Privacy

Your training log, your email address, and nobody else. This website counts its readers; the app does not. The long version follows.


GETSIXPACK is built and operated by Data Sauna LLC, a Wyoming limited liability company, at 30 N Gould St, Ste R, Sheridan, WY 82801, USA. We are the data controller for everything described here. Contact: .

This website and the app are separate sections, because what they hold is genuinely different. The website is a marketing page and a blog. The app is the product, and it holds your training history — which is the sensitive part and is treated as such. Both measure how they are used; neither carries an advertising identifier, and there is no advertising anywhere in either.

There are no ads on this site or in the app, there is no ad network, and none is planned. Nothing here is funded by selling attention or data.

This website

Three tools measure traffic to getsixpack.app, and they are gated differently because they store different things:

  • Vercel Analytics and Cloudflare Web Analytics run for every visitor. Neither stores anything on your device — no cookie, no browser storage, no fingerprint. Vercel counts a visit by hashing your IP address and your browser together on its own server, and that hash is discarded and rebuilt every day, so it cannot be joined to yesterday's or followed to another site; Cloudflare derives a visit from the request and discards the derivation. Neither company has an advertising business feeding on it.
  • Google Analytics runs only if you choose it on the banner. It is not on the page before that — not even in a cookieless mode, because the request itself would still send your IP address and the page you are on to Google.
  • Microsoft Clarity runs only if you choose it, and it is a separate choice on the banner because it is a different kind of thing: it records your visit as a playable session replay — mouse movement, clicks, scrolls and the path you took through the site — with typed text hidden by its default masking.

The full list, with cookie names and lifetimes, is in the Cookie Policy. You can change your answer at any time with , here or in the footer. We honour the Global Privacy Control browser signal as an overriding opt-out.

The site loads nothing else from a third-party server — the fonts, images and stylesheets are served from this domain, and there are no embeds. It is hosted on Vercel, which keeps standard server request logs (IP address, user agent, the URL requested) for operational purposes. That is a property of hosting anything on the internet rather than a choice this site makes about you.

Legal basis: consent for the cookie-based tools; legitimate interest in knowing whether anyone reads the site, for the cookieless ones and for the server logs.

The app

The app stores three kinds of thing:

  • Your email address, used to sign you in. There is no password — you get a one-time link by email. The address is the account.
  • Your training data: the workouts you programme, every set you log with its weight, reps and effort, the rest you take between them, your bodyweight if you record it, an optional display name and profile photo, and the preferences that go with them, such as units. It also includes any note you write against an exercise — a short line of your own, for the seat number or the grip or whatever else makes the next set start right. That is the one field in the app where you can type anything at all, so if what you type describes your body, it is covered by the Consumer Health Data Privacy Policy along with the rest of your log. It is never sent to an analytics tool, it is never read by us for any purpose, and it is deleted with your account.
  • Your device's time zone — the name of the zone, such as Europe/Helsinki, and nothing more precise. Your app sends it so that a session logged late in the evening lands on the day you trained rather than the next one, which is what every weekly total and every square on your calendar is counted from. It is not location: it is the same name your phone shows in its own clock settings, shared by everyone in a region several hundred miles across. We do not read GPS, we do not ask for location permission, and neither app contains any location code.
  • A local copy of all of it, in the app's own storage on your device, so it works with no signal. Writes queue there first and sync when they can.

Server-side data is held in a Postgres database hosted by Supabase, with row-level security so an account can only ever read its own rows. Deleting the app clears the copy on your device; deleting the account removes the server side.

Heart rate, if you turn it on, is read and thrown away. With the setting enabled the app reads your current heart rate from Apple Health during a rest timer and shows it on the timer. It is never written to our database, never sent to any analytics tool, never cached, and no part of the progression engine reads it. Turning the setting off ends the reading. Health data stays on your device and under iOS's own permissions.

Analytics inside the app

The app uses PostHog and Google Analytics to understand how it is actually used — which screens get opened, which features go untouched, where a flow is abandoned, and whether something crashed. These are product analytics, not advertising.

What they receive is behaviour, not your training. That line is the important one, and it is drawn deliberately:

  • They do get: which screens you open and in what order, that an action happened (a set was logged, a workout was finished, a setting was changed), app version, device model, operating system version, language, approximate region derived from IP, and crash and performance diagnostics.
  • They do not get: the loads you lift, your reps, your effort ratings, your bodyweight, your heart rate, your exercise history, your name, your profile photo, or the contents of any set. The numbers in your log stay between your device and our database.
  • There is no advertising identifier. The app does not use Apple's IDFA, does not ask for App Tracking Transparency permission, and does not track you across other companies' apps or websites.

