Privacy Policy
This Privacy Policy explains how the seto mobile application, website, and related backend services (“seto”, “we”, “us”, or “our”) collect, use, store, and share personal data.
seto does not sell personal data, does not share personal data with advertisers, and does not use personal data for cross-app advertising or behavioural advertising.
1. Who we are
seto is operated by Aleh Laliyeu, an individual based in Poland. There is currently no separate legal entity operating seto. If this changes, this Privacy Policy will be updated to identify the new data controller.
For privacy questions or requests, contact: Email: contact@seto.fit.
Aleh Laliyeu is the controller responsible for personal data processed through seto.
2. Who may use seto
You must be at least 13 years old to use seto.
seto is not directed to children under 13, and we do not knowingly collect personal data from children under 13.
Users who have not reached the age of legal majority in their country may use seto only with the permission of a parent or legal guardian. Where applicable law requires parental authorization for the processing of personal data, the parent or legal guardian must provide or authorize that consent.
If you believe that a child under 13 has provided personal data to seto, contact us at contact@seto.fit. We will investigate the request and delete the relevant data where appropriate.
3. Personal data we collect
We collect only the information reasonably necessary to operate, secure, and improve seto.
3.1 Account data
When you create an account, we may collect:
- your email address;
- your password in securely hashed form;
- your internal seto user identifier;
- your email-verification status;
- authentication and session information;
- the date your account was created and last accessed.
Your email address is required to register, verify your account, sign in, recover your password, and receive essential account-related messages. We do not store your password in readable form.
3.2 Apple and Google sign-in data
When you use Sign in with Apple or Google Sign-In, we may receive:
- a provider-specific account identifier;
- your email address;
- your name, if the provider makes it available;
- a profile-image URL, if the provider makes it available.
The exact information received depends on your settings and the information provided by Apple or Google. Apple and Google independently process information relating to your use of their authentication services under their own privacy policies.
4. Profile and fitness data
When you use seto, you may choose to provide:
- display name;
- age in years;
- sex;
- height;
- weight;
- training experience;
- primary training goal;
- equipment availability;
- training preferences;
- preferred measurement units;
- body measurements you choose to record over time — for example body weight, body-fat percentage, lean mass, and circumferences such as waist, chest, hips, neck, shoulders, arms and thighs.
seto asks for your age in years and does not require your complete date of birth.
Some profile information may be used to personalise training recommendations. Optional fields can generally be left blank, although certain personalised features may not work without the relevant information.
5. Workout and training data
When you create or record workouts, we may process:
- exercises performed;
- custom exercises created by you;
- sets and repetitions;
- weights and resistance values;
- workout and exercise duration;
- workout dates and times;
- workout templates and routines;
- training history and personal records;
- statistics calculated from your workouts;
- optional workout notes;
- exercise searches you make inside the app, which we keep against your account to rank future search results.
At the effective date of this Privacy Policy, seto does not collect user-uploaded progress photographs or workout videos.
6. Physical limitations and health-related information
seto may allow you to select physical limitations or injuries from a predefined list so that workouts can be adapted to your circumstances. Providing this information is optional.
Information about injuries and physical limitations may constitute health-related personal data. We use selected limitations only to:
- adapt exercise selection;
- exclude potentially unsuitable exercises;
- personalise workout recommendations.
You may use seto without providing physical limitations, and you can remove a selected limitation at any time in the app's training settings.
seto is a fitness application. It does not provide medical diagnosis, treatment, physiotherapy, or professional medical advice. Consult a qualified healthcare professional before beginning a new exercise programme if you have an injury, medical condition, or other health concern.
7. Automated workout personalisation
seto may use an internal algorithm to generate or adjust workout recommendations based on information such as:
- age, training goal, and training experience;
- workout history and previous performance;
- available equipment;
- selected physical limitations.
This processing takes place within seto's own systems. At the effective date of this Privacy Policy, workout and health-related data are not sent to OpenAI, Anthropic, Google Gemini, or another external generative-AI provider for workout generation.
Automated workout personalisation does not produce legal effects and is not intended to make decisions that similarly significantly affect you. Recommendations are informational and should be adjusted based on your personal condition, experience, and professional medical advice where appropriate.
8. Device, session, and security data
When you access seto, we may automatically collect:
- device model and OS type/version;
- app version;
- IP address and user-agent information;
- language and locale settings;
- request dates and times;
- authentication and session identifiers;
- login and verification events, including failed login attempts;
- limited server and security logs;
- information required for rate limiting and abuse prevention.
We use this information to operate the app, maintain active sessions, let you view and manage active devices, protect accounts, detect suspicious activity, prevent abuse, apply rate limits, and diagnose technical problems.
