The privacy-first playbook is coming for your ops stack — and it changes how you think about vendor lock-in
Cross-border sellers spend most of their tooling budget on the same three things: ads, analytics, and fulfillment. Privacy rarely makes the list. But a small Product Hunt launch this week — a web-based workout and coaching app called Eat Train Feel from solo maker Aleš Sušnik — is worth a look anyway, because it packages three architectural decisions that the next generation of seller-side SaaS is quietly copying: client-side encryption, no app-store dependency, and full CSV export with no lock-in. If you run a DTC brand or manage marketplace accounts, those choices are about to show up in the tools you buy. Here’s what’s actually interesting, what isn’t, and what I’d test.
What Eat Train Feel actually is (and what problem it solves)
Strip away the fitness framing and the product is a two-sided coordination tool. On one side, a coach needs to send a workout for a specific day, confirm it was completed, and see what the client ate — all in one place. On the other side, an athlete training at home wants today’s plan on their watch without playing the “did it sync?” lottery. Sušnik’s own framing is blunt: a friend asked for a few workouts, and by number five he was copy-pasting from notes while she screenshotted his messages. That’s the origin story — not a grand vision, just an unsustainable manual workflow.
The interesting engineering detail: the app writes workouts to a Garmin watch (he trains with a fenix 8), where LAP advances to the next exercise and Garmin Connect receives a proper activity with one lap per exercise. That’s a genuinely hard integration to get right, and it’s the kind of “last mile” problem most indie SaaS never touches because it requires device-side cooperation.
The rest of the spec sheet is short and deliberate:
- Workouts are built from the equipment you actually have
- Data is encrypted in the browser, so the server can’t read it
- No app store — it’s a web app on any device, synced
- Free, no ads, export everything to CSV
That’s it. No pricing tier, no enterprise plan, no “contact sales.” For a cross-border operator used to $99/month SaaS with a 14-day trial and a mandatory onboarding call, the shape of this thing should feel alien.
Why Amazon sellers should care more than Shopify ones
If you’re purely on Shopify with a clean DTC stack, this launch is a curiosity. If you’re on Amazon Seller Central, it’s closer to a warning shot. Amazon sellers live inside a platform that owns the customer relationship, the ad auction, the buy box, and — increasingly — the data exhaust from your own listings. Every third-party tool you bolt on (Helium 10, Jungle Scout, Sellerboard) is another place your sales, margin, and PPC data lives. The pitch of “your data encrypted in the browser, the server can’t read it” is a direct answer to a fear that Amazon-native sellers have learned to live with: that the tooling layer knows more about your business than you do.
The coach-client encryption question raised in the comments is the exact same problem marketplace sellers face with agencies and VAs. More on that below.
The encryption tension nobody has solved cleanly
The most substantive exchange on the launch page is between Sušnik and Gal Dayan, who builds Dial and asks the obvious question: if a coach is supposed to see what a client ate and how the workout went, doesn’t client-side encryption mean the coach needs a shared key or access grant? And if the server holds the key, what does “encrypted” even mean?
Sušnik’s answer is honest and, frankly, more useful than most vendor marketing: what you share with the coach gets decrypted so the coach can see it, and that’s disclosed in the policy. He says he has an idea for a token-exchange model similar to how the watch and app exchange data, but hasn’t implemented it. He also makes a pragmatic argument — if you’re deliberately sharing a workout with someone, why would you want it encrypted from them? — and points out that images are handled differently, with per-picture share and stop-sharing controls.
This is the same unresolved problem every cross-border operator hits when they give a VA or agency access to Seller Central, Shopify admin, or a Klaviyo account. You either hand over the keys (and accept the risk) or you build a token-scoped access layer (and accept the engineering cost). Most sellers do the former and pretend it’s fine. The launch thread is a reminder that “privacy-first” is a spectrum, not a binary, and the honest vendors are the ones who say so.
Where the math breaks
Free, no ads, CSV export, browser-side encryption, Garmin integration. Pick any three and you have a sustainable indie product. Pick all five and you have a question about who pays for the servers. Sušnik doesn’t say, and the source doesn’t disclose a business model. For a cross-border seller evaluating tools, that’s the single most important missing data point. Free tools in the seller stack have a long history of either dying quietly, getting acquired and enshittified, or pivoting to a paid tier that breaks the original promise. The CSV export is the only real hedge — if the tool dies, you keep your data. That’s a design choice worth stealing regardless of what you think of the product.
