Privacy Policy
Version 3 — Last updated: 6 September 2026
Durata ("we", "our", or "us") is a training log. This policy explains what we collect, why we collect it, where it goes, who else touches it, and what you can require us to do about it. It covers the Durata app on iOS, Android and the web, and this website.
1. Who We Are
Durata is operated by Jamie Blakeney, based in the United Kingdom. We are the data controller for the personal data described below.
You can reach us at [email protected], or by post at:
Jamie Blakeney
5 Springers Close
Devizes
Wiltshire SN10 3SG
United Kingdom
2. Data We Collect
When you use Durata, we collect:
- Account — your email address. Sign-in is passwordless: a one-time 6-digit code sent to your email. Authentication is handled by Supabase Auth — we never see or store a password.
- Workout & fitness data — exercises, sets, reps, weights, body metrics, nutrition, cardio, sleep, goals and timestamps you log. Under UK and EU data protection law this is health data, a special category that gets extra protection. We treat it accordingly.
- Progress photos — if you add them, they are stored on your device only. They are never uploaded to our servers, never included in a cloud sync, and never sent to any third party. If you delete the app without exporting them, they are gone.
- Photos and documents you import — separate from progress photos. If you use Import a Session, the images or PDF pages you choose are sent to Anthropic so the routine in them can be read back as exercises and sets. This happens only when you start an import, only with the pages you select, and only for as long as that request takes. See section 4.
- Settings you sync — your preferences, units, gyms, equipment and any third-party connection keys you have entered (see section 6). These sync with your account so a second device behaves like the first.
- Purchase status — whether you hold a Durata Pro entitlement, and the store transaction it came from, via RevenueCat. We never see or store your card details; payment is handled entirely by Apple or Google.
- Diagnostics — if the app hits an error we collect crash data (error details, app version, browser/OS) via Sentry to fix bugs. Sentry is configured not to attach personal data to reports.
- Usage analytics — in-app events (which screens and features you open, and counts) via PostHog, so we can tell what is used and what is ignored. These events are pseudonymous, not anonymous: once you sign in they are tied to your account ID, so we can tell one person's session apart from another's. They contain no workout content — no exercises, weights, reps, photos or body metrics — and they are never used for advertising. Session recording and automatic event capture are switched off.
We do not collect precise location, we do not use advertising identifiers, and we do not run ads, tracking pixels or third-party marketing tags anywhere in the app or on this site.
3. Why We Use It, and Our Legal Basis
Under UK GDPR we need a lawful basis for each purpose. Ours are:
- Running your account and syncing your data across devices — necessary to perform our contract with you (Article 6(1)(b)).
- Storing and displaying your health and fitness data — because workout logs, body metrics, sleep and nutrition are special category health data, we rely on your explicit consent (Article 9(2)(a)), which you give when you accept this policy and start logging. You can withdraw it at any time by deleting your account, which erases the data.
- Sending sign-in codes and essential account emails — performance of our contract.
- Reading a photo or document you ask us to import — performance of our contract, on your specific instruction each time.
- Diagnosing crashes and improving the app — our legitimate interest in a product that works (Article 6(1)(f)). You can object; see section 10.
- Confirming whether you hold a Pro entitlement — performance of our contract.
We do not sell or rent your data, and we do not share it with third parties for their own marketing.
4. Where Your Data Is Stored, and Who Processes It
Your account and synced fitness data (workouts, body metrics, nutrition, cardio, sleep, routines, goals and settings) live in a single Supabase project — a managed PostgreSQL platform. Data is not routed to different regions for different users; everyone's account is in that one project. Supabase is SOC 2 Type II compliant.
The other companies that process data on our behalf:
- Cloudflare — hosts this website and the app, and runs the import endpoint. Request metadata including your IP address is processed there, partly to rate-limit abuse of that endpoint. Exercise demonstration videos and stills are served from a separate Cloudflare bucket at
videos.dropsetapp.com, which still carries our former brand name; it is our own storage, not a third party's. - Anthropic — receives the images or PDF pages you submit through Import a Session, and returns the routine it reads in them. It receives only what you select for that import. It is not sent your workout history, your account email or your other data, and imports are not used to train models. We keep a counter of how many imports you have run, to enforce fair-use limits; we do not keep the images.
- RevenueCat — manages Pro purchases and entitlements across the App Store and Google Play. It receives your account ID and your purchase history for that purpose.
- Sentry — crash diagnostics.
- PostHog — product analytics, on its EU-hosted service.
- Resend — delivers sign-in code emails and essential account emails.
