1. Scope
This Privacy Policy explains how JLD collects, uses, stores, and shares information when you use the JLD mobile application and related services.
JLD is a fitness logging product, not a medical service or medical device. JLD is intended only for people aged 18 or older.
2. Information We Collect
Account And Authentication
We collect your email address, an internal JLD user identifier, authentication-provider identifiers, and session information needed to create, secure, and recover your account. Authentication is provided through WorkOS. If you choose Sign in with Apple, Apple and WorkOS process the information required for that sign-in method.
JLD does not require a phone number. Authentication services also process technical information, such as IP addresses, browser or device details, and sign-in activity, to operate and secure sign-in.
Profile And Onboarding
We collect the information you provide to configure the app, including your display name, age eligibility and age range, sex, height, starting bodyweight, training experience, goals, available equipment, schedule, measurement preferences, language, country, timezone, and health or training limitations. Your country and timezone are profile settings, not GPS location. We also keep your onboarding answers and records of consent choices. Body measurements and training limitations can be sensitive health information.
Workouts And Progress
We collect workout plans, sessions, exercises, sets, repetitions, weight, duration, distance, RIR or RPE, rest periods, notes, personal records, progression choices, and related training history. We also collect daily completion, streak, and weekly-summary records derived from your logs.
For workout synchronization, the app creates a persistent random installation UUID. JLD transmits and retains this identifier with your account to identify which app installation owns an active workout session, detect conflicts, and keep workout changes synchronized safely. It is not a hardware identifier or advertising identifier, and JLD does not use it for tracking.
Nutrition And Body Data
We collect nutrition targets and the daily calorie, protein, carbohydrate, and fat totals you enter. We collect bodyweight and optional body-fat, soreness, energy, and check-in notes when you choose to provide them.
Apple Health
If you choose to connect Apple Health, JLD requests read access only to step count and, separately, bodyweight. JLD does not request permission to write to Apple Health.
When you import Apple Health data, JLD stores an effective daily step total or eligible bodyweight value in your JLD account, together with limited import metadata. JLD does not store every raw HealthKit sample. You can use manual steps and bodyweight entry without connecting Apple Health, and you can manage HealthKit permissions in Apple's Health or Settings app.
Stack And Protocols
We collect the supplements, medications, peptides, or other items you choose to track, including names, categories, doses, schedules, protocols, reminders, adherence, and notes. JLD records this information for logging and reminders; it does not prescribe, diagnose, or recommend treatment.
Notifications
We collect notification preferences and delivery or interaction records needed to schedule reminders, prevent duplicates, respect quiet hours, and maintain notification history. Sensitive Stack reminders use private notification text. The current app schedules notifications locally on your device; it does not use a remote push-delivery service.
Product Usage And Diagnostics
We collect limited first-party product interaction events to understand onboarding, daily logging, workout usability, reminders, weekly summaries, and exports. These events may be linked to your JLD account but do not contain raw Apple Health samples, exact bodyweight, Stack item or medication names, doses, private notes, or full workout-set payloads.
When the app catches a handled interface failure, it may send JLD a bounded technical diagnostic linked to your account. This record contains only an error category, app area, non-content fingerprint, severity, platform, app and build version, release channel, time, and an optional server request identifier. JLD does not transmit the raw error message, stack trace, screen URL, user-entered content, health values, Stack details, tokens, or request bodies through this reporting path. JLD does not include a separate crash-reporting SDK in this release. Apple may separately provide developer diagnostics according to your Apple device settings and Apple's policies.
Our hosting and network providers also process connection metadata, such as IP addresses, request times, and technical request details, to deliver and secure the service. These infrastructure records are separate from the app's restricted diagnostic payload.
Exports
JLD can prepare PDF reports and image summaries. The rendered export file is created on your device and is not uploaded or retained by JLD. JLD stores the privacy-filtered source snapshot and export audit metadata used to prepare it. Stack names, doses, schedules, protocols, and notes are excluded from exports, although an aggregate adherence summary may be included. Recipients you choose may retain their own copies.
Website And Support
When you visit getjld.com, the hosting and security providers process technical connection information needed to serve and protect the pages. Our support and policy pages do not embed advertising or analytics scripts.
