Vollkraaft ← Back to plans

Privacy Policy

Last updated: 1 August 2026 · Version 1.0 (draft)

This policy explains what personal data Vollkraaft processes, why, on what legal basis, and the rights you have under the EU General Data Protection Regulation (GDPR).

Draft — complete before public launch. Fill every [placeholder], confirm the sub-processor list and their locations, and have this reviewed by a data-protection lawyer. Health data (see §3) is a special category under Art. 9 GDPR and needs explicit consent and extra safeguards.

1. Controller

The controller responsible for your data is:

Controller
[Legal entity name]
Address
[Street, postcode, city, country]
Email
timonseul@icloud.com
Data protection
[DPO contact, or "no DPO is required" with a brief reason]

2. Who this covers

Vollkraaft has three kinds of user: personal users who train themselves, clients who are coached by a trainer, and coaches who program for clients. Where a coach and a client are linked, each is a separate controller for the data they themselves enter; Vollkraaft provides the platform that lets them share it with each other on the client's consent.

3. What data we process

CategoryExamplesSpecial category?
AccountEmail, password hash, role (personal / client / coach), display name, avatarNo
Training & healthPrograms, logged sets/reps/loads, RPE, bodyweight, injuries and pain reports, progress graphs, camera-based movement estimatesYes — Art. 9
NutritionMeals, macros, barcode/food-database lookups, meal descriptions you submit for analysisCan reveal health data
MessagesChat between coach and client, per-day notesMay contain health data
AI assistantPrompts and content you send to Thor and to the meal analyser, and the generated repliesMay contain health data
LocationGPS track of an outdoor run, only while you actively record oneNo
PaymentSubscription plan, status, Stripe customer and subscription IDs. Card details go directly to Stripe — we never see or store themNo
TechnicalIP address, device/browser type, timestamps and security logsNo

4. Why we process it, and our legal basis

PurposeLegal basis (GDPR)
Create and run your account and deliver the app's core featuresArt. 6(1)(b) — performance of a contract
Store and display your training, health and pain data, and share it with a coach you have linkedArt. 9(2)(a) — your explicit consent, on top of Art. 6(1)(b)
Thor AI chat, camera form-check and AI meal analysisArt. 6(1)(a) / 9(2)(a) — your consent (you choose to use these; the Free plan works without them)
Take payment and manage subscriptionsArt. 6(1)(b) — contract; Art. 6(1)(c) — legal (tax/accounting) retention
Keep the service secure and prevent abuseArt. 6(1)(f) — legitimate interest in a secure service
Answer support and legal enquiriesArt. 6(1)(b)/(f) and, for a contact form, Art. 6(1)(a)

You can withdraw any consent at any time (see §9). Withdrawing does not affect processing that already happened, but it stops the feature going forward — for example, removing your coach withdraws your Art. 9 consent to share health data with them from that moment.

5. AI features

Thor (the in-app assistant) and the camera form-check send the content you choose to share to an AI provider to generate a reply or an estimate. The AI meal analyser sends the meal text you enter to an AI provider to estimate macros. These features are optional and are only used when you use them.

Thor, the camera form-check, and the AI meal analyser all use Anthropic (USA, under the EU-US Data Privacy Framework / SCCs — see §6). No meal or training data is sent to any provider outside the safeguards listed there.

AI output is assistive only and can be wrong. We do not use it to make any decision that produces a legal or similarly significant effect about you (no automated decision-making under Art. 22 GDPR).

6. Who we share data with (processors)

We use the following service providers as processors under Art. 28 GDPR. They act only on our instructions.

ProviderPurposeLocation / transfer safeguard
SupabaseDatabase, authentication, file storage[Region — confirm; SCCs if outside EEA]
NetlifyWebsite & serverless hostingUSA — [SCCs / DPF]
StripePayment processing (as an independent controller for payment data)USA/EU — SCCs / EU-US DPF
AnthropicThor AI assistant, camera form-check & AI meal/macro analysisUSA — EU-US DPF / SCCs
Map tiles (CARTO/OpenStreetMap)Displaying the run-tracker mapEU — no personal data sent beyond map tile requests

We do not sell your data or share it for advertising. A coach only ever sees a client's data after that client has linked to them and given consent, and loses access the moment the client withdraws.

7. International transfers

Where a processor is outside the European Economic Area, the transfer relies on an EU adequacy decision, on Standard Contractual Clauses, or on your explicit consent under Art. 49(1)(a) GDPR. See the safeguards column in §6. You can ask us for a copy of the relevant safeguard.

8. How long we keep it

  • Account and training data: for as long as your account is open. When you delete your account we delete or irreversibly anonymise it within [e.g. 30 days], except where the law requires us to keep something longer.
  • Payment and invoice records: kept for the statutory retention period ([e.g. 6–10 years] for tax/accounting).
  • Support messages: deleted once the enquiry is closed and any limitation period has passed.
  • Security logs: [e.g. up to 90 days].

9. Your rights

Under the GDPR you have the right to: access your data; rectify inaccurate data; erase data ("right to be forgotten"); restrict or object to processing; data portability; and withdraw consent at any time. You also have the right to lodge a complaint with a supervisory authority — in particular the one in your country of residence.

To exercise any of these, email timonseul@icloud.com. We answer within one month. Withdrawing your coach link, or deleting your account, are also available directly in the app.

Supervisory authority: the lead authority for the operator is [name + website of the competent Data Protection Authority]. You may also complain to the authority where you live or work.

10. Security

Access to your data is enforced at the database with row-level security, so users can only reach their own rows (and, for a linked coach, the client rows the client has shared). Passwords are hashed by the authentication provider, card data never touches our servers, and traffic is encrypted in transit. No system is perfectly secure, but we take appropriate technical and organisational measures under Art. 32 GDPR.

11. Children

Vollkraaft is not intended for children under [16 — adjust to your Member State's age of digital consent]. We do not knowingly process their data. If you believe a child has given us data, contact us and we will remove it.

12. Changes

We may update this policy. We will post the new version here with a fresh "last updated" date and, for material changes, notify you in the app or by email.

© 2026 Vollkraaft
Privacy Terms Cookies Health Withdrawal Cancel a contract Legal Notice