Privacy Policy
Version 2.2 · Effective from 2026-09-08
1. Data Controller
Setlist ("we", "us") is the data controller for your personal data. Contact: hello@setlist.no You can contact us at any time with questions about privacy or to exercise your rights under the GDPR.
2. What data we collect
We collect the following categories of personal data: Profile data: Username, display name, email address, profile picture. Date of birth: When you sign up, you provide your date of birth to confirm you are 16 or older — this is used only for that age calculation and is not stored. You can additionally, optionally, add a date of birth in your profile settings to get more accurate heart-rate-zone and calorie calculations; this version is stored on your account until you delete it or your account. Training data: Workout sessions with duration, distance, intensity, and interactions (kudos given, comments, saved sets). Location data (GPS): If you use an outdoor activity and grant permission, we record GPS coordinates, speed, and elevation during your workout. We may request "always" location permission (background) for more reliable GPS tracking during an ongoing session, but we never record location data in the background outside an active workout. Health data (with your consent): Heart-rate data and other biometric data may be recorded via a connected heart-rate monitor or imported from Apple Health / Google Health Connect. These are processed only with your explicit consent (GDPR Article 9). Third-party sign-in data: If you sign up or sign in with Sign in with Apple or Google, we receive your name and email address from Apple or Google respectively to create and identify your account. See section 6 for details on this sharing. Technical data: IP address (at login), device type and identifier, app version, and anonymous usage data (PostHog). Push notification token (via Expo Push Service). We do not use advertising identifiers (such as IDFA on iOS or GAID on Android), and your data is never used for ad tracking or retargeting. Content you create: Interval sets, photos attached to workouts, comments, group posts, and descriptions.
3. Legal basis (GDPR)
We process personal data on the following legal bases: Contract (Article 6(1)(b)): Profile and training data necessary to deliver the service. Consent (Articles 6(1)(a) and 9(2)(a)): Heart-rate and other health data. GPS tracking. Push notifications. Usage analytics and crash reporting. You can withdraw consent at any time in Settings. Legitimate interests (Article 6(1)(f)): Security, abuse prevention. Legal obligation (Article 6(1)(c)): Where we are required to retain or disclose data under Norwegian law.
4. Purpose and use of data
We use your data to: • Provide and improve training and interval-training features • Show your activity history, statistics, and progress • Enable social features (following users, groups, challenges) • Send push notifications you have enabled • Analyse product usage anonymously to improve the service, with your consent (PostHog, EU servers) • Handle subscriptions and billing (RevenueCat, EU server) • Prevent abuse and maintain security We never use training or health data for marketing directed at third parties, and we never sell your personal data.
5. Automated coaching and recommendations (AI)
Setlist uses an internal recommendation engine ("CoachingEngine") that analyses your training history — completed sessions, intensity, heart-rate data (only where you've given consent), and goal achievement — to generate: • Personalised training suggestions and progression in training plans • Predictions for race times and fitness trends • Explanatory feedback and insights after a completed session These are advisory recommendations, not automated decisions with legal effect on you (cf. GDPR Article 22). You always decide for yourself whether to follow a suggestion, and can always choose a different training plan or disregard the recommendation. The calculations are made from your own training data and are not shared with third parties.
6. Data processors and sharing
We never share personal data with third parties for their own marketing purposes. We use the following data processors, who process data on our behalf: Supabase (EU — Ireland): Database storage, authentication, and file storage. All data is stored primarily in the EU. RevenueCat (EU server): Subscription management. Processes only transaction data. PostHog (EU): Anonymous product analytics. No directly personally identifiable data is shared. Sentry (USA): Crash reporting. Not currently active — no data is sent to Sentry yet. Will only be enabled with your consent if/when crash reporting is turned on. Expo (USA): We register your device for a push token via the Expo Push Service, so we can send you notifications you've enabled. Receives only the push token, not the content of your notification. Note: notification delivery may currently be unreliable while this feature is being finalized. Apple / Google (as data processors): Payments via the App Store / Google Play. If you use Sign in with Apple or Google, they also act as independent data controllers for the authentication data (name, email) they themselves handle — see their own privacy policies. Google Maps: Map display in the app. Google receives technical requests for map tiles (no location data is sent unless you navigate the map yourself).
7. Transfers to third countries
Some of our data processors (Expo, as well as Apple and Google acting as independent controllers for sign-in data) are located in, or transfer data to, the USA. These transfers are secured using the EU's Standard Contractual Clauses (SCC), cf. GDPR Article 46, supplemented where relevant by the EU-US Data Privacy Framework where the provider is certified. Sentry (also USA-based) will be added to this list if/when crash reporting is activated. All primary data (workout sessions, GPS, profile) is stored on Supabase servers in the EU (Ireland). RevenueCat and PostHog also process data on EU servers.
8. Retention period
We store personal data for as long as your account is active. Training data and GPS tracks are retained for the account's entire lifetime, as this is the core value of the service to you. If you delete your account, all personal data is deleted within 30 days, cf. GDPR Article 17. Anonymised aggregate statistics may be retained for service improvement. Push notification tokens are deleted when you log out or disable notifications. Usage analytics data (PostHog) is retained for up to 12 months, after which it is automatically anonymised by the provider. Security and abuse-prevention logs are retained for up to 90 days.
