Summary
This summary is provided for convenience only. It does not replace the full Policy set out below and must be read together with it.
- Your training data belongs to you. We do not sell personal information, and the Provere app contains no advertising, analytics or tracking software (sections 3 and 8).
- Certain information that you enter is stored only on your device and is never transmitted to us (section 4).
- The principal categories of information that we receive are your account details, your logged training, your body measurements and the answers that you give during setup (section 2).
- You may delete your account from within the app at any time, and you may request access to the personal information that we hold about you (sections 12 and 13).
- We are based in Australia. Our service providers are located overseas, and your personal information is stored and processed principally in Singapore and the United States (sections 8 and 9).
1. About this Policy
Provere is a training application operated by a sole trader carrying on business under the name Provere (ABN 16 594 081 135) of 183 City Road, Southbank, Victoria 3006, Australia ("Provere", "we", "us" and "our"). We are the entity responsible for the personal information described in this Policy, and our contact details are set out in section 17.
This Policy applies to the Provere mobile application ("App") and to the account through which you use it (together, the "Services"). It does not apply to any third-party website or application that you choose to open from the App. This Policy also applies to the early-access list that we operate on our website at provere.app, which is described in sections 2 and 5.
In this Policy, "personal information" has the meaning given to it in the Privacy Act 1988 (Cth) and includes all of the information relating to you that is described in this Policy.
2. Personal information that we collect
We collect the following categories of personal information:
- Account details: your first and last name, your preferred name (if you give one), your username and email address, the sign-in method that you use (email and password, Google or Apple) and, if you add one, a profile photograph.
- Training data: the workouts, plans, schedules, sets, repetitions, weights, durations, distances, rest times, RPE and RIR values, tempo and personal records that you log.
- Saved items: the gyms that you save, the exercises that you mark as favourites, and any exercises or equipment that you create (including their names, descriptions and settings), so that they are associated with your account rather than with a single device.
- Free-text entries: workout titles and notes, notes on individual exercises and sets, gym names and notes, and notes attached to a body-weight or measurement entry. Search terms that you enter in your Logbook are also transmitted to us so that results can be returned.
- Body data: your body weight, body measurements, height and body type, and the targets that you set.
- Setup responses: your training experience, how consistently you have trained, the number of days per week on which you train, your preferred session length and the goals that you select. These are held against your account so that reinstalling the App or changing device does not require you to repeat setup, and so that your recommended plans are preserved.
- Set-entry preferences: whether a dumbbell weight denotes a single dumbbell or the pair, and whether repetitions on a single-arm or single-leg exercise denote one side or both. These are held against your account so that your entries are interpreted on a new device in the way that you intended.
- Subscription status, if you purchase a subscription: the plan to which you are subscribed, whether it is active and when it renews. We do not at any time receive your payment card details.
- Technical information accompanying a request: your device time zone when you start a workout, your App version and platform when the App checks which features are enabled for you, and the IP address that necessarily accompanies any request made over the internet.
- Diagnostic information: crash and error reports, which we use to identify and rectify faults.
- Early-access list: if you join the early-access list on our website, the email address that you enter, the country and the type of phone (iPhone or Android) that you select, and the time of your request. We send one email to that address asking you to confirm it, and an address that is not confirmed is sent nothing further. Every email sent to an address on the list contains a link by which the address may be deleted from the list. The country that the form first displays is an estimate made from your network address, which is not kept. To limit misuse of the form, we keep for a limited period a count of the requests made from a network address, recorded against a one-way hash of that address and not against the address itself.
3. Information that we do not collect
We do not collect any of the following:
- Advertising identifiers. The App contains no third-party advertising, analytics or attribution software development kits.
- Contacts.
- Location. We do not request location permission and do not collect GPS or other precise location data. The App may read your device's language setting in order to display the appropriate wording. That is a device setting and not location data.
- The contents of your photo library, other than the single image that you select as a profile photograph, at the time at which you select it.
- Health data from Apple Health or Google Health Connect. The App neither reads from nor writes to either service.
- Biometric data. Face ID, Touch ID and Android biometric authentication are performed entirely by your device. The App is informed only of whether the check succeeded and does not receive your biometric data.
4. Information that remains on your device
The following information is stored on your device only. It is not transmitted to us and does not form part of your account:
- Your date of birth. Providing it is optional, it is never transmitted to us, and no feature of the Services relies on it.
- Your App settings, being your units of measurement, theme, first day of the week and notification preferences, and whether App Lock is enabled.
5. How we use personal information
We use personal information for the following purposes:
- to operate your account and keep you signed in;
- to build, adjust and schedule your training, and to display your progress, personal records and streaks;
- to provide the reminders that you enable, which are scheduled by your device and are not sent by us;
- to operate the Live Activity shown on your lock screen during a workout, as described in section 6;
- to manage any subscription that you purchase and give you access to the features for which you have paid;
- to invite you, if you have joined the early-access list and a place is available, to test the App before its release;
- to notify you, if you have joined the early-access list, should the App become available in the country that you selected;
- to respond to your support requests; and
- to identify faults and keep the Services secure and reliable.
6. Workout Live Activity
If you use the lock-screen Live Activity on iOS, your device provides us with a delivery token that is issued for that workout alone. We send that token to Apple together with the content that the Live Activity is to display, being the name of the current exercise and a line of text such as "Set 4, 5 to 7 reps, 100 kg". This allows the timer to be updated while the App is closed.
The token is discarded when the workout ends. Turning the workout lock screen off in Profile stops this processing entirely.
7. Subscriptions and payments
Where Provere is offered by paid subscription, billing is handled by the app store through which you subscribe, being Google Play or the App Store. The app store is the merchant and processes your payment. We do not see or store your payment card details.
