Privacy Policy
Last updated: July 13, 2026
1. Introduction
Reaction Academy® is a progressive web application for cognitive-motor reaction training provided by Martim Miguel Pinheiro Benedito. It is designed for athletes, coaches, children, seniors, rehabilitation programmes and anyone who wants to train reaction — not only competitive sport.
An account is required to use the app. Your training data — session history and any custom exercises you build — is stored in your account through our backend provider and protected by row-level access controls, so that only your authenticated account can read or modify it. An internet connection is required to record and retrieve this data.
Live Rooms (group training). When you join a Live Room as a participant, your per-stimulus reaction times for that round are transmitted to the session host and aggregated into the host's group report (participant count, average and best reaction, group-sync score). A summary of your own performance is also saved to your personal history. The host's group report is stored under the host's account and is accessible only to the host.
2. Data Controller
For the purposes of the General Data Protection Regulation (GDPR), the Data Controller is:
| Entity | Martim Miguel Pinheiro Benedito |
| Trading Name | Reaction Academy® |
| Tax ID (NIF) | 249 246 481 |
| Registered Address | Rua Manuel Ferreira 27, 2.º Esq., 2795-229 Linda-a-Velha, Portugal |
| Contact | contact@martimbenedito.com |
3. Your Rights
As a Data Subject you have the right of access, rectification, erasure ("right to be forgotten"), restriction, portability, and to object to processing or withdraw consent at any time. You may also lodge a complaint with the Portuguese Data Protection Authority (CNPD) or another competent supervisory authority.
To exercise your rights, contact us at contact@martimbenedito.com, providing enough information (such as your account email) to identify your records. We respond within applicable legal timelines.
4. Lawful Bases for Processing
- Performance of a Contract (Art. 6(1)(b) GDPR): to create and secure your account and provide the features you request.
- Legitimate Interests (Art. 6(1)(f) GDPR): for security, abuse and bot prevention, reliability, support, and product improvement.
- Consent (Art. 6(1)(a) GDPR): where legally required, including for any optional non-essential cookies.
- Legal Obligation (Art. 6(1)(c) GDPR): to comply with applicable law.
5. What Data We Process
| Category | Examples | Purpose | Legal Basis |
|---|---|---|---|
| Account & Authentication | Email, User ID, password (hashed by our provider), session tokens, terms-acceptance timestamp. | To create, manage, and secure your account. | Contract |
| Profile & Preferences | Display name and chosen interface colour. | To personalise your account and interface. | Contract |
| Training Activity | Session history, exercises completed, duration, reaction times, custom exercises you build, and — in Live Rooms — group session reports. | To track progress and, for hosts, to report on group sessions. Stored in your account through our backend provider. | Contract |
| Technical & Security | IP address, device/browser metadata, anti-bot verification tokens. | To keep the service secure and prevent automated abuse. | Legitimate Interests |
| Support | Your email and message contents. | To respond to your requests. | Legitimate Interests |
Reaction Academy uses your device's audio, speech-synthesis, and screen wake-lock capabilities to run sessions. These operate entirely on your device — we do not record, transmit, or store any audio, microphone, or camera data.
6. Data Recipients and Sharing
We do not sell, rent, or lease your personal data. It is shared only with the essential providers needed to operate the service:
- Supabase, Inc. — authentication, database hosting, and backend APIs for your account and synchronised data.
- Cloudflare, Inc. — application hosting and content delivery, plus Cloudflare Turnstile for anti-bot protection at sign-up.
7. International Data Transfers
Our operations are based in the European Union. Some processors (e.g. Supabase and Cloudflare) may process data outside the European Economic Area, including in the United States. Where this occurs, we rely on approved GDPR safeguards, in particular Standard Contractual Clauses (SCCs).
8. Data Retention
- Account & Profile Data: retained while your account is active.
- Training data: retained in your account until you delete the record or delete your account.
- Support Records: up to 2 years after resolution.
- Deleted Accounts: associated backend data is removed subject to legal retention constraints.
9. Security Measures
- Data encrypted in transit via HTTPS / TLS.
- Secure authenticated access controls and hashed credentials via our backend provider.
- Row-level database security rules for account records.
- Environment-based secret management and anti-bot verification.
No service can guarantee absolute security. You are responsible for keeping your credentials safe and protecting access to your device.
10. Age Requirements and Children's Privacy
The minimum age to create an account is 13, or the minimum age of digital consent required by law in your country (for example, 16 in certain European countries). If you are under 18, you may use the app only with authorisation from a parent or legal guardian. We do not knowingly collect data from children under 13; if you believe a child under 13 has created an account, contact us at contact@martimbenedito.com.
11. Account Deletion
You may request permanent deletion of your account and associated personal data at any time:
- In the app: use the sign-out and deletion options in your Account settings; or
- By email: send a request from your account email to contact@martimbenedito.com with the subject "Account Deletion Request". We process requests within 30 days.
Deleting your account permanently removes your profile, training history, custom exercises and group-session reports from our backend, subject to any legally required retention.
12. Changes to This Policy
We may update this Policy to reflect product, legal, or operational changes. Substantial changes will be communicated in the app or on the website. The "Last updated" date reflects the latest revision.