Skip to content
MethodFAQAbout
App
MethodFAQAboutApp
↖ Back to the site
PrivacyDelete account
Italiano ↗

FORM4 — Privacy policy

Effective: 2026-09-23 · Last updated: 2026-09-23 · v9

In this policy
  1. 01In short
  2. 02Who is responsible for your data
  3. 03Account and authentication
  4. 04Training and profile data
  5. 05What stays on the phone
  6. 06Automatic FORM4 cloud backup, with your consent
  7. 07First-party usage statistics
  8. 08Error diagnostics
  9. 09Feedback and OCR
  10. 10Service providers and sharing
  11. 11The form4.fit website
  12. 12Purposes and legal bases
  13. 13Retention
  14. 14Deleting your account and data
  15. 15Your rights
  16. 16Security and international processing
  17. 17Children
  18. 18Changes to this policy

In short

FORM4 is a local-first training logbook. Your main training data is saved first in a database on your phone. An account is required. Only with your explicit consent, while you are signed in, FORM4 can automatically send an account-scoped copy to its cloud backup when a connection and the backup state allow it.

FORM4 does not sell personal data, use it for advertising or include an advertising network. The cloud backup runs only with your explicit consent. After authentication FORM4 sends the minimized first-party usage statistics and sanitized error events described below, which you can switch off at any time in Settings.

Who is responsible for your data

FORM4 is the name of a project, not a company. Its three founders, Zaccaria Ragni, Luca Tramontani and Giacomo Alberani, decide together which personal data FORM4 processes, why, with which providers and for how long. They are therefore joint controllers under Article 26 GDPR. In this policy, “FORM4” means the three of them acting together.

They have agreed in writing how they share the work. In short: any substantial change to this policy, to the providers, to the categories of data or to the retention periods needs the approval of all three; privacy requests reach one common address, are shared among the three and then assigned to one of them, who answers for all.

The common contact point for privacy questions, rights requests and account-deletion requests is start.form4@gmail.com. You can nevertheless exercise your rights in respect of and against each of the three joint controllers.

Account and authentication

FORM4 uses Supabase for account creation, email verification, password sign-in, password recovery and session management. Supabase receives your email address, account identifier and authentication data. FORM4 does not store your password in its local training database; the signed-in session is kept in the secure storage provided by the operating system.

If you choose Continue with Google, Google takes part only in that sign-in and returns your name, email address and profile-picture link, which Supabase stores with the account; FORM4 shows the name in the app. On iPhone you can choose Sign in with Apple: Apple confirms your identity and gives FORM4 your email address (or a private relay address, if you choose Hide My Email) and, the first time only, your name. Google and Apple sign-in are optional; the FORM4 account is not. Different sign-in methods create different FORM4 accounts, so use the same one on every device.

Training and profile data

Training data can include programs, schedules, workouts, exercises, sets, loads, repetitions, reported RIR, rest outcomes, notes, custom exercises and machines, machine setups, preferences and workout timestamps and status. FORM4 also stores the profile fields you provide, such as preferred units, height, body weight and its date, year of birth, biological sex, training experience and primary goal.

FORM4 uses these records to operate the logbook, restore your history and show your own progress. FORM4 is not a medical device, gives no medical advice and does not use these records for advertising.

What stays on the phone

Each account has its own local SQLite training database and local backup bookkeeping. A separate device-global SQLite queue stores minimized analytics events until authenticated delivery; account-owned rows are isolated and are never reassigned on logout or account switch. The active-workout marker and account-claim recovery files are local and account-scoped. The Photo Import correction memory (the phrases you confirmed and the exercise you chose for each) stays in the account’s database on this phone and is not part of the cloud backup.

Android system Auto Backup and Android device-to-device transfer are disabled for FORM4. On iPhone, FORM4 excludes its databases and files from iCloud Backup and from computer backups, and keeps the signed-in session in this iPhone’s Keychain only: it does not move to another device, and after reinstalling FORM4 you sign in again. None of these channels copies FORM4 databases or app files to Google Drive or iCloud or silently moves them to another phone. FORM4 cloud backup, described next, is a separate authenticated service.

Automatic FORM4 cloud backup, with your consent

Only if you have given your explicit consent, and while you are authenticated, FORM4 checks for local changes at account startup, when the app returns to the foreground and periodically while it is open. If the connection and restore state permit, it automatically uploads pending backup objects and retries temporary failures. A training action is saved locally first and never waits for the upload.

The backup can contain completed and incomplete workout records and their sets, programs and schedules, custom exercises and machines, machine setups, exercise preferences, profile/account settings and deletion markers. It therefore can include exercise names, loads, repetitions, RIR and notes that belong to the product record. This product backup is different from the minimized analytics described below.

