01

Introduction

WorkoutPath ("we," "us," or "our") operates the fitness tracking web application available at workoutpath.fit. We are committed to protecting your personal data and complying with applicable privacy laws, including the European Union General Data Protection Regulation (GDPR) and the Turkish Personal Data Protection Law (Kişisel Verilerin Korunması Kanunu — KVKK, Law No. 6698).

This Privacy Policy governs all personal data processed through our web application, including data you provide during account registration, data generated through your use of the app, and data collected automatically via our third-party analytics provider.

For privacy-related questions or data requests, contact us at: pathworkout@gmail.com

02

Data We Collect

We collect the following categories of personal data:

(a) Account Data

When you register for a WorkoutPath account, we collect:

  • Email address — used as your primary account identifier and login credential
  • Password — we never store your password in plain text; Supabase Inc. handles authentication and stores only a cryptographic hash of your password using industry-standard hashing algorithms (bcrypt)

Legal basis (GDPR Art. 6(1)(b)): Processing necessary for the performance of the contract (providing you with access to the service).

(b) Profile Data

To personalize your workout program, we collect the following profile information:

  • Name — used to personalize the app experience
  • Gender — used to generate appropriate workout recommendations
  • Activity level — used to calibrate program intensity (stored in both our database and your browser's localStorage under the key wpActivityLevel)

Legal basis (GDPR Art. 6(1)(b)): Necessary for the performance of the service you requested.

(c) Fitness Data

Fitness and training data is classified as health-adjacent sensitive personal data under KVKK (özel nitelikli kişisel veri). Explicit consent is required before we process this data, which you provide at account creation.

We collect and store:

  • Training program selection — your chosen workout split from our 14 available programs (stored under localStorage key wpSelectedProgram and synced to Supabase)
  • Workout days and schedule — which days of the week you train
  • Exercise data — exercises completed, sets, reps, and workout progress from our library of 104+ exercises

Legal basis (GDPR Art. 9(2)(a) / KVKK Art. 6): Explicit consent, provided during account registration.

(d) Usage Data — Google Analytics

We use Google Analytics 4 (GA4) to understand how users interact with WorkoutPath. GA4 automatically collects the following data through cookies and tracking scripts:

  • IP address — automatically collected by Google; used to infer approximate geographic location (city/region level); Google anonymizes IP addresses by default in GA4
  • Device type and model — e.g., mobile, tablet, desktop; manufacturer and model where available
  • Browser and operating system — browser name, version, and operating system information
  • Pages visited — which pages or screens of WorkoutPath you viewed and in what order
  • Session duration — how long you spend in the application per session
  • Referral source — how you arrived at WorkoutPath (e.g., search engine, direct, social media)
  • Events and interactions — button clicks, navigation events, and feature interactions as configured in GA4

Legal basis (GDPR Art. 6(1)(a)): Consent obtained before loading Google Analytics scripts. GA4 ID: G-146133G10J.

(e) Local Data — Browser Storage

WorkoutPath uses your browser's localStorage to enable offline functionality and reduce server requests. The following data is stored locally on your device:

  • wpUser — your basic account identifier (for session persistence)
  • wpProfile — your profile preferences (name, gender, activity level)
  • wpSelectedProgram — your active workout program selection
  • wpActivityLevel — your configured activity level

This data remains on your device and is not transmitted to our servers independently — it is synced to Supabase only when you are online and actively using the application. You can clear this data at any time through your browser settings.

03

How We Use Your Data

Purpose Data Used Legal Basis
Account creation and authentication Email, password hash Contract performance (Art. 6(1)(b))
Personalizing your workout program Gender, activity level, fitness data Contract performance + Explicit consent
Delivering the service (app functionality) All account and profile data Contract performance (Art. 6(1)(b))
App analytics and improvement Usage data via GA4 Consent (Art. 6(1)(a))
Support and communication Email address Legitimate interest (Art. 6(1)(f))
Legal compliance and safety As required Legal obligation (Art. 6(1)(c))

We do not sell your personal data. We do not use your data for advertising targeting beyond aggregate analytics. We do not share your fitness data with third parties for commercial purposes.

