Privacy Policy

Last updated: August 2026

1. Data Controller and Contact

The controller of your personal data is NodeonLabs s. r. o., Vajanského nábrežie 64/5, 811 02 Bratislava, Slovakia, company ID (IČO) 57464031, registered in the Commercial Register of the Bratislava III City Court, Section Sro, Insert No. 196669/B, tax ID (DIČ) 2122767911, VAT ID (IČ DPH) SK2122767911. We operate Treneris — the web app at treneris.sk and the Treneris mobile app for iOS and Android. For anything to do with your personal data, including exercising your rights, write to hello@treneris.sk; it is the single contact address for the whole product. We have not appointed a Data Protection Officer — at our scale of processing the GDPR does not require one.

2. Who These Terms Apply To

Three groups. Clients who train with their coach through Treneris. Coaches who run their clients through Treneris. And visitors who fill in the interest form on our website or book a consultation through a coach's public page. Your coach can see the data you entered in the app or shared with them — that is the point of the service, not a leak. Progress photos are shown to your coach only when you explicitly share them. How a coach handles your data while delivering their own coaching services is the coach's responsibility; we are responsible for running the platform and for the processing described here.

3. What Categories of Data We Process

Identity and contact data: name, email, phone number, profile photo, language. Health and fitness data: date of birth, sex, height, weight, activity level, body measurements (chest, waist, hips, arms, thighs, abdomen, calves), training goal, progress photos, workout records including individual sets, reps and weights. Dietary data: allergies, intolerances, preferred and disliked ingredients, dietary goals, meal plans and food diary entries. Service data: bookings and sessions, group class attendance, credits and cooperation terms, coach notes and tasks, requests to extend or end the cooperation, ratings, reviews and any feedback you send us from the app. Payment data: payment records, amounts, dates and status; if you are a coach, also your bank details (IBAN, bank name, account holder) for payouts. Communication data: notifications, the emails we send you, invitations, and records of consents granted and withdrawn. Technical data: see sections 8 and 9. Prospect data: name, email, phone, and optionally gym name, Instagram handle and your answers to the coach's pre-consultation questions.

4. Health Questionnaire and Electronic Signature

Before training starts, your coach may ask you to complete a health questionnaire (PAR-Q). It stores your answers about heart conditions, chest pain during exertion and at rest, dizziness, bone and joint problems and blood pressure medication, plus a list of medical conditions, allergies and intolerances, medications you take, past surgeries, injuries and any additional notes. This is health data — a special category under Art. 9 GDPR — and we process it solely on your explicit consent, so your coach can build a training and nutrition plan that is safe for you. You confirm the questionnaire with an electronic signature. Alongside the signature image and the time of signing we also store the IP address and the browser or app identification (user agent) at the moment of signing. These three items exist only as evidence that the signature was made — we do not use them for tracking, profiling or location, and we do not disclose them to your coach. We store the same two items, IP address and user agent, every time a consent is granted or withdrawn, and the IP address on audit records and on public form submissions. The legal basis for them is our legitimate interest in proving that consent was valid and in protecting the platform (Art. 6(1)(f) GDPR).

5. Legal Bases for Processing

Performance of a contract (Art. 6(1)(b) GDPR): running your account, bookings and sessions, credit and payment records, transactional emails and notifications. Explicit consent (Art. 6(1)(a) together with Art. 9(2)(a) GDPR): all health, fitness and dietary data including progress photos and the health questionnaire, and publishing your review. You can withdraw consent at any time in Settings → Privacy, without affecting the lawfulness of processing before withdrawal. Legal obligation (Art. 6(1)(c) GDPR): accounting and tax records. Legitimate interest (Art. 6(1)(f) GDPR): platform security, protection against bots and abuse, audit records, evidence of signature and consent, error diagnostics and fraud prevention.

6. Artificial Intelligence Features

Two Treneris features send text to the external service OpenRouter (openrouter.ai), which routes the request to a language model provider (by default OpenAI, model GPT-4o). Their servers are outside the European Economic Area. Meal plan generation: we send the calorie target, the number of days and meals, your training goal, dietary preferences and goals, allergies and excluded ingredients, your language, and your coach's free-text nutrition notes about you. We do not send your name, email, phone number, date of birth, photos or account identifier. Food diary calorie estimates: we send exactly the text you typed into the diary, the meal slot and the language. The text is sent unchanged — if you type a name or another personal detail into it, it goes too, so keep the meal description to what you actually ate. The same applies to the free-text nutrition notes your coach writes. Both features are blocked server-side whenever you have Restrict Processing switched on in Settings → Privacy; the text then never leaves our database. An AI result is a draft, not medical advice — your coach reviews and edits it. We do not carry out automated decision-making with legal or similarly significant effects under Art. 22 GDPR.

