1. Who we are
The controller of your personal data is Edward Baltaza (sole proprietorship), NIP 8212577665, ul. Lindleya 16, 02-013 Warsaw, Poland — trading as Swimlog. You can reach us about anything in this policy at edward@swimlog.dev.
"Swimlog", "we", "us" and "our" mean the controller above. "App" means the Swimlog mobile application for iOS and Android. "You" means the person using the App.
2. The data we process
What we hold depends on how you use the App:
- Account & identity. Your email address and either a password or Sign in with Apple (handled by our authentication provider — we never see or store your password ourselves), plus a unique account identifier. This is required to create an account and sign in.
- Swimmer profile. Your @handle, display name and initials, preferred stroke, pool preferences, weekly distance target, display units, your primary event, an optional profile photo you choose to add (or a generated avatar), and your account start date.
- Training data. The workouts, sets, intervals, effort/RPE, equipment and notes you log; your personal bests; and the meets and results you plan and record.
- Apple Health pool-swim data. If you explicitly connect Apple Health on iPhone, Swimlog reads compatible pool-swim workouts from HealthKit: distance, duration, pool length, lap and pause timing, stroke style, workout date and timezone, and the source/device that recorded the swim. We do not read heart rate, calories, routes or open-water workouts, and we never write to Apple Health. Imported swims are copied into your Swimlog training log and synced to your account like workouts you enter yourself.
- Whiteboard scans. If you use the whiteboard scan, the photo you take or pick is sent — downscaled and with location metadata removed — to our AI scan provider (see §8), read into workout text and returned. We never store your scan photos; we keep only a daily count of scans on your account to enforce the fair-use limit.
- Purchase & subscription status. Which Swimlog Pro plan you hold and whether it's active, trialling or expired — received from Apple (or Google) via our subscription-management provider (see §8) and tied to your account identifier. We never receive or store your payment card details; the store processes all payments.
- Teams data. If you create or join a team: the team name and join code, membership and role, and the training summaries you contribute to that team as a member (see §7).
- Diagnostics & usage data. To fix bugs and improve the App, we collect crash and performance reports and a small set of product-usage events — which screens and actions you use (for example opening capture, saving a workout, sharing a card), never the content you type — along with basic device and app details (model, OS and app version). This is described in §3.
- On-device preferences. Settings such as your theme, notification opt-ins and onboarding state. These live only on your device and are not sent to us.
- Support messages. If you email us, we keep the message and your contact details so we can help and keep a record of the request.
- Limited technical data. When cloud sync is on, our backend processes the standard connection data needed to operate and secure a network service (such as IP address and timestamps in server logs).
3. Analytics & diagnostics (to improve the App)
To find and fix crashes and understand what to improve, the App sends a limited amount of first-party diagnostic and usage data to two privacy-focused processors. Both are configured to host data in the European Union.
- Crash & performance (Sentry). When the App errors or runs slowly, we receive a report with the technical details needed to fix it — a stack trace, device model, OS and app version — tied to your account identifier.
- Product analytics (PostHog). A small set of typed events about how the App is used — for example completing onboarding, opening capture, saving a workout, unlocking an achievement, or sharing a card — plus coarse profile attributes (your pool type, display unit, and roughly how many workouts you've logged) so we can understand the experience. Product analytics runs only in the public App Store release; it is disabled in TestFlight, development builds and simulators. We do not use session replay, automatic screen or touch capture, or feature-flag tracking, and we never capture the content you type.
We use this data only to operate, fix and improve Swimlog — never for advertising, never to build a cross-app profile of you, and we never sell it. Our lawful basis is our legitimate interest in a reliable, well-made app (Art. 6(1)(f) GDPR). You can object at any time — just email edward@swimlog.dev and we'll stop processing your diagnostics/usage data and delete what's tied to your account.
Apple Health workout details are never sent to Sentry or PostHog. We record only aggregate import counts and closed error categories, with no HealthKit identifiers, dates, distances, durations, lap times or stroke details.
4. What we do not do
Beyond the diagnostics in §3, we've kept Swimlog deliberately quiet:
- No advertising, no ad networks, and no ad SDKs.
- No advertising identifiers and no cross-app tracking. We don't access the IDFA/GAID, we don't build a profile of you across other apps or websites, and we show no App Tracking Transparency prompt because we don't do that kind of tracking.
