SwolverSwole, solved.Get the app

Privacy

Short version: the free tools on this site work with no account and store nothing about you. An account stores your email address, your settings and the training you log, and you can download or delete all of it yourself, immediately.

Using the site without an account

Nothing you type by hand is stored. The manual pages let you pick lifts or type in a few recent sessions and read a diagnosis on the spot. What you enter is processed in memory to produce it and then discarded. We do not save the lifts you picked, the sessions you typed, or anything else about them. This does not change when you have an account.

Exercise names we could not recognize. We keep a list of exercise names we could not match to our catalog: each name, one example of how it was written, and which app it came from, with no account, IP address, or upload attached to it. We also kept the corrections people made to our guesses, stored the same way. They came from exports people uploaded while the website still accepted them. Nothing adds to them now: this website no longer takes uploads, and when the app imports your history, a name it cannot match becomes a lift you added on your own account, described below, and never goes on this list. They are not linked to anyone or to each other, and they are what teaches Swolver to recognize a name. Corrections are deleted after 180 days; the unrecognized names themselves are kept, because they are the vocabulary list.

Those names are matched by an AI model. Once a night, the unrecognized names, just the names and nothing else, are sent to Anthropic's API to be matched against our exercise catalog. Nothing that could identify a person goes with them, because nothing that could identify a person was stored with them.

What an account stores

Your email address. That is the account. There is no password: signing in means we email you a single-use code for the app, and a link that does the same on this website, which expire in an hour, so there is no password to store, leak or reset. Your address is held by Supabase, which runs our database and sends those emails.

Your settings. Eleven of them: what you are training for, how measurements are shown, your rest timer, your bar and plates, the app's colors, how experienced you say you are, when the app asks how hard a set felt, whether effort shows as reps left or as rpe, how many days a week you aim to train, which day your week starts on, and whether you help improve the coach. With Pro, it also keeps up to five themes you made, each with its name, its colors, and when you made and last changed it. With the settings, five dates: when the account was created, when your settings last changed, when your current goal was set, when you answered or skipped the first-launch questions, and when you last changed which day your week starts on. Each time you change your goal we also record the new goal and the date, so there is a history of what you were training for and when. If you change which day your week starts on after building up a streak, we also keep the length of that streak so it carries across the change instead of resetting. The account row also still holds four fields left over from earlier versions of the app: a template name, a height, a body weight and the date of that weight. Nothing in the app reads or writes any of them, so they are empty for every account, and they are in your download because the download is everything on the row.

Helping improve the coach. Swolver's coach runs on written rules. To check and tune those rules, for example how soon the watchlist should flag a lift, we may count what happened across many lifters' logs: how often a rule fired, and what came next. We only ever look at totals across at least 20 lifters. We never look at, export or share one person's training, and nothing is sold.

We don't count anything yet. When we start, it will use the training already in your account, not a copy. Turn off Help improve the coach in Settings to be left out of every count, including ones already planned. Deleting your account removes your training from all of them.

The time zone your phone reports. The app saves the time zone name your phone reports, like America/Chicago, by itself. There is no setting for it, and that is deliberate: a setting would go stale the moment you travel, and a wrong one would put your check-back dates on the wrong day. It is here so the dates we work out for you, like the day a check-back is due or the day you set a goal, land on your day rather than on a server's. A zone name is a region that keeps the same clock, so it narrows you to a country and sometimes to a part of one. It is not your location: no coordinates, no address, and usually not even a city, because one zone covers many. Only the current one is kept. A new one replaces it, and we keep no list of the zones you have been in, so it is not a record of where you have traveled. It is in your download, and it goes when the account goes, like everything else here.

