Skip to content

Documents

Privacy Policy

Updated 17 August 2026

Podhod is a workspace for personal trainers and their clients. This page explains who processes the data, what exactly is processed, on what legal basis, where it is stored, and for how long.

Who processes the data

Podhod is provided by Ilya Miadzvetski, an individual. Questions about processing, and requests for access, correction, or deletion, go to support@podhod.fit — the operator's contact address.

Roles are split as follows. For the coach account, the workspace, the subscription, and technical logs, Podhod is the controller. For client data entered by a coach — contacts, goals and limitations, attendance, payment records — the coach is a controller in their own right: they decide whose data to enter and why. In that part Podhod acts on the coach's instructions and only to run the service. For questions about data your coach entered, contact them; we will help process the request on our side.

Coach data

Signing in and running a workspace may require:

  • an email address and secure password hash for email sign-in, or an Apple/Google account identifier for provider sign-in;
  • the coach's name, language, time zone, preferred units, and accounting currency when provided;
  • an optional profile photo. It is kept in a private object-storage bucket; the signed-in coach can access only their own photo, and the app displays it through a short-lived signed URL;
  • workspace content: clients, exercises, templates, programs, calendar, gyms, and schedule records;
  • the subscription plan, its state, and App Store transaction identifiers received from Apple;
  • technical request, authentication, and security logs.

Client data

Client data is entered by the coach or by the client in their own portal: name, date of birth, phone number, Telegram username, general goals and limitations, assigned sessions, attendance, and actual results — weights, reps, duration, distance, rated effort, and comments.

If the coach keeps a payment ledger, the service also stores the client's session balance, charges and payments, outstanding debt, the currency, and the settlement method the coach selected — for example cash, card, or transfer. Podhod does not process payments between a client and a coach and never receives card or bank credentials: this is the coach's internal bookkeeping.

A coach's private notes are stored separately from the shared client profile. They are never shown to the client and never handed to another coach.

Legal bases for processing

Account, workspace, and subscription data is processed to perform the contract with the coach — that is, to provide the service itself. Technical logs, abuse prevention, and incident investigation rest on the legitimate interest in a secure and functioning service. Retention of subscription and deletion records also rests on compliance with legal obligations.

Health data — goals, limitations, wellbeing, rated effort, comments about injuries — is a special category. It is processed on the explicit consent of the person it concerns. A client gives that consent to their coach when they agree to be coached and share the information; the coach is responsible for obtaining it. Consent can be withdrawn at any time — write to your coach or to support@podhod.fit. Withdrawal does not affect processing carried out before it.

The client's link

Clients reach their portal through a permanent secure link — no mandatory sign-up, no PIN. Only a cryptographic hash of the secret is stored in the database. The secret travels in the URL fragment, so it does not reach web server logs, and it is removed from the address bar as soon as access is granted.

A coach can reset the link at any time; the previous one stops working immediately, along with every session it granted.

Data on your device

The client portal is a web app that keeps some data in the browser: the anonymous access session, a queue of unsaved changes, a draft of the current session, and a versioned cache of the exercise catalog so it keeps working on a poor connection. The coach app keeps builder drafts and the same queue of unsaved changes on the device.

This is technical storage required to run the service; there are no advertising or tracking cookies. Server-confirmed records are removed from the queue, and when a link is reset or access is lost, private portal state is cleared — including in other open tabs.

Service providers and storage

Supabase processes authentication and hosts the managed PostgreSQL database and object storage. Access is enforced at the row level: a coach reaches only their own workspace, a client only their own sessions. Podhod's public website and client portal run on a dedicated server.

The database and application servers are located in the European Union. The registrar, DNS provider, certificate authority, and network providers may process ordinary connection metadata such as IP address, timestamp, and requested host.

Apple and Google process provider sign-in, and Apple additionally processes App Store subscriptions and transaction records. These companies may process data outside the EU under their own terms and the European Commission's standard contractual clauses. The service makes no other transfers outside the EU.

Analytics and diagnostics

The service includes no third-party advertising, analytics, or crash-reporting SDK. Operational server logs are used to keep the service available and investigate errors.

First-party product analytics is limited to events on the plans screen — impression, plan selection, purchase outcome — with a short predefined property allowlist, so we can tell whether subscribing actually works. Goals, limitations, notes, comments, session content, financial records, and link secrets never reach analytics or public web logs, and analytics identifiers are pseudonymous: they carry no email, phone number, or name.

Moving to another coach

Training history belongs to the client's profile. A new coach receives the transferable part of that history only after the client explicitly confirms the transfer. Private notes, internal comments, financial records, and the previous workspace's templates do not move.

After the relationship ends, the previous coach keeps read-only access to sessions their workspace ran, and does not see new sessions.

Retention

Account and workspace data is kept while the account is active. Completed client and workout history is retained while the client profile and the relevant coaching relationship exist because both sides plan from it and it may belong to more than one coach relationship. Archiving a client, template, or workspace does not by itself delete history.

A coach's profile photo is removed when the coach removes it in the app or deletes the account. Temporary display links expire automatically.

Security and deletion-operation receipts are retained only as long as needed to prevent duplicate processing, investigate abuse, and meet legal obligations. Backups and infrastructure logs expire on their provider schedules; deleted data can remain there until the normal backup or log cycle completes.

Security

Connections are protected with TLS, passwords are stored only as a secure hash, and the client link secret only as a cryptographic hash. Data access is enforced at the database row level, and privileged operations run through server-side functions that re-check the caller's rights. No method of transmission or storage is absolutely secure, so never forward your password or a full portal link to anyone else.

Account deletion

A coach can start deletion inside the iOS app: open Settings, open Profile and account, choose Delete account, confirm, enter the word shown by the app, and verify identity. Active sessions and portal grants are revoked, provider authorization is revoked where supported, the avatar is deleted, direct identifiers and the coach profile are anonymized, and the account can no longer sign in.

Client and workout history that must remain meaningful for clients or other coaches is preserved without the deleted coach's direct identifiers. If you cannot open the app, write to support@podhod.fit from the account email and we will help verify and process the request.

Your rights

You can request access to your data and a copy of it, correction of inaccuracies, deletion, restriction of processing, and you can object to processing based on legitimate interest or withdraw consent you gave earlier. Send the request to support@podhod.fit: we reply within one month at the latest and may ask you to confirm your identity when there is no other way to be sure the data is yours.

If a coach entered the data about you, say so in the message — the request is handled together with them, because they are the controller for that data. If you are in the EU and believe the processing infringes your rights, you may lodge a complaint with the data protection supervisory authority where you live or work.

Children

The service is not intended for independent use by anyone under 16. Sessions for minors are run by a coach with the consent of a legal guardian, and it is the coach who obtains that consent. If we learn that a portal is used independently by a child under 16 without such consent, access will be closed and the data deleted on request to support@podhod.fit.

Changes

When this document changes materially, the date at the top changes with it. The current version always lives at podhod.fit/privacy/; the previous revision of this policy was dated 13 August 2026.

An app for personal trainers

App Store↗Privacy PolicyTerms of UseEN/RU