Setlist
Privacy policy
Effective 4 October 2026
Setlist is a strength-training log for iPhone, published by Benjamin Gadbaw. This policy describes what Setlist does with your data.
The short version: Setlist works without an account. Without one, your training data stays on your iPhone and in your own iCloud account, and I cannot see it. If you create an account, my server keeps your name, your email address, your program setup answers, a copy of your finished workouts, and a record of how you use Setlist. Body measurements and anything from Apple Health stay on your iPhone either way. Setlist also sends usage counts and crash reports, and you can turn them off.
What Setlist stores
Setlist stores what you put into it:
- Workouts — date, start and end time, title, notes, and every set with weight, reps, distance, duration, RIR, set type and superset grouping.
- Routines and programs — exercise order, prescriptions (sets, rep range, target RIR, rest, tempo), folders and schedules.
- Exercises — the built-in library plus any exercise you add or edit, including your pinned notes.
- Body measurements — body weight, body fat percentage and up to fourteen tape measurements, with dates and notes.
- Preferences — your first name if you enter one, units, training goal, training days per week, rest defaults, bar weight and plate inventory, and colour palette.
Setlist does not ask for your phone number, date of birth, location, contacts, photos or payment details. It has your email address only if you create an account; see “Your account” below. If you invite a trainer, it asks for that person’s name and phone number or email address; see “Sharing with your trainer” below.
Where it is stored
Your workouts, routines, programs and exercises are stored on your iPhone and, if you are signed in to iCloud, in the private database of the app’s iCloud container, which is part of your own iCloud account. That private database is what makes those records appear on your other devices signed in to the same Apple Account. An app’s CloudKit private database is readable only by the Apple Account that owns it. I have no access to it, no console view of it, and no ability to export, restore or delete it on your behalf. Apple operates iCloud and handles that data under Apple’s own privacy policy, not this one.
If you invite a trainer, Setlist also keeps a copy of your workouts, routines and programs in a separate area of your iCloud account that is shared with that one person. See “Sharing with your trainer” below. It is still your iCloud account and your storage; I have no access to it.
Your body measurements are not stored in iCloud. Body weight, body fat percentage and tape measurements are kept on the device where they were recorded, and are not synced to iCloud or anywhere else.
If you are not signed in to iCloud, Setlist keeps everything on the device only, and Settings shows “This device only”.
Your account
Setlist offers an account when you first open it, and in Settings. You can sign in with Apple, with Google, or with a code sent to your email address. An account is optional: “Not now” skips it, and logging, routines, history, sync and Setlist Pro work the same without one.
If you create an account, my server keeps:
- the identifier Apple or Google gives Setlist for your account with them, or the email address you sign in with;
- your email address, which with Sign in with Apple can be a relay address that hides your own, and whether you want email from me about Setlist;
- your name, if Apple or Google shares it or you type it in Setlist;
- your program setup answers: your goal, up to three areas to prioritise, your experience, how many days a week you train and which days are off, how long you train, whether you train at a gym, at home or in a hotel, and how many weeks the program runs; and the kind of program built, for example upper and lower, three days a week, six weeks;
- whether you have Setlist Pro and which kind, and your app version;
- a copy of your finished workouts: each workout’s date and length, title, notes, routine name and program week, and for each exercise its name, muscle group, equipment, notes and every set (set type, weight, reps, RIR, time, distance, and whether it was completed). The copy is updated when you edit or delete a workout, and cleared when you use “Erase all data and start over”;
- how you use Setlist: the same usage events described under “Usage data” below (for example that a workout was finished, how long it ran in broad bands, which tab was opened, that a trial started), each with its time, and when you last used the app. These are kept only while “Share usage data” is on;
- for each iPhone signed in, a session record (the session key itself is stored only in scrambled form) and when it was last used; with Sign in with Apple, a token from Apple that is kept only so it can be revoked when you delete the account.
The areas you ask a program to go easy on are not sent; they stay on your iPhone. Neither are your gym’s name, your routines and programs as templates, body measurements or anything from Apple Health, including heart rate. Signing in with the same email address through Apple, Google or a code reaches the same account.
