Privacy notice
Last updated 9 October 2026.
Who runs this
Erg Training Log is a small, invite-only app run by the person who invited you, who is the data controller. Questions or requests: ask the person who invited you.
What it stores, and why
- Your account: your email address and a one-way scrambled (hashed) form of your password, so you can sign in. Lawful basis: providing the service you asked for.
- Your training: each session’s date, type, distance, time, splits, stroke rate, effort, how you felt and notes, plus your test scores. Lawful basis: providing the service.
- Heart rate (only if you agree): average and split heart rates and your maximum heart rate. Heart rate is health data, a special category under UK GDPR, so it is only stored with your explicit consent, which you can give at sign-up or later on the Account page. Lawful basis: explicit consent (Article 9(2)(a)).
- Security records: sign-in attempts (email, network address, time) for 7 days, to block password guessing. Lawful basis: legitimate interest in keeping accounts safe.
- Photo-read records: when a photo was read, which AI model read it, its size in tokens and its cost. No image is kept.
Photos of the monitor
A photo you choose is shrunk on your phone, sent to Google’s Gemini AI service (free tier). On the free tier Google may keep and use what is sent to improve its products, so the photo is shared with Google on those terms to read the numbers, and then discarded. It is never saved on the server.
Who can see it
Only you can see your sessions, scores and heart rate. The person running the app can see the list of accounts (email, join date, number of sessions) on an admin page, and could technically access the database on the server, but doesn’t look at individual training data. Nothing is sold or shared for marketing. There are no adverts, analytics or third-party trackers; fonts and scripts are served by the app itself.
Other services involved: Google (Gemini) (photo reading); Tailscale, which carries the encrypted connection to the server but can’t read it; Telegram, which receives the operator’s alerts (these never contain your data).
Where it is kept, and for how long
- On a server in the operator’s home in the UK. Connections are encrypted (HTTPS).
- Your data is kept while you have an account. Deleting your account deletes it straight away.
- Encrypted backups are taken nightly and kept for 30 days, so deleted data disappears from backups within 30 days.
- Withdrawing heart-rate consent deletes every stored heart rate straight away.
Your rights
- See and take your data: Account → Your data downloads everything (JSON) or your sessions (CSV).
- Correct it: edit any session in the training log.
- Delete it: Account → Delete account removes your account and all your data.
- Withdraw consent for heart rate at any time on the Account page.
- You can also object, ask for restriction, or complain to the Information Commissioner’s Office (ico.org.uk, 0303 123 1113).