Legal
PrivacyPolicy.
SquadPT is an application for planning team physical training and, where a unit chooses to use it, for recording fitness test results and waist-to-height measurements. This policy describes exactly what the service stores and who can see it. Fitness and body-measurement data is the most sensitive content the service holds, and it is deliberately visible to fewer people than anything else — see Who can see your data.
What we collect
- A username you choose. No email address is attached to accounts, and none is needed to sign in.
- A password, stored only as a salted cryptographic hash by our authentication provider. We never see or store your password in readable form.
- A display name you set (rank and last name), visible only to your own team.
- The training plan content you enter — session details, group events, and related notes — along with the date each entry was last updated.
- For new-team access requests only: a team name, a short justification, and a contact email used to acknowledge the request and deliver the team's access code. The email is deleted from the application database the moment the request is approved, rejected, or expires; it is never attached to any account. A copy of the request (including the contact email) is also delivered to the platform operator's mailbox for review, and is not retained beyond handling the request.
- For platform administrator accounts only: an Apple push-notification device token, used to alert the operator to new access requests. Member and team accounts never register push tokens.
- Feedback you choose to send. If you use the in-app feedback form, we store the message you write along with your username, your team or platoon name, and your role, and relay a copy to the operator’s mailbox so we can act on it. Feedback is kept for one year, which also lets us limit abuse of the form. The form says so where you type: never include a password, and nothing you would not want read by the developers.
- Army Fitness Test results, if your unit records them. For each test: the date, whether it was diagnostic or for record, your age and sex on the test date (used only to select the correct scoring table — we do not store a date of birth), your raw score for each event, whether any event was taken as an alternate event or skipped under a profile, the result of an alternate aerobic event, and any note the person recording it adds. Point values and totals are calculated when displayed and are never stored.
- Waist-to-height measurements, if your unit records them. A waist measurement, a height, the date, and whether the measurement was diagnostic or for record. The ratio itself is calculated when displayed — and compared against the Army’s published standard of 0.55 — but is never stored. This is recorded separately from fitness tests and on its own dates.
- Fitness results and measurements are entered by your squad leader or platoon leadership, not by you, and each record notes who entered it.
SquadPT is not an official record. DA Form 705-AFT and your unit’s Army Body Composition Program screening record remain the systems of record; anything here is a training-management copy.
What we do not collect
- No email addresses or phone numbers are stored for accounts.
- No advertising, no analytics or tracking scripts, and no third-party trackers.
- No location data, no contacts, and no device fingerprinting.
- The only browser storage used is the session token that keeps you signed in and, if you set them, small on-device preferences: your color theme and dismissed first-run hints.
Who can see your data
Training plans and team content are scoped to your team: database-level access rules ensure that an account belonging to one team cannot read or modify another team’s content, and everyone on your own team can see the team’s plans and roster.
Fitness test results and waist-to-height measurements are narrower than that. Database-level rules restrict each soldier’s records to:
- the soldier themselves;
- their own squad leader — not other squads’ leaders;
- their platoon sergeant, platoon leadership, and team administrators or owner.
Nobody else can read them. Other members of your team cannot, other squads cannot, and company-level command accounts cannot. Neither can SoloNova LLC: the operator’s read-only support view, which can open a team to diagnose a problem, is deliberately excluded from these two record types and cannot display them.
Note that marking an event as an alternate event or a profile exemption can imply a medical restriction. That is part of why the visibility rule above is as narrow as it is.
After-action comments are narrower still. When you add an AAR to a training day — what to improve, what to sustain — it is stored under your name, and database-level rules restrict it to you, your own squad leader, and your platoon sergeant, platoon leadership, and team administrators or owner. Other squads’ leaders cannot read it, company-level command accounts cannot, and neither can SoloNova LLC: the operator’s read-only support view is excluded from these comments the same way it is excluded from fitness records.
- Only you can edit your own comment. Nobody — not your squad leader, not an administrator, not the operator — can change the words that appear under your name.
- You, your platoon sergeant, platoon leadership, or a team administrator can delete it. Your squad leader cannot, deliberately: an AAR is often about the training they ran.
One exception worth stating plainly. Before this feature existed, “AAR” was a shared text field on the training day itself, written by whoever was editing the plan rather than by an individual. Any such text entered previously is not covered by the rules above: it is part of the training plan, it stays visible to your whole team, and it remains within reach of the operator’s support view. It is now shown read-only, and it is never carried into a new comment.
SoloNova LLC does not sell, rent, or share your data with anyone, does not use it for advertising or analytics, and does not use it for any purpose other than operating the service.
Where it is stored
Data is held in a managed PostgreSQL database operated by Supabase, hosted in the United States. The website itself is served by Hostinger, and transactional email (access-request acknowledgements, team codes, and relayed feedback) is delivered by Resend. These providers process data solely to operate the service. All traffic is encrypted in transit using HTTPS.
Retention and deletion
Content is retained until it is deleted by your team or the account is removed. Fitness results and measurements can be deleted individually by the squad leader or platoon leadership who can see them, and deleting an account removes that soldier’s results and measurements with it. Feedback messages are kept for one year.
You can delete your own account from inside the app at any time: Profile → Delete account, which asks you to type DELETE to confirm. It signs you out and removes your account together with your fitness results and measurements. If you own a team you will be asked to hand off ownership or remove the other members first; a sole owner deleting their account deletes the team and its plans with it. To request deletion of a team’s data by another route, contact us at the address below and we will action it.
Contact
SoloNova LLC — info@squadpt.com