Privacy Policy

Last updated 2026-09-09

What we collect, why we collect it, who else sees it, and what you can make us do about it. We collect as little as the service can run on.

1. Who is responsible for your data

Dor Pinhas, trading as forconn.ai, a sole trader based in Israel. That trader is the data controller. Contact us about anything in this policy at dor.fitness.training@gmail.com.

We do not have a Data Protection Officer; we are not required to appoint one. Requests go to the address above and are handled by us directly.

2. What we collect

  • Account details. Your email address, and your name and account identifier from Google when you sign in. We do not receive or store your Google password.
  • Purchase records. What you bought, when, currency, amount, subscription status, and renewal dates. We never see or store your card details or billing address — those go to Paddle.com Market Ltd, who takes the payment.
  • Plan and delivery history. Which weekly plans have been released to you and, once email delivery is live, whether an email was delivered, opened, or clicked.
  • Training you log — not yet collected. The guided session view keeps your place as you work through a week, but it keeps it in your own browser. It is not sent to us and we do not store it. If that changes, this page will say so before it does.
  • Your equipment and training profile. If you fill in the setup questions, we store your answers against your account — your age band (never your date of birth), your training goals, whether you train with a kettlebell, your own bodyweight or both, which kettlebells you own, how experienced you are, and how often you train now and want to train. They decide which written programs the app shows you first, and they are deleted with your account. A question you leave unanswered stores nothing; if you skip the whole thing, we record only that you skipped. The second set of questions adds which kettlebells you own and how each one feels to you, what you can do on a few movements, and what you'd like to focus on. There is one free-text box — anything you'd like to be able to do, in your own words: we store exactly what you type, nothing in the app reads it, your profile shows it back to you so you can change it or clear it, and it is deleted with your account like the rest.
  • Which public pages get opened. When you open one of our public pages we record the page, the referring site (its address only, never the page you were on), and any ?ref=tag we put in a link we posted — so we can tell whether anyone is actually arriving. We also record the kind of device (phone, tablet or computer), your screen size rounded down to the nearest 100 pixels, and which page on this site you came from; we do not store your browser's user-agent string. This is our own record, it sets nothing on your device, and it needs no consent. We do not record which weeks or workouts you open on these public pages. Your dashboard, your plans and your account are excluded outright. It carries no name or email; if you are signed in it is stored against your account, and deleting your account detaches it — what is left describes a page, not a person. When you start a workout signed in, your progress — which workout and how far you got — is saved to your account so your dashboard can show it. Start a program and we keep the same kind of record — which program, and which day of it you are on. Both are deleted with your account.
  • Emails you send us. If you reply to one of our emails or write to dor.fitness.training@gmail.com, we store the message so we can answer it.
  • Technical data. Standard server logs from our hosting and security providers, including IP address, browser, and request times.

We do not ask for your weight, measurements, injuries, or medical history. We do not want them and we do not store them. The only weight we record is the kettlebell's, not yours. Please do not send us medical information by email.

3. Why we are allowed to use it

For anyone in the EU or UK, these are our legal bases under the GDPR and UK GDPR:

  • Performance of a contract. Running your account, delivering the plans you paid for, keeping the training you choose to log, and handling billing status.
  • Legitimate interests. Keeping the service secure, preventing abuse, understanding whether our emails are arriving, and answering your messages. We use the least data that achieves this.
  • Legal obligation. Keeping records we are required to keep, including for tax.
  • Consent. Only where we ask for it explicitly — analytics cookies, and any future marketing email unrelated to your subscription. You can withdraw consent at any time, from the cookie settings link in the footer or by emailing us, and it is as easy to withdraw as it was to give.

