Ordivum
Privacy Notice
Last updated: 27 July 2026
This notice explains what personal data Ordivum uses, why it uses it, who receives it, how long it is kept, and the choices and rights available to you. It covers the website and the Ordivum iOS app.
1. Controller and contact
Ordivum is operated by Thomas William Delaney, an individual based in England, United Kingdom, trading as Ordivum. Thomas William Delaney is the data controller.
Privacy requests and questions: thomaswdelaney115@hotmail.com
2. Data, purposes, and legal bases
Swipe horizontally to read each purpose and legal basis.
| Data | Why we use it | Legal basis |
|---|---|---|
| Email, password hash, authentication state | Create and secure your account; send essential account messages | Contract, UK GDPR Art. 6(1)(b) |
| Exact date of birth, age declaration and reauthentication time | Enforce the 13+ account and AI boundary and apply age-appropriate safeguards | Contract and legitimate interests, Arts. 6(1)(b) and 6(1)(f) |
| Keyed email and IP fingerprints after a confirmed under-13 DOB | Prevent registration until the declared thirteenth birthday without retaining the raw email or IP in the block record | Legitimate interests and child protection, Art. 6(1)(f) |
| Display name, optional avatar, preferences, timezone | Personalise the service and show records on the correct local day | Contract, Art. 6(1)(b); consent for an optional avatar, Art. 6(1)(a) |
| Workout, exercise, recovery, notes, and progression records | Provide your training ledger, calculations, history, and progress analysis | Contract, Art. 6(1)(b), plus explicit consent for health data, Art. 9(2)(a) |
| Programme-authored preparation, completion or skip records, manual movement-check definitions and results, frozen methods and conditions, and short-lived feature-access metadata | If independently enabled for your account, provide optional preparation and repeatable manual fitness observations; enforce the release boundary; preserve exact private history; export or erase it | Contract, Art. 6(1)(b), plus explicit consent for health data, Art. 9(2)(a); legitimate interests, Art. 6(1)(f), for minimal release-security metadata |
| Optional programme safety signal and private note | Stop the selected programme item, preserve your private safety history, synchronise it, and include it in your export | Contract, Art. 6(1)(b), plus separate explicit consent, Art. 9(2)(a) |
| Nutrition, water, supplements, height, age, sex, targets, body weight and measurements | Provide nutrition logging, estimates, trends, and body-progress features | Contract, Art. 6(1)(b), plus explicit consent, Art. 9(2)(a) |
| Progress and meal photos | Store and show your private visual records | Contract, Art. 6(1)(b), plus explicit consent, Art. 9(2)(a) |
| Consent statement, version, action, time, and platform | Record and demonstrate your legal choices | Legal obligation and legitimate interests, Arts. 6(1)(c) and 6(1)(f) |
| IP address, request, authentication, and security logs | Operate and protect the service; prevent fraud and abuse | Legitimate interests, Art. 6(1)(f) |
| Support messages and privacy requests | Respond, keep a record, and resolve complaints | Contract, legal obligation, and legitimate interests as applicable |
We receive data directly from you, from your device when it provides technical context such as timezone, and from Supabase when it authenticates and serves your account. We do not buy personal data, sell it, build advertising profiles, or use it to train AI models. We do not make solely automated decisions that have legal or similarly significant effects on you.
AI features are not active and no account record, prompt or photo is currently sent to an AI provider. Planned paid AI for eligible users aged 13+ requires a separate explicit choice and an updated notice before processing begins. The AI Notice describes that prepared boundary.
3. Health and fitness consent
Fitness records can reveal information about your physical health and are treated as special category data. Account terms and age confirmation are presented separately from an unticked, explicit health-data consent. If you consent, we record the wording, policy version, time, action, and whether the choice was made on web or iOS.
A personal fitness ledger cannot operate without processing the fitness information you ask it to store. You may decline and sign out. You may also withdraw later in Settings → Data & privacy. Withdrawal erases the health and fitness records held in your account, clears the app's relevant device cache when that device next processes the withdrawal, and prevents new health-data entries until you make a new explicit choice. Your basic account and immutable consent history remain so we can respect and demonstrate the withdrawal. Withdrawal does not make earlier lawful processing unlawful.
3A. Optional programme safety records
During a programme workout, you can choose to record one of a short list of factual concerns: pain or discomfort that is sharp or increasing, numbness or tingling, instability or giving way, or pain that changes your technique. You may add a private note. This stops the affected preparation step or its linked programme item and keeps a factual safety-history entry; it does not diagnose the cause, decide whether another exercise is medically safe, prescribe treatment or rehabilitation, or replace a qualified health professional or emergency service.
