Sign in

Perstantia

Privacy and terms

Written in plain language, and accurate about what the software does. The same words are under Settings once you are signed in.

Data controller: Datawise s.r.o., the Czech Republic. Last updated 3 Oct 2026.

Privacy

What is stored, who reads it, where it goes, how long it stays, and your rights.

This notice says how Perstantia handles personal data: what is kept, who can read it, where it goes, for how long, and what you can do about it. It is written in plain language by the people who run the software, and every claim in it about the software is one the software is tested against.

Read privacy in full

Who is responsible

The data controller — the legal person responsible for what this application keeps about you — is Datawise s.r.o., and the governing law is the law of the Czech Republic.

Registered address: Mariánské nám. 15, 688 01 Uherský Brod. Privacy questions: info@datawise.cz.

What is stored

The record you log and the minimal product receipts described below. There is no advertising identifier, page-view tracking or third-party script watching you use the app.

Most of it is information about your body and your health — your weight, what you eat, what you take, how you sleep and how you train. The basis for keeping it is your explicit consent, given when you tick the box on sign-up; keeping the account itself rests on the terms you accept there. Withdrawing the consent is deleting the account.

One row is different: your profile is the one you write rather than log — the answers you give about yourself when you arrive and whenever you change your mind. What it holds is set out here in the export's own words, so a question this app starts asking is a question named here in the same breath: One row: your name, date of birth, height, units, timezone, the water amounts you told us you pour, what you said you record every day and the weekdays you take a progress photo on, how far back you said we may ask about blank days, the day you asked to be graded from, the equipment you said you can train with, the paragraph you wrote about your goals, your work and your family, what you said about your gender and the country you are in, whether you asked for a photoshoot to be cleaned up and drawn from on its own, the maximum heart rate you declared for yourself where you declared one, the sentence you wrote about the room your photographs are taken in, the weekday and start date of a weekly waist-measurement reminder, where you asked for one, and the age range your iPhone shared with the app, or that you declined to share it, with the time it was read.

This list is generated from the same place the export is, so it cannot drift from what the product actually holds:

  • Your record: what you skipped, around training, the evening reminder's streak, days you declared off.
  • What you declared: declared commitments.
  • Training: workouts, sets, heart-rate curves, plans, plan phases, plan weeks, plan days, plan groups, plan exercises, set prescriptions, plan history, days you swapped, the order of your weeks, missed days you did later, days you arranged something else for, your own exercises, pictures, clips and videos on movements, stand-ins you declared, what your sources call your movements, progression rules, progression decisions, personal records.
  • Nutrition: meals, water and day type, nutrition targets, estimated daily burn history, expenditure-informed target reviews, meal schedule.
  • Body: weigh-ins, tape measurements, photoshoots, progress photos (the list), ai projections (generated, not photographed), weekly projection sets (one prediction, seen from your angles), weekly projection set membership, manual projection requests, projection scenarios the app would not draw, ai-cleaned photos (edited by a model, not photographs), ai projections you checked against a later photo, themed pictures you asked for.
  • Recovery: morning check-ins, pain and niggles, steps, energy burnt.
  • Coaching: decisions, goal-support reviews, goal-support constraints.
  • Inventory: consumables, stock movements, supplements seen running out, protocols, protocol doses.
  • Integrations: connected sources, import ledger, sync runs, integration log.
  • Account: profile, goals, connected ai apps, ai activity, what you reported, pictures you reported and shared, ai photo editing consent, eligibility observations, image request receipts, product delivery and activity receipts, ai generations, the coach's notes, invitations you made, links with other people, what your friends may see, what your friends can see now, kudos you sent, pages you shared publicly, what you asked to be reminded of, reminders that went out, what your account is entitled to, ai answers granted and spent, photo themes you have earned, photo theme you chose for future pictures, ai picture credits held, taken and returned, who you are at the payment provider, friends you introduced, and what it paid.

Who can read it

You. Every table in the database carries a rule that ties each row to the account that owns it, and those rules are tested against a real database with two ordinary accounts, a third holding the owner role and a fourth that is an accepted friend: the second account has to see nothing of the first's, everywhere, and it does.

Your own AI, while you let it. Connecting an agent is a grant you give in a browser, and it reads and writes by the same rules you do — see below.

The owner of this deployment, for twenty-five things and nothing else: the reports people file through Feedback, how many seats there are and which accounts hold one, the waiting list (an invitation marks the row it was sent for), the error log, the public pages accounts have opened, what anybody reported about one of those pages, what the application did about accounts nobody has signed in to for a year, what it drew for accounts that asked for their week to be drawn without pressing for it, how often each thing an agent can do has been used, how many people are here by age, by country and by what they said about their gender, what every account is entitled to today and where that entitlement came from, what a payment provider has told this deployment about a payment, which accounts arrived on somebody else's invitation, what the invitation programme has paid the people who sent them, what this deployment has spent on a model this month, how many accounts came in through each way in, what became of the accounts each way in brought, what became of the accounts each month brought, and the monthly product measurements described below, and what it cleaned up for accounts that asked for their photographs to be cleaned up without pressing for it, the latest aggregate scheduled image-job health described below, and which accounts had one picture request take more than one call to a model, the last validator refusal for each AI use, and a picture somebody reported and shared with the owner, for as long as the sharing lasts. Each refusal contains only the validator's reason and the proposed item's kind and property names, never the model's prose, your record, an account identifier or a timestamp. The error log names a screen, a kind of error and a fingerprint of its message, and is kept thirty days; it has no column for who was signed in or what was typed. The owner's reading is a role the database enforces, proved in the same test as the rules above: the role reads those eleven tables and zero rows of anybody's anywhere else.

The tenth and the eleventh are counts and never rows, and they were the first two of five. The record of what an agent did is each account's own — you see yours under Settings › AI activity, and nobody else does. What the owner sees of it is one figure per action: how many times it went through, added up over every account since the log began, with no account named and nothing about any call. The tenth is the same shape asked of people rather than of actions: how many accounts fall in each decade of age, in each country and under each answer about gender — three tallies, drawn over everybody at once, naming nobody and reaching no row. Neither one can be read back to a person: the same three answers describe thousands of people, and nothing is reported that is not a total. A figure under a floor is printed as fewer than it rather than as a number, because a count of one is a person. They exist so the product can learn what anybody actually uses and who is actually using it, and they are the only way across the line between accounts that either record has.

Two of those ten arrived with public pages, and they are a real widening of what the owner can see rather than bookkeeping. Somebody who opens a page you shared can report it, and somebody has to be able to look at what was reported and take it down. So the owner sees the list of pages every account has opened — the heading and the words frozen onto each, when it was made and when it stops — and can end one. They see no picture in that list: the picture is on the page itself, at the address anybody holding your link can already open. Nothing under a page is reachable from it, and no page names the account it belongs to.

