Privacy Policy
Effective date: 7 March 2026
Last updated: 16 September 2026
1. Data Controller
Alberto Bonino
Turin (Torino), Italy
Email: privacy@caliance.app
2. What This Policy Covers
This Privacy Policy explains how Caliance ("we", "us", "our") collects, uses, stores, and protects your personal data when you use the Caliance mobile application, its Apple Watch app and related services (the "Service"). Caliance is a workout tracking application that allows you to upload workout plans, have them parsed using artificial intelligence, and track your training sessions.
This policy applies to all users of the Service, including those accessing it through the closed beta programme.
3. Data We Collect
3.1 Account Data
When you create an account, we collect:
- Email address, if you sign in with a one-time code. We do not collect a password: signing in means receiving a six-digit code at that address and typing it back. The code is valid for ten minutes and stops working once it is used. Your account record never contains the code itself, only a bcrypt hash of it; the code appears in readable form only in the email we send you and, briefly, in the system that sends that email
- Provider identifier and avatar URL, if you sign in with Google or with Sign in with Apple, together with a marker recording whether the address Apple gave us is one of its private relay addresses. We do not collect or store a name from either provider
3.2 Workout Data
When you use the Service, we collect:
- Workout plans: structured data extracted by AI from files you upload, including exercise names, prescriptions, and metadata
- Session logs: reps, loads, durations, difficulty ratings, notes, and completion status you enter during training sessions
- Progress analytics: volume, load progression, and estimated repetition maximum values derived from your session logs
- Maximum heart rate, if you enter one on your profile, which we use only to compute heart-rate zones
- Heart rate and energy from Apple Watch, if you use the watch app and agree to it. Section 14 describes exactly what, and on what basis
3.3 File Uploads
- PDFs and images of workout plans you upload for AI processing
3.4 Trainer Assets
If you use trainer features:
- Images and videos associated with exercises and plans
3.5 Credit Information
- Credit balance and grant history used for AI processing features
3.6 Device-Stored Data
The following data is stored locally on your device and is not transmitted to our servers:
- Authentication tokens: stored in platform-native secure storage
- User preferences: theme, language, sound and haptic settings
This local storage is strictly necessary for the app to function and does not require consent under the ePrivacy Directive.
4. How We Use Your Data
We process your personal data for the following purposes:
| Purpose | Legal Basis (GDPR) |
|---|---|
| Providing the core Service (account management, workout tracking, session logging, progress analytics) | Performance of contract — Art. 6(1)(b) |
| AI processing of uploaded workout plans to extract structured workout data | Consent — Art. 6(1)(a) |
| Showing and storing heart rate and energy from Apple Watch (section 14) | Explicit consent — Art. 9(2)(a) and Art. 6(1)(a) |
| Security, anti-abuse measures, and maintaining service integrity | Legitimate interest — Art. 6(1)(f) |
5. AI Processing
When you upload a workout plan (PDF or image), we send the file to third-party AI processing providers to extract structured workout data (exercises, sets, reps, loads, etc.). This is how the AI processing works:
- Your uploaded file is sent to one of our AI processing providers for analysis
- The provider returns structured data that we store in your account
- Once sent, your files are subject to the AI provider's own terms and data policies, which may include temporary storage or processing beyond the immediate request. We select providers that offer data protection commitments, but we cannot guarantee how they handle data internally.
- AI-extracted data may contain errors, so you should always verify the output
You consent to this processing when you accept these terms at signup. You may withdraw consent at any time by deleting your account, which will remove all your data including uploaded files.
6. Third-Party Recipients
We share data with the following categories of service providers, who process data on our behalf:
| Category | Data Shared | Purpose |
|---|---|---|
| AI processing providers | Uploaded workout plan files, user notes, sport category | Extracting structured workout data from plans |
| Cloud storage providers | Uploaded files, trainer assets | Storing files you upload |
| Video hosting providers | Trainer video files | Hosting exercise demonstration videos |
| Email delivery providers | Your email address | Sending transactional emails (sign-in codes, welcome and sign-in notices, and administrative invitations) |
| Authentication providers | The sign-in token your device receives from the provider | Google and Apple sign-in |
| Infrastructure hosting providers | All application data | Hosting the application and database |
Specific providers are documented in our internal Record of Processing Activities. We ensure all providers offer appropriate data protection guarantees.
7. International Data Transfers
Our application database is hosted in the EU (Frankfurt, Germany). However, some data is transferred outside the EU:
AI processing providers are based in the United States. These transfers are covered by:
- The EU-US Data Privacy Framework, where the provider is certified
- Standard Contractual Clauses (SCCs) as a fallback mechanism
Other providers may process data in various locations. We ensure appropriate safeguards (such as SCCs or adequacy decisions) are in place for any transfers outside the EU/EEA.
