Last updated: August 4, 2026
This policy explains what Done in 20 LLC ("we", "us") collects when you use Done in 20 — donein20.fit and the app — what we do with it, and what control you have over it.
We keep this short on purpose. If something isn't clear, email hello@donein20.fit and ask.
We collect the minimum we need to run a workout app: who you are, what you did in your workouts, and whether your payment went through. We don't sell your data. We don't run ads. We don't collect photos of you, we don't ask for your body weight, and we don't track your location.
Account information. Your email address, your name if you give us one, and your password (stored hashed — we can't read it). If you sign in with Google or Apple, we receive your email address and basic profile details from them, not your password.
Preferences you set. Whether you train in pounds or kilograms, whether you have a pull-up bar, your reminder settings, and similar choices.
Workout data. Which workouts you started and finished, when, and what you logged for each exercise — reps, and the weight of the dumbbells you used.
To be precise about one thing: when we say "weight", we mean the weight you lifted. We do not ask for or store your body weight, body measurements, or photographs of you.
Content you create. Workouts you build, and any workout you choose to share or publish.
Payment information. Handled entirely by Stripe. We receive confirmation that a payment succeeded or failed, your subscription status, and the last four digits and card type. We never see or store your full card number.
Communications. Emails we send you and whether you opened or clicked them, and anything you send us when you contact support.
Technical data. IP address, browser and device type, and basic usage information — which pages loaded, which features were used, and any errors. We use this to keep the app working and to fix things that break.
We do not use your data to make automated decisions with legal or similarly significant effects.
We rely on: contract for running your account and subscription; legitimate interests for security, fixing problems, and improving the Service; legal obligation for tax and accounting records; and consent for anything optional, such as marketing email you've opted into — which you can withdraw at any time.
We don't sell your personal information, and we don't share it for cross-context behavioural advertising. We use a small number of service providers who process data on our behalf:
| Provider | What they do | What they get |
|---|---|---|
| Supabase | Database and login | Account details, preferences, workout data |
| Stripe | Payments and subscriptions | Your email, payment details you enter with them |
| Mux | Video hosting and delivery | Video playback requests, technical data |
| Resend | Sending email | Your email address and message content |
| Vercel | Hosting | Technical data such as IP address |
Each is bound by contract to use your data only to provide their service to us.
We may also disclose information if we're legally required to, to protect our rights or someone's safety, or to a buyer in connection with a merger, acquisition, or sale of the business — in which case this policy continues to apply until you're told otherwise.
Content you publish to a community feed is visible to other members. Don't put anything there you wouldn't want seen.
We use cookies and browser storage to keep you signed in, remember your preferences, and hold your workout logs on your device during a workout so they survive a dropped connection and sync afterwards.
We don't use advertising cookies or third-party tracking pixels for advertising.
Ask us to delete your account and we'll delete or anonymise your personal data, except what we're legally required to keep. Workouts you published to the community may remain, disconnected from your name.
Wherever you live, you can ask us to:
If you're in the UK or EU, you also have the right to object to or restrict processing, and to complain to your local data protection authority.
If you're in California, you have the right to know what we collect and why, to delete it, to correct it, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we have not done so in the past 12 months.
To exercise any of these, email hello@donein20.fit. We'll respond within the time the law allows — generally 30 days — and we may need to verify who you are first.
We use encryption in transit, hashed passwords, access controls, and reputable infrastructure providers. No system is perfectly secure, but we take this seriously, and if a breach affects your personal data we'll notify you and the relevant authorities as the law requires.
Done in 20 is for adults. It is not directed at anyone under 18, and we don't knowingly collect personal data from anyone under 18. If you believe a minor has given us their information, email us and we'll delete it.
We're based in the United States, and our providers may process data in the US and elsewhere. If you're in the UK or EU, that means your data may be transferred outside your country. Where that happens, we rely on the appropriate safeguards our providers have in place, such as Standard Contractual Clauses.
We'll update this policy from time to time. If a change is material, we'll tell you by email or in the app before it takes effect. The date at the top always shows the current version.
Done in 20 LLC Meridian, ID 83646 hello@donein20.fit