Analytics events are tied to a pseudonymous identifier for your install so that a sequence of screens reads as one session rather than as unrelated events. Where that identifier is associated with your account, the resulting data is personal data and everything in Your rights over it applies to it too — including deletion.

Turning it off. Email and app analytics is switched off for your account. On iOS you can also switch off Share With App Developers in Settings › Privacy & Security › Analytics & Improvements, which stops Apple sharing your diagnostics with us.

Video demonstrations, and the two steps that reach YouTube

Some exercises carry a short demonstration clip, hosted on YouTube. The card holding it is closed until you open it, and while it is closed nothing is requested from Google at all. Opening an exercise, or scrolling past the card, contacts nobody — there is no player, no image and no connection behind a panel you have not expanded.

Open that card and one thing is fetched: the clip's own still image. That is a single request to Google's image server for a single picture. No player is loaded, no video is streamed, and nothing about you is sent with it. The still is held in memory only, exactly as the player's own data is, and is gone when you leave the screen.

Press play and your device connects to Google to stream the video, the same as opening YouTube in a browser. Google receives what any web request carries — your IP address, your device and app version — and handles it under Google's own privacy policy, not ours. Google is not acting on our instructions here, which puts it in the same position Microsoft is in for Clarity: a controller in its own right for what it collects.

Two things limit it. The player is loaded from youtube-nocookie.com, Google's reduced-tracking embed, which does not set advertising cookies until playback. And whatever it does store is held in memory only and discarded when you leave the screen — it is never written into the app's own storage, so it does not survive to the next session and nothing follows you between exercises. We send Google nothing about you: no identifier, no account, and none of your training log.

Legal basis: your explicit consent for your training log and your bodyweight. A training log is data about your body, which European law treats as a special category — so we ask for it in its own words when you sign up rather than folding it into an agreement to the Terms, and you can take it back by deleting the account, which deletes the data with it. For your email address, performance of the contract to provide the app you asked for. For analytics, your consent, as above. No marketing basis is claimed anywhere, because no marketing is done with any of it.

Your training log is also consumer health data under Washington and Nevada law, and that has its own notice with its own rights: the Consumer Health Data Privacy Policy.

What is not done with it

  • Your training data is never sold or shared. We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are used in US state privacy law — not for money and not for anything else of value. The analytics tools are configured so that neither may use what it receives for its own advertising: Google Signals and ads personalisation are switched off on our property, and PostHog does not have an advertising business.
  • Your training log is never sent to an analytics tool. It goes to our database and nowhere else.
  • There is no advertising anywhere, no ad network, no advertising identifier and no social pixel — in the app or on this site.
  • It is not used to build a profile of you for advertising or to make any automated decision with a legal or similarly significant effect.
  • Nothing you lift is published anywhere. There is no feed and no social layer.
  • Nothing you type is used to train an AI model, ours or anyone else's.

Aggregate, non-identifying figures may be used to work out whether the progression engine is any good — for example, whether prescribed load increases are actually being completed. That work happens on the data already stored and produces numbers about the model, not about you.

Who else processes it

These are the only companies that touch any of it, and each does one job:

CompanyWhat forWhich product
Supabase The database your account and training log live in, plus the sign-in emails. The only processor that touches your training data. App
PostHog Product analytics — which screens and features get used. Receives behaviour and device metadata, never your training log. App
Google Google Analytics. In the app, usage and crash measurement. On the website, cookieless for everyone and cookie-based after consent. App + Website
Apple App Store distribution, and App Analytics — installs, sessions, crashes and performance, reported to us in aggregate, and only from devices whose owner left Share With App Developers on. We receive no identifiable customer data from Apple. Apple's own handling of it is governed by Apple's privacy policy, not ours. App
Vercel Hosting for this website, plus cookieless traffic counts. Website
Cloudflare Cookieless traffic counts. Stores nothing on your device and builds no profile. Website
Microsoft Clarity heatmaps and session replay. Loaded only after consent. Website
YouTube (Google) Exercise demonstration videos. Contacted when you open a demonstration card, for the clip's still image, and again if you press play, for the player itself — from youtube-nocookie.com, and never sent anything about you. Not a processor — Google is a controller for what it collects here. App

Two of these are not processors, and the distinction is worth the sentence. Supabase, Vercel, Cloudflare, PostHog and Google Analytics act on our instructions for the data described above. Microsoft and YouTube do not. For Clarity, Microsoft is a data controller in its own right and uses what it collects for its own purposes as well as producing our heatmaps. For a demonstration video, Google is a controller for whatever the player collects from you. Both are their decision rather than ours, and both are why those two are the only things on either surface that wait for you to act first — Clarity for your consent, a video for your opening the card it sits in.

