Last updated: September 29, 2026
Perside is a strength-training app operated by William Ye, an individual doing business as PerSide, located in Pennsylvania, United States. You can reach me at support@getperside.com. Because Perside is run by one person, this policy is written in the first person: "I" means William Ye, and "Perside" means the app at https://getperside.com.
This policy tells you what data Perside stores, why, where it lives, and how to get it removed. I have tried to make it exact rather than reassuring. If anything here is unclear, email me.
Your account. Your email address, the date your account was created, the date your email was verified, a random internal user ID, your unit preference (lb/kg), the implements you own (types and weights), your chosen app theme, your timezone (captured silently from your browser once, so your training week schedules correctly), and the days of the week you have told the app you are available to train. If you sign in with Google, this also includes your name and a profile picture URL — see "Signing in with Google" below.
Your training setup and progress. The movements you have unlocked or built yourself, which onboarding path you took (recorded once, used only in aggregate — no feature in the app reads it per-user), and the names you give your programs, along with internal state that tracks your program slots, achievements, and rank/milestone history.
Your training log. For each session: the sets, reps, and weight the engine prescribed, what you actually completed, how long the session took, and the date. Perside also keeps every planned training day, including days you rescheduled or skipped. Taken together, these records show when you trained and when you did not. Optional fields you may choose to fill in — these are the most personal things Perside holds, so I want to be specific:
If you sign in with Google, Google shares the following with Perside: your Google account ID (a stable identifier, not your email address), your email address, whether Google has verified that email address, your name, and your profile picture URL, if you have one. We request only the openid, email, and profile scopes — nothing about your Google Drive, Calendar, contacts, or any other Google product — and we never see or store your Google password.
We use this information for exactly one purpose: creating and signing you in to your Perside account. Perside identifies your account by email address — if you already have an account under a given email address and later sign in with a Google account using the same, Google-verified email address, we treat that as the same account rather than creating a second one. If Google reports the email on your Google account as unverified, we will not use it to sign you in or link it to an existing account.
Behind the scenes, signing in with Google also stores a Google-issued access token, an ID token, and, where Google provides one, a refresh token, on your account record, so the sign-in system can complete the flow. These tokens are encrypted at rest by our database provider, the same as everything else described in this policy.
Perside's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements, to the extent they apply to us.
siteverify endpoint as part of confirming you are not a bot.Perside does not collect device fingerprints, precise location data, contacts, photos, or anything from other apps or sites.
Some of what you can log in Perside describes your body and how it feels: effort ratings, the pain flag, tests taken to muscular failure, body measurements, and anything you choose to write in a note. Depending on where you live, the law may treat some of this as health data. Rather than argue about labels, here is the position:
Perside records two separate acknowledgements, because they cover different things:
Neither acknowledgement is a substitute for judgment: Perside still asks you to keep medical information out of the app, which is not built to be a medical record.
Perside sets no analytics or advertising cookies. None. The complete list of what it puts on your device:
| Name | What it holds | Lifetime |
|---|---|---|
ft_onboarding | Your email address and your draft program, stored as readable JSON on your device (it is httpOnly and sent only over HTTPS in production, but it is not encrypted). Deleted early when you create an account. | 48 hours |
| Session token | An encrypted token holding your email and user ID, so you stay signed in. | Up to 14 days since your last visit, refreshed while you are active; capped at 60 days total from when you signed in, whichever comes first. You can also sign yourself out of every device at once from Profile → Account. |
| Callback URL cookie | Where to send you after sign-in. | Until you close your browser |
| CSRF token | Protects the sign-in form from forgery. | Until you close your browser |
localStorage.theme | Your light or dark mode choice. Never leaves your device. | Until you clear it |
flowtracker:…-dismissed | Which one-time hints (the cycle intro, the veteran build hint) you have dismissed, so they do not reappear. Never leaves your device. | Until you clear it |
If Cloudflare Turnstile is active on a sign-in form (see above), the widget itself loads a script from challenges.cloudflare.com and may set its own cookies under Cloudflare's domain as part of the bot check; that is Cloudflare's mechanism, not something Perside's own code sets.
