Privacy Policy

Effective date: September 25, 2026

Vidar is a training app: you tell it about your body, your equipment, and your workouts, and it writes your sessions. That only works if you trust us with that data, so this page says plainly what we collect, where it lives, and what we do with it. The short version: we collect only what we need to operate the service and program your training, we don’t run ads, we don’t sell your data, and we don’t use third-party analytics or trackers.

What we collect

Account. Your email address and the sign-in method you choose. Authentication is handled by Supabase (our database and authentication provider). If you use email, Supabase stores your password in hashed form — we never see or store the plain text. If you continue with Google, Google may supply your verified email address, account name, profile-image URL, and a stable Google account identifier to Supabase. Supabase may retain those identity details with your authentication record. Vidar uses the verified email and provider identity to sign you in and link the account; it does not import the Google name or image into your training profile or display them. Vidar never receives your Google password.

Google sign-in requests only basic identity access. It does not give Vidar access to Google Drive, Calendar, contacts, or other Google services, and we do not send your profile, health, or training data to Google.

Profile and body data. What you enter during onboarding and in Settings: display name, age in years, biological sex, height, bodyweight entries, training experience, goals, preferred training frequency and session length, injuries you flag, exercises you exclude, and the equipment available at your training locations. Vidar uses this to write and adapt your sessions, show your progress, and provide the sharing and export choices described below. Previously supplied dates of birth remain in existing profiles. New age entries do not create an estimated birthday; you can update your reported age in Profile settings.

Training data. The workouts you log: exercises, sets, reps, weights, session dates, your daily readiness check-ins (sleep, energy, soreness), and the recovery and progress numbers the engine derives from them.

Coach connections (optional). If you accept a coach invitation, we store the relationship, the names shown to each side when it was accepted, and which sharing categories you turn on or off. We also store messages you send to each other, the coach check-ins you submit, and their review status. Coaches can save their own reusable training and check-in templates. Declining an invitation does not attach your identity to it.

Nutrition and meal planning (optional). We store the food entries you log. If you use meal planning, we also store your weight goal, meal and snack schedule, dietary preferences, allergies and food exclusions, saved plan versions, and meal-planning sharing choices. The general-purpose planner records whether you confirmed its eligibility statement and when; it does not ask you to enter a diagnosis or a medical history. Planned meals enter your food log only when you record what you ate.

Coach discovery and private libraries (optional). Coaches can publish a profile, portrait, qualifications, specialties, location, and package price for anyone to browse. Draft profiles remain private until published. We store inquiries and replies for their two participants. Creating an inquiry does not create a coaching connection, authorize a payment, or share health records. Coach-created movements, foods, and recipes remain in that coach's private library. Assigned versions travel with the client's plan and performed history.

Progress photos (optional). We store the photos you upload, the dates and views you select, your captions and private notes, and your explicit photo-sharing choices. Uploads are processed into fresh JPEGs with the original file metadata removed. The original files are not retained. Identifying information visible in the photo itself remains visible.

Coaching billing (optional). Stripe handles payment details and coaches' business verification and payout details. Payment requests include the payer's email when available, account and relationship references, and the package name and price. VidarFit stores payment-provider references, subscription status, paid periods, refund status, and funding consent so a payment can be matched to the correct coach and client. Card and bank details are entered through Stripe's hosted pages.

Feedback (optional). If you use the feedback bubble, we store your message plus context that helps us fix things: the page you were on, your browser’s user-agent string, viewport size, device type, and the app version. If you’re signed in, the feedback is linked to your account; if you’re signed out, adding an email is optional. A copy of each message, with its page and an account reference, is kept in a private GitHub repository that the VidarFit team uses to track fixes.

Help chat (optional). If you ask the signed-in VidarFit helper a question, we store a redacted version of the question, the validated answer, its help-article citations, a normalized page category, documentation commit and support-model profile metadata, and the chat's review status. That record is linked to your account so ordinary members cannot read one another's chats. Authorized support administrators can review these redacted records to resolve issues and improve the help documentation. A blocked or unrelated message is not kept as readable text in the safety log; the system keeps only keyed, one-way message and network identifiers for closure and rate limiting, plus a general closure reason.

We don’t intentionally collect your precise location, your contacts, or anything from other apps.

Where your data lives

Your data is stored with Supabase, a managed cloud database provider. Access is protected by row-level security: ordinary member accounts cannot read one another's rows except through the sharing features described here: consented coach categories, participant conversations and inquiries, separate meal-planning permission, selected progress photos, and published coach profiles. Narrow server operations and authorized support administrators can access the redacted help records needed for delivery, abuse prevention, and support review.

The app itself is served through Cloudflare. Like any host, Cloudflare processes the technical request data needed to deliver the site (such as IP addresses) as part of operating its network.

Photos are stored in private Supabase storage. The app checks access before delivering photo bytes; it does not publish storage links for progress photos. Public coach portraits are available while included in a published profile. Payment and payout information is processed by Stripe under its own privacy policy.

Some short-lived app state stays in browser storage on your device: your login session token, today’s check-in answers and unfinished draft, and temporary workout and timer resume state. An unfinished onboarding draft also stays on this device, associated with your account, including profile answers, injury notes, exclusions and equipment choices. Completing setup or signing out clears it on that device. Completing setup elsewhere does not clear another device’s draft; it remains until that device clears it, such as at sign-out. Interface preferences such as tour progress and the feedback-button position also stay on the device. Your kg/lbs preference is part of your profile and is stored with Supabase. We use no advertising or tracking cookies.

Google processes the basic sign-in request only when you choose Continue with Google. That request can include the identity details listed above. Google’s privacy policy governs its part of the authentication step; Supabase then maintains the Vidar session.

