Privacy Policy
Who we are
Crua is a personal workout-tracking app. It is built and operated by Daniel Lynch, who is the data controller for the purposes of the GDPR. If you have any questions about this policy or your data, contact danolynch98@gmail.com.
Data we collect
When you create an account and use the app, we store:
- Account credentials - your email address and a hashed password. The password is hashed by our authentication provider (Supabase) and is never visible to us in plain text.
- Profile information - an optional display name you set at sign-up, and an optional gender, which you can decline to give.
- Workout data - the workouts you log: exercises, sets, weights, reps, timing, personal records, and any notes you attach to exercises.
- Programmes - any training programmes you build, including planned sessions, mesocycles, and exercise selections.
- Settings - preferences such as your weight unit, default rest time, and whether rest-timer notifications are enabled.
- Equipment profiles - any gym/equipment configurations you create.
- Usage data - the dates on which you opened the app, and when you last used it. We use this to understand whether the app is working for people.
If you turn on bodyweight tracking
Bodyweight tracking is off unless you switch it on. If you do, we also store the weights you log and the date of each weigh-in, the training goal you are working towards (gaining, losing, or maintaining) along with its intensity and your stated training experience, and your reminder time if you enable reminders. You can turn the feature off at any time in Settings.
If you use the AI programme features
Two features send data off your device to Anthropic, the company behind Claude, which turns it into a training programme. The app asks for your explicit permission before the first time either one sends anything, and tells you what will be sent.
- Importing a programme from photos - the images you choose are sent to Anthropic for reading. We do not store the images themselves.
- Generating a programme from the quiz - your quiz answers are sent to Anthropic, along with your gender if you have set one, because it affects the exercise selection.
In both cases we keep a record that the attempt happened, with its date and time, which is what enforces the daily limit on these features. For programme generation that record also includes the quiz answers you gave, which we use to investigate failures and improve the feature.
Your data is not used to train AI models. This is accurate for Anthropic's commercial API, which is the route this app uses.
If you joined the waitlist
If you gave us your email address on crua.app before the app launched, we store that address and which page it came from. To stop automated abuse of that form we also store a salted, one-way hash of the sending IP address for a short period. We cannot recover the original address from that hash.
Notifications
If you grant notification permissions, the app schedules local notifications on your device for rest-timer and reminder alerts. The schedule for those lives entirely on your device.
Separately, if your account is an administrator account (developer accounts only, not beta testers), the app registers a push-notification token with our servers so that operational alerts about app usage can be sent to that device. These are delivered via Expo and Apple Push Notification service, who process the message in transit. No push-notification token is registered for ordinary user accounts.
What we do not collect
- Location data.
- Contacts, or files from your device beyond the images you deliberately choose to import.
- Health-app or HealthKit data. The app does not request HealthKit access, and nothing you log in Crua is written to or read from Apple Health.
- Cross-app or cross-site tracking identifiers.
- Advertising identifiers or marketing/analytics SDKs.
Who processes your data
We use a small number of service providers. They process data on our instructions and are not permitted to use it for their own purposes.
| Provider | What they handle | Why |
|---|---|---|
| Supabase | Your account, and everything you log in the app | Hosting, authentication and database. Runs on AWS infrastructure. |
| Anthropic | Programme images and quiz answers, only when you use those features | Reading a programme photo, and generating a programme from the quiz. |
| Sentry | Crash diagnostics | Identifying and fixing crashes. See below. |
| Expo | Your device's update requests, and admin push notifications | Delivering app updates, and the developer-only alerts described above. |
| Apple | Admin push notifications in transit | Delivery to the device, via Apple Push Notification service. |
| Resend | Your email address and the message body | Sending account emails such as sign-up confirmation and password resets. |
| Vercel | Standard web request data when you visit crua.app | Hosting the website and the email confirmation links. |
Crash reports
When the app crashes, we send the crash error and the React component stack to Sentry (sentry.io) so we can identify and fix the bug. We have configured Sentry to strip user IDs, email addresses, and IP addresses before transmission, and we do not record analytics breadcrumbs (network requests or console logs). Crash reports never contain your workout data, programmes, or password.
Where your data goes
Our providers are based in, or store data in, the United States. Where data leaves the UK or the European Economic Area, the transfer relies on the standard contractual clauses approved for that purpose under Article 46 of the GDPR, which each provider offers in its data processing agreement.
How long we keep it
- Your account data is kept until you delete your account. Deletion is immediate and cascades through every table that holds your data.
- Waitlist emails are deleted automatically 6 months after you join, or sooner if you ask us.
- Anti-abuse records, such as the hashed IP address described above, are removed automatically shortly after the period they protect.
- Crash reports are held by Sentry under its standard retention schedule and deleted at the end of it.
What we do with the data
We use the data to power the app's features - saving your workouts, generating personal-record callouts, sending rest-timer notifications, and showing your training history - and to run and improve the app.
We do not sell your data, share it with advertisers, or pass it to third parties for marketing.
Your rights
You can request a copy of your data, ask us to correct anything wrong, or delete your account at any time.
- Delete in-app: Profile → Settings → Account → Delete account. This permanently removes your authentication record and every row of your workout, programme, bodyweight, settings, personal-records and notes data. We retain no personal data about deleted accounts. We do keep an anonymous record that an account was deleted, noting only the date, how many days it had existed and how many workouts it contained, with no name, email address or account identifier attached.
- Waitlist: a waitlist entry is not attached to an account, so deleting an account does not remove it. Email us and we will delete it.
- Email: danolynch98@gmail.com if you'd prefer to make a request by email or have any questions.
If you are in the EU/UK, you have rights under the GDPR (access, correction, deletion, portability, objection). If you are in California, you have rights under the CCPA (know, delete, opt out of sale - note we do not sell data). To exercise any of these rights, email the address above.
Children
Crua is not directed at children under 13 (or under 16 in the EU/UK), and we do not knowingly collect data from them. If you believe a child has created an account, please email us and we will delete the account.
Changes to this policy
We may update this policy from time to time. Material changes will be flagged at the top of this page and the "Last updated" date will be revised. The URL of this page will not change.