Skilltrackr.

user privacy policy

Effective date: September 19, 2026 Applicable law: GDPR (EU 2016/679)

Legal notice (LCEN)

In accordance with French Law n°2004-575 of June 21, 2004 for confidence in the digital economy (LCEN), the following information is provided:

Publisher & data controllerFONTAINE Nathanaël
Address5 avenue de l'aviation, 66250 Saint-Laurent-de-la-Salanque, France
SIRET853 311 041 00034
Publication directorFONTAINE Nathanaël
Contacthello@skilltrackr.app
Websitewww.skilltrackr.app
Applicationmy.skilltrackr.app
Hosting providerIONOS SARL — 7 place de la Gare, 57200 Sarreguemines, France — www.ionos.fr
This Privacy Policy explains what personal data skilltrackr. — written “skilltrackr” in the rest of this document — collects, why we collect it, and how you can control it. skilltrackr (my.skilltrackr.app) is a coaching management platform that allows coaches to structure training programs and athletes to track their progress in real time. For the purposes of the GDPR, FONTAINE Nathanaël, operating as skilltrackr, is the data controller for all personal data processed through the platform. Questions? Contact us at privacy@skilltrackr.app

1. Data we collect

We only collect data that is necessary to provide the service, keep it secure, and meet our legal obligations.

DataWhen collectedRequired
UsernameAt registrationYes
Email addressAt registration or via Google Sign-InYes
Password (hashed)At registration (standard login only)If not using Google
Google IDIf you choose Sign in with GoogleNo — optional
User roleAt registration (coach or athlete)Yes
Language & time zoneIn-app settings; time zone detected from your browserNo
Training data (exercises, goals, progress, notes, plans, tasks)During use of the appYes — core of the service
Messages between coach and athleteWhen you send a message in the appYes — core of the service
Coach–athlete relationshipsWhen an athlete is attached to a coachYes
Session data (login time, session and "remember me" tokens)At each loginYes — for security
IP addressAt login attempts, on security events and in access logsYes — for security and abuse prevention
Notification preferences and, if you enable push, a push subscription (browser endpoint and encryption keys)When you enable notificationsNo — optional
Billing data (Stripe customer and subscription identifiers, plan, status, invoices, amounts and dates)Only if you subscribe to a paid planYes, for subscribers
Bug reports (your message, the page concerned, your browser)Only if you submit oneNo — optional
Reason for leaving (a reason picked from a list, and an optional comment)Only if you answer — when you delete your account, or after cancelling a subscriptionNo — optional
Demo mode (fictional demo accounts, and the IP address of the visitor who starts one)Only if you try the demo without an accountNo — optional
Video links on exercises (the address only — we never host or copy the video)When you or your coach adds oneNo — optional
Exercise prescriptions (sets, value, unit, load — e.g. 4 × 12 at 60 kg)When you or your coach adds one to an exerciseNo — optional
Personal records (a label, a value, a unit, a date, and optionally a link to one of your exercises)Only if you add one, from your stats page. Written by the athlete only — a coach can read them but cannot create or change them.No — optional
Perceived effort (a rating from 1 to 10 on a program session)Only if you rate a session. Written by the athlete only — a coach can read it but cannot enter or change it.No — optional
Emergency contact (name, relationship, phone number)Only if you fill it in, from your profileNo — optional
Height and weightOnly if you fill them in, from your profileNo — optional
Health information (allergies, treatments, past injuries — free text)Only if you fill it in and tick the specific consent boxNo — optional
Card details: we never see or store your payment card. Card data is entered on and held by Stripe; we only receive an identifier, the plan, its status and the resulting invoices.
Health data: athletes have one optional field for health information — allergies, treatments, past injuries — so that a coach knows what to do if something happens during a session. It is never stored unless you tick the dedicated consent box next to it, and unticking that box and saving erases what was stored. It is visible to the coaches you are attached to, and to no one else; the screen says so before you write anything. Leaving it empty has no effect on the service. Everywhere else in the app — task categories, notes, free text — anything you write is stored as ordinary training content, and we recommend you do not record medical details there.
Performance and effort are training data, not health data. A personal record ("bench press, 100 kg") and a perceived-effort rating ("that session felt like a 7 out of 10") describe what you did and how it felt. They are stored like your exercises and notes, on the same legal basis, and they are not part of the optional health field described above — which keeps its own separate, explicit consent. They are also not a medical measurement: the effort rating is your own subjective judgement of a session, nothing more. As everywhere else in the app, please do not use these fields to record injuries, symptoms or treatments; the health field exists for that, with the protection that goes with it.