8. Data Retention
- Account data and workout data are retained for as long as your account is active
- Uploaded files are retained for as long as your account is active
- Authentication tokens expire automatically and are rotated regularly
- Sign-in codes expire ten minutes after they are sent, and your account record never contains the code itself, only a bcrypt hash of it
- Sign-in code requests leave a record of the email address the code was sent to and the time it was asked for. We keep that record after the code expires, and after an account is deleted, because it is how we limit the number of codes one address can request in an hour; deleting and recreating an account would otherwise clear that limit. These records are not yet removed on a schedule
- Moderation records (reports, moderation decisions and enforcement actions) are kept under section 12, on a legitimate-interest basis, after an account is deleted
- Content preserved for a child-safety investigation is kept for 90 days from the point it is reported to the authorities, and longer where they ask us to keep it. Section 12 explains what this covers
- Direct messages are kept indefinitely, until somebody deletes them. There is no automatic expiry and no scheduled purge of message content; section 13.6 explains what ends a message's life, and 13.8 explains what happens to the messages you sent when you delete your account
- Heart rate and energy from Apple Watch are kept with the session they were recorded in, for as long as that session exists, and can be deleted per session; section 14.6 explains what is kept on your devices before it reaches us
- When you delete your account, your data is permanently removed, including uploaded files from our cloud storage. What is kept is described in sections 12 and 13 and in the sign-in code request records above
9. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Access: You can request a copy of all personal data we hold about you. You can also use the "Download My Data" feature in the app to export your data at any time. The export does not yet include the heart rate and energy from Apple Watch; section 14.7 explains how to get a copy of them.
- Rectification: You can update your profile information directly in the app, or contact us to correct inaccurate data.
- Erasure: You can delete your account at any time from the app's Profile page. This permanently removes your data, including uploaded files. The sign-in code request records described in section 8 and the moderation records described in section 12 survive deletion; those two sections say what is kept. If you need the text of comments you wrote erased as well, write to safety@caliance.app; section 12 explains why that is a separate request.
- Data portability: You can export your data in a machine-readable format (JSON) using the "Download My Data" feature, except the Apple Watch data described in section 14.7.
- Restriction of processing: You can request that we limit how we process your data.
- Objection: You can object to processing based on legitimate interest.
- Withdraw consent: Where processing is based on consent, you can withdraw consent at any time: for AI processing, by deleting your account; for heart rate and energy from Apple Watch, by turning off "Record heart rate from my watch" in the app's Health settings, as section 14.1 explains.
To exercise any of these rights, contact us at privacy@caliance.app. We will respond within 30 days.
Right to Lodge a Complaint
You have the right to lodge a complaint with the Italian Data Protection Authority:
Garante per la protezione dei dati personali
Piazza Venezia 11, 00187 Roma
Website: www.garanteprivacy.it
Email: garante@gpdp.it
PEC: protocollo@pec.gpdp.it
10. Local Storage and Cookies
Caliance does not use cookies or third-party analytics trackers. The app uses the following local storage mechanisms, all of which are strictly necessary for the Service to function:
- Authentication tokens: stored in platform-native secure storage to keep you signed in
- User preferences: theme, language, sound and haptic settings stored via Capacitor Preferences
- Active session state: temporary data for in-progress workout sessions
Because this storage is strictly necessary for the app to function, no consent is required under the ePrivacy Directive.
11. Minimum Age
The Service is intended for users aged 16 and older. We do not knowingly collect personal data from anyone under 16. If you believe a person under 16 has provided us with personal data, please contact us at privacy@caliance.app and we will take steps to delete that data.
12. The Social Feed
The social feed is an optional part of Caliance. If you never join it, nothing in this section describes any processing of your data.
12.1 Our Legal Basis Is Your Consent
Everything else in this policy rests on the contract between us: you asked us to track your training, so we process what that needs. The social feed rests on your consent instead, which you give when you create a handle and can withdraw.
Withdrawing consent means deleting your posts and your handle. It does not affect your training data, which we keep processing under the contract as before.
12.2 What Joining the Feed Collects
- A handle: the public name other people see. You choose it, and it is not your email address
- A date of birth: collected to check you are at least 16. We store it but never publish it, and it is not on your profile
- Your acceptance of the Community Guidelines, and which version you accepted
- A profile picture, if you upload one
- The accounts you follow and the accounts that follow you, plus any accounts you block or mute
12.3 What a Post Publishes, and to Whom
A post is a frozen copy of a finished session, made when you publish it. It carries the figures of that session and, if you chose them, up to four photographs and a caption. Editing or deleting the underlying session afterwards does not change a post that already exists, because the post is its own copy.