I use the account to restore your setup on a new iPhone; to understand how Setlist is used and improve it, for example which features people return to and where they stop; to build features on your training such as a web view of your history or connections to other apps; and, only if you turn on “Email me Setlist news”, to email you about Setlist. I do not sell any of it, use it for advertising, or share it with anyone except the processors named below. Your workouts on your iPhone and in iCloud remain the record; the account’s copy does not replace them.
The server runs on Fly.io in the United States. To send a sign-in code, your email address and the code go to Resend, which delivers the email; the code works for 10 minutes and my server keeps it only in scrambled form. With Sign in with Apple or Google, those companies handle your sign-in under their own privacy policies.
Settings, Account, “Download account data” gives you a copy of everything the account holds, including the workout copy and usage record. “Delete account” removes all of it from my server straight away, with no retention period, and tells Apple to stop Setlist’s access to your Apple Account. Your workouts stay on your iPhone and in your iCloud. If you signed in with Apple, you can also stop it from iOS Settings, your name, Sign in with Apple; my server then removes that sign-in, and the account with it when it has no other way in.
Apple Health
Setlist uses Apple Health in two directions, each behind its own switch in Settings, each off until you turn it on, and each asked for separately by iOS.
Reading. Setlist can read body mass (body weight), body fat percentage, heart rate, heart rate variability, resting heart rate, sleep, and workouts with their active energy. Nothing else.
Writing. Setlist can save a workout you have finished as a strength-training session, so it appears in Fitness alongside everything else. That session carries its start and end time, its title, how many working sets and exercises it had, its total volume, and the routine it came from. If you leave the energy estimate switched on it also carries an estimated active-energy figure, calculated from the session’s length, its working sets and your body weight. That figure is a calculation, not a measurement, and Setlist writes none at all if it has no body weight on file.
Setlist on Apple Watch. The watch app asks for the watch’s own Health permission. While a workout you started on your iPhone is in progress, the watch runs a strength-training workout session, so it measures your heart rate and active energy throughout and shows your current heart rate on the watch. When you finish the workout on your iPhone, the watch saves it to Apple Health with the heart rate and active energy it measured, and your iPhone does not save a second copy. If you discard the workout, the watch saves nothing. The watch keeps no copy of your workouts: it shows what your iPhone sends it over the direct connection between the two, and sends back only the sets you log.
- Setlist never writes your body measurements. Body weight, body fat and tape measurements are read only, in one direction, always. The only thing Setlist writes to Apple Health is a workout you finished.
- Those are the only health data Setlist reads. It does not read steps, nutrition, menstrual or reproductive health, clinical records, or anything else in Health.
- What Setlist does with them: it files each weight and body fat reading against a date in the Body tab and charts it alongside anything you typed in yourself. It shows your average and peak heart rate for a workout you logged. When it suggests a workout, it reads last night’s sleep, heart rate variability and resting heart rate, and after a short night or a strained morning it suggests one set fewer on each exercise. When a watch recorded a strength workout at the same time as a workout you logged, it shows the watch’s time and active energy, and does not save a second copy of that workout to Health. Heart rate, heart rate variability, resting heart rate, sleep and workouts are read when the screen opens and are not saved in Setlist. Nothing else.
- Health data read from Apple Health is never used for advertising, marketing or use-based data mining, and is never sold, shared or disclosed to any third party.
- Health data read from Apple Health stays on the device that read it. It is not copied to iCloud and is not transmitted anywhere.
- You can turn either direction off at any time in Setlist’s Settings, or revoke them in the Health app under Profile, Apps, Setlist. Turning reading off stops all further reading; readings already filed into the Body tab stay until you delete them. Turning writing off stops all further writing; sessions already in Health stay until you delete them, either in Health or by deleting the workout in Setlist, which removes the Health copy with it.
Sharing with your trainer
Setlist can share your training with one trainer you choose. Nothing is shared until you invite someone, and you can stop at any time.
Inviting. You type your trainer’s name and phone number or email address. Setlist gives the phone number or email address to Apple’s iCloud only to find the Apple Account it belongs to; the invitation works for that account alone. Setlist then opens Messages or Mail with the invitation, and you send it. I do not receive the name, number or address.
