Privacy Policy
What Beat It processes, why it is needed, and how you can control or remove your information.
Last updated: September 7, 2026
1. Who is responsible?
David van den Pol is responsible for the personal data processed to provide Beat It. In this policy, “Beat It”, “we”, “us” and “our” refer to this service. Contact david@webwrk.nl for privacy questions or requests.
This policy explains data processing in the Beat It iOS app, related account services and communications with support. Apple, Google and other providers may also process data for their own services under their own policies.
2. Information we process and where it comes from
- Account and identity. When you use Sign in with Apple or Google, we receive a provider identifier and account information made available by that provider, such as an email address and name. Apple may supply a private relay email address. We also process your Beat It account ID, chosen display name or handle, authentication state and session credentials.
- Profile and preferences. Information you choose to enter can include date of birth, sex, height, body weight, preferred weight units, language and notification or analytics choices. Optional profile fields can be left blank or edited in Settings.
- Workouts and fitness data. We process exercises, custom exercise names, workout plans, sessions, sets, weights, repetitions, timestamps, rest intervals, reps in reserve, goals and related progress. This includes derived training estimates, plateau indicators and program state needed to show your training history and suggestions.
- Training feedback. The app can record workout difficulty and answers about pain associated with a set. This may reveal health-related information and can be sensitive. Only provide information you want processed for the relevant training feature. This policy is not itself a request for consent to health-data processing.
- Purchases and access. Apple and RevenueCat provide purchase and transaction identifiers, product information, subscription status, renewal or expiry information and entitlement results so we can provide paid access and restore purchases. We do not receive your full payment-card number from Apple.
- Optional analytics and diagnostics. If you opt in to PostHog analytics, we process app and screen interactions, training- and goal-related events, subscription and paywall events, error information and technical context such as app version, platform and device or SDK identifiers. These events can be connected to your account ID and subscription status. They are linked or pseudonymous data, not anonymous crash-only reports.
- Support and service delivery. We process messages and contact details you send us. Requests to our hosting and service providers also involve technical connection information, such as IP addresses, request times and service or security logs. Do not include unnecessary sensitive information in support messages.
The current app does not request Apple Health access or import HealthKit records. Information is obtained from your entries, the app’s use of its services, your chosen sign-in provider and Apple/RevenueCat purchase records.
3. Why we use this information
- Create and secure your account, maintain sessions, and synchronize your data.
- Save your workouts, apply your preferences and calculate training statistics, Goal Path estimates and plateau guidance.
- Verify purchases, deliver paid features, restore access and handle purchase-related support.
- Schedule optional local reminders and display the system features you use.
- With your analytics choice, understand feature use, investigate errors and measure how the app and purchase experience perform.
- Answer support and privacy requests, prevent misuse and meet applicable legal obligations.
Training calculations are intended to help you understand your own records. They are not medical diagnoses and do not make decisions with legal or similarly significant effects about you.
4. Choices, permissions and consent
- Optional analytics: when configured, PostHog collection starts only after you opt in. Change the analytics switch in Settings → Account and data. Turning it off stops future optional collection and clears the app’s local analytics state. It does not automatically erase previously processed server events; request deletion or delete your account if you also want those records removed.
- Notifications: allow or deny the iOS notification permission. Change it later in iPhone Settings for Beat It. Notifications are optional; disabling them does not cancel a trial or subscription.
- Optional profile details: skip these fields or update or clear them through the available profile controls. Contact us if you need help removing a field or a recorded item.
- Sharing: progress is not posted to a public feed by default. If you use a share action, you choose the destination. Copies held by recipients or other apps are not removed when you delete your Beat It account.
- Account services: declining optional analytics does not stop the processing needed for login, saving data, subscription verification or security.
Where GDPR applies, processing needed to provide the service you request is based on performance of a contract; optional analytics is based on consent. Service security and appropriate support administration may rely on legitimate interests, subject to your rights. Records required by law are processed to comply with legal obligations. Withdrawing consent does not affect the lawfulness of processing before withdrawal.
Health-related data may require an additional legal condition under applicable law, such as explicit consent. Acceptance of this policy or the Terms is not, by itself, that consent. Contact us with questions about processing or removing health-related training information.
