RF-01 · Privacy
Privacy, in plain English.
Effective 4 August 2026
The short version: your training log is private to you, we collect only what the product needs to work, there is no advertising or analytics tracking anywhere, and you can export or permanently delete everything yourself.
What we store
Your email address and a hash of your password (we never store the password itself). Your profile name and role. The training entries and certifications you log — dates, titles, durations, notes. Standard server logs (IP address, request path, timestamp) kept for abuse prevention and debugging.
Cookies
Three, all functional: a session cookie that keeps you signed in, a CSRF token that protects your account against forged requests, and a flag that remembers whether onboarding is complete. No advertising cookies, no analytics cookies, no third-party trackers. The emails we send contain direct links — no tracking redirects, no read receipts.
Where it lives
The website is served by Vercel; traffic is routed through Cloudflare; transactional email (verification, password resets, cert reminders) is delivered by Resend; encrypted backups are stored with Cloudflare R2. These providers process data to run the service and for no other purpose of ours. We do not sell data, share it for advertising, or run analytics on you.
Your controls
Export your complete file (JSON or CSV) from settings at any time. Delete your account from settings — deletion is immediate and permanent: the account, entries, certifications, and sessions are removed, and backup copies age out of the backup retention window on their own. There is no recovery period because we don't keep a copy to recover from.
Questions
Ask via the contact form. If practice ever changes, this page changes first and the effective date above moves.