When you share with a coach

Coach sharing is optional and invitation-only. Accepting an invitation creates the connection and shares all six categories with that coach: training setup, health constraints, training history, readiness, body metrics, and daily nutrition totals. You can turn any of them off afterwards, and a category that is off is not available to that coach.

The name on an invitation comes from the inviter’s Vidar profile. This version does not verify professional coaching credentials, so accept only a link you expected from the coach you intend to connect.

What a coach can see is whatever you leave on, and accepting starts those six on. Read access lets a connected coach see a category; it never lets them change it. Separately, you can let a coach write and schedule your training. You choose at any time whether your coach or the algorithm programs you, and you can switch back without losing anything you have logged. You can turn off any category, turn off programming, or end the relationship in Settings; each removes that access on the next read. A coach can never change your account, and can never delete your data.

Training goals and recovery context is a separate, optional sharing category that starts off. It includes your goal, experience, age and weekly schedule. When Readiness is also shared, it includes the timing and settings needed to calculate your current muscle recovery. Your date of birth and private recovery-adjustment reasons are not shared.

Meal planning has its own permission. When you turn it on for a coach, they can see your meal preferences, allergies and exclusions, age, height, sex, current weight, training-activity estimate, nutrition targets, eligibility result and meal plans. They can propose a weight goal and meals, but the proposal changes your active plan and goals only when you accept it. This permission does not share your item-level food log. You can turn it off independently of training programming; accepted meal plans remain yours.

Messages and answers submitted to a coach check-in are shared with that coach. These check-ins are separate from the private Quick Check-In before a workout. If the connection ends, the athlete can still read their past conversation and submitted check-ins; the coach loses access through that connection, and neither side can send new messages there.

The training-category views do not share personal notes, Quick Check-In answers, private session feedback, item-level food entries, supplements, discarded workouts, help conversations, feedback reports, or other internal engine data with a coach. Coach-funded access can cover your paid VidarFit features after you accept its terms and payment is confirmed. It does not transfer ownership of your account or history. Ending the connection ends that funding; your own records and any independent membership or lifetime access remain yours.

Progress photos start private. You choose individual photos and a specific active coach connection before sharing them; an optional expiry can limit that access. Ordinary training permissions do not share photos, and future uploads are not shared automatically. Coaches see the selected photos and their shared captions, never your private photo notes. Revoking a share or ending the connection stops future access through VidarFit. A recipient may retain a copy of something they already viewed.

Where the app uses AI

Workout and meal generation use programmed rules. Meal planning selects from the reviewed catalog and permitted private coach recipes; it does not send your meal preferences, allergies or weight goal to an external AI provider.

The signed-in help chat uses an AI provider. Before a question is sent, the app removes many common contact, credential, identity, address, date, account, network, and payment patterns. Ambiguous introductory phrases are removed locally; the chat closes when clearer self-identifying or location disclosures cannot be safely minimized. It sends the resulting question, a normalized non-identifying page category, and the reviewed public-safe help articles needed to answer it. The app does not automatically attach your profile, workout history, email address, account id, payment records, or another member's records. Details you type may still be included if they do not match a redaction pattern, which is why the chat asks you not to include personal or sensitive information. The AI runs on Cloudflare Workers AI, on Cloudflare's own network (the same provider that hosts VidarFit), using openly licensed models from Meta, Mistral AI, Alibaba Cloud's Qwen team, and IBM. If one model is busy, the question is sent to the next one. Cloudflare's terms say it does not use this content to train AI models or to improve its services.

The VidarFit team reads the feedback you send. To help sort it, the text of each feedback message is also analyzed by the same Cloudflare-hosted models after common contact, credential, and identity patterns are removed, and without your name, email address, or account id. The models turn it into suggested product improvements that only the VidarFit owner can see.

Please do not put passwords, sign-in codes, payment information, private health details, or another person’s information into help chat. The chat cannot perform account, billing, privacy, security, or medical actions; use the contact address below for those requests.

What we don't do

No ads. No selling or renting your data — to anyone, ever. No third-party analytics or tracking scripts (we checked: the app ships none). No marketing emails. Supabase sends account emails such as confirmations and password resets when they apply to your sign-in method. Stripe may send transactional receipts and billing notices for its payment flows.

Your data, your choices

See and change it. You can view and edit your profile, injuries, equipment, and history in the app at any time.

Export it yourself. When you’re signed in, Settings → Your data downloads your own data straight from the app — a versioned account archive as a JSON file, or your training log as a spreadsheet-ready CSV. You do not need to email us first. That page summarizes what each file contains and leaves out. The JSON archive also includes meal-planning records and the coaching conversations, check-ins and templates available to your account, as well as your directory/inquiry records, private coach library, photo metadata and sharing records, and coaching billing summaries. Download your own photo files separately from Progress photos. If a feature's storage is unavailable on a deployment, the archive labels that omission. Key exclusions include discarded sessions and their sets, complete payment-provider records and identifiers, shared group sessions, the shared movement library, and private help conversations or feedback.

Delete a progress photo. Use Delete in Progress photos. It becomes unavailable immediately, its notes and captions are cleared, and its stored image files are removed asynchronously with retries if storage is temporarily unavailable. This cannot remove copies a recipient already saved.

Delete it. Deleting your account is not self-serve yet — there is no delete button in the app. Email hello@vidar.fit and we’ll delete your account and its data by hand, promptly. Until the app has a delete button, emailing us is the way to do it.

Honesty about our stage

Vidar is in active development, and this policy describes the app as it is today. If we ever add something that changes how your data is handled — a new integration, a new data type — we’ll update this page and change the date at the top before it ships.

Contact

Questions about privacy or your data: hello@vidar.fit.

See also the Terms of Service.