Security
Privacy is the architecture, not a feature.
The things you would worry about, atheo simply cannot do. It is built so that your identity never enters the system in the first place.
By design
What atheo can't see.
No facial recognition
atheo reads your body as anonymous points of movement. It never identifies a face, and it never tries to.
Nothing leaves the gym
The visual feed is processed on an edge device inside the gym. Your image never travels over the internet.
Nothing is recorded
Frames are read in real time and discarded immediately. There is no footage to store, leak, or request.
Only movement is kept
The single thing that leaves the edge device is the workout itself: the exercise, the reps, the weight on the bar.
Under the hood
How the data stays yours.
the frame is discarded the moment it is read
Read on the edge
The gym camera feeds an on-premise edge device. Our models run locally, so the visual feed never leaves the building.
Process, then discard
The model detects the exercise, counts reps, and reads the plates, then drops the frame. No recording, no facial recognition, full anonymity.
Send only the summary
Just the workout (exercise, reps, estimated weight) is sent on with TLS 1.3. It carries no image and no biometric data.
Store it locked
Your workout history sits behind 256-bit AES encryption at rest, with access controlled by authentication and authorisation.
Compliance
Honest about where we are.
Built around the privacy regulations from day one. We complete formal certifications as we approach launch, and we will not claim a badge we have not earned.
GDPR
Privacy-first design
CCPA
Privacy-first design
SOC 2
Planned
ISO 27001
Planned
Found a vulnerability?
We appreciate responsible disclosure. Tell us privately and we will work with you to keep members safe.
security@atheo.ai