Skip to content
STRENQO
Explore the app⌄
TrainingWeekly plans, strength sessions, cardio and sport. Every set has a place.↗Recovery & sleepSleep, recovery and strain, with context from the data you choose to connect.↗NutritionFood search, barcodes, photo estimates, meal plans, macros and hydration.↗ProgressPersonal records, body check-ins and trends across training and nutrition.↗CommunityA training feed, follows, compliments, teams and voluntary leaderboards.↗IntelligenceAn AI assistant inside STRENQO, grounded in your available fitness context.↗
Devices & connectionsFree & Pro
AboutSupportLegal centre
EN ⌄
  • English✓
  • Italiano
  • Français
  • Deutsch
  • Español
  • Português
  • Nederlands
  • 中文
Launching October 2026↗
本文件目前提供英语和意大利语版本。下方为最新英语正文。 Italiano
← Legal centre

Privacy policy

What STRENQO collects, why it is used, where it goes and how to exercise your choices.

Updated: 2026-09-15Version for the planned October 2026 release
On this page
1. Who is responsible2. Information and sources3. Why information is used4. Health, AI and sharing controls5. Providers and overseas processing6. Retention and deletionNotifications and background informationAI photos and shared illustrations7. Access, correction, export and complaints8. Automated processing and AI9. Age and younger users10. Security and policy changes
Contact us↗

1. Who is responsible

STRENQO is operated by Andreas Mondo in Australia. He is responsible for personal information handled for the service and is the controller where the GDPR applies. Andreas Mondo, ABN 40 907 562 679. Postal correspondence: GPO Box 320, Sydney NSW 2001, Australia. Email: strenqo-support@strenqo.eu.

This policy covers the app, its connected services and this website. Australian privacy protections form the primary framework. Additional rights in the place where you live continue to apply; moving the operator to Australia does not remove those rights.

2. Information and sources

We receive information you enter, information from connections you authorise, and technical information produced when the service runs. Depending on the features you use, this includes:

  • Account and profile: email, account identifier, sign-in provider, credentials handled by the authentication service, profile image, goals, preferences, country, language, units, subscription status and age-verification information. Age checks can include date of birth and a minimised proof containing birth year, a user-bound hash, country, threshold and acceptance time.
  • Training and body: plans, exercises, sets, repetitions, load, timers, completed sessions, perceived intensity, weight, body measurements, optional body photos and notes.
  • Nutrition: meals, food queries and barcodes, photos you submit, portion sizes, recipes, calorie and macro targets, water, dietary preferences, allergies or intolerances you disclose, and supplement schedules.
  • Health and devices: authorised heart rate, HRV, intervals between heartbeats and Night HRV recordings, resting heart rate, sleep and stages, steps, distance, energy, oxygen saturation, temperature and supported body measurements, menstrual flow and inferred cycle context where available. Availability varies by device, platform and permission. We also process derived scores, source identifiers, timestamps and time-zone information.
  • Location: outdoor route coordinates when you use GPS recording, including while an active outdoor session continues in the background. Optional GPS clipping hides route endpoints in supported displays and exports; it does not erase the underlying stored route.
  • AI: messages, selected files or photos, relevant fitness context, generated results and memory preferences or summaries where enabled.
  • Community: participation consent, handle, profile visibility, follow relationships, team roles and membership, invitations, chosen posts and aggregate metrics, compliments, reports and blocks.
  • Creator codes and existing rewards records: code claims, offer eligibility, referral or purchase references and, for existing creator programme participants, application and verification records, campaign submissions, payout account references, ledger entries and security/review signals. A payout provider may collect identity and bank details directly.
  • Operations: device and app version, push tokens, connection tokens, network and server logs, security events, support correspondence, requests and consent records. The website host receives ordinary request information such as IP address, time and requested resource.

3. Why information is used

Information is used to provide the features you request, keep your account and devices in sync, maintain security, manage purchases, respond to support and rights requests, and meet legal obligations. We do not sell personal information or use health data for advertising.

UseRelevant basis where the GDPR applies
Account, saved plans, requested features and billingPerformance of the contract; health information also requires an Article 9 condition, normally explicit consent.
Optional health connections and AI processing of sensitive contextSpecific consent and, for special-category data, explicit consent; an OS permission alone does not replace every legal consent requirement.
Voluntary public posts and shared fitness aggregatesYour requested Community participation and sharing choices; explicit consent where special-category data is involved.
Security and abuse preventionLegitimate interests in protecting users and the service, balanced against their rights.
Records required by law and regulatory requestsCompliance with a legal obligation.

4. Health, AI and sharing controls

Health connections are optional. Choose categories in Apple Health or Health Connect and connect or disconnect supported cloud accounts in Settings. Imported or derived information used for saved workouts, daily snapshots and trends can be stored in your STRENQO account; health data is not necessarily confined to your phone.

AI data use is controlled separately in Settings. The current app profile initially enables the AI preference; review this setting before using AI features. When it is disabled, Intelligence, AI photo analysis, plan generation and AI-personalised notifications are blocked. Memory has a separate control where available. Disabling a setting stops future use covered by that setting; it does not itself delete previously stored conversations or revoke an already completed request.

