Cntinue — Privacy Policy
Cntinue is a training log. This policy describes exactly what it collects, where that data goes, and what never leaves your phone.
Effective 7 September 2026 · Last updated 7 September 2026
1. Who we are
The controller of your personal data is Est Normalis OÜ, Tartu mnt 67/1-13b, 10115 Tallinn, Estonia (VAT EE102370900).
For anything in this policy — a question, a request, a complaint — write to admin@estnormalis.com.
2. What this covers
The Cntinue mobile app on iOS (com.est-normalis.cntinue-fe)
and Android (com.estnormalis.cntinuefe), and this website,
estnormalis.com.
3. What we collect, and why
- Your email address
- Held so you can sign in and so we can reach you about your account. You sign in with a one-time code sent to that address, or with Sign in with Apple. We never see or store a password.
- Your profile
- Display name, profile photo, date of birth, gender, chosen member-card design, and whether your profile is public. Date of birth and gender are optional and used to make training suggestions relevant; leaving them blank does not stop the app working.
- Your training history
- Workouts, exercises, sets, reps, weights, distances, durations, routines, the equipment you have, your favourites, and workout battles you take part in. This is the app.
- Who you follow and who you block
- Follow and block relationships, and the feed entries produced by your workouts. Whether your workouts appear in anyone else's feed is governed by your own public/private setting and by who follows you.
- Photos and video you choose to upload
- Profile pictures and images or clips you attach to an exercise or a workout. Please note these are stored on unguessable but publicly readable URLs, so that the app and its caches can load them: anyone holding the exact link can open it.
- A push notification token
- Only if you turn notifications on. It identifies your device to Apple's and Google's push services so a notification can reach it, and nothing else.
- Crash and error reports
- When the app fails, we receive the error, its stack trace, the app version, the operating system version and the device model, through Sentry. Personally identifying data is switched off in that integration: your name, your email and your training data are not attached. We collect no performance traces, no session replays and no profiling.
Your address book — only when you ask
If you open the Find people screen and grant contacts permission, the app reads the email addresses in your address book and sends them to our server to check which of them already belong to Cntinue accounts, so it can show you who to follow.
Those addresses are compared in memory and thrown away with the reply. They are never written to a database and never written to a log — our logs record how many addresses were checked, never which. Your contacts' names never leave your phone at all, and your own address is filtered out before the request is made. If you never open that screen, no contact data is read and no permission is requested.
4. What never leaves your phone
Two of the app's features look like they would need a server. Neither one does — both run entirely on your device:
- Speaking a set. When you say "85 kilos, 12 reps", the audio is captured and transcribed on the phone by a speech model running locally. The recording is not uploaded, not stored, and not sent to any transcription service.
- Pointing the camera at equipment. The photo is analysed on the phone by a local vision model to guess what machine you are looking at. The photo is not uploaded and is not kept.
The model files themselves are downloaded once, the first time you use each feature. That download carries no data about you — it is the same file for everybody.
Cntinue is also offline-first: your training data lives in a database on your phone and is synchronised with your account so you can use the app with no signal.
5. What we do not do
- We do not sell or rent your data, to anyone, ever.
- We show no advertising and share nothing with advertising networks.
- We use no analytics or tracking SDKs. Crash reporting is the only diagnostic integration in the app.
- We do not collect your location. The app requests no location permission.
- We do not build profiles about you for anyone else's purposes.
6. Coaching advice
The app can suggest a workout and explain why it is suggesting it. Which muscle groups to train, how many sets and what rep range are decided by fixed rules on our own servers, from your own training history. Two steps of that are then handed to a language model hosted by Anthropic (Claude Haiku): choosing and ordering exercises from a fixed list we supply, and rewriting our reasons into readable sentences.
What is sent to Anthropic, and only this:
- The list of exercises the suggestion may choose from — the shared exercise library plus any exercises you created yourself — with the target muscle groups and a set and rep range.
- Short sentences our own rules had already written, such as which muscle group you have not trained in a while.
Your name, your email address, your account identifier, your photos and your workout log are not sent. Anthropic processes this on our instructions as a sub-processor, under commercial API terms that do not use the data to train models. The feature is optional in the engineering sense too: if the model is unavailable or returns anything unexpected, the suggestion falls back to the rules alone, and the app still works.
7. Legal bases
Under the GDPR we rely on:
- Performance of a contract (Art. 6(1)(b)) for your account, your profile, your training history and the social features — without this data there is no app to provide.
- Consent (Art. 6(1)(a)) for access to your contacts, your camera, your photo library, your microphone and push notifications. Each is asked for separately, at the moment it is first needed, and each can be withdrawn in your device settings without losing the rest of the app.
- Legitimate interests (Art. 6(1)(f)) for crash reporting and security — keeping the app from breaking, and finding out why when it does.
8. Who processes data on our behalf
We use the following providers. Each acts on our instructions only, under a data processing agreement.
| Provider | What it does | Where |
|---|---|---|
| Supabase | Database, authentication, file storage | EU (Stockholm) |
| PowerSync | Synchronises your data between phone and database | EU (Ireland) |
| Hetzner Online GmbH | Hosts our application server | EU (Finland) |
| Anthropic PBC | Generates coaching suggestions — see section 6 for exactly what is sent | United States |
| Functional Software, Inc. (Sentry) | Crash and error reporting | United States |
| Expo (650 Industries, Inc.) | App updates and push notification delivery | United States |
| Apple, Google | App distribution, push delivery, Sign in with Apple | United States and EU |
Where a provider is outside the EEA, the transfer is covered by the European Commission's Standard Contractual Clauses or by the EU–US Data Privacy Framework.
9. How long we keep it
- Your account and training history: until you delete your account.
- Workouts you started but never finished: deleted automatically after 30 days.
- Crash reports: 90 days, then deleted by Sentry.
- Contact email addresses sent for matching: not retained at all — they exist only for the duration of the request.
10. Deleting your account
In the app: Profile → settings → Edit Profile → Delete account. You confirm twice, and the account is then erased immediately — your profile, training history, feed entries, uploaded media and push tokens go from our servers, and the copy on your phone is wiped with them. There is no grace period and no undo.
If you cannot get into the app, write to admin@estnormalis.com from the address your account uses and we will do it for you within 30 days of confirming the request is yours.
Battles you took part in stay with the people you competed against, with your identity removed: you appear there as "Unknown user", with no score. Anonymous, aggregated counts that cannot be traced back to you also remain. The full procedure, and exactly what survives, is on the account deletion page.
11. Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, hand it to you in a portable format, or object to processing based on legitimate interests. Where we rely on consent you may withdraw it at any time, which does not affect what we did before you withdrew it.
Write to admin@estnormalis.com. We answer within one month.
If you think we have handled your data badly you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee), or to the supervisory authority in the country where you live.
12. Children
Cntinue is not intended for children under 16, and we do not knowingly collect data from them. If you believe a child has created an account, write to us and we will remove it.
13. Security
Everything between the app and our servers travels over TLS. Access to your rows in our database is enforced per-user at the database itself, not only in the app. Data at rest is encrypted by our hosting providers. No system is perfect; if a breach ever affects your data we will tell you and the supervisory authority as the GDPR requires.
14. This website
estnormalis.com sets no cookies, runs no analytics and has no tracking. It does load the Montserrat typeface from Google Fonts, which means Google receives your IP address and browser details when a page loads — that is the only third party this site contacts.
15. Changes to this policy
If we change how we handle your data we will update this page and move the "last updated" date at the top. Material changes will also be announced in the app.