Legal

Privacy Policy

Effective Fitness is in public beta. Features, and the data behind them, are still changing. This page describes what the service does with your data today, in plain English. When something changes, this page changes with it.

Last updated: 29 August 2026

Not finished - do not launch with this page as it stands

The amber [OWNER: ...] markers below are details only the operator of this site can supply: the legal entity, its registered address, a working contact email, the governing jurisdiction, the retention period, and the minimum age. Fill them all in, and have the result reviewed by someone qualified, before taking real signups.

Who we are

Effective Fitness is operated by [OWNER: legal entity name], registered at [OWNER: registered address]. If you have a question about your data, or you want a copy of it or want it deleted, email [OWNER: contact email].

What we collect

Only what the product needs to work. There is no analytics package, no advertising script and no third-party tracker in this application.

Your account

Your email address, display name and profile picture. Sign-up runs through Clerk, so Clerk holds your password or social login - we never see or store a password. When Clerk tells us an account was created we copy the email, name and avatar URL into your profile row.

Your profile

Whatever you choose to fill in: username, bio, training goal, experience level, training days per week, equipment, location, and links to Instagram, TikTok, YouTube, Reddit, X and Discord. All of it is optional except the username, which is generated for you at signup.

Your training data

Workouts you log: the exercises, set numbers, reps, weight, RPE, rest times, your notes, session duration and total volume. We also keep running totals - workout count, current streak, longest streak, lifetime volume and the date of your last workout.

What you post

Community posts and comments, the posts you like or save, plan reviews, wiki article drafts and suggestions, blog posts if you write for us, and any content report you file (which records who filed it).

Files you upload

Profile pictures, community post images, exercise images, and plan and wiki cover images. The file goes to UploadThing and we keep the URL it gives back. A workout CSV is the exception: it is read inside your browser and never uploaded, so all that reaches us is the workouts you confirm on the preview screen.

Payments

If you subscribe, we store your Stripe customer ID, subscription ID, status, the price you are on and when the current period ends. Card details go straight to Stripe on their own checkout page. We never see or store a card number.

Discord, if you connect it

Only if you start the connect flow yourself: your Discord user ID, username, display name and avatar. The access token Discord issues is used once, to read that identity, and is then thrown away - we do not keep it, so we cannot act on your Discord account afterwards. You are never asked for your Discord password.

Coach applications

If you apply to coach: your stated name, headline, location, bio, intro video URL, specialities, certifications, years of experience and the packages you want to offer, plus our reviewer notes on the application.

Server logs

Our host, Vercel, keeps standard request logs which include IP addresses, for security and debugging. We do not build profiles from them.

What is public by default

This is the part most worth reading, because the defaults are open. Effective Fitness is a community site, and it is built that way from the start.

Your profile is public

New profiles are public. Your username, display name, avatar, bio and headline stats can be seen by anyone, including people who are not signed in, and appear on the leaderboard. You can turn this off, and hide your workout history, bodyweight, progress photos and social links individually, under Settings > Privacy.

Workouts you log are marked public

Every workout you start is currently saved as public, which is what lets it feed the community and the leaderboard. There is no per-workout toggle in the interface yet. If you do not want your sessions visible, set your profile to private, which hides them along with the rest of your profile.

Posts and comments are public

Anything you post to the community feed, and any comment you leave, is visible to everyone. Treat it as public writing.

Health information

Your training log says more about your body than it looks like it does: what you can lift, how often you train, and when you stopped. We do not sell it, we do not share it with advertisers, and nobody outside the processors listed below sees it. Settings offers switches for bodyweight and progress photos as well, but nothing in the app stores either of those yet - those switches are ahead of the product, and there is no such data to hide.

Who else handles your data

We do not sell your data and we do not share it with advertisers. We do use other companies to run the service, and your data passes through them:

Clerk

Accounts, sign-in and session management. Holds your login credentials.

Neon

The Postgres database. Everything described above that is not a file or a payment lives here.

Stripe

Subscription payments and the billing portal. Holds your payment method and billing history.

UploadThing

Storage for the images you upload. Not the workout CSV, which is parsed in your browser and never sent anywhere.

Vercel

Hosting and request logs.

Discord

Only if you connect your Discord account yourself, and only to read your Discord identity and server membership.

Each of these has its own privacy policy and its own security practices, which we do not control. We may also disclose data if we are legally required to, under the law of [OWNER: governing jurisdiction].

Cookies

We use a small number of cookies, all of them necessary to run the site. There are no advertising or analytics cookies. The detail is on the cookie notice.

Getting your data, and getting it deleted

We would rather be honest about what is built than promise a button that does not exist. Here is exactly where things stand during the beta:

Editing your own data - self-serve

You can change your profile, your privacy toggles and your social links yourself under Settings, and you can manage or cancel your subscription through the Stripe billing portal linked from Settings > Billing.

Deleting posts and workouts - not self-serve yet

There is no button in the app today for deleting a post, a comment or a completed workout. You can delete individual sets while logging. For anything else, email us and we will remove it.

Deleting your account - by email

There is no in-app account deletion yet, and deleting your Clerk login does not by itself remove your data from our database. Email [OWNER: contact email] from the address on your account and we will delete your profile and everything attached to it: workouts, sets, stats, badges, posts, comments, likes, saved posts, uploads and connected accounts. Ask us and we will confirm when it is done.

A copy of your data - by email

There is no self-serve export yet. Email [OWNER: contact email] and we will put together a machine-readable copy of what we hold about you.

Your legal rights

Depending on where you live you may have rights to access, correct, delete, restrict or object to our use of your data, and to complain to a data protection regulator. The specific rights that apply, and the regulator you would complain to, depend on [OWNER: governing jurisdiction]. We will honour any request that reaches the contact address above, whether or not the law requires it.

How long we keep it

While your account is open, we keep your data so the product works: your history is the product. After you ask us to delete your account we remove your records within [OWNER: retention period, for example 30 days]. Some traces outlive that and we would rather say so: payment records held by Stripe are kept for as long as tax and accounting rules require, moderation records of content that was removed for breaking the rules are retained so the same problem can be recognised again, and host request logs age out on our host's own schedule.

Security

Traffic is encrypted in transit. Passwords are held by Clerk and never reach our servers. Card numbers are held by Stripe and never reach our servers. The token Discord hands us while you link your account is used once and never written down. That said, this is a beta run by a small team, not a bank - no service can promise perfect security, and you should not store anything here you could not stand to lose or to have exposed.

Age

Effective Fitness is not intended for children. You need to be at least [OWNER: minimum age, must match /terms] to hold an account. If you believe a child has an account with us, email the contact address above and we will remove it.

Changes to this policy

The product is moving quickly, so this page will change. When it changes in a way that matters we will update the date at the top and say so in the app. Continuing to use the service after a change means you accept the updated policy.

Contact

Privacy questions, data requests and deletion requests all go to [OWNER: contact email]. See also the terms of service and the cookie notice.