PLAIN-LANGUAGE NOTICE · LAST UPDATED JULY 25, 2026
Privacy
This plain-language notice explains the current Built by Grace website, launch list, and Grace Circle private beta. It is not a claim of legal completeness and should receive professional review before a broad public launch.
What the beta stores
- Your ChatGPT sign-in email and available display name for account identity. The email is not shown in the public feed.
- The date and policy version recorded when you confirm adult eligibility and accept the current Terms and Community Guidelines.
- Profile fields you choose to add: handle, bio, fitness goal, favorite workout style, optional squad name and pronouns, music preference, optional broad location, Spotify playlist, up to three approved SiriusXM station picks, top-three handles, controlled theme and accent, current status, and favorite verse. Preset avatar and banner choices, banner crop position, alternative text, and whether that custom appearance is public or private are also stored with the profile.
- Posts, comments, Grace cheers, post reactions, reports about posts, stories, individual comments, or profiles (including an optional explanation), blocks, and self-reported workout check-ins and minutes. Video posts and stories may also keep the Spotify item type, item ID, and optional title for a separately attached soundtrack link. A profile report keeps a bounded copy of the reported profile text as it appeared when the report was sent so later edits do not erase the review evidence.
- Stories you share, their automatic 24-hour expiration time, optional photo or short-video reference, unique signed-in view count, reactions, and story reports. Viewer identities are not shown to story authors in the current beta.
- Daily interaction counters used to enforce reaction and report limits and reduce automated abuse. They record the account profile, action type, date, and count—not the content of a new message.
- Private dashboard records for the seven-day reset: program and template version, start and completion dates, status, and four daily practice checkmarks.
- Private training records you create: scheduled sessions, selected exercises and approved swaps, completed sets, repetitions, load and unit, effort rating, rest timing, completion time, and calculated personal progress estimates. The Built by Grace training log does not ask for a diagnosis, written medical note, sleep score, or soreness score.
- If you choose to import a supported TrainHeroic personal-data export, Built by Grace stores a private derived archive: import metadata, historical session payloads, exercise records derived from your personal history, imported/inferred blocks and program cycles, source labels you enter, and—only when you separately opt in—readiness responses from
readiness_survey_data.csv. Derived exercises, circuits, and programs are labeled as imported or inferred; they are not represented as TrainHeroic's complete library, an active team membership, or coach-owned content. If you separately confirm that you have publishing rights, Built by Grace can store a sanitized public copy with its source, attribution, permission confirmation time, and publication status. - If you deliberately create or join Coach Studio, Built by Grace stores the space name, mode and branding, your role and membership time, hashed expiring invite records, group or direct messages you send, program assignments, coach-library items and their visibility, optional demo-video references, short-video review requests and feedback, and coach payment-plan links. Raw invite codes are shown once and are not stored. Training-progress sharing is off until a member separately enables it and is limited to completed Built by Grace My Training records on or after the displayed sharing date. Joining never shares your imported archive or readiness responses with a coach.
- If you create, accept, or join a Grace Arena competition, Built by Grace stores the competition rules and dates, format, roster and invitation status, your name-visibility choice, opt-in time, team name, and aggregate score events derived from your own completed Built by Grace training. Standings do not publish raw sets, loads, body weight, imported history, readiness answers, medical information, or another member's private score evidence. Reports about competition rules are stored for human review.
- Uploaded image or short-video bytes plus size, dimensions when available, type, duration, moderation status, accessible description, and review notes.
- Account restrictions, report-abuse findings, suspension dates, and a moderator action history showing who took an action, the target, reason, and time.
- If you join the launch list: your normalized email, optional first name, selected program interest, signup source, consent time, and update time.
- Music favorites and recently opened playlists saved locally in your browser can include Spotify playlists and SiriusXM station destinations. Built by Grace does not receive or attach those browser-only choices to your account. SiriusXM profile picks are different: if you intentionally save up to three to your Grace profile, their approved internal station IDs can appear publicly.
- Basic security and operational logs that the hosting and identity platforms may create.
Location is optional. Use a broad area such as “Texas,” not a home address, workplace, gym schedule, or live location. Do not upload medical records or place private diagnoses in posts.
How information is used
Data supports personalized profiles, 24-hour stories, the community feed, encouragement, user-initiated Spotify embeds and official SiriusXM station handoffs, self-reported consistency rankings, safety review, abuse prevention, account controls, and service operation. It is not used to create a clinically verified health record. The current beta does not sell leaderboard placement or let purchases change scores.
Seven-day reset records provide the signed-in member’s private dashboard, daily progress, and account export. They are not used for public points, community rankings, medical monitoring, or proof that an activity occurred. The tracker does not ask for or store a written prayer, reflection, diagnosis, symptom report, or workout-generator health answer.
