01 Who is responsible for your data
Setlane is operated by Serhii Hrybkov, an independent developer based in Ukraine ("Setlane", "we", "us", or "our").
For privacy questions or requests, contact support@setlane.app.
02 Who may use Setlane
Setlane is intended only for people who are at least 18 years old. We do not knowingly collect personal data from anyone under 18. If you believe that a person under 18 has provided us with personal data, contact us so that we can delete it.
03 Information we collect
3.1 Account and profile information
When you create or use a Setlane account, we may process:
- your email address;
- an internal account identifier;
- authentication information managed by our authentication provider;
- basic profile information supplied by Google if you choose Google Sign-In, such as your name, email address, and profile image;
- account confirmation, password reset, and account security information.
We do not receive or store your plaintext password.
3.2 Workout and fitness information
The Service stores information that you choose to enter, including:
- workout routines and templates;
- exercises and custom exercises;
- workout dates, duration, exercise order, sets, repetitions, and weights;
- body-weight entries;
- workout history and progress information;
- related settings and preferences needed to provide the Service.
This information may constitute health or fitness data under applicable law.
3.3 Purchase and subscription information
If you purchase Setlane Pro through Google Play, we may process:
- the purchased product and base plan;
- purchase and order identifiers;
- a Google Play purchase token;
- purchase status, acknowledgement status, renewal status, and expiration date;
- limited Google Play verification responses required to confirm and maintain your entitlement;
- an account-binding identifier used to prevent a purchase from being claimed by a different Setlane account.
Google Play processes your payment method and payment transaction. Setlane does not receive or store your complete card or bank account details.
3.4 Technical and operational information
Our infrastructure providers may automatically process limited technical information necessary to operate and secure the Service, such as:
- IP address;
- device or browser type and user agent;
- request time, response status, and diagnostic logs;
- authentication, security, and error events.
The Setlane mobile application and web application at app.setlane.app do not use advertising SDKs, third-party behavioral advertising, or third-party analytics SDKs. They use limited first-party product analytics operated through Setlane's own Supabase infrastructure to understand onboarding and workout flows, measure feature use and retention, evaluate subscription conversion, diagnose problems, and improve the Service.
First-party analytics may include:
- a randomly generated installation identifier, a session identifier, and your internal Setlane user identifier when you are signed in;
- the event name and time for actions such as first open, session start or background, signup, routine creation, workout start, first set, workout completion or discard, rest-timer start, personal-record detection, paywall view, trial, purchase, restore, subscription status change, and successful export;
- app version and build, platform, environment, and Free or Pro status;
- country derived from your device locale, and limited first-touch source and cleaned UTM campaign fields;
- limited event properties such as counts, duration, broad row-count buckets, or a normalized feature trigger.
On Android, Setlane may use Google Play Install Referrer once after installation to extract limited source or UTM attribution. Raw referrer data and click identifiers are discarded and are not stored in analytics. Country is based on device locale, not IP geolocation.
First-party analytics does not include your email or name, routine or exercise names, comments, weights, repetitions, complete URLs or referrers, Google click identifiers, Google Play purchase tokens, advertising identifiers, or hardware identifiers. Events may be held in a limited on-device queue while offline and sent to Supabase in batches when a connection is available. The web application does not start this analytics when the browser reports an enabled Do Not Track preference.
The setlane.app website uses cookieless analytics from Vercel and Umami Cloud to count page views, conversion events on selected buttons, and to aggregate referrer, country, device and browser information. It sets no cookies, does not track you across other websites, and is not used to identify individual visitors or to build advertising profiles. A first-touch referrer hostname may be stored in sessionStorage for the browser session so conversion events can be attributed to the original site; that value is first-party, session-scoped, and is not a cookie. A first-party localStorage flag in that browser can disable this website analytics.
On the first external visit to the homepage, the website may redirect you to a supported language based on your saved choice or browser language preferences. Direct links to language versions, articles and page sections are not redirected. Your chosen language is stored in localStorage, and a flag in sessionStorage prevents repeated automatic language selection during the same session. If no supported language is found, the website remains in English.
3.5 Information stored on your device
Setlane stores certain information locally to support authentication, offline use, faster loading, workout recovery, and rest-timer functionality. This may include:
- your authentication session;
- offline copies of workout and body-weight data;
- pending changes waiting to synchronize;
- cached screens and app preferences;
- rest-timer state;
- a limited analytics queue and random installation and session identifiers.
When connectivity returns, pending account data may synchronize with the Service. CSV files that you export are saved to a location selected or controlled by you and are no longer controlled by Setlane.
