Last updated: August 1, 2026
Perside is a strength-training app operated by William Ye, an individual doing business as PerSide, located in Pennsylvania, United States. You can reach me at support@getperside.com. Because Perside is run by one person, this policy is written in the first person: "I" means William Ye, and "Perside" means the app at https://getperside.com.
This policy tells you what data Perside stores, why, where it lives, and how to get it removed. I have tried to make it exact rather than reassuring. If anything here is unclear, email me.
Your account. Your email address, the date your account was created, the date your email was verified, and a random internal user ID. The database has columns for a name and a profile photo, but Perside never asks for them and never fills them in. They stay empty.
Your training setup. The implements you own (types and weights), the movements you have told the app you are proficient in, and the names you give your programs.
Your training log. For each session: the sets, reps, and weights the engine prescribed, what you actually completed, the weight lifted, how long the session took, and the date. Perside also keeps every planned training day, including days you rescheduled or skipped. Taken together, these records show when you trained and when you did not.
Optional fields you may choose to fill in. These are the most personal things Perside holds, so I want to be specific:
One onboarding record. When you sign up, Perside records whether you took the "guided" or "veteran" onboarding path. This is stored permanently. No product feature reads it. I keep it so I can see, in aggregate, which signup path people take. That is the only measurement of this kind in the app.
Perside does not collect device fingerprints, location data (beyond what an IP address implies), contacts, photos, or anything from other apps or sites.
Some of what you can log in Perside describes your body and how it feels: effort ratings, the pain flag, tests taken to muscular failure, and anything you choose to write in a note. Depending on where you live, the law may treat some of this as health data. Rather than argue about labels, here is the position:
Perside sets no analytics or advertising cookies. None. The complete list of what it puts on your device:
| Name | What it holds | Lifetime |
|---|---|---|
ft_onboarding | Your email address and your draft program, stored as readable JSON on your device (it is httpOnly and sent only over HTTPS in production, but it is not encrypted). Deleted early when you create an account. | 48 hours |
| Session token | An encrypted token holding your email and user ID, so you stay signed in. | 30 days |
| Callback URL cookie | Where to send you after sign-in. | Until you close your browser |
| CSRF token | Protects the sign-in form from forgery. | Until you close your browser |
localStorage.theme | Your light or dark mode choice. Never leaves your device. | Until you clear it |
flowtracker:…-dismissed | Which one-time hints (the cycle intro, the veteran build hint) you have dismissed, so they do not reappear. Never leaves your device. | Until you clear it |
Because there is no cross-site tracking of any kind, browser signals like Do Not Track and Global Privacy Control do not change anything: there is no tracking for them to turn off, and no sale or sharing for them to opt you out of.
That is the complete list. Perside makes no other outbound network calls: no analytics provider, no payment processor, no ad network, and nothing that tracks you across sites.
Perside is operated from the United States, but the database is in Canada. If you are in the US, this means your data is stored outside the US. If you are in the European Economic Area or the UK, your data is transferred to the US (Vercel for hosting, and Sentry for crash reports) and to Canada (Supabase for the database). The European Commission has recognized Canada as providing adequate protection, but only partially: the decision covers commercial organizations subject to Canada's federal private-sector privacy law (PIPEDA). For transfers not covered by an adequacy decision, I rely on the data processing agreements offered by these providers, which incorporate the European Commission's standard contractual clauses.
That is the whole list. If you are in the EEA or UK, the legal bases are: performance of our contract (your account and training data), legitimate interest (rate limiting and security), and your consent for the optional fields described above. Every account confirms, by ticking a box, that they understand training data is stored including effort ratings, pain flags, and notes, and the date and time of that agreement is recorded. Existing accounts are asked the same thing the next time they open a page that shows their data. That consent is not a substitute for judgment: I still ask you to keep medical information out of the app, which is not built to be a medical record.
Honestly: your account and training data are kept until you ask me to delete them. There is no automatic expiry on them today.
Rate-limiting records and expired sign-in tokens are swept whenever someone requests a sign-in link: records past their window and expired tokens are deleted then. Because that sweep is triggered by sign-in traffic rather than a fixed schedule, a record created just before a quiet stretch can outlive its cutoff until the next sign-in request arrives. The onboarding cookie expires after 48 hours, the session cookie after 30 days, and each sign-in token is deleted the moment it is used.
There is no delete-account or export button in the app yet. Both are done by hand. Email support@getperside.com from the address on your account and tell me what you want:
I honor these requests from anyone, anywhere, regardless of whether a particular law requires it. If you are in the EEA or UK you also have the right to object to or restrict processing and to complain to your local supervisory authority. If you are a California resident, you will not be discriminated against for exercising any request, and Perside does not sell or share personal information as those terms are defined in California law.
Data is encrypted in transit. Separation between users is enforced by the application code. The database is hosted by Supabase and is reachable over the internet by anyone holding its credentials; those credentials are held only by me and by the deployed app. To be precise, Perside does not use database-level row security, because the app's database role would bypass it anyway; the isolation guarantee lives in the application layer. No system run by one person, or by anyone, is perfectly secure, and I will not pretend otherwise. If I learn of a breach affecting your data, I will notify you as the law requires.
Perside is for adults. You must be 18 or older to use it, and I do not knowingly collect data from anyone under 18. If you believe a minor has an account, email me and I will delete it.
If this policy changes in a way that matters, I will update the date at the top and, for significant changes, note it in the app or by email. The current version always lives at https://getperside.com.
William Ye, doing business as PerSide
Pennsylvania, United States
support@getperside.com