DYLD — Get Dialed Last updated: August 31, 2026
This policy is for residents of Washington State and is published under the My Health My Data Act (RCW 19.373). Residents of Nevada (SB 370) and Connecticut have substantially the same rights described here, and we honor them the same way.
It is a separate document on purpose. The law requires consumer health data to be described on its own, not folded into a general privacy notice. Our full Privacy Policy covers everything else and does not replace this one.
Everything you write stays on your phone. Your training log, your food log, your journal and your check-ins are stored in a database on your device. We cannot see them, we have no copy, and nobody here can retrieve them.
Three things about you are stored on our servers, and they are health data, so they are named here first rather than buried:
Sections 4(a) and 4(b) say exactly what is in each and why.
Three more things you choose to do send health data off your device for one request only: asking the AI coach a question, scanning a meal photo, and speaking a food log. Each exists for the length of that single request and is not stored — not by us, and not by the provider that processes it.
We have never sold consumer health data and we never will. We do not use it for advertising, we do not share it with data brokers, and we operate no geofence of any kind.
The law defines consumer health data broadly. In DYLD, these categories qualify:
| Category | What it is in the app |
|---|---|
| Bodily measurements | Bodyweight, age band, personal records, lifts, sets, reps, strength history |
| Exercise and fitness activity | Workouts, routines, training plans, completed sessions, your W–L record |
| Nutrition and food consumption | Food logs, meals, calories, macros, protein targets, barcode scans, meal photos |
| Mental and behavioral health | MIND check-ins, the state you pick, journal entries and free-writes, reflections |
| Health-related goals | What you tell us you are trying to change about your body or your habits |
| Data that could be inferred | Anything about your physical or mental health reasonably derivable from the above |
Faith content (WORD) is not health data, but we treat your decision about it with the same care. Your verses, notes and sessions never leave your device. Whether the WORD pillar is switched on does travel, because the list of pillars you turned off is part of the account backup in section 4(a) — which is why the App Store privacy label declares a sensitive category. Nothing about your religion is ever asked or stored.
We collect consumer health data from exactly one source: you, typed, spoken, photographed or tapped into the app.
The following is written to a database on your phone and is never transmitted to us:
This is the part a new phone does not get back. We keep no backup of it and cannot restore it. What a new phone does get back is section 4(a), which is a much smaller thing.
⚠ A correction to an earlier version of this policy. Until 2026-08-31 this section also listed your plan, your W–L record and your profile answers, and stated that your date of birth never reached our servers. That stopped being true on 2026-08-17, when the account backup was built so a reinstall would not wipe a man's system. This policy did not catch up until 2026-08-31, and the correction is printed here rather than quietly edited out. Section 4(a) describes what is actually stored.
Your account holds a backup of your system so a new phone does not hand you an empty app. Three things travel, and all three are consumer health data:
| What is stored | Why | How long |
|---|---|---|
| Your body facts and answers — date of birth and age band, sex, height, weight, activity level, pillars you turned off, session length, food constraint and the note you wrote about it | So your plan can be rebuilt on a new device without asking you everything again | Until you delete your account. One current copy, overwritten on change — not a history |
| Your plan — your commitments, the promise you wrote in your own words, your daily blocks | Same | Same |
| Your W–L record — date, result, and which blocks you finished, day by day | It is the thing you cannot rebuild, and losing it is the failure this backup exists to prevent | Same |
Nobody reads it. It is scoped to your own account by a database policy, there is deliberately no administrator path to it, and nothing is derived from it, sold, or used for advertising.
Your win/loss totals are also published to Crew and are visible to every other member, alongside your display name and profile picture. That is section 4(c) of the Privacy Policy, and it is the one piece of your health data other people can see.
| What is sent | When | Why | Retained? |
|---|---|---|---|
| Recent training, food numbers, MIND check-ins, journal entries from the last 7 days in your own words, goals, onboarding answers, and the coach's recent notes and messages | Only when you ask the AI coach a question | So the answer is about your actual life instead of generic advice | No. Exists for one request, then gone |
| A photo of a meal | Only when you take one to scan | To estimate what is in it | No. One request, then gone |
| A transcript of what you said you ate (speech becomes text on your phone; the audio never leaves it) | Only when you speak a food log | To estimate what you ate | No. One request, then gone |
| A barcode number | Only when you scan one | Food lookup against a public database | No |
If you never open the coach, never scan a meal and never speak a log, nothing in this table ever leaves your phone. Section 4(a) is separate and is not something you opt into: the account backup happens because DYLD requires an account.
Anything you type into Crew is a public post. If you write there about your training, your weight, your eating or your state of mind, you are publishing it to other members, and it is stored on our servers so the community works. Crew is 13+, so assume anything you post there can be read by a member who is a minor, and by every other member.
