Privacy Policy
This Policy explains how personal data is processed in the Trexana app and on the trexana.app website: what is collected, on what legal basis, for what purposes, who it is shared with, how long it is kept and what rights you have. It is drafted to meet the requirements of the Law of Georgia on Personal Data Protection (in force since 1 March 2024), the EU General Data Protection Regulation (GDPR), the Brazilian General Data Protection Law (LGPD) and, where applicable, the California Consumer Privacy Act as amended (CCPA/CPRA).
In short. Workout video and pose detection never leave your device: the analysis runs locally. Only the numeric results of a set — technique scores, detected error types and joint angles — together with your account data reach our server. Your health questionnaire answers and your body calibration profile stay on the device only. We show no ads, use no advertising or analytics SDKs, collect no location data, create no advertising identifiers and never sell personal data.
Contents
- Who is responsible for processing
- What this Policy covers
- What data is processed on our server
- What is processed on your device only
- Device permissions
- What we do not do
- Health and fitness data
- Legal bases, refusal and withdrawal of consent
- Automated processing and profiling
- Who we share data with
- International data transfers
- Retention periods
- Deleting your account and data
- Your rights and how to exercise them
- Complaints and supervisory authorities
- Age restrictions
- Security and data breaches
- The website: cookies, fonts, logs
- Changes to this Policy and language versions
- Contact
1. Who is responsible for processing
The data controller (in LGPD terms, the controlador) is the owner of the Trexana service — an individual entrepreneur registered in Georgia, Tbilisi. Full registration details, including the registered name and address, are provided on written request to privacy@trexana.app.
No separate data protection officer has been appointed: the scale of our processing does not meet the thresholds for mandatory appointment. The person responsible for data protection matters, including the role of encarregado under Article 41 LGPD, is the service owner. Send any data-related enquiry to privacy@trexana.app; we respond within the time limits set out in section 14.
2. What this Policy covers
This Policy applies to the Trexana mobile app and to the trexana.app website. It does not cover processing by the app stores (Google Play, App Store) — when you download the app or buy a subscription they act as independent controllers under their own privacy policies — nor third-party services to which you choose to send content created in the app (for example, a messenger you share a workout card to).
Using the app requires an account. Technique analysis is not available without one, so providing the data marked in section 3 as necessary for the performance of the contract is a condition of using the service.
3. What data is processed on our server
The table below lists every category of data that leaves your device for our server, with the purpose, legal basis and retention period. Legal bases are cited under the GDPR; the equivalent bases under the LGPD (Articles 7 and 11) and Georgian law apply on the same terms.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Email address | Account identification, sign-in, service messages (password reset, material changes to the terms) | Performance of a contract — Art. 6(1)(b) GDPR | Until the account is deleted; then see section 12 |
| Name (if provided) | Addressing you in the interface and in emails | Performance of a contract — Art. 6(1)(b) GDPR | Until the account is deleted |
| Password hash (cryptographic, irreversible) | Authentication | Performance of a contract — Art. 6(1)(b) GDPR | Until the account is deleted |
| Google or Apple sign-in identifier, plus the name and email address received from the sign-in provider | Signing in without a separate password | Performance of a contract — Art. 6(1)(b) GDPR | Until the account is deleted |
| Set results: exercise type, date and duration, repetition count, per-repetition technique score, detected error types, joint angles at key points of the movement, detected camera angle | Workout history, statistics, progress, syncing across devices and restoring your data after reinstalling | Performance of a contract — Art. 6(1)(b) GDPR. See also section 7 on the status of this data | Until the account is deleted, or until you delete the individual record |
| Complex sessions: the make-up of the complex, its sets and the result of each exercise | As above | Performance of a contract — Art. 6(1)(b) GDPR | Until the account is deleted, or until you delete the record |
| App version and operating system version — sent alongside a workout record | Compatibility diagnostics and investigation of analysis failures | Legitimate interest — Art. 6(1)(f) GDPR (keeping the service working) | For as long as the related workout record |
| IP address | Protection against password guessing and abuse (rate limiting), server technical logs | Legitimate interest — Art. 6(1)(f) GDPR (security) | Not stored in our database. In technical logs, no longer than 30 days |
| Password reset code (stored as a hash) | Resetting a forgotten password | Performance of a contract — Art. 6(1)(b) GDPR | 15 minutes, or until the code is used; a maximum of 5 attempts |
| Email change log (the previous address) | Identifying support enquiries and protecting against account takeover | Legitimate interest — Art. 6(1)(f) GDPR (account security) | Until the account is deleted |
| Subscription status: active or not, product type, next billing date, your identifier in the subscription management system | Granting access to paid features | Performance of a contract — Art. 6(1)(b) GDPR | Until the account is deleted. Records of the payments themselves are kept by Google and Apple under their own rules |
| Support correspondence: your email address, the text of your enquiry and any attachments you send | Answering your enquiry and confirming that it has been resolved | Performance of a contract — Art. 6(1)(b) GDPR; legitimate interest — Art. 6(1)(f) GDPR (defence of legal claims) | 24 months after the enquiry is closed; longer only where the correspondence is needed to establish or defend legal claims |
| Anonymised aggregated statistics — summary figures per exercise, not linked to any account | Verifying and calibrating the technique scoring algorithms and correcting systematic detection errors | Legitimate interest — Art. 6(1)(f) GDPR (improving the service); the data is aggregated so that you cannot be identified from it | Indefinitely, in anonymised form |
We do not ask for or store on our server your height, weight, date of birth, gender, phone number, payment details or location data.
