Who we are
Sweatr is a training and wellbeing app: you log your sessions, you follow your progress, and you connect with the coaches, physiotherapists and nutritionists you work with. Sweatr is the data controller for everything described here, which means we decide what is collected and we answer for it.
Write to us at:
privacy@getsweatr.comThis policy covers the Sweatr mobile app and the getsweatr.com website. It does not cover a professional's own records: once you book a physiotherapist, whatever they write in their own clinical system is theirs, under their own policy.
The terms of use are the other half of the agreement: what the app does, what it does not do, and the rules everyone signs up to.
Read the terms of useWhat we collect
We collect what the app needs to work, and we classify every field before it is stored. Nothing here is inferred, bought, or pulled from another service.
| Data | Why we have it | Storage |
|---|---|---|
| Email address | Signing in, verifying your account, service mail | Encrypted |
| Display name and handle | How other members find and recognise you | Plain text |
| Profile photo and cover image | Your profile card | Plain file |
| Bio and gender | Optional profile details you choose to fill in | Encrypted |
| Body weight | Optional. Feeds the calorie estimate on a session | Encrypted, audited |
| Activities: sport, date, duration, distance | Your training log and your progress charts | Plain text |
| Activity notes and free-text location | Optional. How a session felt, where it happened | Encrypted |
| GPS route of a tracked session | Optional. Drawing the map of a run or a ride | Encrypted, audited |
| Bookings with a professional | Requesting, confirming and showing appointments | Encrypted, audited |
| Friends, follows and group membership | Sharing sessions and running challenges together | Plain text |
| App settings and notification preferences | Keeping the app the way you set it | Encrypted |
| Push notification token | Delivering a notification to your device | Plain text |
| Technical logs | Keeping the service up and investigating abuse | Record identifiers only |
Our logs never contain an email address, a name, a note or anything decrypted. They record identifiers, so we can debug a problem without reading your training.
Location
Sweatr asks for location permission for three things. It never reads your position in the background unless you started a tracked session yourself.
- Finding professionals near you. Your position becomes a search radius. We do not store it.
- Placing a pin on an activity you host, so other members know where to turn up. That pin is public by design, and the app only lets you set one on a public activity.
- Recording the route of a session you are tracking, while the session is running.
Recorded routes are the most identifying thing in the app: a route shows where you live, where you work and when you are out. They are encrypted at rest, every read is logged, and they are never shown to anyone but you unless you publish the activity.
You can refuse the permission and keep using Sweatr. You lose route tracking and distance-based search, nothing else.
Health data
Some of what Sweatr holds is health data under Article 9 of the GDPR, and it gets stricter treatment than the rest.
- Your body weight.
- Training notes, which often mention pain, injury or how a body felt.
- Bookings with a physiotherapist, which say something about your health simply by existing.
- Anything a professional records about you inside Sweatr, once that feature ships.
We process it on your explicit consent, which you give by entering it. Every field above is optional. Every one is encrypted with a separate key. Every decryption writes an audit entry naming who read it and when, and those entries cannot be edited or deleted by anyone, including us.
Why we use it
Each purpose below has a legal basis under the GDPR. We do not repurpose data for something you did not sign up for.
| Purpose | Legal basis |
|---|---|
| Running your account and the features you use | Performance of our contract with you |
| Health data: weight, notes, routes, bookings | Your explicit consent |
| Sending push notifications and service email | Performance of our contract, and your device permission |
| Keeping the service secure and handling abuse reports | Our legitimate interest in a safe service |
| Keeping access and erasure audit trails | Our legal obligation to demonstrate compliance |
Where consent is the basis, you can withdraw it by deleting the data or the account. Withdrawing does not undo processing that already happened, but it stops anything further.
Who can see it
Sweatr is social, so some data is meant to travel. It travels only where you send it.
Other members
Your handle, display name and profile picture make up your public card, and anyone can find them. Everything else follows the visibility you set on it: private, friends, group, or public. An activity you keep private stays private.
Professionals
A coach, physiotherapist or nutritionist sees only what a booking or a share gives them. Being listed in the directory does not give a professional a view of anybody, and neither does having worked with you before.