Community requires separate acceptance. The initial profile is private, not discoverable and excluded from global leaderboards. You choose supported sharing metrics and posts. Other users can see content according to the audience you select and may copy public content.

You can use this website without creating an account. Account-based features require enough information to identify your account; anonymous use of those features is not practical. Withholding an optional permission prevents the related feature, rather than granting that permission implicitly.

5. Providers and overseas processing

The service-provider register explains the services used and the information involved. Providers include Supabase, Google Gemini, Cloudflare Workers AI, RevenueCat, Resend, Apple, Google, Expo and the wearable or food services relevant to your choices. Some are processors; others act independently for their own platform services.

Operating from Australia does not mean all information is stored in Australia. Processing may involve Australia, the European Union and the United States, depending on the service and its infrastructure. An overseas recipient must be assessed under applicable Australian requirements; European transfers require a valid Chapter V mechanism, such as applicable contractual safeguards or an adequacy decision. Ask us for the safeguards relevant to your information. This policy does not represent an unverified provider contract or certification as already completed.

6. Retention and deletion

Account records, saved activity, content and preferences are generally kept while needed to provide your account. Delete individual records where supported or request account deletion. Connected-provider tokens are kept while required for the connection; disconnecting does not necessarily delete historical workouts or derived trends already saved.

The configured privacy workflow retains limited audit events for up to 90 days and completed, failed or cancelled privacy requests for up to 30 days. Export confirmation links expire after 24 hours and deletion confirmation links after one hour. Unfinished requests may remain while being resolved. These periods are distinct from legally required purchase, dispute or fraud records.

Deleted information may remain temporarily in restricted backups until overwritten under the hosting provider’s retention cycle. Provider-side logs and store transaction records follow their applicable retention rules. We do not promise instant erasure from every backup or every independent provider.

Notifications and background information

Server notifications pass through Expo Push Service and the Apple/Google delivery services. Tokens, title/body and data payload may include personalised fitness or briefing context. Manage notifications in Settings and the operating system, including what appears on a lock screen. Disabling AI does not by itself revoke all non-AI reminders.

Bluetooth/Night HRV may process intervals between heartbeats, and supported recovery functions can use cycle-related context. These remain sensitive wellness information. Background location is associated with an active outdoor session; GPS clipping affects supported displays/exports, not the stored source route.

AI photos and shared illustrations

Cloudflare Workers AI processes selected image/document requests, while Gemini handles Intelligence and relevant text stages. Meal and exercise illustration generation sends descriptive text; generated output may be cached and reused across accounts. Free-text labels may still contain personal information, so omitting an account ID does not prove anonymisation. See the photo and AI-image notice.

Generic non-personal artwork may remain in the shared catalogue after account deletion. Personal source files and records follow the normal deletion rules; no shared-cache exception permits unlawful retention of identifiable information.

7. Access, correction, export and complaints

Open Settings → Privacy, data and support for the supported data export and support controls. Account exports contain supported data sections; they may not include every conversation or the binary contents of every attachment. Contact us for access to additional personal information, including AI conversations, or for help obtaining files.

You may request access and correction, withdraw consent and seek deletion. Depending on your region you may also have rights to portability, restriction, objection or review of certain automated decisions. See account deletion and the regional notices. We verify identity proportionately and do not ask for your password or tax file number.

Send requests or complaints to strenqo-support@strenqo.eu or our postal address. We aim to respond within 30 days; GDPR requests are answered without undue delay and normally within one calendar month, with any permitted extension explained. Where Australian law applies, you can complain to the OAIC after first giving us a reasonable opportunity to respond. You can also contact your local privacy regulator.

8. Automated processing and AI

STRENQO calculates fitness estimates and trends and uses AI for replies, plans, photo estimates and briefings. These features support personal fitness decisions; they are not intended to make decisions about employment, insurance, credit, healthcare eligibility or legal rights. Subscription access, rate limits and security controls also use automated rules. Contact us to challenge an incorrect account restriction or result. See AI transparency.

9. Age and younger users

The current app applies these product sign-up thresholds: Australia 15; EU/EEA and Switzerland 16; UK, US and Canada 13; other or unknown countries 16. These are product rules, not a statement that each country has a universal legal age for every activity. Additional consent, consumer and online-safety requirements may apply. Parents or guardians can contact us about a child’s information or deletion.

10. Security and policy changes

The service uses access controls, encrypted transport and security checks appropriate to its functions. No service can guarantee complete security. Security incidents are assessed and notified to affected people and authorities when required by applicable law, including the Australian Notifiable Data Breaches scheme where applicable.

Material changes will be communicated through appropriate in-app or direct notices where required. A revised policy does not retroactively create consent for a new purpose. The date above identifies this document version.

← Legal centreBack to top ↑
STRENQO

The fitness app for training, nutrition, recovery and progress. With Intelligence inside.

Explore the app

TrainingRecovery & sleepNutritionProgressCommunityIntelligence

Support

Devices & connectionsFree & ProAboutContact usLegal centrePrivacy & dataConsumer health data privacy

Postal contact

Andreas Mondo
ABN 40 907 562 679

GPO Box 320
Sydney NSW 2001
Australia

strenqo-support@strenqo.eu
© 2026 Andreas Mondo. All rights reserved.Coming to iOS and Android · October 2026