Anonymous usage statistics: to know which screens are useful, the app adds 1 to a daily counter each time a screen is displayed (for example: "Tasks screen, athletes, 19 September") and each time you go from one screen to another. It counts the same way whether the app was opened from the home screen or in the browser, and how people answer the suggestion to turn on notifications. These counters carry no identifier, no IP address and no cookie: they cannot be traced back to you, to a device or even to a visit.

We do not collect geolocation data, we do not use advertising identifiers, and we do not track you across other websites.

The demo: "Try it" creates fictional accounts filled with invented content, which you can use for one hour; they are then deleted with everything in them. To limit abuse, we record the IP address that started a demo for 24 hours, after which it is erased. What remains is an anonymous entry — role, plan, sport and language — that no longer identifies anyone. Nothing you do in a demo is kept or shown to anyone else.

2. Why we collect it

We process your data exclusively for the following purposes: providing and operating the platform, authenticating users and securing accounts, enabling the coach–athlete relationship, storing training history and progress, sending you service emails and the notifications you enabled, processing subscriptions and issuing invoices, personalising your interface (language and time zone), detecting and preventing abuse, and maintaining the technical infrastructure. We do not use your data for advertising, profiling, automated decision-making, or sale to third parties.

3. Legal bases (GDPR Art. 6)

ProcessingLegal basis
Account creation and managementContract performance — Art. 6(1)(b)
Authentication and session securityContract performance — Art. 6(1)(b)
Training data, plans, progress, messagesContract performance — Art. 6(1)(b)
Exercise prescriptions, personal records, perceived effortContract performance — Art. 6(1)(b)
Subscriptions and payment processingContract performance — Art. 6(1)(b)
Retention of invoices for 10 yearsLegal obligation — Art. 6(1)(c)
Google Sign-In (Google ID)Consent — Art. 6(1)(a)
Push notificationsConsent — Art. 6(1)(a)
Support access to your accountConsent — Art. 6(1)(a)
Language & preference settingsLegitimate interest — Art. 6(1)(f)
Security logs, IP addresses, abuse preventionLegitimate interest — Art. 6(1)(f)
Technical logs and error trackingLegitimate interest — Art. 6(1)(f)
Emergency contact, height and weightConsent — Art. 6(1)(a)
Health information (special category data)Explicit consent — Art. 6(1)(a) and Art. 9(2)(a)

Health information is a special category of personal data under Article 9 of the GDPR, and nothing else you accepted covers it — neither creating your account, which rests on the performance of our contract, nor the optional box about product emails, which concerns emails and nothing else. It has its own consent, given at the moment you write the field and withdrawable at any time by unticking the box and saving — which deletes the field and the record of that consent.

About the tick-box at registration: it covers one thing only — occasional emails about new features and tips. It is optional, unticked by default, and refusing it changes nothing about your account. It is not an acceptance of this policy and it is not a consent to process your training data: that processing rests on the performance of our contract with you, as set out in the table above.

4. Who sees your data

We do not sell, rent, or trade your personal data. It is shared only in the following cases:

RecipientWhat they receiveLocation
Your coach — or coachesYour training data, tasks, progress and messages, plus the optional profile information you chose to fill in: emergency contact, height and weight, and health information if you consented to it. They also see your personal records and your perceived-effort ratings, in read-only: a coach can never create, edit or delete either of them. An athlete may be attached to several coaches; each of them sees the same data — deliberately, since any of them may be the one present when something happens. You accept every attachment individually and can detach a coach at any time from your settings, which ends their access.
Your athletes (if you are a coach)The exercises, plans and messages you create for them
IONOS SARL — hostingAll platform data, stored on servers in the European UnionEU
Google LLC — off-site backup copyA copy of the database, encrypted before it leaves the server, is stored on a Google Drive space. Google holds a file it cannot read: the decryption key stays on the server and never travels with the backup. Without that key nothing is sent — the service refuses to ship an unencrypted backup. This copy exists so that a server failure does not take your data down with it.United States (encrypted)
Stripe Payments Europe, Ltd. — paymentsYour email, subscription and billing details. Card data is collected directly by Stripe.EU (Ireland)
Brevo — transactional emailYour email address and the content of service emails we send youEU (France)
Google LLC — optional sign-inYour email address and Google ID, only if you use Sign in with Google. Governed by Google's Privacy Policy.USA
YouTube (Google) and Vimeo — embedded videoIf a coach attached a video link to an exercise and you open that video, the player is loaded from YouTube or Vimeo. They receive your IP address and the fact that this video was opened. Nothing is sent until you tap play on that exercise: no player is loaded when the page opens. We use YouTube's no-cookie domain, which stores nothing until playback starts.USA / EU
Your browser's push service (Google, Mozilla, Apple…)Only if you enable push notifications: the encrypted notification and your device endpoint. The content is encrypted end-to-end and is not readable by the push service.Varies
Legal authoritiesOnly what the law requires, on a valid legal request

Transfers outside the EU: two transfers routinely leave the European Union. The first is Google Sign-In, which is optional — you can avoid it entirely by registering with an email address and password. The second is the backup copy stored on Google Drive: it is encrypted before it leaves and the key stays on the server, so Google holds a file it cannot read anything from. Such transfers rely on the European Commission's standard contractual clauses and the EU–US Data Privacy Framework.

5. Support access to your account

To investigate a problem you report, an administrator may need to view your account as you see it. This never happens silently: a request appears in the app and access is granted only if you accept it. Your answer — whether you accept or refuse — is recorded with the date and your IP address, so that a consented support session can always be distinguished from an unauthorised access.

You can refuse without any consequence for your use of the service. Administrative actions on accounts are also written to an internal audit log.

6. Data retention

DataRetention period
Account data (email, username, role)Duration of the account — erased immediately on deletion
Training data (exercises, plans, tasks, progress, messages)Duration of the account. Archived items are kept so that historical statistics remain accurate.
Exercise prescriptions, personal records, perceived-effort ratingsDuration of the account — erased with it, or as soon as you delete the record, the session or the exercise they belong to. Deleting an exercise a record pointed to removes the link, not the record.
Session without "remember me"2 hours of inactivity
"Remember me" login tokenUntil you log out — this cookie is deliberately long-lived so that "remember me" does not expire on its own. Logging out deletes it immediately.
Activity log (who changed what)365 days, then automatically deleted
In-app notifications90 days
Email delivery log180 days
Push queue (once sent)30 days
Demo accounts and their content1 hour, then deleted
IP address of a visitor who started a demo24 hours, then erased
Technical access logs (including IP addresses)30 days
Invoices10 years — required by Article L.123-22 of the French Commercial Code
Records of support-access consentKept as evidence of consent, detached from the account after deletion
Emergency contact, height and weightDuration of the account — erased with it, or as soon as you clear the fields
Health information and the record of your consent to itDuration of the account — erased with it, and erased immediately if you untick the consent box and save
Anti-abuse counters (sign-up attempts on an address that already has an account, invitations sent by a coach)2 days, then erased automatically
Reason for leaving, after an account deletionKept without any link to you — the account no longer exists
Reason for cancelling a subscriptionDuration of the account; detached from it when the account is deleted
Anonymous usage countersKept as statistics — they contain nothing that relates to a person
BackupsEncrypted backups are overwritten within 30 days on the server. The off-site copy stored on Google Drive follows its own rule: the last twenty of each type are kept, older ones are deleted automatically.
Account deletion is immediate and irreversible. When you confirm deletion, your account, exercises, tasks, messages and progress are erased from our live systems straight away — not after a delay. Only invoices and consent records survive, because the law requires it, and they are no longer used to identify you as a user.

