Privacy Policy
Last updated: 8 August 2026
Overlood is a workout tracking app operated by Ruben Eppink, based in the Netherlands ("Overlood", "we", "us"). This policy explains what personal data we collect through the Overlood mobile app and this website (overlood.com), and what we do with it.
We are the data controller for the data described here. You can reach us at support@overlood.com.
The short version
- We collect what the app needs to work: your account and your training data.
- We run no advertising, no ad trackers, and no third-party analytics. This website sets no cookies.
- We never sell your data.
- Your data is stored in the European Union (Microsoft Azure, West/North Europe).
- Your training data is yours alone — nobody else on Overlood can see it.
Data we collect
Account and profile
- Email address and display name — needed to create and identify your account. Sign-in is handled by Auth0, our authentication provider.
- Optional profile details — date of birth, height, and biological sex. All optional; the app works without them. We store your date of birth rather than your age so it stays accurate.
- Photos — optional. The camera and photo-library permissions on your phone are used for setting a profile photo, attaching a photo to a custom exercise you created, and saving a workout share card to your camera roll — nothing else; the microphone is never used. Your profile photo and any custom-exercise photos are stored in your private file storage, where only you can see them. Saving a share card writes that image to your device only; the card is never uploaded or shared with us.
- Preferences — units, language, rest timer, and similar app settings.
- Notifications — optional. If you allow them, your phone shows a notification when a rest timer runs out, and a card with your current set while a workout is running. They are created on your device and never leave it: no push service, no server, nothing collected. Say no and the app works the same, and it won’t ask again; you can change it any time in your phone’s settings. On Android the app also declares two permissions that grant access to no data and that your phone never asks you to approve:
SCHEDULE_EXACT_ALARM, so a rest cue arrives at the second it is due, andPOST_PROMOTED_NOTIFICATIONS, so the workout card can show in the status bar and on the lock screen.
Training data
- Workouts — exercises, sets, weights, reps, effort ratings (RPE/RIR), timestamps, duration, and any notes you write. Timestamps are stored in your device's local time, and each set you tick off records the moment you ticked it, so rest times and how long an exercise took can be worked out later.
- Routines and programs you create or follow.
- Body metrics — bodyweight, body measurements, and body-fat entries, if you log them.
- Imported history — if you import workout history from another app (such as Hevy or Strong), we store the parsed workout data. The uploaded file itself is discarded once the import finishes. The import also records your device's timezone to date your workouts correctly.
Collected automatically
- Request logs — our servers record the method, path, response status, and duration of each API call, plus the app version and platform the mobile app reports so we know which versions are still in use. Each record also carries your account ID and a trace ID that the mobile app attaches to any crash report it sends, so one problem can be followed from your device to our server, together with the database calls that request made (timing only, never the data in them). When a request fails unexpectedly, the error and its stack trace are recorded with those same IDs. These records are kept for 30 days.
- Device and app details — when you first sign in from the mobile app, we store the platform (iOS or Android), the app version, your device language, and your device's timezone on your account, so we know which platforms and languages to support. The timezone is refreshed if your device reports a different one.
- Last active day — we record the day you last used the app (once per day, never the individual requests), so we can see how many people keep training with Overlood.
- IP address — used transiently for rate limiting (protecting the service from abuse).
- Crash reports (mobile app only) — if the app crashes, a crash report is sent to Sentry so we can fix the bug. This is active only in release builds, and we have configured it not to include personally identifying information.
Data we do not collect
- No advertising identifiers, ad networks, or marketing trackers.
- No third-party analytics (no Google Analytics, no Amplitude, or similar).
- No location data, no contacts, no health-platform data (Apple Health / Google Fit).
- No payment data — Overlood is currently free.
How we use your data
- To provide the service — storing and syncing your training data and powering your progress charts and personal records. Legal basis: performance of our contract with you.
- To keep the service secure and working — rate limiting, request logs, and crash reports. Legal basis: our legitimate interest in running a secure, reliable service.
- Anonymous benchmarks (opt-in only) — the app has a setting, off by default, to contribute your demographics anonymously to future strength benchmarks. Nothing is used for this unless you switch it on. Legal basis: consent, which you can withdraw at any time in the app.
We do not sell your data or use it for advertising.
Sharing
Your training data is private to your account. Other Overlood users cannot see your workouts, body metrics, or profile. If we ever add social or coaching features that share data between users, they will be described here before they launch.
Service providers
We use a small number of processors to run Overlood. They process data on our behalf and are bound by data-processing agreements:
| Provider | Purpose | Location |
|---|---|---|
| Microsoft Azure | Hosting, database, and file storage | European Union (West/North Europe) |
| Microsoft Azure Communication Services | Sending transactional email (such as the account-deletion confirmation) | European Union |
| Auth0 (Okta) | Sign-in and account authentication | United States |
| Sentry | Crash reporting (mobile app) | United States |
| Expo (EAS) | Delivering app updates | United States |
| Apple App Store / Google Play | App distribution | United States / European Union |
Where a provider processes data outside the European Economic Area, transfers rely on recognised safeguards such as the EU–US Data Privacy Framework or Standard Contractual Clauses.
Cookies
This website (overlood.com) sets no cookies and runs no trackers — that is why there is no cookie banner. The mobile app does not use cookies; it stores its sign-in tokens in your device's secure storage.
Retention and deletion
- Your account and training data — including the device details and last active day stored on your account — are kept for as long as your account exists, and are erased with it.
- After an account is erased we keep one anonymous statistics record — the date the account was created, the date it was deleted, whether it was a coach or an athlete account, and how many workouts it logged. It contains nothing that identifies you and cannot be linked back to you.
- Server request logs are deleted after 30 days.
- Abandoned photo uploads are cleaned up after 24 hours.
- You can delete individual records — workouts, body metrics, routines, programs, your profile photo, custom-exercise photos — directly in the app at any time.
- To delete your entire account and all associated data, use the Delete account option in the app's profile settings, or — without the app — the account deletion page on this site. Erasure is immediate and irreversible. You can also email support@overlood.com from your account's email address.
Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- correct inaccurate data;
- have your data erased;
- restrict or object to processing;
- receive your data in a portable format — the app includes an export of your full workout history as CSV or JSON;
- withdraw consent (for the opt-in benchmark setting) at any time;
- lodge a complaint with a supervisory authority — in the Netherlands, the Autoriteit Persoonsgegevens.
To exercise any of these rights, email support@overlood.com. We respond within one month.
Age
Overlood is not intended for children under 16. We do not knowingly collect data from anyone under 16; if you believe we have, contact us and we will delete it.
Security
All traffic is encrypted in transit (HTTPS). Data is stored on Microsoft Azure with access limited to what the service needs. Sign-in credentials are handled by Auth0 — we never see or store your password. On mobile, tokens live in your device's secure storage.
Changes to this policy
When we change this policy, we update the date at the top. For material changes — new data collected, a new provider, or new sharing — we will notify you in the app or by email before the change takes effect.
Contact
Ruben Eppink (Overlood), the Netherlands — support@overlood.com