Because there is no cross-site tracking of any kind, browser signals like Do Not Track and Global Privacy Control do not change anything: there is no tracking for them to turn off, and no sale or sharing for them to opt you out of.
That is the complete list. Perside makes no other outbound network calls: no analytics provider, no payment processor, no ad network, and nothing that tracks you across sites.
Perside is operated from the United States, and the database is hosted by Supabase in Canada. If you are in the US, this means your data is stored outside the US. Perside is offered to users in the United States; the app is not currently marketed to, and does not target, users in the European Economic Area or the UK.
That is the whole list. Every account confirms, by ticking a box, that they understand training data is stored including effort ratings, pain flags, and notes, and the date and time of that agreement is recorded. Existing accounts are asked the same thing the next time they open a page that shows their data. That consent is not a substitute for judgment: I still ask you to keep medical information out of the app, which is not built to be a medical record.
Your account and training data are kept until you delete your account or ask me to delete them. There is no automatic expiry on them today.
Rate-limiting records and expired sign-in tokens are swept whenever someone requests a sign-in link: records past their window and expired tokens are deleted then. Because that sweep is triggered by sign-in traffic rather than a fixed schedule, a record created just before a quiet stretch can outlive its cutoff until the next sign-in request arrives. The onboarding cookie expires after 48 hours, the session cookie after up to 14 days of inactivity (60 days at the outside), and each sign-in token is deleted the moment it is used.
When you delete your account, your data is removed from the live database immediately and cannot be recovered from the live system — deletion is a single database transaction that removes your account and everything that hangs off it (cycles, sessions, entries, achievements, rank events, week-plan snapshots, benchmark and sizing results, freeform entries, body measurements, and your consent/disclaimer records), and every other device you are signed in on is signed out within a few minutes. Copies of your data can still remain, for a limited time, in places outside the live database:
| Copy | Where | How long it survives deletion |
|---|---|---|
| Encrypted database backups | GitHub, private repo, GPG/AES-256 | Up to 14 days (daily backups) and up to 8 weeks (weekly backups), then automatically pruned. Never restored to production except in a declared disaster, and never to look up one account. |
| Error reports | Sentry | Up to 30 days |
| Sign-in email delivery logs | Resend | Up to 30 days. Message bodies (the link itself) are not retained by this log. |
| Server request logs | Vercel | About 1 hour. May contain a user ID in a URL or an IP address. |
There is no analytics product, no data warehouse, no third-party sync, and no marketing list.
You can delete your own account instantly from Profile → Account → Delete account — see above for exactly what that removes and what may briefly survive in backups and provider logs.
Every account, free or paid, can download its training history — every logged session entry and freeform entry — as a CSV file with one click from Settings → Data. That file does not cover everything Perside holds (your account details, programs, benchmark and sizing results, or body measurements, for example), so for a complete copy, or anything else, email support@getperside.com from the address on your account and tell me what you want:
I honor these requests from anyone, anywhere, regardless of whether a particular law requires it. If you are a California resident, you will not be discriminated against for exercising any request, and Perside does not sell or share personal information as those terms are defined in California law.
Data is encrypted in transit. Separation between users is enforced by the application code. The database is hosted by Supabase and is reachable over the internet by anyone holding its credentials; those credentials are held only by me and by the deployed app. To be precise, Perside does not rely on database-level row security for that isolation, because the app's own database role would bypass it anyway; the isolation guarantee lives in the application layer. No system run by one person, or by anyone, is perfectly secure, and I will not pretend otherwise. If I learn of a breach affecting your data, I will notify you as the law requires.
Perside is for adults. You must be 18 or older to use it, and I do not knowingly collect data from anyone under 18. If you believe a minor has an account, email me and I will delete it.
If this policy changes in a way that matters, I will update the date at the top and, for significant changes, note it in the app or by email. The current version always lives at https://getperside.com.
William Ye, doing business as PerSide
Pennsylvania, United States
support@getperside.com