3.6 Optional AI connections
You may choose to connect Setlane to a compatible third-party AI service, such as ChatGPT or Claude, through Setlane's Model Context Protocol (MCP) connection. The connection uses OAuth authorization and is optional. During authorization, you choose whether the connection receives read-only or read and write access.
When you authorize and use an AI connection, it may receive:
- workout routines and templates, including saved exercise order;
- exercises and custom exercises, workout dates and durations, sets, repetitions, and weights;
- training summaries, progress metrics, estimated one-repetition maximums, and personal records available under your Setlane plan;
- body-weight measurements;
- internal identifiers for workouts, templates, exercises, and sets when needed to retrieve the information you request;
- whether your account has access to Free or Pro capabilities, without disclosing payment-card details, Google Play purchase tokens, or billing records.
The connection does not provide the AI service with your Setlane email address, password, authentication credentials, purchase tokens, or payment details. Read-only access allows the AI service to retrieve only the Setlane data available under your plan.
If you choose read and write access, the AI service may also send instructions to Setlane to perform supported changes on your behalf, including:
- creating, updating, or deleting workout templates;
- creating or updating custom exercises;
- adding or updating today's body-weight entry;
- changing the date or exercise order of a completed workout and updating existing sets in completed workouts;
- deleting completed workouts or sets.
AI connections cannot control an active workout. Supported permanent deletions use a preview and require your separate explicit confirmation before Setlane executes them. Write actions are limited to Setlane's registered tools and server-side authorization checks. Because requests originate in the third-party AI service you choose, review proposed changes and conversation content before approving them.
To operate and secure the connection, we and our infrastructure providers may process OAuth authorization records, your selected access level, and limited diagnostic information such as a request identifier, requested tool, hashed connector identifier, response count, latency, status, and errors. For supported write actions, Setlane may also temporarily retain an operation identifier, tool name, request hash, and the result of the change to prevent a retried request from applying the same change twice. Setlane's MCP operational logs do not contain the full training-data response returned by a read tool.
3.7 Communications
If you contact us, we process your email address, message, and any information you choose to include so that we can respond and maintain appropriate support records.
04 How we use information
We use information to:
- create, authenticate, and maintain your account;
- save and synchronize workouts, routines, exercises, body-weight entries, and progress;
- provide offline functionality and restore interrupted workouts;
- verify Google Play purchases and provide Setlane Pro features;
- prevent purchase theft, fraud, abuse, and unauthorized access;
- operate rest-timer notifications and other features you request;
- provide optional AI connections with the read-only or read and write access you authorize, carry out supported changes you request, and enforce applicable Free or Pro feature limits;
- measure onboarding, feature use, retention, subscription conversion, and other aggregate product performance through the limited analytics described above;
- provide customer support;
- diagnose failures, protect the Service, and improve reliability;
- comply with legal obligations and enforce our Terms of Use.
We do not sell your personal data.
05 Legal bases
Where the GDPR, UK GDPR, or similar law applies, we rely on the following legal bases:
- Performance of a contract: to create your account and provide the Service and purchased features.
- Legitimate interests: to secure, maintain, troubleshoot, and improve the Service, understand aggregate product use, prevent fraud, and respond to support requests.
- Consent: where required for optional device permissions or other processing for which consent is legally required, including when you choose to authorize an optional AI connection to access fitness information or make supported changes at your direction. You may withdraw consent through your device settings, by revoking the connection in Setlane or the third-party AI service, or by contacting us.
- Legal obligation: where processing is necessary to comply with applicable law or valid legal requests.
06 Device permissions
Setlane may request notification permission so that it can show an active rest-timer notification and notify you when a rest period ends. If you deny the permission, the related notification may not appear, but the rest of the Service remains available.
On supported Android versions, Setlane may request permission to schedule exact alarms for accurate rest-timer completion. Setlane does not use these permissions for advertising or unrelated tracking.
Older Android versions may request storage permission only when needed to save a CSV export to your Downloads folder.
07 Service providers and disclosure
We disclose information only as necessary to operate the Service, process purchases, comply with law, or protect users. Our main service providers include:
- Supabase: authentication, database hosting, server functions, and related infrastructure, including storage and processing of Setlane's first-party product analytics;
- Google: Google Sign-In, Google Play Billing, purchase verification, subscription notifications, and related Google Cloud services;
- Vercel: website hosting, network delivery, and cookieless website analytics, as described above;
- Umami Cloud: cookieless pageviews and conversion events on the website, as described above; not used to build advertising profiles;
- OpenAI: when you choose to connect Setlane to ChatGPT, requested Setlane data and results of supported changes are provided to OpenAI, and OpenAI may send supported change instructions to Setlane, to handle your requests through that service;
- Anthropic: when you choose to connect Setlane to Claude, requested Setlane data and results of supported changes are provided to Anthropic, and Anthropic may send supported change instructions to Setlane, to handle your requests through that service;
- other infrastructure providers: network delivery, security, and operational logging.
