IpsoFit

Privacy Policy

Version 1.3 — last updated 15 September 2026

1. Who is responsible

IpsoFit is developed and operated by Carlos Barrado, an individual developer ("we", "us"). We are the data controller for the account data described in this policy. Contact: support@ipsofit.com.

2. In short

3. Data that stays on your device

Everything IpsoFit knows about your training lives in a database file inside the app's private storage on your device: Pomodoro sessions, exercise blocks and sets, completed repetitions, muscle-group statistics, exercise calibration, equipment context, reminders and every other setting. This data is not uploaded, synchronised or backed up by us. It is removed when you uninstall the app (Android), when you use the operating system's "Clear data" (Android), or when you tick "Also erase workout data on this device" while deleting your account (desktop). The Android app opts out of Android's automatic app backup, so no copy of this data — or of your sign-in session — is kept in your Google account backup, and a reinstall starts fresh.

On desktop you can export this database to a file of your choosing (Settings → Data → Export) and import it again later. The exported file is yours: where you keep it and who you share it with is under your control.

4. Account data we process on a server

IpsoFit is in a closed beta. To use it you create an account, and an administrator approves your request. For that we process:

DataWhy
Email addressIdentifies your account; lets us notify the administrator of your access request and contact you about it.
Sign-in method and, for Google sign-in, the identifier and basic profile information Google shares (name, profile picture URL)Authenticates you. Stored by our authentication provider as part of the identity record.
Role (user, tester or admin), access status (pending, approved or rejected) and a subscription tier (unused during the beta)Controls what the app lets you do. Included as claims in your sign-in token.
Access request record: your email plus a one-time token, only while your request is pendingPowers the administrator's approve / reject links. Deleted the moment a decision is made.
Authentication logs: IP address, device/browser identifier and timestamps of sign-in eventsKept by our authentication provider for security and abuse prevention, for a limited period set by the provider.
Session tokensStored on your device so you stay signed in; refreshed automatically.

Legal basis. We process this data to provide the service you asked for and to run the beta under the Terms of Use (performance of a contract), and to keep the service secure and limited to approved people (our legitimate interest). If you choose Google sign-in, Google's own privacy policy governs what Google does on its side.

Passwords for email sign-in are hashed by our authentication provider; we never see or store them in clear text.

5. Connections the app makes

That is the complete list. IpsoFit does not send telemetry, usage statistics, crash reports or advertising identifiers anywhere.

6. Service providers

We use a small number of providers who process data on our behalf:

ProviderWhat they do for usWhere
Supabase, Inc.Authentication, the database holding the account records in section 4, and the file storage that serves app updates.Our project is hosted on AWS in eu-west-1 (Ireland, EU). Supabase is a US company; its Data Processing Addendum with standard contractual clauses covers any access from outside the EU.
Resend, Inc.Sends the administrator one email per access request, containing the requesting email address.United States. Only your email address and the request links are in that message.
Google LLCIdentity provider, only if you choose "Sign in with Google".Per Google's privacy policy.
GitHub, Inc.Hosts this website and the page the administrator uses to confirm an approval (GitHub Pages).GitHub Pages records visitor IP addresses for security under GitHub's privacy statement.

We do not sell personal data, share it with advertisers, or use it for profiling.

7. How long we keep data

8. Your rights and how to use them

Under the GDPR and similar laws you can ask for access to, rectification of, erasure of, or a copy of your personal data, ask us to restrict or object to processing, and complain to your data protection authority. Most of it you can do yourself:

9. Children

IpsoFit is not directed at children. Do not create an account if you are under 16.

10. Security

All connections use TLS. Account rows are protected by row-level security so a signed-in user can read only their own record; administrative actions run through server-side functions that verify the caller. Approval links are single-use tokens. Your workout data never reaches a server, which is the strongest protection we can offer for it.

11. Changes to this policy

We will post any change here with a new version number and date. If a change materially affects what we do with your data, the app will tell you the next time you open it.

12. Contact

Carlos Barrado — support@ipsofit.com
92 Kingsmere, London Road, Brighton BN1 6UY, United Kingdom.