Your training history. When you log while signed in, we store what you log. For each session: when it started and finished, when it was last changed, its name if it has one, which program day it was if you follow a program, which of your routines you started it from if you did, the tags you give it, and the note you write for the day. The routine is kept as that routine's id, so a lift that has a rep range in a routine keeps its own weight history in that routine, and the id is only ever matched against your own routines. A tag you make up yourself is stored as the words you typed. For each set: the lift, the weight, the reps, whether it was a warm-up, a drop set or taken to failure, and when you ticked it. After a set, you can also say how many more reps you say you could have done; it is kept with the set, shown back as reps left or as rpe depending on your setting, and nothing is stored if you skip it. A note you write on a lift is stored with that session. A lift you add yourself is stored with its name, its movement pattern, its equipment and the muscles you picked. A routine you save is stored with its name, its list of lifts and set counts, the rep range or exact number you set for a lift in it, and which lifts are done together as supersets. A split you make is stored with its name, whether it runs on fixed days or in a rolling order, which of your routines sits on which day or in which place in the order, and the rest days in it. It points at your routines by their ids, matched only against your own routines. For the one you make active, we store when you made it active. If you follow a program, we store which one, the day you started it, the day you stopped, and the training maxes it runs on. If you undo a change a program made, we store a short key naming that change, built from the lift, the kind of change and its date, so every phone you use agrees it was undone. If you change how long a lift rests, that length is stored against the lift. A target you set for a lift is stored with its weight, its reps and the day you set it. A weigh-in you log is stored with its date and weight; we do not work out a BMI or any other score from it.

Importing from another app. The app can bring your history over from a Strong, Hevy, Fitbod or JEFIT export. The file is read on your phone and is not uploaded or kept. What it holds is sent to us as sessions, sets, notes and lifts you added, and stored like anything you log.

If you have Pro. Pro is not on sale yet, and a few accounts have early access to it. For accounts with Pro only, two more kinds of record are kept, and every other account stores neither. When a stalled lift is given a change to try, we store the lift, the likely cause, the change, the number the lift needs to beat, the date to check by, and later whether it worked. When you start a plan around something that hurts, we store which joint it is for (shoulder, elbow, wrist, low back, hip or knee), the day it started, the day its swaps run until, the day it ended, and your answer at each check-in: better, the same or worse, or whether it hurt, with the 0 to 10 number if you gave one. That is a record about pain, so it is worth saying plainly: it is stored only because you started the plan, it is in your download, and it goes when you clear your training history or delete the account.

Something Hurts, and what it does not keep. Something Hurts is not medical advice, and the free part of it stores nothing about what hurts: picking a joint or a muscle shows which lifts load it and what to swap, and only the lifts you then log are stored, like any others. Before it offers a plan, it asks a few yes or no questions, about things like sharp pain, numbness or swelling. Your answers are used on the spot and then forgotten: they are never written to your phone's storage and never sent to us.

If you buy Pro. When Pro goes on sale, you buy it in the app through Google Play, which takes the payment, and RevenueCat, a service that keeps track of app subscriptions for us, passes Google Play's messages about the purchase on to our server. Both keep their own records of the purchase, under their own privacy policies. The account keeps a record of what it holds: that it has Pro, the store's name for the plan, when the current period ends, whether it will renew, and when it was refunded if it was. It also keeps the store's reference for the last message it sent about the purchase, and when, and when the record was made and last changed. The record is written from the store's messages, never from the phone, and Swolver never sees your card. It is in your download. Clearing your training history and restoring a download leave it alone. Deleting the account deletes it. When you open the Pro purchase screen, or buy, restore or manage Pro, the app talks to RevenueCat directly and names your account by its account id, never your email address, so a purchase lands on the right account.

Tied to your account. Every one of these records is stored against your account, and the database's own access rules let a signed-in account read or change only its own records.

Deleting part of it. Deleting a set or a session in the log removes it from the database as soon as the delete reaches us. It is not flagged or hidden. Clearing a note removes it the same way, and so does deleting a routine or a weigh-in. A session you did from a routine you later delete still records that routine's id, which then matches nothing, and it goes when the session does. Deleting a split removes it the same way, and so does removing a target. A split that names a routine you delete no longer offers it: that day, or that place in its order, reads as a rest day instead, the same way a deleted routine's id on a session matches nothing. Lifts you added, undone program changes, check-backs and plans around what hurts have no delete control of their own; clearing your training history removes them, and so does deleting the account. Rest lengths and your goal history go only when the account does.