- We never sell or rent your personal data, and we never share it for advertising or with data brokers.
- Apple Health data is never used for advertising or marketing. It is used only to provide the pool-swim import and the Swimlog training features you choose to use.
- We don't read your content for analytics. Your workout notes, PB notes and meet names are never sent to our analytics tools.
- Notifications stay on your device. The optional weekly digest and streak reminders are scheduled locally by your phone; their content is generated on-device and nothing is sent to a push server.
5. Local-first storage & cloud sync
Swimlog is local-first: your training data is written to a private database on your device and the App works fully offline.
- Cloud sync is part of the service. Your profile, workouts, personal bests and meets are mirrored to your account on our backend in the background, so they're backed up and available on your other devices. Every save still lands on your device first, and the App keeps working with no connection.
- Team features are online. Because teams are shared by nature, team data is always handled by our backend when you use them.
- Apple Health import is optional. Connecting it imports up to 30 days of compatible pool swims, then checks for new swims when you open the App. Disabling the connection or revoking Health access stops future imports. Workouts already copied into Swimlog remain in your account until you delete those workouts or delete your account.
The diagnostic and usage data in §3 is separate — it helps us fix and improve the App — and never includes your training content. If you don't want your training data stored on our backend, you can delete your account at any time (§12), which removes it from our servers.
6. Why we process it (legal bases)
Where the GDPR applies, we rely on:
- Performance of a contract (Art. 6(1)(b)). Creating and running your account, providing the App's features, syncing your data when enabled, keeping workouts you ask us to add to your training log, and supporting you.
- Consent (Art. 6(1)(a), and Art. 9(2)(a) where applicable). Accessing Apple Health is off by default and begins only after you connect it and approve HealthKit access. You can withdraw access at any time in Swimlog or iPhone Settings; this stops future HealthKit collection without affecting the lawfulness of processing before withdrawal.
- Legitimate interests (Art. 6(1)(f)). Keeping the service secure, preventing abuse, maintaining reliability, and the diagnostics and analytics in §3 (fixing crashes and improving the App). You can object to the §3 processing at any time.
- Legal obligations (Art. 6(1)(c)). Complying with applicable law, including responding to valid requests.
The optional "sex" field is processed on the basis of your choice to provide it, and team sharing on your choice to join a team.
7. Teams — what others can see
Joining a social team makes your roster identity (handle, display name, initials and avatar) and your role visible to other members of that team, along with your training: your weekly training volume on the leaderboard, your logged workouts in the team's activity feed, your personal bests on the team board, and head-to-head comparisons of your training against your teammates'. Sharing is part of what a team is — if you'd rather not share your training, don't join one (or leave it, which stops the sharing). Apple Health imports follow these same visibility rules once copied into Swimlog.
Your email address is never shown to teammates, and your meets and workout templates are never shared with a team. You can report or block any member; blocked members are hidden from your team surfaces.
Coached teams in the private iOS pilot use different sharing rules. Coaches manage your group assignments and publish practices to those groups. Staff can see that you logged a team practice and the feedback, effort or modifications you explicitly choose to share. Personal journal notes and unrelated training remain private. Coach replies are visible to team staff and the swimmer receiving them, not other swimmers. Staff debrief notes are visible only to coaches. Private coaching workspaces are not shared unless a coach explicitly copies content into the team workspace.
Leaving a group removes access to its shared practices when the app next checks access. Your completed journal snapshots remain yours; later coach edits do not rewrite them. Team practices and journals sync through Supabase, with account-specific copies on your device for offline use. Coaching caches are cleared on sign-out. Practice and reply notifications follow your notification settings.
8. Service providers
We use a small number of trusted providers to run the App:
- Supabase — our backend for authentication and, when cloud sync or team features are used, for storing your synced and team data.
- Sentry — crash and performance diagnostics (§3), configured for EU hosting.
- PostHog — first-party product analytics for the public App Store release (§3), configured for EU hosting. Session replay and automatic capture are disabled.
- RevenueCat — subscription management. Receives your account identifier and purchase events from the store so the App knows whether your Swimlog Pro plan is active. Never sees your payment card details.
- Cloudflare — storage and delivery of the optional profile photo you upload. Photos are stored under your account identifier and served over our domain; they're removed when you delete your account or remove the photo.
