Privacy Policy
Last updated: 28 June 2026
1. Introduction
We respect your privacy and protect your personal data. This policy explains what data we collect, why, on what legal basis, who we share it with, how long we keep it and what rights you have, under Regulation (EU) 2016/679 (GDPR) and applicable national law.
2. Data Controller
The Data Controller is Alexandru Francisc Mihalache, developer of Speenji (a natural person).
For any request about your data or to exercise your rights, write to: support@speenji.it.
We have not appointed a Data Protection Officer (DPO), as the legal requirements for one do not apply.
3. Information We Collect
Account data:
- •Email address — for authentication and service communications
- •First and last name — to personalize your experience
- •Gender (M/F/Other) — to personalize some features
- •User and device identifier — for session security
- •Authentication token — for secure access management
Workout data:
- •Training plans and personalized programs
- •Exercises, sets, reps, weight, duration, distance
- •Progress, history, dates and workout notes
- •Body measurements you enter voluntarily
Friends feature data (if you use it): when you search for a friend by email, send a request or share a plan, your name and possibly your email are shown to the other user.
Technical data: iOS version and device model; features used, crashes and performance metrics.
We do not collect: GPS location, contacts, gallery photos (photos used to import a plan are processed only on your device with on-device text recognition and not sent to our servers), or payment data (purchases are handled by Apple).
4. Legal Basis for Processing
We process your data on these legal bases (Art. 6 GDPR):
- •Performance of a contract (Art. 6.1.b) — to create and manage your account, store plans, workouts and progress, and provide the app's features. By accepting the Terms you enter into a contract with us: this, not consent, is the basis of the service.
- •Legitimate interest (Art. 6.1.f) — for security, abuse prevention and app improvement.
- •Consent (Art. 6.1.a and 9.2.a for health data) — for the optional Apple Health connection and any non-service communications. It can be withdrawn at any time.
- •Legal obligation (Art. 6.1.c) — when required by law.
5. How We Use Your Information
We use your data to provide the service (account, login, features), store plans and progress, enable the friends and sharing features you activate, improve the app by analyzing usage and crashes, send you important service updates and protect your account from unauthorized access.
6. The Friends Feature and Sharing
Social features are optional and activated by you:
- •You can search for another user by their exact email and send a request.
- •You can share a plan or workout via a code/link: the recipient can save a copy.
When you use these features your name (and possibly your email) is visible to the users you interact with. We do not make your data public or show it to users you have not chosen.
7. Apple Health (HealthKit)
Speenji can optionally connect to Apple Health, only if you enable it and grant permission through the iOS prompt. This concerns health data (a special category, Art. 9 GDPR) and is based on your explicit consent.
- •Data we read from Health: workouts, heart rate (including resting), steps, active energy, distances (walking/running, cycling, swimming), sleep analysis.
- •Data we write to Health: workouts, heart rate, active energy, walking/running distance.
This data is used for the app's workout and progress features and, currently, is processed and stored locally on your device and not transmitted to our servers; we do not share it with third parties and do not use it for profiling or advertising. You can revoke permission at any time in iOS → Settings → Privacy & Security → Health, or by disconnecting the feature in the app.
8. Data Storage and Security
On your device: token and user identifier in the iOS Keychain (encrypted); other data in the app's protected storage.
On our servers: backend on Railway.app; PostgreSQL database with encrypted connections; transmission via HTTPS/TLS 1.2+; API access protected by JWT tokens.
Security measures: HTTPS encryption of all transmissions; passwords stored only as hashes; regular security updates; access controls on backend systems.
9. Data Sharing and Third Parties
We do not sell, trade or rent your personal data. Providers we use:
- •Railway.app — backend and database hosting (data processor, under a DPA).
- •Apple — app distribution (App Store), beta testing (TestFlight) and management of Premium subscription purchases. Apple processes payment data as an independent controller; we do not receive your card details.
We share data with authorities only when required by law, to protect rights or safety, or with your consent.
10. International Data Transfers
Your data may be stored on servers in Europe or the United States (Railway.app, Apple). For transfers outside the European Economic Area we apply the safeguards required by the GDPR, in particular the European Commission's Standard Contractual Clauses (SCC) and/or applicable adequacy mechanisms, through data processing agreements with our providers.
11. Your Rights (GDPR)
You have the right to:
- •Access your data
- •Rectify it
- •Erase it (right to be forgotten)
- •Restrict its processing
- •Object to processing based on legitimate interest
- •Receive it in a structured, machine-readable format (portability)
- •Withdraw consent you have given (e.g. Apple Health)
To exercise them, write to support@speenji.it; you can also delete your account from the app. You also have the right to lodge a complaint with a supervisory authority: in Italy, the Garante per la protezione dei dati personali (www.garanteprivacy.it).
12. Data Retention
We keep your data while your account is active. If you delete it, data is permanently removed within 30 days and backup copies within 90 days. We keep proof of acceptance of the legal documents (date and version) for as long as needed to document the contractual relationship.
13. Children's Privacy
Speenji is not intended for users under 14 (the age of digital consent in Italy, Art. 8 GDPR and national law). We do not knowingly collect data from children under 14. If you believe a minor has provided us with data, write to support@speenji.it and we will delete it.
14. Cookies and Tracking
The app does not use cookies: authentication is via JWT tokens stored locally in the Keychain. The website only uses essential technical cookies (e.g. language preference) and no profiling or advertising cookies. Details in the Cookie Policy.
15. Changes to This Policy
We may update this policy. For significant changes we will inform you by updating the date at the top, via an in-app notice and, where applicable, by asking you to accept the documents again when you open the app.
16. Version and Acceptance
This policy has a version (the last-updated date). On registration you accept the Privacy Policy and Terms of Service: we record the date and version of your acceptance as proof (accountability, Art. 5.2 GDPR). When we substantially update the documents we ask you to accept the new version to keep using the app.
Acceptance constitutes conclusion of the contract and acknowledgement of this policy; it is not consent to processing under Art. 6.1.a, since the basis of the service is performance of the contract. Consent is required only where indicated (e.g. Apple Health).
17. Contact
Email: support@speenji.it — Website: speenji.it