TrainUp is a training app: you log sets, reps and weight, and the app gives you back your progress. For Your private history is stored on your device; only data needed for your account, social features, purchases and features you enable leaves it. This policy explains what is processed, where, why and for how long.
1. Who processes your data
The data controller is TrainUp, developer of the TrainUp app for iOS. You can reach us about anything related to your data — including exercising your rights — at victxrgxnzalez@gmail.com.
2. Your account
The first time you open the app, an anonymous session is created: an account with no email and no password, which provides an identity for online features. We ask for no personal data before you start training.
When you choose to link an email and a password, that same account becomes recoverable — that is what lets you sign back into that account. From then on we process your email address, and we use it only to identify you at sign-in and to reset your password. We do not send marketing email to that address.
We do not know your password: it is handled by our authentication provider and stored hashed, never in plain text.
3. What stays on-device and what we store on servers
| Category | What it includes |
|---|---|
| Identity | Account identifier, email address if you link one, display name and username if you fill them in. |
| Public profile and Community | Display name, username, bio, follows, posts and their photos, reactions, comments, invitations, reports and blocks. |
| Workout posts | Only when you post: a summary prepared by the phone and your chosen audience. Your full history is not uploaded. |
| Shared steps | If you enable friend comparison: the daily total, without hourly segments, route or source. Turning it off deletes shared totals. |
| Purchase | Whether TrainUp Pro is active, the product and its expiry. See section 7. |
| Consents | Document, version, language, date and withdrawals. |
| Notifications | Push notification identifier, only if you grant permission. |
| Product analytics | Pseudonymous identifier, screens, lifecycle and limited usage events, without content or health data. See section 8. |
Private workouts, routines, sets, records, weight, measurements, weekly reviews, scan results, food diary and goals live in the device's local database. Deleting the app deletes that copy and a linked account does not restore it.
4. Health data and your explicit consent
Your sex, bodyweight, measurements and food diary are health-related data under Article 9 of the GDPR. They are treated separately because of that:
- We ask for them with an explicit consent, separate from the one for the terms and this policy, during onboarding.
- That consent is recorded with its date and the version of the document you were shown, and you can withdraw it at any time by contacting us.
- They are not used for profiling with legal effects, are never shared with advertisers, and are used only to compute what you see.
- They never go to analytics. Weight, sex, meals, workouts and HealthKit values are excluded by design.
Withdrawing consent does not retroactively erase what was already lawfully processed, but it stops processing going forward. If you also want it deleted, delete your account (section 14).
5. Photos and camera
The app may ask for camera or photo-library access for private exercise photos, photos you choose to publish, and body or food analysis. Private photos remain on-device. Photos you publish are stored with the post until you remove it or delete your account.
Analysis photos are sent encrypted through our API to OpenAI. TrainUp does not store them: they are deleted from the phone after a verdict and are not written to our database or logs. OpenAI may retain abuse-monitoring logs containing content for up to 30 days and does not train on API data by default. Only the result is kept locally. Text and images you attempt to post are also sent to OpenAI to detect harmful content.
6. Notifications
If you grant permission, the app schedules local alerts (for example, the end of a rest timer) that never leave the device. It also registers a push notification identifier issued by Apple, needed for alerts sent from the server. You can revoke the permission in iOS Settings at any time; the identifier is deleted when you delete your account.
7. Purchases and subscription
TrainUp Pro is purchased inside the app. Payment is processed by Apple: we never see or store your card, your Apple ID or your billing address. To know what you bought we use RevenueCat, which receives your TrainUp account identifier — a UUID, not your email — the product identifier, the subscription status and technical device data (model, OS version, store country).
The result — whether you have Pro and until when — is stored in our database. The app decides what you can use by reading that record, never by asking the store.
8. Analytics and diagnostics
We use PostHog on its European infrastructure to measure screens, launches and a closed catalogue of actions such as completing onboarding, a workout, a scan or a purchase. It receives a pseudonymous account identifier. We do not send email, username, content, photos or health data.
Session replay, automatic touch capture and IP geolocation are disabled. Technical API logs contain status, route, duration and model usage, never photos or social text.
9. What we don't do
- We do not sell your data, and we do not pass it to data brokers.
