Legal
Privacy
Last updated 6 September 2026
Reckoner is a strength-training coach: a Garmin watch app, a website, and a server that adapts your programme from what you actually lifted. To do that it holds training and health data about you. This page says exactly what is kept, why, for how long, and how to get it back or have it deleted.
The short version
- Your account is an email address. There is no password; we email a 6-digit code.
- We store your training log (sets, reps, weights, RPE, notes, a heart-rate summary) and a small profile (bodyweight, sex, height, date of birth, goal). That is health data, and it is only there because you enter it.
- Everything lives in one SQLite database on one server in the EU. It is not sold, not shared, not used for advertising.
- We email you to run the account: the sign-in code, an address change, a hold, the reply to something you reported. Those cannot be turned off, because sign-in is passwordless. We may also write about getting started if you signed up and have not, and one click in that email stops it for good while your sign-in codes keep working.
- Two things about you can ever be shown to other athletes: the display name you choose, and only if you say yes, and a founding-member number if you have one. Your email address appears on no page other than the operator's own console. Never to another athlete, and never on a public page.
- If you report a bug or request a feature, what you write appears on the public board right away, in your own words. Your display name is shown only if you have chosen to make it public, and your email address is never shown. Someone at Reckoner reads every submission, responds with a reason, and may clean up the wording or remove a row from the board.
- If you accept, we use Google Analytics to see which features get used. It sets its own cookies, so it runs only with your consent, carries no advertising, and does not follow you to other sites. It receives no account id, no training data and nothing you type, and that is enforced in the code rather than promised.
- Two cookies are set without asking: the sign-in session, and one holding your answer to the analytics banner. Both are set out in full in the cookie policy.
- We log the coaching decisions the engine makes for you and what you did about them, so it can coach you better, and we keep a copy of each one with you taken out of it so the coaching gets better for everybody. That copy carries no name, no email, no account id and nothing you typed.
- Want it gone? Delete the account yourself on the Account page: it erases everything on the spot. Or email hello@reckoner.fit and we will do it for you.
Who is responsible
Reckoner is operated by Inner Skill Set, registered in the Netherlands with the Kamer van Koophandel under number 75619563, and it is the data controller for the personal data described here. The controller and the server are both in the European Union, so the GDPR applies to all of it.
Contact for anything on this page: access, correction, export, deletion, or a complaint at hello@reckoner.fit.
The terms of service, which set out the agreement this data is processed under, are at reckoner.fit/terms.
What we collect, and why
Account
Your email address, and the date the account was created. Signing in mails
you a 6-digit code; the code is stored only as a hash, expires after 60 minutes,
is single-use, dies after 5 wrong attempts, and you can request at most 5 codes an
hour. A successful sign-in creates a session token, stored only as a hash, and sets
one cookie, rk_session, which is HttpOnly, SameSite=Lax, Secure over
HTTPS, and lasts 90 days or until you log out. It exists to keep you signed in.
It is not used for tracking or profiling. That cookie, and everything else this
site keeps in your browser, is listed key by key in the
cookie policy.
Email we send you
Your address is what the account runs on, so some email is not optional and cannot be switched off: the sign-in code, the confirmation when you change your address and the heads-up that goes to the old one, a notice if the account is put on hold and why, and the reply if you report something or send a request. Sign-in is passwordless, so an email you cannot receive is an account you cannot reach, and no setting on this site is allowed to silence it.
We may also write to you about your own account and about getting started. If you open an account and do not finish setting it up, or set it up and have not trained yet, you may get a note about picking it up. That is about your account rather than about anything we sell, and nothing is sold in it. One click stops it, from a link in the email itself: no signing in, no settings page to find, and it takes effect the moment you click rather than at the next send. Your sign-in codes keep working, and so does everything else in the paragraph above.
Two more are yours to set: the weekly numbers, which are off until you turn them on, and the training nudge if you go quiet, which is on unless you turn it off. Those two and the note about getting started all have a row on the Account page, and every recurring message carries the same one-click link. Your mail app may draw its own Unsubscribe button beside any of them, and that does the same thing.