4. What is processed on your device only
Some data technically never leaves your device: it is not sent to our server, is not backed up by us and is not accessible to us in any form. This applies to the following.
- Camera video and pose detection. Frames are processed locally by a human pose detection library. Neither images, nor video files, nor the frame-by-frame coordinates of body points are transmitted to our server — only the numeric results of the set listed in section 3.
- Video recordings of your sets. Saved to device storage so that you can review a repetition, and deleted together with the app's data.
- Body calibration profile — the ratios between limb segments (for example, thigh to torso) used to adjust the analysis thresholds. Computed and stored on the device.
- Health questionnaire answers. The optional questionnaire (pregnancy and the post-partum period, lower back pain or a disc hernia, sensitive joints, cardiovascular or blood pressure limitations, a recent injury, balance problems, returning to training after a break) exists only so that the app can show warnings before higher-risk exercises. The answers are stored on the device.
- Profile photo. If you pick an avatar from your gallery or take one with the camera, the image stays on your device; only a reference to the local file within that device is stored.
- Achievements, streaks and interface settings (theme, language, rest duration, reminders) — computed and stored locally.
Biometrics. Pose detection serves solely to assess movement technique. It is neither intended for nor used for uniquely identifying a person, and the data processed is therefore not biometric data within the meaning of Article 4(14) GDPR. We do not use facial recognition and do not build biometric templates.
Sharing. A workout result card can be saved as an image and sent anywhere using your operating system's share function. Such a transfer happens only on your instruction, the image is generated on the device and it does not pass through our server.
5. Device permissions
The app asks for permissions immediately before the relevant feature is first used. Any permission can be withdrawn in your operating system settings; withdrawing it disables the corresponding feature and leaves the rest working.
| Permission | Why it is needed | If you refuse |
|---|---|---|
| Camera | Recording a set and detecting your pose on the device | Technique analysis is impossible — this is the app's core function |
| Photos and media | Choosing a profile photo from your gallery; saving set recordings on the device | Your avatar stays schematic and video review is unavailable |
| Notifications | Local workout reminders and achievement messages. Notifications are scheduled by the device itself; no push token is created or sent to our server | No reminders; nothing else is affected |
| Network access | Signing in, syncing results, checking subscription status | Results stay on the device and are not synced |
6. What we do not do
- We show no ads and embed no advertising networks.
- We use no analytics or tracking SDKs, collect no advertising identifiers (Google Advertising ID, IDFA) and apply no device fingerprinting.
- We do not collect location data, contact lists, clipboard contents or the list of installed apps.
- We do not sell personal data and do not share it for targeted advertising. In the past twelve months we have not sold or shared personal data within the meaning of the CCPA/CPRA, and we do not intend to.
- We do not track you across other websites or apps.
- We do not disclose health or workout data to third parties for marketing purposes.
- We do not use your data to train general-purpose machine learning models. The technique scoring algorithms are deterministic rules calibrated by hand; only anonymised aggregated statistics are used to check that calibration (section 3).
