Loading...

Privacy Policy

Last updated: October 7, 2026

1. Introduction

PRzilla ("we," "our," or "us") provides a web and mobile application for tracking CrossFit workout scores and progress. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data.

2. Information We Collect

Account Information

When you create an account, we collect your email address and name. If you sign in with Google or Apple, we receive this information from your identity provider. We also generate a unique user ID for your account.

Workout Data

We collect the workout data you enter, including WOD scores (time, reps, load, rounds, distance), movement and lift logs, session dates, and any notes you add. This data is linked to your account so you can track your progress over time.

Workout Export Files (Optional)

If you ask us to import history from another workout app, you can select and upload that app's export file. Depending on the source, the file can contain workout names and descriptions, dates, scores, reps, loads, times, fitness or health metrics, notes, and account or location fields included by the source app. The file is linked to your signed-in PRzilla account and read only to complete the import you requested. We retain it so we can correct or rerun that import. You can ask us to delete it at any time by emailing hello@przilla.app.

Affiliate Report Data

With a CrossFit affiliate's approval, we may import workout programming and member results from that affiliate's SugarWOD account to create an affiliate report. Imported data can include member names and SugarWOD identifiers, workout dates and descriptions, divisions or scaling choices, scores, and result units, including member-entered notes attached to those results. These reports are separate from PRzilla accounts.

Profile and Training Preferences

If you add them to your profile, we collect your gender, date of birth, body weight, preferred weight and distance units, and weekly training-day target. These values are linked to your account and used to personalize workout displays, progress features, and AI coaching. AI prompts receive your completed age rather than your exact date of birth.

Leaderboards and Community Scores

Global leaderboards may rank your workout totals, benchmark fitness, improvement, consistency, and catalog activity. Signed-out viewers see anonymous per-board handles, never your name or email. Signed-in viewers may see your first name and last initial when name sharing is enabled. On eligible benchmark WODs, Community Scores show anonymous qualifying scores to signed-out visitors, without names or country flags. Signed-in viewers may also see that shortened name and your selected country flag beside your score. You can turn off name sharing in Settings to use an anonymous handle instead. You can add, change, or remove a country flag independently. The app may initialize that flag once from the country or region in your device locale. For existing accounts, it may instead use the approximate country PostHog associated with the account's first analytics activity. The flag stores only a two-letter country code. Your preference and selected country code are stored with your account for app functionality and are not used for advertising or cross-app tracking. If you choose to share your public athlete profile, signed-in PRzilla athletes who tap your name on a leaderboard or in Community Scores can also see your bio and social handle (if you add them), your profile photo (only if you separately share it), your age (only if you are 18 or older), gender, country, join date, the date of your first logged session, completed-session count, Fitness Level, estimated one-rep maxes and the sets behind them, best Rx benchmark results, and skill records, with the dates you set them. The profile stays private until you share it, is never shown while your name is hidden, and can be turned off in Settings at any time. It never includes your email, date of birth, notes, or health data.

Daily Check-Ins (Optional)

If you log how you feel, PRzilla stores your daily mood, soreness, and optional note with your account. Recent check-ins, including note text, may be processed by AI model providers when AI Coach generates or refreshes your automatic daily briefing, or when you chat with Coach, so its response can account for what you reported. Product analytics include the mood and soreness ratings, where the check-in was opened, and whether a note was provided, but never the note text. This data is not sold or used for advertising.

Workout Photo Scans (Optional)

If you use Scan photo on the web or mobile app, the image you select or capture is sent to PRzilla for analysis by Google Gemini or, for the OCR path, Google Vision. If you are signed in, the request is linked to your account. The scan service does not save the original image. You can review the result before saving a workout. Images shown on the web page may be included in Sentry session replay as described below.

Roadmap Screenshots (Optional)

If you attach a screenshot to a feature request on the web, we store it with that request and show it on the public Roadmap. The app attempts to delete the stored image when you remove or replace it, or delete the request. If storage cleanup fails, the public file may remain accessible after it disappears from the Roadmap.

Profile Photos (Optional)

If you choose or take a profile photo in the mobile app, we store it with your account until you replace or remove it. If you sign in with Google, Google may also provide a profile image URL that we save with your account. Your photo appears on your public athlete profile only if you separately turn on Share profile photo in Settings; otherwise viewers see your initials. Photos you upload are re-encoded on our servers, which removes location and camera details.

AI Coach Images (Optional)

If you attach an image to AI Coach chat, we send it with your account-linked request to an AI model provider to answer your message. Our server stores an attachment marker in the chat history, not the image. After a successful request, the mobile app also saves a copy in its Documents directory so the chat can show it again. The app does not currently delete that copy when the conversation ends; it can remain until app data is removed. The mobile app requests camera and photo library access for these optional actions and for workout scans and profile photos. If a Coach request leads to an error report, Sentry may also receive diagnostic metadata linked to your account: user and conversation IDs, image type and size, model provider, model, and platform. That report does not include the image through this diagnostic path.