We do not sell your address, rent it, or hand it to anybody to advertise to you, and there is no mailing list you were added to without being told. The address goes to Resend to deliver a message and nowhere else, which is set out under "Where it is stored, and who else touches it".
Your display name, your picture, and what other athletes can see
You can give the account a display name and a picture. Both are optional, both are yours to change or clear at any time on the Account page, and an account with neither works exactly the same: it shows a neutral label and a plain initial. The picture is stored in the database with the account, not uploaded to a file anybody could link to, so deleting the account deletes the picture with it.
The display name is the only thing about you that can be shown to another athlete, and it is shown only if you say so. We ask once, plainly, and both answers are a decision the account keeps: say no, or never answer, and you appear as the neutral label everywhere. There is no setting that has to be found and turned off, because nothing is published until you turn it on. The name has a policy: up to thirty-two characters, at least one letter or number in it, and the terms Reckoner, Admin, Support and Moderator are refused, so nobody can pass themselves off as us.
Your email address is not a fallback for a missing name. That is worth stating because it is the ordinary way an address leaks: a page reaches for "the athlete's name", finds none, and prints the address. Reckoner resolves every name through one piece of code that cannot return an email address at all, so there is no page that could do it by being written carelessly. The only screen in the whole product that shows an email address is the operator's own admin console.
Inviting somebody
You can send one person an invitation from the Invite someone screen. Reckoner writes the mail, it carries your display name and never your email address, and it goes to the address you typed and nowhere else. There are no reminders: one invitation is sent and nothing follows it.
The address you type is not stored. What is kept is a one-way fingerprint of it, a SHA-256 digest, alongside your account and the day you sent it. A digest cannot be read back into an address and cannot be written to, so there is nothing here that any mail could ever be sent from, and no address book of people who never joined. It is kept for one reason: it is the only thing that can recognize the same address a second time, which is what stops a second invitation ever reaching the same person and what holds the limit of five invitations a day. It is deleted with your account.
An invitation to an address that already has a Reckoner account is not sent. Nothing about that is reported back to you, in either direction, so this screen cannot be used to find out whether somebody is here. Reckoner never reads your contacts or an address book, and there is no way to invite more than one person at a time.
Founding members
The first hundred accounts carry a founding-member number and the date it was granted. It is given automatically, in the order accounts were created, and it is permanent: it does not depend on training, it does not lapse, and it is never reissued to somebody else, including after an account is deleted. It is a fact about when you arrived rather than a status you hold.
The number is public in the same way the display name is: it identifies you as one of the first hundred, and nothing else. It carries no email address, no training data and no date of birth. A founding member who has asked not to show a name is shown as their number alone, which is deliberate: the number is what lets two people who chose the same display name be told apart, so opting out of the name costs you nothing else. The total number of founding members is published as a count. No individual account is named by it.
What you report, and what gets published
You can report a bug or ask for a feature from inside Reckoner. What you send is stored: which of the two it is, what you wrote, and, if the form asked, which screen it was about and which of your watches was involved. It is tied to your account, because the answer comes back to you by email. The screen you were on and the watch you were using are not published. They are only there to help the person answering.
What you write appears on the public board right away, in your own words. We do not turn it into a summary first or wait for someone to approve it. The words you send are published on a page anyone can read.
Someone at Reckoner reads every submission and responds with a decision and a reason. We may clean up the wording so it is easier for everyone to understand. If we change the wording, the board makes that clear. We may also remove a row from the board, which removes it everywhere it appears.
Your name is shown only if you have chosen to make it public. If you have allowed us to show your display name, it appears with your submission. If you have a founding member number, that may appear too.
If you have not chosen to show your name, the submission is credited to your member number instead, or to "An athlete" if you do not have one. Anything submitted before 6 September 2026 is shown without a name.
Your email address is never shown on the board or anywhere else another user can see it. It is only visible to us in the operator console.
