Suta

Privacy Policy

Effective 8 September 2026 · Last updated 8 September 2026

Suta is a training app that keeps your workouts on your own device. It has no user accounts, no analytics, no advertising and no tracking. This policy explains the little that does leave your phone, and why.

The short version. Every session, set and record you create stays in a database on your device. The app does not send it anywhere. The only information that leaves your phone is what the App Store and our purchase provider need in order to sell you the Founding Member unlock and remember that you own it — and none of that identifies you by name.

1. Who is responsible

Suta is developed and published by Andrei Vataselu, an independent developer ("we", "us"). For the purposes of the UK and EU General Data Protection Regulation, we are the data controller for the limited personal data described in this policy.

You can reach us at contact.vtsoft@gmail.com.

2. Data stored on your device

Everything you record in the app is written to a private database inside the app's own storage area on your device:

None of this is transmitted to us or to anyone else. There is no server component to Suta and no way for us to read your training data. It is visible only on the device where you created it.

If you have iCloud Backup or an encrypted device backup enabled, your app data may be included in that backup. That backup belongs to you and is governed by Apple's Privacy Policy, not by this one.

3. Purchases

Suta offers an in-app purchase that unlocks the paid features. Two parties are involved, and neither of them gives us your identity.

Apple

The purchase itself is made through the App Store. Apple handles payment end to end. We never see and never receive your name, email address, card details or billing address. Apple's handling of that transaction is covered by Apple's Privacy Policy.

RevenueCat

To validate your purchase receipt and remember that you own the unlock — including after you reinstall the app or set up a new device — the app uses RevenueCat, a purchase infrastructure provider acting as our data processor. When you open the app, RevenueCat may receive and store:

DataWhy
A randomly generated anonymous app user ID To attach an entitlement to an install without an account. It is not linked to your name, email or Apple ID.
Purchase receipt and transaction history To verify the purchase is genuine and still valid.
Device and app information — platform, OS version, app version, country, locale, time zone To deliver the correct offer and to make purchases work across a user's devices.

RevenueCat processes this on our behalf under a data processing agreement. Their handling is described in the RevenueCat Privacy Policy. We use the aggregate revenue figures RevenueCat reports; we do not use it to build profiles of individual users, and we cannot tell from it who you are.

Your training data is never sent to RevenueCat.

4. What we do not do

To be explicit, Suta contains:

5. If you email support

If you write to us, we receive your email address and whatever you choose to put in the message. We use it only to answer you, and we keep the correspondence no longer than we need to for support and record-keeping purposes.

Where the UK or EU GDPR applies, we rely on:

We do not rely on consent for any processing described here, because none of it is optional to the operation of the app; if you would rather none of it happened, do not make a purchase.

7. How long data is kept

8. International transfers

RevenueCat is based in the United States, so purchase-related data described in section 3 is processed there. Where such transfers are subject to UK or EU data protection law, they are made under the European Commission's Standard Contractual Clauses, incorporated into our agreement with RevenueCat.

9. Your rights

Depending on where you live, you may have the right to request access to your personal data, correction, deletion, restriction of processing, portability, or to object to processing; and under the CCPA, to know what is collected and to opt out of sale or sharing (we do neither). Exercising any of these rights will never make the app worse for you.

Because there are no accounts, we usually hold nothing that identifies you, and the honest answer to an access request is often "we have nothing under your name". Where a request concerns your purchase record, write to us and we will pass it to RevenueCat and confirm the outcome.

To make a request, email contact.vtsoft@gmail.com. We aim to respond within 30 days. If you are in the EEA or the UK and are not satisfied with our response, you may lodge a complaint with your national data protection authority.

10. Deleting your data

Deleting Suta from your device permanently removes every session, set and record it stored, along with its preferences. This cannot be undone, and we cannot restore it for you, because we never had a copy.

A purchase is separate from your data: it stays attached to your Apple ID, and reinstalling the app and using Restore Purchases brings the unlock back — but not your training history.

11. Children

Suta is not directed to children under 13 (or the minimum age of digital consent where you live, if higher), and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.

12. Security

Your training data is protected by iOS itself: app storage is sandboxed and encrypted at rest when your device has a passcode set. Communication with RevenueCat and the App Store uses encrypted connections. No system is perfect, but there is no database of ours to breach — which is the strongest security property this app has.

13. Changes to this policy

If we change what the app does with data, we will update this page and change the effective date at the top. Material changes will also be noted in the app's release notes. Continuing to use the app after a change means you accept the updated policy.

14. Contact

Andrei Vataselu
contact.vtsoft@gmail.com