Some of these process data outside the UK. Where they do, the transfer is covered by the UK International Data Transfer Addendum or the EU Standard Contractual Clauses under each provider's data processing agreement.
Their policies: Supabase, Cloudflare, Anthropic, RevenueCat, Sentry, PostHog, Resend.
5. Apple Health and Health Connect
If you connect Apple Health (iOS) or Health Connect (Android), Durata reads only. It has no write permission and never sends anything back to those platforms.
With your permission it reads: workouts, weight, body fat, steps, heart rate, resting heart rate, heart rate variability, sleep, nutrition and hydration.
What you import is then treated like anything else you log. A weight reading from Apple Health is saved to your body metrics, a sleep session to your sleep log, and so on — which means it is stored in your Durata account and synced to your other devices in the same way as a workout you type in by hand. It does not stay on the device. We think that is what you want from a training log that syncs, but you should know it before you grant the permission.
Health platform data is never used for advertising or marketing, is never sold, and is never shared with third parties other than the processors in section 4 who store it on our behalf. You can revoke the permission at any time in Apple Health or Health Connect; Durata stops reading immediately, and anything already imported stays in your log until you delete it or delete your account.
6. Connections You Choose
Durata can send your workouts to Hevy if you connect it. This is off unless you turn it on, and it has three settings: off, private, or public.
- Private sends the workout to your Hevy account only.
- Public posts it to your Hevy feed, where other Hevy users can see it. Once posted, that workout is governed by Hevy's terms and privacy policy, not ours, and we cannot take it back for you.
To connect Hevy you paste in a Hevy API key. That key is stored in your synced settings, which means it is held on our servers so the connection follows your account to a new device. It is only ever used to talk to Hevy on your behalf. You can clear it at any time by disconnecting Hevy in Settings, and deleting your account deletes it along with the rest of your settings.
7. Purchases
Durata Pro is sold through the App Store and Google Play. We never receive your card or payment details — those go to Apple or Google and stay there. We receive only the fact of a purchase and the entitlement it grants, through RevenueCat. Billing terms are in our Terms of Service.
8. Data Retention
Your data is kept for as long as your account is active. If an account is not signed into for 24 months, we will contact you at your registered address and then delete the account and its data if we get no response.
You may delete your account and all associated data at any time from within the app (More → Settings → Account → Delete Account), or by emailing [email protected]. See Delete Your Account & Data for step-by-step instructions.
Deletion removes your data from our live database immediately and irreversibly. Encrypted backups of that database are kept on a rolling basis and residual copies of a deleted record age out of them within 30 days; they are not accessible to the app and are never used to restore an individual account.
9. Cookies and Local Storage
On this website. We set no cookies and store nothing on your device. There are no analytics tags, no tracking pixels and no third-party scripts, which is why you have not been asked to dismiss a consent banner. Nothing follows you between visits or across other sites.
In the app. Durata uses your browser's or device's localStorage to hold your sign-in session, your preferences, and the pseudonymous analytics identifier described in section 2. This is storage the app needs to work, not advertising storage. Clearing it signs you out; your data is safe in your account.
10. Your Rights
If you are in the UK or the EU you have the right to:
- Access your data, and get a copy of it.
- Correct anything inaccurate — most of it you can edit directly in the app.
- Delete your data. The in-app Delete Account button does this in full; see section 8.
- Port your data. You do not need to ask us: More → Settings → Backup produces a complete JSON file of everything you have logged, on demand.
- Object to or restrict processing we carry out under legitimate interests, which means crash diagnostics and product analytics.
- Withdraw consent for us to hold your health data. Withdrawing it means deleting your account, because that data is the service.
To exercise any of these, email [email protected]. We will respond within one month.
If you think we have handled your data badly, please tell us first so we can fix it. You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office — ico.org.uk/make-a-complaint, or 0303 123 1113. If you are in the EU you may complain to your own national supervisory authority.
11. Children's Privacy
Durata is not directed at children. You must be at least 13 to use it, or older if the country you live in sets a higher minimum age for consenting to online services without a parent — several EU countries set 16. We do not knowingly collect data from anyone below that age. If you believe a child has provided us data, contact us and we will delete it promptly.
12. Changes to This Policy
We may update this policy. Each version is numbered, and the number at the top of this page is the current one. For material changes — a new category of data, a new processor, or a new purpose — the app will ask you to review and accept the new version before you continue. Other changes take effect when published.
13. Contact
Questions about this policy, or about anything in it you think is wrong? Email us at [email protected].