When you email support@getjld.com or privacy@getjld.com, we receive your email address, message, and any attachments you send. Cloudflare routes inbound messages to a Google Gmail inbox managed by the operator. Please do not send passwords, sign-in codes, or unnecessary medical details. Email forwarding is not end-to-end encryption. Replies may come from the operator's Gmail address.
Information Stored On Your Device
JLD keeps local account data, cached records, preferences, and pending changes so that logging can work during connectivity interruptions. Authentication credentials use the operating system's secure storage. Records already downloaded or exported may remain on devices or with recipients until removed there; disconnecting Apple Health does not automatically erase values previously imported into JLD.
3. How We Use Information
We use information to:
- Authenticate and secure your account.
- Provide workout planning, logging, progress, nutrition, steps, bodyweight, Stack, reminders, summaries, and exports.
- Sync your records across devices and recover pending changes.
- Identify the app installation that owns an active workout session and prevent conflicting workout updates.
- Calculate user-facing completion, trends, PRs, and rules-based recommendations.
- Maintain reliability, prevent duplicate writes or notifications, diagnose failures, and protect the service.
- Understand coarse product usage and improve JLD.
- Deliver the public website and respond to support and privacy correspondence.
- Process account deletion and other privacy requests.
- Comply with applicable law and enforce service security.
JLD does not use your information for advertising, does not sell your information, and does not use health, fitness, workout, nutrition, Stack, or body data for cross-app or cross-site tracking.
Where applicable law requires a legal basis, ordinary account and service processing is based on providing the service you request; proportionate security and service improvement may rely on legitimate interests, subject to your rights; and legally required processing relies on the relevant legal duty. Consent is used where required, with an additional lawful condition for sensitive health data. Agreement to the Terms is not a substitute for explicit consent or a regulatory permission required for health-data processing.
JLD's estimates and progression suggestions are rules-based fitness aids. They do not make decisions about access to employment, insurance, credit, healthcare, or other similarly significant matters.
4. Health And Fitness Data Commitments
JLD uses HealthKit-derived data only to provide health and fitness functionality to you. It is never used for advertising, marketing profiles, or data-broker activity. JLD discloses HealthKit-derived data only with your express permission and only to processors acting on JLD's instructions to deliver JLD's bona fide health and fitness service. Any disclosure must also be permitted by applicable law and Apple's rules.
JLD is not a substitute for professional medical advice. Tracking an item or protocol does not mean JLD considers it safe, effective, or appropriate for you.
5. Service Providers
JLD uses service providers to operate the product:
- WorkOS for authentication and account identity: https://workos.com/legal/privacy.
- Railway for API and database hosting: https://railway.com/legal/privacy.
- Apple for HealthKit, optional Sign in with Apple, App Store distribution, and device services: https://www.apple.com/legal/privacy/.
- Expo Application Services for mobile build, signing, and submission workflows: https://expo.dev/privacy. Build tooling is not itself a recipient of your workout records.
- Cloudflare for the public website's delivery/security and inbound email routing: https://www.cloudflare.com/privacypolicy/.
- Google for the operator's support and privacy email inbox: https://policies.google.com/privacy.
- GoDaddy for domain registration and DNS administration; it is not the JLD workout database: https://www.godaddy.com/legal/agreements/privacy-policy.
Providers receive information relevant to their service. Providers acting as our processors must follow the applicable processing arrangements; some providers also process service-security or account information for their own purposes under their notices. We may disclose information when required by law, to protect legal rights and service security, or to recipients you authorize. We do not give every provider access to every category of app data.
6. Retention
We retain account and product records only for as long as needed to provide JLD, meet security and legal obligations, and resolve deletion or integrity operations.
The following retention rules apply:
- Active account data: while your account remains open and the records are needed to provide your history and the service, until you delete the relevant records or your account, subject to limited legal or security needs. Inactivity alone does not currently trigger automatic deletion.
- Product analytics and bounded client diagnostics: eligible for deletion after 90 days from their event timestamp. The cleanup runs at startup and normally every 6 hours; failures may delay completion.
- Operational and security logs: our current hosting plan makes the last 7 days of logs available to us. Provider-held connection, authentication and security records may remain longer where needed to operate services, investigate abuse, resolve disputes or meet legal obligations, according to the relevant provider notices linked above. The log viewing window is not a guarantee of physical deletion from provider systems.
