Privacy
Privacy Policy
This Privacy Policy explains how Adaptive Strength Coach collects, uses, stores, and shares information when you use the app, website, subscriptions, support, and related services.
Last updated: August 3, 2026.
This policy is intended to be practical and robust, but it is not a substitute for solicitor review.
Contents
1. Controller and Contact
Arx Algorithms, the developer of Adaptive Strength Coach, is responsible for deciding how personal data is used for the app and website.
Contact: [email protected]
If you contact us about privacy, account deletion, data export, correction, or access, please use the email address associated with your account where possible so we can verify the request.
2. Data We Collect
The data we collect depends on how you use the service.
Account and authentication data
- email address;
- user ID and authentication identifiers;
- login/session data;
- account creation and deletion information.
Training data
- goals, experience level, schedule, equipment, and onboarding choices;
- active plans, training blocks, workout schedules, and settings;
- workout logs, exercises, sets, reps, loads, warm-ups, manual finish reasons, deleted sets, swaps, added exercises, and completion records;
- workout history, progression inputs, personal records, e1RM estimates, Strength Dashboard inputs, reports, and training summaries;
- Recovery & Capacity settings, cardio logs, ignore-this-week state, and related recommendation inputs;
- custom exercises, custom programmes, preferences, unavailable/pain-related exercise notes where you choose to enter them.
Subscription status
- premium entitlement status;
- trial status and trial period information where available;
- subscription product/package identifiers;
- renewal, expiry, restore, and purchase state supplied by the stores and RevenueCat.
We do not receive or store your full payment card details. Payments are processed through Apple App Store, Google Play, and RevenueCat.
Device, app, and diagnostics data
- device type, operating system, app version, and environment information;
- crash logs, error reports, performance diagnostics, and reliability data if enabled;
- basic website logs and technical data such as IP address, browser type, pages visited, and timestamps.
Support messages
- email messages you send to support;
- screenshots or diagnostic details you choose to provide;
- records of requests such as account deletion, restore help, or bug reports.
3. How We Use Data and Lawful Bases
Where UK GDPR or similar laws apply, we rely on lawful bases such as contract, legitimate interests, consent where required, and legal obligations.
| Purpose | Examples | Lawful basis |
|---|---|---|
| Provide the app | Create accounts, generate plans, log workouts, restore purchases, sync supported data. | Contract |
| Personalise training features | Use goals, history, settings, equipment, and workout logs to provide adaptive plans, reports, and recommendations. | Contract / legitimate interests |
| Subscriptions and access | Check premium entitlement, trial status, restore purchases, manage access. | Contract / legitimate interests |
| Cloud sync and durability | Back up and restore supported training data across devices. | Contract / legitimate interests |
| Reliability and security | Diagnose crashes, prevent misuse, protect accounts and infrastructure. | Legitimate interests / legal obligation |
| Support | Answer questions, handle deletion/export requests, troubleshoot bugs. | Contract / legitimate interests |
| Legal compliance | Keep records where required, respond to lawful requests, enforce terms. | Legal obligation / legitimate interests |
4. Subscriptions and Payment Status
Subscriptions are handled through Apple App Store and Google Play. RevenueCat is used to manage subscription status, trial status, purchase/restore state, and premium entitlement checks across platforms.
Apple and Google process payments under their own terms and privacy policies. RevenueCat helps us understand whether your account has an active entitlement, trial, cancellation, renewal, expiry, or billing issue. We do not receive full card details.
5. Cloud Storage and Sync
We use Supabase for account authentication and the cloud account profile. The app also contains cloud-sync requests for supported settings, active-plan and completed-training data. Those requests run only when you are signed in and online; unsupported or unavailable cloud tables fail closed and the training data remains local to the device.
The current live production database contains the account profile table and no file-storage buckets. Some training data therefore remains local-only. Derived reports may be rebuilt from local workout history rather than stored separately.
6. Diagnostics, Analytics, and Support
The current production app does not include a separate advertising, behavioural analytics, or crash-reporting SDK. Supabase and RevenueCat process operational events needed for authentication, cloud requests, subscription status and purchase handling. Development-only diagnostics are excluded from the production route and payload.
Support messages are used to respond to you, troubleshoot issues, verify account requests, and improve product reliability.
8. International Transfers
Some providers may process or store data outside the United Kingdom or European Economic Area. Where required, we rely on appropriate safeguards such as standard contractual clauses, adequacy regulations, provider data processing terms, or other lawful transfer mechanisms.
9. Retention
The Supabase authentication account and account-linked live database rows are retained while the account is active. After the owner confirms the automated deletion request, those live records and the linked RevenueCat customer profile are deleted immediately. The current Supabase free project has no automatic database backups.
Supabase platform logs on the current plan are retained for one day. The deletion form deliberately keeps the submitted email and one-time token out of page URLs and application logs. Routine website infrastructure logs follow Railway's plan-specific retention period; the website application does not log deletion-form email addresses, tokens, or request bodies.
Apple and Google may retain store transaction records for billing, fraud prevention, tax, and legal compliance under their own policies. Those store-controlled records are not kept in the deleted Adaptive Strength Coach account, and Arx Algorithms does not set their retention periods.
No support record is created by the automated deletion flow. If you separately contact support, correspondence is retained only as needed to answer the request, resolve a dispute, or meet a legal obligation; no fixed support-mail deletion schedule is presently configured.
10. Your Rights
Depending on your location, you may have rights to:
- access personal data we hold about you;
- correct inaccurate data;
- request deletion of your account and personal data;
- request a copy or export of your data;
- object to or restrict certain processing;
- withdraw consent where processing relies on consent;
- complain to a data protection authority.
To make a request, contact [email protected]. We may need to verify your identity before acting on a request.
You can request account deletion at /delete-account or by emailing support from the account email address.
11. Security and Children
We use reasonable technical and organisational measures to protect personal data. No system is perfectly secure, and we cannot guarantee absolute security.
Adaptive Strength Coach is not directed at children under 16. If you believe a child has provided personal data without appropriate consent, contact us so we can review and take appropriate action.
12. Changes, Complaints, and Contact
We may update this Privacy Policy from time to time. If changes are material, we will take reasonable steps to notify users, such as updating this page, updating the app, or providing in-app notice.
If you are in the UK and are unhappy with how we handle personal data, you can contact the Information Commissioner's Office (ICO): https://ico.org.uk/make-a-complaint/.
Contact: [email protected]