WODone Privacy Policy

Last updated and effective: 2026-09-12

WODone records CrossFit workouts (WODs) inside ChatGPT. This policy states everything the service receives, why it is used, who else handles it, where it is held, how long it is kept, and how you get it back or removed.

1. Who is responsible

WODone is operated by Seongbae Park, an individual developer, who is the data controller for the information described here. Contact: pseongbae@gmail.com.

2. How WODone fits into ChatGPT

You do not use WODone directly. You talk to ChatGPT, and ChatGPT decides when to call WODone's tools and what to put in the call.

This means ChatGPT, not WODone, controls what reaches us. ChatGPT composes each tool call from your conversation, so the text it sends — a workout description, a benchmark name, a note about scaling — is drawn from what you wrote or photographed in that exchange, and can include wording you did not expect to be stored. ChatGPT may also share relevant chat context and memories with connected apps; anything it passes in a tool call is received by WODone and, for the fields listed below, saved. Whatever you would not want stored, do not put in a workout you ask WODone to save.

OpenAI's handling of your conversation before it reaches us is governed by OpenAI's own privacy policy, not this one.

3. What WODone receives and stores

CategoryDataSource
Account Your email address and an account identifier (a UUID). Your password is held by Supabase Auth as a salted hash and is never visible to WODone. OAuth access and refresh tokens issued when you connect the app. You, at sign-up and when connecting.
Workout records Date performed, workout type, optional benchmark name, the workout text as supplied, and for each movement its name, reps, calories, distance, duration, load and notes. Where a score exists: its type, time, rounds, reps, load, whether it was Rx, and notes. The name, notes and workout text are free text composed by ChatGPT from your conversation. ChatGPT, on your instruction.
Operational logs Request and response metadata (time, path, status) and error output when a request fails. These can include your account identifier. Generated automatically as the service runs.
Browser storage When you sign in on our login or consent page, Supabase Auth stores your session (an access token, a refresh token and your account identifier) in your browser's local storage so you are not asked to sign in again. It stays on your device, is not sent to us beyond the request that needs it, and is cleared when you sign out at /logout. No advertising or analytics cookies are used. Your browser.

4. What each tool receives and returns

WODone exposes five tools to ChatGPT. Each is restricted to your own account.

ToolReceivesReturnsEffect
log_wod Date, workout type, optional name, the workout text, movements with quantities and loads, and the score — as composed by ChatGPT from your conversation. The saved record.Creates a record.
update_wod The identifier of one of your records and a complete replacement for it. The updated record.Overwrites that record.
delete_wod The identifier of one of your records. Confirmation of deletion.Deletes it permanently.
list_wods Optional filters: date range, movement name, maximum count. Your matching records, newest first.Reads only.
get_wod_detail The identifier of one of your records. That record and your earlier sessions containing the same movements. Reads only.

Loads and distances given in pounds, pood, miles, feet or yards are converted to kilograms and metres before storage, and movement names are normalized to one spelling, so stored values can differ in form from what you typed.

5. What WODone does not receive

6. Why the data is used, and on what basis

Your data is used only to provide the features you invoke: saving a workout, listing your history, showing one workout alongside your past performance of its movements, correcting a record and deleting one. Operational logs are used only to keep the service running and to investigate faults.

The basis for this is performing the service you asked for; your account exists because you chose to create one. WODone does not profile you, does not advertise, does not sell or rent your data, does not share it for anyone else's marketing, and does not use it to train machine-learning models.

7. Who else handles the data, and where

RecipientRoleLocation
OpenAIOperates ChatGPT, through which every request reaches us Per OpenAI
SupabaseDatabase and authenticationSeoul, South Korea
CloudflareApplication hosting and operational logs Edge locations worldwide

No one else receives your records. Because Cloudflare serves the app from the location nearest you, a request made outside South Korea is processed abroad before reaching the database in Seoul; by using WODone you accept that transfer. We disclose data to authorities only where the law requires it, and we do not sell it in any circumstance.

8. How long it is kept

9. Your rights and controls

Requests are answered within 30 days and are free of charge.

10. Security

Traffic is served over HTTPS. Reaching your records requires an OAuth 2.1 access token issued by Supabase Auth, which WODone verifies on every request against the issuer's published keys. Every database query is restricted to the account owning the records, so one user's workouts are not reachable by another. If a breach affects your data, we will notify you by email at the address on your account, and the relevant authority, without undue delay.

11. Children

WODone is not directed at children under 13 and we do not knowingly collect their data. If you believe a child has created an account, email pseongbae@gmail.com and it will be removed.

12. Changes

Material changes are reflected in the date at the top of this page. If a change materially affects how your existing records are used, we will email account holders before it takes effect.

13. Contact

Seongbae Park — pseongbae@gmail.com. See also Support and Terms of Service.