Skip to content
Ascend.Blue

Privacy Policy

Last updated: 2026-08-03

THE SHORT VERSION

Ascend.Blue (“Ascend”) turns your real training into a character that grows. To do that, we store the data you give us: your account, your profile, your workouts, what you post if you join a cluster, and anything you entered in earlier beta features. Nothing else. We don’t sell your data. We don’t share it with advertisers. There are no advertising cookies. See “Cookies” below for the one analytics cookie we do use. You can permanently delete your account, yourself, at any time.

WHAT WE COLLECT

Account. Your email address and a password, handled by Supabase Auth (our authentication provider). Your password is stored only as a secure hash. We never see or store it in plain text.

Profile. What you enter during onboarding and in Settings: your first name (and optional last name), a gamertag (your public handle), gender (it selects which character model you see), your date of birth (used to confirm you’re at least 13), and display preferences (lb/kg, RIR/RPE). If a cluster you join requires legal names, the legal name you provide for that cluster.

Pictures. Your profile picture, if you add one, and any photos you attach in cluster chat. Every image is re-encoded on your device before upload, which strips hidden metadata — including GPS location. One honest note: profile pictures are stored in a public bucket, so anyone who has a picture’s direct web address can view it. Cluster chat photos are private: they are served through expiring links, to cluster members only.

Your training data. Everything you log to make the game work: programs, program days, and training cycles, workouts, sets, reps, weights, effort ratings, one-rep maxes, and the XP, levels, and attributes the app derives from them. If you used features from earlier beta releases (like goals), what you entered there stays stored and is erased with your account like everything else.

Cluster content. If you join a cluster: the messages you post, the photos you attach, and an in-app notifications inbox (for example, when someone mentions you).

Security events. When something security-relevant happens on your account — like signing in, changing your password, a failed re-authentication, or deleting your account — we record the event with your IP address and browser user-agent string. This is a tamper-evident security log that protects your account (and lets us investigate if something goes wrong). Because it exists to detect abuse, these log entries are retained after you delete your account, until we purge them. See “Deleting your data” below.

COOKIES

We use session cookies to keep you signed in, plus short-lived httpOnly cookies that carry your email during sign-up and password-reset verification, and opaque tokens while you follow a share or cluster-invite link. Our analytics tool, PostHog, sets one additional cookie to recognize your browser between visits so we can measure usage over time. It stays on ascend.blue, is never sold or shared with advertisers, and isn’t used to track you across other sites. No advertising cookies, no cross-site tracking.

HOW WE USE YOUR DATA

To run the app: show your progress, compute your XP and levels, resolve your training targets, and secure your account. Email is transactional only: verification codes and password resets. We don’t send marketing email.

ANALYTICS

Ascend uses PostHog to measure product usage: pageviews, a small set of product events (like logging a workout, earning XP, or leveling up), and error reports.

Product events are tied to your account id, so we can understand retention and fix what breaks. After you sign in, pageviews and error reports are linked to your account as well. Events carry only minimal fields (an event name plus, for example, an XP amount or level number), never your workout content, goals, notes, or personal details.

Your browser’s Do Not Track setting switches off our browser-side analytics (pageviews and error reports). Product events tied to your account — like logging a workout — are part of how the app works and are recorded regardless.

Three things are switched off in the app’s own code, so they cannot be enabled remotely: session recording (we never capture a replay of your screen), in-app surveys, and location lookup from your IP address (we instruct our analytics tool to discard it, and we don’t collect location any other way).

SHARING PROGRAMS

Sharing is optional and nothing is shared until you create a share link. When you share a training program, you publish a frozen copy of that program’s content (its name, days, exercises, and targets, plus your working weights only if you switch that on) together with your display name, to anyone who has the link, until you revoke it.

Revoking a link removes the shared program content from our systems. One honest caveat: preview cards already sent into chat apps may persist in those apps’ caches. That part is outside our control.

When someone installs your shared program, we record which account shared it and which account installed it. As the author you only ever see a count of installs, never who.

CLUSTERS

Clusters are small, invite-only groups. Inside a cluster you are visible to the other members: your gamertag (and legal name, in clusters that require it), your profile picture, your chat messages and photos, and your training activity in the shared feed — including the working weights you lift, which are always visible to your cluster. If that’s more than you want to share, clusters are optional.

One honest caveat, about the invite link itself. That link opens without an account, so anyone holding a live link sees the cluster’s name, how many members it has, and the rules they would be joining under. That is deliberate: nobody should have to create an account to find out what they are being invited to. Nothing about an individual member is on that page — no names, no activity, no chat, no weights. The page asks search engines not to index it and the link is unlisted, so the only way to reach it is to be sent it; if a link gets out, the cluster owner can rotate it, which kills the old one immediately.

WHO WE SHARE WITH

Nobody, for money: we never sell your data and never share it with third parties for advertising. The services that run Ascend process data on our behalf:

  • Supabase: database, authentication, and file storage (where your data lives)
  • Vercel: hosting (serves the app)
  • Resend: delivers our transactional email (verification codes, password resets)
  • PostHog: product analytics (pageviews, minimal product events, error reports)
  • ImprovMX: forwards email you send to support@ascend.blue to our inbox

DELETING YOUR DATA

You can permanently delete your account from Settings at any time: no email required, no waiting period, no retention tricks. Deletion cascades through every table: your profile, programs, workouts, XP, and progress are all erased.

A few honest caveats. Entries in the security-event log (event type, IP address, user-agent, timestamp) are kept after deletion so we can investigate abuse or account-takeover attempts; they currently have no automatic expiry. Messages and photos you posted in a cluster stay visible to the remaining members — your name is detached from them, but the content itself is not withdrawn. Ascend no longer sells anything, so no new payment records are created; if you made a purchase back when founding a cluster was paid, that checkout record — what it was for, when, and the amount — is kept after deletion with a reference to the account, for accounting and fraud prevention. Uploaded image files may persist in storage for a time after deletion until we purge them. And short-lived abuse-prevention counters keyed to a scrambled form of your email address expire on their own schedule.

THE iOS APP

The iOS app is the same product with the same data practices. It stores your sign-in session on your device so you stay logged in, and it collects nothing the web app doesn’t. Nothing is for sale in the app, and nothing is for sale on the web either, so no purchase data is collected on any platform. Anything left over from the retired paid founding flow is described under “Deleting your data” above; nothing new is added to it.

CHANGES TO THIS POLICY

If our data practices change, including adding analytics, we’ll update this page and the “Last updated” date at the top.

CONTACT

Questions about your data? Email support@ascend.blue.

Terms of Service