The seventh of the ten is a widening of a different kind, because it is not about anything you logged. It is the record of what the application did about an account nobody has signed in to for a year: a warning sent, a reminder a month before the deletion, the deletion itself, and the day of each. The owner can read it because something has to answer for an act taken while you are not here to see it. It holds your account's identifier, which act it was and when — no address, no name and nothing from your record — and the one row that outlives the account is the one saying it was deleted, because a record of an erasure that is erased by the erasure records nothing.

The ninth is the same kind of thing about a different act. If you asked for your week's projection pictures to be drawn without pressing for them each time, a daily job draws them, and it leaves a row saying it ran: your account's identifier, the day, whether it was your declared photo day or simply a week since the last one, how many pictures came out, what the drawing cost this deployment, and — if nothing came out — which gate stopped it, in the same words the screen would have shown you. It holds no picture, no photograph and no figure from your record. The owner can read it for the reason above and one more: something spent money on your behalf, and somebody has to be able to see what. It goes with your account when you delete it. Turning the instruction off in Settings › Privacy and terms stops the job on the spot, and nothing is drawn for you again.

The twelfth and the thirteenth arrived with paying, and the twelfth is the widest thing on this list: what every account is entitled to today. That is the kind of entitlement — the exemption for an account from before the launch date, a gift from the owner, a subscription — the day it began, the day it ends if it ends, and which payment provider wrote it. It holds nothing else: no amount, no card, no address, and nothing you have ever logged. The owner can read it because somebody running a paid service has to be able to see how many people are on a trial, how many are paying and how many have fallen out, and no count of those can be taken without reading the rows they are counted from. The thirteenth is what a payment provider told this deployment — that a payment happened, when, which account it was about, and what was done about it. What the provider actually sent is kept whole in the database and is not readable on any screen, because it carries figures and addresses this product has deliberately never held. Neither of the two is a rule on a table: each is a single question only this account may ask, so these reads add no table policy.

The fourteenth and the fifteenth arrived with invitations. The fourteenth is which accounts joined on somebody else's invitation — ids and nothing else, and the owner needs it because an account that joined that way has a longer trial, so a count taken without it would report somebody as lapsed while they are still trialling. The fifteenth is what the programme has paid: for each reward, what state it is in, which of the three kinds it was, how much of it and when. It names **neither person** — not who sent the invitation and not who accepted it — because how many rewards were given and what they cost is the question, and who introduced whom is not the owner's to read. These reads also add no table policy.

The sixteenth is the third of the counts, and it is about money rather than about people. When you use one of the declared AI features, this deployment pays a model provider for that call. The owner can see what that came to this month: for each of the declared uses, how many calls went through, how many failed, what they cost altogether, how many carried no price the provider had published yet, and how many accounts are behind the total. It names no account, holds nothing you wrote, sent or were shown, and cannot be read back to a person any more than the other two can. It exists for the plainest reason on this list: something is spending money, and somebody has to be able to see how much. Your own allowance is counted where you can see it, under Settings › Subscription.

The seventeenth, the eighteenth and the nineteenth are three current-state counts, and they are about how people arrive. Every account carries one word saying which way in it was made through: the page a stranger lands on, somebody's invitation, the documentation page a connector directory publishes, or nothing at all, which is what an arrival nobody can attribute is. It is written the moment the account is made and never afterwards, it is in your export, and **nothing in this product decides anything on it** — it grants nothing, prices nothing and refuses nothing. What the owner reads is three tallies of it and no row: how many accounts each way in brought; how many of each way in's accounts are in each entitlement state today; and the same by the month an account was created, as a month and never a day. The same floor applies to all three, and it bites hardest here, because these are the smallest figures in that room. They exist so the product can tell whether a way in has brought people in each current state. Those snapshots do not establish conversion or churn.

The twentieth is the ninth's twin, about a different act. If you asked for your photographs to be cleaned up without pressing for each one, a daily job cleans up whatever is still waiting — including a photograph you uploaded rather than took in a sitting, which is the whole of why the job exists — and it leaves a row saying it ran: your account's identifier, the day, how many pictures it cleaned up, what they cost this deployment, and, where it stopped early, which gate stopped it, in the same words the screen shows you. It holds no photograph, no cleaned copy and no figure from your record. The owner can read it for the ninth's reason exactly: something spent money on your behalf, and somebody has to be able to see what. It goes with your account when you delete it. Turning the instruction off in Settings › Privacy and terms stops the job on the spot, and nothing of yours is cleaned up again.

The twenty-third is the one place the record of AI calls names an account, and it exists to put a mistake right. Every call to a model leaves a row saying it happened, and a picture you ask for is one request however many times the app tries to draw it. Until 20 September 2026 two parts of the app could draw the same picture at the same moment, and each was counted against your weekly allowance. Since that date one request is drawn once, and a picture whose call came back without one is asked for once more — so a request that took two calls is ordinary as well as a sign of the older fault, and only a delivered picture spends your allowance. The owner can see which accounts a request took more than one call on: your account's identifier, which AI feature it was, how many pictures that happened to, how many calls that came to, how many of them answered, and what they cost this deployment. It holds no picture, no photograph, nothing you wrote and nothing the model was sent. The owner can read it because an allowance spent twice on one picture is given back by hand, to the account it was taken from, and nobody can do that without knowing which account it was.

The twenty-fifth is the only one that reaches a picture, and it opens only when you open it. If you report a picture this app drew for you — a projection, a studio clean-up, a re-lit copy or a themed picture — and tick the box that says so, the owner can see that picture, the photograph it was made from, and how it was made: what the picture's own record said about it on the day you reported it, such as the scenario, its assumptions and the model. Nothing else of your account comes with it: no other photograph, no journal and no measurement beyond what that record names. The owner sees it only in the owner's room of this app, never through an AI of their own, and only until the report is answered, until you stop sharing it, or for 30 days, whichever comes first; after that they see only that it was shared and why the sharing ended. A report your AI files for you shares no picture. Deleting the report or your account ends the sharing too.

A friend, and only for the figures you named. Linking with somebody takes an invitation from one of you and a yes from the other, and a link on its own shows them nothing. What they can see is what you opened in Settings › Sharing, moment by moment: that you finished a workout today and at what time, your streak, and how many of your photo days you kept. Nothing else, and nothing underneath them — no weight, no measurement, no set, no meal, no photo, no day-by-day record, and not what the workout was. Everything starts closed, and accepting an invitation opens the three only if you say Share.

A friend may send you kudos on one of those moments, once a day, and you may send them one. The person who receives it learns who sent it and on which day, and nothing else — there is no count and no figure in it — and is told once by a notification on their own devices, carrying the sender's chosen name. The notification is sent by the same scheduled sender as your reminders, which reads the kudos waiting to be told and the receiver's language, and nothing else of either account. Muting a friend stops their kudos reaching you.