9. Push notifications
seto does not currently send push notifications. If push notifications are introduced — for example, workout reminders or account-security alerts — this Privacy Policy will be updated before that processing begins, notification permission will be optional and revocable at any time in your device settings, and we will avoid intentionally including sensitive health information in notification content shown on a locked device.
10. Subscription and payment data
seto Pro subscriptions are purchased through the Apple App Store on iOS or Google Play on Android.
Apple or Google processes your payment information. seto does not receive your complete card number, card security code, bank-account details, or billing address.
Through Apple, Google, and RevenueCat, we may receive:
- subscription status, product/plan identifier;
- purchase, renewal, cancellation, expiration, and trial status;
- transaction or subscription identifier;
- the internal seto user identifier associated with the purchase.
We use this information to confirm purchases, provide seto Pro access, manage subscription entitlements, prevent fraud, and respond to subscription-support requests.
Deleting your seto account does not automatically cancel an active Apple App Store or Google Play subscription. You must cancel the subscription through your Apple or Google account settings.
11. Transactional email
We may use your email address to send essential transactional messages, including:
- email-verification messages;
- password-reset messages;
- account-security notifications;
- email-change confirmations, if this feature is available;
- account-deletion confirmations;
- important service or subscription notices.
We use Resend to deliver transactional email. At the effective date of this Privacy Policy, we do not use your email address for third-party advertising.
12. Diagnostics and error monitoring
We use Sentry to identify crashes, backend errors, performance problems, and unexpected application behaviour.
Diagnostic information may include stack traces, error messages, affected files and code locations, app and backend versions, device and OS information, request or error identifiers, timestamps, your internal seto user identifier, and — where necessary to investigate an account-specific backend error — your account email address.
Our Sentry configuration is set not to collect default personal data (IP address, cookies) and redacts values for known sensitive fields such as passwords and authentication tokens before an error report is sent. Diagnostic reports are not designed to include the full content of your workouts, notes, measurements, or selected physical limitations, but because diagnostics are generated automatically at the time of an error, we cannot guarantee that no such data will ever appear incidentally in a report directly connected to the error being investigated.
13. Analytics, advertising, tracking, and cookies
At the effective date of this Privacy Policy, seto does not use a third-party product-analytics SDK, advertising SDK, session-replay service, or cross-app tracking technology.
In particular, seto does not currently use services such as Meta Pixel or Meta advertising SDK, AppsFlyer, Adjust, Mixpanel, Amplitude, PostHog product analytics, or Firebase Analytics.
seto may use aggregated statistics provided by Apple App Store, Google Play, RevenueCat, and infrastructure providers to understand installations, subscriptions, technical performance, and service reliability.
If a new analytics or monitoring provider is introduced, this Privacy Policy and the relevant Apple App Privacy and Google Play Data Safety disclosures will be updated before or at the time the new processing begins.
The seto.fit website does not set cookies and does not run third-party analytics, advertising, or tracking scripts. No technology requiring consent is in use, which is why the website does not show a cookie consent banner.
If you switch the website's light/dark theme, that preference is saved in your browser's local storage on your device only. It is never transmitted to us or to anyone else, and you can remove it at any time by clearing the website's site data in your browser.
Our hosting provider (Cloudflare) may set strictly-necessary cookies for security and bot protection; such cookies are exempt from consent requirements. If we ever introduce technologies that require consent, a consent mechanism will be added before they are enabled, and this section will be updated.
14. Service providers
We use third-party service providers to operate seto. They receive only the information reasonably necessary to perform their services.
| Provider | Purpose | Information processed |
|---|---|---|
| Apple | App distribution, subscriptions, Sign in with Apple | Authentication information, store and transaction information |
| App distribution, subscriptions, Google Sign-In | Authentication information, store and transaction information | |
| RevenueCat | Subscription validation and entitlement management | Internal user identifier, subscription product information, transaction and subscription events |
| Resend | Transactional email delivery | Recipient email address, email content, and delivery metadata |
| Sentry | Error and performance monitoring | Technical diagnostics, internal user identifier, and account email where necessary |
| Fly.io | Backend and application hosting | API traffic, account data, workout data, and related service data processed by the backend |
| Neon | Managed PostgreSQL database | Account, profile, workout, measurement, and subscription-related data stored by seto |
| Upstash | Rate limiting, caching, and token-revocation infrastructure | IP-related rate-limit records, session-security records, and token hashes |
| Cloudflare | DNS, TLS, network protection, content delivery, and object storage | IP address, user-agent information, request metadata, and content delivered through its infrastructure |
These providers may also process technical information necessary to prevent abuse, maintain security, comply with law, and operate their infrastructure.
Some providers, including Apple and Google, may act as independent controllers for certain activities, such as store accounts, payments, and transactions.
