Privacy Policy
This policy explains what personal data Wodzilla processes, why, with which services, and what rights you keep over your data.
Version 1.5 · Effective date: August 12, 2026
1. Data controller
This policy explains how Wodzilla processes personal data of users of the Wodzilla application, available on pro.wodzilla.app, wodzilla.app, and public sharing links.
POWERSPOT, a French SARL registered under SIREN 878 966 639 and trading as Wodzilla, is the controller for account, authentication, billing, support, service-security, and website data. Contact: contact@wodzilla.app.
For personal data that a professional customer imports, creates, or manages about athletes, employees, or members, that customer or organization is normally the controller and POWERSPOT acts as its processor. The Data Processing Agreement in the Wodzilla Terms applies to that relationship. If an athlete creates a Wodzilla account, POWERSPOT remains controller for that account while it may act as processor for results or content submitted to a professional organization.
2. Data we collect
We collect only the data needed to operate Wodzilla and provide the service.
- Account data: email address, user identifier, display name, language, interface preferences, and Google profile picture if you use it.
- Authentication data: technical information needed for sign-in, account security, email confirmations, password resets, and email address changes.
- Content data: workouts, drafts, blocks, analyses, calendars, programming Cycles, templates, folders, results, scores, tags, equipment, participants, locations, comments, private coach notes, videos, links, revisions, programming preferences, branding, and sharing links created in Wodzilla.
- Athlete data entered by a professional customer: name or alias, email, phone number, date of birth, address, avatar, category, notes, workout assignments, results, scores, RPE, and related group relationships, depending on the fields the customer chooses to use.
- Public-profile data: an Athlete profile is public by default and may display the athlete's name, avatar, Wodzilla join date, category, and public result history. The athlete can make the profile private at any time in account settings.
- Workspace data: Team name, members, roles, invitations, seat capacity, and shared resources.
- Billing data: plan, subscription status, Extra Energy purchases, Stripe customer identifiers, payment history, and billing information. Full card numbers are processed by Stripe, not by Wodzilla.
- Technical data: IP address, user agent, server logs, security events, performance data, errors, usage analytics, and diagnostic information.
- Support data: messages, feedback, support requests, and attachments you voluntarily provide.
3. Sources of data
Data mainly comes from you when you create an account, use the application, invite members, configure a workspace, create content, or contact Wodzilla.
Some data may also come from third-party services used for sign-in or payment, including Google OAuth, Supabase Auth, and Stripe.
4. Purposes and legal bases
We process account, content, and workspace data to perform the contract and provide Wodzilla; billing and tax data to perform the contract and meet accounting or tax obligations; security, diagnostic, and service-measurement data for our legitimate interests in protecting and improving the service; and support data to answer your request.
Where consent is legally required for an optional technology, that processing is based on consent and may be withdrawn without affecting prior lawful processing. We do not use Wodzilla data for third-party advertising and we do not sell personal data.
5. Google sign-in
If you choose to sign in with Google, Wodzilla uses Google OAuth to authenticate you. Access is limited to standard sign-in scopes: OpenID identity, email address, basic profile, and profile picture if available.
Wodzilla does not access Gmail, Google Drive, Google Calendar, or other sensitive Google data through this sign-in flow.
6. Artificial intelligence
When you deliberately use an AI feature, Wodzilla processes the instruction, relevant workout or programming content, language, settings, and context needed to perform the request. Depending on the action, this may be used to generate, transform, analyze, search, or help plan content through specialized service providers acting for Wodzilla.
Only information needed for the requested action is transmitted. Technical providers may change without changing these purposes. Wodzilla does not sell prompts or use them for third-party advertising.
Do not include personal data that is unnecessary for the request, special-category or medical data, or confidential athlete records in AI prompts. Wodzilla is not designed to be a medical record. AI outputs must be reviewed by a competent person before use.
7. Public sharing and workspaces
Some features let you create public links for workouts, calendars, results, and athlete profiles. Anyone with the link may access and re-share the visible content while the link remains active. Public pages may include the information, media, links, branding, comments, and results deliberately included in the shared content; private block coach notes are not shown on public surfaces.
An optional calendar password restricts access to the calendar content but does not necessarily hide its name or social-preview metadata. The owner can disable a public link or change its protection from the product.
Athlete profiles are public by default and can be made private from account settings. A private profile is visible only to its owner, subject to content separately shared through a workout or calendar link.
In a Team workspace, shared workouts, calendars, templates, and settings may be visible to authorized members according to their role. Personal and shared spaces remain separate, and the Team owner or admins can manage certain accesses, members, seats, and resources.
A Team in payment recovery or the seven-day grace period is read-only. Existing public links may remain viewable during those states, but public submissions are disabled. An archived Team remains privately consultable by its members, while its public links are unavailable.
8. Recipients and processors
We do not sell personal data. Access is limited to authorized personnel, the professional customer controlling relevant athlete data, and the providers needed to operate Wodzilla.
- Supabase, for authentication, database, file storage, and authentication-related transactional emails.
- Vercel, for hosting, content delivery, technical logs, Web Analytics, and Speed Insights.
- Stripe, for payments, subscriptions, invoices, billing details, and automatic tax calculation where applicable.
- Google, for OAuth authentication when you choose Google sign-in.
- Specialized AI and search providers, only when you request a feature that requires them.
- YouTube, operated by Google, for video thumbnails and optional playback of videos included in workout content; privacy-enhanced embeds are used where available.
- Competent authorities, advisers, or acquirers only where legally required or necessary to protect rights, handle a dispute, or complete a lawful corporate transaction.
9. Transfers outside the European Union
Some providers may process data outside the European Union. Where applicable, we rely on available legal mechanisms such as adequacy decisions, standard contractual clauses, or equivalent contractual commitments.
