Privacy policy
Effective 20 September 2026. This is the first version of this policy.
slackr is a training log. It needs an email address to give you an account and it keeps the
workouts you record. That is the whole of it: there is no advertising, no third-party
analytics, no tracking SDK in the apps, and nothing is sold or shared for marketing.
Who is responsible
slackr is operated by the publisher of the slackr apps, and is the controller of the data
described here. For anything in this policy — access, correction, deletion, or a complaint —
write to privacy@slackr.pro.
What is collected
Your account
-
Email address. It identifies the account and is where verification and
password-reset messages go.
-
Password. Sign-in is handled by Amazon Cognito. Your password is stored
by Cognito in hashed form; slackr never receives or stores it.
-
Two-factor secret, if you turn on authenticator-app sign-in. Also held by
Cognito.
What you log
- Workouts and the sets in them: exercise, weight, reps and optional RPE.
-
Cardio sessions: activity, indoor or outdoor, distance and duration. Pace is calculated
when shown and never stored.
- Sleep entries, if you use them: when you went to bed and when you got up.
- Routines you create or clone, including every version of them.
- Exercises you add yourself.
- Personal bests, each as a value and the date it was achieved.
- Preferences such as whether you see kilograms or pounds, kilometres or miles.
- Anything you import from a CSV file you supply.
What the service records to run
-
Request logs. Each API request writes a log line holding the time, the
route, the result, the IP address the request came from, the user-agent string and your
account identifier. These are used for debugging, abuse handling and keeping the service
up, and are deleted after 30 days.
What is not collected
- No advertising or marketing identifiers, and no advertising of any kind.
-
No third-party analytics, crash-reporting or tracking SDKs are built into the apps, and
this website loads no fonts, scripts or images from other domains.
- No location data, contacts, photos or device sensors.
- No connection to health platforms or wearables — nothing is read from them.
-
No cookies for tracking. The web app keeps your sign-in session in your own browser's
storage so you stay signed in; nothing about it leaves your device except the token sent
to the slackr API to prove who you are.
Why it is collected
| Data |
Purpose |
Legal basis (UK/EU GDPR) |
| Email address and password |
Create the account, sign you in, reset a password |
Performance of a contract |
| Workouts, cardio, sleep, routines, bests |
Provide the service — it is the thing you asked for |
Performance of a contract |
| Request logs |
Keep the service working and secure |
Legitimate interests |
Sleep entries and body-weight figures may count as health data where you live. They are
collected only because you chose to enter them, and are used for nothing beyond showing them
back to you and calculating your own progress.
Who else sees it
-
Amazon Web Services hosts the service and processes data on slackr's
instructions. Nothing else.
-
Google Play distributes the Android app and handles its own account,
purchase and crash data under
Google's privacy policy.
slackr does not receive your Play account details.
Your data is not sold, and it is not shared for cross-context behavioural advertising. It
may be disclosed if the law requires it, or to protect the service and its users against
abuse.
Where it is kept
In Amazon Web Services' us-east-1 region, in the United States. If you use
slackr from outside the United States, your data is transferred there. Everything is
encrypted in transit with TLS and at rest with AWS-managed keys.
How long it is kept
- Your account and everything in it
- Until you delete the account.
- Detailed personal-best history
-
Expires automatically 365 days after the date of the session it records. Your current
lifetime bests are not on that clock: they stand until you beat them, reset them, or
delete your account.
- Request logs
- 30 days.
- Database backups
-
Continuous backups of the database are kept for 35 days so the service can be restored
after a failure. Deleted data can survive in those backups until they age out.
Your rights over your data
Wherever you live, you can do the following — the first three without asking anyone, from
inside the app.
- Get a copy
-
Export everything held for you as a single JSON file, from your profile in the web or
Android app.
- Correct it
- Edit or delete any workout, set, session, routine or entry, at any time.
- Delete it
-
Delete your account from your profile. See
deleting your account for exactly what happens.
- Object, restrict, or complain
-
Write to privacy@slackr.pro. If you are in the UK
or EU you also have the right to complain to your data protection authority; in the UK
that is the Information Commissioner's Office.
You will not be treated differently for exercising any of these rights — there is no premium
tier that depends on your data, because there is nothing done with your data beyond running
the service.
Children
slackr is not intended for children under 13, and accounts are not knowingly created for
them. If you believe a child has an account, write to
privacy@slackr.pro and it will be deleted.
Security
Sign-in is handled by Amazon Cognito, with optional authenticator-app two-factor. Access
tokens are short-lived. Every request must carry one, and each account can only read its own
data. No system is perfect; if something goes wrong that affects you, you will be told.
Changes to this policy
If this policy changes, the new version is posted here with a new effective date. If a
change materially affects what is collected or why, you will be told in the app or by email
before it takes effect.