4. Who else processes it

We do not sell your data and we do not share it for advertising. We use these providers to run the service, each bound to process data only on our instructions:

  • Supabase — database, authentication, and file storage.
  • Vercel — website hosting and server logs.
  • Paddle.com Market Ltd — payments, invoicing, and tax. They are the seller of record and an independent controller of the payment data you give them.
  • Resend — sending account emails, and the weekly plan once email delivery is live.
  • Cloudflare — domain, network security, and receiving email sent to us.
  • Google— sign-in. Google tells us your email, name, and account ID; what Google does with your use of its own account is governed by Google's privacy policy.
  • Google Analytics — website analytics, only if you accept analytics cookies. It tells us how many people reach the site, where they arrived from, and which pages get read. We do not send it your name, your email, or anything you type, and we do not use it for advertising. If you decline, it is never loaded at all. Data is processed by Google in the United States under Standard Contractual Clauses and Google's EU–US Data Privacy Framework certification.

We may also disclose data where the law requires it, or to establish or defend legal claims.

5. Where your data goes

We are based in Israel and our providers operate internationally, so your data is transferred outside the EU and UK.

Israel holds an adequacy decision from the European Commission, which permits transfers from the EU without additional safeguards. For transfers to providers elsewhere, we rely on Standard Contractual Clauses or an equivalent approved mechanism in our agreements with them.

6. How long we keep it

  • Account, plan, and training history — while your account exists, and deleted when you delete it.
  • Purchase and tax records — up to seven years after the transaction, because tax law requires it. This survives account deletion; we keep only what the obligation covers.
  • Emails you send us — up to two years after the conversation ends.
  • Server logs— typically 30 days, per our providers' defaults.
  • Analytics — 14 months in Google Analytics, then deleted automatically. Only collected if you accepted analytics cookies, and it does not carry your name or email.
  • Our own record of which pages get opened — 24 months, then deleted. The link to your account is removed as soon as the account is deleted, which leaves a row that is about a page rather than a person.

7. Your rights

Wherever you live, you can exercise these by emailing dor.fitness.training@gmail.com. We respond within 30 days and do not charge for it.

  • Access — get a copy of the personal data we hold about you.
  • Rectification — have inaccurate data corrected.
  • Erasure — have your account and data deleted, except records we must keep by law.
  • Portability — receive your data in a machine-readable format.
  • Restriction and objection — ask us to pause or stop a particular use, including anything based on legitimate interests.
  • Withdraw consent — where we relied on consent, at any time, without affecting what came before.

If you are in the EU or UK you may also complain to your national data protection authority — the ICO in the UK — and in Israel to the Privacy Protection Authority. We would rather you told us first, but you do not have to.

8. Cookies

Strictly necessary cookies keep you signed in and protect the site. They are required for the service to work, so they are always on and there is nothing to opt out of beyond signing out or blocking cookies in your browser. We do not ask for consent for these, because the law does not require it and the site cannot run without them.

Analytics cookies are set by Google Analytics and are entirely optional. They tell us how many people reach the site, where they came from, and which pages get read — so we can tell whether any of this is reaching anyone. We ask you first: nothing analytics-related loads until you choose, and declining is one click, in the same place, styled the same way as accepting. Declining costs you nothing — every page works identically either way, and we will not ask again on every visit.

You can change your mind whenever you like from the Cookie settings link in the footer. Withdrawing is exactly as easy as consenting was, and it takes effect immediately.

We do not use advertising cookies, we do not run third-party tracking pixels, and we do not sell or share what analytics collects. If that ever changes we will ask for your consent first and update this policy.

9. Children

This service is for adults. It is not directed at children, and we do not knowingly collect data from anyone under 18. If you believe a child has given us data, contact us and we will delete it.

10. Security

Access is protected by Google sign-in — we never handle a password. Data is encrypted in transit and at rest by our providers, and access to the production database is limited to the operator of this site. No system is perfectly secure; if a breach affects your rights we will notify you and the relevant authority as the law requires.

11. Changes

If we change this policy materially we will email account holders before it takes effect. The date at the top always reflects the current version.

Questions about this document: dor.fitness.training@gmail.com