Skip to content
How it worksEN/RUClient portal↗

Documents

Privacy Policy

Updated 5 August 2026

Podhod is a workspace for personal trainers and their clients. This page explains what the service stores, why, and for how long.

Who processes the data

The service is operated by the owner of Podhod. Questions about processing, and requests for access or deletion, go to support@podhod.fit.

Coach data

Signing in and running a workspace may require:

  • an email address and secure password hash for email sign-in, or an Apple/Google account identifier for provider sign-in;
  • the coach's name, avatar, language, time zone, and preferred units when provided;
  • workspace content: clients, exercises, templates, programs, calendar, subscription plan, and App Store transaction identifiers;
  • technical request, authentication, and security logs.

Client data

Client data is entered by the coach or by the client in their own portal: name, avatar, date of birth, phone number, Telegram username, general goals and limitations, assigned sessions, attendance, and actual results — weights, reps, duration, distance, rated effort, and comments.

A coach's private notes are stored separately from the shared client profile. They are never shown to the client and never handed to another coach.

The client's link

Clients reach their portal through a permanent secure link — no mandatory sign-up, no PIN. Only a cryptographic hash of the secret is stored in the database. The secret travels in the URL fragment, so it does not reach web server logs, and it is removed from the address bar as soon as access is granted.

A coach can reset the link at any time; the previous one stops working immediately, along with every session it granted.

Service providers and storage

Supabase processes authentication and hosts the managed PostgreSQL database and object storage. Access is enforced at the row level: a coach reaches only their own workspace, a client only their own sessions.

Apple and Google process provider sign-in. Apple also processes App Store subscriptions and transaction records. Podhod's public website and client interface run on a dedicated VPS; the registrar, DNS provider, certificate authority, and network providers may process ordinary connection metadata such as IP address, timestamp, and requested host.

Analytics and diagnostics

The current release does not include a third-party advertising, analytics, or crash-reporting SDK. Operational server logs are used to keep the service available and investigate errors. Goals, limitations, notes, comments, session content, and link secrets are not written to analytics or public web logs.

Moving to another coach

Training history belongs to the client's profile. A new coach receives the transferable part of that history only after the client explicitly confirms the transfer. Private notes, internal comments, and the previous workspace's templates do not move.

After the relationship ends, the previous coach keeps read-only access to sessions their workspace ran, and does not see new sessions.

Retention

Account and workspace data is kept while the account is active. Completed client and workout history is retained while the client profile and the relevant coaching relationship exist because both sides plan from it and it may belong to more than one coach relationship. Archiving a client, template, or workspace does not by itself delete history.

Security and deletion-operation receipts are retained only as long as needed to prevent duplicate processing, investigate abuse, and meet legal obligations. Backups and infrastructure logs expire on their provider schedules; deleted data can remain there until the normal backup or log cycle completes.

Account deletion

A coach can start deletion inside the iOS app: open Settings, open Profile and account, choose Delete account, confirm, enter the word shown by the app, and verify identity. Active sessions and portal grants are revoked, provider authorization is revoked where supported, the avatar is deleted, direct identifiers and the coach profile are anonymized, and the account can no longer sign in.

Client and workout history that must remain meaningful for clients or other coaches is preserved without the deleted coach's direct identifiers. If you cannot open the app, write to support@podhod.fit from the account email and we will help verify and process the request.

Your rights

You can request a copy of your data, correction of inaccuracies, or deletion of your profile by writing to support@podhod.fit. If a coach entered the data about you, say so in the message — the request is handled together with them.

Children

The service is not intended for independent use by anyone under 16. Sessions for minors are run by a coach with the consent of a legal guardian.

Changes

When this document changes materially, the date at the top changes with it. The current version always lives at podhod.fit/privacy/.

The workspace for personal trainers.

Documents and support

PrivacyTermsSupportapp.podhod.fit ↗