Privacy policy
Last updated: 2026-09-03. Beta — this policy will be lawyer-reviewed before public launch.
Who controls your data
The data controller under GDPR is Margus Sellin, natural person, based in Estonia. Contact for anything privacy-related: [email protected].
What we store, why, and for how long
| Data | Why | Retention |
|---|---|---|
| Email address | Sign-in, recovery, beta announcements | Until you delete your account |
| Training logs (sets, reps, weights, notes) | Core function — the engine reads your log | Until you delete your account |
| Morning check + symptom scores + pain ratings | Adaptive load adjustments; symptom-load history | Until you delete your account |
| Self-scored assessments (hip check, etc.) | Rehab-programme gating + retest history | Until you delete your account |
| Program state (accepted proposals, phase, week) | Continuity across devices | Until you delete your account |
| Personal contraindications (movements flagged painful) | Safety — the engine refuses to prescribe these | Until you delete your account |
| GPX / FIT files you import | Endurance-session parsing | Never uploaded. Read in your browser; only the numbers you see are saved |
| Consent timestamps | Proof of consent (GDPR requirement) | Kept until 3 years after account deletion (audit trail) |
| Automatic error reports (Sentry) | Debugging crashes | 90 days, email stripped, symptom text scrubbed |
| Bug reports you send from the app | Acting on the problem you reported, and replying to you | 90 days. Includes whatever you type, plus a screenshot only if you attach one |
Lawful basis (GDPR Art. 6 & 9)
- Account + training log: contract with you (Art. 6(1)(b)).
- Symptom scores, pain ratings, self-assessments: your explicit consent (Art. 9(2)(a)) — health data is a "special category" and we store it only because you ticked the box at sign-up.
- Error reports: our legitimate interest in a working service (Art. 6(1)(f)), scrubbed of health content before transmission.
Where it lives
- Account, email, training logs and symptom data: Supabase (managed Postgres, AWS eu-west-3 — Paris, EU).
- Your own device. The app keeps a full copy of your training log and symptom history in browser storage, so it works offline and so a closed tab never loses a set you just recorded. That copy stays on the device until you sign out or clear site data — worth knowing if you use Terav on a shared or work computer.
- Static hosting: Cloudflare Pages (global CDN).
- Error reports and in-app feedback (when enabled): Sentry (US region, sentry.io), under standard contractual clauses.
- Notification email (breach notices, sub-processor changes): Resend (EU region, eu-west-1). Your address is sent only at the moment a notice goes out — we do not keep a mailing list there.
- Payment data (when paid tier launches): handled entirely by Paddle. We never see card numbers.
These providers act as sub-processors under standard data-processing agreements. Sub-processor list is current as of the "last updated" date above; changes will be announced by email.
International transfers
Where each provider stores your data is listed above. Two of them are outside the EU. Error reports and any feedback you send from inside the app go toSentry in the United States under standard contractual clauses: error events are scrubbed of health content before transmission, but a screenshot you choose to attach to a feedback report is sent exactly as you see it, so think before attaching one from the symptom check. Payment processing (Paddle) may transfer minimal transactional data to the US, also under standard contractual clauses. Some CDN edges serve static assets globally; no personal data is involved.
Cookies & tracking
We use one session cookie (Supabase auth) so you stay signed in. We do not use marketing cookies, ad networks, or cross-site trackers. No analytics tools are active in beta.
One exception worth naming: technique demonstrations are YouTube videos, and opening one connects your browser to Google, which receives your IP address. We use the no-cookie player and the video only loads when you tap to watch it — never in the background — so if you don't open a demo, no connection is made.
Automated decisions
The engine proposes load adjustments and program changes. These are proposals, not automatic decisions — nothing changes until you tap Accept. This is confirm-first by design and outside the scope of GDPR Art. 22.
What we don't do
- We don't sell your data. Ever.
- We don't train AI models on your data.
- We don't share your data with third parties beyond the sub-processors listed above.
- We don't use your data for advertising.
Your rights (GDPR)
- Access — export your entire dataset as JSON from Profile.
- Delete — one-click account deletion from Profile. Server-side data is wiped within 30 days; backup rotations may take up to 90 days.
- Correct — edit anything you've logged, any time.
- Portability — the JSON export is a documented, human-readable format.
- Withdraw consent — deleting your account also withdraws consent to health-data processing.
- Complain — you can contact your local data protection authority. In Estonia: aki.ee.
Breach notification
If a personal-data breach happens and it's likely to affect you, we'll notify you by email within 72 hours of becoming aware, per GDPR Art. 34. Notices are sent by a person deciding to send one — nothing in the app emails you on its own, and there is no marketing list.
Children
Terav is not intended for users under 16. We don't knowingly collect data from anyone under 16.
Contact
For anything privacy-related, including exercising the rights above, email [email protected]. We aim to respond within 7 days.