Last updated 3 August 2026
Privacy, with the boundaries made visible.
Training Compass uses a small amount of account and training context to provide one plan at a time. This policy explains what crosses the service, what is kept, and when access ends.
What your iPhone sends
The App prepares a canonical packet from the context you authorize. The service forwards those bytes for generation. The canonical packet is not stored or retained. The Planner Prompt is not stored or retained.
Application logs, traces, and exceptions exclude the packet, Prompt, complete Result, health facts, credentials, tokens, and raw request or response bodies.
Your temporary Result
A completed plan is held in a temporary Result mailbox so the App can reconnect and retrieve it. Access ends at the next midnight in the time zone captured for the request. Daily physical cleanup removes expired mailbox data from the primary database; cleanup timing never extends access.
If the App accepts the Result, the plan is stored locally on your device. The service is not a prescription-history archive.
Non-content service records
A non-content Generation ledger is retained for 90 days for allowance, reliability, and audit purposes. It may contain identifiers, timestamps, lifecycle states, route identity, byte counts, digests, and structured error codes. It does not contain canonical input, Prompts, complete Results, or health facts.
Database and backup retention
Neon protects the primary database and managed encrypted backups with its platform security and retention controls. Logical expiry makes a record unavailable through Training Compass immediately, even when encrypted backup copies may remain for the provider's managed backup-retention period.
Upstream AI handling
Generation travels through Vercel AI Gateway to the selected AI provider. Those upstream services may process or retain request and response content under their own terms and operational policies. Training Compass requests no training where the selected route supports it, but we do not promise zero data retention (ZDR).
Account information
Sign in with Apple supplies a provider-qualified subject used to identify your account. Training Compass stores neither your Apple name nor email address. The Apple refresh token is encrypted, and usable service-session tokens are never stored in plaintext.
Deleting your account removes its account, session, consent, ticket, mailbox, and ledger data from the primary service store after an Apple revocation attempt. Managed backup retention can still apply as described above.
Questions
Internal testers can send privacy questions through the contact channel used for their TestFlight invitation.