7. Your rights

Under the GDPR, you have the following rights. Exercise any of them by contacting privacy@skilltrackr.app. We respond within one month; where a request is complex we may extend this by two further months and will tell you why within the first month.

  • Right of access — Request a copy of all personal data we hold about you.
  • Right to rectification — Ask us to correct inaccurate or incomplete data. Most data can also be updated directly in your account settings.
  • Right to erasure — Delete your account yourself from your settings, or ask us to do it. Deletion is immediate, subject to the legal retention of invoices.
  • Right to restriction — Ask us to restrict processing in certain circumstances.
  • Right to data portability — Ask us for your data in a structured, machine-readable format. We prepare and send it on request.
  • Right to withdraw consent — Withdraw consent for Google Sign-In, push notifications or support access at any time, without affecting processing already carried out. For health information, withdrawal is done in the app itself: untick the consent box in your profile and save — the field and the record of that consent are deleted on the spot.
  • Right to object — Object to processing based on legitimate interests at any time.
  • Right to lodge a complaint — File a complaint with the French data protection authority: CNIL.

Service emails cannot be switched off. Messages about your account — password changes, username changes, account deletion, end of trial, payment issues — are part of the service and are not marketing. Allowing them to be disabled would let an intruder make their actions invisible.

8. Cookies & tracking

skilltrackr uses only strictly necessary cookies on the application. No advertising, marketing, or analytics cookies are used on the app.

CookiePurposeDuration
Session cookie (PHP session)Keeps you logged in during your visit2 hours of inactivity
st_rememberKeeps you logged in between visits if you chose "remember me"Until logout
st_langStores your interface language1 year
st_tri_exosRemembers how you sort your programs1 year — or until the browser closes when it hides programs (a filter)
st_tri_rosterRemembers how a coach sorts the roster1 year
st_att_rosterRemembers the status filter on the rosterUntil the browser closes

These cookies are essential to operate the service and do not require your consent, so no cookie banner is shown on the app. Protection against cross-site request forgery is handled inside your session, not by a separate cookie. The public website at skilltrackr.app is a separate site and may use analytics — see our Cookie Policy.

The app also keeps a few settings in your browser's storage — the theme you chose, which panels you collapsed, how many times it suggested notifications on this device, and the name of the screen you just left (only to count, anonymously, which screen leads to which). They are not cookies and we never read them from the server; the screen name is sent only as part of the anonymous counter described in section 2.

9. Data security

We implement appropriate technical and organisational measures to protect your data: all traffic is encrypted via HTTPS (TLS); passwords are hashed with bcrypt and never stored in plain text; all forms are protected against cross-site request forgery; a strict Content Security Policy limits injection attacks; access control ensures a coach only sees the athletes attached to them and an athlete cannot see another athlete's data; login attempts are rate-limited; sessions are invalidated on logout; push notification payloads are encrypted end-to-end; and the database is backed up regularly, encrypted, with a copy stored off the server so that a hardware failure does not take it down too — that copy is encrypted before it leaves and the decryption key never leaves the server.

In the event of a personal data breach likely to result in a high risk to your rights, we will notify the CNIL within 72 hours and inform you without undue delay, as required by Articles 33 and 34 of the GDPR.

10. Children

skilltrackr may be used by minors, since youth sport is one of its main uses. Anyone aged 15 or over may create an account on their own — this is the age of digital consent in France. Below 15, an account may only be created with the prior consent of a parent or legal guardian, who accepts this policy on the child's behalf.

A coach who invites a minor warrants that they have obtained the consent of that athlete's parent or legal guardian beforehand. A parent or guardian may contact us at privacy@skilltrackr.app at any time to access, correct or delete their child's data.

11. Contact & complaints

For any question or to exercise your rights: privacy@skilltrackr.app

If you are unsatisfied with our response, you may file a complaint with the CNIL:
Commission Nationale de l'Informatique et des Libertés — 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — www.cnil.fr

This policy may be updated from time to time. Material changes will be communicated by email to registered users. Continued use of skilltrackr after changes constitutes acceptance of the updated policy. This version was published on September 14, 2026.