5. Who receives data
- Supabase: account authentication, database storage and server functions for your profile, workouts, plans, goals and account administration. Supabase privacy information.
- Apple: Sign in with Apple if you choose it, App Store distribution, purchase processing and subscription management. Apple retains its own purchase and account records. Apple privacy information.
- Google: Google sign-in if you choose that provider. Google privacy information.
- RevenueCat: purchase validation, account-linked paid entitlements, restoration and subscription support. It receives the Beat It account identifier and purchase-related information. If you opt in to analytics, the account identifier can also be associated with analytics attribution. RevenueCat privacy information.
- PostHog: the optional account-linked product, training, purchase-flow and diagnostic analytics described above. PostHog privacy information.
- Hosting, email and necessary professional support: technical requests, support correspondence or records needed to operate the service, handle a request or comply with the law.
We require providers processing personal data on our behalf to use it only for the agreed purposes and to provide the same or equal protection described in this policy and required by applicable rules. A provider’s own privacy policy does not replace this policy. We may also disclose information when required by law or necessary to protect legal rights, with appropriate limits.
Providers may process data in countries outside your country of residence, including outside the European Economic Area. Where required, international transfers need an applicable adequacy decision or appropriate safeguards, such as standard contractual clauses. Contact us for information about the destinations and safeguards applicable to your data. We do not promise that every provider keeps all data exclusively in the EU.
6. Retention, security and deletion
Account, profile and workout records are kept while you maintain your account so that history and synchronization continue to work, unless you remove a record or request deletion. The 90-day Free history view is a viewing limit, not a promise that older stored data is deleted.
For other records, retention is limited by their purpose: account-linked analytics is used to understand product use and resolve faults; support correspondence is retained to handle the request and any necessary follow-up or dispute; security records are retained for prevention and investigation of misuse; records required by law are retained for the applicable legal period. Records should no longer be retained when those purposes end. Contact us for the retention period that applies to a particular record or to request its deletion.
You can start account deletion directly in the app. Successful deletion removes the active Beat It account and associated profile and workout data. The workflow also revokes the linked Apple authorization where applicable, removes the RevenueCat customer record and submits deletion of linked PostHog data where configured. External deletion jobs can complete after the app confirms active-account deletion.
Active-system deletion is different from expiry of backup copies or records a provider is legally required to retain. Where such records remain, they are subject to the applicable backup cycle or legal retention requirement rather than continued ordinary account use. We will explain any applicable exception and expected timing when handling a deletion request. Apple purchase records and copies you shared outside Beat It are not deleted from those independent systems by deleting your Beat It account.
Connections use HTTPS and app session credentials use iOS Keychain storage. Access controls are used to restrict account data. These measures reduce risk but cannot guarantee that every system or transmission is completely secure.
7. Your requests and rights
Depending on the law that applies, you may request access to your data, correction, deletion, restriction of processing, portability of eligible data, or object to processing based on legitimate interests. You may withdraw consent for optional processing. These rights can be subject to legal exceptions.
Email david@webwrk.nl to make a request. We may ask for proportionate information to verify account ownership. We will not ask for your password or one-time sign-in code. There is no in-app full-data export button in the current release; use this contact route to request a copy.
For GDPR requests, we respond without undue delay and normally within one month. If a lawful extension is necessary, we will explain it within that first month. You may complain to the data-protection authority where you live or work, or where you believe an infringement occurred. In the Netherlands, this is the Autoriteit Persoonsgegevens.
8. Website, children and policy updates
The Beat It page content does not embed advertising pixels, external fonts, videos or analytics scripts. Website hosting and WordPress features can separately involve connection logs or cookies. Any additional optional website tracking requires its own accurate disclosure and consent where required; the app analytics switch does not control website plugins.
Beat It is not directed to children who cannot lawfully provide the consent or agreement required for its services. If you believe a child has supplied personal information without the required authorization, contact us so we can investigate and remove it where appropriate. The App Store age rating is not a substitute for applicable privacy or contractual age requirements.
We may update this policy as the service or applicable requirements change. The date at the top identifies this version. We will provide an appropriate notice of material changes and obtain a new consent where required before using data for a new consent-based purpose.