You can also vote for things on the board. Each person gets one vote per row, and pressing the vote button again removes it. Other users cannot see who voted for what.
If you delete your account, we delete the submissions you made through the board and your votes with them. This is different from the old board, where we published our own write-up of a decision and it could remain after an account was deleted. The board now contains what you wrote, so your submissions leave with your account.
The early-access waitlist
Registration is now open, so the waitlist is closed. If you asked to join before it opened, we still hold the email address you sent and the date you sent it, with a note of whether you have since been invited. We keep it only as a record of who asked, and use it for nothing else. Ask us and we will remove it. Creating an account does not remove the entry on its own: it stays, marked as invited, alongside your new account. Deleting your account deletes it too.
Paired watches
When you pair a Garmin watch, the watch and the site exchange a short code and the
watch receives its own long-lived token (again stored only as a hash). Against it we
keep the label the watch sends (for example Garmin epix2), any
name you give the device yourself, and the created and last-used
timestamps. That is what the Your watches page lists so you can recognize and
revoke a watch. Device tokens do not expire on a timer; they stay valid until you
revoke them on that page.
The watch app also tells us which Garmin model it was built for and which
version of the app is on it, with the time it last said so. It sends those
on the requests it already makes, so we can name your watch on the Reckoner on Garmin
page and tell you when an update is waiting for it rather than telling everyone the
same thing. It also sends the time zone the watch is set to, as a zone name
like Europe/Amsterdam, so a training day you have not finished stays
open until midnight where you actually are rather than midnight where your account
says you live. It is four facts about the watch and none about you, we keep only the
most recent answer, and it goes when you revoke that watch. An older version of the
app does not send them, and then we say nothing about what is on your wrist.
Notifications on your phone or laptop
You can let Reckoner put a notification on your lock screen, one browser at a time, by answering your browser's own permission prompt on the Devices page. Say no, or never answer, and none of what follows exists.
Saying yes makes your browser mint a subscription with the push service its maker runs, and we store exactly what that subscription is: the address the message is delivered to, the two keys your browser hands us to encrypt it with, the date you said yes and the time we last sent to it. The address is a long random URL that belongs to that one browser. It carries no email address, no name and nothing you have logged, and it is held unhashed because it is where the message goes: it has to be used, not compared.
The push service can see that a message went to that browser. It cannot read one. Every message is encrypted to your browser's own keys before it leaves our server, so what the service carries is sealed and it has no way of opening it. There is one kind of message and its words are fixed: a new version of the watch app is out, worded the same for everybody. Nothing about your training is ever sent this way.
It ends four ways and any one is enough: sign out, and this browser's subscription is dropped here and in the browser; turn notifications off in the browser; delete your account; or do nothing, because a subscription the browser has replaced is deleted here the first time a send comes back saying it is gone.
Athlete profile: health data
If you fill it in: bodyweight, sex, height, date of birth, your goal (cut, maintain or gain) and your preferred unit. These feed two things and nothing else: the calorie and macro targets on Today, and the strength standards on the Where you stand page. Leave them blank and those pages simply tell you what is missing.
Training data
Every session you log, from the watch or the website, is stored:
- the training day and plan week, and per exercise the reps for each set, the weight for each set, your RPE, and whether the exercise was done or skipped;
- flags: pain, swap, too hard, or skipped, including the free-text detail you type, and the free-text note you can leave at the end of a session (people describe injuries here, so treat it as health data, because we do);
- a heart-rate summary for the session: average and maximum, and whether it came from a chest strap or the watch's wrist optical sensor. It is a summary only; Reckoner does not receive or store a continuous heart-rate stream;
- provenance: a session id, start and end timestamps, the device label, the watch app version, and, if your watch app supplies one, the Garmin activity id, a number that lets you find the matching activity in your own Garmin account. We store it; we do not use it to fetch anything from Garmin.
From this the engine builds your history: per-exercise progressions, an estimated one-rep max per lift, and the weekly "what changed and why" log.
