Privacy Policy

1. Who holds your data

Plates is operated by Davlatsho Shirinbekov of 156 Hamlet Gardens, London W6 0TR, United Kingdom, a sole trader in England and Wales. There is no company number, because there is no company: Plates is one person, and that person is the data controller under the UK GDPR and the EU GDPR for everything described here — they decide what is collected and why.

For anything in this policy, write to privacy@plates.cloud. There is no Data Protection Officer. One is required for large-scale special-category processing, and this is a one-person service — but the health data in section 6 is exactly the kind that would make it required at scale, so it is a question that gets asked again as Plates grows rather than one that has been settled forever.

2. What is held

What you give us to have an account

What you put into the app

All of it. Plates is a training log, so the point of the product is that it keeps what you write in it:

What the service records by itself

What is deliberately absent

There is no analytics, no advertising, no tracking pixels and no third-party scripts of any kind — on this website or in the app. Nothing about you is sold, rented or shared with anyone for marketing. The fonts are served from our own servers rather than a font network, specifically so that loading a page does not announce you to a third party. The app's Content-Security-Policy forbids it from connecting anywhere except its own origin, which is a rule the browser enforces rather than a promise you have to take on trust.

In this version of Plates, no other user can see anything you write. The social features (Circles) are not switched on, so profiles, posts and walls are visible only to you. If that changes, this policy changes with it, and you will be told before it does.

3. Why, and on what basis

We do not send marketing email. If that ever changes it will be a separate opt-in that you have to actively choose, and unticking it will not affect your account.

4. Cookies

Plates sets exactly one cookie, and it is strictly necessary.

It is HttpOnly (no script on the page can read it, including any script an attacker managed to inject), Secure over HTTPS, and SameSite=Lax so another site cannot make your browser act as you.

There are no analytics, advertising, or preference cookies, and no other local storage is used to identify you. Because the one cookie we set is strictly necessary to deliver a service you asked for, no consent banner is required under the UK's PECR or the EU's ePrivacy Directive — and rather than show you a banner that does nothing, we have written the reason down here instead.

5. Who else touches it

Running a hosted service means other companies hold the data on our behalf. These are all of them. Each is a processor acting on our instructions, under a contract, and none of them may use your data for their own purposes.

That is the complete list. There is no analytics provider, no advertising network, no customer-messaging tool, no AI provider, and no CRM.

6. Health and fitness data

Plates does not ask you for medical information, and it has no fields for conditions, medications, injuries or diagnoses. But it does hold your bodyweight, your sleep, what you eat, your age, your height and your physical performance over time — and free-text notes in which people write whatever they like.

That combination may count as data concerning health, a special category under Article 9 of the UK and EU GDPR, which needs a stronger basis than ordinary personal data. Rather than argue the point, we treat it as though it does:

We have chosen to treat these fields as special-category data and to ask for explicit consent even though it is arguable that a bodyweight is not health data. The cost of being wrong in that direction is one extra checkbox; the cost of being wrong in the other is a special-category breach.

The free-text notes on a session are not covered by that consent, because we cannot know what is in them — they are yours to write, and they are held as ordinary account data under the basis in section 3. Please do not use them to record medical information. If you already have, deleting the note removes it, and deleting your account removes all of it.

What we can say plainly today: this data is never used to profile you, never sold, never shared with insurers, employers or advertisers, and never seen by another user of the app. It exists to be shown back to you.

7. Where it is kept

Your database records are held in the European Union (Frankfurt, Germany) and your uploaded files in Cloudflare R2 under its European Union jurisdiction restriction, which keeps stored objects within the EU. Both therefore sit inside the UK/EEA, so no international transfer mechanism — the UK IDTA or the EU Standard Contractual Clauses — is required for the data at rest.

The website and application code run on Cloudflare's network, which means the server closest to you handles your request wherever you are; your stored data stays in the regions named above.

Two things do leave, and it would be dishonest to leave them out of that sentence. Payment processing (Stripe) and transactional email (Resend) are both run by companies with operations in the United States, and the data they hold — your email address, and for Stripe your billing details and payment history — may be processed there. Each does so under its own data processing agreement with us, carrying the UK International Data Transfer Addendum and the EU Standard Contractual Clauses; those are the transfer mechanisms the paragraph above says are not needed for your training records, and they are needed for these. Nothing you log — no set, session, photo, video or body metric — is sent to either.

8. How long it is kept

9. Your rights

Under the UK and EU GDPR you have the rights below. Two of them are buttons rather than requests, because a right you have to write an email to exercise is a right with a queue in front of it:

We answer requests within one month, as the GDPR requires. There is no charge.

10. How it is protected

No system is perfect. If we ever suffer a breach that is likely to put your rights at risk, we will tell the regulator within 72 hours and tell you without undue delay.

11. The desktop app

The downloadable desktop version of Plates keeps everything in a database file on your own computer. Out of the box it has no account, sends nothing anywhere, and works with no internet connection at all — so for most of what it does there is nothing for this policy to govern.

The one exception is sync, and it is off until you turn it on. The desktop app can be linked to a Plates account so that what you log on your computer appears in the web app, and the other way round. Enabling it takes three deliberate steps in Panel → Sync: entering the address of the server, signing in, and switching it on. Until all three are done, nothing is transmitted and the paragraph above is the whole story.

Once you have turned it on, what travels is your training content — exercises, sets, sessions, programs, your settings and appearance, and the photographs and videos you have attached — and from the moment it arrives here it is covered by the rest of this policy exactly as if you had typed it into the web app. The same rights in section 9 apply to it: you can export it, and you can delete it.

Two things about it are worth stating plainly, because it would be reasonable to assume either the other way round:

Your sign-in for the desktop app is kept in a file separate from your training database, encrypted by your operating system's keychain where it provides one and held only in memory for that session where it does not. Either way it is never written into the database itself — so a backup you make, or send to someone, cannot sign anybody into your account.

12. Age

You must be at least 18 to hold a Plates account. An account is a paid subscription and nothing else, and a contract with a minor is not enforceable the same way everywhere — so rather than sell to someone who cannot be held to the agreement, we do not. If we learn that an account belongs to someone younger, we will delete it.

The free desktop and phone apps are 16 and over, and they have no account, no server and nothing to send anywhere — so there is nothing on that side for this policy to govern until sync is switched on, which needs an account, which needs 18.

We collect a date of birth at sign-up, and it is used for exactly two decisions: refusing an account to anyone under 18, and deciding whether you can give your own consent to health-metric processing. That second permission is available from age 16 — the highest age any EU member state has set for it, applied uniformly rather than varying by country. With the account floor at 18 every account holder is already past it, so in practice that gate never fires on the web; it is kept because it is the same number the desktop app asks, and because the account floor moving must not quietly move this one with it.

13. Changes

If this policy changes in a way that affects you, we will tell you in the app before it takes effect rather than quietly changing the date at the top. The date at the top is the last time anything changed at all.

14. Contact

privacy@plates.cloud — for anything on this page, including access, deletion and complaints. By post, the address in section 1.