9. Your rights (GDPR Articles 15–22)
You have the following rights: Access (Article 15): The right to know what data we hold about you. Use "Export my data" in Settings → Privacy & Data. Rectification (Article 16): The right to correct inaccurate data. Done directly in the app via Edit Profile. Erasure (Article 17): The right to delete all your data. Done via Settings → Privacy & Data → Delete Account. Restriction (Article 18): The right to restrict processing in certain cases. Contact us. Data portability (Article 20): The right to receive your data in a machine-readable format (JSON). Done via Settings → Privacy & Data → Export My Data. Objection (Article 21): The right to object to processing based on legitimate interests, including opting the CoachingEngine out of using your training data (you can still use the app without personalised recommendations). Contact us. Withdrawal of consent (Article 7): You can withdraw consent to health data, GPS tracking, usage analytics, and crash reporting under Settings → Privacy & Data. To exercise your rights, contact hello@setlist.no. We respond to requests within 30 days.
10. Tracking, analytics, and local storage
We use PostHog to analyse how the app is used, only with your consent — anonymised and containing no directly identifying information, running on EU servers. Crash reporting via Sentry is built into the app but not currently active; once enabled it will also require your consent, and Sentry is located in the USA (see section 7 on transfers to third countries). You can disable both usage analytics and crash reporting together under Settings → Privacy & Data → Usage Analytics. The app does not use cookies in the traditional web-browser sense, but stores equivalent data locally on your device: authentication token (securely, via your device's Keychain/Keystore), language preference, temporary workout data for offline use, and an anonymous analytics ID. This local storage is necessary for the app to function and is deleted when you uninstall the app or delete your account. We do not use advertising identifiers and do not share data with ad networks or data brokers.
11. Children’s privacy
Setlist is not intended for children under 16. We do not knowingly collect personal data from children under 16, and we verify age at sign-up. If you are a parent and believe your child has registered, contact us at hello@setlist.no and we will delete the account immediately.
12. Security breach
If we discover a personal-data breach that poses a risk to your rights and freedoms, we will notify you without undue delay and no later than 72 hours after becoming aware of the breach, cf. GDPR Articles 33–34.
13. Changes to this Privacy Policy
We may update this Privacy Policy as needed. You will be notified via push notification or email of material changes, with at least 14 days' notice. The current version is always available in the app under Settings → Terms & Privacy.
14. Right to complain in Norway/EU/EEA
You have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet, www.datatilsynet.no) if you believe we are processing your personal data in violation of the GDPR. Datatilsynet Postboks 458 Sentrum, 0105 Oslo, Norway Tel: +47 22 39 69 00 If you live in another EU/EEA country, you may also complain to your own country's supervisory authority.
15. Your rights in the United Kingdom (UK GDPR)
If you live in the United Kingdom, we process your personal data in accordance with the UK GDPR and the Data Protection Act 2018, which grants you the same rights described in section 9. You have the right to complain to the UK supervisory authority if you believe we are processing your personal data in violation of applicable law: Information Commissioner's Office (ICO) Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF ico.org.uk / Tel: +44 303 123 1113 Transfers of your data out of the UK (to our EU-based processor Supabase, among others) are secured through mechanisms approved under the UK GDPR, including the EU's Standard Contractual Clauses as adapted for UK law (the UK IDTA/Addendum).
16. Your rights in California, USA (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you the following rights in addition to those described in section 9: Right to know: What categories of personal data we have collected about you over the past 12 months, and the purpose of that collection — see sections 2 and 4 for a full overview of categories and purposes. Right to delete: As described in section 9 (Erasure). Right to correct: As described in section 9 (Rectification). Right to non-discrimination: We provide the same service and quality regardless of whether you exercise your privacy rights. We do not sell or share your personal data with third parties for monetary value or for third parties' own advertising purposes, and have not done so in the past 12 months. Setlist therefore has no "Do Not Sell or Share My Personal Information" mechanism to offer, since there is no sale or such sharing to opt out of. We do not process sensitive personal data (such as health data) for any purpose other than delivering the service you request, and never use it to infer characteristics about you for other purposes. To exercise your CCPA/CPRA rights, contact hello@setlist.no. We may ask you to verify your identity before processing the request, in accordance with the law.
17. Your rights in Australia (Privacy Act)
If you are an Australian resident, we process your personal data in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth), which grants you access, correction, and complaint rights equivalent to those described in section 9. If we experience a data breach that is likely to result in serious harm to you, we will notify you and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme (see also section 12 on notification timelines). You can complain to the Office of the Australian Information Commissioner (OAIC) if you believe we are not complying with the APPs: Office of the Australian Information Commissioner GPO Box 5288, Sydney NSW 2001 oaic.gov.au Transfers of your data out of Australia (to our EU-based processor Supabase, among others) are made only to providers contractually bound to a level of protection substantially equivalent to the APPs.
18. Contact
For questions about privacy or to exercise your rights, contact: Email: hello@setlist.no We respond to inquiries within 30 days.