Back to Sweatr

Privacy policy

Sweatr holds your training, your body and who you train with. This page says exactly what we keep, why we keep it, who else ever touches it, and how to take it all back.

Last updated 8 September 2026 Applies to the Sweatr app and getsweatr.com

The short version

Nothing is public unless you make it public.Every activity you log starts private. Friends, groups and professionals see what you open to them, one setting at a time.

Your health data is encrypted before it is stored.Weight, training notes, GPS routes and physio bookings are sealed with a key the database itself does not hold. Every time one is decrypted, we log it.

We do not sell data, and we run no ad or analytics SDK.There is no tracker in the app. Nobody buys a profile of you from us, because we do not build one.

You can export or erase everything.Email us and we do it. Erasure is real deletion, not a hidden flag.

Who we are

Sweatr is a training and wellbeing app: you log your sessions, you follow your progress, and you connect with the coaches, physiotherapists and nutritionists you work with. Sweatr is the data controller for everything described here, which means we decide what is collected and we answer for it.

Write to us at:

privacy@getsweatr.com

This policy covers the Sweatr mobile app and the getsweatr.com website. It does not cover a professional's own records: once you book a physiotherapist, whatever they write in their own clinical system is theirs, under their own policy.

The terms of use are the other half of the agreement: what the app does, what it does not do, and the rules everyone signs up to.

Read the terms of use

What we collect

We collect what the app needs to work, and we classify every field before it is stored. Nothing here is inferred, bought, or pulled from another service.

DataWhy we have itStorage
Email addressSigning in, verifying your account, service mailEncrypted
Display name and handleHow other members find and recognise youPlain text
Profile photo and cover imageYour profile cardPlain file
Bio and genderOptional profile details you choose to fill inEncrypted
Body weightOptional. Feeds the calorie estimate on a sessionEncrypted, audited
Activities: sport, date, duration, distanceYour training log and your progress chartsPlain text
Activity notes and free-text locationOptional. How a session felt, where it happenedEncrypted
GPS route of a tracked sessionOptional. Drawing the map of a run or a rideEncrypted, audited
Bookings with a professionalRequesting, confirming and showing appointmentsEncrypted, audited
Friends, follows and group membershipSharing sessions and running challenges togetherPlain text
App settings and notification preferencesKeeping the app the way you set itEncrypted
Push notification tokenDelivering a notification to your devicePlain text
Technical logsKeeping the service up and investigating abuseRecord identifiers only

Our logs never contain an email address, a name, a note or anything decrypted. They record identifiers, so we can debug a problem without reading your training.

Location

Sweatr asks for location permission for three things. It never reads your position in the background unless you started a tracked session yourself.

  • Finding professionals near you. Your position becomes a search radius. We do not store it.
  • Placing a pin on an activity you host, so other members know where to turn up. That pin is public by design, and the app only lets you set one on a public activity.
  • Recording the route of a session you are tracking, while the session is running.

Recorded routes are the most identifying thing in the app: a route shows where you live, where you work and when you are out. They are encrypted at rest, every read is logged, and they are never shown to anyone but you unless you publish the activity.

You can refuse the permission and keep using Sweatr. You lose route tracking and distance-based search, nothing else.

Health data

Some of what Sweatr holds is health data under Article 9 of the GDPR, and it gets stricter treatment than the rest.

  • Your body weight.
  • Training notes, which often mention pain, injury or how a body felt.
  • Bookings with a physiotherapist, which say something about your health simply by existing.
  • Anything a professional records about you inside Sweatr, once that feature ships.

We process it on your explicit consent, which you give by entering it. Every field above is optional. Every one is encrypted with a separate key. Every decryption writes an audit entry naming who read it and when, and those entries cannot be edited or deleted by anyone, including us.

Why we use it

Each purpose below has a legal basis under the GDPR. We do not repurpose data for something you did not sign up for.

PurposeLegal basis
Running your account and the features you usePerformance of our contract with you
Health data: weight, notes, routes, bookingsYour explicit consent
Sending push notifications and service emailPerformance of our contract, and your device permission
Keeping the service secure and handling abuse reportsOur legitimate interest in a safe service
Keeping access and erasure audit trailsOur legal obligation to demonstrate compliance

Where consent is the basis, you can withdraw it by deleting the data or the account. Withdrawing does not undo processing that already happened, but it stops anything further.