Training records provide the signed-in member's schedule, workout log, rest timer, adherence, volume, and estimated personal best trends. Set loads, effort ratings, and estimated bests stay private by default and are not used for a public strength ranking. Sharing a completion to Grace Circle is a separate member action and does not include private set details.
An imported training archive lets the signed-in member search and review their own historical sessions. Built by Grace derives private exercise, block, and program-like entries from that history without claiming to reproduce a coach's original library or TrainHeroic hierarchy. Imported readiness responses are optional and are not used for public rankings, medical monitoring, or new workout prescriptions. Scheduling an archived session creates a new private calendar copy without treating historical results as a newly completed workout. Public sharing is a separate action that requires a source and rights confirmation and omits workout notes, readiness data, dates, messages, and historical loads.
Coach Studio uses deliberate space membership to support team or one-to-one program assignments, a visibility-controlled custom library, group or direct messaging, opt-in training-progress summaries, and short-video feedback. A coach can see only the completed Built by Grace training progress from the member's chosen sharing date, assignments, messages, and review media authorized inside that space. Progress permission can be revoked. Coach Studio does not expose an imported TrainHeroic archive, optional readiness responses, diagnoses, broader account activity, or private records from another coaching space.
Private Coach Studio access uses a separate adult confirmation and coaching terms record. It does not require a public Grace Circle profile or community participation. Publishing coach-created content to the public Library remains a separate choice and requires the current community and publishing terms.
Launch-list information is used to provide the on-page reset download, understand which programs people want, and send Built by Grace updates or offers when email delivery is connected. Joining the list is optional.
Who can see it
Active profile and visible post information may be visible to site visitors when the community is opened. Media that passes file checks can appear immediately with a post or story. Blocking filters signed-in Grace Circle feeds, stories, and interactions in both directions, but it does not make a public profile URL private. When custom appearance is private, public visitors receive a neutral Built by Grace avatar and banner; the saved creator selections and crop position remain available only to the signed-in member and authorized operations. Reports, blocks, account emails, and moderator notes are restricted to authorized operations. Playlist previews are click-to-load. If you choose to load or open one, Spotify receives that request and its own privacy terms apply. SiriusXM station cards are external links, not embedded or relayed audio. If you open one, SiriusXM receives the request and may require your own subscription or sign-in under its terms. Built by Grace does not receive SiriusXM credentials, billing details, cookies, subscription tokens, account navigation, or listening history.
An attached soundtrack is a Spotify link and player beside a video—not music copied into, mixed with, or synchronized to the video by Built by Grace. Spotify receives a request only after a visitor chooses to load the player.
Private dashboard checkmarks are returned only to the signed-in account that created them and authorized service operations needed to maintain or protect the application. They do not appear in the community feed or leaderboard.
Imported training archives, including any readiness responses you choose to include, are private to the signed-in account and authorized service operations needed to store, export, delete, or protect those records. They do not create a public team or coaching relationship. Only a separately reviewed, sanitized copy becomes public after the member confirms the source and that they have the rights needed to publish it.
Coach Studio spaces are visible only to their owner and active members. Space owners can manage invitations, members, assignments, visibility-controlled library items, progress summaries a member explicitly enabled, review feedback, branding, and coach payment-plan links. Members can see that space's roster, messages addressed to their group or direct coach conversation, team-visible library, and active plans, plus their own assignments and video reviews; they cannot see another member's private training progress or review submissions. Messages are access-controlled but are not end-to-end encrypted. Leaving a space or being removed ends future access and deletes that membership's assignments and review records. Messages already sent remain in the space until the author deletes their profile or the owner deletes the space. An unlinked uploaded clip remains in its owner's media records until that owner separately deletes the media or account.
Grace Arena competitions are visible only to their owner, invited members, accepted participants, and—after human approval—signed-in members browsing a public season. An athlete must explicitly accept or join before a score exists. Athletes may hide their display name while remaining in aggregate standings. Team and individual standings show points and generic evidence labels, not the private workout values used to calculate them. Blocking removes access between affected profiles. Public competition submissions remain non-public until a moderator approves them.
Storage, limits, and security
Structured community records use hosted database storage; images and short videos use private object storage and are served through an access-controlled route. Uploads are limited by type, signature, dimensions, file size, daily count, account count, account storage, and bounded interaction counters. Accepted still-image containers are rebuilt to remove common metadata chunks before storage. Short-video upload is disabled by default and requires both a server-side enablement flag and an exact signed-in email on the server-side beta allowlist. The short-video beta validates a conservative MP4 structure, declared codec, size, and duration, but does not yet provide managed transcoding or malware scanning. No online system can promise perfect security.
