Privacy Policy
Iron Standard holds training data about athletes, many of whom are minors. That deserves a policy you can actually read, so here is the whole picture: what we collect, why we collect it, who else touches it, and how to get it back or get it deleted.
1. Who this covers
Iron Standard is operated as a sole proprietorship by Victor Brankovich. This policy covers the Iron Standard website, the coach web app, and the athlete app.
Two different roles matter here. For a coach’s own account data and for billing, we decide how the data is used. For athlete data, the organization (the school, college, club, or training business) decides what is collected and why — we process it on that organization’s instructions. If you are an athlete or a parent, your first stop is your organization; we will support any request they pass to us.
2. What we collect
- Coach and staff accounts. Name, email address, password (stored hashed, never in readable form), and — if you sign in with Google — the identifier Google returns.
- Organization details. Organization name, timezone, team structure, and any logo or branding you upload.
- Athlete profiles. Name, email address (when the athlete has an account), sport, position, class year, and a coarse age bracket — under 13, 13–17, adult, or undisclosed. We deliberately do not collect a full date of birth; the bracket is the least information that still lets us flag when parental consent is required.
- Training data. Bodyweight and height, workout logs (sets, reps, loads, velocities), personal records, tested maxes, physical testing results, and attendance.
- Wellness check-ins. Self-reported sleep, soreness, stress, energy, and motivation, free-text notes, body-soreness locations, and coach injury flags. This is health-adjacent information and we treat it that way.
- Coaching content. Messages between coaches and athletes, goals, habits, journal entries, and documents a coach uploads.
- Billing. Billing contact details and subscription status. Card numbers are entered on Stripe’s own pages — we never see or store them.
- Technical data. IP address, browser and device information, and server logs, kept for security and debugging. If you turn on push notifications, we store the browser-issued push subscription needed to deliver them.
3. How we use it
- To run the product: show programs, record training, compute analytics.
- To authenticate you and keep organizations separated from each other.
- To send transactional email and notifications you or your coach turned on.
- To take payment and manage subscriptions.
- To investigate abuse, debug failures, and keep the service secure.
- To improve the product using aggregated, de-identified usage statistics.
What we never do: we do not sell personal data, we do not share it with data brokers, we run no advertising and no third-party tracking pixels, and we do not use athlete data to target anyone with marketing.
4. Who else processes your data
We use a small number of vendors to run the service. They may only process data to provide their service to us.
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, and file storage (United States) | All application data: accounts, rosters, workout logs, testing results, wellness check-ins, messages, uploaded documents |
| Vercel | Application hosting, TLS, and aggregate web analytics | All traffic in transit, IP addresses, server logs, and cookieless page-view counts |
| Stripe | Subscription billing and payments | Billing contact details, payment method, subscription and invoice history — no athlete data |
| Resend | Transactional email (invitations, notifications, password resets) | Recipient names and email addresses, including athletes', plus the message content |
| Anthropic | AI program generation and Ask AI — Elite plan only, under the organization's own API key | Prompt content submitted by coaches, which can include team and athlete names and training data |
| YouTube / Google | Embedded exercise demonstration videos | We send no application data, but loading an embedded player exposes the viewer's IP address and device information to Google |
On the Elite plan, AI features run under the organization’s own Anthropic API key: the key is stored encrypted and calls bill to that organization’s Anthropic account. Organizations that would rather send nothing to a model can simply not configure a key — the AI features stay off.
5. Minors, parents, and schools
Most athletes on Iron Standard are high-school age. Our posture:
- The platform is not directed to children under 13. We do not knowingly collect personal information from a child under 13 without consent obtained by their organization.
- When a coach marks an athlete as under 13, the app shows the coach a reminder that verifiable parental consent — or school authorization on parents’ behalf, where that applies — is required first. The organization is responsible for obtaining it.
- We store a coarse age bracket, not a birthdate, to collect as little as possible from minors.
- We show no ads to anyone and do not profile minors for marketing.
- A parent or guardian can ask their organization to review, correct, export, or delete their athlete’s data, and can ask us directly at victor.brankovich1@gmail.com — we’ll coordinate with the organization that holds the record.
The consent model for under-13 athletes (school-authorized consent versus direct parental consent) is one of the open items with counsel. Until it is settled, treat the paragraph above as our operating practice, not as a final legal position.
6. How we protect it
- All traffic is encrypted in transit (HTTPS), and data is encrypted at rest by our hosting providers.
- Every organization’s rows are isolated at the database level by row-level security, so one organization cannot read another’s data even if application code has a bug.
- Passwords are stored hashed. Stored Anthropic API keys are encrypted.
- Administrative database access is server-side only and limited to the owner.
No system is perfectly secure. If a breach affects your data, we will notify affected organizations promptly and describe what happened and what we did about it.
7. How long we keep it
We keep organization data for as long as the account exists, because a training history only has value over years. When an organization asks us to delete its account, we delete its data from live systems within 30 days, and it ages out of encrypted backups after that. We keep billing and tax records for as long as the law requires.
8. Your rights and your export
You can ask to access, correct, export, or delete personal data, and to object to or restrict certain processing. Depending on where you live (for example California or the EU/UK), some of these are legal rights; we extend them to everyone regardless.
- Export. CSV export is built into every plan, including Starter — you can take your data out yourself, any time, without asking us.
- Deletion. Coaches can delete athletes and content in the app; for a full account deletion, email us.
- Athletes and parents. Contact your organization first — they control the record. We will help them fulfill it.
Requests go to victor.brankovich1@gmail.com. We aim to respond within 30 days and will never charge you for a reasonable request.
10. Where data lives
Data is stored and processed in the United States. If you use Iron Standard from outside the U.S., you are sending your data to the U.S.
11. Changes to this policy
If we change this policy in a way that materially affects you — for example by adding a sub-processor that touches athlete data — we will update this page and notify organization owners by email before the change takes effect.
12. Contact
Privacy questions, data requests, and complaints: victor.brankovich1@gmail.com.
See also our Terms of Service and Refund Policy.