you train can reveal your routine even though we don't use location.

5. Messages, blocking, and moderation

Messages are for the people in the conversation. They are not end-to-end encrypted. Authorized OpenSet staff and our service providers can access messages only when needed to investigate a report, deal with a safety or security issue, give support you asked for, or comply with the law and valid legal process, and only as much as that requires. We don't read messages routinely, and we don't use them for advertising.

Your messaging settings decide who can message you directly and whose messages go to Requests. Being in the same gym or group can let someone message you directly; it doesn't mean we've verified who they are. A conversation you've accepted stays open even if you later narrow who can message you. Blocking stops messages both ways. Message notifications never include the message text.

Hiding a conversation removes it from your list but doesn't delete the messages or the other person's copy, and a new message brings it back. When you delete a message, it disappears from the conversation, but we keep a copy for up to 90 days so reports can be investigated. Deleting your account deletes your conversations, including for the other person. Screenshots and copies other people make are outside our control.

Reports are handled by a small number of people. We don't normally tell someone who reported them, but the report itself can make it obvious, and the law can require disclosure. A block isn't secret: the other person can notice its effects. Muting is separate and silent.

Intimate images shared without consent. To have an intimate image of you removed, email report@openset.fit with the subject "Intimate image removal" and a link to or description of where it appears. We act on valid requests as soon as possible, and within 48 hours as the law requires, and we remove copies we can find.

6. Analytics, notifications, and the website

Analytics and error reports. We use PostHog for product analytics and Sentry for error reporting. PostHog receives events tied to your account ID: that you signed up, finished onboarding (with your goal, experience level, and how you heard about us), finished a workout (with counts such as sets and duration), shared something, joined a group, and similar actions, plus the app opening and closing, and basic information about app errors. Sentry receives error reports: what failed, the device model, and the operating-system version. Error reports can occasionally include technical details of what the app was doing at the time. Performance tracing is off. We use this to understand how OpenSet is used and to fix problems, never for advertising.

Notifications. If you allow push notifications, we store a device token and use Expo and Apple to deliver them. Notifications can include someone's name and a short preview, for example the start of a comment; message notifications never include the message. They may be visible on your lock screen depending on your device settings. You can turn categories off in Settings or turn notifications off in your device settings. Signing out removes this device's token from your account, and deleting your account deletes all your tokens.

Our website. openset.fit is a static site delivered by Cloudflare, which processes technical information such as IP addresses to deliver and protect it. The site sets no cookies, runs no analytics or tracking, and has no forms. Because there is no tracking, there is nothing for a browser's Do Not Track or global privacy signal to switch off.

7. When we share information

We share information only:

Our service providers:

ProviderWhat they do
SupabaseSign-in, the database, and file storage
ExpoApp delivery and updates, and push notification delivery
PostHogProduct analytics
SentryError reporting
RevenueCatSubscription status
CloudflareWebsite delivery, and receiving email sent to openset.fit addresses
ResendSending email from openset.fit, such as sign-in codes and replies to support requests
GoogleHosting the mailbox where copies of support, report, and privacy emails arrive
AppleApp distribution, push notifications, and subscription payments, under Apple's own terms

Other providers' policies don't replace our responsibility for the information we give them.

8. No selling and no advertising

We do not sell personal information, including consumer health data, and we do not share it for cross-context behavioral advertising. We don't give it to data brokers, insurers, or employers for their own purposes, and there is no advertising in OpenSet. This covers what OpenSet does; if you share something publicly, anyone who can see it, including an employer, might.

9. How long we keep information

InformationHow long we keep it
Account, profile, training, and social contentWhile your account exists. Deleted from our live systems when you delete your account.
Photos and uploaded filesDeleted when you delete the post, workout, or account, or replace the photo. A delivery cache may serve a copy for up to about an hour.
Direct messagesWhile the conversation exists. Deleted when you or the other person deletes their account.
Deleted messagesA copy kept up to 90 days for investigating reports, then deleted.
Import filesDeleted once your import is finished, rejected, or withdrawn, and in any case within 30 days. We keep only a blank template of the file's layout, with none of your information.
Reports and moderation records1 year after the report is resolved.
Blocks and mutesWhile they're in place. Removed when you undo them or delete your account.
Push notification tokensUntil you sign out on that device or delete your account.
Analytics events (PostHog)Up to 1 year.
Error reports (Sentry)Up to 30 days.
Support and privacy emailsUp to 2 years.
Subscription recordsWe keep your subscription status while your account exists. Apple and RevenueCat keep purchase records under their own terms.
Our database backupsDeleted after 30 days. Our database host may keep short-term system backups for recovery on its own schedule.

Analytics events and error reports are not deleted immediately when you delete your account; they expire on the schedule above. Email privacy@openset.fit if you want them removed sooner.

Groups and custom exercises you created stay available to other members after you delete your account, without your name attached. A group name or description could still identify you; tell us and we'll review it.

Copies other people have made are outside our control.

10. Your choices and privacy requests

In the app you can control your surname display, who sees each post or workout, the Discover switch, live visibility, who can message you, blocks and mutes, and notifications. You can't change or delete every field in Settings, and some changes have limits, such as one name change every 30 days. Contact us if you need something the app doesn't offer.

To ask for a copy of your data, a correction, or deletion, email privacy@openset.fit. You don't need a Premium subscription; Premium's CSV export is a convenience, not the only way to get your data. Depending on where you live, you may also have the right to a portable copy, to withdraw consent, to know who we've shared data with, to limit certain uses, and to appeal a refusal. Nothing in this policy limits your rights under the law.

We verify requests in proportion to what's being asked, and we may ask for what we need to confirm it's you or that someone is authorized to act for you; we won't ask for unnecessary sensitive documents. We respond within the deadlines the law sets, explain any extension, and give reasons if we refuse. Requests are free. To appeal a decision, email privacy@openset.fit with "Privacy appeal" in the subject; we'll explain the outcome and, where one exists, how to complain to a regulator.

We won't treat you differently for using your privacy rights. If you remove information a feature needs, that feature may stop working, and we'll tell you if so.

You can delete your account in Settings. It can't be undone and removes your conversations as described above. Deleting your account doesn't cancel an Apple subscription; cancel it in your Apple account settings.

11. Age requirement

OpenSet is for adults. You must be 18 or older to create an account, and we do not knowingly collect personal information from anyone under 18. We don't ask for a date of birth. If we learn that an account belongs to someone under 18, we close it and delete its information. Email privacy@openset.fit if you believe someone under 18 is using OpenSet.

12. Community Starter accounts

OpenSet runs some accounts itself to start conversation in new or quiet gym communities. They post automatically, and every one is labeled Community Starter on its cards and profile, so they're never presented as independent members. Some of them post less as a group's real members become more active; that adjustment uses counts of activity, not what anyone wrote.

13. Security and where information is processed

We protect information with access controls in our database that limit each person to what they're allowed to see, encrypted connections between the app and our services, and secure storage of your sign-in on your phone. No system is perfectly secure. If a security incident requires notice, we notify affected people and authorities as the law requires.

We operate from the United States. Our service providers process information where they run their services, which may include places outside the United States.

14. Changes to this policy

When we update this policy, we post the new version here with a new effective date. For significant changes, we give clear notice in the app before they take effect, and we ask for your consent where the law requires it.

15. Contact

M3E Brands LLC
1755 North Pebblecreek Parkway, #1239
Goodyear, AZ 85395
United States

OpenSet is a training log and community, not medical advice, diagnosis, or treatment. Our Terms of Use cover fitness risks, subscriptions, content rules, and other terms of the service. Neither document takes away privacy rights the law gives you.