What a post never carries, whatever your settings: your height, your sex, your body measurements, your notes, your perceived effort or pain, why you skipped something, how hard you found it, the name of your plan, or any location you recorded. They are left out of the published copy itself, so no display setting in the app can reveal them.
Who sees it depends on your account:
- A public account's posts are visible to any signed-in Caliance user who visits your profile, and appear in the feed of everyone who follows you
- A private account's posts are visible only to followers you have approved
Nothing on the feed is visible without signing in. There is no public web page for a profile or a post, no shareable link that works for a stranger, and search engines cannot reach any of it.
12.4 Photographs, and How Long an Address Works
Photographs you post are processed before they are published: we strip the file's embedded metadata, including any location the camera recorded, re-encode the image, and check it automatically for content that breaks the Community Guidelines. The original file you uploaded is kept privately and is not published.
The published versions are served from a public content-delivery network at unguessable addresses. Nobody can find one by guessing it, and nothing outside the app links to it.
One consequence is not obvious: an address that somebody already has keeps working, including after the post has been deleted or the account made private, until the image itself is removed, and then for as long as a network cache still holds a copy. Deleting a post removes the image and closes that window, but not instantly, and it cannot reach anyone who saved the address beforehand. Every feed served through a content-delivery network works this way.
12.5 Moderation Records, and Why We Keep Them
When you report something, or when something you posted is reported or flagged automatically, we create a moderation record: what was reported, by whom, the automated system's verdict, the decision a person took, and any appeal. We keep these on a legitimate-interest basis after the content and even the account are gone. You cannot run an appeal, an audit or a repeat-offender process on records that erase themselves.
Content preserved for a child-safety investigation is a narrower and stricter case. Where content is identified as child sexual abuse material, it and the associated account data are moved to a location no ordinary part of the service can read, and kept for 90 days from the point it is reported to the authorities, or longer if they ask. Ordinary deletion, including deleting your account, does not remove it, because destroying that material is itself an offence.
If an account is banned, we store a one-way keyed hash of the email address, and of the sign-in provider's identifier where you signed in with Google or Apple. We store the hash, never the address itself, and we use it for one thing: refusing a new signup from the same address. These hashes are kept for 24 months and then deleted. We deliberately do not fingerprint devices or record IP addresses for this purpose, because that would be a much larger intrusion, it is easy to defeat, and it gets households and shared networks wrong.
12.6 Deleting: Two Paths, Because One Is Not Enough
Deleting your account removes your posts and their photographs, your profile picture, your handle, your follow relationships in both directions, your blocks and mutes, your reactions, your profile statistics and the reports you filed.
Comments you left on other people's posts are anonymised rather than deleted. The link to you is removed: the comment shows as being from a deleted user, and no query can associate it with you again. The words stay, so the conversations you were part of still make sense to the people who were in them. At the point of deletion you can choose to have your comments deleted outright instead.
The words themselves can still contain personal data, and anonymising the author does not erase them. That is why there is a second path: write to safety@caliance.app and ask for the text of your comments to be erased, and we will hard-delete it.
Moderation records survive both paths, for the reasons in 12.5.
12.7 Who Else Sees Any of This
- Amazon Web Services (Ireland/Frankfurt): photographs and text you post, or send in a direct message, are sent to an automated content-classification service to check them against the Community Guidelines before publication or delivery. Section 13.3 says what that means for a message. The result is stored on our own moderation record
- Cloudflare: stores and delivers the published images, and scans images it serves against child-safety hash lists maintained by the relevant authorities
No advertising network, no analytics provider and no data broker receives anything from the feed. We do not sell it and we do not share it for anyone else's purposes.
13. Direct Messages
Direct messages are an optional part of the social feed. If you never join the feed you cannot send or receive one, and nothing in this section describes any processing of your data.
13.1 Our Legal Basis Is Your Consent
Messaging rests on the same consent the social feed rests on, given when you create a handle, and withdrawable the same way. It is not covered by the contract between us for tracking your training, and withdrawing it does not affect your training data.
You can only hold a conversation with someone who follows you and whom you follow. This rule is built into how following works and cannot be changed in settings, so nobody you have not chosen can open a thread with you.
13.2 What a Message Stores
A message carries the text you typed, up to four photographs you attached, and at most one shared card: a frozen copy of one of your own finished sessions, or of a post you can see.