Each of those three is worked out by this app from your own rows, and then written to a small table of its own that your friends can read. Their side never reads your record — it cannot. Two things have to be true for a friend to see one figure: an accepted link with you, and you having opened that figure. Turning the figure off, or removing the link, closes it on the next read rather than at some later tidy-up. The database enforces both, and the test above has a fourth account that is an accepted friend: it sees exactly what was opened and nothing else, and a link that is only pending, or has been removed, sees nothing at all.

Since the guided photoshoot you can take a progress photograph in the app instead of choosing a file. The camera is asked for by your browser, only on that screen, and only while it is open; the frame is turned into a picture on your own device and then stored exactly like a photograph you chose. Nothing is recorded, streamed or kept before you take a frame, and refusing the camera leaves the file picker where it was. A frame it takes also keeps, beside the picture rather than inside it, how far the phone was leaning forwards or back, where the phone reports it, so that a room the picture is later set in can be matched to where the camera stood.

Progress photos, form-check clips, item pictures and projection images sit apart from the rest, in private storage, under a folder named after your account. They are never public. When the app shows you one it creates a link that expires within the hour.

Before any picture or clip is stored the app rebuilds the file out of the parts it can name. Where it was taken, what took it and anything else your phone wrote inside it do not survive that; which way up you held the camera is the only thing kept inside it, because without it the picture arrives on its side.

The people running the deployment can reach the database, as with any hosted software. The application itself never uses that access on your behalf: every read and write the app or an agent makes runs as you, under your own rules.

Your AI, and what leaves the server

Apart from the AI features the next section describes, no model reasons about you here. Perstantia holds your data, the tools that act on it, and the sign-in that connects them — the reasoning happens in your own AI, on your side of the connection. Nothing is sent to an AI provider by this application, with one exception you switch on yourself: the AI-features consent the next section describes, off by default, and while it is off nothing is sent at all.

Your AI is a client you choose and connect yourself — any assistant that speaks the open agent protocol, not one company's. Connecting it means signing in, in a browser, and granting it access; from then on it acts as you, under the same rules, and everything it does is written into an activity log you can read and nobody can edit. Disconnecting it in Settings stops it immediately.

That grant is the one way your data leaves here without you pressing an export button: when your AI reads your record, your record goes to your AI — and what its provider does with what it reads is governed by your agreement with that provider, not by this notice. Choose it as you would choose anyone you hand a medical file to.

Photographs included. When you ask your agent about a progress photo, the app hands it a short-lived link to your own file; the app does not look at the image, describe it, or send it anywhere itself.

A prompt you copy leaves by your own press, as an export does. Where the app offers one — on Today, when your course reads off course and no AI is connected — it is shown in full before you press, figures and all; copying puts it on your device's clipboard and nowhere else. Once you paste it into an assistant it has left Perstantia, and that assistant's provider holds it on its own terms.

Two models do run on this server. One is MODNet, a portrait matting network: when you choose a theme for a picture, it finds the outline of the person in a picture this app has drawn, so that the person can be set in a theme's room. The other is MediaPipe multiclass selfie segmentation, a network that labels skin and clothing: when an outfit is asked for, it reads where your photograph and the picture drawn from it show skin and where they show clothing, so that the outfit never shows skin your photograph covers. Neither measures a body's size or shape, recognises anybody, or is handed a name, a goal or a record. The picture does not leave this server for them, and no provider is involved.

AI features, the one switch

In Settings › Privacy and terms — beside these documents — there is one switch, off by default, that permits something you choose to be sent out to an AI provider. Under it, the photograph you chose, a picture this app drew from the photograph you chose, the words you type about a meal, the photograph you take of a plate, the physique goal you wrote, dated summaries of your training, nutrition, body and recovery record, the equipment you've stated is available, when you've stated it and the figures, dates and exercise names of the day's training, food and recovery facts are sent, and nothing else. What you accept when you turn it on is exactly this, in the words the switch shows:

This switch covers Photo cleanup, Physique projection, Meal estimate, Goal-support proposal and Coach's note — the only features that send anything of yours out to an AI provider, and only when you use them or, for the one said below, while its own switch is on. It is off until you turn it on here, and while it is off the product behaves exactly as if the features did not exist.

When you use one of them, the photograph you chose, a picture this app drew from the photograph you chose, the words you type about a meal, the photograph you take of a plate, the physique goal you wrote, dated summaries of your training, nutrition, body and recovery record, the equipment you've stated is available, when you've stated it and the figures, dates and exercise names of the day's training, food and recovery facts are sent to Google, OpenAI and Anthropic. That is not used to train their models, and it may be kept for up to 30 days for their abuse monitoring; after that it is deleted there. What comes back is never the record: an edited picture is a rendering for sharing, which carries the Perstantia logo in its own pixels, says what it is on every screen it appears on, and says it in its own pixels too on a picture you share; and an estimated meal is a set of numbers you look at and choose to keep. Your photographs and everything you have written stay untouched, stay yours, and stay the record.

The coach's note runs on a clock rather than a press: behind a switch of its own, which is off until you turn it on, it is sent each morning and once when a session closes. What comes back: a coach's note is words over the facts the app already shows, and changes nothing.

The photograph you take of a plate is sent for the answer and this app stores no copy of it — not in your record, not in your files, nowhere on our side. What you get back is an estimate you look at, and only the numbers you press Log on are written down.

One thing no setting removes: every image sent is checked automatically for illegal content, and an image that check flags is kept and looked at by a person at the provider. That happens whatever you choose here.

You can withdraw this at any time on the same screen. Withdrawing stops every future send at once; it cannot recall anything already sent, which is why nothing is sent until you have said yes.

The providers live today are Google, OpenAI and Anthropic. The switch says so too; the words there and here are composed from one declared list, so they cannot disagree, and a provider change rewrites both in the commit that makes it.

Two of the photo features can also run without your pressing anything, and only if you ask them to. Before your first photoshoot the app asks once whether your photographs may be edited, and your future pictures drawn, on their own. Both are off until you say yes, and that one yes turns both on; where you have not answered the switch above, its own words are put in front of you and it is answered with the same press. Each has its own switch in Settings › Privacy and terms — above these documents — where you can turn either on or off at any time. Turning one off stops it at once. Everything else about them is unchanged: the switch above still has to be on, the same weekly allowance still applies, saying yes buys nothing, and nothing is sent that the switch would not have permitted you to send by hand.

In a guided photoshoot, both wait until you keep the sitting. The guide ends by showing you the three photographs, and nothing is sent from them — and a photograph you take again is deleted and replaced — until you press Keep these, leave that screen, or have been away from it for half an hour.

