Last updated : 26 September 2026
Version françaisePrivacy policy
1. Who is responsible for your data?
The data controller is Jean Paul BELLA, Sole proprietor (micro-entrepreneur), SIRET 834 792 905 00038, 195 rue de la Montagne, 57200 Sarreguemines, France (“EnterTrainMe”, “we”). For any question about your data: [email protected]. We have not appointed a data protection officer (DPO).
This policy covers the website enter-train-me.fr, the EnterTrainMe mobile apps (iOS and Android) and their API. It is written in accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act.
2. What data do we collect?
We only collect what is needed to run the service. Depending on the features you use:
| Category | Examples | Source |
|---|---|---|
| Account and profile | Email address, username, password (stored hashed, never in clear text), profile picture, date of birth, sex, height, language, level and experience points. If you sign in with Google or Apple: the identifier and email those services send us. | You, Google, Apple |
| Training data | Trainings, completed sessions, exercises, weights, reps, records, goals, programmes, calendar, badges, rankings, challenges. | You |
| Health and fitness data (sensitive) | Body weight, measurements, injuries and pain, fitness assessments, daily step count and sleep duration read from Apple Health or Health Connect; strength-training workout saved to Apple Health from the Apple Watch (it stays in Apple Health). | You, Apple Health, Health Connect |
| Photos, videos, sound | Photos and videos of sets you record or import (with ambient sound if you allow it), and the body keypoints (“skeleton”) computed on your phone from a video to analyse your movement. | You, your phone |
| Communications | Messages, chats, attachments, comments, session reviews, coaching relationships, requests and groups. | You, your contacts |
| Artificial intelligence | Your personal instructions to the AI, your assistant conversations, generated reviews, your API key for an AI provider (kept encrypted). | You, the AI provider |
| Payments and subscriptions | Customer identifier and transaction history (amount, date, product, status), subscription status, AI credits. We never have access to your card number. | Stripe, Apple, Google |
| Technical data | IP address, device and OS type, app version, notification token, error and connection logs, crash reports. | Your device |
| Optional integrations | If you connect Strava: your activities (“read” and “activity” permissions). | Strava, you |
3. Why, and on what legal basis?
| Purpose | Legal basis (GDPR) |
|---|---|
| Create and manage your account, provide training tracking, coaching, programmes, rankings and messaging | Performance of a contract (Art. 6(1)(b)) |
| Process your health and fitness data (injuries, weight, measurements, steps, sleep, video movement analysis) | Your explicit consent (Art. 9(2)(a)), given by entering the data or enabling synchronisation. You can withdraw it at any time (see below). |
| Artificial-intelligence features (reviews, progression plans, assistant, “JpecTrainer” video analysis) | Performance of a contract, and your consent for the health data they use |
| Sell and manage subscriptions and credits, invoice, prevent fraud | Performance of a contract; legal obligation (accounting); legitimate interest (fraud) |
| Send service emails (password reset, purchases) and, if you enabled it, the weekly summary | Performance of a contract; consent for the weekly summary |
| Send push notifications (reminders, messages, challenges) | Your consent (system permission, adjustable at any time) |
| Ensure security, fix bugs, measure stability (logs, crash reports) | Legitimate interest (Art. 6(1)(f)) |
| Meet our legal obligations (keeping accounting records, answering authorities) | Legal obligation (Art. 6(1)(c)) |
Providing an email address and a password is necessary to create an account; everything else is optional and depends on the features you choose to use. We take no decision producing legal effects on you by solely automated means.
4. Health and fitness data: your choices
Information about your health (injuries, weight, measurements, steps, sleep, fitness) is sensitive data. We use it only to provide the service (tracking, recommendations, reviews) — never for advertising, and we do not sell it.
- Apple Health / Health Connect: the app reads your steps and sleep duration, and only if you grant permission. If you follow a workout on your Apple Watch, the watch app also saves that strength-training session to Apple Health, again only with your permission; that record stays in Apple Health and is not sent to our servers. The app writes nothing else, and nothing to Health Connect. You can withdraw each permission in your phone's or watch's Health settings and turn synchronisation off in the app; data already synchronised is deleted with your account.
- You decide whether to enter your measurements, injuries and fitness assessments, and you can delete them at any time.
- Your coaches: if you accept a coach, they can view your trainings and tracking data to support you. You can end this relationship at any time.
5. Photos, videos and movement analysis
- Your photos and videos are stored with our storage provider (Cloudflare R2) and served through access links. Chat attachments expire automatically (7 days by default, adjustable from 1 to 30 days).
- Movement analysis is computed on your phone: the model detects 17 body points on the video frames. Only those points (coordinates) and derived measures (reps, tempo, angles) are sent to and kept on our servers; they are used only to draw the skeleton on your video and to feed your reviews. They are never used to identify you or to recognise your face.
- If you ask JpecTrainer for feedback on a set, up to 4 still frames from the video (with the skeleton drawn on them) and the measurements are sent to the AI provider you chose, with your own key (see below). Nothing is sent unless you ask.
6. Artificial-intelligence features
- Training reviews and progression plans: we send Google's Gemini API a summary of your sessions over the chosen period (weights, volumes, records, declared injuries, your personal instructions, movement notes) to generate the review. We do not use your data to train models.