Who can see it

Sweatr is social, so some data is meant to travel. It travels only where you send it.

Other members

Your handle, display name and profile picture make up your public card, and anyone can find them. Everything else follows the visibility you set on it: private, friends, group, or public. An activity you keep private stays private.

Professionals

A coach, physiotherapist or nutritionist sees only what a booking or a share gives them. Being listed in the directory does not give a professional a view of anybody, and neither does having worked with you before.

Administrators

Our administrators can read a limited set of data to investigate an abuse report or a support request. That access is logged in the same audit trail as everything else.

Nobody else

We do not sell personal data. We do not share it with advertisers, data brokers or partners. There is no advertising or analytics SDK in the app.

Companies we work with

A handful of services process data on our behalf, each under a contract that limits them to what we ask for.

ServiceWhat it handlesWhere
Google Firebase AuthenticationYour sign-in credentials, email and nameGoogle infrastructure, under standard contractual clauses
Google Firebase Cloud MessagingDelivering push notifications to your deviceGoogle infrastructure, under standard contractual clauses
MapboxTurning an address into coordinates for searchAddress text only, never tied to your account
OpenStreetMapMap tiles shown while you place a pinSees your device IP address, no account data
Our mail providerSending verification and notification emailEmail address and message only

Everything else runs on our own servers. Your training log, your routes, your notes and your bookings never leave our infrastructure.

Where it lives and how it is protected

Sweatr runs on servers in France, in the European Union. Your training data, your health data, your files and your backups stay there. The one exception is your sign-in credential, which Google holds through Firebase Authentication and may process outside the EU under standard contractual clauses.

Encryption

Sensitive fields are encrypted individually before they reach the database, each with its own key that is itself sealed by a key held in a separate vault. Someone who walked away with the whole database would hold ciphertext and nothing else. Files are stored encrypted, backups are encrypted, and traffic between your device and us is TLS end to end.

Access logging

Every decryption of health or personal data appends an entry recording who did it, on which record, and when. Those entries are append-only: no part of our code can change or remove one.

Access rules

By default, data can only be read by the person it belongs to. Where a feature needs to widen that, the exception is written down, reviewed and tested. A request for something you may not see answers as if it did not exist, so nobody can probe the service to learn who is on it.

How long we keep it

  • Account and training data: for as long as your account exists.
  • After you delete your account: erased from our live systems immediately. An encrypted backup archive made before that is never used to bring the account back, and goes when the archive expires.
  • Audit trails: kept for as long as the service runs. They hold an account identifier, the record touched and a timestamp, never a name or anything you wrote. They outlive an erased account on purpose: they are the proof the erasure happened.
  • Waitlist email addresses from this website: until launch, or until you ask us to drop yours.

Delete an individual activity, note or route at any time and it goes immediately, without waiting for the account to go with it.

Your rights

Under the GDPR you can ask us to do any of the following, and we answer within one month.

  • Access. A copy of everything we hold about you, in a machine-readable file.
  • Rectification. Correct anything wrong.
  • Erasure. Delete your account and everything owned by it.
  • Portability. Take that export elsewhere.
  • Restriction and objection. Tell us to stop a specific use.
  • Withdraw consent. For health data, at any time.

Write to the address below and we handle it by hand. Export and deletion from inside the app's settings are being finished; this page will say so when they are live. We never charge for a request, and we never ask why.

If you think we have handled your data badly, you can complain to your national data protection authority. We would rather you told us first.

Age

Sweatr is for people aged 16 and over. We do not knowingly collect data from anyone younger, and we set the bar at 16 because that is the highest digital consent age in the EU and because the app holds health data. If you believe a child has an account, write to us and we will remove it.

The website itself

getsweatr.com sets no cookies and runs no analytics. There is no tracking pixel, no consent banner to click through, and no third-party script beyond the font files the page loads from Google Fonts.

Two things are stored in your browser, and both stay there: the language you picked with the switcher, and the email address you type into the waitlist form. The waitlist has no server behind it yet, so that address is written to your own browser and goes nowhere else. When we do wire it up, this page will say so before a single address is sent.

Changes to this policy

When we change something material, we update the date at the top of this page and tell you in the app before the change takes effect. Small corrections such as fixing a typo or naming a service more precisely get the new date and nothing more.

Contact

Questions about this policy, or a request about your data:

privacy@getsweatr.com

A real person reads that address.