Last updated: 25 August 2026
This policy is a translation. The French version, available at movriva.com/confidentialite, is the reference text and governs in the event of any discrepancy.
Movriva is a strength-training application that builds your sessions from what you have actually lifted.
Movriva is a trading name. The data controller is the person operating it: Léonard Sota, 42 rue des Marguerites, 91160 Longjumeau, France, reachable at contact-movriva@movriva.com and on +33 7 82 22 09 97.
The distinction is not cosmetic. The Regulation requires the controller to be identifiable, and a trading name is not: it is a sign, not a person. So this is the person you address to exercise your rights, and who answers for this document.
We collect nothing the application does not use. Every category below corresponds to fields that exist, and you can obtain their exact contents at any time (see section 7).
Email address, display name, address confirmation, language, time zone, unit system (metric or imperial).
Why: to identify you, to let you sign in, and to show the application in your language and your units.
Legal basis: performance of the contract between us.
A hash of your password — never the password itself — your active sessions with their IP address and device type, and the temporary tokens for address confirmation or password reset.
Why: to keep you signed in, and to detect abnormal access.
Legal basis: performance of the contract, and our legitimate interest in securing accounts.
Goal, stated experience level, sessions per week, duration per session, bodyweight.
Why: bodyweight is used to estimate a starting load when you have no history yet on an exercise. Without it, the application can propose nothing and leaves you guessing.
Optional, and requested only if you open the nutrition section. An account that does not use it never carries them: the columns stay empty, this is not a default value.
Why: to estimate your resting metabolic rate, on which any calorie intake depends. The reference formula requires weight, height, age and sex; without height and age there is no calculation, only a range that teaches nothing.
We ask for the year, not the date of birth: the formula uses only age in years, and an exact date would be a more identifying piece of data collected for no gain in accuracy.
A second use, this one protective: your year of birth lets us not calculate any calorie intake before the age of eighteen. The needs of a growing adolescent are read from paediatric curves, and an adult formula would give a wrong figure with the confidence of a right one.
You may remove them at any time; the estimate then stops, and nothing else changes.
The equipment you have, and the exercises or muscles you rule out, with the reason: plain dislike, equipment unavailable, discomfort felt, or instruction from a health professional.
Why: never to propose a movement you cannot or must not perform.
Those last two reasons are health data. They fall under Article 9 GDPR, which protects them more strictly. We ask for them only because an application that ignores a declared pain is dangerous, and they serve only to rule out exercises — never to profile, never to transmit.
Legal basis: your explicit consent, collected through a separate tick box at the moment you declare discomfort or a medical instruction. It is never pre-ticked, and without it we refuse to record these reasons — the refusal is enforced by our server, not only by the screen.
You may withdraw this consent at any time from your profile. Withdrawal deletes the exclusions concerned at the same time: keeping a declared discomfort after a withdrawal would mean processing health data with no legal basis. Your other exclusions — dislike, equipment unavailable — remain: they say nothing about your condition.
We keep the date of your consent and the version of this text you accepted, because Article 7 requires us to be able to demonstrate it. Withdrawal erases both: there is nothing left to demonstrate once we no longer hold the data.
Generated programmes, prescribed exercises, sessions started and finished, sets with load, repetitions, duration or distance, perceived difficulty out of five, reported discomfort, personal records, and the free-text notes you write.
Why: this is the substance of the service. Progress is calculated from these figures, and without them the application can only repeat the same session.
A caution about free-text notes: they belong to you and we do not analyse them, but everything you write there is kept there. Avoid recording detailed medical information in them.
The history of your weight, with the date and the origin of each reading.
Why: to display your curve and to adjust load estimates.
If you enable them: your device's notification token, its platform, your schedule and quiet-hours preferences, and the record of notifications sent.
Why: to remind you of your sessions at the times you chose, and not to send you the same thing twice.
Legal basis: your consent, withdrawable in the settings or from your phone.
The text produced after a session and — when it comes from a language model — the model's name, the number of tokens consumed and the response time.
Why: not to pay twice for a text already produced, and to track the cost of the service.
The state of your subscription: the store it came through, whether it is a trial or a paid period, its expiry date, and the identifier of the event that told us.
Why: to know whether you are entitled to train, and to show you until when.
Legal basis: performance of the contract between us.
We never see your means of payment. No card number, no bank identifier, no billing address: the purchase concludes entirely with Apple, Google or our subscription-management provider, and we receive only the result — "active until such a date". This is a consequence of how app stores work, and it is to your advantage.
We pass it only to the providers necessary to run the service, and to them alone.
| Provider | What it receives | Why |
|---|---|---|
| Railway | all data, as the hosting provider | to host the application, the database and the media files |
| Resend | your email address and the content of the message | to send address confirmation, password reset, the warning before an inactive account is deleted, and the weekly recap |
| Expo, then Apple or Google | your device token and the text of the notification | to deliver notifications to your screen |
| Microsoft (hosted in the EU) | an encrypted copy of the database, in our SharePoint space | to keep a backup outside our hosting provider |
| OpenAI (if enabled) | the figures of your session, with no identifier | to write the session summary |
| Sentry (hosted in the EU) | the technical context of an error | to fix failures |
| RevenueCat | your internal identifier, and your subscription state | to manage subscriptions and notify us of their changes |
| Stripe (web subscription) | your email address, your card data, your country | to take payment, calculate VAT and send you the receipt |
| Apple or Google (app) | what the store itself handles of your purchase | to take payment and renew the subscription |
This point deserves detail, because it worries people, rightly.
