Back

Privacy Policy

Last updated: July 24, 2026

1. Data Controller

The controller of your personal data and operator of Progresio is MetaCode Michał Gawron, a sole trader established at ul. Jesionowa 45/56, 50-504 Wrocław, Poland, NIP 8961580439, REGON 381052237, VAT EU PL8961580439 (“MetaCode”, “we” or “us”). General contact: [email protected]. Privacy requests: [email protected]. We have not appointed a Data Protection Officer.

2. Data We Process and Its Sources

We process data you provide, data generated when you use Progresio, and data received from trainers, studios, authentication providers, payment providers and invited users:

  • Account and authentication data: name, email address, password credentials handled by our authentication system, optional sex, language, units, country, avatar, account role, verification and login metadata, and Google or Facebook login identifiers where used
  • Workout data: workout dates and duration, exercises, sets, repetitions, weights, RPE, rest time, comments, records, templates, favourites, schedules, assignments, progress statistics and training-day suggestions
  • Trainer, client and studio data: relationships, invitations, client goals and notes, assigned workouts, feedback, presence during live workouts, trainer profile and certification, studio membership, business, tax and billing details
  • Payments and subscriptions: selected plan, billing status and period, Stripe customer and subscription identifiers, billing address, business name and tax identifier; we do not receive complete payment-card details
  • Content and sharing: custom exercises, messages, notes, comments, shared-workout links and view counts, public trainer profile information and invitation information
  • Device and usage data: IP address, device, browser and operating-system information, logs, diagnostics, errors, performance traces, session replay, interactions, advertising identifiers and cookie or similar-technology data

3. Purposes and Legal Bases

We process personal data only where a legal basis applies:

  • Contract: to create and operate accounts, provide workout tracking and collaboration, synchronize data, supply paid features, manage subscriptions, provide support, exports and account deletion
  • Legal obligations: to meet tax, accounting, consumer-protection, payment, fraud-prevention and lawful-authority requirements
  • Legitimate interests: to secure and defend the service, prevent abuse, maintain essential diagnostics, establish or defend claims, improve reliability and produce aggregated business statistics, after balancing these interests against your rights
  • Consent: for non-essential analytics, advertising, ad personalization and access to non-essential information on your device; you may withdraw consent at any time without affecting prior processing

4. Required Data and Health Information

Email and authentication data are required to create an account. Information marked as required at checkout is needed to conclude and perform a subscription and meet billing obligations. Without it, we may be unable to provide the account or paid service. Other profile and workout fields are voluntary, although omitting them may limit relevant features.

Progresio is a fitness log, not a medical service. Ordinary workout records are not intended to contain diagnoses, injuries or other health data. Do not enter special-category health data in free-text fields. If a feature later requires such data, we will provide a separate notice and identify an Article 9 GDPR condition before processing it.

5. Trainers, Studios and Other Users

If you join a trainer or studio, relevant account, workout, progress, assignment, presence, note and relationship data are shared with authorized trainers or studio owners so they can provide their independently arranged coaching services. Trainers and studios generally determine their own coaching purposes and may therefore be separate controllers for their use of your data. Their privacy information and requests concerning their independent processing should be directed to them.

We may receive your name, email, relationship, goals or assignment data from a trainer, studio owner or inviting user. We provide this notice no later than our first communication or within one month, unless an applicable GDPR exception applies.

6. Public and User-Directed Disclosures

Trainer profile details and avatars may be public. Anyone with a valid invitation link may see limited trainer, studio and inviter details. Anyone with an active shared-workout link may see the workout information included in that share. Links are bearer links: recipients can forward them. Review content before sharing and revoke links you no longer want active.

We also disclose data when you direct us to do so, where needed to perform the service, to professional advisers, competent public authorities, or in connection with a lawful business transfer.

