Privacy
The video stays on the phone.
The daily check uses your camera for about 15 seconds. The page samples frames in the browser. It passes if it sees a person or if the frames change enough to count as movement. A person means body landmarks from an on-device pose model when that model loads from a public CDN, or a face when your browser has the FaceDetector API. That face API is a Chromium feature. It is not in every browser.
The check does not count reps. It does not name an exercise. It does not recognize food. It does not read your writing. It does not identify you, and it does not store your location. If the pose is only partly visible, the day can still pass. With the coach, that result repeats tomorrow's task. Without the coach, nothing about tomorrow changes.
If the browser blocks the camera, you get a video file input. That is the backup. The file is played and sampled on the phone. It is not uploaded. You can delete it after.
The server receives a verdict only: pass or fail, a short reason, the duration, a motion score, whether a pose was seen, the lane, and the date. A pass is stored on the contract. A fail is not stored, so you can try again the same day. The contract record holds the lane, the length, the daily amount, the start date, the timezone, whether the coach is on, a short day log, and the refund id once a refund is sent. Paid contracts live on the Stripe PaymentIntent. Owner contracts live in a signed cookie on your browser.
The work timer runs on the page. It pauses when the tab is hidden. It does not record the screen.