Kept only in your browser
Some things are kept in localStorage, which is not a cookie and is
never attached to a request: it stays on the device until it is deleted. Your
light/dark theme choice is one, under the key reckoner-theme, so a
page does not draw in the wrong colors before it hears back. Whether you want
kilograms or pounds on the calculators at /tools is another,
under rk_unit. Both hold a setting rather than anything about you:
one of two words, chosen by you on a control, readable by nobody else, and never
sent to us.
The rest is what makes Reckoner work in a gym with no signal.
reckoner-day holds today's training day and the plan it comes out
of, so the app can still show you what to lift when it cannot reach the server.
It is used only on the day it was saved on, and on any later day it is ignored
rather than shown to you. reckoner-outbox holds a session you
logged with no signal, on the device, until it reaches us; it is deleted the
moment it is saved. reckoner-install holds how many times you have
opened Reckoner and whether you have been offered the note about adding it to
your home screen, so you are not asked twice. reckoner-watch-nudge-hidden
holds whether you have dismissed the note about pairing a watch, for the length
of one browser session only, so it does not reappear on every page; how many
times you have actually dismissed it is kept on your account instead.
Two more exist only on the operator console, and only an operator's own browser
ever writes them: reckoner-admin-col-order holds which order that
console's accounts table has its columns in, and reckoner-admin-page-size
holds how many rows of it to show at once. Neither holds anything about an
athlete.
Signing out deletes your day and anything still waiting to be sent, so a shared device does not leave one person's training in front of the next. Clearing your browser data clears all of it. A session that had not yet reached us goes with it, so open Reckoner somewhere with a connection before you clear anything you logged offline. The cookie notice lists every key, including ones nothing writes any more.
Server logs
The web server in front of the app keeps standard access logs (IP address, timestamp, the URL requested, and the browser's user-agent string) for security and troubleshooting. They rotate on the server's normal schedule and are not used to build any profile of you. The application itself writes no per-request log.
Analytics
If you accept it in the cookie banner, we use Google Analytics 4 to understand which features are actually used, so what gets built next follows behavior instead of opinion. It sets its own cookies (named in the cookie policy) and loads only after you consent. Google Signals and advertising personalization are switched off, so this data cannot be joined to an advertising profile or used to follow you to other sites.
What it can see is limited by the code, not by a promise. Every event the site counts goes through a single function, which drops any parameter that is not on a fixed list for that event and rejects any value that is not a number, a true or false, or a member of a fixed set of words. There is no other route to Google. That one rule is what makes it structurally impossible for a name, an email address or anything you typed to leave the page, and it is why the list below is a description of the software rather than an undertaking about our conduct.
What Google receives:
- which page or screen you opened, as a plain word or a fixed address;
- that a feature was used, as one of a fixed list of event names;
- your browser and device type;
- your IP address, which Google truncates, uses to derive an approximate location, and does not pass on to us.
What it never receives, on any of our analytics:
- No account id of any kind. Not your email, not a hash of it, not a session token, not a number standing in for you. Until this page was last updated we did send your numeric account id as Google Analytics' User-ID. We stopped, and nothing replaced it, which means signed-in visits no longer join up over time. That is a real cost and it was accepted deliberately.
- No training data. No loads, reps, RPE, one-rep-max estimates or tonnage; no bodyweight, body fat, height, age or sex. That a feature was used is counted; what you entered into it is not.
- No free text. Nothing you write, in a note, a flag or a form, reaches an event.
- No page titles from the signed-in app, since a title could carry a display name. The app sends a plain word for the screen instead.
- Nothing identifying in an address. Query strings are stripped whole rather than filtered, and any address with a person in it is rewritten before it is sent.
- No raw counts. Numbers are grouped first, even harmless ones: a session with five lifts is counted as "4 to 6".
One consequence is worth stating plainly, because it cuts the other way too. Because we send nothing that identifies you, there is nothing in Google Analytics keyed to you, and so deleting your account cannot delete anything there: there is nothing to find. We would rather say that than promise a deletion we could not carry out. Deletion of everything we do hold about you is covered under Your rights below.