10. Retention
We keep account and content data while your account is active or as long as needed to provide the service.
- Account and personal-space content is kept while the account is active, then deleted or anonymized following an account-deletion request, subject to the exceptions below. Content contributed to a Team workspace may remain with that workspace when a member leaves.
- Draft workouts are autosaved and kept for up to 90 days after their latest content change. Deleting a draft or saved workout moves it to Workouts Trash, where it is permanently deleted after 15 days unless restored first. Technical capacity limits may remove the oldest Trash items sooner.
- Workouts in continuous calendars are kept for up to two years after their scheduled date, and their dated programming Cycles for up to two years after their end date, then permanently removed from professional calendars. Fixed-duration calendars and their Cycles are not subject to this automatic deletion. Results submitted through an authenticated athlete account may retain a limited workout and block snapshot in that athlete's history; guest and coach-added results linked only to expired calendar content are deleted.
- Workout revision history is limited to the most recent versions and each stored revision is kept for up to 30 days.
- Content accepted from an AI action becomes part of the relevant workout or programming content and follows its retention period. Temporary instructions, proposals, results, search indexes, and limited technical usage records are kept only for the period needed to provide, secure, support, and account for the feature; short-lived results may expire before their source content.
- A result hidden through moderation is permanently deleted after 30 days.
- Public links remain available until the owner disables them or the related content, account, or workspace is deleted. An anonymized result may remain in a leaderboard after athlete-account deletion where the product explains this outcome.
- Cancelling a Team subscription does not delete shared content. At the paid-period end the Team enters a seven-day read-only grace period and then a read-only archive. The archive remains until the owner reactivates it or explicitly confirms permanent dissolution.
- Permanent Team dissolution deletes shared Team content and invalidates its public links. An authenticated Athlete submission may retain only the approved minimal workout and block snapshot in that Athlete's private history, with the Team link, branding, coach notes, public scope, and Team leaderboard context removed. Guest and coach-added results that exist only in the Team are deleted.
- Minimal dissolution tombstones and financial, invoice, Energy-forfeiture, legal, and audit evidence may be retained where necessary. These records are minimized and do not preserve a usable Team workspace.
- Minimal legal-acceptance evidence, such as a pseudonymous account identifier, account kind, document versions, locale, acceptance source, and timestamps, may be kept to establish, exercise, or defend legal claims and meet compliance obligations, generally for up to five years after the end of the relationship. It is then deleted or irreversibly anonymized unless a longer legal hold is required.
- Invoices and accounting records are kept for the legally required period, generally ten years in France.
- Technical logs, security events, and observability data are kept for a limited period proportionate to security, diagnostic, and maintenance needs.
- Deleted data may remain temporarily in rolling backups or longer where needed for a legal obligation, fraud prevention, security, or a dispute, and is not restored for ordinary product use.
11. Security
We use reasonable technical and organizational measures to protect data, including secure authentication, access control, user and workspace data isolation, security logs, TLS, and secure development practices.
No online service can guarantee absolute security. You must use a strong password, protect your session, and share public links only with authorized people.
12. Your rights
Under GDPR and applicable laws, you may request access, rectification, erasure, restriction, objection, or portability of your personal data.
You can exercise your rights by contacting contact@wodzilla.app. We may request reasonable information to verify your identity. For data controlled by a coach, gym, or other professional customer, contact that organization first; Wodzilla will assist it as processor.
You may lodge a complaint with the French data protection authority, the CNIL (cnil.fr), or your local supervisory authority.
13. Account deletion
Wodzilla offers account deletion from account settings. Deleting an athlete account removes its public identity, email, name, and avatar from the athlete profile; results may be retained only in anonymized form. Deleting a professional account follows the content and workspace-ownership rules explained before confirmation.
A Team owner must resolve ownership or permanently dissolve owned archives before deleting the professional account. Team dissolution is a separate owner-only action that requires recent authentication and the exact confirmation shown in the product.
Some data may be retained where needed to comply with a legal obligation, resolve a dispute, ensure security, or keep accounting records.
14. Cookies and similar technologies
Wodzilla uses strictly necessary cookies for authentication and session security. Browser localStorage stores device-side preferences, language or view choices, temporary guest workout content, recent emojis or metadata, navigation state, and similar continuity data; sessionStorage stores short-lived navigation or notification state. Durable authenticated workout drafts are stored server-side as described above.
On public result forms, a guest display name, category, and random submission key may be remembered in localStorage for up to 30 days after they are saved so the form can be reused. You can clear these items through the product where available or through browser settings.
Vercel Web Analytics and Speed Insights provide aggregated audience and performance measurement without advertising profiles. Wodzilla does not use advertising cookies. Any future non-essential measurement requiring consent will be disabled until the required choice is obtained.
15. Voice dictation
Where available, voice dictation uses the recognition capabilities of your browser or device. Wodzilla does not intentionally store an audio recording; the resulting transcript is inserted into the instruction field and is processed like other text only when you submit it. Your browser or device provider may process audio under its own terms.
16. Minors
A paid or professional Wodzilla account is for adults aged 18 or over. An athlete may create an autonomous account from age 16 and, when aged 16 or 17, must have parental or legal-guardian authorization where required. A person under 16 cannot create an autonomous account and may appear only in a profile managed by an authorized coach, responsible organization, parent, or guardian, with data minimized and preferably identified by an alias.
17. Changes
We may update this policy to reflect product, provider, legal, or practice changes. The version and effective date displayed at the top identify the applicable text; material changes will be brought to users' attention by an appropriate channel.
Privacy contact and controller address: POWERSPOT, 38 rue des Vallées, 92700 Colombes, France — contact@wodzilla.app.