1. Who operates Strongbod
Strongbod is operated by Vanette's Place Global LLC ("Strongbod", "we", "us", or "our"). For data-protection purposes, Vanette's Place Global LLC is the controller of personal information processed for Strongbod, except where a named service provider acts as an independent controller under its own terms.
You can contact us at support@asaplinks.com or by mail at Vanette's Place Global LLC, 2810 N Church St PMB 607081, Wilmington, Delaware 19802-4447, United States.
2. Information we collect
We collect information you provide, information created as you use Strongbod, limited technical information collected automatically, and information returned by services you choose to connect.
- Account and authentication information: your Firebase user identifier, email address when you use email sign-in, selected authentication provider, verification and account status, and security information processed by Firebase Authentication such as IP address and user agent.
- Training profile and setup: experience level, training goal, focus areas, gym type, gym names, available equipment, weekly frequency and preferred days, time zone, notification choices, units, height, weight, birth year, and whether a value was entered manually or imported from a supported health connection.
- Workout and history information: generated, saved, active, completed, reused, and manually added workouts; exercise snapshots and instructions; target muscles; planned and logged sets; reps, lifted weight, exertion, rest timing, timestamps, workout duration, volume, records, recovery estimates, and manual recovery adjustments.
- Optional progress photos: an image you choose to attach privately to a completed workout, along with its file type, size, storage identifier, and integrity hash. Progress photos are optional and are not included in shared workout-summary cards.
- Referral information: your invite code, the code a referred account redeems, the referring and referred account identifiers, redemption time, promotional-access period, and abuse-prevention state.
- Health-connection information: with your permission, supported body-stat values made available through Apple HealthKit or Android Health Connect. Strongbod requests only supported data needed for the feature you choose. You can decline or revoke access and enter values manually.
- Notification information: reminder preferences, local reminder time, time zone, delivery state, and a device push token used through Firebase Cloud Messaging. Push tokens are treated as confidential service credentials and are not sent to product analytics.
- Subscription information: app-store account context, product and offering identifiers, entitlement status, purchase, renewal, expiration, restore, and cancellation metadata received from Apple, Google, and RevenueCat. We do not receive or store your full payment-card details.
- Device, network, and reliability information: device platform, app and build version, language, connectivity and sync state, IP address in ordinary server requests, request and correlation identifiers, bounded diagnostic information, and typed error or retry categories. We do not put raw provider responses, secrets, or sensitive profile values in ordinary logs.
- Product analytics and attribution: pseudonymous identifiers and explicit events about feature use, such as onboarding steps, workout generation, set logging, completion, settings, purchases, and failures. Analytics may include safe categories, counts, bands, platform, app version, and approved copy variant, but not your name, email, phone number, raw health data, body measurements, exact recovery percentages, exact lifted weight, free-text searches, notes, push token, or exercise-provider credentials.
- Support communications: the email address, message, attachments, and technical context you choose to send when you contact support.
3. How we use information
- Create and secure your account, verify sign-in, and keep your Strongbod data tied to the correct user.
- Save your setup, gyms, equipment, exercise exclusions, preferences, workouts, logged sets, records, estimated one-repetition maximums, optional progress photos, history, and recovery state across sessions and devices.
- Build and adapt workouts using your goal, experience, schedule, equipment, recovery inputs, and logged training history.
- Provide workout logging, rest timing, offline continuity, synchronization, records, recovery estimates, reminders, exports, and account deletion.
- Confirm subscription status, unlock premium access, restore purchases, prevent duplicate purchase reporting, and support store-managed billing.
- Issue and redeem referral codes, provide time-limited promotional access, enforce one-redemption and no-self-referral rules, and prevent referral abuse.
- Measure activation, reliability, and feature use; attribute installs and registrations where permitted; diagnose failures; prevent abuse; and improve Strongbod.
- Respond to support and rights requests, enforce our Terms, comply with law, and protect Strongbod, our users, and others.
4. Legal bases for processing
Where the General Data Protection Regulation or similar law applies, we process information as necessary to perform our contract with you, including providing your account, subscription access, workouts, history, and requested features. We also process information with your consent, including optional health access, notifications, iOS tracking permission, and certain advertising attribution.
We rely on legitimate interests to secure and improve Strongbod, diagnose reliability problems, prevent fraud and abuse, understand feature use with data minimization, and provide support, provided those interests are not overridden by your rights. We process information when necessary to comply with legal obligations and to establish, exercise, or defend legal claims. You may withdraw consent through Strongbod, your device settings, or by contacting us; withdrawal does not affect earlier lawful processing.
5. Service providers and disclosures
We do not sell personal information for money. We disclose information to service providers only as needed to operate Strongbod, and we may disclose information when required by law, to protect rights and safety, or as part of a merger, financing, reorganization, or sale of assets.
- Google Firebase: Firebase Authentication handles account identity and email or federated sign-in; Firebase Cloud Messaging processes installation and device-token information to deliver enabled notifications. Strongbod does not use Firebase Analytics as its product analytics provider.
