Privacy Policy
Last updated: October 8, 2026
Ninja Train is operated by DailyMind LTD, a company registered in Cyprus under registration number HE 439959. This policy explains how we handle personal data when you use Ninja Train at https://ninjatrain.app/.
DailyMind LTD is the data controller for personal data processed by Ninja Train.
1. Data We Collect
Account Data
When you sign up, we store your email address and display name. Sign-in uses one-time email links, so we store no password. This is the minimum needed to identify your account and protect your training data.
Training Data
We store the exercises you add to your programme, your logged training sessions (sets, reps, hold time, weight, rest), and your streak count. This data is yours — it powers your progress tracking.
Health Data (Discomfort Ratings)
Discomfort ratings (0–10) are health data under GDPR Article 9. We store them only after you give explicit consent in Settings → Discomfort tracking. Without consent, sessions are saved without a rating. You can withdraw consent at any time in Settings; withdrawing erases your stored ratings. Withdrawal does not affect processing before it.
Technical Data
The website is served through Cloudflare. Cloudflare may process standard technical logs such as IP address, user agent, request URL, timestamps, and security events for delivery, security, and performance.
We use a privacy-friendly Umami analytics counter. Umami tracks page views, referrers, device and browser type, and country-level location. It does not store training data or email addresses, and is not used for advertising or cross-site tracking.
We use Cloudflare Turnstile for bot verification on the login form. Turnstile processes browser signals to determine if a visitor is human. It does not require cookies and does not track you across sites.
2. How We Use Data
- To let you sign in, track exercises, log training sessions, and view your progress.
- To understand minimal site usage after analytics consent, such as page views and basic events.
- To keep the site available, secure, and performant.
- To detect and prevent abuse.
3. Legal Basis
- Contract performance — to provide the exercise tracking service you use.
- Explicit consent (GDPR Art. 9(2)(a)) — for storing discomfort ratings, which are health data.
- Consent — for analytics cookies and optional features.
- Legitimate interest — for security, debugging, abuse prevention, and service reliability.
- Legal obligation — where we must keep or disclose information to comply with law.
4. Sharing
We do not sell personal data and do not use personal data for ad monetization. We share data only when necessary with:
- Cloudflare for hosting, CDN, security, and bot verification (Turnstile).
- Umami (self-hosted) for privacy-friendly website counters.
- Paddle as merchant of record for payment processing, if you purchase a paid plan.
- Authorities or professional advisers if required for legal compliance, security, or dispute handling.
We do not use Ninja Train data to track you across apps or websites owned by other companies for advertising purposes.
Where a service provider processes personal data for us, we rely on appropriate data processing terms and contractual safeguards. If personal data is transferred outside the EEA, we use legally available transfer mechanisms such as standard contractual clauses where required.
5. Local Storage
Ninja Train uses localStorage in the browser for your auth token and UI preferences. Essential storage is used for session management and remembering your cookie choice. You can delete local data by clearing site data for ninjatrain.app in your browser or using the app's sign-out function.
6. Retention
- Training data and programme data remain until you delete your account or request deletion.
- Discomfort ratings are kept until you withdraw consent or delete your account.
- Cloudflare logs are retained according to Cloudflare's operational policies.
- Umami analytics events are retained according to our product reliability needs (typically 24 months).
- Payment records via Paddle are retained according to Paddle's policies and legal accounting requirements.
7. Security
We use HTTPS, one-time login links, and minimal server-side data exposure. Personal data is accessible only to people who need it to operate, debug, secure, and support Ninja Train. Browser storage is controlled by your browser and device.
If we become aware of a personal data breach, we will investigate, mitigate it, and notify affected users or regulators where required by applicable law.
8. Your Rights
Under GDPR, you may have rights to access, rectify, erase, restrict, port, or object to processing of your personal data. You may also withdraw consent where processing is based on consent.
You may request access, correction, deletion, restriction, portability, or objection by contacting us.
You may also have the right to lodge a complaint with a data protection supervisory authority.
9. Children
Ninja Train is not directed to children under 16, and we do not knowingly collect personal data from children.
10. Medical Disclaimer
Ninja Train is an exercise tracking tool, not a medical device. I'm not a doctor — the exercises in the catalog are based on general rehabilitation protocols. You are responsible for consulting your physiotherapist or doctor before starting any exercise programme. If something hurts beyond normal exercise discomfort, stop and seek professional advice.
11. Changes
We may update this policy from time to time. The updated date above shows the current version.
12. Contact
DailyMind LTD
Aglantzia, Kythiron 8, Apartment 204
Nicosia, 2103, Cyprus
Registration number: HE 439959
VAT: CY10439959M
Ninja Train: [email protected]