Health Data (Optional)

If you enable recovery sync, PRzilla reads resting heart rate, sleep stages, and awake periods from Apple Health on iOS or Health Connect on Android. On iOS it can also read heart rate variability. Sleep timelines, source identifiers, and onset timestamps stay on your device. PRzilla derives and stores account-linked daily aggregates such as total and main sleep, nap-aware duration, bedtime deviation, and interruption counts and minutes. These recovery metrics are used for in-app recovery history and scoring and may be included as context when you invoke AI coach features. If you enable Apple Health workout sync, recent workouts are read on your device to offer an import list. Only workouts you choose to import are sent to PRzilla and stored as training-log entries with heart rate, distance, calories, and elevation. Raw heart-rate samples are stored with the imported workout to calculate and update training zones. You can also enter a maximum heart rate for that calculation. PRzilla requests read access only and does not write data back to Apple Health or Health Connect. Health data is not sold or used for advertising.

Calendar (Optional)

If you turn on Share calendar with coach in Coach settings in the mobile app, you choose which of your phone's calendars your coach can read, and you can change that choice later. The app uploads the title, dates, and start and end times of the events on those calendars for the next two weeks, up to 100 events, with times read in your phone's time zone. Cancelled events and invitations you declined or have not answered are not uploaded. Notes, locations, links, and attachments are never read. The guest list is checked on your phone only to see how you answered an invitation, and is never uploaded. The app refreshes the list when you open it, and PRzilla stores only the latest list with your account. The list is used only when you chat with AI Coach: it is included with your message and processed by AI model providers to write the reply. Your automatic daily briefing does not receive it. Turning sharing off deletes the stored list, and a list that stops refreshing is emptied after 7 days. Replies your coach already wrote, and facts it remembered from those conversations, are not deleted with the list; you can delete remembered facts under Remembered by coach in Coach settings. iOS has no read-only calendar permission, so the app asks for full access; PRzilla only reads events and never adds, changes, or deletes them. On Android the app asks for read-only access. Calendar data is not sold or used for advertising.

Usage Data

We use PostHog for product analytics to understand how features are used and improve the app. This includes page views, feature interactions, and general usage patterns. When you log a workout or lift, PostHog also receives your account ID and email with exact result values such as time, reps, load or weight, and distance. PostHog may collect technical information such as browser type and device type and derive approximate location (country or region, not precise location) from your IP address.

Error Diagnostics and Web Session Replay

We use Sentry to investigate errors and performance. An internal error during a signed-in API request can send your account ID and email, the exception and request path, database error and connection details, and deployment identifiers to Sentry. The web app also sends sampled performance traces, browser error and warning logs, and session replays. Replays include some ordinary web sessions and sessions with errors. Page text and media are not masked in the replay configuration, so visible content may be included. These diagnostics are used to maintain the service, not for advertising or cross-app tracking.

Referral Data

Redeeming a referral code reveals your first name to the person who referred you. We do not collect an email address before signup for referral attribution. If either account is permanently deleted, we remove its account link from the referral record while retaining the anonymized reward ledger needed to honor the other participant's earned reward and prevent promotion abuse.

3. Information We Do Not Collect

We do not collect precise location data, user-uploaded videos, financial or payment card information, contacts, phone numbers, or advertising identifiers. Apple and Google process subscription payments. We receive subscription status and purchase-history details from RevenueCat, but we do not receive your payment-card number or bank-account details. Except for optional Apple Health or Health Connect recovery sync and Apple Health workout imports that you enable in the mobile app, we do not collect health data from device sensors. The scan service does not keep original workout photos after analysis; web page content may be included in Sentry session replay as described above.

4. How We Use Your Information

We use your information to:
  • Provide and maintain the workout tracking service
  • If you opt in, send you a product newsletter about once a month, covering notable changes and announcements. Every issue carries a one-click unsubscribe link. Unsubscribing stops the newsletter and does not affect transactional email such as password resets; you can also email hello@przilla.app to be removed.
  • Authenticate your identity and secure your account
  • Store and display your workout history and progress
  • Read an export you select from another workout app to complete your requested import
  • Store and display optional Apple Health or Health Connect recovery metrics, when you enable sync
  • Provide optional recovery context to the in-app AI coach, when recovery sync is enabled
  • Store daily mood, soreness, and optional notes and use recent check-ins as context for automatic daily briefings and AI Coach conversations
  • Store the upcoming events on the calendars you choose to share and use them as context for AI Coach chat only, when calendar sharing is on
  • Validate purchases, provide subscription features, and restore PRzilla Pro access across signed-in devices
  • Attribute and fulfill referral rewards
  • Rank leaderboard activity and qualifying benchmark scores, and apply your name and country-flag preferences
  • Improve the app based on usage patterns