We also store, per conversation: which two accounts it is between, when it started, when it was last active, how far each of you has read, whether either of you has muted or hidden it, and the emoji reactions each of you left. Drafts you have not sent stay on your device and never reach us.
13.3 Who Can Read a Message — and We Say Plainly That It Is Not Encrypted End to End
Ordinarily, two people can read a message: you and the person you sent it to. Two automated processes also see it, both described in full below: an automated classifier checks every message before it is delivered, and, unless the recipient has turned previews off, the message's own text is sent to our push-notification provider so it can alert their device.
Messages are not end-to-end encrypted. They are encrypted in transit and at rest, which protects them from anyone outside Caliance, but they remain within our technical reach.
That reach is narrower than "we can read your messages" would suggest, and the system itself enforces the limits below:
- A message is read by a person at Caliance only after it has been reported. There is no browsing, no search across conversations, and no tool that takes a conversation and returns its contents
- A report captures a frozen window: the reported message plus the 10 messages before it and the 10 after, taken at the instant the report was filed. That copy is all a reviewer sees. It is never widened and never refreshed from the live thread
- Every one of those reads is logged: which reviewer opened which item, and when. The log entry is written before the content is returned, and a failed log write fails the read
- Before it is delivered, every message is checked by machine. The text you typed is sent to the automated content-classification service named in 12.7, and any photograph you attached is checked by the same service. This happens on every message you send and on every edit you make. If the check refuses the text, the message is never stored and never sent: the composer tells you it cannot be sent, no person is involved in that decision, and no person sees what you wrote. If it refuses a photograph, the message is not delivered either: it stays visible to you, marked as failed, and never reaches the other person. Where the result is neither a clear pass nor a refusal, the message is delivered normally and an entry is added to our own moderation record for a person to look at. A clear pass is recorded nowhere
- A push notification also carries the text, unless the recipient has turned that off. To tell them a message arrived, we send its text, truncated to a short preview, to Google's Firebase Cloud Messaging, which builds the alert on their device. This follows the recipient's own preference: turning off "Show message previews" in message settings makes every notification they receive from then on say only who a message is from, never what it says
13.4 Photographs, and How Long an Address Works
Photographs you send in a message are processed exactly as photographs you post: we strip the file's embedded metadata including any location the camera recorded, re-encode the image, and check it automatically against the Community Guidelines. All of that happens before the message reaches the other person, and a photograph the check refuses is never delivered. The original file is kept privately and is not served.
They are then served from the same public content-delivery network at unguessable addresses, and the consequence in 12.4 applies here too: an address that somebody already has keeps working until the image itself is removed, and then for as long as a network cache holds a copy. Because a message photograph is delivered by its address, forwarding that address is not the same act as forwarding the message: it hands the image to whoever receives it.
13.5 A Shared Card Is a Permanent Copy
When you share a session result or a post into a conversation, we store a copy of it in that message, made at the moment you sent it.
Deleting the original session, editing it, or deleting the post does not change the card in the thread. We do this deliberately, because a conversation whose contents rewrote themselves would be a poor record of what was said. It also means the copy you shared outlives the original. The only thing resolved live is the button that opens the original: if the original is gone, or you can no longer see it, the card says so and opens nothing.
13.6 How Long We Keep Messages
Indefinitely, until somebody deletes them. There is no automatic expiry, no rolling window and no scheduled purge of message content. People expect to be able to scroll back through a conversation. Deleting it silently after a set period would amount to disappearing messages, a feature we chose not to build.
What ends a message's life is one of: you delete it, the other person deletes it, or an account deletion under 13.8. When both participants have deleted their accounts, the whole conversation including every body is hard-deleted.
13.7 What Your Export Contains, and What It Does Not
"Download my data" gives you your half of every conversation: the messages you sent, with their photographs and shared cards, your reactions, your read positions, and which threads you muted or hid. For each conversation it also gives the other person's handle, when it started and when it was last active.
It does not contain the other person's messages. Their words are their personal data, not yours, and an automated machine-readable copy of them is materially different from what you can already see on screen. A header in the export file explains this, because half a conversation reads oddly without it.
13.8 Deleting: the Same Two Paths as Comments
Deleting your account hard-deletes your message photographs and the images themselves, your shared cards, your reactions, your read positions, and your mute and hide state. It anonymises the messages you sent rather than deleting them: the link to you is removed, the message shows as being from a deleted user, and no query can associate it with you again. At the point of deletion you can choose to have the messages you sent emptied outright instead. They then stay in place as "message deleted" markers, so the other person's conversation is not left full of gaps.
