Privacy Policy

Last updated: 2026-09-19

This Privacy Policy explains, in detail, what data NoMoreQuiting collects for each of its features, why we collect it, and how we protect it.

1. Account data

We collect your username, email address, and password (stored only as a bcrypt cryptographic hash, never in plain text), along with your account's role (regular user, admin, moderator, or founder).

2. Profile data

We store your first name, last name, birth date, gender, height, and weight, your preferred unit system (metric/imperial), the name of the gym where you train (optional), and the avatar you upload. We also save your profile visibility settings - what's public, what's visible to friends only, and what you choose to hide, including gender and age.

3. Workout data

We keep the workout categories you create, the exercises you pick from the catalog, your recurring schedules, and your workout sessions. Abandoned sessions aren't kept - their data is deleted on abandon. We also save the sets you log (weight, reps, date/time), your body weight history, and the per-exercise weight preferences you save.

4. Fitness activities and location data

For a GPS-tracked activity, we periodically collect your device's location (latitude, longitude), plus accuracy, altitude, and speed when available - only while the activity is actually in progress. For a manually entered activity (treadmill/indoor), we only store the distance, duration, and elevation you type in directly - no location data at all.

Before GPS tracking starts, your browser will explicitly ask you to grant permission to access your location - tracking only happens if you grant that permission. We use this location data exclusively to compute distance, pace, and elevation gain, and to draw the route you took.

Raw location samples are only kept in our database while an activity is in progress. Once you finish it, we simplify the full track down to a compact, permanent set of points (enough to redraw the route later) and delete the original moment-by-moment samples - we don't keep a precise, every-few-seconds record forever.

A finished activity and its route follow the exact same visibility settings as the rest of your profile (see section 2) - there is no separate, always-public visibility level for routes. A route can reveal sensitive information, such as where you live or train, especially at its start or end point - choosing the visibility level for your activities and profile is entirely your own decision (see the Terms & Conditions).

5. The social layer

We keep your friendship relationships (requests sent, received, and accepted), follow relationships, and the blocks you configure. We also keep the achievements you unlock automatically by using the app, including the ones you choose to showcase on your profile.

6. Two-factor authentication (2FA)

If you enable 2FA, the generated cryptographic secret is encrypted (AES-256-GCM) before being stored in the database - it is never kept in plain text, not even internally. It's used exclusively to validate the codes generated by your authenticator app.

7. Support tickets and attachments

We keep the subject, category (Support, Feature request, Bug report, Other), and content of the messages you send through a support ticket, including any attached file (Word document, PDF, or image). Files are validated both by their extension and their actual content, and are stored on our servers, remaining associated with that ticket.

8. Security and audit logs

To protect your account, we keep: a log of authentication events (successful/failed login, logout, temporary lockouts from repeated attempts), with the IP address and a device identifier; a history of username/email changes (old value, new value, IP address, and date), so you can later verify a change was really made by you; and, if you hold an administrative role, a log of the administrative actions you perform. These logs are kept for up to 365 days, after which they're archived.

9. Preferences and technical data

We store your visual theme preferences (colors, dark/light mode, gamified menu) and language, as well as a session token (managed via Redis, a single active session per account) and the IP address used at login, to limit abusive login attempts. We don't use this data for profiling or advertising.

10. What we don't do

We don't sell your data to any third party. We don't show ads and we don't use third-party analytics/tracking tools in the App.

11. Third-party services we use

We use an email (SMTP) delivery provider to send transactional emails (account confirmation, password reset) and emails related to support tickets - it only receives your email address and the content of that email, not the rest of your data. Replies sent by email to a support ticket are picked up by an email-routing service and added automatically to the conversation in the app.

12. How data is stored and protected

Data is stored in a MySQL database, while sessions and rate limits are managed via Redis. Your password is never stored in plain text - only as a one-way cryptographic hash (bcrypt). Your two-factor secret is encrypted separately (AES-256-GCM). The App automatically limits how many login, password-reset, and ticket-creation attempts can be made, to prevent abuse.

13. How long we keep it

We keep your account data for as long as your account is active. You can delete your account yourself at any time from Account Settings (see the Terms & Conditions, section 13) - this immediately deletes your workouts, activities, categories, achievements, social connections, and every other record tied to it. We keep only your username, user ID, and email, to prevent immediate re-registration and for the legal retention purposes described in this section, and your password is invalidated so nobody, including us, can log in as you again. Support tickets are kept after deletion for legal-defense and abuse-history purposes. Security and audit logs (e.g. login history, admin actions) are kept for up to 365 days regardless of account status, since they exist to protect the platform as a whole, not just your account. If you'd like even the few fields we retain after self-service deletion erased, write to us through a support ticket (before deleting your account, since a deleted account can no longer open one) or at the address on the Contact page and we'll process the request as soon as we can, subject to any remaining legal obligation to retain it.

14. Your rights

You have the right to request access to your data, correction of it, deletion of it, or a copy of it in a portable format. You can delete your account yourself at any time (see section 13 above); for the other rights, or to request deletion of the few fields we retain after self-service deletion, write to our contact address. Note that the history of username/email changes is kept separately, for security purposes, even after you choose a new value.

15. Automated decisions

We don't use any fully automated decision-making process that produces legal or similarly significant effects on you. Automatically unlocked achievements and the leaderboard are gamification features only, not evaluations of your account.

16. Minimum age

The App is not intended for, and may not be used by, anyone under 18 years of age (see the Terms & Conditions, section 2) - when creating an account you're asked to explicitly certify that you are at least 18. We do not knowingly collect data from anyone under 18.

17. Reporting a profile picture or account

If you believe a profile picture unlawfully uses copyright-protected material, or that an account is impersonating someone, see section 14 of the Terms & Conditions for how to report it and what happens next.

18. Changes to this policy

If we make a substantial change to this policy, you'll be asked to re-confirm it the next time you log in, together with the Terms & Conditions.

19. Contact

Questions about your data? Reach out through a support ticket - details are on the Contact page.