Gradus
Privacy Policy
This app keeps a record of your training and, if you choose to give them, a few facts about your body. This page says exactly what is stored, what each field is used for, who can reach it, and how to take it back or destroy it.
Last updated [EFFECTIVE DATE — set before launch]
1. Who we are
Gradus is a strength-training log, used in a web browser on a phone or a computer. It is operated by [LEGAL ENTITY — set before launch] (“we”, “us”). You can reach us at [CONTACT EMAIL — set before launch].
We are not a healthcare provider and this app is not a medical device. See the Terms of Service for what the coaching and calorie figures are and are not.
2. What we collect
All of it comes from you. We do not buy data about you, and we do not collect anything in the background that is not listed here.
Your account
- Email address
- Identifies your account at sign-in and is where a password-reset link is sent.
- Name
- Shown to you in the app. Nothing else reads it.
- Password
- Stored only as a bcrypt hash. The password itself is never written to the database, and we cannot recover it or read it back — which is why a forgotten password can only be reset, never retrieved.
- The date the account was created
- Recorded automatically when you sign up. Routines and goals carry a creation date in the same way. All of them appear in your export.
We do not ask for a phone number, a postal address, a photograph, or a payment method.
Your training
Everything you log, and only what you log:
- Sessions — the workout type, the date, the times you started and finished, any notes you write, and a stored calorie figure where one was recorded.
- Exercises — which movements you did, chosen from a shared exercise library.
- Sets — reps, weight, set order, whether the set was completed, whether it was a warm-up, the rest prescribed for it, and your RPE (rating of perceived exertion) when you record one.
- Drop sets — the reps and weight of each drop.
- Routines — the templates you build: their name and description, their exercises, target sets, target rep ranges and rest.
- Strength goals — your target one-rep max, the unit you stated it in, an optional target date, and the date you hit it.
- Movements you add to the shared library — if the exercise you want is not already listed, the name you give it and any muscle group, equipment and instructions you enter, recorded with you as its author. Because the library is shared, these behave differently from everything else here when you delete your account — see section 8.
Your body weight
Each weigh-in you enter: a number and the date you entered it for. This is health information, and it is treated as such throughout this policy.
Your preferences
Whether you work in kilograms or pounds, and your default rest between sets.
Technical data
- One cookie. A session cookie, set when you sign in on the web. It holds a signed token and nothing else, it is marked
HttpOnlyso page scripts cannot read it, it is restricted to this site, it is sent only over HTTPS in production, and it expires after seven days. There are no analytics, advertising or tracking cookies, because there is no analytics, advertising or tracking in this app at all. - On phones and tablets the sign-in token is kept in the operating system’s secure storage — Keychain on iOS, Keystore on Android — rather than in a cookie.
- Failed sign-in counters. Repeated failures are counted in the server’s memory, keyed by the email address that was tried and — only where the server sits behind a proxy it has been configured to trust — by network address. These counters expire after fifteen minutes and are lost whenever the server restarts. They are never written to the database.
- Server logs. Ordinary operational and error logs. Height, date of birth and biological sex are deliberately kept out of them: when a write of those fields fails, the code logs the error and not the values.
3. Optional biometrics
Three fields are optional in the strongest sense: the app works without them, every screen works without them, and you can add them, change them or clear them at any time. They are height, date of birth, and biological sex.
They exist for one reason — sharpening the calorie estimate, and in the case of age, the projection toward a strength goal. When one is missing, the app does not substitute an average. It widens the estimated range and tells you on screen which fact it was missing, so a guess is never presented as a measurement.
What the biological sex field is
It selects a coefficient set, and does nothing else. The Mifflin-St Jeor resting-metabolic-rate equation — the one this app uses — is published as two sets of coefficients, fitted on the cohorts the original studies labelled male and female. Choosing between those two constants is the entire purpose of this field.
It is not a question about gender identity, it is never displayed, exported or reused as one, and it is not shared with anyone. It offers two options because the equation has two, not because people do. Leave it blank and the estimate simply covers both coefficient sets and says so on screen.
4. What we do not do
- We do not sell, rent or trade your data. Not to anyone, ever.
- We do not show advertising and we do not share anything with advertisers, data brokers or analytics companies.
- We do not track you across other sites or apps. The app loads no third-party scripts, pixels or fonts at run time.
- We do not build a profile of you from anything other than the training you logged yourself.