This optional processing has its own unticked explicit-consent choice at the first safety interaction. It is separate from the service-wide health choice, Terms, marketing, AI and subscriptions. Refusing it leaves ordinary workout logging and the non-symptom substitution route available. Safety records are private by default, are not shared with another user or coach, and use the same high-privacy defaults for adult and teen accounts.
You can withdraw this programme-safety choice in Settings without withdrawing the wider ledger consent. Withdrawal deletes the programme safety events and optional notes held for your account, removes queued copies and the relevant cache when the current iOS device processes the change, reopens affected programme items, and blocks new safety records until you make a fresh choice. Ordinary set, session, nutrition and body records remain. A lost or offline device cannot receive the deletion instruction until it reconnects or its owner erases it. We retain the minimal consent-event evidence needed to respect and demonstrate your choice.
3B. Programme preparation and manual movement checks — prepared, held inactive
At the date of this notice, these two capabilities are prepared in the service but held off for general customer use behind independent server-controlled release switches. The presence of a screen or database structure does not mean either capability is active for your account. While a switch is off, Ordivum blocks new authoring, new standalone movement-check results, publishing affected programme changes and starting an affected session at the database boundary.
If enabled later, programme preparation can store an author's ordered title, explanation, movement, side, repetitions, time, distance or load target and whether you manually completed, skipped or stopped a step. A performed exercise-specific ramp can create one linked warm-up set. Preparation remains skippable, is excluded from working-set progression, volume, personal records and adherence penalties, and does not use an Apple sensor or infer that a movement was performed.
Manual movement checks can store a private reusable label, dimension, side rule, written method, method version, repeatability conditions, entered value and unit, canonical conversion, measurement time and optional note. A comparison is shown only for the same method version, dimension and side. It is a factual comparison of values you entered, not a normal range, diagnosis, injury assessment, treatment recommendation or sensor-derived measurement.
Revoking a release switch does not hide or silently discard existing records. An already-started frozen session remains finishable. Existing definitions and results remain readable, exportable and erasable: individual results can be deleted, definitions can be archived, wider health-consent withdrawal removes the authored preparation, checkpoints, manual results and runtime preparation records, and account deletion removes the remaining live rows. Minimal feature-access metadata contains only the account identifier, two release decisions, check time and source revision; it contains no movement or measurement content.
4. Children and age
You must be at least 13. Signup asks for your exact date of birth and an affirmative statement that it is yours and accurate. We do not ask for an ID document or use a third-party age-check provider. This reduces data collection and friction but cannot prove that a stated DOB is true. If you believe an under-13 has an account, contact us so it can be investigated, restricted and removed where appropriate.
The service applies privacy-protective defaults to everyone: records and photos are private, there is no advertising, behavioural profiling, public profile, precise-location feature, or marketing messaging. Before public launch, the operator must complete and keep under review a Children's Code data-protection impact assessment covering likely access by under-18s.
If a signup DOB is under 13, we explain the consequence and ask the person to confirm it. Confirmation creates a keyed one-way fingerprint of the normalised email and source IP, the DOB, confirmation evidence and an expiry date. The raw email and raw IP are not stored in that block record. New registration using that email is blocked until the declared thirteenth birthday; existing-account sign-in is not affected. A mistaken entry can be challenged through support.
Planned AI uses the same 13+ boundary, recent reauthentication, a separate AI consent and conservative safeguards for all users. Teen accounts are not used for advertising, public profiles or behavioural targeting. Date-of-birth correction is bounded so changing a date cannot silently bypass the age gate.
5. Service providers and disclosures
Supabase
Provides authentication, the PostgreSQL database, and private file storage. The project's primary database and storage region is AWS eu-west-2 (London, United Kingdom).
Vercel
Hosts and delivers the web service. Vercel processes request data such as IP address, request URL, browser information, and operational logs, and may process that limited data in the United States and other locations where its network operates.
Open Food Facts
Only when you search for food or scan a barcode, the query or barcode is sent to Open Food Facts. Your Ordivum account ID is not included. Results are community-contributed and may be incomplete or inaccurate, so check product packaging where accuracy matters.
Upstash
When the production rate-limit service is configured, Upstash Redis holds short-lived counters keyed by an account identifier or IP address to restrict abuse of login, export, upload and other sensitive operations. It does not receive workout, nutrition, photo or note content.
Microsoft
Hosts the operator's support and privacy mailbox. If you email Ordivum, Microsoft may process the message, sender details and delivery metadata under the mailbox service terms. Do not include more health information than is needed to explain the request.
