PRIVACY POLICY
Weightlifting Engine — last updated: July 26, 2026

1. What data we collect

To make the app work, we collect:

· Account data: email, password (never stored in plaintext, only its hash).

· Profile data: sex, age, body weight, experience level, training goal (competition/general/strength) and any competition date, training preferences (sessions per week, duration, preferred days).

· Training data: sessions completed, exercises/loads/reps, RPE, maxes, pre- and post-workout feedback (fatigue, sleep, stress, motivation, localized pain/DOMS, free notes).

· Technical notes you write yourself in Settings, used as input for the system that generates the program.

· Minimal technical data: IP address, used only temporarily and in memory (never saved to the database) to limit automated login attempts; it expires on its own within minutes/hours.

2. Health data (special category, GDPR art. 9)

Free notes and localized pain/DOMS fields may contain information related to your health (e.g. lower back pain). We process this data only if you voluntarily write it — the app does not request or actively ask for it. The system that generates programs (assisted by an AI language model) uses it exclusively as algorithmic input to modulate volume/intensity or propose warm-up/activation patterns, and has the explicit instruction to never ask you any question about pain or discomfort, in any form — it can only act silently on the programming (e.g. proposing activation exercises), never commenting on or explaining that a change is due to reported pain. This is in no case an evaluation by a coach or professional: it is AI-assisted processing. Importing it into your account only requires a manual copy-paste step by the data controller, for technical reasons, which does not constitute a review or evaluation of the content. By voluntarily entering this information you give your explicit consent to its processing for this specific purpose; you can request its deletion at any time (see point 8).

3. Why we process your data

· Providing you the service: generating and showing you personalized training programs, tracking your progress (legal basis: performance of the requested contract/service, GDPR art. 6.1.b).

· Service communications: account verification emails, program update notifications, password reset (same legal basis).

· Any health data entered: only with your explicit consent, revocable at any time (GDPR art. 9.2.a).

4. Who else processes your data on our behalf

We rely on external providers that process data only to make the service work, never for their own purposes:

· Supabase — hosts the database (EU region, Ireland).

· Vercel Inc. — hosts the web application (global infrastructure; may involve processing outside the EU, covered by the EU standard contractual clauses that Vercel adopts as a sub-processor).

· Resend — sends transactional emails (account verification, notifications, password reset).

None of these providers use your data for their own advertising or profiling purposes.

5. Cookies

We use a single cookie, strictly necessary to keep you logged in (login session). It is not a profiling or advertising cookie and does not require consent under current regulations. We do not use analytics or third-party tracking tools.

6. Data controller

Alessio Quercioli, a private individual, reachable at alessio.quercioli@yahoo.it for any request regarding your personal data.

7. How long we keep your data

For as long as your account remains active. If you request account deletion, your data is deleted except for what the law requires us to retain.

8. Your rights

You can at any time request to: access your data, correct it, delete it, receive a copy of it (portability), object to processing, or revoke the consent given for health data. Write to alessio.quercioli@yahoo.it.

9. Consent traceability

The date and time when you accept these Terms and this Privacy Policy are recorded and retained, as is the explicit consent given for the processing of health data (see point 2). This allows us to document that consent was actually given, for the protection of both you and the data controller.

10. Security

Passwords protected with bcrypt hashing, sessions via a protected and signed cookie, connections always over HTTPS, automatic limits on login attempts. No system is 100% secure, but we adopt industry-standard practices proportionate to a free service of this scale.

11. Minimum age

The service is not intended for people under 16 years of age.

12. Changes to this notice

We may update this document; the date at the top indicates the last revision. Substantial changes will be flagged to you in the app.