The second of those two can also be declined for one sitting. Before the first frame of a photoshoot the app shows what your standing answer is and lets you say no to this sitting alone: the photographs are saved and no week is drawn from them. It only ever says less than your standing answer and never more — a sitting cannot turn the drawing on for somebody who never asked for it — and the answer is written on that sitting rather than changing anything for the next one.

One thing you can type yourself travels with those two picture features: the background you describe in the box above these documents. The instruction the app composes goes to the provider with the photograph, and one sentence of that instruction is yours once you have written one. It reaches that sentence and no other — nothing you type there changes what the instruction says about your body — and leaving the box empty means the app's own words go instead, as they always have.

A theme you have earned changes where a picture is set, and nothing about what is sent. The room is a picture of an empty room that is part of this app, the same for every picture of a set; it is never sent to a provider and never asked of one. Your picture is drawn as it would have been without the theme, and the person in it is then set in the room on this server.

Perstantia is for people aged 18 or older. Every new account is asked for a date of birth — on the sign-up form, or on the screen that follows a first sign-in with Apple or Google — and a date below that age is refused there and wherever it is later changed; an account holding one cannot switch the AI features on or send a photograph to a provider.

Inside the iPhone app, and only where the phone says the law of the place you are in requires it, the app also asks Apple for your age range, through Apple's Declared Age Range feature. Apple asks you whether to share it, or the place you are in has it answer; what comes back is whether the range was shared or declined and, where it was shared, the two ages the range lies between. The app keeps that on your profile with the time it was read, and nothing more: not how your age was established, and nothing on the phone. It is read for one purpose — to hold the minimum age where the law asks for more than a date somebody typed. A range wholly below 18 is treated as a date of birth below it is, and one wholly at or above 18 answers the question whatever date is stated; if you decline, if the phone does not ask, or if the range does not settle it, your stated date of birth stands. A decline is not asked about again. The answer leaves in your export with the rest of your profile and is deleted with your account.

Who processes it on our behalf

The companies below process data on the deployment's behalf. Each processes only what its role needs, under its own data-processing terms; where one moves data outside the European Economic Area it does so under the contractual safeguards those terms provide.

The application sends three things of its own with nobody asking, and nothing else: a ping to the owner that somebody joined the waiting list, which carries no address; an invitation email to a waiting address when the owner opens a seat for it; and, to an account that has gone twelve months without a sign-in, the warning the promise above states, with a reminder a month before the deletion. All three are off until the deployment sets a channel, and the owner's room says which is in use. The one send you can switch on is the AI-features consent above — what it covers goes only while that stands, and only when you use the features it names or a switch of its own under it says so. If the owner has also set an error-monitoring endpoint, the same error fingerprints the log holds — never who, never what was typed — are posted there as well.

  • Vercel hosts the application and runs its server code. It sees every request you make, as any web host does — where it came from, what it asked for, and the data in it while it is being handled. It keeps request logs for its own operation. Nothing you log is stored there.
  • Supabase holds the database, the file storage and the sign-in. It sees everything listed under what is stored, your photos and clips as files, your email address and a hash of your password. It sends sign-up, password reset and change-of-address emails in your language, copied to your sign-in record. It also keeps the database backups.
  • Apple, for Sign in with Apple, confirms who you are when you choose Apple to sign in, or add it on Settings › Account. It sees that you signed in here and when, with the Apple account you pressed with, which is theirs already. What comes back to this deployment is an identifier Apple gives this account, the email address Apple chooses to send — a relay address when you ask it to hide yours — and a name if it sends one. Nothing of your record reaches Apple this way: no weight, no measurement, no workout, no meal, no photograph. Removing it on Settings › Account stops it signing you in and withdraws nothing Apple already holds. Deleting your account from the iPhone app asks Apple to revoke this app's sign-in; from anywhere else, remove Perstantia under Sign in with Apple in your Apple Account settings. It is in use only if you choose it.
  • Google, for Sign in with Google, confirms who you are when you choose Google to sign in, or add it on Settings › Account. It sees that you signed in here and when, with the Google account you pressed with, which is theirs already. What comes back to this deployment is an identifier Google gives this account, the email address Google chooses to send and a name if it sends one. Nothing of your record reaches Google this way: no weight, no measurement, no workout, no meal, no photograph. Removing it on Settings › Account stops it signing you in and withdraws nothing Google already holds. It is in use only if you choose it.
  • Resend sends the invitation email to a waiting address when the owner opens a seat for it, the two warnings an account gets before a year of silence ends it, a reminder you asked for to your sign-in address when you have no device turned on for it, and the owner's own ping when the owner has chosen email for it. It sees the address an invitation or a dormancy warning goes to and the words of it, which name no person and hold nothing from any account — a warning carries the date the account would be deleted and the two periods the promise states, and nothing you have logged; the address a reminder goes to and its words, which are the kind you asked to be reminded of and its time, with a supplement's name or your run of days where the reminder carries one and nothing else of your record; and the owner's address when the ping is by email. It is in use only once the deployment has set it up, and until then nothing is emailed by the application.
  • Telegram, or a Signal bridge, carries the owner's ping when the owner has chosen one of them rather than email — one of the three, never more than one. It sees that somebody joined the waiting list, and a link to the owner's room — never the address, which the ping is not handed. It is in use only once the deployment has set it up, and until then the owner is not pinged.
  • Google is sent the photograph you chose, a picture this app drew from the photograph you chose, the words you type about a meal, the photograph you take of a plate, the physique goal you wrote, dated summaries of your training, nutrition, body and recovery record and the equipment you've stated is available, when you've stated it, when you use one of the AI features — reached through the Vercel AI Gateway and only under the consent switch described above the documents. It sees the photograph you chose, a picture this app drew from the photograph you chose, the words you type about a meal, the photograph you take of a plate, the physique goal you wrote, dated summaries of your training, nutrition, body and recovery record and the equipment you've stated is available, when you've stated it, only while the AI-features switch is on and only when you use one of the features it covers. What is sent is not used to train models and may be kept up to 30 days for abuse monitoring; an image its automatic check flags is kept and reviewed by a person there. Until you switch that on, it sees nothing at all.
  • OpenAI is sent the photograph you chose and the physique goal you wrote, when you ask for a goal picture — reached through the Vercel AI Gateway and only under the consent switch described above the documents. It sees the photograph you chose and the physique goal you wrote, only while the AI-features switch is on and only when you ask for a goal picture. What is sent is not used to train models and may be kept up to 30 days for abuse monitoring; an image its automatic check flags is kept and reviewed by a person there. A goal picture asks it for its less strict moderation setting rather than its default, and one set in a theme keeps the default; its automatic check still runs, and a picture it refuses is not asked for again at another setting. Until you switch that on, it sees nothing at all.
  • Anthropic is sent the figures, dates and exercise names of the day's training, food and recovery facts, each morning and once when a session closes, while its own switch is on — reached through the Vercel AI Gateway and only under the consent switch described above the documents. It sees the figures, dates and exercise names of the day's training, food and recovery facts, only while the AI-features switch is on and only each morning and once when a session closes, while its own switch is on. What is sent is not used to train models and may be kept up to 30 days for abuse monitoring; an image its automatic check flags is kept and reviewed by a person there. Until you switch that on, it sees nothing at all.
  • Apple is the seller of a subscription or an answer pack bought in the iPhone app: it takes the payment, collects the tax for your country and sends your receipt. It sees what you bought and when, against the account you already keep with them on your phone — the payment method and billing details are the ones they hold, and are never entered or seen here. With a purchase the app hands them this account's identifier, a random string that says nothing about you, so that a later renewal finds the right record. Nothing of your record reaches them: no weight, no measurement, no workout, no meal, no photograph. What comes back to this deployment is the purchase's identifier at them, what was bought, and the day the period you have paid for ends. It is in use only once you buy something, and an account that never does is never known to them through us.