The backup uses a random app-generated device identifier scoped to this account on this installation. It is not an advertising ID, Android ID, IMEI or hardware fingerprint. The server derives ownership from the authenticated session.

This is a durable outbound backup with an explicit restore or merge flow; it is not continuous real-time synchronization between devices. Restore is offered before training on an empty installation when the account already has a backup. Starting without restoring can make a later replacement restore unsafe, although an additive merge may still be offered.

You give or refuse consent on the first screen after sign-in, and you can change it at any time in Settings → Backup. Without consent nothing is uploaded and your training stays only on the phone; the FORM4 server also refuses backup data from an account without a recorded consent. Withdrawing consent deletes the cloud copy (backup objects, device and sync records) at once and stops further uploads; it does not affect the lawfulness of the backup before the withdrawal.

First-party usage statistics

FORM4 sends minimized first-party usage statistics to its authenticated Supabase backend. You can switch them off at any time in Settings → Privacy → Usage statistics: FORM4 then stops collecting and sending them, deletes the events still waiting on the phone and deletes those already received for your account. There is no anonymous analytics endpoint and no third-party analytics SaaS. Installations that never reach signup are represented only by aggregate Google Play acquisition reporting; the local first-open record is linked and uploaded only after authentication. If the app is first opened from a link that carries campaign parameters (utm_source, utm_campaign, utm_content), the first-open record keeps those three values, sanitized and shortened; otherwise it records “Unknown”. FORM4 reads no advertising ID and uses no fingerprinting for this.

Minimized events include a server-assigned account ID, a random app-scoped installation ID, event and app-session IDs, event time, app version and version code, platform, operating-system major version, the device language setting, the time-zone offset, a development-build flag, the sign-up method (email, Google or Apple), the FORM4 identifiers of the program and workout involved (the same random identifiers the backup uses), onboarding state, manual program-creation lifecycle and aggregate program size counts, workout lifecycle, a once-per-workout first-real-set signal, and aggregate set, exercise, repetition and duration counts and a logbook-completeness indicator at workout closure.

Analytics do not contain workout contents, exercise names, loads, detailed repetitions, RIR, notes, body weight, email addresses, names, authentication secrets, raw stack traces, raw error messages, OCR images or raw OCR text. OCR analytics contain only a random import ID, lifecycle stages, timing/counts, cloud-call and model token counts, closed failure and layout categories and minimized aggregate correction counts; never before/after values. No event is emitted for every set.

Switching usage statistics off also stops the error events described in the next section. For statistics FORM4 keeps nothing on the device beyond what the app needs to queue the events; it sets no cookies and uses no advertising identifiers.

Error diagnostics

FORM4 keeps up to five recent render-crash records locally. They can contain the time, app version, error name, a bounded error message and a bounded React component stack. They are shown in Settings so you can copy them; the raw local journal is not uploaded. Backup status logs contain structural status and counts, not training values.

For a render failure, FORM4 sends a separate minimized error event containing a random error ID, a closed category and code, fatal status, workflow or screen, time, app version and pseudonymous identifiers. Raw stacks, raw messages and user-entered content are excluded. FORM4 uses no crash-reporting SaaS for analytics V1.

Feedback and OCR

Settings → Send feedback lets a signed-in person send a problem, an idea or another message. It is text only: no images or attachments. FORM4 sends the message, the kind you chose, whether we may reply, and the technical facts listed under “Included data” before you send: app version, operating-system version, device manufacturer and model, and app language. Only if you switch it on, it also sends the error name, a bounded error message and a bounded component stack of the last local crash record. It contains training data only if you type it into the message yourself. The message is linked to your account; FORM4 replies to the account email only when you allowed it. Without a connection the message waits on the phone, for that account only, until it can be sent. At most 10 messages per account are accepted in 24 hours. Feedback is read by the FORM4 team in its Supabase backend and is not part of product analytics. If you email start.form4@gmail.com instead, the message and the contact information you choose to provide are processed to answer you.

Photo Program Import lets you select or take a workout image, review a structured draft and create a program only after your confirmation. On Android, FORM4 first reads the image on the phone with Google ML Kit text recognition, which does not send the image or its text to Google; only when that result is not enough does the app send a temporary prepared copy of the image, together with the text already read, through an authenticated FORM4 server function to Google Gemini (Gemini API). On iPhone, FORM4 does not yet read images on the device, so every imported image is sent to Gemini in the same way. The notice shown before you choose a photo says which case applies. FORM4 does not place the image in permanent cloud storage or a provider File API, and deletes its prepared cache copy after processing. Under the Gemini API terms that apply to FORM4, Google does not use these inputs to improve its products and logs prompts and responses for a limited period only to detect misuse and for legally required disclosures.

