Legal

Privacy Policy

Effective March 20, 2026

What this service does

OTF Platform ("the Service") lets you connect your Orangetheory Fitness account so that AI assistants — such as ChatGPT (OpenAI) and Claude (Anthropic) — can answer questions about your workouts, class schedule, membership, and progress.

Data we collect

When you link your Orangetheory account, the Service syncs and stores the following categories of data:

  • Profile information — name, email address, phone number, home studio
  • Membership details — membership tier and status
  • Class data — upcoming bookings, available classes, studio information
  • Workout history — dates, calories, splat points, heart-rate zones, treadmill and rower metrics
  • Progress stats — aggregated performance over 7-day, 30-day, 90-day, yearly, and lifetime windows
  • Challenges and benchmarks — participation records and personal records
  • Body composition — InBody scan results (body fat %, muscle mass, BMR) and Transformation Challenge measurements

How data is stored

  • Data is stored in a PostgreSQL database hosted on Heroku.
  • Orangetheory authentication credentials are encrypted at rest.
  • All connections use HTTPS/TLS.
  • A session cookie keeps you logged in. A CSRF token protects form submissions. No tracking or advertising cookies are used.
  • IP addresses are used for rate limiting but are not stored.

How data is shared

When you use the Service through an AI assistant, your fitness data is sent to that assistant's provider as tool responses. This means:

  • OpenAI receives your data when you use the Service through ChatGPT.
  • Anthropic receives your data when you use the Service through Claude.

The Service does not sell your data or share it with any other third parties.

Data retention and deletion

  • Your data is retained as long as your Orangetheory account is linked.
  • You can remove your data at any time. This only removes data stored on OTF Platform — your Orangetheory Fitness account is not affected.
  • Once deleted, data is permanently removed from the database.

Your rights

  • Access your data via the dashboard or AI assistant tools at any time.
  • Remove your data and permanently delete all synced information.
  • Revoke AI assistant access by revoking the OAuth token from your dashboard.

Contact

For questions about this privacy policy or your data, reach out at [email protected].

This policy may be updated from time to time. Changes will be reflected on this page with an updated effective date.

John =) Contact Guide Privacy Terms Remove Data