Privacy Policy
Last updated: 24 September 2026
Training data is personal, and body measurements, photographs and injury notes are sensitive. This page says plainly what we hold, who it reaches, and how long it lasts.
1. Who this covers
This policy explains what MONOLITH Company (“MONOLITH”, “we”) collects, why, who else sees it, and what you can do about it. It forms part of the Terms of Service.
It covers everyone who uses the Service: Coaches, Athletes, people on the waiting list, and visitors to public pages.
Coaches process their Athletes’ data too. For the training record a Coach builds, the Coach decides what is recorded and why; MONOLITH stores and processes it on their behalf. A Coach’s own obligations to their Athletes are theirs (Terms §5).
2. What we collect
You give us:
- Account — name, email address, password (stored only as a hash, never in readable form), phone number, role, profile photograph, biography, certifications, company name and logo.
- Training — programmes, days, sessions, exercises, sets, reps, loads, tempo, rest, RPE, coaching cues and notes, comments and questions between Coach and Athlete.
- Health and body data — body weight, measurements, and any injury, condition, or note a Coach or Athlete records.
- Media — progress photographs, form-check video, and voice notes.
- Payment — the tier purchased, amount, date, period covered, and any note on the transfer.
- Support — messages you send us, and anything you put in them.
Health and body data is sensitive information. Record only what the coaching actually needs. We never see or store your card number: transfers go directly to a bank account and we record only that a payment arrived.
We collect automatically: your IP address, browser and device type, pages visited and timestamps, and a signed cookie that keeps you logged in.
3. Cookies and similar technology
We use a signed session cookie (tra-uid) to keep you logged in. It is necessary for the Service to work; without it you cannot stay signed in.
We use local storage in your browser for interface preferences — a remembered tab, a collapsed section, an unsent draft. It never leaves your device.
We do not use advertising cookies and we do not run third-party ad trackers.
4. Why we use it
| What | Why |
|---|---|
| Account and credentials | To create and secure your account, and to sign you in |
| Training and health data | To deliver the coaching you asked for — the core of the Service |
| Media | To let a Coach review technique and track progress |
| Email address | To send sign-in codes, password resets, receipts, and expiry reminders |
| Payment records | To run your subscription and meet accounting obligations |
| Technical data | To keep the Service secure, prevent abuse, and diagnose faults |
| Support messages | To answer you |
We do not sell your data. We do not rent or trade it, and we do not use your training data, photographs, video, or audio for advertising. We do not use your Content to train AI models.
We may publish anonymous aggregate statistics — for example, how many programmes exist on the platform — that cannot identify you.
5. Who can see your data
Your Coach sees everything in your Client Record: programmes, every log, comments, measurements, progress photographs, form-check video and audio, RPE, and history.
Other Athletes cannot see your record. A Coach’s roster is visible only to that Coach.
MONOLITH personnel may access data only to operate, support, secure, and back up the Service, to comply with law, or with your permission.
The public sees only what you publish:
- a workout story, for the 24 hours it exists — anyone with the link, no account needed, and it may be indexed by search engines while live;
- a published coach catalog — name, city, country, disciplines, photograph, biography and catalog content.
Law enforcement and legal process — we may disclose data where we are legally required to, and will tell you unless prohibited.
6. Sub-processors, and where your data is held
We rely on specialist third-party providers to run MONOLITH. What matters to you is what each kind of provider receives:
| Purpose | What that provider receives |
|---|---|
| Application hosting and media storage | Data passing through the app, and your media files |
| Database hosting | All stored data |
| AI features | The content of the request — a programme, a question, or roster figures |
| Email delivery | Name and email address |
| Operational alerts to our administrators | Name, email address, phone number, and the content of support messages |
These providers are established international services, and your data may be stored or processed in any country in which they operate. They act on our instructions and are not permitted to use your data for their own purposes.
We will tell you here if the kinds of provider we use change. If you need to know exactly which providers we use, ask us at the address in §11 and we will tell you.
7. How long we keep it
30-day media deletion
All Media attached to a training session — photographs, video and audio, including form checks, progress photos and voice notes — is permanently deleted 30 days after the session date. This runs automatically every day and cannot be undone. Save anything you need locally before it expires.
Stories are deleted after 24 hours, the record and the media together.
Training text — programmes, sets, loads, reps, RPE, comments, measurements — is kept for as long as your account is active.
Backups are taken daily. Deleted data may remain in a backup for up to 30 days before it is overwritten.
Closed accounts. If an account is closed, or a subscription is not renewed, we may delete the account and its data after 12 months’ notice to the email on the account.
Payment records are kept as long as accounting law requires.
8. Your rights
- Access and export. Ask us for a copy of your data.
- Correction. Ask your Coach to correct your training record, or us to correct your account details.
- Deletion. Ask us to delete your account and data. We will keep only what the law requires and anonymous aggregate statistics.
- Withdraw consent to Media. Delete a photograph, video, or recording of yourself at any time, or ask us to. Withdrawal is not retroactive to copies already lawfully shared.
- Unlink from a Coach. If you stop training with someone, ask us to unlink or delete the Client Record.
- Object. Tell us if you do not want a particular processing to continue, and we will consider it and reply.
We respond to any of these within 30 days. Write to the address in §11.
9. Children
Accounts are for people 18 and over.
A Coach may keep a record for a person under 18 only with written consent from a parent or legal guardian, which the Coach must hold and produce on request (Terms §3).
If we learn we hold data about a child without that consent, we will delete it. Tell us at the address in §11.
10. Security
Passwords are stored as hashes and never in readable form. Sessions use a signed cookie that cannot be forged. Access to a Client Record is checked on every request.
We take daily backups.
No system is perfectly secure, and we cannot guarantee absolute security. Keep your password to yourself and tell us at once if you think your account has been accessed by someone else.
If a breach occurs that is likely to affect you, we will tell you and describe what happened and what we are doing about it.
11. Contact and changes
Questions, requests, or complaints: info@monolith.coach
We may update this policy. The current version is always at monolith.coach/privacy with its effective date. For a material change we give at least 14 days’ notice by email or in the app.
This policy is published in English, and the English text is the operative version.