You can withdraw consent at any time from the cookie policy page, which stops the analytics and clears its cookies. If you reject, or if your browser sends a Do Not Track or Global Privacy Control signal, none of it loads at all, and nothing runs quietly in its place. Google is a processor for this, acting on our instructions; details are in the third-parties section below, and the full cookie picture is in the cookie policy.
What we do not do
- No advertising networks, no advertising identifiers, and no ad targeting. The one analytics tool we run is Google Analytics, only with your consent, described under Analytics above, and it carries nothing to any advertiser.
- No selling, renting or sharing of your data with anyone. There are no data brokers involved.
- No advertising or cross-site tracking cookies. The two cookies set without asking are the functional sign-in session and the record of your analytics answer, both described in the cookie policy; the analytics cookies are set only if you accept them.
- No location data, no continuous heart-rate stream, no contacts, no photos.
- We never ask for, receive or store your Garmin Connect password, and Reckoner does not read your Garmin Connect account. The watch app talks only to reckoner.fit, authenticated with the device token you granted it when you paired it.
Legal basis
| Data | Why | Legal basis |
|---|---|---|
| Email, session, device tokens | To give you an account, keep you signed in, and let a watch you paired talk to the server | Performance of a contract, Art. 6(1)(b) |
| Email about your account, and about getting started | So a sign-in code, an address change, a hold or a reply to something you sent us reaches you, and so somebody who opened an account and stopped hears about picking it up | Performance of a contract, Art. 6(1)(b), for the mail that runs the account, which is why it cannot be switched off. Our legitimate interest in the people who signed up actually getting to use what they signed up for, Art. 6(1)(f), for the note about getting started, which you can stop in one click at any time and which stops for good when you do |
| Display name and picture, and whether the name may be shown | So you have something to be called, and so the answer to whether other athletes see it is one you gave rather than one we assumed | Your consent, Art. 6(1)(a), withdrawable at any time by turning it off or clearing the name |
| Founding-member number and grant date | To record that this account is one of the first hundred, which is what the founding-member terms are owed against | Performance of a contract, Art. 6(1)(b) |
| Bug reports, feature requests and board votes | So a problem you found reaches a person, gets answered with a reason, and is visible on the board rather than quietly filed | Our legitimate interest in fixing and improving the service, Art. 6(1)(f). Publishing your display name beside an item rests on your consent to show a name at all, Art. 6(1)(a) |
| Waitlist email | To keep a record of who asked to join before registration opened | Our legitimate interest in holding a record of who asked, Art. 6(1)(f) |
| Notification subscription: the delivery address your browser mints and the keys it encrypts to | So a notice can reach the browser you said yes in | Your consent, Art. 6(1)(a), given in the browser's own permission prompt and withdrawable there or by signing out |
| Training log, plan, history | The service itself: storing what you lifted and adapting next week from it | Performance of a contract, Art. 6(1)(b) |
| Bodyweight, sex, height, date of birth, heart rate, pain and injury notes | Health-related data you choose to enter so the coach can set loads, targets and standards for you | Your explicit consent, Art. 9(2)(a), withdrawable at any time |
| Server access logs | Keeping the service up and secure | Legitimate interests, Art. 6(1)(f) |
| Analytics (page and event data, IP address; no account id) | Understanding how the site is used so it can be improved | Your consent, Art. 6(1)(a), given in the cookie banner and withdrawable at any time |
Withdrawing consent for the health data means clearing those profile fields, or asking us to delete the account. It does not affect processing already carried out.
Automated adaptation
Reckoner automatically changes next week's numbers based on the sets, RPE and flags you logged. That is the product, and every change is explained in the weekly log. It produces no legal or similarly significant effect. When you leave a note, or flag pain or an exercise swap, the day is deliberately not auto-progressed: it is held aside for a person to rewrite. Your data is not sent to any third-party service for that review.