What cross-border sellers can borrow from this
Three things, in order of how quickly you can act on them.
1. Make CSV export a non-negotiable vendor requirement
Every tool in your stack — ad platforms, analytics, helpdesk, email — should let you pull your raw data out in a machine-readable format on demand. Not a “request your data” form. Not a 30-day email. A button. If a vendor won’t give you one, that’s a signal about how they think about your leverage. The GDPR data portability right exists in the EU, but it’s slow and inconsistently enforced. A CSV button is faster and tells you more about the vendor’s incentives.
2. Treat “no app store” as a feature, not a limitation
The web-app-only decision means no 30% platform tax, no review delays, no forced SDK updates. For sellers, the equivalent is being deliberate about which parts of your stack live inside someone else’s walled garden. TikTok Shop and Temu are the obvious examples — you’re renting distribution, not owning it. The question isn’t whether to be there (you should, if the unit economics work) but whether your customer data, creative assets, and fulfillment logic are portable enough to survive a platform policy change. If they aren’t, you’re not running a brand; you’re running a channel.
3. Scope access instead of handing over keys
The coach-client encryption thread is a proxy for the VA-and-agency problem. Most sellers give their Upwork VA full Seller Central access because scoping permissions is annoying. That’s a choice, and it has a cost. Amazon’s own user permissions system lets you restrict by tool and by marketplace; Shopify has staff accounts with granular scopes. Use them. The token-exchange model Sušnik describes — where access is granted per-share and revocable — is the right mental model even if the tooling isn’t there yet.
Where my judgment says it falls short
Two honest criticisms, one of the product and one of the framing.
First, the product is solving a problem that’s real but small. Personal trainers coordinating with a handful of clients is a market measured in hundreds of thousands, not millions, and the willingness to pay is low because the alternative (WhatsApp plus screenshots) is free and familiar. The Garmin integration is the only feature here that’s genuinely hard to replicate, and it’s tied to one device ecosystem. If Sušnik wanted to build a business, the smarter move would be to license the watch-sync layer to existing coaching platforms rather than compete with them on the front end.
Second, the “privacy-first” positioning is doing more work than the architecture supports. Browser-side encryption is real, but the moment you share with a coach, the data is decrypted server-side or client-side with a key the server can probably reach. That’s not a knock on Sušnik — he’s upfront about it — but it’s a caution for any seller who reads “encrypted” on a vendor’s landing page and assumes it means what they think it means. Ask the uncomfortable question: who holds the key, and what happens when I revoke access?
The comparison I’d actually make
If you’re shopping for this category, the incumbents to benchmark against are Trainerize and TrueCoach, both of which have years of feature depth, payment processing, and client management that Eat Train Feel doesn’t attempt. The differentiator isn’t features — it’s the architectural stance. Trainerize and TrueCoach are conventional SaaS: your data lives on their servers, you access it through their app, and export is a feature they control. Eat Train Feel inverts that. For a cross-border seller, the lesson isn’t “switch your coaching tool.” It’s “notice which vendors are willing to give you an exit, and weight that in your buying decisions.”
What I’d watch / test next
This week, three concrete moves.
One: audit your stack for CSV export buttons. Spend an hour and check every tool you pay for — Klaviyo, your helpdesk, your 3PL portal, your PPC tool. If more than two require a support ticket to get your own data out, you have a portability problem worth fixing before your next renewal.
Two: tighten one access grant. Pick your highest-risk credential — usually Seller Central or your Shopify admin — and move one VA or agency from full access to scoped access. The friction is one afternoon; the downside of not doing it is a bad week you can’t undo.
Three: watch how Eat Train Feel handles the encryption-sharing question over the next few months. If Sušnik ships the token-exchange model he described, it’s a template worth copying for how you grant temporary, revocable access to contractors. If he doesn’t, and the product quietly adds a paid tier or gets acquired, that’s also a lesson — about what “free and private” usually means in practice. Either way, the architectural choices here are more instructive than the product itself.