5. Data Sharing

We do not sell your personal data. Your data is sent only to our backend servers and service providers acting on our behalf to provide the service. Google and Apple receive authentication requests when you sign in and process purchases made through their respective app stores. RevenueCat receives your PRzilla account ID and store purchase history to validate purchases and provide subscription status; it does not receive your workout history or payment-card details from us. We use PostHog for analytics, which processes the account-linked results and other usage data described above on our behalf. When you use AI features, images you attach to AI Coach and relevant workout, recovery, and self-reported daily check-in context, including optional check-in note text, along with relevant profile demographics, body measurements, training target, and unit preferences, may be processed by AI model providers, such as Anthropic or OpenAI, acting as service providers/subprocessors to generate the response. If you share calendars, the titles, dates, and times of the events on them are processed the same way, only when you chat with AI Coach. We do not sell this data, use it for advertising, or share it with data brokers. For global leaderboards, signed-out viewers see anonymous handles, ranking values, and selected country flags. Signed-in viewers may see your first name and last initial when name sharing is enabled. Public Community Scores show anonymous benchmark scores without names or country flags. Signed-in viewers may also see that shortened name, your qualifying benchmark score, and selected country flag. You can replace your name with an anonymous handle and remove the flag independently from Settings. If you share your public athlete profile, signed-in viewers who tap your name may also see the profile details described above until you turn it off. For approved affiliate reports, public leaderboard views use pseudonymous athlete aliases. Member names are available only through an affiliate- and report-specific review link intended for authorized affiliate recipients. Review links remain stable across report refreshes so an authorized recipient can keep using the same private URL. Workout export files submitted for a requested import are stored privately by Vercel Blob. Resend processes the account identity and request metadata needed to notify us of the request; the notification does not contain the export file or its private storage URL.

6. Data Storage and Security

Your data is stored in a PostgreSQL database hosted with industry standard security practices. Authentication tokens are transmitted over HTTPS. We do not store passwords in plain text — social sign-in uses OAuth tokens, and email/password authentication uses secure hashing. Workout exports submitted for import are compressed in the app, transmitted over HTTPS, and stored as private Vercel Blob objects. They are not included in product analytics.

7. Account Deletion

You can delete your account at any time from the Settings page in the app. When you request account deletion, your account is deactivated immediately. After 30 days, PRzilla removes your account and workout records from its primary database. During those 30 days, you can contact us to cancel the deletion and restore your account. Account-linked analytics records held by PostHog, including logged workout and lift results, and diagnostic records held by Sentry are not removed by that database cleanup and may remain under those providers' retention settings. Contact hello@przilla.app about those records. Deleting the account does not clear AI Coach images cached in the mobile app's Documents directory; remove the app or clear its data to erase those local copies. A public Roadmap screenshot may remain accessible after account deletion if an earlier storage cleanup failed after its request reference was cleared. If you know the image URL, email hello@przilla.app to request its removal. Workout export files submitted for a concierge import are retained separately so we can correct or rerun the import; email hello@przilla.app to have an export file deleted.

8. Third-Party Services

We use the following third-party services:
  • Google Sign-In — for authentication (provides your email, name, and optional profile image URL to PRzilla)
  • Apple Sign-In — for authentication on iOS (provides your email and name to PRzilla)
  • PostHog — for product analytics (receives the account-linked fitness results and other usage data described above)
  • Sentry — for error reporting, sampled performance data, and web session replay as described above; an AI Coach attachment error report may also contain the diagnostic metadata described in the AI Coach section, but not the image through that breadcrumb
  • Google Gemini or Google Vision API — for optional workout photo scanning (receives the selected image for text extraction)
  • YouTube — requests a video thumbnail when you open a movement detail with a video, before you play it; opening the video loads the YouTube player
  • Google Fonts — downloads display fonts when you first render a score share card and caches them on your device
  • AI model providers — for optional AI coach and workout analysis features (receives the workout, recovery, self-reported check-in, relevant profile/preference context, and any image you attach to AI Coach needed to generate a response; in AI Coach chat only, also the events on the calendars you share)
  • RevenueCat — for in-app purchases and subscriptions (receives your account ID and store purchase history, but not payment-card details)
  • Firebase Cloud Messaging — sends optional push notifications to your device using an account-linked device token and the notification content
  • SugarWOD — as the source of approved affiliate workout programming and member-result data used in affiliate reports
  • Vercel — for hosting, web analytics, private storage of workout export files submitted for import, and public storage of Roadmap screenshots
  • Resend — for transactional email, including import-request notifications that contain account and request metadata but not the export file or private storage URL, and for the monthly product newsletter described above

9. Your Rights

You have the right to:
  • Access your personal data through the app
  • Delete your account and its primary workout records; see Account Deletion above for retained processor, public, and local data
  • Contact us about deleting account-linked analytics or diagnostic records held by service providers and public Roadmap screenshots
  • Disable Apple Health or Health Connect recovery sync and delete stored recovery data from Settings in the mobile app
  • Turn off calendar sharing in Coach settings in the mobile app, which deletes the stored list
  • Export your workout data
  • Hide your name or country flag from leaderboards and Community Scores in Settings
  • Turn your public athlete profile on or off in Settings
  • Unsubscribe from the product newsletter at any time
  • Ask us to correct or remove your data from an affiliate report
  • Ask us to delete a workout export file submitted for import

10. Children's Privacy

PRzilla is for people 16 and older. We do not knowingly collect personal information from anyone under 16. If you believe someone under 16 has provided us with personal data, please contact us so we can remove it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of material changes by updating the "Last updated" date at the top of this page.

12. Contact Us

If you have questions about this Privacy Policy or your data, please contact us at hello@przilla.app.