Privacy policy

Last updated: 2026-09-03. Beta — this policy will be lawyer-reviewed before public launch.

Who controls your data

The data controller under GDPR is Margus Sellin, natural person, based in Estonia. Contact for anything privacy-related: [email protected].

What we store, why, and for how long

DataWhyRetention
Email addressSign-in, recovery, beta announcementsUntil you delete your account
Training logs (sets, reps, weights, notes)Core function — the engine reads your logUntil you delete your account
Morning check + symptom scores + pain ratingsAdaptive load adjustments; symptom-load historyUntil you delete your account
Self-scored assessments (hip check, etc.)Rehab-programme gating + retest historyUntil you delete your account
Program state (accepted proposals, phase, week)Continuity across devicesUntil you delete your account
Personal contraindications (movements flagged painful)Safety — the engine refuses to prescribe theseUntil you delete your account
GPX / FIT files you importEndurance-session parsingNever uploaded. Read in your browser; only the numbers you see are saved
Consent timestampsProof of consent (GDPR requirement)Kept until 3 years after account deletion (audit trail)
Automatic error reports (Sentry)Debugging crashes90 days, email stripped, symptom text scrubbed
Bug reports you send from the appActing on the problem you reported, and replying to you90 days. Includes whatever you type, plus a screenshot only if you attach one

Lawful basis (GDPR Art. 6 & 9)

Where it lives

These providers act as sub-processors under standard data-processing agreements. Sub-processor list is current as of the "last updated" date above; changes will be announced by email.

International transfers

Where each provider stores your data is listed above. Two of them are outside the EU. Error reports and any feedback you send from inside the app go toSentry in the United States under standard contractual clauses: error events are scrubbed of health content before transmission, but a screenshot you choose to attach to a feedback report is sent exactly as you see it, so think before attaching one from the symptom check. Payment processing (Paddle) may transfer minimal transactional data to the US, also under standard contractual clauses. Some CDN edges serve static assets globally; no personal data is involved.

Cookies & tracking

We use one session cookie (Supabase auth) so you stay signed in. We do not use marketing cookies, ad networks, or cross-site trackers. No analytics tools are active in beta.

One exception worth naming: technique demonstrations are YouTube videos, and opening one connects your browser to Google, which receives your IP address. We use the no-cookie player and the video only loads when you tap to watch it — never in the background — so if you don't open a demo, no connection is made.

Automated decisions

The engine proposes load adjustments and program changes. These are proposals, not automatic decisions — nothing changes until you tap Accept. This is confirm-first by design and outside the scope of GDPR Art. 22.

What we don't do

Your rights (GDPR)

Breach notification

If a personal-data breach happens and it's likely to affect you, we'll notify you by email within 72 hours of becoming aware, per GDPR Art. 34. Notices are sent by a person deciding to send one — nothing in the app emails you on its own, and there is no marketing list.

Children

Terav is not intended for users under 16. We don't knowingly collect data from anyone under 16.

Contact

For anything privacy-related, including exercising the rights above, email [email protected]. We aim to respond within 7 days.