Privacy Policy
Effective date: July 25, 2026
This Privacy Policy explains how the Phaserr team ("Phaserr", "we", "us") handles information across the marketing site at phaserr.com (the "Site") and the Phaserr app at app.phaserr.com (the "App"), where you create an account and build training programs.
Information we collect on the site
We keep data collection to the minimum needed to run the site:
- Analytics — we use PostHog (EU region) to understand how the site is used. Until you accept analytics cookies, PostHog runs in a cookieless mode that sets no cookies; once you accept, it sets first-party cookies to recognise your device across visits and may record an anonymised replay of your session — with all form inputs masked — to see how the page is used. You can decline at any time from the cookie banner. We do not use advertising cookies or third-party advertising trackers.
Your account
When you create a coach account in the App, we store:
- your email address, and the first and last name you enter;
- the language and display preferences you choose (units, date format, list layout);
- when you accepted the Terms and this Privacy Policy — and, where we captured it, which version;
- your answers to the optional setup questions — your sport, roughly how many athletes you coach, the tools you use today;
- the time you last signed in.
How you sign in
You can sign in in several ways. Each one stores only what it needs:
- Email code — we email you a one-time code and keep only a hash of it. The code is single-use and expires within minutes.
- Password — kept only as a bcrypt hash. We never store the password itself and cannot read it.
- Passkey — we keep only the public key your device gives us. The private key never leaves your device.
- Google — if you choose "Continue with Google", Google tells us your email address, your name, and an identifier for your Google account, and we store those to link the account to you. We ask Google only for your name, email address, and basic profile: never for Gmail, Drive, Calendar, or any other Google service. We do not receive or keep a long-lived Google token, so we cannot reach into your Google account afterwards.
- Security log — for each sign-in, sign-out, and failed attempt we record the time, your IP address, and your browser's user-agent. We use it to spot abuse and stop brute-force attempts, and for nothing else.
- Session — while you are signed in we keep only a hash of your session token, never the token itself.
Data you enter about your athletes
Phaserr is a tool for coaches, and athletes do not have accounts. You enter and control their data: names, an optional email address, programs, logged sets, one-rep maxes, injuries, and any notes you write.
That is personal data about other people. We process it only to provide the App to you, on your instructions. You are responsible for having a lawful basis to enter it and for what you record about the people you coach. You can delete it from the App at any time.
How we use your information
We use the information above to:
- run your account and provide the App to you;
- email you sign-in codes and the messages your account needs;
- keep the service secure — spotting abuse and blocking brute-force sign-in attempts;
- understand which channels bring coaches to Phaserr;
- show the site and the app in the right language;
- measure aggregate traffic so we can improve the product.
Legal basis
Where data-protection law applies, we rely on:
- performance of a contract — to run your account and provide the App;
- your consent — given when you accept analytics cookies, and given to Google if you choose to sign in with it;
- our legitimate interest — in keeping the service secure and improving the product.
Who we share it with
We do not sell your data. We share it only with service providers that help us run Phaserr:
- Hetzner — the servers and database behind the App, in Nuremberg, Germany;
- Cloudflare — hosting, security, and encrypted backups;
- Resend — delivering your sign-in codes and account email;
- PostHog — privacy-focused product analytics and feature flags (EU region);
- Sentry — error reports, so we can find and fix crashes;
- Google — only if you choose "Continue with Google", and only to confirm who you are at that moment;
- Telegram — the feedback you choose to send us from inside the App;
- Anthropic — the AI model that drafts training blocks, used only when you ask the App to generate one. We send the brief you write plus the athlete context the program needs: body metrics, injuries, personal records, and the notes you keep. We do not send their name or contact details. Anthropic returns the program and does not use this data to train their models.
Where your data lives
The App's servers and database run in Nuremberg, Germany. Some of the providers above operate globally and may process data outside the EU on our behalf.
How long we keep it
Different data has different lifetimes:
- your account and the training data in it — until you ask us to delete it;
- sign-in codes — minutes, and they are destroyed the moment they are used;
- sessions — they expire after 14 days of inactivity, and 60 days at the most;
- site analytics — aggregated and not tied to your identity; we keep it only as long as we need it to improve the product.
Your rights
You can ask us to:
- access the personal data we hold about you;
- correct it if it is wrong;
- delete it, including your account and everything in it;
- withdraw analytics consent at any time from the cookie banner.
Contact
Questions about this policy, or want to exercise any of your rights? Email us at privacy@phaserr.com.
Changes to this policy
We may update this Privacy Policy as Phaserr develops. When we do, we will change the effective date at the top of this page.