Security
How miaforo protects each gym's data.
Last updated: 29 August 2026
Essential protection
- The servers are in Berlin and the nightly encrypted copy in Falkenstein, both inside the European Union.
- Connections use HTTPS and passwords are never stored in plain text.
- Each gym is separate and permissions are checked on the server.
- Signing up creates a new, empty gym, never access to one that already exists. We store no cards or bank credentials.
miaforo handles data on the gym’s behalf. We do not sell it or use it for advertising. Rights and retention periods are in the privacy policy.
Backups and incidents
The database and the photos are copied every night, encrypted, and seven days are kept. We monitor the service and tell the gym without delay if an incident affects personal data. The status page is hosted outside these servers, so it answers when miaforo does not: https://instatus-miaforo.instatus.com/.
Report a problem
Write to chema@miaforo.com with the address and the steps that reproduce it. Do not access, change or delete other people’s data, or run brute-force or load tests. The same address is published in security.txt.