At Smarty Workout (smartyworkout.com) we value your privacy and are committed to protecting your personal data. This Privacy Policy explains how Smarty Workout collects, uses, stores, and protects your information when you use our AI-generated personalized training service. Our practices comply with the General Data Protection Regulation (GDPR) (EU) 2016/679, the ePrivacy Directive 2002/58/EC, and applicable data protection laws worldwide.
1. Data We Collect
Account & Profile Data
- Name, email address, and password (stored hashed) when you create an account.
- Optional profile information: display name, timezone, and notification preferences.
- Billing information needed to process your monthly membership payment (handled by our payment processor — we do not store full card numbers).
Fitness & Training Data
- Self-reported information such as age, gender, height, weight, fitness level, training goals, available equipment, and injury or physical-limitation notes.
- Your generated workouts, exercise preferences, and workout logbook entries (sets, reps, weights, dates).
- Health-screening answers relevant to safe exercise, such as diagnosed medical conditions or pregnancy status, where you choose to provide them.
Usage & Technical Data
- Technical data such as IP address, browser type, device type, and operating system.
- Aggregated usage analytics (which features you use, workouts completed).
2. How We Use Your Data
- Generate your personalized daily workouts and recommend exercises from the library.
- Exclude injuries, disliked exercises, and unavailable equipment from your workouts.
- Save your logbook entries and history so you can track your progress over time.
- Process your monthly membership payment and manage your subscription.
- Send transactional emails (account, billing, security) and, with consent, product updates.
- Improve Smarty Workout through anonymized, aggregated analytics.
- Ensure legal compliance and platform security.
We will never sell or rent your personal data to third parties.
3. Legal Basis for Processing (GDPR Article 6)
- Consent (Art. 6(1)(a)): Marketing emails, optional analytics.
- Contractual necessity (Art. 6(1)(b)): Running your account, generating workouts, processing your membership payment, and saving your logbook.
- Legal obligation (Art. 6(1)(c)): Record keeping, tax compliance, fraud prevention.
- Legitimate interests (Art. 6(1)(f)): Service security, product improvement.
- Health-related self-reports (injuries, conditions, pregnancy) are processed only with your explicit consent and used solely to make your workouts safer and more relevant. We do not share them for any other purpose.
4. Data Sharing & Sub-Processors
- Cloud hosting provider — database hosting and authentication.
- AI provider(s) — used only to generate your personalized workouts from your profile. No direct identifiers (name, email) are sent to the AI provider unless strictly required.
- Payment processor — securely handles your membership billing.
- Email delivery provider — for transactional and (with consent) marketing emails.
All processors are required to comply with GDPR standards and maintain appropriate technical and organizational security measures.
5. Data Retention
- Account data: retained while your account is active and deleted when you delete your account, except where short operational backup windows or legal obligations apply.
- Workout & logbook data: retained while your account is active and deleted with your account.
- Transaction records: retained for 7 years as required by tax law.
- Marketing preferences: retained until you withdraw consent.
- Anonymized analytics: may be retained beyond account deletion in fully anonymized form.
6. Your Rights Under GDPR
- Right of Access (Art. 15)
- Right to Rectification (Art. 16)
- Right to Erasure (Art. 17) — delete your account and data from settings.
- Right to Restrict Processing (Art. 18)
- Right to Data Portability (Art. 20) — download your data in JSON format.
- Right to Object (Art. 21)
- Right to Withdraw Consent (Art. 7)
- Right to Lodge a Complaint with your local data protection authority.
7. Security Measures
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Hashed passwords and secure session management.
- Row Level Security (RLS) ensuring each user can only access their own data.
- Strict access controls and least-privilege principles.
- Regular dependency, infrastructure, and security reviews.
8. Cookies & Local Storage
Smarty Workout uses cookies and local storage for the following purposes:
- Essential: authentication tokens, session security, fraud prevention.
- Functional: UI preferences, workout progress.
9. Children
Smarty Workout is intended for users aged 18 and over. Users between 13 and 18 may only use Smarty Workout with parental or guardian supervision and consent. We do not knowingly collect data from children under 13.
10. International Transfers
Your data is primarily processed within the EU. Where transfers outside the EU are necessary, we rely on Standard Contractual Clauses or other lawful transfer mechanisms approved under GDPR.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of material changes via the app or email.
12. Contact
Data Controller: Smarty Workout (smartyworkout.com). Contact smartyworkout@outlook.com.