When the feature is enabled, only the following leave: the type of session, its duration, the number of sets and repetitions, total tonnage, the muscles worked, the difficulty you reported and any records. Not your name, not your address, no identifier at all — an automatic check inspects the payload before sending and blocks anything resembling an identifier or an email address.
Your body measurements are not included, although nothing required that. A training summary talks about training.
The content of your free-text notes is never transmitted.
If this feature is not enabled, the summary is computed by us, from your figures alone, and nothing leaves.
RevenueCat, a company incorporated in the United States, acts as intermediary between the app stores and our server. It receives your internal identifier — a string of characters with no meaning outside our database, neither your name nor your address — and whatever the store passes it about the transaction: product purchased, currency, expiry, trial or not.
The collection of device identifiers for advertising networks, which its library offers and enables by default, is explicitly disabled in our code. We use no attribution network.
This provider hosts its processing in the United States. It is the only one on the list in that position, and section 5 explains what that implies.
Subscribing from a browser goes through Stripe, which RevenueCat uses to collect. You give it your email address, your card details, and your billing country — the last because the VAT rate depends on the customer's country, not ours.
We never see your card number. The payment form does not belong to the application: it is displayed and encrypted by Stripe, and our servers receive nothing from it. What comes back to us is what section 4.2 describes — a subscription is active, until such a date. That is all the application needs in order to grant you access, and therefore all it asks for.
Subscribing from the installed application does not go through Stripe but through Apple or Google, depending on the store it came from.
In Europe, in the Netherlands (Amsterdam), with our host Railway: the database, the cache, the application and the media files. Nothing you record — sessions, sets, measurements, notes — leaves the European Union.
The exceptions concern payment, and they stop there.
RevenueCat processes in the United States. What it receives is described in section 4.2: your internal identifier and your subscription state, without your name or your address. That transfer is covered by the European Commission's standard contractual clauses.
Stripe contracts in Europe — its Irish entity — and may transfer to the United States for matters within its group. That transfer is covered by its data processing agreement and the same standard contractual clauses.
Neither of these two exceptions concerns your training. Your sessions, your sets, your records and your measurements do not leave the European Union.
Microsoft is not one of them either. An encrypted copy of the database is placed several times a day in a SharePoint space we control, in a tenant located in the European region. That copy exists for one reason: to be able to give you your data back if our host lost it. It is encrypted before being sent, and the key is known only to us — Microsoft stores a file it cannot read.
Sentry is not one of them. Error reports are stored in the service's European region. Their content is limited to the technical context of a failure: not your email address, not your IP address, and none of the data you entered. Your account identifier accompanies the report, and it alone — without it, there would be no way to tell whether a failure affects one person or everyone.
The app stores — Apple, Google — and the notification services also process outside the Union as regards their own part, under their own policies, which we do not control.
Twenty-four months without signing in, then deletion. After that period, your account and everything attached to it are erased automatically.
You are warned by email thirty days beforehand, and simply signing in cancels the deletion: the counter restarts from zero.
Why two years and not one: strength training stops and starts again. An injury, a move, a child, and you come back a year later wanting to find your records — that is the very point of a history. One year would delete precisely those people, at the moment the application becomes useful to them again.
The rest is bounded more tightly:
| Data | Duration |
|---|---|
| Notification delivery receipts | 24 hours |
| Sign-in sessions, and the IP addresses they carry | 7 days |
| Log of administrative actions on the catalogue | 3 years |
| Everything else | until the account is deleted |
We have no accounting obligation to retain: we issue no invoices, it is the app stores that collect payment and keep theirs. Nothing therefore obliges us to keep your data beyond what is written above.
You may of course delete your account at any time, without waiting (section 7.2).
The GDPR gives you rights that the application applies directly, without your having to write to us.
Profile → Export my data. You immediately obtain a file containing everything we hold about you, in a machine-readable format. Exercises are named rather than given as internal identifiers, so that the file remains understandable outside the application.
One exception: your devices' notification tokens are not included. They are technical secrets, and copying them into a file you then share would be a risk with no benefit.
Profile → Delete my account. Your password is required: this is the only irreversible action in the application, and an accidental tap must not be enough.
Deletion is physical and immediate. Sessions, sets, programmes, records, body measurements, preferences, device tokens and summaries disappear along with your account's row. There is no grace period and nothing is kept "just in case".
One exception, which concerns administrators only: if you have modified the shared catalogue, the log of those actions retains the email address used at the time of the action. Deleting your account is a right; erasing the trace of what that account did to a common catalogue is not, and published media remain online.
Goal, level, rhythm, equipment, exclusions, weight and units can be changed at any time from your profile. For any other request — rectification, restriction, objection — write to contact-movriva@movriva.com. We reply within one month.
You may also refer the matter to the data protection authority of your country. In France, that is the CNIL.
What the application does, in concrete terms:
No system is impregnable. In the event of a breach likely to result in a risk to your rights, we will inform you and the competent authority within the time limits set by the GDPR.
Movriva is not intended for people under sixteen and we do not knowingly collect their data. If you hold parental authority and find that an account has been created by a minor, write to us: we will delete it.
Movriva proposes exercises and loads on the basis of figures. It is not a medical device, and nothing in the application constitutes a diagnosis or a treatment. Recovery indications are estimates, not physiological measurements. In the event of pain, injury or doubt, consult a health professional — and declare the exercise concerned in your exclusions so that it is no longer proposed to you.
Any substantial change to this document will be signalled to you in the application before it takes effect. The date at the top indicates the latest version.