Clearing your training history. In the app, Settings, then Your data, has Clear training history, behind the word clear. It deletes every session, set and note, every program you followed, every undone program change, check-back and plan around what hurts, the same way a delete does. You choose whether it also takes your routines (and with them your splits), your splits, your targets, your weigh-ins and the lifts you added. It leaves your email address, your settings, your goal history, your rest lengths and any purchase record. There is no undo, other than restoring a download you made before.

How long. Until you delete it, or delete the account. We do not expire accounts or training history, and we keep no copy afterward beyond the database backups described under Deleting your account.

Never sold, never shared. Your email address is not sold, rented, or handed to advertisers. It is used for signing you in, and for one thing more: our server compares it with two short lists it keeps in its own settings, of the addresses given early access to Pro and of the addresses shown Pro for sale before everyone else. Those lists are kept apart from the database, so deleting an account does not by itself take an address off them. Your training history is not sold, rented, or handed to advertisers either.

Taking your data with you

One file, on demand. Settings has a download control that gives you everything this account holds, as JSON: your email address, your account id, when the account was created and when you last signed in, your settings, your goal history, and your training history, meaning every session, set, note, lift you added, routine, split, program you followed, program change you undid, rest length you set, target, weigh-in, and, if you have Pro, check-backs and plans around what hurts. It also includes what the account holds if you have bought anything. It is built from your own account and nothing else.

Restoring from that file. Restoring happens in the app now, not on this website. The file is read on your device and is not uploaded or kept; its rows are sent to us in batches, checked the same way as anything you log, and added to your account, where they are kept like anything you logged. A restore never writes over what the account already has. If the file came from this same account, anything in it you have deleted since is listed first, and only what you choose comes back.

If it is ever too big. One file holds up to 200,000 records of each kind, far more than years of daily training. If your history ever goes past that, the file says it was cut short rather than leaving records out without saying so.

Deleting your account

Immediate and irreversible. Settings has a delete control, in the app under Your data, and on this website once you sign in. It asks you to type the word delete, and then the account record and everything attached to it is deleted from the database on the spot. Not flagged, not hidden, not queued. There is no undo. Deleting from the app also signs that phone out, which deletes the app's copy of your log from it. Supabase, which runs our database, keeps backups of the whole database, so a copy of a deleted account can remain in those backups for up to 7 days before they are replaced. Signing in again with the same address gives you a new, empty account.

What deletion does not touch is the anonymous exercise-name records above, because they were never connected to your account and there is nothing in them to connect. They contain no address, no identifier, and nothing from your workouts beyond an exercise name. Nor does it reach records other services keep themselves: Google Play's and RevenueCat's records of a purchase, and email you sent us.

Export first, if you want a copy. Deleting the account deletes your training history with it, and once it is gone there is nothing left to download. The download control in Settings, described above, gives you a copy to keep.

The app on your phone

What it keeps on the phone. A copy of your log, so the app works with no signal; the changes still waiting to reach us; and the session you have open. They sit in the app's own storage, which other apps cannot read. Your sign-in is kept encrypted, with its key in the phone's secure keystore. The app also remembers a few choices about what its screens show: which Pro features you turned off, cards you closed or hid, today's pick for your next session, the start of a lighter week, and program changes you undid. It also remembers whether you turned off crash reports. And it remembers the address the last sign-in code went to, and when, so the countdown to asking for another survives a trip to your email app.

What signing out clears. Signing out deletes the copy of your log, the waiting changes and the open session from the phone, and ends that phone's sign-in. The screen choices, the crash-report choice and the address the last code went to stay on the phone until the app is uninstalled or its storage is cleared. The app turns off Android's backup of its storage, so none of this goes into your Google account's backup. If you have Pro and add the Swolver widget to your home screen, the app keeps a short summary for it on the phone: this week's sessions against your goal, and your next session. It never leaves the phone, and signing out clears it.

Notifications. The rest timer's alert is scheduled on the phone itself. There is no push service: no notification token is made, and none is sent to anyone.

App updates. When the app starts, and when you come back to it, it asks Expo, the service that delivers its updates, whether there is a new version. That check sends which version of the app you have, which update it is running, and a random id the update system made up when the app was installed. The id is not your account, your email address or anything about your phone's hardware. If the app failed to start the last time, the check also sends the error message, so a bad update can be pulled.