- OpenAI — reads whiteboard-scan photos into workout text (§2). Receives only the downscaled, location-stripped photo — never your name, email or account identifier. Under OpenAI's API terms the content is not used to train their models and is retained for at most 30 days for abuse monitoring, then deleted. Processing takes place in the United States.
- Apple and Google — the App Store and Google Play distribute the App; their operating systems handle local notification scheduling and the share sheet when you choose to share a workout card. On iPhone, Apple's HealthKit framework provides the pool-swim data you explicitly authorize Swimlog to read; Apple does not receive your Swimlog account data from us through this feature.
We share only the minimum needed for these services to function, and only when the relevant feature is used. Each provider acts as our processor under a data-processing agreement.
9. International transfers
We aim to keep your data in the European Union — our analytics and diagnostics providers (Sentry, PostHog) are configured for EU hosting. Some providers process data in other countries — for example subscription management (RevenueCat) and profile-photo delivery (Cloudflare's global network). Where data is transferred outside the European Economic Area, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
10. How long we keep it
- Data synced to your account is kept while your account is active.
- Apple Health workouts copied into Swimlog are kept like other workouts until you delete them or delete your account. Disabling Apple Health stops future imports but does not remove existing copies.
- Diagnostic and usage data (crash reports and product events) is kept only as long as needed to fix and improve the App, after which it ages out or is aggregated.
- When you delete your account, we delete your data from our backend (see §12). Residual copies in routine encrypted backups age out within a limited technical window.
- Data held only on your device remains there until you delete it or uninstall the App.
- Support emails are kept only as long as needed to handle your request and our records.
11. Your rights
Subject to your location and applicable law, you have rights over your personal data. Under the GDPR (EEA/UK) these include access, rectification, erasure, restriction, objection (including to the analytics in §3), and portability, and the right to lodge a complaint with a supervisory authority — in Poland, the President of the Personal Data Protection Office (UODO).
If you are a California resident, the CCPA/CPRA gives you the right to know what we collect, to access and delete it, to correct it, and to opt out of "sale" or "sharing" of personal information — and we do not sell or share your personal information.
You can exercise most rights directly in the App (edit your profile, manage sharing, export by contacting us, or delete your account). For anything else — including objecting to diagnostics and analytics — email edward@swimlog.dev and we'll respond within the time the law requires. We won't discriminate against you for exercising a right.
12. Deleting your account & data
You can delete your account at any time inside the App, under Profile → Delete account. When you confirm:
- we permanently delete your account and your data from our backend — your profile (including any uploaded profile photo), workouts, including Apple Health imports, personal bests and meets, your team memberships, private coaching records and any social teams you own;
- your sign-in is removed so the account can no longer be used;
- scheduled notifications are cancelled; and
- all Swimlog data stored on that device is wiped.
Shared coached-team content and other swimmers' completed snapshots survive a staff member's account deletion. The departing author's account link is removed. A coached-team owner can transfer ownership before leaving; otherwise the team is archived. Your private coaching records and personal journals are deleted with your account.
Diagnostic and usage data (§3) tied to your account identifier is pseudonymous and ages out on its own; if you'd like it deleted sooner, email us and we'll remove it.
Note: ordinary sign-out does not erase the data on your device's personal logbook (so you don't lose your log by accident). Account-specific coaching caches are cleared on sign-out. If you can't access the App but want your account removed, email edward@swimlog.dev from your account address and we'll handle it.
13. Children
Swimlog is intended for swimmers who want to train with purpose. It is not directed at children under 13 (or under the minimum age of digital consent in your country, which can be up to 16 in the EEA), and we don't knowingly collect their data without the consent of a parent or guardian. If you believe a child has provided us personal data without that consent, contact us and we'll delete it.
14. Security
Data sent between the App and our backend is protected in transit with TLS, your synced data is scoped to your account, and our backend runs on managed, access-controlled infrastructure. No method of storage or transmission is perfectly secure, but we work to protect your data and keep what we hold to a minimum.
15. Changes to this policy
We may update this policy for legal or product reasons. We'll change the "last updated" date above and, for material changes, give notice in the App. Continuing to use Swimlog after an update means you accept the revised policy.
16. Contact
Questions about privacy or your data? Email edward@swimlog.dev — we read every message.