Privacy policy
This privacy policy explains which personal data Built. processes, why we do so, and what rights you have.
1) Who we are
Built. is a fitness app for planning and tracking workouts.
Website: https://builtfitness.nl
2) What data we process
We only process data needed for the app to work:
- Account data: your user id in our system; sign-in via Sign in with Apple and/or email and password; if you use email sign-up, your email address and name fields you provide; if Apple shares it, your name or email from Apple.
- Workout data: training plans, scheduled workouts, and logged training (such as sets, reps, weight, and date), including optional race entries and related notes you add.
- Community and profile data (optional), if you enable community features: public or semi-public username, bio, profile photo / avatar, visibility settings (private, followers-only, or public), follow relationships (who follows whom and request status), activity feed entries you choose to share (for example completed workouts, PR highlights, captions), reactions (for example kudos) you give or receive, optional leaderboard participation flags, and a timestamp showing you joined the community.
- Photos you upload for the activity feed or profile are stored with our provider. The workout photo bucket is configured for public read via URL: anyone who has or guesses the image URL may be able to view that image. Do not upload sensitive images you are not willing to treat as potentially public.
- Push notification tokens (if you enable notifications): device token so we can send reminders or social-related notifications you opt into.
- Technical and diagnostic data: basic logs for sign-in, sync, and troubleshooting (for example whether a sync or crash occurred).
3) Why we process this data
We use your data to:
- let you sign in and manage your account;
- store and sync your training data across devices;
- operate optional community features you explicitly enable (discovery, following, feeds, leaderboards, reporting) according to your visibility choices;
- deliver notifications you request;
- keep the app stable and secure (detect and fix errors).
4) Legal basis (GDPR)
We process personal data on the basis of:
- Performance of a contract: to provide the app functionality you use (including sync and core training features);
- Legitimate interests: for security, reliability, fraud prevention, and improvement of the service;
- Consent, where legally required — for example when you turn on community features, share content to the feed, or enable certain notifications.
5) Sharing with third parties
We do not sell your personal data and do not share your data for advertising purposes.
Community content you make visible may be seen by other users according to your settings (for example public profile, followers, or feed participation).
To deliver the service we use processors:
- Supabase (authentication, database, file storage for images, and hosting of app data);
- Apple (Sign in with Apple and related account services);
- Email infrastructure used to send authentication and transactional email when you sign up with email.
These parties process data only on behalf of Built. and in accordance with their own security and privacy terms. Where data is transferred outside your country, we rely on appropriate safeguards as required by law.
6) Retention periods
- We retain your account and workout data for as long as your account is active.
- If you request account deletion, we will delete your personal data and associated training data within a reasonable timeframe, unless we are legally required to retain something longer.
7) Your rights
You have the right to access, rectify, erase, restrict, and port your personal data, and in certain cases to object.
You can submit a privacy request via: info@builtfitness.nl
8) Security
We take appropriate technical and organizational measures to protect your data against loss, misuse, and unauthorized access.
9) Minors
Built. is not intended for children under 13 (or the higher minimum age that applies locally). If we believe data from a minor has been collected without valid consent, we will delete that data.
10) Changes to this privacy policy
We may update this privacy policy, for example when we add features or laws change. The most recent version is always available at https://builtfitness.nl/privacy.