04

Third-Party Processors

We engage the following data processors who may access your personal data as part of providing our service:

Supabase Inc. — Database & Authentication

Role: Data Processor. Supabase provides our backend database and authentication infrastructure.

Data processed: Account data (email, hashed password), profile data, fitness data, and all structured data in our application database.

Servers: Supabase operates on Amazon Web Services (AWS) infrastructure. Our database is hosted at zftocjpdkiqvurnxmjdh.supabase.co. Data may be processed in both EU and US regions depending on the AWS region configuration.

Privacy information: supabase.com/privacy

Google LLC — Analytics

Role: Data Processor. Google provides our analytics service (Google Analytics 4, GA4).

Data processed: Usage data including IP address (anonymized), device information, browser information, pages visited, session duration, and behavioral events.

How it works: GA4 uses JavaScript tracking code embedded in our pages. This code sets cookies (see Section 5) and sends data to Google's servers. We only load GA4 scripts after obtaining your consent. Our GA4 Property ID is G-146133G10J.

Data transfers: Google may process analytics data in the United States. Google LLC is certified under the EU-US Data Privacy Framework.

Privacy information: policies.google.com/privacy | GA Opt-out Browser Add-on

Vercel Inc. — Hosting

Role: Data Processor. Vercel hosts and delivers the WorkoutPath web application.

Data processed: Vercel may process server access logs, which can include your IP address, request timestamps, pages requested, and HTTP headers — standard data for web hosting and CDN delivery.

Servers: Vercel operates a global CDN with edge nodes in multiple regions. Vercel is headquartered in the United States.

Privacy information: vercel.com/legal/privacy-policy

05

Cookies & Tracking

WorkoutPath uses cookies and similar tracking technologies. Below is a summary of what we use and why:

Cookie / Storage Type Purpose Duration
_ga Analytics (GA4) Distinguishes unique users for Google Analytics 2 years
_ga_XXXXXXXX Analytics (GA4) Maintains session state and stores session data for GA4 (the suffix corresponds to our GA4 property) 2 years
Supabase auth token Functional (Essential) Maintains your authenticated session so you stay logged in Session / 7 days
localStorage (wpUser, wpProfile, wpSelectedProgram, wpActivityLevel) Functional (Essential) Stores app state locally for offline functionality Persistent (until cleared)

Consent for Analytics: We obtain your explicit consent before loading Google Analytics scripts or setting analytics cookies. You can withdraw consent at any time by adjusting your preferences through the cookie consent interface or by using the Google Analytics Opt-out Add-on.

Essential cookies (Supabase authentication tokens and localStorage keys) are necessary for the app to function. You cannot opt out of these without losing access to the service.

You may also manage cookies through your browser settings. Most browsers allow you to refuse or delete cookies. Note that refusing functional cookies may impair your ability to use WorkoutPath.

06

Data Retention

Data Category Retention Period Notes
Account data (email, password hash) Duration of account + 30 days after deletion 30-day grace period allows account recovery; after that, data is permanently deleted from Supabase
Profile data (name, gender, activity level) Duration of account + 30 days Deleted along with account data
Fitness data (training programs, workouts) Duration of account + 30 days Deleted with account; no archival copies retained beyond the grace period
Analytics data (Google Analytics) As per Google's retention settings Default GA4 retention is 14 months for event-level data; aggregate reporting data may be retained longer by Google per their terms
Server access logs (Vercel) Per Vercel's logging policy Typically short-term operational logs; not specifically retained by WorkoutPath
Browser localStorage Until you clear browser data Managed entirely on your device; we have no control over this after data is written
07

Your Rights

You have meaningful rights over your personal data. We take these rights seriously and will respond to all verified requests within 30 days.

