Zenith Privacy Policy
Effective October 8, 2026 · Version 2026-10-08
Blooms AI Technologies LLC operates Zenith. Questions and privacy requests can be sent to info@zenith-hrx.com. This policy explains the information Zenith collects, why it is used, who may receive it, and the controls available to you.
Information you provide
We collect your email address, authentication data, optional profile fields such as name, handle, biography, city, gym and race category, and content you choose to create or send. Your posts may contain photos, videos, captions, tagged people, place labels, workouts, comments, or reactions. We also store follows, blocks, membership, saves, reports, messages, and preferences needed to provide the social features.
Training is optional. If you use it, Zenith processes session history, goals, race results, metrics, notes, and optional connected-device or Apple Health data that you explicitly import. With your Health permission and only when you ask, Zenith can read running workouts, walking and running distance, heart rate, resting heart rate, heart-rate variability (SDNN), and sleep records. Available measurements depend on what your watch or another app has written to Apple Health and what you allow Zenith to read. Connected devices may separately provide workouts, resting heart rate, sleep, and HRV measured by a labelled device method. These records can be sensitive. Imported training records save privately on your device. When you import workouts from a connected device through Stridee, Zenith also keeps up to 500 private workout summaries on its servers to prevent duplicate imports and recover interrupted imports. These summaries contain the activity identifier, provider, title, date, duration, distance, average heart rate when available, sport and workout type. They are separate from an account backup. Apple Health records and connected-device wellness readings are not saved in this server import cache. A complete account backup is uploaded only when you choose Save account backup. Imported records are not automatically published. A workout is shared socially only after you choose to publish it for that occasion.
Information generated when you use Zenith
We process account identifiers, device and app-version information, login and security events, network information needed to deliver requests, content review decisions, and diagnostic records. We may infer basic usage patterns to operate and protect the service. We do not use your contacts list to invite friends. A founding invite code links a qualifying signup to the referring account; the referrer sees a count, not the invitee's private account information.
For the Founding500 offer, we check your verified account identity, unique username, adult account setup and the server-owned allocation. A verified website claim uses the same account and can record an eligible Pro reward awaiting approved activation. A separate referral reward requires the disclosed new-member activation and Apple DeviceCheck qualification. When that device-verification capability is authorized and configured, we send Apple's opaque device token to Apple to check the offer's allocated bit. We do not store the raw token in the server database. We retain a token hash, the verification state and an account/request-bound receipt, and keyed hashes of verified identities to detect duplicates. These records are private. DeviceCheck is not required for free social membership or the base email-qualified Founding500 allocation. Unknown provider outcomes are retained for review rather than treated as a successful check.
Why we use information
We use information to authenticate you; show your chosen profile and content to the audiences you select; provide training, messages, notifications and connected-device features; process subscriptions and promotional eligibility; prevent abuse and investigate reports; maintain security and reliability; answer support requests; and comply with legal duties. We use Apple Health information only for the fitness features you request. We do not use it for advertising or marketing. We do not sell personal information or share it for cross-context behavioral advertising in the current app.
Visibility and recipients
Other members can see content you publish to them, subject to your privacy settings, blocks, and Community permissions. A message recipient can see the messages you send. Tagged people receive a request before a photo-position tag becomes public. Authorized safety reviewers may access reported content and associated evidence to resolve a report.
We use service providers to host accounts and databases, process and deliver private media, run permitted safety review and AI or voice features, support connected devices, and process App Store purchases. These currently include Supabase, Cloudflare, Apple, and, only when the relevant feature is active, configured AI, media-safety, transcription, and wearable providers. We limit provider access to the data needed for the feature and require appropriate protections. We may disclose information to authorities when legally required or to address serious safety threats.
AI, health, and place information
Safety screening may process text, images, video, audio, and report context before or after publication. Optional AI coaching or voice features process the request you send and relevant training context. The separate AI Processing Notice gives more detail. Place search uses the query you enter and the place you choose; Zenith does not require continuous location tracking for social membership.
Retention and deletion
We keep an active account, its selected content, private records, and settings while you use the service or until you remove them. Deleting your account removes the active account record and cascades associated content and backups; external media objects are queued for physical deletion. Backups, security records, and report evidence may remain for a limited period when needed for recovery, legal duties, abuse prevention, or dispute handling. We do not retain them to keep an account publicly visible after deletion. A recipient may retain content you previously sent or copied outside Zenith.
Founding Offer identity hashes and private device-check receipts are retained for up to 180 days after account deletion and then removed by scheduled cleanup. They contain no raw email, phone, Apple identity or device token. Apple may retain its DeviceCheck bit independently, including across app reinstall or device erasure. Contact info@zenith-hrx.com to request review of an incorrect eligibility flag; Zenith does not automatically reset a device-wide Apple bit.
Deleting your Zenith account also queues revocation of its connected-device authorizations. Zenith access is withdrawn immediately. If a provider is unavailable, Zenith retains only the account-bound cleanup receipt and identifiers needed to finish revocation, and retries until the provider outcome is confirmed. The deletion confirmation tells you when external cleanup remains pending.
Your choices and rights
Optional launch and community email updates are off by default. If you choose them in Founding status, we use your verified email, account identity and ordinary social activation, such as published posts, follows or discussion participation, to prepare relevant updates. We do not use Apple Health or private training data for marketing. You can withdraw this consent in Founding status at any time. Withdrawal suppresses eligible unsent marketing records; an unknown or already-dispatching provider outcome is retained for review. Verification and essential account messages remain separate. A prepared template or delivery record does not itself send a campaign.
In Settings you can change account privacy, message requests, notification choices where available, and the founding reminder; manage follows and blocks; disconnect training devices; review Community documents; sign out; and initiate account deletion. You can edit or remove your own content using its controls. Email info@zenith-hrx.com to request access, correction, deletion, or a copy of data, to object to a use, or to ask about a privacy choice. We may verify your identity before fulfilling a request and will explain any lawful exception. California residents may also request to know, correct, or delete covered information and may exercise rights without discriminatory treatment. Because Zenith does not currently sell or share information for cross-context behavioral advertising, there is no sale or sharing to opt out of in the current app.
Security, international use, and age
We use access controls and other safeguards, but no service can guarantee absolute security. Zenith's hosted infrastructure may process information in the United States and through service providers in other locations. The service is for adults 18 and older. We do not knowingly offer accounts to minors; contact us if you believe a minor has provided information.
Changes and contact
We will update this policy when practices change and provide notice of material changes where required. The effective date above identifies this version. Contact info@zenith-hrx.com with privacy questions or requests.