Stored and sent are two questions

The list at the top says what is kept. It does not say what is sent, and for almost everything in it the answer is nothing: it sits in your own rows and moves when you ask it to move — to your AI, or into your export.

The export is that same distinction from the other side. It tells you what leaves with you when you press the button — which is everything — and it has nothing to say about anything leaving without you being the one who asked. There is exactly one kind of row in this product where those two questions come apart, and the next section is about it.

The one thing here that is written to be read

Everything above is a record of something that happened to you: a set you lifted, a meal you ate, a decision you took. A problem you report is the exception, and it is the only one. It is correspondence — the whole point of writing it is that somebody else reads it — so it is described here separately rather than folded in with the rest.

A report is correspondence rather than a private note: it is written to be read by whoever maintains this application, which today is one person — the owner of this deployment, reading every report in a room of the app that a role in the database opens for that one account. It is not forwarded anywhere, no other account can see it, and nothing here trains a model on it. Once it has been read it cannot be unsent — deleting a report removes the row, not the reading. What goes in the box is stored exactly as typed, so anything that should not be read does not belong in one.

The same sentence appears above the box before you type in it, and your agent is told to say it before it offers to file anything on your behalf. It is one sentence in one place, so this page and that box cannot end up describing two different promises.

Nothing about this is a mechanism for anyone else to read your reports: there is no forwarding, no shared list, and no second kind of account. If that ever changes, it changes here first.

Measuring whether the product delivers

The owner can also read the latest scheduled image-job health: when it was attempted, aggregate eligible and skipped counts with fixed reasons, completion or failure, and whether an error alert was sent or failed. This health record contains no account identifier, photograph or words you typed. The existing weekly and studio run logs also record bounded recovery attempts and notification status. Your image request receipts link to the run that made them, so provider costs and saved pictures can be reconciled without treating another request at the same time as part of the job.

We keep minimal server receipts to measure trial eligibility, delivered pictures and pairs, completed workouts and days of intentional logging in the app or through your AI. Payment and renewal measurement reuses the payment record. These receipts hold identities and times, never photographs, health figures, words you typed, IP addresses or device identifiers.

Your own receipts are readable in your export, remain for 400 days and leave when you delete your account. They are hidden after expiry and removed by daily maintenance; an unavailable maintenance run can delay physical removal. Deleting an individual picture or workout keeps its minimal receipt until that expiry. Earlier history that was never collected stays unknown.

The owner sees only fixed monthly figures about delivery, return and payments, with no account named. Small counts and every related total are withheld together under the existing floor of ten. A released anonymous figure cannot change on repeated reads or after an account leaves, and is retained for 400 days after its observation cutoff. No raw personal receipt crosses that boundary. These figures assess the product; they do not decide your access or advice.

What the activity log holds

Which tool ran, from which surface, when, what it was allowed to do, how it ended, and the names of the details it was given — never the values. That is deliberate: the log cannot be edited or deleted by anyone, so a weight or a meal copied into it would be something you could never remove. Your data belongs in your own tables, where deleting it deletes it.

How long it stays

Everything you log stays for as long as your account exists and not a day longer. Deleting the account deletes it in the same request — there is no archive, no soft delete and no thirty-day window.

The one rule about the account itself, for when nobody comes back to it: Twelve months without a sign-in brings an emailed warning, and deletion about three months after it; your export is available throughout.

Your files go first. Every file stored under your account's folders — photos, clips, item pictures, projection images — is removed from storage before any row is, and a deletion that cannot remove them stops there and leaves the account intact, so a picture of you can never outlive the record that it exists.

The activity log and the history of every version your plans have been in are deleted with the account; deleting the account is the only thing that deletes them. The error log is purged after thirty days and never held a name. A waiting-list address is kept until the person asks for it to be removed or, once they are invited, for thirty days after the invitation. A connected agent's tokens are revoked the moment you disconnect it.

What connecting an agent leaves behind has an end too. An authorization code or a token is deleted a day after it expires, and the registration of an agent client that never connected a day after it was made. The two addresses an agent client registers and exchanges tokens at count how often one network address asks, so that a client that will not stop can be told to wait: what is kept is a one-way digest of the address and a count, never the address, and it is deleted a day after the count began.

One record outlives the account, and it is not yours to read: what Apple tells this deployment about a purchase — that a subscription was bought, renewed, cancelled or refunded — is kept after deletion with the account's id taken off it, because the seller's ledger has to stay reconcilable against what it was told. It names no person; the one identifier inside it is the random string the seller's row above describes, which then points at nothing.

The database provider keeps backups so the service can be recovered after a failure. A deleted row can persist in a backup until that backup ages out, and a backup is never read to bring one person's data back.

One thing deletion cannot do, and it is worth saying plainly rather than letting you find out: it cannot unsend a report. Deleting removes the row. If somebody has already read what you wrote, they have read it, and no button here reaches into that.

Your rights, and the button for each

You have the rights the law gives you over your own data — to see it, to correct it, to take it with you, to have it erased, to withdraw your consent, and to object. In this product each of them is a button rather than a request:

  • To see it and to take it with you: Settings › Export gives you everything you own as a file, for any period you name, with nothing trimmed. Your own agent can fetch the same file.
  • To correct it: every row you logged can be edited or deleted, on the screen or through your agent.
  • To erase it and to withdraw your consent: Settings › Account deletes the account and everything in it, files first, in the same request.
  • To object, to ask a question, or to ask for a waiting-list address to be removed: write to the privacy contact named above, or, while none is named, through the feedback box.
  • To complain: you can lodge a complaint with the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů).

What you are promised

Most of this notice describes how the software behaves today. What follows is different: each sentence is a promise about whatever Perstantia becomes, decided by the people who run it on a named day and recorded with its reasons. The same words are printed on the page where you create an account, so nobody joins without having read them.

