Privacy Policy
Last updated 27 July 2026
Not in force yet
Motric is in development and has no public users. These documents describe how the product actually behaves today, but they are not yet in effect: the operating company is not named below, the contact addresses are not live, and a qualified lawyer has not reviewed them. They are published so the behaviour they describe can be checked against the product.
Still to be completed: the controller’s legal entity, registered address and company number; the privacy and security contact addresses; the lead supervisory authority that follows from the place of establishment; and the governing law and venue.
The short version
Motric is a strength-training app. To do its job it holds things most apps don’t: your bodyweight, your height, your injuries, what you ate, how you slept, how sore you are, and — if you choose to add them — photographs of your body.
Under EU law most of that is health data, which gets the strictest treatment there is. We only process it because you explicitly agreed to, you can withdraw that agreement, and withdrawing it actually stops the processing.
Three things worth knowing up front:
- Your training record is stored in the European Union (Frankfurt). Photographs are placed in western Europe, which is a weaker promise — §7.
- Movi, the AI coach, is AI. What you type to Movi, plus your current training numbers, is sent to a model to generate a reply. Section 5 says what goes and where.
- A human coach you accept sees everything in your account. Nothing is shared until you accept them, and you can end it at any time.
1. Who is responsible for your data
- Controller: not yet completed
- Registered address: not yet completed
- Privacy contact: privacy@motric.app
- EU representative (Art. 27 GDPR), if required:
- Data Protection Officer (Art. 37 GDPR), if required:
Services: the app at fit.everfast.dev, the site at
marketing-fit.everfast.dev, and the Motric mobile apps.
2. What we collect, why, and on what legal basis
2.1 Account and sign-in
| What | Why | Legal basis |
|---|---|---|
| Name, email address, whether your email is verified, profile image | To create and identify your account | Art. 6(1)(b) — performance of the contract |
| Sign-in credentials and verification tokens | To authenticate you and confirm it’s you | Art. 6(1)(b) |
| Sign-in session records, including IP address and browser/device type | To keep you signed in and let you end sessions | Art. 6(1)(b), and Art. 6(1)(f) legitimate interest in account security |
2.2 Your training profile — health data
Your goal, experience level, how many days a week you train and which ones, priority muscles, your gyms and their equipment, exercises you or your coach create, your units and whether AI memory is on. Plus:
- bodyweight and height, and limb-proportion measurements;
- mobility limitations and injury flags;
- sex at birth and birth year (used to work out your calorie maintenance; your age is calculated when needed, not stored);
- gentle mode, set when our eating-disorder screen triggers (§10).
Purpose: to generate your training programme.
Legal basis: Art. 6(1)(b) and — because this is data concerning health — Art. 9(2)(a) GDPR, your explicit consent. to confirm the Art. 9(2)(a) route and the granularity of the consent flow.
2.3 Your training log — health data
Every session you schedule and perform; every set, with the exercise, weight, reps and reps-in-reserve, whether it was a warm-up, and if you swapped an exercise, what you swapped from and why (including “discomfort”). Your bodyweight over time, body-site measurements (waist, hip, chest, arm, thigh and so on), and your check-ins: soreness, sleep, energy.
Purpose: progression, load suggestions, deload decisions, and your progress charts. Legal basis: Art. 6(1)(b) + Art. 9(2)(a).
2.4 Diet — health data
Your maintenance and target calories, your protein/fat/carb targets and deficit, your food preferences and dislikes, your budget and effort preferences, the meal plans we generate, and everything you log eating — item, calories, macros, date.
Note that dislikes and preferences can reveal things you did not intend to declare — a religious dietary rule, an allergy, an intolerance. We treat the whole diet record as health data for that reason.
Legal basis: Art. 6(1)(b) + Art. 9(2)(a).
2.5 The AI coach (Movi) — health data
Your conversations with Movi, and the memory notes Movi keeps about you — preferences, what worked, injury notes, how an exercise fits you, events.
These notes are written automatically, after a conversation, from what you said in it — you do not have to ask for something to be remembered. That is the point of the feature, and it is also why it is worth saying plainly: if you mention an injury or a diagnosis in passing, that can become a stored note.
Memory is optional and you control it. In the app you can see everything remembered, delete any single note, or switch memory off entirely — and switching it off deletes every stored note, it does not merely stop using them.
