← cave

cave — Privacy Policy

Last updated: 1 September 2026

cave is a training coach. This policy explains exactly what it collects, where that goes, and what you can do about it. It is written to be checkable against the app's behaviour rather than to sound reassuring.

Who we are. Abdullah Ahmed ("we", "us"), an individual developer based in Egypt. cave is operated from Egypt; your data is stored in the United Kingdom (see §3). Contact: abdullah@getcave.app.

Who publishes it. cave is distributed on the App Store through the Apple Developer account of Yaseen Ahmed, so that is the seller name shown on the App Store listing. That account is the publisher only: it has no access to your data, and everything described in this policy is done by, and answerable to, the operator named above.


1. Your account

cave asks you to sign in before anything else, with Sign in with Apple. It is the only way in: cave is an iPhone app, so you already have an Apple ID, and a second provider would mean sending your sign-in through one more company for no benefit to you. There is no cave password: you never create one, and we never see the one you use with Apple.

The account exists for one reason. Your plan, your logs and everything the coach has learned about you are attached to it rather than to the handset, so a new phone, a reinstall or a mis-tap on Delete App does not end your training history. Signing back in anywhere brings it with you.

What the provider tells us when you sign in

We do not ask Apple for your name, your profile photo, your contacts, or anything else, and we never receive your Apple password.

Signing out is not deleting. Me → Settings → Sign out leaves your data with us so you can sign back in and pick it up. Delete my data is the one that erases it — see §6.

2. What cave collects

When you sign in

Things you tell it, to build your plan

Things cave records as you train

Things you import, if you choose to

Things your device provides

Notifications: cave does not send them cave sends you no notifications of any kind. There are no push notifications from a server, and no local reminders scheduled on your device either. The app requests no notification permission and keeps no notification schedule. If a pre-release build had already queued a reminder on your phone, it is cancelled the first time you open this version.

What cave does NOT collect

3. Where it goes

On your device

Your plan, memories, chat history, imported documents, and app settings are stored locally. Chat transcripts and imported documents never leave your device except as described in §3.3.

Our server (Supabase)

Your profile, training plan, workout logs, exercise sets, and approved memories sync to a Postgres database hosted by Supabase (London, United Kingdom). Every table is protected by row-level security keyed to your account: one user's rows cannot be read by another. We do not run analytics over this data.

If you are in the EU, storage in the UK is covered by the European Commission's adequacy decision for the United Kingdom, so no further transfer safeguard is needed for it. The transfer that does need your consent is the one to the coaching model, described next.

The coaching model

When you ask the coach something, cave sends your message plus the context needed to answer it to a large language model through OpenRouter, which routes it to DeepSeek (deepseek-v4-flash), or to OpenAI (gpt-4.1-mini) if the first is unavailable.

That context includes: your name if you gave one, your goal, your current training week, your approved memories (including self-reported injuries and constraints), a summary of recent sessions, and — if you have imported documents — excerpts from them.

Two things about this you should know:

Our own proxy passes these requests through and stores none of them. We keep no log of your conversations on our servers.

Apple

4. Why we are allowed to do this (UK/EU users)

Where UK or EU data protection law applies, our lawful bases are:

PurposeBasis
Creating and holding your account so your training survives the devicePerformance of a contract
Running the app you asked for — building and adapting your planPerformance of a contract
Sending your context to the coaching model to answer youPerformance of a contract
Keeping the service working and preventing abuse (rate limits)Legitimate interests
Processing health-related information you tell us — injuries, physical limitsYour explicit consent, given when you enter it
Sending your context outside the UK/EEA to the coaching model (see §3)Your explicit consent, given by choosing to use the coach

You can withdraw consent for health-related information at any time by deleting those entries under Me → Memory, or by deleting your data. Withdrawing does not affect processing already carried out.

5. Health information

Some of what you tell cave — an injury, a joint that hurts, a limit a clinician gave you — is information about your health. We treat it as sensitive:

Residents of Washington State, Nevada, and Connecticut have specific rights over consumer health data. See §9.

6. How long we keep it

We keep your data until you delete it. There is no automatic expiry, except:

Delete my data (Me → Settings) deletes your rows from every table we hold them in — profile, workout logs, exercise logs and sets, memories, plans, plan snapshots, win days, entitlement, and rate-limit records — and clears everything stored locally on the device. It is immediate and irreversible. Sign out, next to it, does none of that: it releases the device and leaves your data with us until you come back.

7. Security

Data in transit is encrypted with TLS. Data at rest is encrypted by Supabase. Access is restricted by row-level security tied to your account, so no other user of cave can read your rows. We hold no passwords: you never create one for cave, and the one you use with Apple is never sent to us. No system is perfectly secure, and we do not claim otherwise.

8. Children

cave is not intended for anyone under 18, and we do not knowingly collect data from them. If you believe a child has provided us data, contact abdullah@getcave.app and we will delete it.

9. Your rights

Wherever you are, you can see everything cave remembers about you (Me → Memory), correct or delete any of it, and erase everything (Me → Settings → Delete my data).

Depending on where you live you may also have the right to access a copy of your data, to object to or restrict processing, to portability, and to complain to a regulator — in the UK, the Information Commissioner's Office; in the EU, your national authority.

California. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use it for cross-context behavioural advertising. Exercising your rights will never get you worse service.

Egypt. cave is operated from Egypt, and Law No. 151 of 2020 on the Protection of Personal Data may apply to that processing. Under it you can ask what we hold about you, have it corrected, and have it erased. The fastest route to all three is inside the app — Me → Memory shows and edits everything cave remembers, and Me → Settings → Delete my data erases the lot — because neither needs us to identify you first.

Washington, Nevada, Connecticut. Where the My Health My Data Act or equivalent applies, the health-related information described in §5 is consumer health data. We collect it only with your consent, use it only to provide the app, and do not sell it. To exercise a right or withdraw consent, use Delete my data or contact abdullah@getcave.app.

To make a request, email abdullah@getcave.app from the address attached to your account, which is how we identify you. If you signed in with Apple and chose Hide My Email, write from the relay address Apple gave you — it reaches us and it matches your account. If the provider gave us no address at all, we have no way to connect an email to your rows, and the complete route is Me → Settings → Delete my data inside the app, which needs no verification because it acts from the signed-in device itself.

10. Changes

If we change what we collect or who we send it to, we will update this policy and its date, and show a notice in the app before the change takes effect.

11. Contact

Abdullah Ahmed · abdullah@getcave.app

The current version of this policy is published at <https://getcave.app/privacy>, and the same text is bundled inside the app under Me → Settings → Privacy Policy. They are rendered from one source, so if the two ever disagree, that is a bug worth reporting.