ProgLabAi is a private, invitation-only service. This page states what is collected, why, and what you can require.
Florian Berger · contact: florian@proglabai.com. The service is hosted by Infomaniak Network SA, Genève (Suisse), a Swiss provider; the data stays in Switzerland.
The email address is what lets the service notify you, account created, program assigned, and reset your password if you forget it. It is required in the request form: without it there is no way to answer you. An account opened another way can do without one; it works exactly the same, but then receives no notification and its password can no longer be reset by email.
No medical record or certificate is requested. The form invites you to mention an injury or a constraint if you find it useful: say only what helps adapt the sessions. The same goes for the notes fields inside the app: do not record there anything you would rather not have stored.
Account data authenticates you; training data displays and tracks your program. The legal basis is performance of the service you asked for, plus legitimate interest in securing access for the failed-attempt log.
A request sent through the contact form rests on your consent, given by ticking the box before sending, and on steps taken prior to the service you are asking for. It is used to reply to you and to write your program, nothing else. You may withdraw that consent at any time by writing to florian@proglabai.com: the request is then erased, with no need to explain yourself.
No advertising, no data sold or shared, and audience measurement reduced to anonymous counters (see below). Your training data can be read by the administrator, who can also restore it to help you recover from a mistake, and by the assigned coach on your programme, if there is one: that is what lets them follow what you do and adjust your plan. No other coach has access, and that reading never changes anything.
One exception, and only if you gave an email address: sending a notification necessarily hands the message and your address to the outgoing mail provider (Infomaniak, in Switzerland), which routes it to your mailbox. Your training data, ticked sessions, recorded loads, personal notes, is never part of it.
There is a second case where data leaves the server, and it concerns backups only: every night a full archive of the site is sent to a private storage space, described below under "what becomes of deleted data". It is encrypted before it leaves (AES-256), and the password that opens it is written nowhere on the server: the host of that space cannot read it.
Notification emails contain your display name, your username and the name of the program concerned. No password ever appears in them: at most, the welcome email carries an invitation link, single-use and valid seven days, through which you choose your own password.
A request sent through the contact form follows the same path: it is stored on the server, then forwarded by that same provider to the administrator, and a confirmation goes to the address you gave. That message carries everything you filled in: including any constraint or injury you chose to mention, and nothing else. The confirmation itself contains your name and, where an order was placed, its summary: order number, invoice number, service, cycle length, price, payment method, date, and the version of the terms of sale accepted. Your invoice is attached to it as a PDF: it carries your name, the amount and the date, as the law requires.
Writing a training plan from your request relies on an artificial intelligence assistant provided by Anthropic (United States). What you describe about your training is submitted to it: discipline, goals, level, equipment, place, availability, maxes, and any constraints or injuries you chose to mention.
Your name, e-mail address and phone number are never sent to it. The sheet submitted carries only a randomly drawn pseudonym, of the form « ATH-3F9C ». Your contact details stay on the Swiss server, in columns separate from the technical sheet, and are used only to reply to you.
Your training data once the plan is running, sessions ticked, weights entered, personal notes, never goes through it: it does not leave the server.
Together with the payment described below, these are the only two processes that leave Switzerland. There is no other.
Payments are handled by Stripe Payments Europe Ltd (Ireland), which may process this data in the United States. Payment happens on Stripe's own pages: no card details pass through this site, are seen by it, or are stored on it.
What WE pass to it is limited to your e-mail address, so that it can send you a receipt, the amount, and the order lines: the tier name (« Program, Hybrid ») and, if you took the follow-up option, a second line naming it with the number of four-week blocks (« Premium follow-up, 4 weeks × 3 »). Two lines rather than one total, so that your receipt explains itself: Stripe therefore learns that you took the follow-up and for how long. Not one line of your request is passed to it: no goal, no injury, no constraint, no equipment, not a single piece of training data.
Stripe, for its part, also processes what it needs in order to carry out and secure the payment: your payment method details, the transaction identifiers, technical data such as your IP address and browser, and where applicable billing details. That processing is its own and falls under its own privacy policy, which its payment page makes available to you.
The follow-up option you tick is stored with your order, because it is what opens, or does not open, your discussion thread with your coach. It also appears on your invoice and on your Stripe receipt, as said above: what you are billed for has to be legible on what serves as your proof of purchase.
On our side, we keep what was sold, at what price and on what date, along with the transaction identifiers, together with the version of the terms of sale you accepted and when you did, with no name and no address. It is an accounting line, not a customer record. The register of who paid is held by Stripe, whom you can approach directly about your own rights.
The site counts its page views, to know what is read and what is not. No IP address is stored, and no cookie is set for this measurement.
The country a visit comes from is resolved at request time, from a database installed on the server: DB-IP, under the CC BY 4.0 licence. Your address is therefore disclosed to nobody, not even for that resolution: no request goes out to any geolocation service. It is then dropped.
