Privacy Policy

Last updated 13 August 2026

TrainFloor is run by Vasyl Prindyn, an individual developer. This page says what the app collects, why, and who else sees it. It describes the app as it actually works, not as a template.

What TrainFloor collects

Your account

An email address, which you provide directly or which Apple or Google returns when you sign in with them. If you use Sign in with Apple and choose to hide your address, TrainFloor receives Apple's relay address and never sees your real one. Passwords are handled by our authentication provider and are never visible to us.

Your profile

A handle, a display name, and anything else you choose to fill in: a bio, a location, years of training experience, gender, an avatar and a cover image. Every one of these is optional except the handle and the name. Location is a free-text field you type, such as a city. TrainFloor does not request or receive GPS or device location.

What you post

Workouts, comments, replies, direct messages, voice notes, images, records of workouts you have trained, and leaderboard results. Who you follow, block and save is stored so the app can show it back to you.

Your settings

Notification preferences and the privacy switches you set, such as whether your profile is private or whether you appear on leaderboards.

Your device, only for notifications

If you turn on push notifications, TrainFloor stores a push token and your platform (iOS or Android) so a notification can reach the right device. Turning notifications off removes it.

Safety

Reports you file about other people or their content, including what you reported and why.

What TrainFloor does not collect

Who else processes your data

WhoWhat they handle
SupabaseSign-in, the database, and stored images and voice notes
HetznerThe server that receives a posted workout
Moonshot AIAutomated review of posted text, see below
Apple, GoogleSign-in only, if you choose those buttons
CloudflareThe domain, and email sent to our published addresses

These are processors acting on our instructions. Your data is not sold, and it is not shared with advertisers or data brokers.

Automated review of what you post

When you post a workout, its text is sent to an AI model operated by Moonshot AI so the app can classify it and check it is a workout rather than spam or something unsafe. Comments and messages may be reviewed the same way. This means text you post leaves our systems and is processed by a third party. It is used to make that decision and nothing else. Personal profile details are not sent with it.

What other people can see

Your handle, name, bio, location, experience, avatar, cover image and posted workouts are public to anybody signed in to TrainFloor. Comments are public on the workout they belong to. Direct messages are visible only to you and the person you sent them to. Leaderboard placements are public unless you turn them off in settings, and a private account limits who sees your profile.

Deleting your account

You can delete your account from inside the app, in Settings. Deleting removes your sign-in record, your profile and the content attached to it. Deletion is immediate and cannot be undone. If you would rather ask us to do it, or you want a copy of your data first, email privacy@trainfloor.com.

How long it is kept

Your account and content are kept until you delete them. Reports are kept after they are resolved so a pattern of behaviour can be recognised. Backups are retained for a short period and then overwritten.

Your rights

You can see and change your profile in the app at any time, and delete your account. Depending on where you live you may also have the right to a copy of your data, to correct it, to restrict how it is used, or to complain to a data protection authority. To exercise any of these, email privacy@trainfloor.com.

Children

TrainFloor is not for children under 13, and we do not knowingly collect anything from them. If you believe a child has an account, email us and it will be removed.

Security

Data is encrypted in transit. Access to the database is restricted per-account by row-level security, so one account cannot read another's private data. No system is perfectly secure, and we will tell affected users if a breach occurs that puts their data at risk.

Changes

If this policy changes materially, the date at the top changes and the app will point you here. Continuing to use TrainFloor after a change means the new version applies.

Contact

privacy@trainfloor.com