PRONAX / Privacy

Privacy policy

How PRONAX handles your information during the closed beta.

Last updated:

This policy describes the PRONAX application’s data practices. This separate public website provides privacy and support information.

Information we collect

  • Account information: email, display name, user ID, role, account status, and account creation time.
  • Authentication information: passwords received for verification and stored only as bcrypt hashes; authentication tokens and session state; and password-reset token hashes and timestamps.
  • Training information: workout dates, lifts, weights, sets, reps, target and perceived RPE (rating of perceived exertion), and set style.
  • Programs: program names, spreadsheet and grid content, formulas stored as text, formatting, dimensions, merged cells, and program history.
  • Custom lifts and coaching: custom lift data, fallback relationships between lifts, and coach/athlete relationship status and timestamps.
  • Derived information: per-user trained models and associated scaling and feature metadata derived from that user’s training data.
  • Request information: application and Fly.io logs may contain URLs, status codes, and client-address information.

The application uses browser storage for authentication and session state and user preferences.

How we use information

PRONAX uses this information to manage accounts and authentication, provide password recovery, store and use training records and programs, support coaching relationships, and produce training predictions.

Prediction models run within PRONAX application infrastructure. No external AI provider receives workout or program data.

PRONAX has no advertising or analytics/tracking SDKs, no HealthKit integration, and no payment collection. It does not deliberately collect location information; request logs may still include client-address information as described above.

Coaching access

Authorized coaches can access an athlete’s identity, training history, custom lifts, readiness and fatigue information, predictions, and program history. They can also upload, edit, rename, and activate the athlete’s programs.

Removing a coaching relationship prevents future server access through that relationship. It cannot retract information a coach has already viewed or copied.

Service providers

  • Fly.io: application hosting, persistent files, logs, snapshots, and deployment infrastructure.
  • Neon: PostgreSQL database hosting and recovery copies.
  • Resend: transactional password-reset email delivery. Password recovery sends the recipient’s address and reset-email content through Resend.
  • Recipient email providers: receive and store password-reset messages.

Data storage and retention

Application information is stored in the hosted database and persistent files. Authentication and session state and preferences are also stored in the browser. Logs, snapshots, and database recovery copies may contain information outside the live application records.

Backups, provider records, and previously sent emails may persist according to provider and recovery retention. This policy does not specify fixed retention periods for those copies.

Account deletion

Self-service account deletion removes your live application database records and coaching relationships. It also attempts immediate deletion of your stored model and data directory. Failed filesystem cleanup is retried.

Account deletion does not guarantee immediate deletion from every backup or external provider. Backups, provider records, previously sent emails, and information another person has already viewed or saved may persist. Removing your account cannot retract those personal copies.

Security

Passwords are received for verification but stored only as bcrypt hashes. Password-reset tokens are stored as hashes with timestamps. Authentication uses JSON Web Tokens (JWTs) and session state. A coach’s server access to athlete information depends on an authorized coaching relationship.

Changes to this policy

Updates to this policy will appear on this page with a revised “Last updated” date.

Contact

For questions about privacy or account deletion, use the contact details on the support page.

luke@pronaxtraining.com