P
Persist

// Legal

Privacy Policy

Effective date: September 28, 2026

Overview

Persist ("Persist," "we," "us," or "our") operates a mobile app that helps fitness trainers track client progress through daily and weekly check-ins, workout sessions, and messaging. This policy explains what information we collect, how we use it, who we share it with, and the choices you have.

Information We Collect

We collect the following information when you use Persist:

  • Account data — your email address, name, and role (trainer or client), managed via Supabase Auth. When you sign up, we also record when you confirmed you are 18 or older and accepted the Terms of Service and this Privacy Policy, and which version of the Terms you accepted.
  • Check-in data — daily and weekly self-reports you submit, such as whether you completed your workout, whether you followed your diet, your energy level, and your sleep hours, plus weekly body measurements such as weight, waist, chest, and arms.
  • Meal photos — photos you optionally attach to a check-in. These are stored in a private Supabase Storage bucket and are never given a permanent public URL; the app accesses them only through short-lived, expiring signed URLs.
  • Workout and session logs — exercises, sets, reps, perceived effort (RPE), session duration, and calorie estimates you or your trainer record.
  • Chat messages — messages exchanged between a trainer and their client inside the app, delivered via Supabase Realtime.
  • Training plans and call requests — PDF plans your trainer uploads for you, which are stored in a private Supabase Storage bucket and accessed only through short-lived, expiring signed URLs. Also the time slot and note you add when you ask your trainer for a call.
  • Push notification token — a device registration token (via Firebase Cloud Messaging) used only to deliver notifications to your device. We do not use this token for advertising or analytics.
  • Payment records — if your trainer tracks payments in the app, we store the amount, due date, and status your trainer enters. Persist does not process payments and does not collect card numbers, bank account details, or other payment credentials.
  • Crash and error diagnostics — when the app crashes or hits an unexpected error, we collect the type of error, where in the app it occurred, and a technical stack trace, together with identifiers for the account and record involved so a fault can be traced to the action that caused it. Meal photos, chat messages and check-in values are not collected this way.

How We Use Your Information

We use the information above to:

  • Operate core app features — check-ins, session logging, messaging, and progress tracking.
  • Let trainers see their clients’ adherence and progress.
  • Deliver push notifications relevant to your account (e.g., a check-in reminder or a new message).
  • Parse natural-language entries (like a workout description) into structured data using AI, as described below.
  • Maintain the security and reliability of the service.

Third-Party Services

Persist relies on the following third-party services to operate:

  • Supabase — provides our database, authentication, file storage, and realtime messaging infrastructure. All the data described above is stored on Supabase-hosted infrastructure, protected by row-level security rules that restrict access to your own account and (if applicable) your linked trainer or client.
  • Firebase Cloud Messaging (FCM) — used solely to deliver push notifications to your device. To deliver a notification, FCM receives your device's delivery token and the notification's text. That text can include a sender's or client's name, a plan title, or a short preview of a chat message (up to 100 characters). FCM does not receive your check-in values, workout logs, meal photos, or payment details.
  • Google Gemini API — used to parse natural-language entries (for example, turning "did incline press 32.5kg for 8 reps" into structured workout data). These requests are routed through our own server-side proxy (a Supabase Edge Function); our Gemini API key never ships in the app, and your device never sends data to Google directly.
  • Sentry — receives crash reports and non-fatal error events from the app, including stack traces and the account and record identifiers attached to them, so we can find and fix faults. Sentry does not receive your meal photos, chat messages, or check-in values. We do not enable Sentry's user-profile capture, performance tracing, or session replay.

No Tracking, No Ad Sales

Persist does not track you across other companies' apps or websites, and we do not use your information for advertising. We do not sell your personal information to data brokers or any third party.

Data Retention & Deletion

We retain your data for as long as your account is active. You may request deletion of your account and associated data at any time by contacting us at persist.teamsupport@gmail.com. We will delete your data within a reasonable time after a verified request, except where we are required to retain certain records by law.

Children's Privacy

Persist is intended for users aged 18 and over. It is not directed at anyone under 18, and we do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us with personal information, contact us at persist.teamsupport@gmail.com and we will delete it.

Changes to This Policy

We may update this policy as Persist evolves. If we make material changes, we will update the effective date at the top of this page.

Contact Us

Questions about this policy or your data? Contact us at persist.teamsupport@gmail.com.