Privacy Policy
SquadPT is a scheduling application for planning team physical training. This policy describes exactly what the service stores and who can see it. It is deliberately short because the service collects very little.
What we collect
- A username you choose. No email address is attached to accounts, and none is needed to sign in.
- A password, stored only as a salted cryptographic hash by our authentication provider. We never see or store your password in readable form.
- A display name you set (rank and last name), visible only to your own team.
- The training plan content you enter — session details, group events, and related notes — along with the date each entry was last updated.
- For new-team access requests only: a team name, a short justification, and a contact email used to acknowledge the request and deliver the team's access code. The email is deleted from the application database the moment the request is approved, rejected, or expires; it is never attached to any account. A copy of the request (including the contact email) is also delivered to the platform operator's mailbox for review, and is not retained beyond handling the request.
- For platform administrator accounts only: an Apple push-notification device token, used to alert the operator to new access requests. Member and team accounts never register push tokens.
What we do not collect
- No email addresses or phone numbers are stored for accounts.
- No advertising, no analytics or tracking scripts, and no third-party trackers.
- No location data, no contacts, and no device fingerprinting.
- The only browser storage used is the session token that keeps you signed in and, if you set them, small on-device preferences: your color theme and dismissed first-run hints.
Who can see your data
Content is scoped to your team. Database-level access rules ensure that an account belonging to one team cannot read or modify another team's content. SoloNova LLC does not sell, rent, or share your data with anyone, and does not use it for any purpose other than operating the service.
Where it is stored
Data is held in a managed PostgreSQL database operated by Supabase, hosted in the United States. The website itself is served by Hostinger, and transactional email (access-request acknowledgements and team codes) is delivered by Resend. These providers process data solely to operate the service. All traffic is encrypted in transit using HTTPS.
Retention and deletion
Content is retained until it is deleted by your team or the account is removed. To request deletion of an account or a team's data, contact us at the address below and we will action it.
Contact
SoloNova LLC — info@solonova.io