7. Payments, Subscription and Invoicing

Payments are processed by Stripe (Stripe Payments Europe, Ltd. and Stripe, Inc.). You enter card details directly on Stripe's page — they never pass through our servers and we never store them. We keep only the amount, date, status, payment method, the payment note and Stripe's reference identifiers. For a client's online payment we send Stripe the amount, the currency and a line-item name, which is the payment note or, if there is none, the client's name. The Warmup plan is free and involves no payment, so nothing is sent to Stripe for it. For a paid Lift subscription we send Stripe the coach's name, email and internal identifier; the billing address and card details are entered by the coach directly into Stripe's form. If a coach enables online payments, Stripe opens a Stripe Connect account of the Standard type for them. Identity and source-of-funds verification (KYC) is carried out by Stripe directly — name, address, date of birth, identity documents and bank details are entered by the coach into Stripe's form and we neither see nor store them; from our side, Stripe receives only the coach's email and internal identifier. Payouts are made by Stripe directly to the coach. Bank details (IBAN, bank name, account holder) that a coach enters inside Treneris for payments outside Stripe are stored by us and used only for payouts. Coach subscriptions are purchased and managed on the web only.

8. Push Notifications and Device Data

If you turn notifications on, we store the identifier they are delivered to: in the mobile app it is an Expo token, which is then routed through Firebase Cloud Messaging (Android) or the Apple Push Notification service (iOS); in a browser it is a push endpoint address and two public keys. That identifier belongs to one installation of the app on one device, not to you as a person — reinstalling produces a new one, and a device is only ever linked to a single account at a time. We do not store your device model, its advertising identifier, your location or your phone number, and we never use the identifier for cross-app tracking. Notification text may contain your name or your coach's name, a class name, a session time or a payment amount. In the mobile app that text is sent unencrypted through Expo and onward through Firebase Cloud Messaging or the Apple Push Notification service; in a browser the notification content is encrypted and the delivery service sees only the endpoint address. If you would rather it did not, turn notifications off — at any time in the app (Settings → Notifications) or in your device's system settings. We remove the identifier when you sign out and when the delivery service reports it as invalid.

9. Technical, Diagnostic and Security Data

We use Sentry for error detection, with its reports received by Better Stack on servers in the European Union (Germany). An error report carries technical context — the error type, the screen address, the app version, the browser type and the connection's IP address, and for a failed notification delivery also an internal user identifier. Sending personal data is disabled on both the web and the server side (the sendDefaultPii setting is false). On the web, session replay is enabled — roughly 5% of visits are recorded, plus every visit during which an error occurs. Text and filled-in fields are automatically masked in the recording and media is blocked, so a replay shows the page layout and clicks, not the content you typed. The mobile app sends no diagnostic or analytics data at all. Public forms — booking a consultation with a coach — are protected against bots by Cloudflare Turnstile; on verification Cloudflare receives the sender's IP address and a verification token, and we also store that IP address with the request. We also keep audit records of access to personal data and of consent changes, containing the actor's identifier, the time, the action and the IP address. We use no third-party analytics, marketing or advertising tools.

10. Recipients and Processors

Your coach (and, if you are a coach, your clients, to the extent you share data with them). Supabase — authentication, database and photo storage; it holds everything stored in Treneris, hosted in the European Union (Ireland). DigitalOcean — the servers our application runs on; data centre Frankfurt (FRA1), Germany — European Union. Cloudflare — bot protection for public forms (Turnstile) and R2 storage, which holds encrypted database backups , with the storage jurisdiction set to the European Union. Stripe — payments, subscriptions and coach payouts (see section 7). OpenRouter and the language model provider it routes to — the AI features (see section 6). Resend — delivery of transactional emails and of emails from the forms on our website; it receives the recipient's name and email address and the message content, including password reset links. Expo, Google (Firebase Cloud Messaging) and Apple (Apple Push Notification service) — delivery of push notifications to your device (see section 8). Better Stack and Sentry — error diagnostics and web session recording, servers in the European Union. We may also disclose data to our accounting, legal and tax advisers, and to public authorities where the law requires it. We have a data processing agreement under Art. 28 GDPR in place with every processor. We do not sell personal data and we do not use it for third-party advertising.

11. Transfers Outside the European Economic Area

Most processing happens inside the European Union: the database, photo storage, the application servers and the error records. Three flows leave the EEA. The content of AI requests goes to the United States — OpenRouter and the model provider it routes to (see section 6). Payment processing and coach verification through Stripe also go to the United States. And push notification delivery passes through the infrastructure of Expo (United States), Google and Apple, which is global. These transfers are covered by the European Commission's Standard Contractual Clauses under Art. 46(2)(c) GDPR, or by an adequacy decision (the EU-US Data Privacy Framework) where the recipient concerned is certified under it. We will provide copies of the relevant safeguards on request at hello@treneris.sk. If you do not want the AI features, switch Restrict Processing on in Settings → Privacy; their content will then never leave our database. If you do not want notification content transferred, turn push notifications off.