Legal basis: Art. 6(1)(b) + Art. 9(2)(a).
We do not store your conversations with Movi. Each turn is answered on its own: your app holds the thread and sends the recent part of it back with your next question, and nothing is written to our database. The consequence is worth stating plainly, because it is stronger than any retention period we could promise — there is no transcript here to retain, to hand over, or to lose.
2.6 Body photographs — health data, and the most sensitive thing here
The images themselves, held in encrypted object storage, plus the small amount of metadata needed to show them to you and to record your consent.
The rules, which are enforced in code and not just promised:
- Optional. Nothing about the product requires them.
- Consent is checked every time a photo is read, not just recorded when you upload. A photo whose consent was withdrawn is not served, to anyone, ever.
- Visible only to you — with one exception you control: a human coach you accept (§4).
- Never repurposed, never used to train models, never shared with other users.
- Deletion is real. Deleting a photo removes the image itself, not just a database record. Withdrawing consent purges all of them in one action.
Legal basis: Art. 9(2)(a) — separate, explicit, revocable consent, distinct from the consent covering the rest of your training data.
Where the images sit is the one thing we cannot promise as tightly as the rest. Your training record is in a database contractually located in the European Union; your photographs are in object storage set to prefer western Europe, which is a placement preference and not a guarantee that no copy is ever held elsewhere. We are not going to describe a preference as a guarantee. Tightening that is on the list before this notice comes into force, and §7 says the same thing in the round.
2.7 Coaching relationships
Who coaches whom, the status of the link (invited / active / paused / ended), who invited whom, and the messages between a coach and a client.
Legal basis: Art. 6(1)(b) for the relationship itself; the disclosure of your health record to a coach rests on Art. 9(2)(a) — your acceptance of the link is the explicit consent event (§4).
2.8 Is providing this required?
Art. 13(2)(e): providing your data is not a statutory requirement. It is a contractual necessity for the parts of the service you ask for. Without a training profile there is no programme; without diet inputs there are no calorie targets; without a photo there is no photo. If you don’t give us something, that feature simply doesn’t work — nothing else follows.
2.9 What we do not collect
- No advertising identifiers, no ad networks, no third-party analytics or tracking SDKs. at launch, including the marketing site.
- No location data.
- No contacts, no calendar, no health-platform sync (Apple Health / Google Fit) as of this draft.
- No payment data — there is no billing in the product yet. when billing ships, this section must be rewritten.
3. How we protect it
Your data is separated from every other user’s, and that separation is enforced independently in more than one layer, so a mistake in one does not open the other. The design fails closed: if we cannot establish who is asking, the answer is no data, not the wrong data. Both layers are covered by automated tests and by live verification against the real database before each release.
Encryption. In transit: TLS throughout. At rest: your database and your photos are encrypted by the providers that store them.
Access by us. State plainly who inside the company can access user data, on what basis, and whether that access is logged. A health-data notice that is silent on internal access is incomplete, and this is a fact about the organisation rather than about the code — the owner must supply it.
(We deliberately do not publish the mechanics of these controls. Art. 32 requires appropriate measures, not published ones.)
4. Human coaches — who can see what
Motric lets a human coach manage your training. This is the one case where another person sees your health record, so it is worth being blunt:
A coach you accept can see everything in your account — your plan, every logged set, your progress, your diet, your check-ins, your body photos if you have any, and your eating-disorder-screen state. They can also adjust your training.
The controls:
- Nothing is shared until you accept. An invitation alone grants no access. The acceptance is the consent event, and you see the full disclosure before you accept.
- You can pause or end it at any time, and access is lost immediately.
- You keep everything when it ends. The record is yours; the coach loses all access.
- You can have more than one coach (e.g. lifting and nutrition). Each is a separate link you accepted separately.
- A coach cannot write as you. Messages between you are always attributed to the real sender.
5. What leaves Motric — the AI coach, specifically
5.1 What is sent
When you send a message to Movi, we send a language model: your message, your current training numbers (your session’s exercises, sets, reps, targets and loads, your recent training history, your bodyweight trend, your injury and mobility flags), your calorie and macro targets if you use the diet features, your memory notes if memory is on, and background material from our research library that contains no personal data.