Administrators
Our administrators can read a limited set of data to investigate an abuse report or a support request. That access is logged in the same audit trail as everything else.
Nobody else
We do not sell personal data. We do not share it with advertisers, data brokers or partners. There is no advertising or analytics SDK in the app.
Companies we work with
A handful of services process data on our behalf, each under a contract that limits them to what we ask for.
| Service | What it handles | Where |
|---|---|---|
| Google Firebase Authentication | Your sign-in credentials, email and name | Google infrastructure, under standard contractual clauses |
| Google Firebase Cloud Messaging | Delivering push notifications to your device | Google infrastructure, under standard contractual clauses |
| Mapbox | Turning an address into coordinates for search | Address text only, never tied to your account |
| OpenStreetMap | Map tiles shown while you place a pin | Sees your device IP address, no account data |
| Our mail provider | Sending verification and notification email | Email address and message only |
Everything else runs on our own servers. Your training log, your routes, your notes and your bookings never leave our infrastructure.
Where it lives and how it is protected
Sweatr runs on servers in France, in the European Union. Your training data, your health data, your files and your backups stay there. The one exception is your sign-in credential, which Google holds through Firebase Authentication and may process outside the EU under standard contractual clauses.
Encryption
Sensitive fields are encrypted individually before they reach the database, each with its own key that is itself sealed by a key held in a separate vault. Someone who walked away with the whole database would hold ciphertext and nothing else. Files are stored encrypted, backups are encrypted, and traffic between your device and us is TLS end to end.
Access logging
Every decryption of health or personal data appends an entry recording who did it, on which record, and when. Those entries are append-only: no part of our code can change or remove one.
Access rules
By default, data can only be read by the person it belongs to. Where a feature needs to widen that, the exception is written down, reviewed and tested. A request for something you may not see answers as if it did not exist, so nobody can probe the service to learn who is on it.
How long we keep it
- Account and training data: for as long as your account exists.
- After you delete your account: erased from our live systems immediately. An encrypted backup archive made before that is never used to bring the account back, and goes when the archive expires.
- Audit trails: kept for as long as the service runs. They hold an account identifier, the record touched and a timestamp, never a name or anything you wrote. They outlive an erased account on purpose: they are the proof the erasure happened.
- Waitlist email addresses from this website: until launch, or until you ask us to drop yours.
Delete an individual activity, note or route at any time and it goes immediately, without waiting for the account to go with it.
Your rights
Under the GDPR you can ask us to do any of the following, and we answer within one month.
- Access. A copy of everything we hold about you, in a machine-readable file.
- Rectification. Correct anything wrong.
- Erasure. Delete your account and everything owned by it.
- Portability. Take that export elsewhere.
- Restriction and objection. Tell us to stop a specific use.
- Withdraw consent. For health data, at any time.
Write to the address below and we handle it by hand. Export and deletion from inside the app's settings are being finished; this page will say so when they are live. We never charge for a request, and we never ask why.
If you think we have handled your data badly, you can complain to your national data protection authority. We would rather you told us first.
Age
Sweatr is for people aged 16 and over. We do not knowingly collect data from anyone younger, and we set the bar at 16 because that is the highest digital consent age in the EU and because the app holds health data. If you believe a child has an account, write to us and we will remove it.
The website itself
getsweatr.com sets no cookies and runs no analytics. There is no tracking pixel, no consent banner to click through, and no third-party script beyond the font files the page loads from Google Fonts.
Two things are stored in your browser, and both stay there: the language you picked with the switcher, and the email address you type into the waitlist form. The waitlist has no server behind it yet, so that address is written to your own browser and goes nowhere else. When we do wire it up, this page will say so before a single address is sent.
Changes to this policy
When we change something material, we update the date at the top of this page and tell you in the app before the change takes effect. Small corrections such as fixing a typo or naming a service more precisely get the new date and nothing more.
Contact
Questions about this policy, or a request about your data:
privacy@getsweatr.comA real person reads that address.
Early access