Privacy Policy
Last updated: September 21, 2026
Often is operated by Brian Alexander Perez, an individual based in Jacksonville, Florida, United States (“Often,” “we,” “our,” or “us”). This policy explains how we handle information in the Often app, its account and sharing services, and our websites.
Information we collect
Accounts. We process your email address, password and authentication information, account identifier, display name, username, and any profile photo you choose to provide. Your display name does not need to be your legal name.
Workouts and other content. Often stores the workout plans, templates, exercise settings, sets, repetitions, history, progress entries, body-weight entries, goals, notes, and photos you provide. It also records information generated by your use of workout features, such as session times, duration, and completion history. Some content stays on your device; content included in cloud backup is also stored on our backend.
Apple Health and Apple Watch. With the permissions you grant, supported features read and record workout information, including heart-rate summaries and active energy burned. Summaries saved in your Often history may also be included in cloud backups. You can change permissions in Apple's settings. Withdrawing permission stops the related access but does not erase information already saved in Often or Apple Health.
Support. We receive messages and attachments you send to dev@often.so or privacy@often.so. Please include only information needed for your request.
Technical information. Our infrastructure providers process request information such as timestamps, request paths, results, IP addresses, approximate location derived from IP addresses, browser or device information, and account identifiers for signed-in requests. Our email provider processes recipient addresses, message content, and delivery information for account emails.
TestFlight. The app does not include third-party advertising, product-analytics, or crash-reporting SDKs. Apple may provide TestFlight diagnostics and feedback under its own settings and terms. Feedback can contain screenshots or other information you submit.
Our websites and advertising tracking
Our marketing website, often.so, uses Framer's built-in analytics to measure visits. Framer describes this analytics service as cookieless, using a hashing secret that is changed and deleted daily.
The website also uses Meta Pixel. It loads on page visits without a consent prompt, including when we are not running advertising campaigns. It sends website-visit information to Meta, such as pages viewed, event times, IP addresses, browser information, and advertising identifiers, and may set or read cookies. This information supports advertising measurement and audience features. Meta processes information under its own Privacy Policy.
The website currently does not provide an on-site control to disable Meta Pixel. Meta offers ad preferences, and browsers offer cookie and tracking controls, but these do not necessarily stop all information from being sent by our website. A link to this policy is informational; it does not turn tracking off.
The Often app and the workout, plan, and password-reset pages at app.often.so do not include Meta Pixel. We do not send your stored workout, health, account, or profile records to Meta for advertising. Website visits are separate from these app records, although the pages visited may reveal an interest in Often or fitness.
How we use information
We use information to operate and secure accounts; provide workout planning and tracking; save, back up, and restore data; provide public sharing that you choose; send account and security emails; respond to support and privacy requests; and investigate technical problems, misuse, or security incidents. Website-visit information is also used for analytics and the advertising purposes described above.
Account and security messages are separate from promotional emails. Any product-update emails we send require a separate opt-in. Using Often or accepting its Terms does not itself authorize marketing emails or grant Apple Health permissions.
Public links and profile images
Profile privacy and public workout or plan links are separate settings. A private profile can still publish a public link.
When you publish a workout or plan, people with access to the link can view and forward it. The page can show your display name, username, profile photo, workout or plan title, description, exercises, programming details, and publication information. Plans can show schedules and the workout templates they contain, even when those workouts do not have separate public links. Editing published content may update the same link.
Profile photos use publicly accessible image URLs. Someone with the URL can view the image even if your profile is private. Personal workout photos are stored with your workout data and backups; they are not intended for publication through the workout-sharing feature.
Use a link's sharing controls to make it private, and wait for server confirmation. Do not assume deleting a workout or plan locally has immediately removed its public page, especially while offline. Contact dev@often.so with the link if you need help removing a page. Other people may keep screenshots, downloads, or copies outside our control.
Providers and other disclosures
We use these providers:
Supabase for authentication, databases, backup data, and image storage.
Vercel for public workout and plan pages and the password-reset website.
Framer for the marketing website, policy pages, and built-in website analytics.
Meta for website advertising measurement and audience features through Meta Pixel.