  • Reading your record back and exporting all of it are never behind a wall: free, forever, and unconditional, including after a subscription ends. There is no window and no expiry — nothing you have logged is ever locked away from you. Decided on 4 Sept 2026.
  • If anything here is ever charged for, it does not reach accounts that already exist: an account created before that point keeps everything Perstantia can do, at no cost, permanently. Decided on 4 Sept 2026.
  • An account created after that point has its first 14 days with everything Perstantia can do open to it, and afterwards keeps its whole record to read and to export. Decided on 6 Sept 2026.
  • A subscription or an answer pack is bought in the iPhone app, through Apple and under its Media Services terms. Apple is the seller: it takes the payment and collects your country's tax. Datawise s.r.o. provides the service. Decided on 21 Sept 2026.
  • A refund is asked of Apple, which took the payment and is the only one able to return it — from your purchase history in the iPhone's Settings, or at reportaproblem.apple.com. Decided on 21 Sept 2026.
  • Ask within 14 days of your first subscription payment and it is refunded in full. A renewal is not refunded, nor are answers already spent; an unspent answer pack is refunded in full within 14 days of buying it. Decided on 16 Sept 2026.
  • A subscription is cancelled on Apple's own subscription sheet, which Settings › Subscription opens in the iPhone app. Cancelling stops the next renewal and nothing else: everything stays open until the day you have paid through. Decided on 21 Sept 2026.
  • Twelve months without a sign-in brings an emailed warning, and deletion about three months after it; your export is available throughout. Decided on 2 Sept 2026.

What the export leaves out

The export contains every row that is yours. A few tables are left out, each because it is not about you, and the reasons are the export's own, in the same words:

  • Anonymous fixed monthly product figures; no personal rows.
  • Operational collection watermark; no person or count.
  • The access tokens for a connected source. Every column is either encrypted text or a description of it, so there is nothing about you in it — and a long-lived key in a file you keep on a laptop is a risk with no matching benefit. Disconnecting a source is how you get rid of one.
  • The list of muscle groups the app ships with. The same for everybody, written by nobody.
  • The list of equipment the app ships with.
  • Which AI apps are registered with the sign-in server. Not about you.
  • The one-time codes a sign-in uses. Each is valid for seconds, used once, and describes a handshake rather than anything you did.
  • Hashes of the access tokens behind a connection. The connection itself is exported.
  • How often one network address asked to connect an AI app: a one-way digest of the address and a count, kept a day. It names no account.
  • How many people can sign up. A setting of the app, the same for everybody.
  • Whether the sign-up gate let each account in. It says nothing about you beyond that you were admitted, and it is what lets the sign-up page tell the truth about how many places are left.
  • Which account runs this deployment. One row, set by whoever holds the database and never by the app; it is what lets the owner read every report, the seat count and the waiting list, and nothing else of anyone's.
  • Errors the server hit: which screen, what kind of error, and a fingerprint of its message so repeats can be counted. Never who was signed in, never what was typed, never the address bar's query — there is no column for any of those. Kept thirty days; the owner reads the last seven.
  • What people who opened a public page said was wrong with it: which page, and one of five reasons. Nothing about who reported it — there is no column for a name, an address or anything else — so it is not anybody's row to download, including yours.
  • What the payment provider told this app, kept exactly as they sent it, so that the same message arriving twice can never be acted on twice. It is this app's record of being told rather than your record of what happened — what it *did* to your account is in what you are entitled to, which is here, and the invoice for what you paid is the provider's own and is on their pages.
  • The record of what the application did about an account nobody signed in to — a warning sent, a reminder sent, an account deleted. It is the product's own log rather than part of your record: it holds nothing you logged, and the last row in it is written about an account that no longer exists.
  • The record of the application drawing your week for you on a day you did not press for — whether it drew, how many angles, what it cost this deployment, and which gate stopped it if one did. It is the product's own log rather than part of your record: the pictures it produced are in your export, under your projections.
  • The record of the application cleaning your photographs up on a day you did not press for — whether it cleaned any, how many, what it cost this deployment, and which gate stopped it if one did. It is the product's own log rather than part of your record: the cleaned pictures it produced are in your export, beside the photographs they were made from.
  • Latest scheduled image-job health, with counts and fixed reason codes only. It names no account and is not part of your record.
  • A device subscription is key material — two secrets and an address anybody holding it can post to. What the user actually wants to know, which devices are on, is on Settings › Notifications; what would leave in the file is a way to notify them.
  • A lock-screen push address — Apple's URL for the token iOS issued one workout's card. It is a way to redraw that card and says nothing about the workout, which is in the sessions section.
  • The addresses of people who asked for a place when the seats were full. They are not your rows — each one belongs to somebody who has no account here — so they are not part of your data to download.

Public pages

You can put one card — a week, a personal record, a training day, a projection beside the photo that answered it, or a before-and-after — at a web address anybody holding the link can open. No account, no sign-in, and you are never told who looked. It is the only thing in this product readable by somebody with no account at all, and it happens only when you press the button under the picture.

What is on one: the picture as it was painted, the words that were on the card, the day you shared it, the day it stops, and the first name you typed for that page if you typed one. Nothing under it — no other figure, no other day, nothing about the account. The values are frozen when you make the page and never update, so a link somebody kept for six months shows what you shared six months ago and not what is true today.

It ends, always. Thirty days unless you chose otherwise when you made it, and never more than a year and a day from the day it was made — there is no forever, and the database refuses one. You can take it down before that from Settings › Sharing, which stops the page and its picture in the same moment. What anybody already saved or screenshotted while it was up is theirs, and no button here reaches into that.

The page asks search engines not to keep it, and this deployment asks them not to fetch one at all. Neither is a lock: the address itself is what keeps a page private — twenty-two characters nobody guesses — and a link you send is a link whoever you sent it to can send on.

Every page carries a way to report it. Anybody who opens one can say it is theirs and was shared without them, that it is explicit, abusive or spam, or that something else is wrong; the owner of this deployment reads those and can take the page down. Reporting records nothing about the person reporting — no account, no address — which also means nobody can be written back to.

Apple Health, your Watch and a heart-rate strap

With your permission, the iPhone app reads weight, workouts, sleep, resting heart rate and HRV, water, steps, active energy and resting energy from Apple Health — each kind asked for separately on Settings › Integrations, and only the kinds you allow. What it reads becomes rows of your own record, marked as having come from Apple Health, and anything you logged yourself stays exactly as you logged it.

It writes weight, workouts and water back into Apple Health, each only if you allow that too: one entry per row you log here, carrying this record's own id, updated when you change the row and removed when you delete it. Nothing that came from Apple Health is written back into it.