Making the coaching better
Reckoner keeps a log of the coaching decisions it makes for you: a lift reset, a swap offered, what you decided to do about it, and how that lift went afterwards. The log is yours and it is there to coach you. It is how the app knows you have already held through a reset once, so the second time it says something different instead of repeating itself, and it is in your data export with everything else.
A second, de-identified copy of each decision is written with you taken out of it, and we use that set to make the coaching better for everyone. It holds the movement's pattern and muscle, the decision, your answer to it, the result, and a few coarse bands: roughly how long you have been training, an RPE band, and the load step as a percentage rather than a weight. It holds no name, no email address, no account id, nothing you typed and no actual loads. The id it does carry is a random number minted for you and kept in a table of its own, so one lifter's decisions can be studied together without being studied as anybody. Which of these answers actually breaks a plateau, and for whom, is the only question it is used to answer. It is not sold, not shared with anyone, and not used for anything else. Deleting your account deletes the log and the number that links you to it, and what is left in that set can no longer be connected to you.
Where it is stored, and who else touches it
All account, profile and training data lives in a single SQLite database on one server rented from OVH in the EU. Each account's state is isolated by user id. Deployments push code to that server and explicitly never transfer the database, so your data does not travel to a developer machine as part of shipping a release.
That database is backed up, and saying so is part of saying where it is. A compressed copy of it is taken every night and kept on the same server, and a copy of that server's backup set is written off the server once a week, to storage in the EU. A backup is the database as it stood when it was taken, so a backup made before you delete your account still holds what was in it, and every backup made afterwards does not. See "How long it is kept" for how long each one lasts.
These are the parties involved, each narrowly:
- OVH: hosting provider for the server in the EU. They hold the machine the data sits on.
- Resend (Resend, Inc., United States): delivers every email Reckoner sends. That is the sign-in code, the confirmation when you change your address, an account notice, a note about getting started if you signed up and have not, the weekly numbers if you have those turned on, the training nudge unless you have turned it off, and the invitation you send to somebody else, which is the address you typed rather than your own. Which of those you can stop, and how, is set out under "Email we send you". Your address and the words of the message are passed to them to deliver it and for nothing else, and they tell us what became of each one, so a sign-in code that bounced is something we can see rather than guess at. This is a transfer of your email address outside the EU.
- Google (Google Ireland Limited): runs Google Analytics, as our processor and on our instructions, but only for visitors who accept it. It receives page and event data and your IP address, and it sets analytics cookies in your browser. It receives no account id and no training data. Google may process some of this outside the EU under its standard data-transfer safeguards.
- Backblaze (Backblaze, Inc., United States): the weekly off-server copy of the backup set is written to their storage service, into a private bucket in their EU Central region, stored encrypted. Each copy is deleted sixteen days after it is written. The data stays in the EU. They are a US company, so they act as our processor under standard contractual clauses. It is the database as described above, and nobody reads it unless the server is lost.
- The push service your browser's maker runs: only if you turned on notifications, only in that browser, and only ever to carry one sealed message it cannot read. Which company that is depends on the browser you used, because your browser chooses it and tells us where to send. It is described in full under Notifications above.
One thing can be loaded from outside reckoner.fit. Once you accept analytics, the
Google tag is fetched from googletagmanager.com on every page except the
three policy pages, the admin console and our own internal pages, so it never loads
here at all. The icon font the app draws its menu glyphs with used to come from a
public CDN. It is served from reckoner.fit itself now, the same as every other file
on the site, so it is not a second address and there is nothing further to disclose
about it. Your browser's IP address is visible to Google when the tag fetches, and to
nobody else.
How long it is kept
- Account, profile and training history: for as long as the account exists. Nothing is deleted automatically; it is your log and it is meant to be long-lived.
- Display name, picture and founding-member number: for as long as the account exists, and gone with it. A number is never given to anybody else afterwards, which means nothing about you is left behind: what is retired is the number, not a record of who held it.
- What you reported or asked for, and your votes: for as long as the account exists, and gone with it. If you delete your account, what you sent us through the board is deleted with it, along with your votes. It does not stay on the board.