Loops for transactional account emails. It receives recipient addresses, message content, and delivery information. These emails may contain account-action links. Loops states that its transactional emails do not use open or click tracking and do not automatically add recipients to a marketing audience.
Google Workspace for our support and privacy email inboxes.
We do not exchange your app records for payment or use your stored health or workout records for advertising. Meta Pixel does disclose website-visit information for advertising-related purposes; describing our app records separately does not mean the website has no advertising-related sharing.
We may disclose information where required by applicable law or where permitted and necessary to protect users, investigate misuse, secure the service, or address legal claims. These disclosures remain subject to applicable protections for personal and health information.
Storage, retention, and security
Our backend database and file storage are located in the United States. Website delivery and provider operations may involve other locations. We use authentication and access controls to restrict private account data. Public pages and image URLs are exceptions described above. No system can guarantee complete security.
Current backups. We retain your current cloud backup to provide backup and restore until it is replaced or removed through account deletion. It does not automatically expire because you stop using Often. Deleting content on your device updates the current cloud backup only after a successful upload; if your device remains offline or stops backing up, the previous cloud copy can remain.
Backup history. We keep up to forty previous backup versions. The newest eight may remain regardless of age. Additional versions are thinned into daily, weekly, and monthly groups across progressively older periods, extending to approximately 280 days. A scheduled cleanup applies these rules even when a user is inactive. The 280-day period is not a universal expiry for the newest eight versions. Deleted content may remain in older versions, and restoring a version can bring that content back.
Temporary recovery copies. Temporary recovery copies created during system upgrades expire after 30 days and are automatically deleted within the following 24 hours. If you delete your account sooner, we remove your data from these recovery copies as part of account deletion.
Provider records. Our Supabase Free plan provides access to one day of backend logs, and our Vercel Hobby plan provides one hour of runtime logs. These plan windows do not establish a deletion deadline for every security, operational, or other record held by those providers. Email content, delivery records, and other provider-held information are handled under the relevant provider's retention practices and contractual obligations. We do not promise a fixed expiry period for Loops delivery logs.
Messages and deletion records. Support and privacy messages remain in our Google Workspace inboxes until we delete them; provider recovery mechanisms may retain deleted messages afterward. We have not configured custom Google Workspace retention or Vault rules. We retain account-deletion records containing the former account identifier, relevant timestamps, and limited completion details or counts, without workout content, photos, or email addresses. We have not set an automatic expiry for these deletion records.
Your choices and account deletion
You can manage supported profile settings, health and camera permissions, and public-link access in the app or device settings. Often also offers export and account-deletion features.
Deleting your account removes your sign-in account, profile, current backup, backup history, public workout and plan pages, and your rows in temporary recovery copies. Uploaded profile images, including replaced images, are queued for removal from storage. Images are normally removed within about ten minutes; failures are retried, with delays that can reach daily attempts. Cached copies may remain available briefly after removal.
The app clears its local workout data and related files on the device where you delete your account. Copies you exported or saved elsewhere are not removed. Other signed-in devices may retain local data. When they reconnect and their session is rejected, they lose account access; this can take approximately an hour while online. Account deletion does not remotely erase those local copies. Use the app's erase-data control where accessible, or remove the app from those devices.
Signing out does not delete your account or necessarily erase local data. Removing the app does not delete your cloud account. Revoking Apple Health permission does not delete existing Often or Apple Health records. Account deletion does not automatically erase correspondence or every record held by our providers.
For requests to access, correct, export, or delete information, email privacy@often.so. Brian Alexander Perez monitors that inbox. We may need information sufficient to verify your connection to an account before disclosing or changing its data; please do not send passwords. Depending on applicable law, you may have additional privacy rights, including rights concerning consumer health information. You may contact us at the same address to request review of our response.
Intended audience
Often's account-based service is intended for United States residents aged 18 or older. If you believe a child has provided personal information to Often, contact privacy@often.so. This statement does not mean we independently verify a person's age or identity.
Changes and contact
We will post updates to this policy with an updated date and provide additional notice or obtain consent where required by applicable law.
Operator: Brian Alexander Perez
Location: Jacksonville, Florida, United States
Privacy: privacy@often.so
Support: dev@often.so