What your trainer sees. Your name as you entered it in Setlist, your units and training goal, your workouts (exercises, sets, weight, reps, RIR, notes), and your routines and programs. If you choose “Share only from today on”, workouts before that day are not shared.
What your trainer does not see. Your body weight, body fat and measurements, and anything from Apple Health. These are never placed in iCloud. If you tap “Send body stats”, Setlist creates a small file and opens Messages so you can send it yourself; your trainer’s copy of Setlist keeps it on their phone only. Once sent, that file is outside Setlist’s control, like an exported CSV.
What your trainer can do. Send you routines and programs, which you can add, change or ignore. Your trainer cannot change or delete anything you have logged.
Stopping. In Setlist, Your trainer, “Stop sharing”. Your trainer loses access the next time their Setlist syncs, and their copy of your training is deleted from their phone. Routines and programs they sent you stay yours. Body stats files you sent by Messages stay wherever Messages put them.
If you are the trainer. Your clients’ training is shown to you from their iCloud accounts and cached on your phone, not in your own iCloud. You can leave a client at any time. Treat what your clients share with you with the care your profession expects; how you use it is between you and them.
Sharing a routine by link
“Share routine” and “Share program” make a link to gadbaw.com/setlist/r that carries the routine inside the link itself: its name, your first name if you set one, an optional note, and each exercise with its sets, reps, RIR, rest, tempo and notes. It never carries your workout history, weights, dates, body data or contact details. The routine sits after the “#” in the link, a part that browsers do not send to any server, so it is not seen by me or by the site’s host. The page reads it in the recipient’s browser and makes no requests of its own. Anyone you send the link to can open it, and can pass it on.
Inviting a friend
“Invite friends” makes an invite code for you and a link to gadbaw.com/setlist/i that carries the code and your first name if you set one. Like a shared routine, they sit after the “#” in the link, so they are not sent to me or to the site’s host.
To count the friends who join, Setlist keeps two small records in the public database of the app’s iCloud container. Unlike your private database, I can read that one. The records are: your invite, which holds the code; and, if you accept a friend’s invite, your acceptance, which holds their code, the date you accepted and the date you finished your first workout afterwards. iCloud attaches to each record an identifier for the Apple Account that made it. It is a string of letters and digits that is used only by Setlist, and I have no means of turning it into a name, an email address or a person. The records hold no name, no contact detail and nothing about your training. The months of Setlist Pro you have earned are kept in your private database, which I cannot read.
A friend’s free first month is an App Store offer. Apple handles it as it handles any subscription, and tells Setlist only that the subscription is active.
You can delete both records at any time: Invite friends, then “Remove my invite records from iCloud”. Links you have sent stop working when you do.
Sharing a workout as an image
“Share workout” draws an image of one finished workout on your iPhone: its name, date, length, total weight lifted, number of sets, how many personal records it set, and up to three exercises with their best set. It never includes your body weight, body measurements, heart rate or anything else from Apple Health. The image goes only where you send it through the share sheet, with a line of text that links to Setlist on the App Store. I do not receive it. Choosing “Save Image” asks for permission to add it to your photos; Setlist cannot read your photo library.
Usage data
Setlist sends anonymous usage counts to TelemetryDeck, an analytics service run by TelemetryDeck GmbH in Augsburg, Germany, so that I can see which features are used and whether people start a trial. If you have an account, the same events are also kept with your account on my server (see “Your account”); TelemetryDeck’s copy stays anonymous. It is on until you turn it off in Setlist’s Settings, “Share usage data”. Turning it off stops all further sending, to both.
Crash and performance reports. With the same switch on, Setlist sends my server the daily reports iOS prepares through Apple’s MetricKit: where the app crashed or hung, how long it took to launch, and how much battery and memory it used, with the app and iOS versions. They are sent with no account, session or other identifier, and the server does not store your IP address, so a report cannot be tied to you.
Ad attribution. If you install Setlist after tapping an ad for it, Apple may send my server a report saying which campaign led to an install. Apple builds these reports to carry no information about you, and Setlist does not ask to track you.