During a workout the app can read your heart rate live, from a Bluetooth strap you pair on the workout screen — the phone asks for Bluetooth the first time — or from the Watch app, which starts a workout session for its own sensor. The curve is stored on that workout as samples in beats per minute with the name of the device it came from, and it is in your export like the rest of the workout.

Nothing read from Apple Health, the Watch or a strap is used for advertising, sold, or matched against anything outside your record. It leaves the server only the way any figure of yours does — to your own AI when it asks, in your export, or inside the dated summaries the AI switch above names while that switch stands — and never because of where it came from. Disconnecting Apple Health on Settings › Integrations stops the reading at once, and you choose then whether what it brought stays in your record or goes with it; deleting the account deletes all of it. Writing into Apple Health is a permission you gave the phone, and it is taken back there.

Reminders on your phone

You can ask to be reminded of your doses, your meals, a weigh-in, your tape measurements, a workout, to finish logging the day, that a supplement is about to run out, or in the evening that your run of days is at risk — at a time and on the days you choose. You can also ask to be told when a photoshoot's pictures are done: that one comes once for each photoshoot you keep, at no set time, only to your devices and never by email, and it is sent by the work that made the pictures, acting as your account, rather than by the reminder sender; it says whether they are ready and carries no picture. Nothing reminds you of anything unless you asked it to, and turning one off stops it at once.

A reminder says only what you asked to be reminded of. It carries no figure from your record — not how many doses, not whether the day is finished, not your weight — because the thing that sends it cannot read any of that. What it reads is which reminders you declared and when, the devices you turned on, the timezone and language on your profile — so that seven o'clock is seven where you are — and your sign-in address, for when there is no device. The one reminder that names something is the one about a supplement running out: when the app, open in your own hands, sees a supplement reach its reorder point, it writes a note of that, and the sender reads the note and the supplement's name — never how much you have, how fast you take it or how many days are covered. The one reminder that carries a figure is the one about your run of days: whenever the app, open in your own hands, works out your days in a row, it writes that one number down with whether the day is still open, and the sender reads that note in the evening — never the record behind it. Nothing else of yours is reachable from it. If you want to be told what is actually left to do, ask your AI; it reads your record and this does not.

To put one on a lock screen, your browser mints a subscription and this app stores it: an address at your browser's own push service, two keys the message is encrypted to, and a short name for the device that your browser composed — never a full description of your browser. That row is a key rather than a fact about you, so it is the one thing that is deliberately not in your export. You can see every device on Settings › Notifications and forget any of them there.

The push service is your browser's, not ours: Google's for Chrome, Apple's for Safari, Mozilla's for Firefox. It is handed the encrypted message and the address it belongs to, and it cannot read the message — the encryption is keyed to your device. It does learn that this application sent something to that device at that moment. If you have no device turned on, a reminder goes to your sign-in address by email instead, through the provider named above.

In the iPhone app there is no browser subscription. The phone registers a device token with Apple's push service instead — an address Apple issues to this app on this phone, with no keys, because there the sender is vouched for rather than the message encrypted — and, while a workout is on your lock screen, a second token for redrawing that card, which the phone rotates and this app replaces. Both are addresses rather than facts about you. Apple is handed the message itself, which says what this section says a reminder says and nothing more, and learns what any push service learns. The first is forgotten when you forget the device on Settings › Notifications; the second is kept with that workout's record, of no use once the card has gone, until the workout is deleted; and both when the account is deleted.

Cookies

Two. One keeps you signed in. The other is set when you choose a language and remembers the choice for a year, so a page you open before signing in is in it. There is no other cookie and no cross-site tracking of any kind.

This device also keeps the last workout you opened, its prescription and your unsent sets so you can reopen it without a connection. The working copy is replaced when you open another workout and removed when you finish or cancel it, sign out, or change accounts on this device. It is not a fresh read of your record; other screens still need a connection. Clearing this site's device storage removes the copy and any unsent sets.

It also keeps the pictures of your body you have already looked at — your photographs, their cleaned-up copies and your projections — so a second look does not download them again. Only your own, only on this device, up to about 100 MB with the oldest let go first. A picture you delete, or your AI deletes, is let go the next time the app is open, and all of them are removed when you sign out or delete your account. Clearing this site's device storage removes them too.

Changes

These words were last changed on 3 Oct 2026. When they change, that date changes with them, and a change that affects what is kept or who reads it is made here before it is made anywhere else.

Terms

What this is, what is paid for, and what you can rely on.

These are the terms you agree to when you create an account. They are written in plain language and they mean what they say: what Perstantia is, what is paid for and from when, what you can rely on and what you cannot.

Read terms in full

What Perstantia is

A record of your training, nutrition, body, recovery and supplements, kept honestly and completely, and a connection that hands your own AI the whole of it on every question — so it guides you from what actually happened rather than from what either of you remembers. The app itself decides nothing about you: every figure it shows is arithmetic over your own rows and names the rows it came from.

It is run by Datawise s.r.o., and these terms are governed by the law of the Czech Republic.

What is paid for, and from when

Perstantia is paid for by subscription, and a launch date decides what an account gets. Until the date is set, every account has everything Perstantia can do. An account created before the date keeps everything, permanently and at no cost; an account created after it has its first fourteen days with everything open, and afterwards a subscription is what keeps new entries open. Whatever happens, the whole record stays free to read and to export.

How many accounts Perstantia takes at a time is a number the owner raises as capacity allows. When there is no room, you can leave an email address and the owner writes to you when there is; that is a ceiling on accounts, not a queue, and no place is promised.

Perstantia changes. Features can be added, altered or removed, and the service can be paused or ended. If it ends, you are told before it does, with time to export; your data is never kept after the account it belongs to is gone.

Your account

One account, yours, for an adult. You must be 18 or older to hold an account, and creating one asks for your date of birth and refuses a date below that age. Keep your password and the devices you sign in on to yourself: anything your account can do, whoever is holding it can do. If you lose the password, the sign-in page sends a link to set a new one.

You may also sign in with Apple or Google, and add or remove either on Settings › Account. Each is another way into the same account; the privacy notice says what each is told and sends back.

An account used to attack the service or the people on it can be closed by the owner. Any other reason an account ends is yours: you can delete it at any time, and nothing asks you why.

Paying, cancelling and refunds

A subscription or an answer pack is bought in the iPhone app, through Apple and under its Media Services terms. Apple is the seller: it takes the payment and collects your country's tax. Datawise s.r.o. provides the service.

A refund is asked of Apple, which took the payment and is the only one able to return it — from your purchase history in the iPhone's Settings, or at reportaproblem.apple.com.

Ask within 14 days of your first subscription payment and it is refunded in full. A renewal is not refunded, nor are answers already spent; an unspent answer pack is refunded in full within 14 days of buying it.