7. Health and fitness data
Information about how you perform exercises may, in some jurisdictions, fall into a special category — "data concerning health" (Art. 9 GDPR), "sensitive personal data" (Art. 11 LGPD) and "sensitive personal information" (CPRA). We split such data into two groups and treat them differently.
Health questionnaire answers. The questionnaire described in section 4 relates directly to your health. That is precisely why it is optional and why its results are not sent to our server: processing takes place locally, on the basis of your explicit consent, given by the act of completing the questionnaire, and solely in order to display warnings before exercises. You can withdraw consent at any time by clearing the boxes in your profile, after which the warnings stop appearing.
Workout results. Technique scores, error types and joint angles describe the quality of a movement rather than a state of health: they contain no diagnosis, symptom, anthropometric or clinical measurement and support no inference about a medical condition. We process them on the basis of performance of the contract rather than consent, because the service cannot function without them. We nevertheless apply to them the heightened safeguards appropriate to special categories of data, do not use them for marketing profiling and disclose them to no one other than the infrastructure providers listed in section 10. Should the law applicable to you nonetheless classify this information as health data, the additional basis for processing is your explicit consent, given when you create your account, which you may withdraw by deleting your account.
Trexana is not a medical device and issues no medical findings. The conditions of use relating to your health are set out in the Health Disclaimer; our liability is governed by the Terms of Use.
8. Legal bases, refusal and withdrawal of consent
We rely on four legal bases, identified for each category in the table in section 3:
- Performance of a contract (Art. 6(1)(b) GDPR; Art. 7(V) LGPD) — running your account, technique analysis, history and statistics, access to paid features.
- Legitimate interest (Art. 6(1)(f) GDPR; Art. 7(IX) LGPD) — security and protection against abuse, failure diagnostics, algorithm calibration on anonymised data, defence of legal claims. We have weighed our interest against your rights and limited the data to the minimum needed for those purposes; you may object to this processing (section 14).
- Explicit consent (Art. 9(2)(a) GDPR; Art. 11(I) LGPD) — only for the optional health questionnaire, which is processed on the device.
- Compliance with a legal obligation (Art. 6(1)(c) GDPR; Art. 7(II) LGPD) — retaining records we are required by law to keep, for example for tax purposes.
Consequences of not providing data. Account data and set results are necessary to deliver the service: without them you cannot register or use technique analysis. Everything else — the health questionnaire, your name, a profile photo, notifications, calibration — is optional, and declining it limits only the corresponding feature.
Withdrawing consent. You may withdraw consent at any time, in the app's settings or by writing to privacy@trexana.app. Withdrawal does not affect the lawfulness of processing carried out before we received it.
9. Automated processing and profiling
Technique scoring, repetition counting, awarding achievements and assigning a league are performed automatically, according to predefined rules. This processing does not amount to a decision producing legal effects concerning you or otherwise significantly affecting you within the meaning of Article 22 GDPR and Article 20 LGPD: the output is a training recommendation and has no bearing on your rights, your access to the service, the terms of the contract or the price you pay. We do not use automated processing for creditworthiness assessment, scoring or any other decision about you as a person. Under Article 20 LGPD you may request a review of an automated outcome — write to us and we will examine the individual set manually.
10. Who we share data with
We do not sell data and do not share it with advertising networks. Access is granted only to the service providers needed to operate the service; each acts as a processor (operador) under a data processing agreement, within the scope of our instructions and with no right to use the data for its own purposes.
| Provider | Role | What it processes | Country | Transfer mechanism |
|---|---|---|---|---|
| Railway | Backend and PostgreSQL database hosting | All data in the table in section 3 | Netherlands (EEA) | Data processing agreement. Processing takes place within the EEA |
| RevenueCat, Inc. | Subscription status management | User identifier, subscription status and product type | Netherlands (EEA) | Data processing agreement. Processing takes place within the EEA |
| Google (Google Play Billing, Sign in with Google) | Payment processing and authentication. For payments Google acts as an independent controller | Payment details (never passed to us), email address and name on sign-in with Google | Ireland, United States | Google's terms, EU-US Data Privacy Framework, EU Standard Contractual Clauses |
| Apple (App Store, Sign in with Apple) | Payment processing and authentication, on Apple devices only. For payments Apple acts as an independent controller | Payment details (never passed to us), email address and name on sign-in with Apple | Ireland, United States | Apple's terms, EU Standard Contractual Clauses |
| Plus Five Five, Inc. (Resend) | Transactional email delivery — for example, password reset codes | Email address, message content | United States | Data processing agreement, EU Standard Contractual Clauses. Sub-processor list: resend.com/legal/subprocessors |
| Cloudflare, Inc. | Website hosting, DNS and email routing for the domain | Website visitor's IP address and request headers; the content of email sent to @trexana.app addresses | United States, global network | Data processing agreement, EU Standard Contractual Clauses |
We may also disclose data where the law requires it — in response to a binding request from a competent authority — or where disclosure is necessary to establish, exercise or defend legal claims, or to prevent a threat to life and health. We notify the data subject of such requests unless the law prohibits it.
