Blok SessionsJoin the waitlist

What Blok Sessions knows about you

Last updated

Blok Sessions is a training app for boulderers. It works fine without an account, and most of what it records never leaves your phone. This page says exactly what does.

Blok Sessions is made by Frank Blokdijk, trading as KMFFWJD (KvK 42113691, VAT NL005504221B81), in the Netherlands. He decides how the data described here is used, which makes him responsible for it under the GDPR (the “controller”). Contact: hello@bloksessions.com.

At a glance

What Where it lives
Your training log: sessions, blocks, plans, test results, readiness check-ins, custom exercises and metrics Your phone. Copied to our server only while you’re signed in, so a new phone can get it back.
Account details: your email address and the name you chose Our server. With Sign in with Apple and a hidden email, we only see Apple’s relay address.
Cycle tracking (off unless you turn it on) Your phone. Left out of the cloud backup unless you separately switch that on.
Benchmark contributions (off unless you turn it on) Our server, with no name, email or account attached.
Waitlist email (only if you sign up on this website) Our server, until the launch email is sent. Then it’s deleted.
Payment details Never collected. Purchases run entirely through Apple.
Website page counts Our server: which page, which website sent you there, and the day. Nothing that identifies you.
Tracking and advertising Never, in the app or on this website.

This website

This website sets no cookies and loads nothing from third parties: fonts and images are served from this site. Like any website, our hosting provider keeps short-lived request logs, including your IP address, for security and troubleshooting. They are not linked to anything else and are not used to profile you.

Page counts

To see whether anyone reads this site, each page view adds one to a daily counter for that page. The counter stores three things: the page’s address, the domain of the website that linked you here (for example reddit.com, never the full link) or the campaign tag in the link you followed (such as ?via=instagram), and the date. It stores no IP address, no browser or device details, no cookie and no identifier, so a count can’t be traced back to you or linked to your other visits. If your browser sends a Do Not Track or Global Privacy Control signal, nothing is counted at all.

The counts are stored in the same EU database as everything else and kept for as long as they’re useful for seeing how the site is doing. Because they contain no personal data, we rely on our legitimate interest in knowing whether the site works.

Abuse protection

To stop someone flooding the waitlist, the page counter or the app’s benchmark pool, each keeps a scrambled version of your IP address: a one-way, salted hash, never the address itself. It’s used only to count how many requests come from the same network within an hour, it isn’t linked to your email or to anything else, and it’s deleted after 24 hours. The legal basis is our legitimate interest in keeping the service working.

The waitlist

If you join the waitlist, we store your email address, the date you signed up, and which version of this policy you agreed to. It sits in the same EU-hosted database as the app’s data (see below), in a table nobody can read from the website.

We use it for one thing: a single email when Blok Sessions is available on the App Store. After that email is sent, the list is deleted. If the app hasn’t launched within 12 months of your sign-up, your address is deleted anyway. To be removed sooner, email us and we’ll do it within a few days. We process it on your consent, which you can withdraw at any time.

Using the app without an account

You can use Blok Sessions as a guest. In guest mode there is no account, no email address, and nothing is sent to our server except the request that downloads the exercise catalogue, and anonymous benchmark contributions if you switch them on (see Benchmarks below). Everything you log lives on your phone, and it goes away if you delete the app.

That’s the trade: guest mode is private by construction, and it also means we can’t get your training back for you if you lose the phone.

Signing in

Creating an account gets you a backup and lets your log follow you to a new device. You can sign in two ways:

  • Sign in with Apple. Apple gives us a stable identifier for you and, if you allow it, your name. If you choose to hide your email, Apple substitutes a relay address and we never learn your real one.
  • Email and password. We store your email address. Your password is handled by our authentication provider and stored only as a hash. We never see it in readable form.

If you logged sessions as a guest and then sign in, that training is attached to your new account and uploaded, so you don’t lose it by signing up.

