Skip to content

Privacy Policy

This policy explains what personal data Wodzilla processes, why, with which services, and what rights you keep over your data.

Version 1.3 · Effective date: July 26, 2026

1. Data controller

This policy explains how Wodzilla processes personal data of users of the Wodzilla application, available on pro.wodzilla.app, wodzilla.app, and public sharing links.

POWERSPOT, a French SARL registered under SIREN 878 966 639 and trading as Wodzilla, is the controller for account, authentication, billing, support, service-security, and website data. Contact: contact@wodzilla.app.

For personal data that a professional customer imports, creates, or manages about athletes, clients, employees, or members, that customer or organization is normally the controller and POWERSPOT acts as its processor. The Data Processing Agreement in the Wodzilla Terms applies to that relationship. If an athlete creates a Wodzilla account, POWERSPOT remains controller for that account while it may act as processor for results or content submitted to a professional organization.

2. Data we collect

We collect only the data needed to operate Wodzilla and provide the service.

  • Account data: email address, user identifier, display name, language, interface preferences, and Google profile picture if you use it.
  • Authentication data: technical information needed for sign-in, account security, email confirmations, password resets, and email address changes.
  • Content data: workouts, analyses, calendars, templates, folders, client records, results, scores, categories, avatars, notes, programming settings, branding, and sharing links created in Wodzilla.
  • Athlete and client data entered by a professional customer: name or alias, email, phone number, date of birth, address, avatar, category, notes, workout assignments, results, scores, RPE, and related group or client relationships, depending on the fields the customer chooses to use.
  • Workspace data: Team name, members, roles, invitations, seat capacity, and shared resources.
  • Billing data: plan, subscription status, Extra Energy purchases, Stripe customer identifiers, payment history, and billing information. Full card numbers are processed by Stripe, not by Wodzilla.
  • Technical data: IP address, user agent, server logs, security events, performance data, errors, usage analytics, and diagnostic information.
  • Support data: messages, feedback, support requests, and attachments you voluntarily provide.

3. Sources of data

Data mainly comes from you when you create an account, use the application, invite members, configure a workspace, create content, or contact Wodzilla.

Some data may also come from third-party services used for sign-in or payment, including Google OAuth, Supabase Auth, and Stripe.

4. Purposes and legal bases

We process account, content, and workspace data to perform the contract and provide Wodzilla; billing and tax data to perform the contract and meet accounting or tax obligations; security, diagnostic, and service-measurement data for our legitimate interests in protecting and improving the service; and support data to answer your request.

Where consent is legally required for an optional technology, that processing is based on consent and may be withdrawn without affecting prior lawful processing. We do not use Wodzilla data for third-party advertising and we do not sell personal data.

5. Google sign-in

If you choose to sign in with Google, Wodzilla uses Google OAuth to authenticate you. Access is limited to standard sign-in scopes: OpenID identity, email address, basic profile, and profile picture if available.

Wodzilla does not access Gmail, Google Drive, Google Calendar, or other sensitive Google data through this sign-in flow.

6. Artificial intelligence

When you deliberately use generation or analysis features, the instructions, workout content, language, and settings needed to perform the request are sent to OpenRouter and the selected model provider, currently including OpenAI models; a direct OpenAI connection may also be used depending on service configuration.

OpenRouter states that it does not retain prompt and completion content by default unless its customer has opted into logging. The selected underlying provider applies its own retention terms, and provider routing may evolve. Wodzilla does not promise zero-data-retention routing unless that safeguard is expressly enabled for the relevant request.

Do not include personal data that is unnecessary for the request, special-category or medical data, or confidential client records in AI prompts. Wodzilla is not designed to be a medical record. AI outputs must be reviewed by a competent coach before use.

7. Public sharing and workspaces

Some features let you create public links for workouts, calendars, or results. Anyone with the link may access the shared content while the link remains active.

In a Team workspace, shared content, calendars, libraries, and settings may be visible to authorized members according to their role. The Team owner or admins can manage certain accesses, members, seats, and resources.

A Team in payment recovery or the seven-day grace period is read-only. Existing public links may remain viewable during those states, but public submissions are disabled. An archived Team remains privately consultable by its members, while its public links are unavailable.

8. Recipients and processors

We do not sell personal data. Access is limited to authorized personnel, the professional customer controlling relevant client data, and the providers needed to operate Wodzilla.

The codebase supports optional Sentry or PostHog diagnostics, but those tools are not treated as active providers unless configured. This policy and any required consent mechanism must be updated before optional non-essential tracking is enabled.

  • Supabase, for authentication, database, file storage, and authentication-related transactional emails.
  • Vercel, for hosting, content delivery, technical logs, Web Analytics, and Speed Insights.
  • Stripe, for payments, subscriptions, invoices, billing details, and automatic tax calculation where applicable.
  • Google, for OAuth authentication when you choose Google sign-in.
  • OpenRouter and the selected underlying model provider, including OpenAI where applicable, for AI analysis and generation when you request those features.
  • YouTube, operated by Google, for optional movement tutorial playback when you choose to open a tutorial; privacy-enhanced embeds are used where available.
  • Competent authorities, advisers, or acquirers only where legally required or necessary to protect rights, handle a dispute, or complete a lawful corporate transaction.

