Who is responsible
SetProof is operated by the developer identified in the applicable app-store listing, who acts as the data controller for the app. Privacy questions and requests can be sent to idosavion+setproof@gmail.com.
Eligibility
SetProof is intended only for people who are at least 18 years old. The app asks account holders to confirm this before use. If you believe a minor provided data, contact SetProof so it can be investigated and removed where appropriate.
What SetProof processes
- Account data: an account ID, email address, sign-in status, and authentication metadata managed through Amazon Cognito.
- Training data: routines, exercises, sets, repetitions, weight, RPE, workout history, progression choices, and sync status.
- Video and analysis data: a clip you record or select, an on-device motion summary, selected frame times, private evidence frames, capture-quality signals, inferred exercise and repetition estimates, observations, confidence, limitations, and feedback.
- Choice records: the version and time of Terms/Privacy acceptance, adult confirmation, and video-analysis permission or withdrawal.
- Operational data: request IDs, timestamps, errors, service latency, model-routing and usage details, and security events needed to operate and protect the service.
Record only yourself unless every other visible person has agreed. Keep bystanders, documents, screens, and other sensitive details outside the camera view.
How video processing works
The native app creates a smaller analysis copy, removes its audio, and strips source metadata before upload. The backend verifies the media and deletes/rejects a clip if an audio track remains. The private copy is processed in SetProof's AWS environment in eu-central-1. Selected evidence frames and a compact motion summary—not the full video, audio, source filename, account email, or source metadata—may be sent through OpenRouter to the configured model provider. Requests require provider data collection to be denied, zero-data-retention routing, and providers that support those parameters.
Why the data is used
SetProof uses account and training data to provide the service you request; video data when you separately consent to automated analysis; operational data for security, abuse prevention, troubleshooting, and reliability; and any data necessary to comply with law or protect legal rights. SetProof does not sell personal data, show behavioral advertising, or use training videos for advertising.
Storage and retention
- Encrypted raw analysis videos are configured to expire from AWS storage after 7 days.
- Derived results and evidence artifacts are configured to expire after 30 days.
- API and worker operational logs are generally retained for up to one month.
- Account and training records remain until you delete the account or the service is ended, unless a shorter legal or operational retention rule applies.
- A minimal deletion marker can remain for up to 7 days to stop still-valid tokens or delayed jobs from recreating deleted data.
- Signed-out device data remains in that account's protected local area so offline work is not lost. Use “Remove data from this device,” delete individual videos, uninstall the app, or delete the account to remove it.
Service providers and transfers
Amazon Web Services provides authentication, API, database, queue, storage, and processing infrastructure. OpenRouter routes the limited evidence payload to a configured model provider. App distribution providers such as Apple or Google may process store, download, purchase, diagnostic, or review data under their own notices. Processing may occur outside your country.
Your choices and consent
Video analysis is optional. Immediately before first camera or library use, the app explains the processing and asks for affirmative permission. You can deny camera access, keep training without video, or withdraw permission for future video analysis in Profile. Withdrawal does not undo analysis already completed, but you can remove individual videos, export device and server data, remove local device data, or permanently delete the account. You can also use the account-deletion page. Contact SetProof to request access, correction, export, restriction, objection, or deletion where applicable.
Security and safety
SetProof uses authenticated access, per-user data boundaries, encrypted private storage, short-lived signed media links, request throttling, limited upload size and frequency, and deletion checks. No system is perfectly secure. Automated feedback can be wrong and is general fitness information, not medical advice or a substitute for professional care. SetProof is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. Stop exercising and seek qualified care for pain, injury, or health concerns.
Changes
Material notice changes will be posted here with a new version and effective date. When appropriate, the app will ask you to acknowledge a new version before continuing.