So: yes, health data is sent to a model provider. That is what makes the coach able to say anything specific about your training.
5.2 What is not sent
- Your name and email are not included in what we send.
- Your body photographs are never sent to any chat model.
- If our eating-disorder screen has flagged you, no calorie or macro numbers are included at all — so the model has none to repeat. That is enforced before the request is built, not asked of the model.
- The model cannot change your plan, your sessions or your logs. It explains; it does not act.
5.3 Where it goes
Model inference — chat, the embeddings behind memory, and speech-to-text — is performed by Cloudflare’s AI service. Cloudflare’s sub-processors for that service include entities in the United States and the United Kingdom, so this is an international transfer; see §7 for the safeguard.
Cloudflare’s commitment, quoted exactly: “Cloudflare does not use your Customer Content to (1) train any AI models made available on Workers AI or (2) improve any Cloudflare or third-party services.”
5.4 Movi is AI, and we say so
Movi is labelled as AI everywhere it speaks, and AI-generated guidance carries a disclaimer: “AI-generated · general fitness info, not medical advice.” This is also an obligation under the EU AI Act’s transparency rules (Art. 50), applicable from 2 August 2026. to confirm our compliance position, including whether we are a provider or only a deployer of AI systems.
5.5 One more outbound call
When you search for a food, the search term is sent to the USDA FoodData Central API in the United States to look up nutrition data. No identifier of yours is attached — just the food name. Results are cached so the same search isn’t sent twice.
6. Who else processes your data
| Processor | What they do for us | Where |
|---|---|---|
| Cloudflare, Inc. | Runs the app and the API, caches sign-in sessions, stores photos, and performs AI inference | US company, global network |
| Neon, LLC | Managed database — your training record | Database in AWS Europe (Frankfurt); US company |
| USDA FoodData Central | Nutrition reference lookups (a food name, no identifier) | United States |
Each of these uses its own sub-processors. Rather than reproduce their lists here — they change, and a stale copy is worse than a link — we point to them: Cloudflare, Neon.
7. Where your data is, and when it leaves the EU
Your training record is stored in the European Union — in Frankfurt.
Being straight about the rest, because a residency claim that isn’t literally true is a misrepresentation:
- Processing happens near you. Our API runs on a global network, so a request made from outside Europe is processed outside Europe, even though the stored data stays in Frankfurt.
- Sign-in session records are cached globally.
- AI requests are processed by Cloudflare’s AI service, whose sub-processors include entities in the United States and the United Kingdom (§5.3).
- Photographs are placed, not guaranteed. The image store is set to prefer western Europe. That is a placement preference; unlike the database it is not a contractual residency guarantee, so we do not claim one for them (§2.6).
- Our providers are US companies, so their support and operations staff may access data remotely — which counts as an international transfer even when no copy is made.
Transfer mechanism. Cloudflare’s Data Processing Addendum incorporates the EU Standard Contractual Clauses (Modules Two and Three) and the UK Addendum, and Cloudflare also states that it complies with the EU–US Data Privacy Framework. We rely primarily on the Standard Contractual Clauses.
You can request a copy of the safeguards we rely on by writing to us.
8. How long we keep things
Art. 13(2)(a) asks for a period or the criteria used to determine one, and the criteria below are the ones the system actually enforces. That is deliberate: a stated period we do not delete against is a promise broken by default, and worse than an honest rule. Where a period would be an improvement rather than a correction, it is listed as an open decision — not as a placeholder we published.
| Data | Retention | Status |
|---|---|---|
| Account and training record | For as long as your account is open | Actual — deleting the account erases it immediately (§9). an inactivity cut-off would be an improvement, not a fix |
| Short-term database recovery history | 6 hours | Actual, configured |
| Body photographs | Until you delete them or withdraw consent | Actual — deletion is immediate and permanent |
| Memory notes | Until you delete them or turn memory off | Actual |
| Movi conversation history | Not stored at all | Actual — turns are stateless; see §2.5 |
| Coach↔client messages | Until either party deletes their account | Actual — the thread belongs to both people, so it goes when either one leaves. deleting them when a coaching link ends would need a change: today ending a link revokes access, it does not remove the thread |
| Sign-in sessions | Expire after 30 days | Actual, configured |
| AI request logs | — | — |
| Everything, after account deletion | Immediate and permanent | Actual — see §9 |
9. Your rights
Under the GDPR you have the right to:
- Access your data and get a copy (Art. 15)
- Correct anything wrong (Art. 16)
- Erase your data (Art. 17)
- Restrict processing (Art. 18)
- Portability — receive your data in a machine-readable format and have it sent elsewhere (Art. 20)
- Object to processing based on legitimate interests (Art. 21)
- Withdraw consent at any time, as easily as you gave it (Art. 7(3)) — and because health data is processed on the basis of your explicit consent, withdrawing it stops that processing
- Complain to a supervisory authority (Art. 77) — see §12
We respond within one month (Art. 12(3)).