The validated import draft and your corrections can remain in the account-scoped database on this phone so an incomplete review can be resumed. Missing and uncertain values remain explicit, and the source image URI is not saved in the draft. To limit cloud reads to 20 a day per account, the server keeps only a daily request count for each account, for 7 days, and deletes it with the account.

Service providers and sharing

Supabase provides hosted authentication and the database used for FORM4 account backup and first-party analytics; its data-processing agreement names Supabase Pte. Ltd. (Singapore) as the processor. It processes the account identifiers, backup payloads and minimized event rows described above on FORM4’s behalf. Supabase may use its own authorized subprocessors under its data-processing terms. Supabase and Cloudflare keep technical request logs (IP address, the approximate location derived from it such as city, region and postal code, app or browser identifier and time), and Supabase’s authentication logs include the account email, to run and protect the service for the limited periods of their plans. Supabase’s privacy information is available at https://supabase.com/privacy.

Google processes the authentication exchange when you choose Google sign-in, provides Gemini processing for Photo Import fallback, provides the privacy-contact mailbox and provides aggregate Google Play acquisition reporting outside FORM4’s event pipeline. The fallback image can contain workout content and is sent only after you start an import and accept the upload notice. On Android, Google ML Kit, used for on-device text recognition, may send Google diagnostic and usage data about the device and the app (such as manufacturer, model, operating-system version, app package and version, a per-installation identifier not intended to identify a user, performance metrics and API configuration), but not the image or the recognized text. Google’s privacy terms are at https://policies.google.com/privacy. Where Google or Supabase process data outside the European Economic Area, the transfer relies on the safeguards in their data-processing terms, such as the European Commission’s Standard Contractual Clauses or the EU-US Data Privacy Framework.

Apple processes Sign in with Apple when you choose it on iPhone, and the revocation of that sign-in when you delete the account; Apple’s privacy policy is at https://www.apple.com/legal/privacy/. Cloudflare, Inc. hosts the form4.fit website, as described in the next section. Using a service provider is not third-party advertising or tracking. FORM4 does not sell personal data, share it with advertising networks or data brokers, or use marketing/attribution SDKs; the campaign parameters described under analytics are read by FORM4 itself. Data may be disclosed where legally required or necessary to protect the service and its users.

The form4.fit website

The form4.fit website is served by Cloudflare. To deliver and protect the site, Cloudflare processes your IP address and technical request data such as the page requested, browser type and time, and keeps request logs for a limited period. The website sets no cookies and uses no analytics, advertising or tracking scripts, and no third-party fonts or scripts. Cloudflare’s privacy information is at https://www.cloudflare.com/privacypolicy/.

The account-deletion page, https://form4.fit/delete-account, is the only page that handles account data. When you sign in there, your email and password, or the Google sign-in exchange, go directly from your browser to FORM4’s Supabase authentication service. The access token stays in the page’s memory for that visit only and is not saved in cookies or browser storage.

Purposes and legal bases

FORM4 processes account and authentication data, the data you send through Photo Import and the answers to your requests to provide the service you ask for (GDPR Article 6(1)(b)). It processes narrowly necessary security and abuse-prevention data for its legitimate interest in protecting accounts and the service (Article 6(1)(f)). Feedback you choose to send is processed for FORM4’s legitimate interest in handling reports and improving the service (Article 6(1)(f)). The record of your privacy choices is kept to demonstrate consent (Article 6(1)(c) and Article 7(1)).

Usage statistics and error events are processed for FORM4’s legitimate interest in measuring activation, retention, feature performance and service reliability and in fixing errors (Article 6(1)(f)). FORM4 has balanced this interest against yours: it collects no workout contents, uses pseudonymous identifiers and lets you object at any time directly in the app (Article 21).

Training and body-profile data can be data concerning health (Article 9). The cloud backup that contains them is therefore based on your explicit consent (Article 6(1)(a) and Article 9(2)(a)), which you can withdraw at any time. On the phone, this data is processed only to provide the logbook you use (Article 6(1)(b)).

Retention

On this phone, account-scoped product data remains until you delete it, delete the account, clear FORM4 storage or uninstall the app. The device-global crash journal remains until you clear it, clear app storage or uninstall. Exported files, and workout cards you save to Photos or share, are controlled by you and the destination you choose.