What is sent. That Setlist was opened, and how long it stayed open; and that one of a fixed list of things happened: onboarding finished, and which way into the app was chosen at its end (suggest a workout, bring history from another app, start an empty workout, or look around first); one of Setlist’s four tabs was opened, counted at most once a day for each tab; a Setlist Pro or Setlist for Trainers offer was shown, and which feature led to it; a purchase or trial went through, was cancelled or failed, with the product and a failure code; purchases were restored; how you have Setlist Pro changed (free, trial, subscribed, lifetime and so on); a workout was started, and whether it came from a suggestion, a routine, a program or nothing; a workout was finished, with its length in one of four bands (under 30 minutes, 30 to 60, 60 to 90, over 90), its number of sets in one of five bands (none, 1 to 5, 6 to 15, 16 to 30, over 30), whether it came from a suggestion and whether it was the first finished on that phone; a workout was discarded, with its sets in the same bands; workout history was imported, and from which app (Hevy, Strong, Trainerize or another app), never what was in it; a suggestion was used; the program setup was opened, whether there was a workout log to start from, and which of its screens were reached (goal, areas to prioritise, experience, training days, time, place, areas to go easy on, which lifts, the finished program), never the answers given on them; a gym or a piece of equipment was added; a trainer was invited, a client accepted, or a routine or program sent to a client; the Invite friends screen was opened, and from where; an invite was sent or its code shown; an invite was accepted, from a link or a typed code, or refused, and for which reason; the first-month offer was opened; someone who joined with an invite finished a first workout; a month or Pro for life was earned from invites, never the code or who invited whom; a share link was opened; an image of a workout was shared, with its size (story or square) and background (light, dark or clear), never what was on it. With each one, TelemetryDeck’s software adds details of the phone and the app: iPhone model, iOS version, app version, language, region, time zone, the day and hour, and accessibility settings such as text size; and counts it keeps on the phone: how many times and on how many days Setlist has been opened, the date of the first time, and how long it usually stays open.
What is never sent. Your workouts, exercises, weights, reps and notes; your routines and programs; your body measurements; anything from Apple Health; your name or your trainer’s; contact details; prices, receipts or your Apple Account; anything about your Setlist account. Setlist sets no user identifier of its own. TelemetryDeck’s software makes a random identifier for this installation and sends only a hash of it, which TelemetryDeck hashes again when it arrives, so neither TelemetryDeck nor I can connect it to you. TelemetryDeck does not store IP addresses. The data is held on TelemetryDeck’s servers in Germany and the Netherlands under TelemetryDeck’s privacy policy. Test builds mark what they send as test data.
What is not collected
- No session recording. Beyond the usage events, crash reports and, with an account, the workout copy described above, nothing about how you use Setlist leaves your phone.
- No advertising and no advertising identifiers. Setlist does not track you and does not use the App Tracking Transparency framework, because there is nothing to ask you about.
- Two third-party libraries. ZIPFoundation reads zip archives you choose to import; it runs on your device and sends nothing anywhere. TelemetryDeck’s open-source software sends the usage counts above and nothing else.
- No passwords. An account, if you create one, signs in with Apple, Google or an emailed code. Invites are counted through your iCloud account, as described under “Inviting a friend”.
- Apart from the usage data, crash reports and the account described above, Setlist makes no network requests of its own. The only other network traffic it causes is iCloud synchronisation, sharing and invites, which iOS performs; purchases, which the App Store handles; and opening a YouTube search if you tap “Watch a demo on YouTube” on an exercise, at which point you have left Setlist and YouTube’s own terms and privacy policy apply.
Sharing and selling
Nothing is sold. Setlist has no partners and no affiliates. Its processors are TelemetryDeck, for the anonymous usage counts above; Fly.io, which hosts the account server, the workout copy, usage record and crash reports; and Resend, which delivers sign-in codes. Otherwise the only sharing is the sharing you start yourself: inviting a trainer or sharing a routine (see above), exporting a CSV, or sending body stats.
Apart from those processors, no data is disclosed to a third party except where you deliberately send it yourself. An exported CSV or a body stats file goes wherever you choose to send it, and is then outside Setlist’s control.
Your trainer is a person you choose, not a partner of mine, and receives your data only because you shared it. If Setlist ever shares data with anyone else, this policy will be updated before the change ships, and the change will be described in the app’s release notes.