- AI assistant and JpecTrainer use your own API key with Anthropic, OpenAI or Google (which you enter in the app; it is stored encrypted on our servers). Your messages and, for JpecTrainer, the images and measurements are then sent to that provider, which processes them under its own terms. Choose a provider whose rules you accept.
- Voice commands: speech recognition is performed by your operating system (Apple or Google); we do not receive the audio, only the transcribed text.
- AI output is an estimate, not medical advice. It can be wrong: see the terms of use.
7. Payments and subscriptions
- On the website, payment is handled by Stripe (Stripe Payments Europe, Ltd., Ireland). Your card details are entered with Stripe and never pass through our servers. We keep the customer identifier and the history and status of transactions.
- In the apps, the purchase is handled by the App Store (Apple) or Google Play, under their terms and privacy policies. We receive a purchase confirmation (transaction identifier, product, dates, status) that we verify with the store, but never your payment methods.
8. Who receives your data?
We do not sell your data and do not use it for advertising. It is accessible to us and to service providers (processors) acting only on our instructions:
| Provider | Role | Location / safeguards |
|---|---|---|
| Hostinger International Ltd (Hostinger) | Server hosting (API, database, website) | Data centre in Europe; European Union company |
| Cloudflare, Inc. | Storage of videos and media (R2), content delivery | United States; standard contractual clauses / Data Privacy Framework |
| Google (Firebase, Gemini, Google sign-in, YouTube) | Authentication, push notifications, AI review generation, embedded exercise videos | Google Ireland Ltd / United States; Data Privacy Framework, standard contractual clauses |
| Apple | Sign in with Apple, push notifications, in-app purchases, Health | Apple Distribution International (Ireland) / United States; Apple's safeguards |
| Stripe | Payments on the website | Ireland / United States; standard contractual clauses, Data Privacy Framework |
| Resend | Sending service emails and the weekly summary | United States; standard contractual clauses |
| Sentry (Functional Software, Inc.) | Crash and error reports for the app and API | United States; standard contractual clauses |
| Vercel Inc. | Anonymous, cookie-free website audience measurement | United States; Data Privacy Framework |
| Strava, Inc. (optional) | Import of your activities if you connect your account | United States; at your initiative |
| Anthropic, OpenAI, Google (optional) | AI assistant and JpecTrainer, with your own key | United States; your data is sent to them at your request |
Recipients also include, depending on your choices, other users (see below) and, where required by law, competent authorities.
9. Transfers outside the European Union
Several of these providers are based in the United States. Those transfers are covered by the European Commission's adequacy decision for the Data Privacy Framework (where the provider is certified) or by the Commission's standard contractual clauses. You can ask us for a copy of these safeguards at the address above.
10. What other users can see
- Your username, picture, level and rankings may be visible to other users (rankings, challenges, groups, chats).
- Trainings, programmes and coach profiles that you publish are public, including on the website.
- Your videos are private by default; you choose, video by video, to make them public (they are then accessible to anyone with the playback link).
- A session share link gives access to that session to anyone who has the link.
- Your messages are visible only to their recipients.
11. How long do we keep your data?
| Data | Duration |
|---|---|
| Account, profile, training, health data, media, communications | As long as your account exists; deleted when you delete it (immediately from the app) |
| Chat attachments | 7 days by default (1 to 30 days depending on your setting) |
| Technical logs (connections, errors) | 30 days at most |
| Password-reset tokens | Very short validity, then deleted |
| Crash reports (Sentry) | According to Sentry's settings, generally 90 days |
| Accounting records and payment transactions | 10 years (legal obligation), with our payment providers and in our accounting records |
| Technical backups | Until they rotate out; never used to restore a deleted account |
13. Security
Communications are encrypted (HTTPS), passwords are stored using irreversible hashing, API keys you save are encrypted, access to the database is restricted and the apps use device attestation (Firebase App Check). No measure offers absolute security; in the event of a data breach likely to put you at risk, we will inform you and the CNIL within the legal deadlines.
14. Your rights
You have the rights of access, rectification, erasure, restriction, objection (notably to processing based on legitimate interest) and portability, and the right to withdraw your consent at any time (without affecting what was done before). You may also set instructions for what happens to your data after your death.
- Correct: from your profile in the app.
- Delete your account and data: from the app (My profile → Settings → Delete my account) — see Account deletion.
- Any other request (access, export, objection, restriction): email [email protected]. We reply within one month; we may ask you to prove your identity.
If, after contacting us, you believe your rights are not respected, you may lodge a complaint with the French data protection authority, the Commission nationale de l'informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — cnil.fr — or the authority of your country of residence.
15. Minors
The service is intended for people aged 15 or over. Below that age, the agreement of a parent or holder of parental authority is required; we do not knowingly collect data without it and will delete any we become aware of.
16. Changes
We may update this policy, for example for a new feature. The date of the last update is shown at the top of the page; for a significant change we will tell you in the app or by email.
17. Contact
Jean Paul BELLA — 195 rue de la Montagne, 57200 Sarreguemines, France — [email protected]. See also the legal notice.