What works today, in the product:
| Right | How |
|---|---|
| Get a copy of everything we hold (Art. 15, Art. 20) | Download your data as a single machine-readable file, from your account |
| Delete your account and everything in it (Art. 17) | Delete your account — you type your email to confirm. It removes your record and your photos permanently. There is no undo and no restore |
| See and delete memory notes | Memory screen — list, delete individually, or switch memory off (which deletes all of them) |
| Delete a body photo | Delete it in the app — the image is permanently removed |
| Withdraw photo consent and purge every photo | One action in the app |
| End a coach’s access | Pause or end the link — access is lost immediately |
| Correct or delete individual entries | In the app |
To exercise any right, or if a right above isn’t working: privacy@motric.app.
10. Automated decision-making
Our position: Motric does not make decisions about you that produce legal effects or similarly significantly affect you within the meaning of Art. 22, so the Art. 22 safeguards and the “meaningful information about the logic” duty in Art. 13(2)(f) and Art. 15(1)(h) — both of which are expressly tied to Art. 22(1) and (4) — do not apply. We describe the following anyway, because you should not be surprised by it.
- Your training programme is generated automatically from the profile and logs you provide, by our own rules-based engine. The AI coach explains those numbers; it does not produce them and cannot change your plan. The programme is guidance you are free to ignore.
- An eating-disorder screen can change what the product offers you. If it triggers, we stop giving calorie targets and restrictive plans, switch to a supportive tone, and point you toward professional support. It re-checks continuously against your current information rather than locking a permanent flag, so correcting a mistake in your profile — a mistyped weight, for example — restores normal service.
- An age screen. Below the minimum age we do not give adult calorie guidance, and point to appropriate care instead.
Both screens only ever restrict what the product does. There is no profiling for advertising, pricing or scoring, and no decision here affects your access to anything outside Motric.
If one of these screens is wrong about you, write to us — a person will look at it.
11. Children
The product currently uses a minimum age of 16 for adult calorie and training-nutrition guidance, and that number is marked in the code as a placeholder pending a real minor-users policy. It is a clinical judgment as much as a legal one: the calorie formulas are not validated for children and the calorie floor is an adult floor.
To resolve: the minimum age to hold an account at all (distinct from the age for diet features); how it interacts with GDPR Art. 8, where the digital-consent age varies between 13 and 16 depending on the Member State; and app-store rules for health apps. Then make the code, the Terms and this notice agree.
12. Complaints
If you think we’ve handled your data wrongly, tell us first — privacy@motric.app — and we’ll try to fix it.
You also have the right to complain to a data-protection supervisory authority, in the EU/EEA country where you live, where you work, or where the problem happened. That right does not depend on where we are established, and you do not have to come to us first.
13. Security incidents
If a breach is likely to result in a risk to your rights and freedoms, we notify the supervisory authority within 72 hours (Art. 33) and, where the risk is high, we tell you directly (Art. 34).
14. Changes to this notice
We’ll post changes here and, for anything that materially affects you — a new processor holding health data, a new purpose, a new transfer — we’ll tell you before it takes effect. Where a change requires fresh consent, we’ll ask.
Version: DRAFT, 2026-07-27. Not in force.
Sources
- GDPR Art. 9 — Special categories of personal data
- GDPR Art. 13 — Information to be provided
- GDPR Art. 22 — Automated individual decision-making
- Cloudflare Data Processing Addendum
- Cloudflare sub-processors
- Your Data and Workers AI
- Neon — Security & compliance
- Neon — Sub-processors
- European Commission — Article 50 AI Act transparency obligations