Policies
Privacy Policy
This document explains what data we collect, how we use it and how we protect it.
What data we collect
- Full name, date of birth (optional), and gender (optional) — collected at registration
- Email address
- Payment information — processed exclusively by Stripe. We never store your card details.
- Video watch progress, viewing history (video, trainer, and seconds watched — retained 2 years), favourites, bookmarks, program and trainer follows, content-category interests, and playback preferences — to power your personalised experience
- Marketing attribution — UTM campaign parameters (source, medium, campaign) are stored in your account record, together with the website that referred you (the site's address only — never the full link you clicked) and the first page of ours you landed on; a first-touch attribution cookie (st_attrib) holds these for 30 days in your browser before you register. A referral attribution cookie (st_referral) is also set for 30 days when you arrive via a trainer link, and a member-invite attribution cookie (st_invite) is set for 30 days when you arrive via a member's invite link
- Trainer video audio — used to generate automatic subtitles (applies to trainers only, not regular members)
- Training preferences — your fitness goal, experience level, weekly session goal, how many days a week you train, and your time zone — used to personalise your plan and reminders
- Support and application forms — if you apply as a trainer or contact us through a form we store the name, email address, phone number, social handle and message you send, along with your IP address and browser string
- Gift purchases — the buyer's email address, the recipient's name, the sender name and the gift message, kept as part of the payment record
- Technical error reports — the page address (or, from the desktop and mobile apps, the app screen), your browser or app version and operating system, and the error text, so we can fix faults
- Device region — for mobile app devices you register for notifications, we store a coarse two-letter country code derived from your connection's network location at sign-in or app launch. It is used for regional service and audience segmentation, the same kind of functional signal as the sm_geo cookie described in the Cookies section below.
- Sign-in history — each time you sign in to your account we record the time, IP address, approximate country (a coarse two-letter code derived from your connection) and the device or browser used. We keep this for 180 days to help secure your account and diagnose sign-in problems; it is included in your data download and deleted when you delete your account.
- Desktop app downloads — if you download a class in our desktop app to watch offline, we record the same account-level facts we already record for downloads in our mobile apps: which class, when, and that your download stays within the limits described in our Terms. The video file itself is stored on your device, encrypted with a key generated on your device and held in your operating system's secure credential store (Keychain on macOS, Windows Data Protection (DPAPI) on Windows, or, on some Linux setups without one of those available, a weaker fallback the app discloses to you before it is used) — we never receive a copy of the downloaded file or its key.
- Desktop app update checks — when the desktop app checks for a new version, it sends your IP address and the app's version number to a Salem Moves–owned update server: dl.salemmoves.app for our global service, or dl.salemmoves.net if the app has placed you on our Iran mirror. That IP address is used only to serve the correct update file and is not linked to your account or stored against it.
Salem Moves is not for people under 16. You must confirm you are at least 16 to register; if we learn an account belongs to someone younger we delete it.
How we use it
To activate your account, process payments, send transactional and lifecycle emails (verification, password reset, payment reminders, account notifications) via SendGrid, personalise your content feed, and improve the platform.
We also send occasional one-time account notices: a single message about your account, or about how the service works where you are. Each of these is sent at most once per account. Because they are service messages about your account rather than marketing campaigns, we may send one even if you did not opt in to marketing email; every one still carries a one-click unsubscribe link, and unsubscribing stops them.
Data sharing with third parties
We never sell your data. Data is shared only with the following processors:
- Stripe — payment processing. Your email address and account metadata are shared with Stripe when you subscribe. Card details are entered directly on Stripe's secure form and are never stored by Salem Moves.
- Cloudflare — hosting, file storage, video delivery, automatic subtitle translation (Workers AI) and bot prevention (Turnstile — used on sign-in and registration forms)
- ElevenLabs — trainer video audio is sent to ElevenLabs for Speech-to-Text subtitle generation. Audio is processed under ElevenLabs' standard data-retention policy.
- Google Analytics — visit analytics, enabled only if you opt in via the cookie-consent banner
- SendGrid (Twilio) — transactional and lifecycle email delivery. Your email address and the full content of emails sent to you (verification, password reset, welcome, payment notifications) are transmitted to SendGrid's API for delivery.
- Telegram — if you link Telegram for member notifications, your Telegram chat id and the text of each notification we send you are transmitted to Telegram's API.
- WhatsApp (Meta) — WhatsApp notifications are not available yet. If we switch them on and you link a WhatsApp number, that number and the text of each notification we send you would be transmitted to Meta. We do not operate a WhatsApp support line.
- Sentry (Functional Software) — error monitoring. When a technical fault occurs, the error text, page address (or app screen), and browser, app or operating-system version are sent to Sentry (EU-hosted, Germany) so we can find and fix faults quickly. Sign-in tokens and credentials are stripped before sending. This does not happen on our .net regional service, or — for the desktop and mobile apps, which can be used from anywhere — whenever the app itself determines you are connecting from Iran: in both cases, only the first-party error report described above is kept, on our own systems.
- Expo (Expo push service) — mobile push notifications. When you allow notifications in the Salem Moves app, the app obtains a push token from Expo and we store it against your account so a notification can reach that device. The token, and the title and body of each notification we send you, pass through Expo's push service on their way to Apple (APNs) or Google (FCM). The token is deleted when you sign out or delete your account. It is not an advertising identifier and is never used for advertising or cross-app tracking.
