Privacy Policy

Last updated: April 20, 2026

At EntrenAI, we take the protection of your personal data very seriously. This Privacy Policy transparently explains what information we collect, how we use it, who we share it with, and what rights you have over it.

This policy complies with the General Data Protection Regulation (EU) 2016/679 (GDPR), Spanish Organic Law 3/2018 on Personal Data Protection and Digital Rights Guarantee (LOPDGDD), and Law 34/2002 on Information Society Services and Electronic Commerce (LSSI-CE).

1. Data Controller

EntrenAI is not required to appoint a Data Protection Officer (DPO) under Art. 37 GDPR. However, we respond directly to all privacy inquiries at privacidad@entrenai.app.

📋 Legal identification of the controller (Art. 10 LSSI-CE)
  • Holder: Iván López Martín
  • NIF: 70837112X
  • Address: Calle Flor de Loto 1, Ávila, España

2. Categories of Data We Collect

We collect different categories of data depending on how you interact with our services. Below we detail each category with its corresponding legal basis:

2.1 Registration and Account Data

  • First and last name
  • Email address
  • Password (stored with bcrypt hash, never in plain text)
  • Date of birth
  • Biological sex
  • Profile photo (optional)

📋 Legal basis: Art. 6(1)(b) GDPR – Contract performance

2.2 Training Profile Data

  • Goals (strength, hypertrophy, endurance, weight loss, HYROX, etc.)
  • Experience level (beginner, intermediate, advanced)
  • Sports practiced (gym, running, cycling, swimming, triathlon)
  • Available equipment
  • Available training days and times
  • Previous injuries or physical limitations

📋 Legal basis: Art. 6(1)(b) GDPR – Contract performance

2.3 Health Data (Special Category – Art. 9 GDPR)

⚠️ This data is optional and requires your separate explicit consent. We will never sell or use this data for advertising or purposes other than personalizing your training.

  • Body weight and weight history
  • Height
  • Body fat percentage (if provided)
  • Heart rate and HR zones (if you connect a wearable)
  • Sleep data: duration, quality, phases (if you connect a wearable)
  • Heart rate variability (HRV)
  • Perceived fatigue level (daily check-in)
  • Reported muscle soreness or discomfort

📋 Legal basis: Art. 9(2)(a) GDPR – Explicit consent of the data subject

2.4 Activity and Training Data

  • Complete workout history
  • Exercises performed: sets, reps, weights, RIR/RPE
  • Rest times between sets
  • Personal records (PRs) and historical progression
  • Notes and comments on workouts
  • GPS data from outdoor activities (running, cycling): route, distance, elevation
  • Pace, cadence, power, SWOLF (depending on activity)

📋 Legal basis: Art. 6(1)(b) GDPR – Contract performance

2.5 Wearable and App Integration Data

If you choose to connect external devices or applications, we may receive data from:

  • Garmin Connect: activities, HR, sleep, stress, Body Battery
  • Polar Flow: activities, HR, Training Load Pro
  • Apple Health / HealthKit: activities, steps, HR, sleep
  • Google Fit / Health Connect: activities, steps, HR, sleep
  • Strava: running and cycling activities

🔒 Commitment: Health data obtained from these integrations will never be sold, shared with third parties for advertising, or used for purposes other than personalizing your training experience.

📋 Legal basis: Art. 6(1)(a) and 9(2)(a) GDPR – Consent

2.6 Technical and Usage Data

  • IP address (anonymized for analytics)
  • Device type, manufacturer, model
  • Operating system and version
  • EntrenAI app version
  • Language and timezone
  • Screens visited and features used
  • Errors, crashes, and diagnostic logs

📋 Legal basis: Art. 6(1)(f) GDPR – Legitimate interest (service improvement and security)

3. Purposes of Processing

🎯 Main Service Provision

Create your account, generate personalized AI training plans, adapt the plan based on your fatigue and performance, manage your subscription, and provide app functionalities.

🤖 AI Algorithm Functioning

Analyze your progress, history, and feedback to automatically adjust volume, intensity, and exercise selection. AI models process your data to offer personalized recommendations.

📊 Analysis and Service Improvement

Analyze app usage in aggregate and anonymized form to improve user experience, detect and fix errors, and develop new features.

📧 Communications

Send you notifications about your training, reminders, important service updates, and marketing communications (only with your express consent).

🛡️ Security and Fraud Prevention

Protect your account, detect suspicious activity, prevent fraud, and ensure service integrity.

⚖️ Legal Compliance

Comply with legal and tax obligations, respond to requests from competent authorities, exercise or defend legal claims.

4. Data Sharing with Third Parties

✓ We do not sell your personal data. We never have and never will.

Health data is never shared with third parties for advertising, marketing, or any commercial purpose.

We only share your data in the following strictly necessary circumstances:

Service Providers (Data Processors)

Companies that help us operate the service, with data processing agreements pursuant to Art. 28 GDPR:

  • • Supabase – Database and authentication (EU servers). Privacy Policy
  • • Vercel – Web hosting (US, SCC + DPF). Privacy Policy
  • • Railway – Backend and APIs (US, SCC). Privacy Policy
  • • Cloudflare (R2) – CDN and object storage (exercise images and videos). Privacy Policy
  • • Resend – Transactional email sending (US, SCC). Privacy Policy
  • • Stripe – Payment processing and subscription management (PCI DSS Level 1 certified, SCC + DPF). Privacy Policy
  • • Expo (EAS) – Mobile app distribution and updates. Privacy Policy
  • • OpenAI – Conversational assistant (chatbot) inside the app. Only processes conversations you initiate with the chatbot. OpenAI does not use your messages to train its models. SCC + DPF. Privacy Policy
  • • Firebase (Google) – Solely as certificate infrastructure for Google Sign-In (SSO). We do not use Firebase Analytics, Firestore, or Crashlytics. Privacy Policy
  • • Apple (App Store + Sign in with Apple) – iOS distribution, in-app purchase management, and authentication via Apple ID. Privacy Policy
  • • Google (Play Store) – Android distribution and in-app purchase management. Privacy Policy

Integrations Authorized by You

Garmin Connect, Polar Flow, Apple Health, Google Fit, Strava. Only activated if you initiate the connection and you can revoke access at any time.