In the active cloud database, account and backup records remain while the account exists, including backup deletion markers needed to preserve deletions. Successful account deletion, in the app or on the website, removes the FORM4 object, device and sync-state rows, analytics rows, feedback messages, the daily Photo Import count and the authentication identity in one server transaction. Otherwise feedback messages are deleted 24 months after they are received, or earlier if you ask. The daily Photo Import count is deleted after 7 days. Withdrawing backup consent deletes the backup objects, device and sync records at once. The record of your privacy choices remains while the account exists, as evidence of consent, and is deleted with it.

Infrastructure recovery copies and authentication or security logs may persist for the limited periods applied by Supabase and its plan or legal obligations. FORM4 does not currently have verified evidence for one universal 30-day infrastructure-backup limit and therefore does not promise one here.

Pending analytics rows remain locally for at most 90 days and are bounded to 5,000 rows or 5 MiB. Identifiable server event rows remain while the account exists and are deleted with it, or as soon as you switch usage statistics off. No aggregate analytics snapshot exists in this release.

Deleting your account and data

In the app, use Settings → Delete account. If the account uses Sign in with Apple, you first confirm with Apple and FORM4 asks Apple to revoke its sign-in. If the cloud operation succeeds, FORM4 deletes the account identity and account-owned cloud objects first, signs out, then deletes that account’s local training database, backup sidecar, claim-recovery files and active-workout marker on this phone. The app reports if local removal is incomplete. The operation cannot be undone.

Without the app, you can delete the account at https://form4.fit/delete-account by signing in with the same email and password or Google account (an account created with Sign in with Apple is deleted in the app or by email). This removes the account and its cloud data immediately, but cannot reach the copy on a phone: uninstall FORM4 or clear its data to remove it. You can also email start.form4@gmail.com from the account address; FORM4 will verify the request and respond without undue delay and within the period required by applicable law.

Account deletion cannot erase exports you created, local copies on another device, or data held by another account. The pre-account legacy database on this phone is also left alone because it has no recorded owner and may belong to another person; clearing FORM4 app storage removes it.

Account deletion also removes identifiable server analytics rows and this account’s pending local analytics rows and unsent feedback without reassignment. No aggregate analytics snapshot exists in this release. A future non-identifying snapshot may remain only after a separate implementation and policy update, and only if it contains no person, account, installation, event or small-cohort identifier.

Your rights

Depending on applicable law, you may request access, correction, deletion, restriction or portability, and may object to processing based on legitimate interests. Data Export in Settings creates JSON and CSV copies of training data locally. You can object to usage statistics directly in Settings → Privacy and withdraw consent to the cloud backup in Settings → Backup, at any time and without giving reasons.

Send requests to start.form4@gmail.com. You may also complain to the data-protection authority in the country where you live or work, or where you believe a violation occurred.

Security and international processing

FORM4 stores the account session in operating-system secure storage and encrypts traffic to Supabase in transit. Cloud requests are authenticated; database row-level security and server functions derive the owner from that session rather than trusting an owner ID supplied by the app. No internet service can be guaranteed absolutely secure.

The FORM4 production Supabase project is hosted in Europe. Supabase and its authorized subprocessors may still process some service data outside your country; such transfers rely on the safeguards in the providers’ data-processing terms, such as the European Commission’s Standard Contractual Clauses.

Children

FORM4 is intended only for people aged 18 or over. At first sign-in you confirm that you are at least 18; if you are not, you cannot use the app. If FORM4 learns that an account belongs to someone under 18, it deletes the account and its data.

Changes to this policy

Policy version 9 was last updated on 23 September 2026. It names the three founders as joint controllers instead of a single controller, explains how they share responsibilities and sets start.form4@gmail.com as the common contact point. Version 8, compared with version 7, raised the minimum age to 18 and added Sign in with Apple and its revocation on deletion, the iPhone exclusion from iCloud and computer backups and the device-only session, the fact that on iPhone every Photo Import image goes to Gemini, the data Google sign-in returns, the providers’ request logs and the retention of feedback (24 months) and of the Photo Import count (7 days). Version 7 added the identity of the controller, explicit consent for the cloud backup and its withdrawal, the in-app objection to usage statistics, the confirmation of the minimum age of 16 and the record of privacy choices. Version 6 added the in-app feedback form, the form4.fit website and the web account-deletion page, campaign attribution, the complete list of analytics fields, Google ML Kit and the Photo Import request count.

FORM4

A logbook for serious bodybuilding.

Contactcontact@form4.fit

MethodFAQAboutPrivacyDelete account
Download on the App StoreGet it on Google Play
© 2026 FORM4Language: Italiano