Overload
Legal

Privacy Policy

Effective and last updated September 16, 2026

Overload is a workout tracker built by a single independent developer, not a company with a data business. This page explains, in full, what the app collects, why, and how you can get it deleted. Your training data is yours — it exists to sync your own splits and logs across your own devices, and for nothing else.

The short version

01 What We Collect

Overload asks for exactly two categories of information — nothing more:

Account
Your email address, and a password used only to authenticate you. Your password is handled entirely by Firebase Authentication using industry-standard hashing — Overload's developer never sees or stores it in readable form.
Training data
Everything you log in the app: workout splits and training days, exercises (including custom exercises you create), individual set entries (weight, reps, and date), and body weight entries.

We do not collect your name, location, contacts, photos, advertising identifiers, or device analytics. Overload has no ad network and no third-party analytics SDK embedded in it.

02 How We Use It

Your information is used for exactly one purpose: running the app for you.

  • Your email and password authenticate you when you sign in.
  • Your training data is synced to your account so it's available on any device you sign into, and so it isn't lost if you uninstall the app or replace your phone.

We do not use your data for advertising, profiling, or any purpose beyond operating the app itself.

03 Where It's Stored

Overload is local-first: a full copy of your training data always lives on your device, so the app works instantly, even offline. In the background, that data syncs to your account on Firebase — Google's cloud application platform — specifically Firebase Authentication (for sign-in) and Cloud Firestore (for your synced training data).

Firestore's access rules are configured so that your data is only ever readable or writable by your own signed-in account — not by other users, and not by anyone browsing Firestore directly.

04 Sharing & Third Parties

We do not sell your data, and we do not share it with advertisers, data brokers, or any third party for their own purposes.

The only third party involved at all is Google, via Firebase — the infrastructure that stores your account and training data on our behalf. Google acts strictly as our service provider and processes that data under its own Privacy Policy and Data Processing Terms.

05 Retention & Deletion

Your data is kept for as long as your account exists, so it's there whenever you sign back in. Signing out (Profile → Sign Out) does not delete anything — it just signs you out on that device.

To permanently delete your account and every piece of data tied to it — on your device and in Firebase alike — email support@overload.health from the address on your account. We'll confirm and complete the deletion within 30 days.

06 Children's Privacy

Overload is not directed at children, and we do not knowingly collect information from anyone under 13. If you believe a child has created an account, email us at the address below and we'll delete it.

07 Security

Authentication is handled by Firebase Authentication, and your training data is protected by per-account Firestore security rules — described in Where It's Stored above. No method of transmission or storage is 100% secure, but no design here relies on secrecy of implementation: access is enforced by your sign-in, not by obscurity.

08 Changes to This Policy

If this policy changes, the update will be posted on this page with a revised "last updated" date above. We won't make changes that reduce your rights over previously collected data without clearly notifying you.

09 Contact

Overload is built and maintained by a single independent developer. For any question about this policy, your data, or a deletion request, reach out directly:

Overload Support support@overload.health