A subscription is cancelled on Apple's own subscription sheet, which Settings › Subscription opens in the iPhone app. Cancelling stops the next renewal and nothing else: everything stays open until the day you have paid through.

When the day you have paid through ends, the account is what it would have been without the subscription: one created before the launch date keeps everything at no cost; one created after it has whatever is left of its trial, which is counted from the day it was created and does not pause while a subscription runs; and otherwise nothing new can be logged, while the whole record stays free to read and to export.

Deleting your account here does not cancel a subscription: Apple bills it, so cancel it on Apple's sheet first, or it goes on renewing after the account is gone.

Inviting somebody

Anybody who joins on your invitation starts with thirty days of everything rather than fourteen. When somebody you invited first pays for Perstantia, a paying account earns one contracted monthly payment or one-twelfth of its contracted annual amount as credit on the next invoice. A non-paying account receives thirty days added to its own account, and where you already have everything, a pack of 20 AI answers instead. Nothing is ever given for a sign-up alone, no reward is money and none is paid out in money, and one account may earn 12 rewards in a rolling year at most — a referral past that is recorded and pays nothing. The programme can be changed or ended like anything else here; an earned reward stays owed, including earlier whole-period rewards. Credit is rounded once to the nearest currency unit used for payment, with halves rounded up. Credits add together; anything beyond an invoice stays for following invoices. A later plan change does not change earned value; a currency change waits for reconciliation, with no automatic conversion. Cancellation and refunds do not un-earn rewards or pay them twice.

Your AI

You bring your own. Any assistant that speaks the open agent protocol can be connected, and once connected it acts as you: it logs freely, proposes anything that changes what the app reasons from, and asks before anything destructive. It is limited by the same rules you are and by nothing more.

What it says to you is its own. The app hands it your record and the figures it has measured; the advice your AI builds on top of that comes from your AI, under your agreement with its provider, and the app neither reviews it nor applies it. Nothing changes in your record, your plan or your targets because an agent said so — only because it wrote so, as you, through a tool that records it did.

Your data is yours

It is not sold, not used to train anything, and not shared with anybody you did not name yourself. What leaves your account is a moment you opened to a friend you agreed to link with, one at a time, which you can close again in a tap, and the kudos you choose to send them. You can export all of it at any time and delete all of it at any time, and neither requires asking anybody. The privacy notice says who can read what, and it is the complete list.

Reading your record back and exporting all of it are never behind a wall: free, forever, and unconditional, including after a subscription ends. There is no window and no expiry — nothing you have logged is ever locked away from you.

What you can rely on

Not availability. This is a small deployment; it can be down, and there is no uptime promise. To the extent the law allows, it is provided as it is, and neither the owner nor the controller is liable for a loss that follows from relying on it.

What you can rely on is that your data is not held hostage: the export works from the app and from your own agent, and it contains everything. Keep your own copy of anything you would be upset to lose.

And on what the app says about itself. Every figure names the rows it was measured from, every refusal says why, and nothing here invents a number, presents a generated picture as a photograph, or pays you for an outcome.

Changes to these terms

These terms were last changed on 3 Oct 2026. When they change, that date changes with them. A change you would object to is one you can answer by exporting and leaving, which needs nobody's permission.

Not medical advice

What the app's figures are, what your AI's advice is, and what neither is.

Read this one. It is short, and it is the only part of these documents that is about your body rather than about your data.

Read not medical advice in full

This is not medical advice

Perstantia is not a medical device and nothing in it is medical advice, diagnosis or treatment. It does not know your medical history, your medication, or anything a doctor would ask about before telling you to train harder.

If something hurts in a way that is not ordinary training soreness, if you have a condition that training could affect, or if you are unsure — ask a doctor or a physiotherapist. This app is not a substitute for either and cannot tell when you need one, and neither can your AI.

What the app's figures are

Arithmetic over numbers you typed in. When the app says your load has climbed, it is because a ratio of your recent training to your longer-term average crossed a threshold somebody chose — it is a reading of your own logs, not an assessment of you.

That is also why every figure names the rows behind it. You are meant to be able to disagree with it, and the app never applies a program change on its own.

What your AI's advice is, and what the coach's note is

Your AI is free to coach you on top of that — to say what it thinks of your week, to suggest a change, to answer a question with what it knows. That advice is your AI's, not the app's: the app did not write it, does not check it, and marks every figure of its own so you can tell the two apart. Weigh it as you would weigh advice from any source that has read your diary but has not examined you.

One thing is the app's and not your AI's: the coach's note on Today, which a model this app runs writes over the day's facts the app's own calculations composed, and which is marked as the coach's note wherever it appears. It is words about those facts, not an examination of you, and it does not check them for you any more than your AI does. It may suggest a change and never makes one — a change it suggests goes through the same reviewed proposal as any other — and everything above about a doctor applies to it as it applies to your AI.

Supplements

The app tracks what you have said you take, on the schedule you set. It does not recommend a supplement, a dose or a brand, and it never infers a dose from a product name.

The few notes about taking one thing apart from another come from a small, sourced table that ships with the app; each shows its source and is about absorption, not about health. Nothing here is a claim that any of it does anything for you.

Projections, and projected pictures

Where the app projects a weight or a lift forward, it is extrapolating your own trend and says so, with a range and a confidence rather than a number. It is a description of what has been happening, continued. It is not a promise, and bodies do not read graphs.

One of those projections can now be drawn before there is a trend to extrapolate. Where you have said what you are aiming for — a target weight, the day you want it by, and how often you mean to train — the app will draw *if you hit your targets* from that declaration alone, and every place it appears says so in words: it is arithmetic on what you told it, not a reading of anything measured. It is offered at low confidence with a wider range for each thing your record does not yet say, it is never used instead of an answer your own record can give, and nothing in the app reasons from it.

A projected picture of you is made by your own AI, from a prompt the app writes out of your stated measurements. Every such picture is stored as a projection, shown with that label, never presented as a photograph, and later compared with the real one — and the comparison is the point, not the picture.

The app itself edits or generates an image only inside the features covered by the AI-features switch in Settings, only after you have turned it on, and what it makes is a rendering for sharing: it carries one discreet Perstantia logo in its own pixels, while its type, scenario and dates are stated beside it. It is stored beside your original — which is unchanged and stays the record — and it is read by nothing that computes any figure.

A theme is presentation. It sets a picture in a room, and an outfit, where one is offered, changes what is worn in it. Neither changes the body the picture was drawn with, neither is a photograph of you in that place or in those clothes, and a themed picture is read by nothing that computes any figure.

The same switch covers estimating a meal from your own description. What comes back is an estimate and is shown to you before anything is recorded — nothing is logged until you press Log — and a meal that lands this way is marked as estimated and keeps the words it was estimated from, so your record never confuses a guess with a reading.