Exercises Coverage check Guides Pricing Start free

Privacy Policy

Last updated: July 7, 2026

This Privacy Policy explains what data Full Coverage ("we", "us") collects at fullcoverage.app, why, and what your rights are. The short version: we collect the minimum needed to run a workout tracker, we don't run ads, and we never sell your data.

1. Data we collect

2. Cookies

We use a single first-party, HttpOnly session cookie (auth-token) to keep you signed in for up to 7 days, plus a short-lived cookie during Google sign-in. No advertising or cross-site tracking cookies.

3. How we use data

To operate the Service (sync your training log across devices), to secure it (rate limiting, abuse prevention), to send transactional email (verification, password reset, billing notices), and to provide paid features. We do not send marketing email without separate consent, and we do not sell or rent personal data.

4. Processors we share data with

Hosting is on our own server; your training data is stored there and is not shared with anyone else.

5. Retention and deletion

Your data is kept while your account exists. You can export your training log from Settings at any time. You can also delete your account yourself, from Settings → Data → Delete account: it is immediate and permanent, and it removes your account record and your entire training log together. If you can no longer sign in, request deletion through our contact form and we will complete it within 30 days. Encrypted backups expire on a rolling basis within 30 days and are never used to restore a deleted account. See Delete your account and data for the full detail of what is removed and what we are required to keep.

6. Your rights

Depending on where you live (e.g. GDPR in the EU/EEA), you may have rights to access, correct, export, restrict or delete your personal data, and to lodge a complaint with a supervisory authority. Contact us and we will honour these requests for all users regardless of location.

7. Security

Passwords are hashed with bcrypt, transport is TLS-encrypted, sessions use HttpOnly cookies, and the server applies standard hardening headers and rate limits. No system is perfectly secure; if we learn of a breach affecting your data we will notify you without undue delay.

8. Children

The Service is not directed at children under 16 and we do not knowingly collect their data.

9. Changes

We will post any changes here and update the date above; material changes will be announced by email or in-app notice.

Questions? Contact us.