We do not sell consumer health data. We have never sold it, we do not offer it for sale, and we will not sell it. A sale would require your separate written authorization under RCW 19.373.030. We have never asked for one and do not intend to.
We share consumer health data only with processors acting on our instructions, under contract, and only for the purposes below:
| Third party | Category | What it receives | Purpose |
|---|---|---|---|
| OpenRouter | AI routing | Coach questions with your numbers and recent journal entries; meal photos; spoken food transcripts | Routes each request to the right model |
| OpenAI (or Microsoft Azure) | US-hosted AI provider | The same, for the model that writes the coach's answers | Generates what the coach says |
| DeepInfra, Parasail | US-hosted compute providers | Meal photos, spoken food logs, and the coach's background decisions | Runs the Qwen model |
| Supabase | Cloud hosting | Your account and anything you post in Crew | Hosts the community |
| Open Food Facts | Public food database | Barcode numbers only | Food lookup |
| Apple | Platform | Sign in with Apple, subscription status | Sign-in and payment |
| PostHog | Product analytics | Named events recording that you logged food, trained, checked in or asked the coach, plus your one-word MIND state and your chosen training goal, tied to your account ID. Never text you wrote | Understanding which parts of the app get used |
| Sentry | Crash reporting | Crash diagnostics. Not your entries | Fixing crashes |
| Expo | Push delivery | A device push token, only if you enable notifications | Delivering notifications |
We route only to US-hosted providers contractually barred from retaining your data or training on it, and this is enforced in code rather than only on paper — the allowed hosts and a deny-collection setting are pinned in the app's server code, per model, so a change to that list is a change to this policy.
Two models handle a coach turn. The one that writes every word you read is OpenAI's GPT-5 mini, run by OpenAI or Microsoft Azure in the United States; OpenAI does not train on API traffic. The one that decides — the safety check, what you are asking, which of your numbers to look up — is Qwen, and it also handles meal photos and spoken food logs. Qwen's weights were developed in China by Alibaba and it runs on servers in the United States at DeepInfra or Parasail. Your photos, questions and journal entries are not sent to China. The deciding model never writes anything you read.
We have no affiliates. DYLD is operated by one person. If that changes, this policy is updated before it does.
We do not share consumer health data with advertisers or data brokers, and we never use it for targeted advertising. We share none of it for money, and none of it for anyone else's purposes.
We do share a narrow slice with our analytics processor, and we will not pretend otherwise. The PostHog row above is health data under this law — events saying you trained or checked in, and the one-word mood you tapped. PostHog processes it on our instructions under a signed data processing agreement, in the United States, and may not use it for its own purposes. If you would rather it did not happen at all, deleting your account stops it, and section 7 covers your right to withdraw consent.
We do not, and will not, operate a geofence around any health care facility — or anywhere else. The app does not request location permission and collects no location data of any kind.
You have the right to:
Two ways to exercise them:
Our timeline: we respond within 45 days. If we need more time we will tell you why inside those 45 days and take up to 45 more.
We will never charge you for this, and never treat you differently for asking.
If we say no, we will tell you why, and you may appeal by replying with the word "Appeal." A separate review is done and you get a written answer within 45 days. If we deny the appeal, we will give you a link to file a complaint with the Washington State Attorney General at atg.wa.gov/file-complaint.
Deleting your data ends your ability to use the parts of DYLD that depend on it. That is a consequence of the deletion, not a penalty for asking.
Your account and Crew data sit behind row-level security policies, so one user's data is not reachable by another. Traffic is encrypted in transit. Server-side keys never ship inside the app. No system is perfectly secure, and we will not claim otherwise. If a breach affects your information, we will notify you and the appropriate authorities as the law requires.
If we change the categories of consumer health data we collect, who we share it with, or what we use it for, we will update this policy and obtain your affirmative consent before the new practice starts. We do not apply new uses to data already collected without asking first.
We did not meet that standard once, and it is written down here rather than left out. The account backup in section 4(a) started collecting body facts, plans and W–L records on 2026-08-17, and the product-usage analytics in section 4(d) widened on 2026-08-31. This policy did not describe either until 2026-08-31. During that window DYLD had not launched and its only accounts belonged to a small closed beta. None of that data was sold, shared with an advertiser or a data broker, or used for any purpose beyond the two described here — but the disclosure was late, and the correction is printed in sections 3 and 4 rather than quietly absorbed.
DYLD is operated by RJ Galasieski, San Diego, California, United States.
The legal terms in our Terms of Use — including arbitration and the class action waiver in section 13 — apply to disputes about this policy. Nothing in them waives a right this law gives you that cannot be waived, and exercising any right described here will never be held against you.