Privacy policy

Last updated 29 September 2026

Who is responsible

Ironmade, the app and this website, is published by Ioannis Georgopoulos, an individual developer based in Greece, not a company, who is the controller of your data. For anything in this policy, whether a question, a copy of your data, or a request to delete it, write to ironmadeapp@gmail.com.

What is collected

Only what you type into the app, and what the app records as you use it. There is no tracking, no advertising, and no profiling.

  • Your account: email address and password. The password is stored by the authentication provider as a hash and is never visible to the developer. If you use Sign in with Apple instead, the app receives an identifier from Apple and the email address Apple shares, which may be a private relay address that forwards to you; no password is created.
  • What you tell the app during setup: name, gender, date of birth or age, height, weight, training goals, available equipment, and how often you intend to train.
  • Your training: every workout, the exercises in it, every set with its weight, reps and the time it was completed, session notes, and any custom exercises or routines you create.
  • Your food and drink: what you logged or planned, how much, which meal, and water intake.
  • Your body: weight and any other measurements you record, including ones you invent yourself, each with the date and time you give it.
  • Your preferences: units, theme, reminder days and times.
  • Referrals, only if you use or share a code: which code was used and by whom, whether that person went on to subscribe, and a one-way hash of a random identifier kept on your phone, used only to stop the same phone using more than one code. The hash cannot be turned back into anything that identifies the phone.
  • Subscription status, if you subscribe to Premium: whether your account has Premium, its period, and whether it is in a free trial, as reported by Apple. Payment details are handled entirely by Apple and are never seen by the developer.
  • Problem reports, only when you send one from Settings: what you wrote, the email you give for a reply, the app version, and your phone model and operating system version. They are stored with your account and emailed to the developer through Resend, an email delivery service.

What is not collected

The app contains no analytics, no advertising identifiers, no crash-reporting service, and no social media trackers. Your location is never requested. Your contacts, camera and microphone are never accessed, and your photo library is never read; the app only adds a workout card to it when you choose to save one.

Health data is not read from or written to Apple Health or Google Fit. Everything the app knows about your body is something you typed into it.

Where it is stored

On servers operated by Supabase, in the eu-central-1 region (Frankfurt, Germany). Supabase acts as a processor: they host the database on the developer’s behalf and do not use your data for their own purposes.

Some of it is also kept on your own phone, so the app works without a connection: a copy of what you have recently viewed, and a queue of anything you have logged that has not yet reached the server. Both are removed from the device when you log out.

Who else sees it

Your data is never sold, and there is no advertising network or data broker involved at any point. The only outside companies that handle it are the service providers that run Ironmade on the developer’s behalf, acting as processors under contracts that stop them using it for anything else: Supabase (the app’s database and sign-in), Resend (problem-report and newsletter emails), Vercel (which hosts this website), and Apple (App Store purchases and Sign in with Apple).

Access is enforced at the database itself, per row, so one account cannot read another’s data even in the event of a bug in the app.

The only exception would be a legally binding order, or a genuine need to investigate abuse or a security incident.

Transfers outside the EU

The app’s database stays in the EU (Frankfurt). Some service providers, such as Resend, Vercel and Apple, are based in the United States and may process data there. Where that happens, the transfer is protected by the safeguards EU law requires: the EU-US Data Privacy Framework where the provider is certified under it, or the European Commission’s Standard Contractual Clauses in the provider’s data processing agreement.

Why it is held

To provide the app: showing you your own training history, calculating your targets, and keeping your data available across your devices. Without it there is no product: a training log that forgets is not a training log.

For users in the EU and UK, the legal basis is the performance of the contract between you and the developer when you create an account.

How long it is kept

For as long as your account exists. Training history is deliberately not expired, because a log is worth more the longer it runs.

When your account is deleted, everything belonging to it is deleted with it: your profile, workouts, sets, meals, water, measurements, custom foods and exercises, saved routines and favourites. Deletion is immediate and permanent, and backups holding it are overwritten within 7 days.

Your rights

You can ask for a copy of your data, correct it, or have it deleted. If you are in the EU or UK you also have the right to object to processing, to restrict it, and to complain to a data protection authority. In Greece that is the Hellenic Data Protection Authority (dpa.gr).

  • A copy: Settings → Export data writes everything on your account to a file you can keep, in a readable format.
  • Correction: almost everything can be edited directly in the app.
  • Deletion: Settings → Delete account. It happens immediately and takes everything with it. There is no waiting period and no way to undo it.

Notifications

Reminders are scheduled by your own phone, not sent from a server. The app does not hold a push token and cannot send you anything remotely. Turning notifications off in your device settings stops them entirely.

This website

The website sets no cookies, uses no analytics, and loads nothing from other companies: even its fonts are served from the site itself. The only thing it stores in your browser is a note that you have closed the notice about cookies, so it is not shown again. That note never leaves your device.

Like any website, the servers that deliver it briefly record technical details such as your IP address, browser and the pages requested, to send you the site and keep it secure. These logs are kept by Vercel, the hosting provider, only for as long as that needs and are not used to identify or track you. The legal basis is the developer’s legitimate interest in running a working, secure website.

Newsletter

If you sign up on the website, your email address is used only to send you Ironmade launch news and occasional updates. You are added only after you confirm the address from the email we send you, and nothing else is asked for.

The list is held by Resend, the email service that sends it, acting as a processor on the developer’s behalf. The legal basis is your consent, which you can withdraw at any time: every email has an unsubscribe link, and you can also write to the address above.

Your address is kept until you unsubscribe or ask for it to be deleted. It is never sold, shared, or used for advertising.

To stop spam and abuse, sign-up attempts are counted using a scrambled, one-way form (a keyed hash) of your IP address and email address, which cannot be turned back into either. These records are deleted automatically after 48 hours.

Children

The app is not intended for anyone under 16, and accounts should not be created for them. If you believe a child has created an account, write to the address above and it will be removed.

Changes

This policy will change as Ironmade does. Material changes will be shown in the app and on this page before they take effect. Last updated 29 September 2026.