In that case we hold a record of your entitlement only, being the plan to which you are subscribed, whether it is active and when it renews. The app store provides that status to us so that we can enable the corresponding features.
8. Disclosure of personal information
We do not sell your personal information, and we do not disclose it to advertisers.
We engage the following service providers to process personal information on our behalf, to the extent necessary to operate the Services:
- Google Firebase: sign-in and account authentication.
- Neon: the database in which your account content is held.
- Railway: the hosting of our servers.
- Cloudflare: the routing of traffic between the App and our servers, the delivery of your profile photograph, the forwarding of email sent to our support address, and the hosting of our website and of the early-access list.
- Backblaze B2: the storage of your profile photograph. A profile photograph is served from a publicly accessible web address and should be regarded as public rather than private. Backblaze B2 also holds encrypted backups of the database, which Backblaze is unable to read.
- Resend: the sending of account emails, such as verification and password-reset emails, of emails to addresses on the early-access list, and of our replies to support requests.
- Expo: the delivery of updates to the App. The App contacts Expo when it starts in order to check whether an update is available.
- Sentry: crash and error reporting. Reports include your account identifier so that a fault can be traced to a session. Your email address, username and display name are never included.
- Google: the mailbox in which email sent to our support address is received.
- Apple: the delivery of Live Activity updates to your lock screen (see section 6).
- Apple and Google: the billing of any subscription that you purchase through their app stores.
- Apple and Google: the distribution of test versions of the App to those who accept an invitation to test it.
9. Overseas storage and processing
Each of the service providers listed in section 8 is located outside Australia and New Zealand. Most of them are located in the United States. The database and the servers that operate the Services are hosted in Singapore, account emails are sent from Japan, crash and error reports are stored in Germany, and profile photographs and database backups are stored in the United States. Your personal information is accordingly stored and processed outside Australia and New Zealand, principally in those four countries. The early-access list is the exception: it is held by Cloudflare in its Oceania region. Emails to addresses on that list are sent from Japan.
We take reasonable steps to engage service providers that are contractually bound to protect your personal information. However, information that is held overseas is also subject to the laws of the country in which it is held. By using the Services, you acknowledge and accept that your personal information will be handled outside Australia and New Zealand on that basis.
10. Security
Information transmitted between the App and our servers is encrypted in transit. Your sign-in session is held in your device's secure credential store, being the Keychain on iOS and encrypted storage on Android.
You may enable App Lock in Profile, which requires Face ID, Touch ID or your device's biometric authentication before the App will open.
No system is completely secure. If a data breach occurs that is likely to result in serious harm to you, we will notify you and the relevant regulator as required by law.
11. Retention
We retain your account content for as long as your account exists.
Archiving a workout does not delete it. An archived workout is hidden from your lists, but the record is retained and you may restore it. Deleting a workout removes it.
Sets that you log while offline are held on your device and are sent to us when you reconnect. Any set that has not been sent within seven days is discarded.
Uploading a new profile photograph deletes the photograph that it replaces. Deleting your account removes every photograph that you have uploaded, including any that you had previously replaced.
Encrypted backups of the database are made daily, and each backup is retained for approximately five weeks. Information that has been deleted, including on the deletion of an account, may therefore remain in a backup until that backup expires.
Diagnostic reports are retained for a limited period and are then deleted.
An address on the early-access list is held until you delete it by means of the link contained in any email sent to it, or until it is no longer required for the purpose for which you gave it, whichever is the earlier.
12. Access, correction and your choices
Most of the personal information that we hold about you can be viewed and corrected within the App, under Profile, then Profile Information, Body Metrics or Goals. The email address registered to your account can be changed only by you, within the App. We do not change it on request.
You may also request access to, or the correction of, the personal information that we hold about you by contacting us (see section 17). We will need to verify your identity before we act on a request. We will respond within a reasonable period, and ordinarily within 20 working days. We may decline a request, in whole or in part, where the law permits us to do so, in which case we will give you our reasons.
In addition, you may at any time:
- delete your account, as described in section 13;
- turn reminders off, under Profile, then Notifications; and
- sign out, which clears the cached copy of your information from the device.
13. Deletion of your account
You may delete your account from within the App by selecting Profile, then Privacy, then Delete account.
Deleting your account removes your sign-in credentials and erases every copy of your information that is held on the device from which you delete it. It also sends a request to our servers to remove your account content, including every profile photograph that you have uploaded.
Copies of your account content that are held in database backups are not removed at the time of deletion. They are deleted when the backup concerned expires (see section 11).
On request, we will confirm in writing that the deletion of your account content from our servers has been completed (see section 17).
Deleting your account does not cancel a subscription. Any subscription that you hold must be cancelled separately through the app store through which you subscribed.
14. Children
The Services are not directed to children under the age of 13, or under any higher minimum age that applies in the country in which they reside, and we do not knowingly collect personal information from them. If we become aware that we have collected personal information from a child under the applicable minimum age, we will take reasonable steps to delete it.
15. Complaints
If you consider that we have mishandled your personal information, you may make a complaint by contacting us (see section 17) and describing your concern. We will respond within a reasonable period, and ordinarily within 30 days.
If you are not satisfied with our response, you may refer your complaint to the relevant regulator. In Australia, that is the Office of the Australian Information Commissioner (oaic.gov.au). In New Zealand, it is the Office of the Privacy Commissioner (privacy.org.nz).
16. Changes to this Policy
We may amend this Policy from time to time. The date at the top of this Policy shows when it was last updated. If an amendment materially affects the way in which we handle your personal information, we will notify you in the App before the amendment takes effect.
17. Contact
Questions about this Policy, requests for access or correction, and complaints should be sent to support@provere.app.
To protect your personal information, we may require you to verify your identity before we act on a request, and we may decline to act on a request if your identity cannot be verified.