Legal
Privacy Policy
Last updated 24 Aug 2026
This describes what Bina (BinaFit and BinaLaga), operated by Izzi Adimy trading as Bina Bersama / IA Studio, collects and how it's handled. It covers both trainers who register for the service and their clients, whose data trainers enter on their behalf.
1What we collect
| From trainers | Name, email, phone number, business name, an optional bio, and at least one coaching location. |
|---|---|
| From clients | Whatever their trainer enters to run their coaching — name, phone number, goals, injuries noted by the trainer, body measurements, session notes, progress photos, and messages exchanged through the portal. Clients don't create their own account or password — access is a link tied to their record. |
| Payments | A reference code and the amount for each bank transfer. We don't collect or store card numbers or bank account details — there's no payment gateway in the product. |
2How it's used
Only to run the service: showing a trainer their schedule and client list, showing a client their own sessions and progress, matching a bank transfer to a payment record, and sending the notifications either side has opted into. We don't use this data for advertising, and we don't build profiles from it beyond what the product itself shows you.
3Where it's stored
On Cloudflare (Workers, Pages, and file storage for progress photos) and Neon (the Postgres database). Each trainer's data lives in its own separate database — not a shared table filtered by permission — so there's no query path from one trainer's account into another's data.
4Who can see it
A trainer sees their own clients' data. A client sees only their own record, through their own portal link. We (the small team operating Bina) can access account data to provide support or fix a bug when asked, and don't otherwise look at it. We don't sell data, and we don't share it with third parties for their own marketing purposes.
5Service providers
Running Bina means trusting infrastructure to Cloudflare (hosting, compute, storage) and Neon (the database) — both process data on our behalf under their own security and privacy terms. We don't use any other third-party processor for client data.
6Security
- No passwords to leak — trainers sign in with a one-time magic link, and clients with a one-time link tied to their record, exchanged for a secure, HTTP-only session cookie.
- Each trainer's data is isolated in its own database, not row-level permissions on a shared one.
- Traffic is encrypted in transit (HTTPS) end to end.
No system is perfectly secure, and we can't guarantee against every possible breach — but these are deliberate design choices, not an afterthought.
7Data retention and deletion
Data is kept for as long as an account is active. If a trainer cancels and asks us to delete their account, or a client asks us to remove their own record, email [email protected] and we'll action it — for a client request, we'll also let their trainer know, since it's the trainer's coaching record being removed.
8Clients under 18
A trainer's client list may include minors. It's the trainer's responsibility to have appropriate consent from a parent or guardian before entering a minor's information into Bina — we don't independently verify age or consent for any client record.
9Changes to this policy
If how we handle data changes materially, we'll say so directly — by email or WhatsApp — rather than leave it to a silent page edit.
10Contact
Questions about your data, or a deletion request: [email protected] or WhatsApp +673 839 6949.