Amazon Web Services and Anthropic — planned, inactive
The proposed paid AI route uses Amazon Bedrock and may route selected tasks to Amazon Nova or Anthropic Claude models. No account record, prompt or photo is currently sent to either provider. Before activation, the final processor terms, regions, retention, subprocessors and transfer safeguards must be verified and this notice and the in-product consent must match them.
Providers may also disclose data where law requires it. We do not disclose personal data for advertising. We will name and assess a new processor before it begins handling user data.
6. Cookies and device storage
The website uses authentication and short-lived security-flow cookies, a recovery-proof cookie, and a timezone cookie. It also uses device storage for choices such as theme and rest-timer settings and for active-workout timing state. The iOS app keeps an offline account cache on the device so the ledger can work without a connection. There is no advertising, analytics, or cross-site tracking. The Cookie Policy gives durations, purposes, and controls.
7. Retention, export, and deletion
Account and ledger data is kept while your account remains open. You can export a machine-readable copy from Settings. Deleting the account starts permanent removal of its live database rows and private files; if a provider step fails, the deletion can be retried safely. Short-lived security and operational logs may remain under provider retention schedules where necessary for security, legal claims, or compliance.
A confirmed underage registration block is retained only until the declared thirteenth birthday, then ceases to prevent registration and may be deleted. The block record contains keyed fingerprints rather than raw email or IP. Age-declaration evidence attached to an account is retained with the account and deleted through the account-deletion process, subject to any narrow legal evidence requirement.
The current Supabase plan does not include automatic database backups. This avoids claiming a backup-retention period that does not exist, but also means an accidental deletion may not be recoverable. Before public launch, an appropriate automatic or independently tested backup and restore process is a release requirement. If the backup arrangement changes, this notice will be updated with the real deletion window.
An ordinary iOS sign-out may retain that account's encrypted-at-rest, OS-protected local cache for offline continuity. Settings provides a control to remove cached and unsynchronised data from the device. Account deletion and health-consent withdrawal also instruct the current app to remove the relevant local cache; data on an offline or lost device cannot receive that instruction until it reconnects or is erased by its owner.
Programme safety records remain until you withdraw the separate programme-safety choice, delete the account, or another applicable deletion request is completed. A separate withdrawal removes the safety content but retains minimal, content-free consent evidence for compliance or claims only while that remains necessary.
If programme preparation or manual movement checks are enabled, their authored and runtime records are kept with your account until you erase the relevant result, withdraw the wider health-data consent, delete the account, or another applicable erasure request is completed. The account export includes these records and the minimal feature-access metadata. Feature-access metadata is refreshed when access is checked and otherwise ends with account deletion.
8. Your rights
Depending on the circumstances, UK data-protection law gives you rights to be informed; access; correction; erasure; restriction; data portability; objection; and withdrawal of consent. You can edit much of your data, export it, withdraw the separate programme-safety choice, withdraw the wider health consent, delete individual manual movement-check results, archive their reusable definitions, and delete the account in Settings. You can also contact us. We may need to verify your identity and normally respond within one month. You may also challenge an inaccurate underage signup block; we will verify the request proportionately before changing it so that one person cannot remove another person's protection.
9. International transfers
Primary account data is stored in the United Kingdom. Vercel's delivery network, Open Food Facts, the production Upstash rate-limit service and the Microsoft-hosted operator mailbox may process limited request, lookup, counter or correspondence information outside the UK. Where UK law requires a transfer safeguard, the operator must use an adequacy regulation, UK addendum or International Data Transfer Agreement, and any required transfer-risk assessment. Confirming the exact processor contracts, service plans, regions and safeguards is a public-launch gate. If paid AI is activated, verified AWS and Anthropic locations and safeguards will be added here before any user data is sent.
10. Security
We use HTTPS, private storage, per-user database row-level security, rate limits, security headers, and one-use recovery proof. No service can promise absolute security. Read the Security page for controls and responsible reporting. If a personal-data breach creates a risk to you, we will assess notification duties and contact affected people and the ICO when legally required.
11. Complaints
Email us with the word “complaint” and enough information to understand the issue. We will acknowledge a data-protection complaint within 30 days, investigate it without undue delay, provide appropriate progress updates, and explain the outcome. You may complain to the Information Commissioner's Office at any time; you do not have to contact us first.
- Website: ico.org.uk/make-a-complaint
- Telephone: 0303 123 1113
12. Changes to this notice
We will update this notice before a new feature changes how personal data is used. Material changes will be explained in the service. Where a change needs a new consent, continued use will not be treated as consent: you will receive a new, specific choice. Previous consent events are retained as an audit record.
13. Contact
Email thomaswdelaney115@hotmail.com for a privacy request, complaint, or question.