- Apple and Google: the App Store and Google Play process downloads, payments, subscriptions, refunds, and platform account information under their own terms. Apple HealthKit and Android Health Connect provide supported health values only after platform permission.
- RevenueCat: processes app-user identifiers, store receipts, product and entitlement metadata, purchase events, restores, and subscription state so Strongbod can verify premium access. RevenueCat and the app stores, not Strongbod, process payment credentials.
- PostHog: processes pseudonymous, explicitly defined product events. Strongbod is designed not to send names, email addresses, phone numbers, push tokens, raw health values, body measurements, exact workout weights, or free-text notes to PostHog.
- Meta App Events: receives limited install, registration, and approved app-event attribution data. On iOS, advertiser-ID collection and attribution are disabled unless you authorize tracking through App Tracking Transparency. Advanced matching uses a pseudonymous external identifier, not raw email or phone. Depending on applicable law, this attribution may be considered sharing for targeted advertising; you can decline iOS tracking, use platform privacy controls, or contact us.
- Amazon Web Services: hosts Strongbod's backend, encrypted PostgreSQL database, private object storage for optional progress photos, logs, backups, networking, and related infrastructure in the United States. Access is restricted to operational needs.
- YMove: supplies licensed exercise metadata, instructions, workout composition, and optional media. Strongbod's backend sends non-identifying parameters needed to request compatible content, such as target muscles, experience or difficulty category, goal, and broad equipment mapping. We do not send YMove your Strongbod email, Firebase identity, raw health values, detailed workout history, recovery percentages, exact logged weights, or payment information.
6. Analytics, advertising, and device choices
PostHog is Strongbod's product-analytics system. Meta App Events is used for mobile advertising attribution. Events are explicit and data-minimized; Strongbod does not use automatic Firebase Analytics collection as a substitute for this plan.
On iOS, Strongbod starts PostHog opted out and disables Meta advertiser-ID collection until the approved consent point. If you decline App Tracking Transparency, advertiser-ID-based Meta attribution remains disabled. On Android, analytics operates subject to platform and user settings. Offline events may be queued on your device and uploaded later with their original occurrence time. Signing out or deleting your account resets the analytics identity used by Strongbod.
7. Storage, retention, and deletion
Strongbod keeps account, profile, workout, history, record, recovery, preference, referral, promotional-entitlement, optional progress-photo, and subscription-state information while your account is active so the Service can function. An active workout and pending sync operations may also remain encrypted or protected by the operating system on your device until they synchronize, you sign out, you discard them, or you delete the app.
When you request account deletion, Strongbod marks the account for deletion, requires confirmation and recent authentication where appropriate, revokes active device tokens and jobs, and deletes or de-identifies account-linked Strongbod data from active systems. Deletion of authentication data and backups may complete later under provider backup cycles. We may retain limited records when required for security, fraud prevention, financial, tax, dispute, or legal obligations. Deleting a Strongbod account does not cancel a subscription managed by Apple or Google; cancel it separately in your app-store account.
Operational logs are kept for bounded security and reliability periods. Data export files are temporary and expire after delivery. Analytics, authentication, messaging, subscription, app-store, and cloud providers retain information under their contracts and documented retention practices. We instruct processors to delete or return account-linked data where applicable.
8. Your choices and privacy rights
You can edit training-profile values, gym and equipment choices, schedule, units, notification settings, health connection, and recovery adjustments in Strongbod. You can revoke health, notification, and tracking permissions in device settings; some features may stop working, but declining optional permissions does not block manual setup.
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing; receive a portable copy; withdraw consent; opt out of sale, sharing, or targeted advertising; and appeal a denied request. Use Export My Data or Delete Account in Strongbod, or email support@asaplinks.com. We may need to verify your identity before completing a request. You may also complain to your local data-protection authority.
9. Security
We use administrative, technical, and organizational safeguards designed to protect information, including encrypted network transport, encrypted cloud storage and database volumes, restricted credentials, secret storage, access controls, request redaction, correlation-aware logging, and backups. No system is completely secure, so we cannot guarantee absolute security.
10. International processing
Strongbod and its providers process information in the United States and other countries where they operate. Those countries may have different data-protection laws. Where required, we rely on contractual protections, provider data-processing terms, adequacy decisions, or another lawful transfer mechanism. Firebase Authentication is operated from United States data centers; other global providers may process data in multiple locations.
11. Children
Strongbod is intended for adults age 18 and older. We do not knowingly collect personal information from children. If you believe a child has created an account or provided personal information, contact support@asaplinks.com and we will take appropriate steps.
12. Changes and contact
We may update this Privacy Policy as Strongbod, its providers, or legal requirements change. We will post the updated policy with a new effective date and provide additional notice when required.
For privacy questions or requests, email support@asaplinks.com or write to Vanette's Place Global LLC, 2810 N Church St PMB 607081, Wilmington, Delaware 19802-4447, United States.