12. How Long We Keep Data

Account data and the health, training and dietary records attached to it are kept for as long as your account exists; you erase them by deleting the account (see section 13). Notifications are deleted automatically after 90 days, as are records of reminders sent. Cancelled, declined and expired invitations are deleted after 30 days. Contact details of inactive prospects are anonymised after 12 months, and unconfirmed consultation requests are deleted after 7 days. Audit records are deleted after 3 years, in line with the general limitation period. Accounting records of payments are kept for 10 years, as required by § 35 of Slovak Act No. 431/2002 Coll. on Accounting; this retention survives account deletion, but the record no longer holds your name or contact details. Consent records are kept for the life of the account and then for the limitation period, so that we can prove consent was given. Emails from the interest form on our website stay in our mailbox until we delete them at your request or no longer need them. Database backups are kept for 14 days and then overwritten — so after you delete your account your data may briefly persist in a backup, from which we do not restore it.

13. Data Export and Account Deletion

You can download a full export of your data straight from the app: Settings → Privacy → Download my data. You get a single JSON file with your profile, sessions, payments, measurements, progress photos (as links valid for 30 days), workouts, meal plans, food diary, health questionnaire, notifications and consent records. The signature image, IP address and user agent from the health questionnaire are deliberately left out of the export — they are security data, not content you created; we will provide them separately on request. You delete your account in Settings → Privacy → Delete account; it works for both client and coach accounts and you do not need to contact us first. Deletion is immediate and cannot be undone: your name, email, phone, date of birth, sex, body data, notes, progress photos and profile photo are removed, your login is revoked, and the health questionnaire including the signature is deleted with it. Records we must keep by law — chiefly accounting records, audit records and consent records — remain only in a form that can no longer be connected to you. If you are a coach, your clients are unassigned and will need to choose a new coach; their own accounts and data are untouched, and deleting the account also ends any subscription, so you do not need to cancel it separately first. The procedure is also described at treneris.sk/delete-account.

14. Your Rights

You have the right of access to your data (Settings → Privacy → Download my data), to rectification of inaccurate data (Settings → Profile), to erasure (Settings → Privacy → Delete account), to restriction of processing (the Restrict Processing switch in Settings → Privacy, which turns off the AI features and automatic reminders), to data portability (the same JSON export) and to object to processing based on legitimate interest. You can withdraw your consent to health data processing at any time in Settings → Privacy; withdrawal does not affect the lawfulness of processing before it. If you cannot exercise a right in the app — because you cannot sign in, for example — write to hello@treneris.sk and we will handle it within 30 days at the latest. If you are unhappy with how we handled it, you can lodge a complaint with the supervisory authority: Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava, dataprotection.gov.sk.

15. Minimum Age of 16

Treneris is intended for people aged 16 and over. Sixteen is the age at which a child in Slovakia can consent on their own to the processing of personal data in information society services, under Art. 8 GDPR and § 15 of Act No. 18/2018 Coll. on Personal Data Protection. We do not knowingly create accounts for anyone under 16 and do not knowingly process their data. If you are a parent or guardian and discover that your child has given us personal data, write to hello@treneris.sk and we will remove the account and the data without delay.

16. Cookies and Local Storage

We use no analytics, marketing or advertising cookies and we do not track you across websites. On the web we use only the strictly necessary cookies that keep you signed in (the Supabase session). Your language, theme and similar interface preferences are stored in the browser's local storage, not in cookies. Fonts are served from our own servers, so loading a page makes no request to any third-party server other than those listed in section 10. In the mobile app, login tokens are stored in the operating system's secure storage (Keychain on iOS, Keystore on Android) and stay on the device.

17. Data Security

All communication between the app and our servers is encrypted over HTTPS/TLS. Data in the database and photos in storage are encrypted at rest (AES-256). Access is restricted at the database level itself — a coach can only reach their own clients' data — and every API endpoint is behind authentication. Access to the production database is limited to a small group of administrators, and access to personal data is audit-logged. Progress photos are private in storage and are served only through temporary signed links. A profile photo, by contrast, is stored in the public part of storage — anyone who knows its exact link can view it without signing in, so do not use anything sensitive as a profile photo. If a personal data breach occurred that posed a risk to your rights, we would notify the supervisory authority within 72 hours and, where the risk is high, you as well.

18. Changes to This Policy

We may update this policy when a new feature or a new processor is added. The current version is always available at treneris.sk/privacy and in the app under Settings → Privacy. The date of the last update is in the header of this document. For a material change affecting the scope of processing or a legal basis, we will notify you in the app or by email and, where necessary, ask for fresh consent.

© 2026 NodeonLabs s. r. o. · hello@treneris.sk