Rechtliches / Legal

Privacy Policy

Last updated: April 2026

1. Data Controller (Art. 13 para. 1 lit. a GDPR)

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

André Bruns
Geschwister-Scholl-Straße 41
28844 Weyhe
Germany

Email: [email protected]

2. Personal Data We Collect

We collect and process the following personal data when you use our platform:

CategoryExamplesPurpose
Account dataName, email addressRegistration, login, communication
Payment dataStripe Customer ID, subscription IDProcessing paid subscriptions
Usage dataCompleted workouts, points, streakProgress tracking, gamification
Technical dataIP address, browser, session cookieSecurity, authentication

Full card details are processed exclusively by Stripe, Inc. and are never stored on our servers.

3. Legal Bases for Processing (Art. 6 GDPR)

  • Art. 6(1)(b) GDPRContract performance — providing the service, subscription management, customer support.
  • Art. 6(1)(c) GDPRLegal obligation — retention of invoice data pursuant to § 147 AO (10 years).
  • Art. 6(1)(f) GDPRLegitimate interests — fraud prevention, IT security, anonymous usage statistics.
  • Art. 6(1)(a) GDPRConsent — push notifications, if you have enabled them.

4. Third-Party Processors

We only share your data where necessary for contract performance or with your consent:

ProviderPurposeLocation
Stripe, Inc.Payment processingUSA (SCCs)
Amazon Web ServicesFile hosting (S3)EU region
Manus AIApp hosting, authenticationUSA (SCCs)

SCCs = EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR for third-country transfers.

5. Cookies and Session Data

We use only technically necessary cookies (session cookie for authentication). No tracking or advertising cookies are used. Consent under § 25 TDDDG is not required for technically necessary cookies.

6. Retention Period

Account data is deleted within 30 days of account closure. Invoice and payment data is subject to the statutory retention obligation of 10 years (§ 147 AO).

7. Your Rights (Art. 15–22 GDPR)

Access (Art. 15)

Right to information about stored data

Rectification (Art. 16)

Right to correction of inaccurate data

Erasure (Art. 17)

Right to deletion ('right to be forgotten')

Restriction (Art. 18)

Right to restriction of processing

Portability (Art. 20)

Right to receive data in machine-readable format

Objection (Art. 21)

Right to object to processing

To exercise your rights: [email protected]. You also have the right to lodge a complaint with the supervisory authority: State Commissioner for Data Protection Lower Saxony (LfD).

8. Minors

Our service is not directed at persons under 16 years of age. If you believe a child has provided us with personal data, please contact us at [email protected].

9. Changes to This Privacy Policy

We reserve the right to update this privacy policy. The current version is always available at /datenschutz. Registered users will be notified by email of material changes.

We use only essential cookies to keep you logged in. Learn more