7. Service Providers and Recipients

Recipients include Hetzner (German backend hosting), Vercel (frontend hosting and content delivery), Stripe (checkout, payments, tax and subscription administration; see docs/stripe-data-retention.md for retention and controller boundaries), Sentry (errors, traces and session replay), Google (Analytics, AdSense and Google login), Meta (Facebook login), Brevo (transactional email) and jsdelivr (CDN for the on-device semantic-search runtime). Our Supabase-compatible database, authentication, storage and realtime services are self-hosted on our backend infrastructure. Providers may act as processors or, for some payment, advertising or login activities, independent controllers under their own notices.

8. International Transfers

Our primary backend is hosted in Germany. Some providers and their subprocessors may process data outside the EEA, including in the United States. Where no adequacy decision applies, transfers are based on appropriate safeguards such as the European Commission Standard Contractual Clauses and, where relevant, supplementary measures. Where a recipient is validly certified, we may rely on the EU-US Data Privacy Framework. Contact us for information or a copy of applicable safeguards.

9. Retention

Account, workout and relationship data are generally kept while the account or relationship is active and then deleted or anonymized, subject to backups and legal needs. Expired export files are kept for about 24 hours; signed download links for about 15 minutes. Shared links normally expire after 30 days and invitations after 7 days, although audit records may remain. Transaction, invoice and tax records are retained for periods required by law. Security logs, diagnostics and support records are retained only as long as needed for security, troubleshooting and claims, according to configured provider periods. Local preferences, consent records, offline workout data and cached resources remain on your device until removed by the application, browser or you. After account deletion, limited records may remain where required by law, needed for claims, held in rotating backups, or retained by an independent controller such as a payment provider.

10. Cookies, Local Storage and Similar Technologies

Strictly necessary browser storage supports authentication, security, preferences, offline synchronization and core application operation. With your consent, Google Analytics measures use and Google AdSense serves and measures advertising, including personalized advertising when enabled. You can accept all, reject non-essential technologies, choose analytics and marketing separately, and later change your choice through Cookie preferences. Withdrawing consent does not affect prior lawful processing. Provider cookies and storage duration vary by technology and configuration.

11. Sentry Diagnostics and Session Replay

Sentry receives error reports, performance traces, technical context and sampled session replays to diagnose failures and protect service reliability. Replays may capture interactions and visible page content. Do not enter sensitive or health information in free-text fields. We configure access and sampling to limit collection, but Sentry processing is separate from optional Google analytics and advertising.

We rely on our legitimate interests for diagnostics that are necessary and proportionate to secure and maintain the service. Where device access or a non-essential diagnostic requires consent, we will request it before that processing. You may object to legitimate-interest processing by contacting us.

12. Automated Processing

Progresio automatically calculates verified achievement candidates, volume, frequency, activity and training suggestions; marks overdue assignments as missed; applies subscription access and client-capacity rules; and selects advertising eligibility based on subscription and consent. These operations do not make decisions producing legal or similarly significant effects about you. Ad providers may personalize advertising only where the required consent exists.

13. Your GDPR Rights

Subject to applicable conditions, you may request access, rectification, erasure, restriction, data portability, or object to processing based on legitimate interests. You may withdraw consent at any time. You may also lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, uodo.gov.pl) or your local EEA supervisory authority.

Use the in-app export and deletion controls or contact [email protected]. We may need to verify your identity. Rights are not absolute; where we cannot fulfil a request, we will explain the applicable reason.

14. Security and Children

We use measures appropriate to risk, including HTTPS, access controls, row-level authorization, private storage where appropriate, backups and monitoring. No system is completely secure. Please protect your credentials and report suspected compromise promptly.

Progresio accounts and subscriptions are intended only for persons aged 18 or older. We do not knowingly offer the service directly to children. Contact us if you believe a minor has provided data so that we can investigate and delete it where appropriate.

15. Changes and Contact

We may update this notice when the service, providers or law changes. We will publish the new date and give appropriate notice of material changes. Changes do not retroactively alter the legal basis for earlier processing.

Privacy requests: [email protected]

General contact: [email protected]