GDPR Rights (EU/EEA Users)
  • Right of Access (Art. 15) — Request a copy of all personal data we hold about you, along with information about how it is processed.
  • Right to Rectification (Art. 16) — Request correction of inaccurate or incomplete personal data.
  • Right to Erasure / Right to be Forgotten (Art. 17) — Request deletion of your personal data when it is no longer necessary for the purposes collected, consent is withdrawn, or you object to processing.
  • Right to Restriction of Processing (Art. 18) — Request that we limit how we use your data in certain circumstances (e.g., while contesting accuracy).
  • Right to Data Portability (Art. 20) — Receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
  • Right to Object (Art. 21) — Object to processing based on legitimate interests or for direct marketing purposes.
  • Right to Withdraw Consent — Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing.
  • Right to Lodge a Complaint — Lodge a complaint with your national supervisory authority (e.g., your country's Data Protection Authority).
KVKK Kapsamındaki Haklarınız
Turkish Users — Rights under Law No. 6698, Article 11

6698 Sayılı Kişisel Verilerin Korunması Kanunu'nun 11. maddesi kapsamında, veri sahibi olarak aşağıdaki haklara sahipsiniz:

  • Kişisel veri işlenip işlenmediğini öğrenme — WorkoutPath'ın hakkınızda kişisel veri işleyip işlemediğini öğrenme hakkına sahipsiniz.
  • Kişisel veriler işlenmişse buna ilişkin bilgi talep etme — İşlenen kişisel verilerinize ilişkin bilgi talep etme hakkına sahipsiniz.
  • İşlenme amacını ve bunların amacına uygun kullanılıp kullanılmadığını öğrenme — Verilerinizin işlenme amacını ve bu amaca uygun kullanılıp kullanılmadığını sorgulamak hakkına sahipsiniz.
  • Yurt içinde veya yurt dışında kişisel verilerin aktarıldığı üçüncü kişileri bilme — Verilerinizin aktarıldığı üçüncü tarafları (Supabase, Google, Vercel dahil) öğrenme hakkına sahipsiniz.
  • Kişisel verilerin eksik veya yanlış işlenmiş olması hâlinde bunların düzeltilmesini isteme — Eksik veya hatalı kişisel verilerinizin düzeltilmesini talep edebilirsiniz.
  • KVKK'nın 7. maddesi çerçevesinde kişisel verilerin silinmesini veya yok edilmesini isteme — Kanunun öngördüğü koşulların sağlanması halinde kişisel verilerinizin silinmesini veya yok edilmesini talep edebilirsiniz.
  • Düzeltme ve silme işlemlerinin üçüncü kişilere bildirilmesini isteme — Verilerinizde yapılan düzeltme veya silme işlemlerinin, verilerin aktarıldığı üçüncü kişilere bildirilmesini talep edebilirsiniz.
  • İşlenen verilerin münhasıran otomatik sistemler vasıtasıyla analiz edilmesi suretiyle aleyhe bir sonucun ortaya çıkmasına itiraz etme — Otomatik işleme sonuçlarına itiraz etme hakkına sahipsiniz.
  • Kişisel verilerin kanuna aykırı olarak işlenmesi sebebiyle zarara uğraması hâlinde zararın giderilmesini talep etme — Kişisel verilerinizin kanuna aykırı işlenmesi nedeniyle uğradığınız zararın tazminini talep edebilirsiniz.

Haklarınızı kullanmak için pathworkout@gmail.com adresine yazılı olarak başvurabilirsiniz. Başvurularınız, Kanun'un 13. maddesi gereğince en geç 30 gün içinde sonuçlandırılacaktır. Kişisel veri işlemelerimize ilişkin şikayetlerinizi Kişisel Verileri Koruma Kurumu (KVKK)'na iletebilirsiniz.

To exercise any of these rights, please email us at pathworkout@gmail.com with the subject line "Data Rights Request" and include your account email address so we can verify your identity.

08

Health Data Notice

Sensitive Data Classification

Your fitness and training data is treated as health-adjacent sensitive personal data. Under KVKK (Art. 6), this data falls within the category of "özel nitelikli kişisel veri" (special categories of personal data). Under GDPR (Art. 9), data concerning health requires explicit consent and heightened protection. We apply additional safeguards to this data as described below.

WorkoutPath collects information about your physical training activities, including workout programs, exercise selections, training frequency, and physical activity levels. While WorkoutPath is not a medical service and does not collect clinical health records, your fitness data is considered health-adjacent and is treated with the same level of legal care as health data under applicable Turkish and EU privacy law.

