Bazzinotrain with intent

Privacy Policy

Effective 31 August 2026. This policy explains what Bazzino collects, why, and the control you have over it.

The short version

  • We collect only what the app needs to work: your account, the body measurements you enter, and the workouts you log.
  • Your weight and height are health data. We process them only with your explicit consent, which you give during onboarding and can withdraw at any time.
  • Your data is stored in the European Union (Frankfurt, Germany). We do not sell it, and we do not use advertising or third-party tracking.
  • You can export everything as a file or delete your account and all its data from inside the app, at any time.

1. Who we are

Bazzino (“Bazzino”, “we”, “us”) is a workout and nutrition web app. For the purposes of the EU General Data Protection Regulation (GDPR), we are the data controller for the personal data described here. You can reach us about privacy at privacy@bazzino.com.

2. Information we collect

We collect only the following, and only from you:

  • Account information. Your email address, and a display name if you provide one. If you sign in with Google, we receive your email address and basic profile from Google to create your account; we never receive your Google password. Passwords for email accounts are handled by our authentication provider and are never visible to us.
  • Health and biometric data. The body measurements you enter (weight and height) and the unit preferences and derived figures (such as BMI and BMR) that follow from them. Under the GDPR this is a special category of personal data, so it gets the extra protection described in section 4.
  • Training data. The routines you build and the workouts you log: exercises, sets, weights, reps and timestamps.
  • Consent records. A timestamped record of the consents you give (for example, to process your health data), kept as proof that consent was obtained.
  • Technical data. A session cookie that keeps you signed in, and standard server logs needed to run and secure the service. We do not build advertising or tracking profiles.

Some of this data is also cached on your own device so the app works offline. That copy stays on your device and is cleared when you sign out or clear your browser storage.

3. How and why we use your data

  • To provide the core service: create and secure your account, calculate BMI and BMR, and store the routines and workouts you log.
  • To show you your own progress over time, such as your recent workouts and per-exercise history.
  • To keep the service secure, prevent abuse, and diagnose faults.
  • To meet legal obligations, such as keeping proof of consent.

We do not use your data for advertising, we do not sell or rent it, and we do not use it to make decisions about you by automated means with legal or similarly significant effects. We also do not use your personal or health data to train artificial intelligence or machine-learning models.

4. Health data and your explicit consent

Weight, height and the figures derived from them are health data. We rely on your explicit consent (GDPR Article 9(2)(a)) to process them. We ask for that consent, separately and clearly, during onboarding, and we record when you gave it.

You can withdraw consent at any time by deleting the data or your account from within the app (see section 8). Withdrawing consent does not affect processing that already took place while consent was valid.

5. Legal bases

Depending on the data, we rely on:

  • Your explicit consent: for health and biometric data (Article 9(2)(a)).
  • Performance of a contract: togive you the account and service you asked for (Article 6(1)(b)).
  • Our legitimate interests: tokeep the service secure and working, balanced against your rights (Article 6(1)(f)).
  • Legal obligation: where the law requires us to keep records (Article 6(1)(c)).

6. Who we share data with

We share data only with the service providers (“processors”) that run the app for us, under contracts that require them to protect it and use it only on our instructions:

  • Supabase: database, authentication and storage. Your data is hosted in the EU (Frankfurt, Germany).
  • Vercel: application hosting. The app’s server functions run in the EU (Frankfurt) region, next to the database.
  • Google: only if you choose to sign in with Google, and only for that sign-in.

We do not sell your personal data or share it with advertisers. We may disclose data if the law requires it, or to protect the rights and safety of our users and the service.

7. Where your data is stored

Your personal data is stored and processed in the European Union (Frankfurt, Germany). If that ever changes, or if a provider needs to transfer data outside the EU, we will use a lawful transfer mechanism and update this policy.

One exception is already in place: if you choose to sign in with Google, that authentication is handled by Google and may involve processing outside the EU under Google’s own safeguards (such as the EU Standard Contractual Clauses and the EU-US Data Privacy Framework).

8. Your rights

Under the GDPR you have the right to access your data, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent. To make this practical, the app gives you two of these directly:

  • Export: download a machine-readable copy of your account, measurements, consents and routines from your profile page (right to data portability, Article 20).
  • Delete: permanently delete your account and all associated data from your profile page. This cascade is irreversible (right to erasure, Article 17).

For anything else, contact us at privacy@bazzino.com. You also have the right to lodge a complaint with your local data protection authority.

9. How long we keep it

We keep your data for as long as your account exists. When you delete your account, your personal data (including your health data) is removed from the live database immediately, and cycled out of any encrypted backups within 30 days. Limited technical logs that may contain an identifier are retained for security for up to 30 days before being rotated out.

10. Security and data breaches

Access to your data is enforced at the database itself: row-level security means one account cannot read another’s data, even if application code were flawed. Connections are encrypted in transit, and we follow the principle of least privilege for the systems that touch your data. No system is perfectly secure, but we design so that a single mistake does not expose your information.

If a personal-data breach ever occurs that is likely to put your rights at risk, we will notify the relevant supervisory authority without undue delay and within 72 hours where the GDPR requires it, and we will tell affected users directly when the risk to them is high.

11. Cookies and on-device storage

We use a small number of essential cookies to keep you signed in and to run the service. We do not use advertising or analytics cookies, so no consent banner for tracking is required. The app also stores some of your data in your browser so it works offline; that copy lives only on your device.

12. Children

Bazzino is not directed at children. You must be at least 16 years old to create an account. If you believe a child has given us personal data, contact us and we will delete it.

13. Changes to this policy

We may update this policy as the service evolves. We will change the effective date at the top and, for significant changes, give notice in the app. Continued use after a change means you accept the updated policy.

14. Contact

Questions or requests about your data: privacy@bazzino.com.