15. Legal bases for processing
Where the General Data Protection Regulation or similar law applies, we rely on the following legal bases.
Performance of a contract: account, workout, subscription, and session data, where necessary to create and maintain your account, save and synchronise workouts, calculate training statistics, manage seto Pro access, and provide customer support.
Consent: optional profile fields and selected physical limitations, and — once introduced — push notifications. You can withdraw consent at any time through the relevant app or device settings or by contacting us.
Legitimate interests: limited technical, diagnostic, and security information, necessary to secure accounts and infrastructure, prevent fraud and abuse, apply rate limits, diagnose errors, and protect our legal rights. We do not rely on legitimate interests for behavioural advertising.
Legal obligations: limited information retained where necessary to comply with applicable law, respond to a valid legal request, prevent fraud, resolve payment or subscription disputes, or establish, exercise, or defend legal claims.
16. International data transfers
seto's primary backend infrastructure is hosted in the European Union, including infrastructure located in Frankfurt, Germany. Some providers identified in this Privacy Policy are established in the United States and may process or access information from outside the European Economic Area.
Where applicable law requires transfer safeguards, personal data is transferred using an applicable mechanism such as an adequacy decision, Standard Contractual Clauses approved by the European Commission, or another legally recognised transfer mechanism.
17. Data retention
- Account, profile, and workout data: retained while your account remains active, and hard-deleted immediately when you delete your account (see § 18) — except where limited retention is required by law or necessary to prevent fraud, resolve disputes, or establish or defend legal claims.
- Sessions and refresh tokens: refresh tokens normally expire within 30 days unless revoked earlier; they are also deleted immediately on account deletion.
- Rate-limit and security records: retained only for the period necessary to apply the relevant security restriction.
- Diagnostic and server logs: Sentry diagnostic events are generally retained for up to 90 days, subject to Sentry's retention configuration.
- Subscription records: retained for as long as necessary to provide paid access, resolve billing disputes, prevent fraud, and comply with legal requirements. Apple, Google, and RevenueCat retain their own transaction records under their respective policies.
- Support correspondence: retained for as long as reasonably necessary to answer the request, document its resolution, prevent abuse, and protect legal rights.
- Backups: residual copies may briefly remain in encrypted, access-controlled backups until the normal backup-rotation cycle overwrites them; they are not used for ordinary business purposes after a deletion request.
18. Account and data deletion
Registered users can initiate account deletion inside the app through Settings → Account → Delete account, or by contacting contact@seto.fit. See also seto.fit/delete-account.
When you delete your account, seto hard-deletes the account and every user-keyed dependent record — workouts, sets, exercises, routines, measurements, personal records, gyms, favorites, notes, and refresh tokens — in a single database transaction. There is no soft-delete flag and no grace period: deletion is immediate and permanent, and there is no restore path.
Deletion does not remove information independently retained by Apple, Google, RevenueCat, or another independent controller, and does not cancel an active Apple or Google subscription (see § 10). Limited information may also be retained where required by law or to resolve a payment dispute or legal claim.
Deleting the seto app from your device does not by itself delete your account.
19. Your privacy rights
Depending on where you live and the law that applies, you may have the right to access, correct, delete, restrict, or object to processing of your personal data; withdraw consent; request data portability; and lodge a complaint with a data-protection authority.
You can view and edit most of your profile, workout, and measurement information directly inside the app. To make another privacy request, email contact@seto.fit. We may need to verify that the request relates to you before providing, changing, or deleting personal data.
Where the GDPR applies, we normally respond without undue delay and within one month; this period may be extended where legally permitted, and we will notify you if an extension applies.
If you are located in Poland, you may lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych). You may also contact the data-protection authority in the country where you live or work.
20. Security
We use technical and organisational measures designed to protect personal data, including encryption in transit (TLS), secure password and token hashing, database access controls, authentication and session protections, rate limiting, infrastructure monitoring, and restricted access to production systems.
No electronic service can guarantee absolute security. If you believe you have discovered a security vulnerability, contact contact@seto.fit rather than disclosing it publicly.
21. Third-party links and services
seto may contain links to websites or services operated by third parties. This Privacy Policy does not govern third-party services that seto does not control. Review the privacy policy of a third-party service before providing information to it.
22. Changes to this Privacy Policy
We may update this Privacy Policy when seto's features, service providers, or data-processing practices change, or when legal or regulatory requirements change. For material changes, we will provide reasonable notice through the app, by email, or through another appropriate method. Where a change requires new consent, we will request that consent before beginning the relevant processing.
The effective date and “Last updated” date at the top of this Privacy Policy identify the version currently in effect.
23. Contact
For privacy questions, access requests, deletion requests, complaints, or other data-protection matters, contact:
Aleh Laliyeu
Poland
Email: contact@seto.fit