How We Protect Your Fitness Data
  • Explicit consent at signup: We obtain your separate, explicit consent to process fitness data before you can begin using the workout tracking features.
  • Access control: Your fitness data is accessible only to you through your authenticated account. Our team does not review individual user fitness records.
  • No third-party sharing: We do not share your individual fitness data with any third party for research, commercial, insurance, or advertising purposes.
  • Encrypted in transit: All data transmitted between your device and Supabase is encrypted using TLS/HTTPS.
  • Encrypted at rest: Supabase encrypts stored data at rest using AES-256 encryption.
Withdrawing Consent for Health-Adjacent Data

You may withdraw consent for processing your fitness data at any time by deleting your account. Deleting your account will permanently erase all fitness data from our systems within 30 days. To delete your account, contact pathworkout@gmail.com.

Please note that withdrawing consent will result in the termination of your WorkoutPath account, as fitness data is core to the service we provide.

09

Children

WorkoutPath is intended for users who are 13 years of age or older.

We do not knowingly collect personal data from children under the age of 13. If you are under 13, please do not use WorkoutPath or provide any personal data to us.

Turkish Law — Parental Consent for Users Under 18: Under KVKK and Turkish law, the processing of health-adjacent (sensitive) personal data of individuals under the age of 18 requires verifiable parental or guardian consent. If you are between the ages of 13 and 17, your parent or legal guardian must review this Privacy Policy and provide consent on your behalf before you create an account or use the fitness tracking features of WorkoutPath.

If we become aware that we have collected personal data from a child under 13, or from a user under 18 without verifiable parental consent for sensitive data processing, we will take steps to promptly delete that data from our systems. If you are a parent or guardian and believe we have collected data from your child without appropriate consent, please contact us immediately at pathworkout@gmail.com.

10

International Data Transfers

Your personal data may be transferred to and processed in countries outside of Turkey or the European Economic Area (EEA), including the United States, where our third-party service providers operate.

Supabase Inc. (US/EU)

Supabase is headquartered in the United States and operates infrastructure on AWS, which may include regions both within and outside the EU. Data transfers from the EEA to the US via Supabase may be covered by Standard Contractual Clauses (SCCs) or other appropriate transfer mechanisms as described in Supabase's Data Processing Agreement.

Google LLC (US)

Google Analytics data is processed by Google LLC in the United States. Google LLC participates in the EU-US Data Privacy Framework (DPF), which provides an adequacy decision basis for data transfers from the EEA to the US. Additionally, Google's Analytics Data Processing Terms include Standard Contractual Clauses.

Vercel Inc. (US/Global)

Vercel is headquartered in the United States and operates a global edge network. Server access log data may be processed in various regions. Vercel provides Standard Contractual Clauses for EU data transfers.

We take reasonable steps to ensure that any international transfer of your personal data is protected by appropriate safeguards consistent with GDPR Chapter V and KVKK Article 9.

11

Contact & Requests

For all privacy-related inquiries, data access requests, erasure requests, or complaints, please contact us at:

WorkoutPath Privacy Contact

Email: pathworkout@gmail.com

Subject line recommendation: "Privacy Request — [your request type]"

We will acknowledge your request within 5 business days and respond substantively within 30 days of receiving a verified request. In complex cases, we may extend this by an additional 60 days (2 months) for GDPR purposes, with prior notification.

If you are an EU/EEA resident and are not satisfied with our response, you have the right to lodge a complaint with your national data protection authority. Turkish users may file a complaint with the Kişisel Verileri Koruma Kurumu (KVKK).

12

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, our services, or applicable law. When we make changes, we will:

  • Update the "Last updated" date at the top of this document
  • Notify registered users via email at the address associated with their account when changes are material
  • Where required by law (e.g., for changes that affect health-adjacent data processing), obtain fresh consent before applying the changes to your data

We encourage you to review this Privacy Policy periodically. Your continued use of WorkoutPath after a policy update constitutes acceptance of the revised terms, provided that any changes requiring explicit consent will be separately obtained.

Previous versions of this Privacy Policy are available upon request at pathworkout@gmail.com.