Most of these companies are in the United States, so data is transferred there. We have a written data processing agreement with each of the ones that process data for us — Supabase, PostHog and Google — under which they act only on our instructions. Transfers out of the EEA and the UK are covered by the European Commission's Standard Contractual Clauses in every one of those agreements. Some of the same providers are also certified under the EU–U.S. Data Privacy Framework, which was upheld by the EU General Court in September 2025 and is under appeal to the Court of Justice. The Clauses are what we rely on, so a change to the Framework's status does not leave a transfer without a basis.

Apple is not one of our processors: it distributes the app and gives us aggregate App Analytics under its own agreement with us, and its handling of your data is governed by Apple's privacy policy rather than by ours.

How long it is kept

Your account and training log are kept for as long as the account exists, because a training log with the old sessions removed is not a training log — the progression engine reads your history to prescribe your next session. Ask for deletion and it goes, along with the account.

Analytics is kept on each tool's own schedule and we set them as short as each allows: Google Analytics deletes event data after 14 months, and Clarity keeps a recording for about 30 days and the aggregate figures built from it for about 13 months. None of it carries your name or your address, and deleting your account clears the app's analytics identifier with it.

Your rights over it

You can ask for a copy of everything held about you, ask for it to be corrected, ask for it to be exported, ask us to restrict or object to how it is processed, or ask for the account and all of its data to be deleted. Email and it gets done. Deletion is deletion, not deactivation, and we do not ask you to justify it.

Where we rely on consent — the website's optional analytics — you can withdraw it at any time, and doing so is one press. If you are in the EU or UK and think we have got something wrong, you can complain to your national data protection authority; we would rather you told us first.

If you are in a US state with a privacy law

Most US state privacy laws apply only above a revenue or user-count threshold, and this company is a single-member LLC well under every one of them. Two laws have no threshold at all — Washington's My Health My Data Act and Nevada's consumer health data law — and Connecticut's dropped its threshold for sensitive data in July 2026. Rather than work out which of them reaches you, we give everybody the same rights.

You can ask us to confirm what we hold, get a copy of it, correct it, take it somewhere else in a portable format, and delete it. You can ask us to stop processing it. Email and it gets done.

We answer within 45 days, and we say so at the start rather than at the end if a request needs the further 45 days the law allows. If we say no, you can appeal, by replying to the refusal. A person reads it, we answer within 45 days, and if we still say no the answer will name your state Attorney General and how to complain to them.

Nothing changes for you if you use any of these rights. The app does not get worse, slower or more expensive, and we will not ask you why. There is no advertising in the app or on this site, so there is no sale or share to opt out of — but if you send the Global Privacy Control signal, this website honours it as one anyway.

Health data has its own notice, because Washington requires it to be a separate document: the Consumer Health Data Privacy Policy.

Security

Data is encrypted in transit and at rest by our hosting providers. Access to your rows is enforced at the database itself with row-level security, so an account cannot read another account's data even if something in the app asked it to. There is no password to steal, because there is no password — which does mean the security of your account is the security of your email inbox.

If your data is exposed, you will hear it from us. US federal rules for health apps require notice to affected people, to the Federal Trade Commission, and — above five hundred people — to the media, without unreasonable delay and inside sixty days of us finding out. We would tell you anyway, and the notice will say what was exposed and when rather than that we take your privacy seriously.

Children

The Service is for adults — 18 and over. It is not directed at children, we do not knowingly collect personal information from anyone under 18, and no account should be created for one. If you believe a minor has created an account, email and it will be deleted.

Changes

If what is stored or who processes it changes, this page changes with it and the date at the top moves. Material changes to how existing data is used get an email, not a silent edit.

Contact

Data Sauna LLC, 30 N Gould St, Ste R, Sheridan, WY 82801, USA. Privacy questions, data requests and deletion requests all go to the same place: . See also the Terms of Use and the Cookie Policy.