Only a fingerprint of your address, hashed with a salt that never leaves the server, survives thirty days: solely so the same person is not counted twice in the same day. After that it is erased, and only the visitor count for that day remains.
What is left, a date, a side of the site, a page, a country, a number, cannot single anyone out. These counters are kept twenty-four months. The administrator's own visits are not counted.
None. Every file the site needs, stylesheets, scripts, icons and typefaces, is served by the site's own server. Your browser never contacts a third party while using ProgLabAi, so no outside company ever learns your IP address through this site.
One exception, and it is entirely up to you. Each exercise sheet carries a Watch a demonstration button that opens YouTube in a new tab. Nothing from YouTube is loaded into this site: no player, no script, no cookie. The link stays inert until you tap it. Once you do, you are on YouTube, and Google's rules apply there, not ours. We do not hand over who you are: the site tells your browser not to reveal which page the click came from.
As long as the account exists. Automatic backups keep at most the 40 most recent states per program. You delete your account yourself, at the bottom of My account: the deletion immediately and permanently erases the account, its email address, its training data, its notification subscriptions, its backups, its conversations, its brief, with everything declared in it (goal, equipment and constraints), and the original request that carried your name, your email address and your phone number. Messages already delivered stay in your own mailbox, which is outside this service's control.
One thing survives, and it should be said: the administration log. It does not record your data but an administrator's actions, such as an account created, a password reset or an account deleted, and it loses all meaning if it disappears with its subject. It is what answers the question "what happened?". It keeps only the last 400 actions: it is a review log, not an archive, and the oldest entries drop off as new ones arrive.
A second, smaller log records incidents: the moments when a page fails on our side. It exists so that a breakage is noticed instead of being silently endured, and it holds the least it can. For each one: the date, the kind of error, the file and line in our own code, the address of the page without its query string, and the numeric identifier of the account that was signed in. No name, no email address, no form content, and nothing you typed. It keeps the last 300 entries, the oldest falling off on their own, and an administrator can empty it at any time.
Notification subscriptions live for as long as you keep them. Each device is switched off separately, from My account; revoking the permission in your browser settings works too, and the server then deletes the subscription by itself as soon as it finds it no longer answers. Anything waiting to be pushed is deleted once sent: no log keeps a record of what you were told about, or when.
Conversation messages live as long as the account. Deleting the account erases the whole conversation, replies and attached files included: half a dialogue serves nobody and would keep your words anyway. Deleting the program concerned also erases its thread and its attachments, which would have no subject left. Conversation attachments are not included in the encrypted backup archive: they are conversation content, not records.
An attachment sent as view once does not live like the others. The file is deleted from the server as soon as the person it was sent to has opened it, and at the latest thirty days after it was sent if they never do. It therefore goes into no backup made after that deletion, and into no encrypted archive. What stays in the conversation is a line saying an attachment was sent and opened, without its content. One honest point: this does not stop the person looking at it from photographing their own screen. No messaging app can.
Reactions placed on a message (an emoji) are recorded with the account that places them. They disappear with the message, with the conversation and with the account.
A program request stays visible to the administrator while it is being handled. Once marked as handled, it is automatically erased after six months: no action needed on your side. If it leads nowhere, or if you change your mind before that, write to florian@proglabai.com: it is erased, no questions asked.
Two honest points about the word "immediately". First, the server keeps technical safety copies of its database, made every day and held for fourteen days: they exist to bring the site back after a failure, nobody reads them, and those that still contained you disappear on their own at most fourteen days after your account is deleted.
Alongside those local copies there is an off-site copy, because a backup kept on the machine that burns saves nothing. Every night a full archive is sent to a private storage space, with a Swiss host; seven copies rotate there, one per day of the week, each replacing the one from the week before. Deleted data therefore disappears from that space within seven days at most. The archive is encrypted before it leaves the server (AES-256) and its password is written nowhere: the host of that space stores bytes it cannot read. Conversation attachments are not part of it.
Second, if you paid for a programme, the corresponding invoice is kept for ten years and survives the deletion of the account. It carries your name, the amount and the date. That is not a choice: Swiss law requires accounting records to be kept (art. 958f of the Code of Obligations). It is used for nothing else.
Access, rectification, erasure, portability, restriction, objection. In practice you already see and edit your data inside the app, and you delete your account yourself, at the bottom of My account: nothing to ask for, nothing to wait for, nothing to justify. The deletion page says exactly what goes and what stays. Write to florian@proglabai.com for an export, or if you no longer have access to your account at all. You may also lodge a complaint with your competent data-protection authority.
Passwords hashed with the algorithm PHP recommends by default, bcrypt today, HTTPS connection, session cookie unreadable by JavaScript, anti-CSRF tokens, and a block after 8 failed attempts within 15 minutes.
Last updated : 15 August 2026