- There are no ads in the app, no advertising identifiers, no third-party pixels.
- We do not track you across other apps or websites. The app declares no tracking in its iOS privacy manifest and never requests the tracking (ATT) permission.
- We do not access your location, calendar or microphone.
- The contact picker shows one person you choose to prepare an SMS; TrainUp does not enumerate, store or upload your address book.
- HealthKit is read-only and shows steps. Only the daily total is uploaded if you voluntarily enable friend comparison.
10. Providers and where the data lives
| Provider | Purpose | Location |
|---|---|---|
| Supabase (on AWS) | Database and authentication | EU — Paris (eu-west-3) |
| Cloudflare | AI API, moderation, technical logs and catalogue images | Global network |
| OpenAI | Photo analysis and moderation of content you attempt to post | United States / global |
| PostHog | Pseudonymous product analytics | EU |
| RevenueCat | Subscription status | United States |
| Apple | Payments, App Store and push delivery | Global |
| Expo | Push notification delivery | United States |
| Vercel and Resend | This website and its waitlist | EU / United States |
Exercise catalogue images are served from public, read-only storage: they are photos of exercises, they contain nothing about you, and requesting one reveals nothing about who you are.
11. International transfers
Private training, measurement and nutrition data remains on your device. Providers outside the European Economic Area (OpenAI, RevenueCat, Expo and Apple) process the subset described in this policy under the Standard Contractual Clauses approved by the European Commission or an equivalent adequacy framework.
12. Legal bases
| Processing | Basis (GDPR) |
|---|---|
| Account, social features and moderation | Performance of a contract and legitimate interest — Arts. 6(1)(b) and 6(1)(f) |
| Weight, sex, measurements and nutrition | Explicit consent — Art. 9(2)(a) |
| Purchases and Pro access control | Performance of a contract — Art. 6(1)(b) |
| Limited analytics, diagnostics and abuse prevention | Legitimate interest — Art. 6(1)(f) |
| Consent records | Legal obligation — Art. 6(1)(c) and Art. 7(1) |
13. How long we keep it
- For as long as you have an account. We keep account, social content and purchases; private history follows your device's retention.
- When you delete your account, your data is removed from the database within 30 days at most, including rotating backups.
- OpenAI may keep abuse-monitoring logs for up to 30 days.
- The consent ledger survives deletion in dissociated form, because it is the proof that consent existed and Art. 7(1) requires us to be able to demonstrate it.
14. Deleting your account
From inside the app: Profile → Settings → Account → Delete account. No need to write to us, no form to fill in, and it cannot be undone. Your profile, workouts, measurements, food diary, posts and social relationships are all deleted.
Deleting your account does not cancel your subscription: subscriptions are managed by Apple and cancelled in iOS Settings → your name → Subscriptions.
15. Your rights
You may exercise at any time the rights of access, rectification, erasure, restriction, portability and objection, and withdraw any consent you have given. Most of them you can exercise yourself inside the app: the data is editable and the account is deletable.
For everything else, write to victxrgxnzalez@gmail.com. We reply within the one-month period the GDPR sets. If you believe we have not handled your request properly, you may lodge a complaint with your supervisory authority — in Spain, the Agencia Española de Protección de Datos.
If you are a California resident: we do not sell or share personal information as defined by the CCPA, and you have the right to know and to delete your data through the same channels described above.
16. Children
TrainUp is not directed at children under 16 and we do not knowingly collect data from anyone under that age. If we find such an account, we delete it. If you are a parent or guardian and believe one exists, write to us and we will remove it.
17. This website
The TrainUp website uses no tracking cookies and no analytics. If you join the waitlist, we store your email and language with Resend for the sole purpose of telling you when we launch. You can unsubscribe from any of those emails or by writing to us.
18. Security
Traffic between the app and our servers is encrypted (TLS). Access to data is restricted by row-level security rules in the database itself: a user can only read and write their own rows, and that restriction is enforced by the server, not by the app. No system is infallible, but that is the design.
19. Changes to this policy
If we change something material, we raise the version number shown above and the app asks you to read it again before continuing. Minor changes are reflected by updating the date.
20. Contact
Any question about this policy or about your data: victxrgxnzalez@gmail.com.