These providers process information under their own terms and privacy commitments and only for the relevant services they provide.
OpenAI and Anthropic are independent third-party services. Information sent to the AI service you select may become part of your conversation history and is processed under that provider's account settings, terms, privacy policy, and retention practices. Setlane does not control the provider's processing after the information has been delivered to it.
We may also disclose information:
- when required by law, court order, or valid governmental request;
- when reasonably necessary to investigate fraud, security incidents, or violations of our Terms;
- as part of a merger, acquisition, financing, reorganization, or transfer of the Service, subject to appropriate safeguards and notice where required.
We do not share personal data with data brokers or advertisers.
08 International processing
Our service providers may process information in countries other than your country of residence. Where required, we rely on legally recognized transfer mechanisms and contractual safeguards. Privacy protections may vary between jurisdictions.
09 Retention
We generally retain account and fitness information for as long as your account remains active or as needed to provide the Service.
First-party product analytics events are normally retained for up to 13 months. Queued analytics events stored on your device expire after no more than seven days. Analytics events linked to your Setlane user identifier are deleted when your account is deleted. Events collected before sign-in that are associated only with a random installation identifier cannot reliably be connected to an account-deletion request and may remain until the normal retention period ends.
OAuth authorization and connection metadata is retained while an AI connection remains active and for limited security, audit, and troubleshooting purposes after it is revoked. Revoking a connection prevents future access by that connection but does not automatically delete information already included in a third-party AI conversation or retained by that provider. You can manage that information through the provider's own controls.
Records used to make MCP write requests idempotent are normally eligible for cleanup after 30 days. Short-lived write-rate and deletion-confirmation records are eligible for cleanup sooner. These records may remain until routine cleanup runs and are also removed when the associated Setlane account is deleted, subject to the limited exceptions below.
When your account is deleted:
- account data and user-linked workout, body-weight, profile, entitlement, and purchase records, including user-linked analytics events, are removed from active Setlane systems;
- an external deletion request will be processed within 30 days after we verify the request;
- processed Google Play subscription-notification records are normally removed after 90 days;
- limited security, error, legal, or dispute records may be retained longer when reasonably necessary or legally required;
- temporary backups and infrastructure logs may remain for a limited period under our providers' retention and security procedures.
Information stored only on your device may remain there after server-side account deletion. You can remove it by clearing Setlane's app data or uninstalling the app.
10 Account and data deletion
You can delete your account inside Setlane:
Settings → Account → Delete account
You may also request deletion without access to the app by following the instructions at setlane.app/delete-account.
Account deletion is permanent. It deletes the Setlane account and associated data from active systems. Setlane attempts to cancel an active auto-renewing Google Play subscription during in-app deletion, but you should always confirm the subscription status in Google Play.
A Setlane Pro Lifetime purchase is linked to the Setlane account on which it was claimed. Deleting that account permanently removes access to the lifetime entitlement, and it cannot be transferred to a newly created Setlane account.
11 Your rights and choices
Depending on where you live, you may have the right to:
- request access to personal data we hold about you;
- request correction of inaccurate data;
- request deletion of your data;
- restrict or object to certain processing;
- request a portable copy of data you provided;
- withdraw consent where processing is based on consent;
- disconnect an AI service at any time through Setlane's AI connections settings or the corresponding AI service's connector settings;
- lodge a complaint with a competent data-protection authority.
You may export available workout information from the Service and may exercise applicable rights by emailing support@setlane.app. We may need to verify your identity before completing a request.
12 Security
We use reasonable technical and organizational safeguards, including encrypted network connections, authenticated access, database access controls, row-level authorization, restricted billing functions, purchase verification with Google Play, OAuth access controls, user-selected read-only or read and write permissions, narrow server-side mutation tools, rate limits, idempotency protection, and confirmation checks for supported permanent deletions.
No method of storage or transmission is completely secure. You are responsible for protecting access to your device, email account, Google account, and Setlane credentials.
13 Third-party services and links
The Service may open or link to Google Play and other third-party services. If you choose to connect ChatGPT, Claude, or another compatible AI service, that service may process the Setlane information returned in response to your requests. Third-party processing is governed by the third party's own privacy policy, terms, account settings, and retention controls. Setlane is not responsible for the independent practices of third-party services.
14 Changes to this Policy
We may update this Privacy Policy to reflect changes to the Service, law, or our practices. We will update the effective date and provide additional notice where required. Continued use of the Service after an update means that the revised Policy applies from its effective date.
