Privacy Policy

Effective: 24.08.2026

1. Controller

The controller responsible for data processing under the General Data Protection Regulation (GDPR) is:

Karl Kuhne
Tieckstr. 11
01099 Dresden
Germany
karlkuhne@t-online.de

2. Data We Process

Account data: email address, password (stored encrypted), display name.

Workout data: routines, training plans, and exercises you create, workout logs (sets, reps, weights), body weight history, exercise notes, and optional details such as height.

Payment-related data: when you take out a Pro subscription or lifetime purchase, Apple processes payment as an independent controller through the App Store. We do not receive payment or card data ourselves — only subscription status information (active/expired) from our payment processor, RevenueCat, Inc.

Technical data: timestamps of changes for synchronization between your devices, and device/app diagnostic data in case of errors.

We do not collect health data via Apple HealthKit or comparable interfaces, and we do not use advertising or third-party tracking services.

Analytics data (only with your consent): if you opt in during onboarding or later in Settings, we collect which screens you open and which features you use, aggregate counts such as workouts finished, sets logged, and sync errors, and your device type, app version, language, and unit setting. This is processed by our analytics provider, PostHog, and linked to your account ID — never your name or email address. You can grant or withdraw this consent at any time in the app's Settings screen; if you do not consent, none of this data is collected or transmitted. It is never used for advertising and never sold.

3. Purposes and Legal Bases of Processing

  • Providing the Application's features and synchronizing your data across devices — Art. 6(1)(b) GDPR (performance of a contract)
  • Managing your user account, including authentication — Art. 6(1)(b) GDPR
  • Processing Pro subscriptions and purchases via Apple/RevenueCat — Art. 6(1)(b) GDPR
  • Analytics on how the Application is used, to identify problems and improve features — Art. 6(1)(a) GDPR (consent), only if you opt in
  • Troubleshooting and maintaining system security — Art. 6(1)(f) GDPR (legitimate interest)
  • Complying with legal obligations, e.g. commercial or tax record-keeping requirements — Art. 6(1)(c) GDPR

4. Recipients of Your Data

Your data is processed only for the purposes stated above and is not sold or passed on to third parties for advertising purposes. The following processors/third parties are involved:

  • Apple Inc. — processing of in-app purchases and subscriptions through the App Store
  • RevenueCat, Inc. — management and validation of subscription status (data processor)
  • PostHog Inc. — product usage analytics (data processor), only if you have given consent; see Section 5 regarding data location
  • Expo (660 York LLC) — mobile app tooling used by the client application; see Expo's own privacy policy
  • Backblaze, Inc. — stores encrypted off-site backups of our database and uploaded files, used solely to recover the service in case of data loss. Backups are encrypted on our server before they are transmitted; Backblaze cannot read their contents.

The servers on which your workout and account data are stored are operated by us; our hosting provider only supplies the underlying server infrastructure and does not access your data for its own purposes.

5. International Data Transfers

Some of our processors (including Apple and RevenueCat) are based in, or transfer data to, the United States. Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards, such as Standard Contractual Clauses approved by the European Commission or an applicable adequacy decision.

Backblaze, Inc. is headquartered in the United States, but the backup data described in Section 4 is stored exclusively in Backblaze's EU data center (Amsterdam, Netherlands) and is encrypted before it leaves our infrastructure, so Backblaze has no access to readable personal data regardless of its location.

PostHog Inc. is likewise headquartered in the United States, but the analytics data described in Section 4 is processed and stored exclusively on PostHog's EU-hosted infrastructure, and only if you have given your consent as described in Section 2.

6. Retention Period

We retain your data for as long as your account exists. If you delete your account, your personal data is deleted from our live database immediately, except where statutory retention obligations (e.g. commercial or tax law requirements for completed purchases) require otherwise.

We also maintain encrypted backups of our database for disaster-recovery purposes, on a rolling retention schedule of up to 12 months. Because backups are taken on a fixed schedule rather than updated individually, your data may continue to exist in an older backup for up to 12 months after account deletion, until that backup is automatically overwritten. These backups are not accessed for any purpose other than restoring the service after data loss, and are permanently deleted once they age out of the rotation.

7. Your Rights

You have the right to access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), and objection to processing (Art. 21 GDPR). Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal. To exercise these rights, simply contact karlkuhne@t-online.de.

You also have the right to lodge a complaint with a data protection supervisory authority, e.g. the Saxon Data Protection Commissioner (Sächsischer Datenschutzbeauftragter).

8. Deleting Your Account

You can delete your account and all associated data at any time directly in the app settings, or by contacting karlkuhne@t-online.de. We will process deletion requests within the timeframes required by applicable law, subject to verification of your identity and any legal obligation to retain certain data.

9. Children

The Application is not intended for children under 16 years of age, or such higher age as required under applicable law. We do not knowingly collect personal data from children under this age. If you are a parent or guardian and believe your child has provided us with personal data, please contact us so we can delete it.

10. Security

We take appropriate technical and organizational measures to protect the personal data we process, including encrypted storage of passwords and encrypted transmission of data.

11. Changes to This Privacy Policy

We update this Privacy Policy when data processing or legal requirements change. The current version is always available at this address; material changes will be communicated within the Application where required by law.