Last updated 9 September 2026
This Privacy Policy explains what data Soloffort ("we", "us") collects when you use soloffort.com (the "Service"), and how we use it. We are Anthony Markson, trading as Soloffort, and act as the data controller for the personal data described below.
Account data. If you create an account, we (via our authentication provider, Supabase) store your email address and a securely hashed version of your password — we never see or store your password in plain text.
Subscription data. If you subscribe to Premium or Coaching, we store whether your subscription is active, and your Stripe customer and subscription reference IDs, so we can keep your access in sync with your billing status. We do not collect or store your card number or other payment details — Stripe handles payment processing directly and is PCI-DSS compliant.
Workout and diet data. Your goal, level, program, and any edits or swaps you make are stored in your browser's local storage. If you create an account, this data also syncs to our servers (so it follows you across devices) and we can access it in that case — if you never create an account, it stays local only and we have no access to it.
Coaching check-in data. If you're a Coaching customer, the post-workout check-ins you submit (effort level, enjoyment, and any pain or comment notes you choose to add) are stored so your coach can review them. That check-in text may also be sent to our AI provider, Anthropic, which produces a short summary and flags anything that may need your coach's prompt attention — this is an assistive step only, to help your coach prioritise reviews; it never generates feedback that's sent to you directly and never changes your programme. Anthropic receives only the check-in text itself, never your name, email, or payment details. All actual coaching feedback and decisions come from your human coach.
We do not use advertising or analytics cookies. The only cookie-like storage used is a strictly necessary session token (set by Supabase) that keeps you signed in, and local storage for the workout/diet data described above.
Error monitoring. If the app crashes or hits an unexpected error, technical details (what went wrong, the browser/device involved) are sent to our error monitoring provider, Sentry, so we can fix bugs. If you're signed in, that report is tagged with your account email and user ID so we can investigate account-specific issues.
We process account and subscription data because it's necessary to perform our contract with you (providing the Service you signed up for), and to comply with legal obligations such as tax and accounting records. We do not use your data for marketing without your separate consent.
We use the following processors to run the Service. Each only receives the data it needs to perform its function, and may process data outside the UK/EEA under their own standard contractual safeguards:
We do not sell your data, and do not share it with third parties for their own marketing purposes.
We keep your account and subscription data for as long as your account is active. You can delete your account yourself at any time from Account in the app — this cancels any active subscription and erases your account data, except where we're required to retain records (e.g. billing records) for legal or accounting purposes. You can also contact us and we'll delete it for you.
Under UK GDPR, you have the right to access, correct, delete, restrict, or port your personal data, and to object to certain processing. You can access and download the data we hold about you, or delete your account entirely, yourself at any time from Account in the app — no need to wait on a request. For anything else (corrections, restricting processing, or if you'd rather we handled it), contact us at the email below. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ico.org.uk) if you believe your data has been mishandled.
The Service is not directed at, and we do not knowingly collect data from, anyone under 16.
We rely on our processors' security measures (including encryption in transit and access controls) to protect your data, and restrict access to what's operationally necessary. No method of storage or transmission is 100% secure, and we can't guarantee absolute security.
We may update this Privacy Policy from time to time. Material changes will be reflected in the "Last updated" date above.
For any privacy questions or to exercise your rights, contact [email protected].