- Waitlist entries: until you ask to be removed, or until an account made from that address is deleted, which takes the waitlist entry with it. Signing up does not by itself clear the entry: it stays, marked as invited, so we can tell who has taken up a place.
- Invitations you sent: the one-way fingerprint of each address and the day you sent it, for as long as the account exists, and gone with it. There is no address to keep and none is kept.
- Sign-in codes: 60 minutes, and deleted the moment they are used.
- Sessions: 90 days, or immediately when you log out.
- Pairing codes: 5 to 10 minutes, single-use, deleted once the watch has its token.
- Device tokens: until you revoke the device.
- A notification subscription: until you sign out of that browser, turn notifications off in it, delete the account, or the browser replaces it, whichever comes first.
- Server access logs: until the server's standard log rotation removes them.
- Backups of the database: a copy is taken nightly and the most recent fourteen are kept, so a nightly copy is gone about a fortnight after it was made. A copy of the server's backup set is written off the server once a week, to storage in the EU, and each of those is deleted sixteen days after it was written. A backup is a copy of the database at one moment, so it holds whatever was in the database that night and nothing that happened afterwards.
Your rights
Under the GDPR you have the right to access your data, correct it, have it erased, restrict or object to processing, withdraw consent, and receive it in a portable format. You also have the right to complain to a data protection authority: your own national one, or ours, which is the Dutch Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). Telling us first is welcome but it is not a precondition, and you never have to go through us to reach them.
- See and export your data. Signed in, the site's own JSON endpoints return it directly in your browser:
/athlete,/plan/current,/session/week,/week/changelogand/auth/devices. That is machine-readable JSON, the portable format. Or email us and we will send the full export. - Correct it. Profile values are editable on the Setup page; a watch can be renamed on the Your watches page. Your display name, your picture and whether the name may be shown to other athletes are all on the Account page, and changing any of them takes effect at once. The founding-member number is the one thing that cannot be edited, by you or by us, because a number that could be changed would not be a record of when you arrived.
- Revoke a watch. Your watches page; revoking deletes that device's token immediately.
- Delete everything. Signed in, the Account page lets you do it yourself: type your own email address to confirm, and the account, the profile, the entire training history, every paired watch's token, any notification subscription, everything you reported or voted on and your entry on the early-access waitlist are removed from the database immediately, not queued and not hidden. Nothing is held back to restore you from: the only copies left anywhere are the backups described above, which are read only if the server is lost and which age out on the schedule in How long it is kept. Taking the waitlist entry too means your address is genuinely gone, at the cost of your place: getting back in means asking again. It happens while you wait, all of it or none of it, and signs you out. If you would rather we did it, email hello@reckoner.fit from your account address and we will run the same deletion, within 30 days and normally much sooner. We will confirm when it is done.
Security
Sign-in codes, session tokens and device tokens are never stored in readable form, only as SHA-256 hashes, so a copy of the database does not hand someone your sessions. The site is served over HTTPS only, and the session cookie is HttpOnly, Secure and SameSite=Lax. Each account's state is isolated per user id, and every request must present a valid session cookie or device token before any of it is returned. No system is perfect; if you believe something is wrong, tell us at hello@reckoner.fit.
Children
Reckoner is not intended for anyone under 13, and we do not knowingly hold data about children. Onboarding asks for a date of birth and refuses to build a program for anyone below that age. In some countries a person under 16 cannot give the explicit consent the health data above relies on without a parent or guardian, so if that is your situation, get it before filling in the profile. If you believe a child has an account, email us and we will remove it.
Not medical advice
Training loads, calorie targets and strength standards produced by Reckoner are approximate and evidence-informed, a starting point to adapt, not a medical or dietary prescription, and not a diagnosis.
Changes
If this policy changes, the date at the top changes with it. A material change is announced in the app and emailed to every account, saying what actually moved rather than that something did, because a notice nobody can act on is a notice nobody reads. That email is about your own data, so it goes to everyone, including anybody who has turned off the note about getting started. The current version is always at https://reckoner.fit/privacy.