Privacy, in plain words

What ExerciseBank stores, why, where, and for how long. ExerciseBank is a product of TotalCoaching, Montréal, Québec, Canada.

The short version

Your account

When you sign up we store your email address, your company name if you give one, and your password as a salted scrypt hash; we cannot read it. API keys are stored as SHA-256 hashes and shown to you once. Logging in sets one cookie, eb_session, which lasts 30 days, is not readable by scripts, and is used only to recognise your session. Changing your password ends your other sessions.

Messages sent through the help form are stored with the email address you give and forwarded to our inbox so that we can answer.

Your usage of the API

For each API key we count requests per day and per month, signed media links issued, the distinct exercises opened per day, and anomaly notes when traffic looks like bulk copying. This is how plans are measured and how the library is protected; you see the same numbers in your dashboard.

Your users

To issue media links the API asks for an end-user id in the X-End-User header. It is an opaque string of your choosing; we recommend a hash of your own user id and ask you not to send names, emails or anything else that identifies a person. For each calendar month we keep the list of distinct ids your account sent, whether each was marked a coach, and the last day it was seen. That list is what "monthly end users" and coach seats are counted from. We do not receive your users' names, emails, devices or IP addresses: your server calls us, not their phones. When a phone or browser plays a clip, the content delivery network that serves it sees that device's IP address for the length of the request, as any web server does.

Under privacy laws such as the GDPR and Québec's Law 25, you are responsible for your users' data and we act on your instructions for the little of it that reaches us. If you need a data processing agreement, ask through the help page.

Feedback you send

Reports sent through POST /v1/feedback are stored with your account, the end-user id if you included one, the reporter details you chose to add (role, locale, app version, your ticket reference) and a copy of the exercise as it was when you reported it. We use them to correct the library and to answer you.

Payments

Card payments are handled by Stripe. Card numbers never reach our servers. We store your Stripe customer and subscription ids, your plan and your subscription status. Depending on the purchase, Stripe may act as the seller of record and handle tax and invoicing; its own privacy policy applies to the payment.

Where it is kept and who helps us run it

ProviderWhat forWhere
SupabaseThe database: accounts, key hashes, usage counts, feedbackCanada (Montréal region)
VercelRuns the site and the API; keeps short-lived request logs, which include the caller's IP addressCanada (Montréal region) for the API; pages are cached worldwide
StripePayments, invoices, taxUnited States and the regions Stripe operates in
Twilio SendGridAccount and support emailUnited States

We tell paid accounts by email before adding a provider that handles their data.

How long

Your rights

You can see most of what we hold in your dashboard and through the API. To get a copy of everything, to correct it, or to have it deleted, write through the help page from the account's email address; we answer within 30 days. You may also complain to your data protection authority; in Québec that is the Commission d'accès à l'information.

Changes

When this page changes in a way that matters, paid accounts are told by email and the date below changes.

Last updated 2026-09-18. Questions: help.