← Back to SkillTrees
Welcome to SkillTrees!
We're committed to protecting your privacy and being transparent about how we handle your data.
This policy explains what information we collect, why we need it, and how we keep it safe.
We've written this in plain language to help you understand exactly what happens with your information
as we don't like overcomplicated privacy policies.
Information We Collect
Account Information
What We Collect |
Why We Need It |
Email address |
To create your account and send important updates |
Name |
To personalize your experience and address you properly |
Password (encrypted) |
To secure your account - we never see your actual password |
Why this matters: Your account information is the foundation of your SkillTrees
experience.
We use industry-standard encryption to protect your password, and we'll never share your email with
third parties for marketing.
Training Profile
What We Collect |
Why We Need It |
Primary sport & athlete level |
To generate appropriate workout difficulty |
Health conditions/injuries |
To avoid exercises that could cause harm |
Workout location preferences |
To suggest exercises matching your equipment |
Why this matters: Your safety is our priority. By knowing your limitations and
available equipment,
our AI can create workouts that challenge you appropriately without risking injury.
Progress & Performance Data
What We Collect |
Why We Need It |
Selected skills & milestones |
To track your progress and suggest next steps |
Workout logs (sets, reps, times) |
To measure improvement and adjust difficulty |
Session notes |
To remember your feedback for future workouts |
Exercise history |
To provide insights and prevent overtraining |
Why this matters: Your training data helps us understand what's working and what isn't.
This allows our algorithms to continuously improve your workout plans based on your actual performance,
not just
generic templates, so each rep and weight you register (to an extend) and note you writte can be used
for next workouts.
Technical Information
What We Collect |
Why We Need It |
IP address |
For security and preventing unauthorized access and mostly bots |
Device information and Browser |
To ensure the app works properly on your device, each browser works differently, so we have
specific rules of each browsers for different sections of the web page |
Login timestamps |
To detect suspicious activity and protect your account |
How We Use Cookies & Storage
Essential Cookies
We use only essential cookies and browser storage for:
- Authentication tokens: Stored securely to keep you logged in
- Session data: Temporary storage for your current workout session
Good news: We don't use any tracking cookies, analytics cookies, or advertising
cookies.
Your browsing habits and personal data stay private.
Data Security
How We Protect Your Information
- Encryption: All passwords are hashed using bcrypt, even we can't see them
- Secure connections: All data transfers use HTTPS encryption
- Token security: Authentication uses JWT with automatic rotation
- Access controls: Only you can access your workout data
What We DON'T Do
- We never sell your data to third parties, all the project is self founded by the developers, and
eventual payments of the premium version
- We don't use tracking or advertising networks, we hate ads
- We don't share your progress with other users without permission, your account is yours and only
yours
- We never store your payment card details (handled securely by Stripe)
Third-Party Services
Services We Use
Service |
Purpose |
What They Access |
Stripe |
Payment processing |
We only have information if the payment is completed or no, we have no possible way to see your
card details in any moment, the payment page is hosted in Stripe. Stripe only sends us back if
the payment is accepted, cancelled or reniewed and with which email was made the payment. |
SendGrid |
Email delivery |
Email address for email verification and password reset |
Google Gemini AI |
Workout generation |
Your fitness goals and constraints, no personal information is shared nor your email or name,
just choosen information like: primary sport, equipment, saved info, goals choosen and so on.
|
Your protection: We've carefully selected these partners for their strong privacy
practices.
They only receive the minimum information needed to provide their specific service. Each they have their
privacy policies if you need more specific information. Stripe is the one that requieres the most
infomration to prevent card frauds.
Your Rights & Choices
You Have the Right To:
- Access your data: You can always ask us to show you the information we retain of
you, your workout history and workouts export functionality will be implemented in next versions.
- Update information: Change your profile details anytime and you have the right to
DON'T give your personal information when creating the account, if you want to have a fake name and
email we accept it, as long as you don't abuse the service, we think that 1 account in the free
version is enough to use the service without paying or making fake accounts. We're a a really small
project that spends more money that can make right now.
- Delete your account: Remove all your data permanently. No exceptions, you have an
easy access in the Settings Page. Your email, name, family name and profile will be deleted.
- Opt-out of emails: Control what notifications you receive
Data Retention
We keep your data as long as your account is active. If you delete your account,
we'll remove your personal information within 30 days, except where we need to keep
certain records for legal or security purposes (like preventing fraud like Stripe).
Changes to This Policy
We'll notify you by email if we make significant changes to this privacy policy that can affect you.
For minor updates that might be relevant, this page will be updated and we will announce the changes in
the changelog inside the feedback section.
Our promise: Any changes will always be designed to better protect your privacy
or to comply with new regulations. We do our best to keep the best security practices in place.