The list of providers may change. The current list is always the one in this section; if we add a provider that gains access to account or workout data, we will announce it as described in section 19.
11. International data transfers
User data is stored on servers in the Netherlands, that is, within the European Economic Area. The controller is registered in Georgia and accesses the data from outside the EEA; some ancillary providers are in the United States.
- Users in the EEA and Switzerland. The primary storage — the service database and files — is located in the Netherlands, so for that processing the data does not leave the EEA. The controller, however, accesses the data from a country outside the EEA in respect of which the European Commission has not adopted an adequacy decision. To the extent that such access amounts to a transfer within the meaning of Chapter V of the GDPR, it takes place on the basis of the standard contractual clauses adopted by the European Commission (Article 46(2)(c) GDPR), supplemented by a transfer risk assessment and technical measures — channel encryption and restricted access. Transfers to individual providers in the United States (section 10) take place under standard contractual clauses or, where the provider is certified, under the EU-US Data Privacy Framework (Article 45 GDPR). A copy of the applicable contractual safeguards can be requested by writing to privacy@trexana.app.
- Users in Brazil. Data is stored in the Netherlands and is accessible to the controller from outside the EEA. Transfers take place on the grounds set out in Article 33 of the LGPD, primarily contractual clauses ensuring a level of protection comparable to that required by the law.
- Users in Georgia. Data is stored in the Netherlands. Transfer of data to another state takes place in accordance with the requirements of the Law of Georgia on Personal Data Protection and on the basis of agreements with providers that ensure appropriate safeguards.
12. Retention periods
The period for each category of data is given in the table in section 3. The general rules are:
- Account and workout data is kept for as long as the account is active.
- When you delete your account, the data is kept for a further 14 days: during that window signing in cancels the deletion, so an accidental or premature decision can be undone. After the 14 days the data is deleted irreversibly.
- Data disappears from backups within 30 days of deletion — a technical buffer against failure.
- Records we are required by law to keep (for example, for tax purposes) are retained for the statutory period regardless of account deletion.
- Records of payments are kept by Google and Apple under their own rules; that period is outside our control.
- Anonymised aggregated statistics are kept indefinitely, as they are not personal data.
13. Deleting your account and data
There are two ways to delete your account.
- In the app: Profile → the "Account" section → "Delete account".
- Without the app: by email from the address the account is registered to, following the instructions on the account deletion page. Requests are processed within 10 business days.
The same procedure applies in both cases: deletion is deferred by 14 days, during which signing in cancels it; after that the account, your workout history and your settings are deleted permanently, and the data disappears from backups within the following 30 days. Video recordings of your sets, your calibration profile, health answers and achievements exist only on your device — they are removed together with the app's data, so deleting the app or clearing its data is enough.
Deleting your account does not cancel a subscription bought through Google Play or the App Store: cancel it separately in the settings of the relevant store. Cancellation and refunds are described in the Subscription Terms.
14. Your rights and how to exercise them
Depending on the law that applies to you, you may:
- obtain confirmation that processing is taking place and a copy of your data, including in a machine-readable format for transfer to another controller (access and portability);
- have inaccurate data corrected and incomplete data completed;
- delete your account and data (erasure);
- restrict processing, or object to processing based on legitimate interest;
- withdraw consent, without affecting the lawfulness of processing before withdrawal;
- find out who your data has been shared with and be informed of the consequences of refusing consent (Art. 18 LGPD);
- request the anonymisation, blocking or deletion of unnecessary or excessive data, or of data processed in breach of the law (Art. 18(IV) LGPD);
- if you are a California resident, know the categories of data we collect, their sources and the purposes of collection, request deletion and correction, and limit the use of sensitive personal information; we neither sell nor share data, so there is no need to exercise an opt-out from sale. We will not discriminate against you for exercising any of these rights;
- if you live in another US state with a privacy statute, additionally appeal a refusal to act on your request; the appeal route is the same as the request route.
