Legal
Privacy Notice
Last updated: July 2026
1. Who we are
Onyx Performance ("we", "us", "our") operates onyxperformance.app and the Onyx Performance app. We are the data controller of the personal data described in this notice. Contact: privacy@onyxperformance.app.
2. Personal data we collect
- Account data: name, email address, password (hashed), country, language.
- Profile & training data: workout logs, program progress, favourites, reviews, body measurements you enter (weight, body fat, etc.), goals.
- Support data: messages you send us and their attachments.
- Usage & device data: pages visited, features used, device type, browser, approximate location (from IP), crash and performance logs.
- Cookies & similar technologies: see section 8.
- Payment data: processed by our reseller Paddle (see section 6). We receive purchase confirmations and metadata (product, amount, country, invoice ID) but never full card numbers.
3. How we use your data & legal bases
- Provide the Service (create your account, deliver programs, sync progress) β performance of a contract.
- Customer support β performance of a contract / legitimate interests.
- Security, fraud prevention & abuse detection β legitimate interests and legal obligation.
- Product analytics & improvement β legitimate interests (aggregated where possible).
- Marketing emails (product updates, tips) β consent, which you can withdraw at any time.
- Legal, tax & accounting β legal obligation.
4. Who we share data with
We do not sell your personal data. We share it only with:
- Merchant of Record β Paddle.com Market Ltd, our online reseller. Paddle handles checkout, payments, invoicing, sales tax and refunds. See Paddle's privacy notice at paddle.com/legal/privacy.
- Infrastructure & hosting providers (cloud database, storage, edge hosting, email delivery, video streaming).
- Analytics providers used to understand product usage.
- Professional advisers (accountants, lawyers) where necessary.
- Authorities when required by law.
5. International transfers
Some of our providers are located outside your country, including the EEA/UK and the United States. Where personal data leaves the EEA/UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or adequacy decisions.
6. Payments
Payments and refunds are handled by Paddle as Merchant of Record. Paddle acts as an independent controller for its own compliance, tax and fraud-prevention purposes.
7. Data retention
We keep your data while your account is active. If you delete your account, we delete or anonymise your personal data within a reasonable period, except where we must keep it for legal, tax or dispute-resolution purposes (typically up to 7 years for financial records).
8. Cookies
We use a minimal set of cookies: essential cookies for login/session, analytics cookies (aggregate usage), and β only if you opt in β marketing cookies. You can manage cookies in your browser at any time; disabling non-essential cookies will not break the site.
9. Your rights
Depending on where you live (including under the EU/UK GDPR, LGPD in Brazil, and similar laws), you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate data.
- Erase your data ("right to be forgotten").
- Restrict or object to processing.
- Data portability.
- Withdraw consent at any time (without affecting prior lawful processing).
- Lodge a complaint with your local supervisory authority.
To exercise any of these rights, email privacy@onyxperformance.app. We respond within one month.
10. Security
We use appropriate technical and organisational measures β encryption in transit (TLS), encryption at rest for sensitive fields, role-based access controls, and audit logging β to protect your data. No system is perfectly secure, but we work continuously to reduce risk.
11. Children
Onyx Performance is intended for users aged 16 and older. We do not knowingly collect data from children under 13. If you believe a child has provided us with personal data, contact us and we will delete it.
12. Changes
We may update this notice. Material changes will be announced in the app or by email. The "Last updated" date at the top reflects the current version.
13. Contact
Privacy questions: privacy@onyxperformance.app