9. Transfers outside the European Union

Some providers may process data outside the European Union. Where applicable, we rely on available legal mechanisms such as adequacy decisions, standard contractual clauses, or equivalent contractual commitments.

10. Retention

We keep account and content data while your account is active or as long as needed to provide the service.

  • Account and personal-space content is kept while the account is active, then deleted or anonymized following an account-deletion request, subject to the exceptions below. Content contributed to a Team workspace may remain with that workspace when a member leaves.
  • Unsaved Generator and Builder history is kept for up to 90 days. Workouts moved to Library Trash are permanently deleted after 15 days unless restored first.
  • Scheduled calendar workouts are kept for up to two years after their scheduled date, then removed from professional calendars. Results submitted through an authenticated athlete account may retain a limited workout and block snapshot in that athlete's private history; guest and coach-added results linked only to the expired calendar workout are deleted.
  • Successful analyses of pasted text are kept for up to 24 months. Failed or abandoned analyses are deleted after 30 days. Full generation request inputs and contexts are kept for up to 90 days, after which Wodzilla retains only limited technical metadata such as model, usage, cost, status, and dates.
  • A result hidden through moderation is permanently deleted after 30 days.
  • Public links remain available until the owner disables them or the related content, account, or workspace is deleted. An anonymized result may remain in a leaderboard after athlete-account deletion where the product explains this outcome.
  • Cancelling a Team subscription does not delete shared content. At the paid-period end the Team enters a seven-day read-only grace period and then a read-only archive. The archive remains until the owner reactivates it or explicitly confirms permanent dissolution.
  • Permanent Team dissolution deletes shared Team content and invalidates its public links. An authenticated Athlete submission may retain only the approved minimal workout and block snapshot in that Athlete's private history, with the Team link, branding, coach notes, public scope, and Team leaderboard context removed. Guest and coach-added results that exist only in the Team are deleted.
  • Minimal dissolution tombstones and financial, invoice, Energy-forfeiture, legal, and audit evidence may be retained where necessary. These records are minimized and do not preserve a usable Team workspace.
  • Minimal legal-acceptance evidence, such as a pseudonymous account identifier, account kind, document versions, locale, acceptance source, and timestamps, may be kept to establish, exercise, or defend legal claims and meet compliance obligations, generally for up to five years after the end of the relationship. It is then deleted or irreversibly anonymized unless a longer legal hold is required.
  • Invoices and accounting records are kept for the legally required period, generally ten years in France.
  • Technical logs, security events, and observability data are kept for a limited period proportionate to security, diagnostic, and maintenance needs.
  • Deleted data may remain temporarily in rolling backups or longer where needed for a legal obligation, fraud prevention, security, or a dispute, and is not restored for ordinary product use.

11. Security

We use reasonable technical and organizational measures to protect data, including secure authentication, access control, user and workspace data isolation, security logs, TLS, and secure development practices.

No online service can guarantee absolute security. You must use a strong password, protect your session, and share public links only with authorized people.

12. Your rights

Under GDPR and applicable laws, you may request access, rectification, erasure, restriction, objection, or portability of your personal data.

You can exercise your rights by contacting contact@wodzilla.app. We may request reasonable information to verify your identity. For data controlled by a coach, gym, or other professional customer, contact that organization first; Wodzilla will assist it as processor.

You may lodge a complaint with the French data protection authority, the CNIL (cnil.fr), or your local supervisory authority.

13. Account deletion

Wodzilla offers account deletion from account settings. Deleting an athlete account removes its public identity, email, name, and avatar from the athlete profile; results may be retained only in anonymized form. Deleting a professional account follows the content and workspace-ownership rules explained before confirmation.

A Team owner must resolve ownership or permanently dissolve owned archives before deleting the professional account. Team dissolution is a separate owner-only action that requires recent authentication and the exact confirmation shown in the product.

Some data may be retained where needed to comply with a legal obligation, resolve a dispute, ensure security, or keep accounting records.

14. Cookies and similar technologies

Wodzilla uses strictly necessary cookies for Supabase authentication and session security. Browser localStorage stores device-side preferences, language or view choices, drafts, library-navigation state, and similar continuity data; sessionStorage stores short-lived navigation or notification state.

On public result forms, a guest display name, category, and random submission key may be remembered in localStorage for up to 30 days after they are saved so the form can be reused. You can clear these items through the product where available or through browser settings.

Vercel Web Analytics and Speed Insights provide aggregated audience and performance measurement without advertising profiles. Wodzilla does not use advertising cookies. Any future non-essential measurement requiring consent will be disabled until the required choice is obtained.

15. Minors

A paid or professional Wodzilla account is for adults aged 18 or over. An athlete may create an autonomous account from age 16 and, when aged 16 or 17, must have parental or legal-guardian authorization where required. A person under 16 cannot create an autonomous account and may appear only in a profile managed by an authorized coach, responsible organization, parent, or guardian, with data minimized and preferably identified by an alias.

16. Changes

We may update this policy to reflect product, provider, legal, or practice changes. The version and effective date displayed at the top identify the applicable text; material changes will be brought to users' attention by an appropriate channel.

Privacy contact and controller address: POWERSPOT, 38 rue des Vallées, 92700 Colombes, France — contact@wodzilla.app.