- We do not use your training data to train machine-learning models.
5. Third parties
Generated workouts stay on our server
The app can fill a session with a prescribed workout. That plan is produced by a coaching engine that runs inside this application, as arithmetic over the training you have already logged. There is no external model, no third-party API key, and no request to any outside service. Nothing about your training leaves our server when you generate a workout.
The app sends email in exactly two situations: when you ask for a password-reset link, and when an administrator creates an account for you and the app mails you your initial sign-in details. Where email delivery is configured, it is sent through Google’s Gmail service, so the message — your email address and the credential it carries — passes through Google’s mail servers and is subject to their handling of mail in transit.
No workout, weigh-in or biometric is ever included in an email. If email delivery is not configured on a deployment, no message is sent at all and a reset request simply produces nothing.
Hosting
The application and its PostgreSQL database run on [HOSTING PROVIDER AND REGION — set before launch], who necessarily have the ability to access the machines the data sits on. Your data is stored in one database that we control; it is not copied to any other service.
6. Who can see your data
- You.
- No other user. Every request that reads a workout, a set, a weigh-in or a biometric carries your account identity into the database query itself, so a request naming somebody else’s record answers “not found” rather than returning it. There is no sharing feature, no social feed and no public profile.
- Administrators, partially. An account marked as an administrator can list the accounts on the deployment — names, email addresses, and whether each is an administrator or enabled. There is no feature, for administrators or anyone else, that returns another person’s workouts, weigh-ins or biometrics.
- Us, when we have to. Operating the service means having access to the database. We read individual records only when it is necessary to run, repair or secure the app.
- Anyone we are legally compelled to give it to, if we receive a valid legal demand.
7. Security
- Passwords are hashed with bcrypt, each with its own salt. We store the hash, never the password.
- Sessions are signed JSON Web Tokens (HS256) that expire after seven days — held in an
HttpOnlycookie, which JavaScript on the page cannot read. - Every authenticated request re-checks your account against the database rather than trusting the token alone, so disabling an account takes effect immediately instead of whenever its token happens to expire.
- Password-reset links expire in thirty minutes and can be used once. Completing a reset invalidates every outstanding reset link for that account.
- Sign-in attempts are throttled, and every failed attempt is answered identically, so the sign-in form cannot be used to discover which email addresses have accounts here.
No service can promise perfect security, and we do not. What we can say is what the code does, which is the list above.
8. Export, correction, deletion
Correct it
Every value you have entered can be edited or deleted in the app itself — a mistyped set, a weigh-in on the wrong day, a biometric you would rather not have given. Clearing an optional biometric erases it; it is not merely hidden.
Export it
You can download a machine-readable copy of your account details, your full training history, your weigh-ins and your biometrics from your profile.
Delete it
You can permanently delete your account from within the app. It is a real deletion, not a flag: the account row and everything that hangs off it are removed from the database.
Deleting your account removes:
- your account record, including your email, name, password hash and biometrics;
- your entire weigh-in history;
- every workout session, and with it every exercise, set and drop set;
- every routine you built, and the exercises in it;
- every strength goal.
One thing survives, and you should know about it before you delete. If you added a custom exercise name to the shared exercise library, that library entry stays — but the record of who created it is erased, so it is no longer connected to you. It has to stay because other people’s logged workouts point at that name, and removing it would tear holes in training histories that are not yours to delete. What remains is the name of a movement and its muscle group, equipment and instructions: nothing that identifies you, and nothing you logged.
Backups are a separate matter: [BACKUP RETENTION AND PURGE WINDOW — set before launch].
9. Retention
We keep your data for as long as your account exists. Nothing expires on a schedule, and that is deliberate: a training log is worth more the longer it runs, and silently dropping a session from three years ago would break the progress and goal projections that read it. When you delete your account, it goes.
The short-lived exception is the failed-sign-in counters described above, which expire after fifteen minutes.
10. Children
Gradus is not directed to children under 13, and we do not knowingly collect information from them. If you believe a child has created an account, contact us and we will delete it.
11. Changes to this policy
If we change what we collect or what we do with it, we will update this page and the date at the top. If a change is significant, we will tell you in the app or by email rather than relying on you to re-read this page.
12. Contact
Questions about this policy, or a request about your data: [CONTACT EMAIL — set before launch], [POSTAL ADDRESS — set before launch].