Crash reports. When the app crashes, or hits an error it cannot recover from, it sends a report to Sentry, a crash reporting service, so we can fix it. A report holds the error and where in the app's code it happened, the app version and update, your phone's model and Android version, a random id Sentry's code makes up when the app is installed, and the names of the last few screens you opened. It never holds your IP address, your email address, your account id, your training data, your notes, or anything from Something Hurts, and Sentry is set not to store your IP address. Reports are kept in Sentry's United States data region for about 30 days, then deleted. Nothing is sent unless something goes wrong, and nothing at all if you turn off Send crash reports in Settings, under Privacy. It is on until you do, and turning it off stops crash reports at once, on that phone.

Where the app connects. Our own server, for everything you log; Supabase, for signing in; Expo, for updates; Sentry, for crash reports; and RevenueCat, with Google Play, when you open the Pro purchase screen or buy, restore or manage Pro. Nothing else. The app has no analytics and no advertising.

Reporting a problem. A report you send from Settings always includes what you typed. If "Include app details" stays ticked, which it is by default, it also carries your app version and update id, your phone's model and Android version, your theme, and a short in-memory list of the screens you visited and any app errors, each with a time. It never carries your training data, your notes, or anything from Something Hurts. You can also attach one screenshot. The app shrinks it and saves it again as a new picture on your phone before it is sent, which leaves out where and with what camera it was taken, and it goes only with that report. It is kept privately with the report, never at a public web address, and attached to the email to our support mailbox. Nothing leaves the phone until you tap Send, and once it has, nobody, including you, can read it back through the app. A sent report is kept with your account and emailed to our support mailbox through Resend, an email service. That email includes your email address, so we can reply, and your account id, so we can find the account. An attached screenshot is kept 30 days and then deleted automatically, and sooner if you delete your account: deleting your account deletes the kept report and its screenshot. Neither reaches the email already in our mailbox, where the emailed copy of a screenshot stays. A report is not in your download, because it is something you sent us, not your training.

Everything else

Rate limiting. To prevent abuse we count requests for one hour at a time. Most of what the app sends while you are signed in is counted against a salted, one-way hash of your account id; everything else, against a salted, one-way hash of your IP address. Requests for sign-in codes and links are counted per connection, and a code asked for from the app is also counted per email address, the address hashed the same way, so nobody can use us to flood someone else's inbox. A hash cannot be turned back into what it came from, and the counts are deleted within a day.

Cookies. Signing in sets a session cookie. It is marked HttpOnly, so page scripts cannot read it, and SameSite=Lax, so it does not travel to other sites. Asking for a sign-in link sets one more short-lived cookie, which is how the link knows it is coming back to the browser that asked for it. Those two are the only cookies we set, and there are none at all if you never sign in. Your unit preference is also remembered in your own browser's local storage, which stays on your device and is never sent to us.

What this browser might still be holding. This website no longer keeps your training on your device. If you used the logger here before phase 9, this browser may still be holding a copy of your log and changes that never reached us, left over from when it worked differently. Signing out clears all of that, along with anything the old offline support left behind. The app on your phone is where your training is kept now.

Analytics. This website uses Vercel Web Analytics, which is cookieless and does not track you across sites. There are no other trackers, and the app has none at all.

Fonts. The typefaces are served from this site, not from a font network, so loading a page here never contacts a third party.

Emailing us. If you write to our support address, your message and your email address are kept in our mailbox, which MXroute hosts, so that we can answer you.

Who else touches this. Vercel hosts the site and the server the app talks to, and provides the website's analytics. Supabase runs the database, keeps its backups, and sends sign-in emails through MXroute's mail servers. Anthropic's API matches unrecognized exercise names, as described above. Expo delivers the app's updates. Sentry receives the app's crash reports. Google Play distributes the app, and will take payment for Pro once it is on sale, with RevenueCat keeping track of the subscription for the app and passing the purchase messages on to us. MXroute also hosts our support mailbox, and Resend delivers the problem reports you send from the app to it. Nobody else, and no advertiser.

Contact. There is no way to flag an exercise name from the site now that the report and its correction control are gone. Email support@swolver.com. The controls in Settings are the way to download and delete everything an account holds.

Privacy · Swolver