What gets backed up, and where it sits

While you’re signed in, the app keeps a copy of your training profiles and records in a database hosted by Supabase, in the EU (Ireland). That copy covers sessions, session templates, training plans, test results, readiness check-ins, custom exercises and custom metrics.

Every row is tagged with your account and protected by database rules that make it readable only by you. Nobody else using the app can query your training, and there is no shared or public feed.

Cycle tracking is treated separately. It is health information, so it is off by default, kept on your device, and left out of the cloud backup unless you explicitly turn that on. Turning it off again deletes the server copy.

Benchmarks

If you switch on benchmark contributions in Settings, each test you log from then on is also sent to a separate pool, so it can be compared with other climbers’ results. A contribution holds the test, the number you logged, that number as a percentage of your bodyweight if you’ve logged your bodyweight, your strength-training experience, age band and highest grade from your intake answers, and the day it arrived. It is sent without your sign-in, so it carries no name, email, account or device identifier. Tests logged before you switched it on, and bodyweight readings on their own, are never sent.

Because the pooled rows carry nothing that points back to you, they can’t be pulled back out individually once submitted, and later edits or deletions in your log don’t reach them. Switching the setting off stops any further contributions.

Blok Sessions Pro

Pro is sold through Apple’s In-App Purchase, as a one-time purchase or a monthly subscription. Apple processes the payment and holds the payment details; we never see your card, billing address or Apple ID. The app asks Apple whether this Apple ID owns Pro and unlocks accordingly.

Managing or cancelling a subscription is done in your Apple ID settings, not in the app.

The exercise catalogue and server logs

The app downloads its exercise catalogue from our server on launch so that corrections reach you without an app update. Like any web request, this leaves an entry in our hosting provider’s logs, which includes your IP address and is kept briefly for security and troubleshooting. It is not linked to your training data and is not used to build a profile of you.

Who else sees any of this

We don’t sell your data, and we don’t share it for advertising. Data reaches exactly these other parties:

  • Supabase hosts the database and handles sign-in, as a processor acting on our instructions.
  • Apple handles Sign in with Apple and all purchases, under Apple’s own privacy policy.
  • Resend sends the app’s account emails (the sign-up confirmation and password-reset links) from the EU, as a processor, so it handles your email address and those messages.
  • Our website host serves this site and keeps its short-lived request logs.
  • Anyone you send something to. If you use the app’s share or export features, that file goes wherever you send it. That’s your choice, at the moment you make it.

We would also disclose data if legally required to. If that ever happened, we would tell you unless prohibited from doing so.

Getting your data, or getting rid of it

You can delete your account from inside the app, under Settings. Deleting an account removes your sign-in credentials and every training record we hold for you, permanently, and it takes effect immediately rather than after a waiting period. Anonymous benchmark contributions are excluded, because they no longer carry anything that identifies which account submitted them.

Deleting the app without deleting your account leaves the backup in place, so you can reinstall and sign back in.

Under the GDPR you can also ask us for a copy of what we hold, ask us to correct it, ask us to restrict how we use it, or object to our use of it. Write to the address below and we’ll respond within 30 days. If you think we’ve handled your data badly, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens.

Why we’re allowed to hold it

Account and training data are processed to provide the service you asked for. Cycle tracking, benchmark contributions and the waitlist are processed on your consent, which you can withdraw at any time.

How long any of it lasts

Your training data is kept for as long as your account exists. A training log is only useful if it stretches back years, so we don’t expire it. Delete your account and it goes with it. Server request logs are kept for a short period and then discarded. Waitlist addresses are deleted as described above.

Blok Sessions is not directed at children and we don’t knowingly collect data from anyone under 16. If you believe a child has created an account or joined the waitlist, contact us and we’ll remove it.

If this page changes

If we change how the app or this website handles your data, this page is updated and the date at the top changes with it. A change that materially affects what we collect will be flagged in the app before it takes effect, not quietly shipped.