Purchases
Setlist and the Setlist for Trainers subscription are sold through the App Store. Apple handles payment; I never see your payment details. Setlist checks on your iPhone whether a subscription is active. The usage counts above say which product was bought and whether a trial started, never a price, a receipt or who you are. Manage or cancel a subscription in iOS Settings, your name, Subscriptions.
Files you import
When you import a CSV or zip export from another app, Setlist reads it on your device and writes the contents into its own store. The original file is not copied elsewhere, not uploaded, and not retained by Setlist after the import. If you placed the file in Setlist’s folder in the Files app, it stays there until you remove it.
Retention and deletion
Setlist keeps your data until you delete it. Without an account, your training data has no copy on my side. The account, if you create one, stays with its workout copy and usage record until you delete it, and the two invite records described under “Inviting a friend” stay until you remove them. Crash reports carry nothing that leads back to you and are deleted after 18 months. TelemetryDeck keeps the anonymous usage counts with no fixed deletion date; because they carry nothing that leads back to you, they cannot be picked out and deleted for one person. Turning the switch off stops new ones.
You can delete:
- One item — a workout, routine, exercise or body entry: swipe, or use the item’s menu.
- Everything — Settings, then “Erase all data and start over”. This deletes every workout, routine, program and custom exercise on the device and in your iCloud private database, every body entry on the device, and restores the built-in exercise library. If you share with a trainer, it also removes your training from their copy; sharing stays on until you stop it in Your trainer.
- The app’s whole store — delete Setlist from your iPhone, then remove its iCloud data in iOS Settings, your name, iCloud, Manage Account Storage.
- Your account — Settings, Account, “Delete account”. It is removed from my server straight away; see “Your account”.
“Download account data” in Settings gives you a copy of what the account holds, and Export CSV gives you a copy of your own workouts and body data, at any time.
Your rights
Under the GDPR, the UK GDPR, the CCPA/CPRA and comparable laws you have rights of access, correction, deletion, portability and objection. In Setlist you exercise those rights directly in the app: you already hold, control, correct, export and delete your training data. With an account, Download account data and Delete account in Settings cover access, portability and deletion of everything the account holds, the workout copy and usage record included; turning off “Share usage data” is your objection to the usage record; for anything else, write through the support form. The anonymous counts at TelemetryDeck and the crash reports are not personal data: nothing in them identifies you. I do not sell or share personal information as those terms are defined under the CCPA/CPRA, and Setlist does not use personal information for cross-context behavioural advertising.
Children
Setlist is rated 9+ and contains nothing unsuitable for children, but it is not directed at children. Without an account it collects no personal information; the anonymous usage counts above are the same for everyone and can be turned off. It asks for no age. The account is optional and holds what is described under “Your account”. The other exception is the name and phone number or email address of a trainer you choose to invite.
Security
Data on your iPhone is protected by the device’s own encryption and passcode. Data in the iCloud private database is protected by Apple’s iCloud security, including Advanced Data Protection if you have enabled it on your Apple Account. The account server is reached over HTTPS only, and its disk is encrypted by Fly.io. It holds no passwords; sign-in sessions and codes are stored only in scrambled form. Each account’s workout copy and usage record can be read only with that account’s own session.
Changes
If this policy changes, the revised version will be posted at this address with a new effective date, and material changes will be noted in the app’s release notes. The version in force is the one published here.
The support form
This website has a support page with a contact form. That form is part of the website, not the app, and Setlist itself never sends anything to it.
If you choose to write in, the form collects the email address you type, an optional note of your iOS version and iPhone model, and your message. It is delivered to me by email so that I can reply, and is used for nothing else. It is not added to a mailing list, not used for marketing, and not sold or shared. Submissions are processed by Netlify, which hosts this site, under Netlify’s privacy policy, and I delete correspondence once the matter is closed. Please do not paste your training data or health information into it; I do not need it to answer a question about the app.
Contact
Through the form on the Setlist support page.
Setlist is a training log, not a medical device and not a source of medical advice. Its progression suggestions are fixed arithmetic rules applied to sets you logged yourself. Talk to a doctor before starting or changing a training programme.