TroughIQ

Legal

Privacy Policy

Effective: August 2026 · Version 2026-08 · CruzNet LLC

The short version: your health data is yours. We store it only to power your dashboard and your coach's view (when you grant access). We never sell it, never share it with advertisers, and run no third-party ad tracking. You can export or permanently delete everything at any time from Settings → Account.

1. Who we are

TroughIQ is operated by CruzNet LLC, a US company, and is the data controller for the personal data described below. You can reach us any time through the in-app feedback form at Settings → Feedback.

2. What we collect and why

  • Account identity — email address, and name/avatar from Google OAuth. To authenticate you.
  • Profile & onboarding — name, sex, age, height, weight, experience, units, goals, mode, competition date. To configure your dashboard.
  • Protocol (cycle) data — protocol name, phase, status, start/end dates, experience, notes; compounds with name, dose, unit, frequency, role; per-week dose windows; injection-site rotation. The core product — to model projected levels and scheduled doses.
  • Bloodwork — panels (lab name, draw date) and markers (e.g. testosterone) with value + unit. To track biomarkers against reference ranges.
  • Daily vitals — weight, blood pressure, glucose, insulin, calories, protein, mood/libido/energy, resting heart rate, notes.
  • Dose administration log — compound, dose, unit, date/time, injection site.
  • Physique check-ins — weight, body fat %, waist, arms, chest, thighs/calves.
  • Workouts — manual or Hevy-synced title, sets/reps/weights, duration.
  • Weekly check-ins — subjective scores, notes, coach notes/flags.
  • Hevy data (optional) — workouts + body measurements, cached from the Hevy API, only if you connect your own Hevy key.
  • Usage events — page view, CTA click, onboarding branch, tied to a browser-local random ID. First-party funnel analytics.

Health, biometric, and fitness data are special-category data under GDPR Art. 9 and are treated as such throughout.

3. Lawful basis

  • Contract (Art. 6(1)(b)) — processing necessary to provide the service you requested.
  • Explicit consent (Art. 9(2)(a)) — for special-category health data. After onboarding, we ask you to affirmatively accept this policy and record the version, acceptance time, and exact consent text. It is the sole basis for processing your health data. Withdrawal = delete your account (see §8).
  • Legitimate interest (Art. 6(1)(f)) — for first-party, pseudonymous funnel analytics. Not health data.

4. How data is stored and secured

  • Supabase (PostgreSQL, us-west-2) — all account data at rest, isolated by user ID with row-level security (RLS). No other user (or unlinked coach) can read your rows. Server-side admin credentials are restricted to three endpoints (account delete, data export, analytics).
  • Your browser — a service worker caches your own data locally for offline use; cleared on sign-out and account deletion.
  • In transit — all traffic is encrypted with HTTPS/TLS, and the app ships a strict Content-Security-Policy.

We run no third-party analytics or advertising SDKs and no ad trackers.

5. Subprocessors

We do not sell or trade personal or health data. The only parties that process your data are:

  • Supabase — database & authentication (all account data at rest).
  • Cloudflare — hosting / edge (all requests transit the edge).
  • Google — OAuth sign-in (name + email only).
  • Hevy (optional) — workout sync via your own Hevy API key.

6. Retention

  • Account, profile, protocols, compounds, dose windows, bloodwork, vitals, doses, physique, workouts, check-ins, Hevy cache — for the life of the account, deleted immediately and irreversibly on account deletion.
  • Protocol edit log + version snapshots — for the life of the account (audit trail for coach-edit undo), deleted with the account.
  • Onboarding drafts (incomplete setup) — 30 days after last edit.
  • First-party analytics events — 24 months, then deleted or aggregated/anonymized.
  • Hevy API key — until you disconnect Hevy.

7. Coaching and sharing

Linking a coach is always an explicit, token-based action by you. A coach sees only the data needed to coach you, and only while the link is active. You can revoke access at any time from Settings → Coach; revoking also rotates the share token so a stale token cannot re-link.

8. Your rights (GDPR + CCPA)

  • Access & portability — export a full JSON copy: Settings → Account → Export my data.
  • Erasure — permanently delete your account: Settings → Account → Request account deletion.
  • Rectification — edit any entry in-app.
  • Restriction / objection — contact us; you may object to analytics.
  • Withdraw consent — for health data, withdraw by deleting your account.
  • Complaint — you may lodge a complaint with your supervisory authority (EU/EEA) or the US FTC.

Requests via Settings → Feedback are answered within 30 days.

9. Cookies & local storage

We do not use advertising cookies. We use browser local storage to cache your app data and store the anonymous analytics ID. No cross-site tracking.

10. International transfers

Data is stored in the United States (Supabase us-west-2, Cloudflare edge). For EU/EEA and UK users this is an international transfer performed under the processor's standard contractual clauses / DPA.

11. Children

TroughIQ is for adults 18 and older. It addresses adult hormone and performance topics. We do not knowingly collect data from anyone under 18.

12. Data breaches

In the event of a personal-data breach, we will notify affected users and, where required, the relevant supervisory authority without undue delay.

13. Changes

Material changes update the effective date at the top and, where we have your email, are notified by email. A material new version triggers a new, non-blocking request for affirmative consent; continued use alone is not recorded as acceptance.

14. Not medical advice

TroughIQ provides tracking and information only. It does not provide medical advice, diagnosis, or treatment. Consult a qualified physician.

Questions or data requests? Use the in-app form at Settings → Feedback, or return home.