- RevenueCat — in-app purchase processing for the mobile apps. When you sign in on the Salem Moves app, your account id is shared with RevenueCat so purchases can be matched to your account; when you subscribe through the App Store, Google Play or the Amazon Appstore, the store purchase receipt (product, renewal and refund state, and the price you paid) is shared as well so your purchase can be verified and your subscription activated across your devices. Card details stay with Apple, Google or Amazon and never reach RevenueCat or Salem Moves.
GDPR / UK GDPR rights
If you are an EU or UK resident, GDPR grants you these rights:
- Access to your personal data
- Correction of inaccurate information
- Right to deletion — delete your account yourself from Dashboard → Profile → Delete account; deletion becomes permanent after a 30-day recovery window
- Restriction of processing
- Access and portability — download a machine-readable copy of your data from Dashboard → Profile → Download my data
Contact us to exercise any of these rights.
Cookies
We use the following cookies:
- Essential: authentication cookies (HttpOnly, SameSite=Strict) — required for sign-in to work. A locale-preference cookie (NEXT_LOCALE, 1-year lifetime) remembers your language choice.
- Functional: referral/attribution cookies — st_attrib (30-day lifetime) records how you first found us: any UTM campaign tags on the link you followed, the address of the site that referred you (the host name only — never the full referring link, and never a referral from our own site), and the first page of ours you opened. It is written once, on your first visit, and a later visit never overwrites it; when you create an account these values are copied into your account record and are not used for anything else. st_referral (30-day lifetime) attributes visitors to referring trainers; st_invite (30-day lifetime) attributes visitors to the member who invited them. The relevant identifier is also stored server-side to link your visit to the referrer. On our Iran mirror site, where the st_referral cookie is not used, the same trainer attribution is kept for the duration of your browser session in sessionStorage (st_trainer_ref) instead. None of these is an advertising identifier and none shares data with third parties. A session cookie (sm_geo) may note that you are visiting from a region our error-monitoring service does not operate in, so the site skips it.
- Analytics (with consent): Google Analytics — activated only if you choose "Analytics" in the cookie-consent banner.
- Your cookie choice: your answer to the consent banner is stored in your browser (sm_cookie_consent). You can change it at any time from “Cookie settings” in the site footer.
- Your language choice: when you pick English or Farsi in the first-visit language prompt, your browser stores a flag (sm_lang_prompt) so we do not ask again, alongside the NEXT_LOCALE cookie above. Functional, not analytics — it carries no identifier and is never shared.
Data retention
Your account data is retained while your account is active. Specific retention periods apply to certain data: viewing history — 2 years; in-app notifications — 1 year; security and audit logs (including IP address and browser information) — 2 years; sign-in history (the time, IP address, approximate country and device or browser of each sign-in to your account) — 180 days; session tokens — 30 days. Changes to your records are also written to an internal replication log kept for up to 180 days. When you delete your account it enters a 30-day recovery window; after that your profile is permanently anonymised. Payment and subscription records, revenue-ledger entries and administrative audit rows are kept afterwards for accounting and legal reasons, and deletion can be delayed while money is still owed to a trainer. To improve your class recommendations we also keep a first-party log of the classes we suggest to you, when you start playing them, the searches you run, and when a class you opened was outside your plan — including whether we then showed or quoted you an upgrade, and whether you took it — stored on our own infrastructure for up to 2 years, included in your data download, and deleted (not merely anonymised) when you delete your account. We also record when you start a checkout for a subscription — which plan you chose, and whether the checkout completed, was abandoned or expired — kept on our own infrastructure for up to 2 years, included in your data download, and deleted (not merely anonymised) when you delete your account. Support requests you submit through our contact form or dashboard, and your email replies to them, are processed through our email delivery provider, SendGrid, to provide member support.
Data replication for members in Iran
To keep Salem Moves reachable for members inside Iran when international internet access is disrupted, we run a mirror of the service on a server hosted with ArvanCloud inside Iran. Account and content data — including your account credentials in protected (hashed) form, so that signing in works on the mirror too — is replicated to that server. The mirror is operated by Salem Moves under the same access controls as our main service; the connection that carries the data is authenticated, and the nightly backups taken on that server are encrypted. If you open a support request on the Iran mirror, that request and any reply from our support team travel between the Iran server and our main service over this same connection. This is true even if your own account is not on the mirror at all: a generic notification record about your support requests — for example, that a reply arrived — still replicates to the mirror server, though it never carries the content of your request or our reply, only that an update happened and a link to view it. The desktop app's automatic update check follows the same regional split described above: if the app has placed you on our Iran mirror, it fetches update files from dl.salemmoves.net on the same ArvanCloud server, instead of our global update host. If you have questions about this, contact us at the address in the Contact section below.
Information you make public
Some of what you do on Salem Moves is visible to other people. Comments you post on articles and classes publish your account name and profile picture on a page anyone can read, whether they are signed in or not. If you take part in community challenges, the leaderboard, team rosters and spotlight publish your display name (or the alias you choose), your profile picture, your progress and your team. You control this: you can set an alias, or take part privately so you do not appear on public boards. If you post in a program's community, your display name (or your initials when you have set no display name) and your profile picture are shown to the other members of that program. Your display name, your profile picture and your progress in that program are also shown to them on the program's progress board — but only if you choose to appear on it: it is off unless you turn it on, and you can turn it off again at any time.
Contact
Privacy questions — contact us at salemmoves.app/contact