Chalk
Privacy Policy
Effective May 14, 2026 · Last updated May 14, 2026
Chalk is a workout logging app for gyms and athletes. This policy explains what we collect, how we use it, who we share it with, and the choices you have. We've tried to keep it short and direct — the same tone we use in the app.
The short version
We store your email, your gym affiliation, and the workouts and PRs you log — that's it. We use Supabase to host the database. We don't sell your data, and we don't share it with advertisers or data brokers.
Information We Collect
Account information
- Email address — used to sign you in and to send essential transactional emails (password reset, account recovery).
- Display name — optional. Shown next to your scores on your gym's leaderboard if you opt in.
- Authentication metadata — your password is hashed before storage; we never see or store it in plaintext.
Gym affiliation
- The gym you joined via invite code, and your role within it (member or coach).
Workout data you log
- Scores against the workouts your gym posts — times, rounds + reps, weights, sets, effort ratings, and optional notes.
- Personal Records (PRs) for movements you train (e.g. Back Squat, Deadlift) and for named benchmark workouts (e.g. Fran, Murph).
- Preferences — your default workout level, unit preference (lbs / kg), and display preferences.
Things we do not collect
- We do not collect location data.
- We do not collect contacts, photos, or files outside of what you explicitly enter into the app.
- We do not use third-party advertising SDKs or analytics SDKs that profile users.
How We Use Your Information
- To operate the app — show you today's workout, save your scores, compute your PRs, and render your gym's leaderboard.
- To authenticate you when you sign in.
- To send essential account emails (password reset, security alerts).
- To improve the app — diagnose bugs, understand which features are used, and prioritize work. This is aggregated and de-identified wherever possible.
We do not use your data for advertising or to build a profile for sale or sharing.
Data Processors
We use a small set of third-party services to operate Chalk. They process your data on our behalf, under contractual agreements that restrict what they can do with it.
- Supabase, Inc. — hosts the database, authentication, and storage that power Chalk. Your account, your scores, and your PRs are stored on Supabase's infrastructure (which runs on AWS in the United States). See Supabase's privacy policy.
If we add new processors (e.g. for crash reporting or email delivery), we will update this list before introducing them into production.
Sharing & Disclosure
- We do not sell your personal information to third parties. We do not share it with data brokers or advertisers.
- Within your gym: other members of your gym can see your name and your scores on the leaderboard only if you have enabled leaderboard opt-in. You can turn this off at any time in Settings.
- Coaches at your gym can view scores and PRs submitted by members of their gym to administer programming and coaching.
- Legal requirements: we may disclose information when we believe in good faith that we are required to by law, regulation, or legal process.
Your Choices & Rights
- Access your data — everything you've logged is visible to you inside the app on the Logbook and Records tabs.
- Update your data — edit your scores, update your PRs, or change your preferences directly in the app.
- Opt out of the leaderboard — flip the leaderboard opt-in off in Settings to hide your name and scores from gym-mates.
- Delete your account — email us at the address below and we will permanently delete your account and associated workout data within 30 days.
- Export your data — email us and we will send you a machine-readable export (JSON) of your account data.
Children's Privacy
Chalk is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe a child has signed up, please contact us and we will delete the account.
Security
We use industry-standard practices to protect your data: encrypted connections (TLS) between the app and our backend, hashed passwords, and row-level security policies in the database so members can only see what they're entitled to see. No system is perfectly secure; if we discover a breach affecting your data, we'll notify you promptly.
Data Retention
We retain your account and workout data for as long as your account is active. If you delete your account, we permanently remove your data within 30 days, except where retention is required for legal reasons (e.g. tax, audit). Aggregate or de-identified data that cannot be tied back to you may be retained longer.
International Users
Chalk is operated from the United States and our data processors store data in the United States. By using Chalk, you understand that your information will be transferred to and processed in the United States, which may have different data protection laws than your country.
Changes to This Policy
We may update this policy from time to time. If we make material changes, we'll notify you in the app and update the "Last updated" date at the top of this page. Continued use of Chalk after a change means you accept the updated policy.
Contact Us
Questions, requests for data export, or account deletion? Email us at [email protected]. We typically respond within a few business days.