Effective date: February 19, 2026

Privacy Policy

This Privacy Policy explains how Exert (“we”, “us”, or “our”) collects, uses, and shares your personal data when you use our service. We are committed to handling your information responsibly and transparently.

1. Introduction

Exert is responsible for the personal data you provide when using this service. If you have questions about how we handle your data, please contact us at [contact email]. This policy applies to all users of the Exert web application.

2. Information We Collect

Account data

When you register, we collect your email address and display name. If you sign up via OAuth, we receive your email address and name from the provider (Discord or Google) and use them only to create and identify your account.

OAuth data

When you connect via Discord or Google OAuth, we receive a limited set of profile information (email, name, and provider ID). We do not receive or store your OAuth provider password, and we access only the scopes necessary to authenticate you.

Workout data

Workout programs you create or fork, training sessions you log, and individual sets and reps you record are stored and associated with your account in our database.

Usage data

We collect basic server-side request logs (pages visited, HTTP status codes, timestamps) for the purpose of diagnosing errors and maintaining service reliability. We do not currently use third-party analytics trackers.

3. How We Use Your Data

We use your data to:

  • Provide, maintain, and improve the Exert service
  • Authenticate you and secure your account
  • Display your programs, session history, and profile information to you and, where applicable, to other users
  • Personalise program discovery recommendations based on your activity
  • Generate anonymous aggregate statistics (e.g., total community workout sessions, number of programs published)
  • Send transactional emails such as account verification or security notices

4. How We Share Your Data

Public program pages, creator profiles, and reviews are visible to all visitors, including unauthenticated users. Your display name is shown alongside content you publish. We do not sell your personal data to third parties. We do not share your raw personal information with advertisers. We may disclose data if required by law, court order, or to protect the rights and safety of our users.

5. Data Retention

Your data is retained for as long as your account is active. If you request account deletion, we will delete your account record and the workout data associated with it. Content that other users have forked prior to your deletion will remain as independent copies attributed to the new owners. Some information may be retained for a limited period in backup systems or where required by law.

6. Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Request deletion of your data (“right to be forgotten”)
  • Object to or restrict certain processing of your data
  • Receive a portable copy of your data

You can manage much of this directly in your account settings. To exercise any right or submit a request, contact us at [contact email].

7. Third-Party Services

We integrate with the following third-party OAuth providers for authentication:

These providers have their own privacy practices that govern their use of your data. We encourage you to review their policies.

8. Cookies & Sessions

We use a single session cookie to keep you authenticated. This cookie is httpOnly and SameSite to protect against cross-site request forgery. We do not use advertising cookies, tracking pixels, or third-party analytics cookies.

9. Children's Privacy

Exert is not directed at children under the age of 13 and we do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13 without parental consent, we will delete that information promptly. If you believe we may have such data, please contact us at [contact email].

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the effective date at the top of this page. Continued use of Exert after changes are posted constitutes your acknowledgement of the updated policy. For material changes, we will make reasonable efforts to notify you via email.

11. Contact

For privacy-related questions, requests, or concerns, please contact us at [contact email].

Last updated: February 19, 2026