The music hub uses browser storage for your optional Spotify playlist link, favorite and recently opened curated Spotify playlists, and approved SiriusXM station IDs. Explore uses the same kind of browser-only storage for interest order, private quest checkmarks, and personal Momentum. Those preferences stay on that browser until you clear its site data. They are not included in account export or deletion because they are not stored in the Built by Grace account database. SiriusXM stations intentionally added to a public Grace profile are stored with that profile, included in its account export, and removed with the profile.
To keep an active workout usable during a temporary connection loss, Built by Grace stores a limited device copy of today's or active session, unsynced set and note changes, rest-timer state, and a stable completion request on that browser. The device copy expires after seven days, does not enter the browser cache used for public pages, and is replaced only after newer changes are reconciled. The account database remains authoritative after synchronization. Clearing site data removes this device-only recovery copy before it can sync.
Unsaved Custom Workout and Plan Builder drafts are also stored only in this browser so a refresh does not erase your work. A Plan Builder draft can include the safety, limitation, and optional body information you entered. These device drafts are cleared by browser site-data controls and by Built by Grace account sign-out or deletion cleanup when available.
The TrainHeroic ZIP is opened and parsed locally in your browser. Built by Grace does not upload or retain the raw ZIP. The importer sends only the derived records needed for your private archive from training_data.csvand, if you opt in, readiness_survey_data.csv. It excludessent_messages.csv, user_info.csv, andnutrition_data.csv; those files are not added to Built by Grace.
Coach Studio invite codes are hashed before storage, expire, have limited uses, and can be revoked. Short MP4 review clips use private object storage and an access-controlled media route. Automatic invite email, push notifications, true instant messaging sockets, managed long-video transcoding, marketplace entitlements, and coach payouts are not connected in the current beta.
A coach-owned payment-plan record can include the coach-stated amount, currency, billing type, description, cancellation, refund, and optional trial terms; the selected Stripe, PayPal Business, or Square checkout link; publication status; and the date and policy version of the coach's checkout attestation. Built by Grace does not receive or store card numbers, bank details, provider passwords, security codes, or provider tokens from that link. Built by Grace does not currently receive payment, refund, dispute, payout, or subscription status because signed provider webhooks and marketplace payment integrations are not connected.
Export and deletion
Signed-in members can download a JSON export and use Delete Built by Grace data from the profile controls. Deletion removes the active profile, posts, stories, views, reactions, reports, community check-ins, private seven-day reset and training records, imported training archive metadata, sessions, derived items, optional readiness records, Coach Studio spaces or memberships, and stored community photos and videos; it does not delete the person’s underlying ChatGPT account. Hosting-provider security logs or backups may follow separate, limited retention outside the app’s direct controls.
The profile row in the JSON export includes saved avatar and banner presets, crop position, alternative text, appearance visibility, and optional training, squad, music, and pronoun fields. Deleting the profile removes these settings from active storage with the rest of the profile.
The member JSON export includes the private derived training archive and any sanitized copies the member chose to share. Deleting the profile cascades through all five archive record groups—imports, sessions, derived items, readiness, and shared copies—so they are removed from active application storage. The original TrainHeroic ZIP is not part of export or deletion because Built by Grace never retains it.
The export also includes Coach Studio settings you own, your memberships and authored messages, assignments and video-feedback exchanges you can access, and library or coach payment-plan records in a space you own. It excludes raw invite codes, invite hashes, and media bytes. A space owner's export can contain member-submitted review titles, notes, feedback, and media metadata already available to that owner. Deleting your profile deletes an owned space and all of its shared messages, assignments, library records, review metadata and feedback, and coach payment plans; if you are a member, it removes your membership, assignments, submissions, and authored messages while preserving other members' accounts. Separate Shopify or other service accounts are unchanged.
Built by Grace may retain a keyed, one-way identity enforcement token for a permanent ban, an unexpired temporary suspension, confirmed abusive-report findings, or an active reporting restriction. This prevents deleting and recreating an application profile from bypassing an active safety action. The token is not displayed publicly or included in member search. A moderator can lift a ban or suspension after a verified appeal; confirmed report-abuse history may remain for abuse prevention.
Launch-list subscribers may unsubscribe from a future email using the unsubscribe control included with that message. Before automated email delivery is connected, a subscriber may request removal through the same owner contact channel used for Built by Grace support. Only the relevant email address is needed for that request.
The public account-deletion page explains the same browser-based process without requiring the installed app. If self-service deletion fails, use the support path shown there and provide only the account handle. Do not send passwords, identity documents, medical records, or payment details.
Adults and changes
Grace Circle is limited to people age 18 or older. Posting and uploads stay locked until a signed-in member confirms adult eligibility and accepts the current Terms and Community Guidelines. This notice may change as moderation, public access, commerce, or new media types are added. Material changes should be shown in the product before they apply broadly.