How to make a request. Write to privacy@trexana.app from the address your account is registered to and state which right you wish to exercise. The sender's address serves as verification of identity; if the message comes from a different address we may ask for additional information to match it to an account — solely for verification and without retaining it. You may also submit a request through an authorised agent, enclosing proof of their authority.
Response times. Under the GDPR, within one month; for complex or numerous requests the period may be extended by a further two months, and we will tell you why. Under the LGPD, immediately in simplified form and within 15 days in full form. Under the CCPA, acknowledgement within 10 business days and a substantive response within 45 days, extendable. Exercising your rights is free of charge; we may charge a fee only for manifestly unfounded or excessively repetitive requests.
15. Complaints and supervisory authorities
If you believe your rights have been infringed, tell us first — we will try to resolve the matter directly. Independently of that, you have the right to complain to a supervisory authority:
- Georgia — the Personal Data Protection Service (personaldata.ge), the authority of the controller's place of registration;
- EEA — the data protection authority of your country of residence, place of work or the place of the alleged infringement;
- Brazil — the National Data Protection Authority (ANPD);
- United Kingdom — the Information Commissioner's Office (ICO);
- California — the California Privacy Protection Agency or the State Attorney General's office.
16. Age restrictions
Trexana is intended for persons aged 18 and over. The restriction reflects not only the rules on minors' consent to data processing (Art. 8 GDPR, Art. 14 LGPD, COPPA) but the nature of the service: the app gives an automated, non-medical assessment of physical exercise, which for anyone under 18 would require the parental control and medical supervision the service does not provide. We do not knowingly collect data from persons under 18. If we learn that an account belongs to a minor, we will delete it and the associated data. If you believe a minor has given us data, write to privacy@trexana.app.
17. Security and data breaches
We apply technical and organisational measures proportionate to the risks of the processing: data travels between the app and the server only over a secure connection (HTTPS/TLS); passwords are stored as cryptographic hashes and never in plain text; access to the production database is limited to those who need it and protected by separate credentials; sign-in and password reset operations are rate-limited; password reset codes are stored as hashes with a short lifetime and a cap on attempts. Video and health data never leave the device, which by itself removes an entire class of risk.
No system is completely secure. In the event of a breach likely to result in a risk to your rights and freedoms we will notify the supervisory authority within 72 hours of becoming aware of it (Art. 33 GDPR) and, where the risk is high, notify you without undue delay, describing the nature of the incident, its likely consequences and the measures taken. Equivalent notifications are made within a reasonable time under the LGPD and the Law of Georgia on Personal Data Protection.
18. The website: cookies, fonts, logs
The trexana.app website uses no cookies for analytics, advertising or tracking and sets no trackers. No analytics service is connected to the site; should one be added, we will update this section before it goes live and, where the law requires it, ask for your consent.
The fonts used on the site are hosted on our own domain and loaded from it. Opening a page triggers no requests to third-party font CDNs, including Google Fonts, and your IP address is therefore not disclosed to any third party for that purpose.
Our hosting provider keeps technical access logs, including the IP address, the date, the address requested and the browser type. This data is processed on the basis of our legitimate interest in keeping the site available and secure (Art. 6(1)(f) GDPR) and is not used to build visitor profiles.
The language you select on the site is stored in your browser's local storage. This is a technical setting needed to show pages in the chosen language; it is not shared with third parties and is removed when you clear site data in your browser.
19. Changes to this Policy and language versions
This Policy may be updated — for instance when new features appear or a provider changes. The effective date and version number are shown at the top of the page. We will announce material changes affecting the scope of data processed, the purposes of processing, the recipients or your rights in the app or by email at least 14 days before they take effect; minor edits such as clarified wording or corrected typos take effect on publication. Where a change requires consent, we will ask for it separately and before the new processing begins.
This Policy is published in six languages. All versions are updated at the same time and are identical in substance. In the event of a discrepancy between translations, this English version prevails.
20. Contact
For data protection matters and to exercise your rights: privacy@trexana.app. For questions about the app and your subscription: support@trexana.app. The controller's full registration details are available on request.