- Pending deletion requests: kept until the deletion process finishes, including the account references and limited retry information necessary to complete it.
- Deletion protection: a one-way hash of the authentication-provider user ID is retained for the lifetime of that identity system to prevent delayed requests from recreating a deleted account. It contains no email, workout records, or other product content. This pseudonymous identifier is not the same as deleting every trace of the account.
- Deletion confirmation: a separate, unlinked hash of a random recovery receipt, completion status and time, and random record ID are retained for the lifetime of the service so a device can confirm deletion after a lost response. The completed record contains no account identity and can be retrieved only using the original receipt.
- Database backups: JLD does not currently operate scheduled database backups. We will update this policy with the applicable retention period if we introduce them. Provider-held recovery or security copies, where applicable, are governed by the relevant provider's retention practices.
- Support and privacy correspondence: we keep correspondence for 12 months after a case is closed, and only a minimal record of privacy-request handling for 24 months after closure. The operator manually reviews records each month and removes those whose retention period has ended. Deletion can therefore take until the next monthly review; Gmail messages moved to Trash normally remain recoverable for another 30 days. Necessary records may be kept longer for a documented legal or security need. We remove unnecessary sensitive attachments sooner, when their immediate purpose ends.
When you delete your account, JLD removes associated active product records, including the linked workout installation UUID, subject to the limited records described above and any applicable legal obligation. Deletion may take longer when a service dependency is unavailable. Deleting active records does not guarantee immediate physical removal from all provider recovery or security copies. If records are recovered, we will reapply applicable deletion requests before returning those records to active service.
7. Account Deletion And Your Choices
You can initiate deletion from Settings > Account > Delete Account. JLD asks you to confirm the irreversible request, revokes active access, and deletes or anonymizes associated data. A support email is not required to begin deletion.
You can also:
- Decline or revoke Apple Health access and continue with manual logging.
- Disable notification categories or all notifications.
- Use private notification text.
- Disable progression suggestions.
- Choose whether and with whom to share a locally rendered export. JLD cannot recall a copy already sent to someone else.
- Request access to or a copy of your personal information, correction, deletion, restriction, portability, objection, or withdrawal of consent where the laws that apply to you provide those rights, by contacting privacy@getjld.com.
Withdrawal does not make earlier lawful processing unlawful. It may prevent the affected optional feature from working; previously stored records are not automatically erased merely by revoking a device permission. You may request their deletion separately. We do not describe limited product analytics as opt-in because the current app has no analytics opt-out control.
We may ask for proportionate information to verify that a request concerns your account, preferably through your existing sign-in or registered email. Do not send identity documents unless specifically needed and a suitable secure method has been arranged. We respond within the deadlines required by the law that applies to your request and explain any lawful refusal or extension. You may complain to your competent data-protection authority, including Qatar's National Cyber Security Agency where applicable, without first contacting us.
8. Security
JLD uses safeguards designed to protect information, including encrypted network transport, secure mobile token storage, authenticated user-scoped API access, database access controls, idempotent sync writes, and provider-supported encryption at rest. No method of storage or transmission is completely secure.
If a personal-data incident requires notice, we will notify the relevant authority and affected people as required by applicable law. Report a suspected privacy or security problem to privacy@getjld.com. Do not include passwords or security tokens in the report.
9. International Processing
JLD is operated from Qatar. Our API and database are hosted in Amsterdam, Netherlands. Authentication, website delivery, email routing, support mail, provider support, and subprocessors may involve other countries, including the United States. A database hosted in Europe does not mean all processing stays in Europe. These countries may have different data-protection laws. Where applicable law requires safeguards for an international transfer, we use the applicable lawful transfer mechanism, such as contractual protections. You can contact privacy@getjld.com for information about the safeguards relevant to your data.
10. Age Restriction
JLD is for adults aged 18 or older. We do not knowingly offer JLD to children. If you believe a person under 18 has provided information, contact privacy@getjld.com so we can investigate and take appropriate action.
11. Changes To This Policy
We may update this policy when JLD's practices or legal obligations change. We will publish the effective date and policy version and request renewed consent when required.
12. Contact
Questions or privacy requests can be sent to:
Mohammed Al-Sulaiti, Qatar privacy@getjld.com