Payment Platforms

Stripe processes subscription payments. Stripe is a PCI DSS Level 1 certified platform and acts as a data processor. EntrenAI does not store or have access to your complete credit card data.

Legal Requirements

When legally necessary: comply with applicable laws, respond to judicial processes, protect the rights of EntrenAI and its users, or in emergencies to protect people's safety.

5. International Data Transfers

We prioritize keeping your data within the European Economic Area (EEA). When it is necessary to transfer data outside the EEA, we ensure an equivalent level of protection through:

  • European Commission adequacy decisions: For countries that guarantee an adequate level of protection (Switzerland, UK, etc.).
  • Standard Contractual Clauses (SCCs): Approved by the European Commission, signed with each provider processing data outside the EEA.
  • EU-US Data Privacy Framework (DPF): For transfers to US companies certified under this framework.

You can request information about the specific safeguards applied by contacting privacidad@entrenai.app.

6. Data Retention Periods

We retain your data only for the time necessary to fulfill the purposes described:

Data CategoryRetention Period
Account dataWhile account is active + 2 years after deletion
Training dataWhile account is active + 30 days after deletion
Health dataDeleted immediately upon account deletion or consent withdrawal
Billing data5 years (Spanish tax legal obligation)
Technical and security logs90 days
Analytics data14 months (anonymized/aggregated)

After requesting account deletion, we complete the deletion of all your personal data within a maximum of 45 days, except for data we must retain due to legal obligations.

7. Your Data Protection Rights

Under GDPR and LOPDGDD, you have the following rights over your personal data:

📋 Access

Obtain confirmation of whether we process your data and request a complete copy in electronic format.

✏️ Rectification

Correct inaccurate data or complete incomplete data.

🗑️ Erasure ("Right to be Forgotten")

Request deletion of your data when no longer necessary, you withdraw consent, or other cases under Art. 17 GDPR.

📦 Portability

Receive your data in structured format (JSON, CSV) and transmit them to another controller.

🚫 Objection

Object to processing based on legitimate interest or for direct marketing.

⏸️ Restriction

Request that we temporarily suspend processing while verifying accuracy or legitimacy.

↩️ Withdraw Consent

Withdraw your consent at any time, without affecting the lawfulness of prior processing.

🤖 Automated Decisions

Not be subject to decisions based solely on automated processing that produce significant legal effects.

How to exercise your rights?

We will respond to your request within a maximum of 30 days (extendable by 60 additional days in complex cases, with notification). Exercising these rights is free.

Complaint to supervisory authority: If you believe your rights have not been respected, you can lodge a complaint with the Spanish Data Protection Agency (AEPD): www.aepd.es, or with the supervisory authority of your country of residence in the EU/EEA. You can find the full list at edpb.europa.eu/about-edpb/about-edpb/members.

8. Security Measures

We implement appropriate technical and organizational measures to protect your data against unauthorized access, loss, destruction, or alteration:

  • Encryption in transit: TLS 1.3 for all communications
  • Encryption at rest: AES-256 for data stored in databases
  • Passwords: Hashed with bcrypt (never stored in plain text)
  • Access control: Principle of least privilege, multi-factor authentication for administrators
  • Monitoring: Suspicious activity detection and real-time alerts
  • Backups: Encrypted, automated, and geographically distributed backups
  • Audits: Periodic security reviews and penetration testing

Data Breach Notification

In accordance with Art. 33 GDPR, in the event of a personal data breach posing a risk to your rights and freedoms, we will notify the Spanish Data Protection Agency (AEPD) within 72 hours of becoming aware of it. If the breach entails a high risk, we will notify you directly and without undue delay in accordance with Art. 34 GDPR.

9. Minors

EntrenAI is not intended for users under 16 years of age. We do not intentionally collect personal data from minors under that age.

  • • Under 16 years: Should not use EntrenAI. We do not intentionally collect data from children under 16.
  • • Between 16 and 18 years: May use EntrenAI with the knowledge and consent of their parents or legal guardians.

If you are a parent or guardian and discover that a child under 16 has provided us with personal data without your consent, contact privacidad@entrenai.app immediately and we will delete that information.

10. Artificial Intelligence and Automated Decisions

EntrenAI uses artificial intelligence to generate and adapt training plans. It is important that you understand how it works and its limitations:

What does our AI do?

  • • Analyzes your profile, training history, and daily feedback
  • • Generates personalized plans adapted to your goals and availability
  • • Automatically adjusts volume, intensity, and exercise selection
  • • Detects fatigue or stagnation patterns to propose changes

⚠️ Important limitations:

  • • AI recommendations are for guidance and may contain errors
  • • They do not replace advice from health professionals or certified trainers
  • • Always use your judgment and listen to your body
  • • Consult a doctor before starting any exercise program

You have the right to request human intervention in decisions that significantly affect you, express your point of view, and contest the decision by contacting info@entrenai.app.

11. Changes to this Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify you of significant changes through:

  • Push or in-app notification at least 30 days before taking effect
  • Email to the address associated with your account
  • Prominent banner on our website

Continued use of the service after the changes take effect constitutes your acceptance of the updated policy.

12. Contact

For any questions about this policy, exercising your rights, or reporting privacy incidents:

We are committed to responding to your inquiries as soon as possible and always within the legally established timeframe.