The words are anonymised, not erased, and the words themselves can still contain personal data, so there is a second path, as there is for comments. Write to safety@caliance.app and ask for the text of your messages to be erased, and we will empty it. The other person's messages are untouched either way.
Records made about reported content (what was reported, the automated verdict, and any content preserved for a child-safety investigation) survive both paths, for the reasons in 12.5.
13.9 Links Somebody Sends You Are Delivered Unchecked
A link inside a message is shown to you as a link, and we do not check it against any list of known phishing or malware addresses before delivering it. This is a gap in our protection.
What we do instead: only somebody you follow, and who follows you, can send you one at all; the address you see is the address that opens, with the real site name shown separately, so a link cannot pretend to be somewhere else; and opening one leaves Caliance and opens your browser, so nothing a message links to is ever loaded inside the app. Treat a link from a stranger the way you would treat one in an email.
14. Heart Rate and Energy from Apple Watch
This section applies only if you use the Caliance app for Apple Watch. If you never install it, or never agree on its consent screen, nothing in this section describes any processing of your data.
14.1 Our Legal Basis Is Your Explicit Consent
Heart rate and the other measures below are health data, a special category of personal data under Article 9 of the GDPR. We process them only with your explicit consent, which you give on a consent screen (on your watch, or in the app's Health settings on your iPhone) before anything is read. We record that you agreed, when you agreed, and which version of that text you agreed to.
You can withdraw your consent at any time. Turn off "Record heart rate from my watch" in the app's Health settings and nothing more is sent from your watch; what was already recorded can be deleted per session (14.6) or with your account. Withdrawing does not affect your other training data.
14.2 What Is Read, and When
While a session you started on your iPhone is running, the watch app reads from your watch:
- Heart rate
- Active energy (the calories your movement burns)
When that session ends, it reads once:
- your latest heart-rate variability (HRV) and resting heart rate for that day, shown with the session as context and never as part of it
- your heart-rate recovery: the one-minute figure Apple computes about three minutes after the workout is saved
Apart from these end-of-session reads, nothing is read while no session is running. Apple Health asks separately for each of these types, and you can refuse any of them in Apple's settings; the app cannot tell a refusal from a missing reading and never asks twice.
14.3 What Is Written to Apple Health
Each finished session is saved to Apple Health as a workout, with its heart-rate and active-energy samples, so Apple's activity rings count it. A discarded session is not written. That workout is yours and lives in Apple Health on your devices: deleting heart-rate data in Caliance does not remove it, and how Apple handles it is governed by Apple's own terms.
14.4 Where It Goes, and What It Is Never Used For
Readings travel from your watch to your iPhone over Apple's encrypted pairing connection, and from your iPhone to our servers with that session's log, where they are stored like the rest of your training data (sections 6 and 7 describe where and with whom). We use them only to show you your own training: the live reading during a session, the average and maximum for each set, the average and minimum for each rest, the session's heart-rate chart and time in each zone, and a heart-rate trend on your progress page.
They are never put in a post or on a share card, never sent in a notification, never used for analytics or advertising, and never sent to the AI providers described in section 5.
14.5 Your Trainer
A separate switch, "Share biometrics with my trainer", is off unless you turn it on. No trainer can see your session logs or your heart rate in Caliance today. The switch records your choice for when a trainer can, and at that point we will respect its value at the moment of each request, with no copy kept for the trainer.
14.6 How Long We Keep It, and How to Delete It
- With the session. Heart rate, energy, zones and the per-set figures are stored with the session they were recorded in, for as long as that session exists in your account.
- Per session. Open the session in your history and choose "Delete heart rate data". This removes the heart rate, energy, zones and per-set heart-rate figures for that session from Caliance; your sets, reps and loads stay, and the Apple Health workout is not touched.
- With your account. Deleting your account removes all of it, together with your consent record, your maximum heart rate and the trainer switch.
- On your devices, before it reaches us. Your watch keeps what it recorded until your iPhone confirms receipt, and deletes it after 24 hours in any case. The app on your iPhone keeps what it received until it has been delivered to your account, and deletes anything still undelivered after 14 days. Discarding a session deletes its readings on both devices. If your watch was out of reach of your iPhone, or its app was closed, when you discarded the session, readings it still held can reach your iPhone later and can stay stored there, on your device.
14.7 What Your Export Contains, and What It Does Not
"Download my data" does not yet include the heart-rate and energy data stored with your sessions. Until the export includes it, write to privacy@caliance.app and we will send you a copy in a machine-readable format.
15. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the app or by email before the changes take effect. We encourage you to review this policy periodically.
16. Contact Us
For any questions or concerns about this Privacy Policy or your personal data, contact us at:
Email: privacy@caliance.app