Vollkraaft logoVollkraaft Back to plans

Privacy Policy

Last updated: 29 September 2026 · Version 1.4 (draft)

This policy explains what personal data Vollkraaft processes, why, on what legal basis, and the rights you have under the EU General Data Protection Regulation (GDPR).

Draft: complete before public launch. Fill every [placeholder], confirm the providers and their locations, and have this reviewed by a data-protection lawyer. Health data (see §3) is a special category under Art. 9 GDPR and needs explicit consent and extra safeguards.

1. Controller

The controller responsible for your data is:

Controller
Vollkraaft Timon Seul
Address
11A An Uerbech, L-7418 Buschdorf, Luxembourg
Email
timon@vollkraaft.com
Data protection
[DPO contact, or "no DPO is required" with a brief reason]

2. Who this covers

Vollkraaft has three kinds of user: personal users who train themselves, clients who are coached by a trainer, and coaches who program for clients. Where a coach and a client are linked, each is a separate controller for the data they themselves enter; Vollkraaft provides the platform that lets them share it with each other on the client's consent.

3. What data we process

CategoryExamplesSpecial category?
AccountEmail, password hash, role (personal / client / coach), display name, avatar, and your gender and phone number if you give themNo
Consent recordsWhich versions of the Terms, Privacy Policy, Health Disclaimer and health-data consent you accepted, and when you turned AI features on or offNo
Training & healthPrograms, logged sets, reps and loads, RPE, bodyweight, injuries and pain reports, self-reports, achievements, progress graphsYes, Art. 9
NutritionDiet plan inputs (bodyweight, height, age, sex, activity level, goal), calorie and macro targets, meals and macros, daily water intake and step counts you enter, barcode/food-database lookups, meal descriptions you submit for analysisCan reveal health data
MessagesChat between coach and client, per-day notes, exercise questions and achievements you share with your coachMay contain health data
AI assistant (only with AI features on)Messages you send to Thor, the training and diet summary the app sends with them (see §5), meal descriptions you submit for analysis, and the repliesYes, Art. 9
LocationGPS route, distance and time of an outdoor run, only while you actively record oneNo
PaymentSubscription plan and status, Stripe customer and subscription IDs. Card details and the billing address you enter at checkout go to Stripe; we never see or store card detailsNo
SupportEmails you send us and messages from our contact or cancellation formsOnly if you include it
TechnicalIP address, device/browser type, timestamps and security logs, and the small browser-storage entries listed in our Cookie PolicyNo

The camera form-check runs entirely on your device. The video and the body-position estimates never leave your phone or computer and we do not store them. A clip is only kept if you choose to save it to your own device. Your date of birth is checked on your device at sign-up to confirm you are 16 or older; it is never sent to us or stored.

4. Why we process it, and our legal basis

PurposeLegal basis (GDPR)
Create and run your account and deliver the app's core featuresArt. 6(1)(b), performance of a contract
Store and display your training, health, pain and diet data, and share it with a coach you have linkedArt. 9(2)(a), your explicit consent: given when you create your account and, for sharing with a coach, again when you accept that coach. Also Art. 6(1)(b)
Thor AI chat, Thor check-ins, Thor Detective and AI meal analysis (see §5)Art. 9(2)(a), a separate, optional explicit consent: AI features stay off until you turn them on (at sign-up, the first time you use Thor, or in Account, AI features) and you can turn them off at any time. Also Art. 6(1)(b)
Take payment and manage subscriptionsArt. 6(1)(b), contract; Art. 6(1)(c), legal (tax/accounting) retention
Keep proof of the consents you gaveArt. 6(1)(c), legal obligation (Art. 7(1) GDPR)
Keep the service secure and prevent abuseArt. 6(1)(f), legitimate interest in a secure service
Answer support and legal enquiriesArt. 6(1)(b)/(f) and, for a contact form, Art. 6(1)(a)

You can withdraw any consent at any time (see §9). Withdrawing does not affect processing that already happened, but it stops it from then on. Removing your coach withdraws your consent to share health data with them from that moment. Turning AI features off stops all AI processing from then on, and the rest of the app keeps working. Because health data is what the app is built on, withdrawing your health-data consent means deleting your account, which erases that data (see §8).

5. AI features

Thor, the in-app assistant, and the AI meal analyser use an AI model from Anthropic (USA, see §6). They only run if you have turned on AI features; with them off, nothing is sent to Anthropic. With them on, content is sent in these cases:

  • Thor chat: when you send Thor a message, the app sends it together with a summary of your recent training, pain reports, self-reports, strength scores, bodyweight and diet, so the reply fits you.
  • Thor check-ins: when you open the app (at most once every three hours) and after you complete a session, save a session log or log food, the app sends the same kind of summary so Thor can decide whether to show you a tip or a warning, for example about pain that keeps coming back.
  • Thor Detective: when a coach asks for a weekly analysis of a client who has turned on AI features, the training data that client shares with the coach is sent.
  • AI meal analyser: the meal text you enter is sent to estimate its macros. The food names are then looked up in USDA FoodData Central from our server, without anything that identifies you.

We send only what a feature needs: your display name and the data above, never your email address or password. [confirm Anthropic data terms]

The camera form-check does not use AI or any server. It runs on your device only (see §3).

AI output is assistive only and can be wrong. We do not use it to make any decision that produces a legal or similarly significant effect about you (no automated decision-making under Art. 22 GDPR).

6. Who we share data with

These service providers process data for us as processors under Art. 28 GDPR and act only on our instructions (Stripe acts as an independent controller for payment data):

ProviderPurposeLocation / transfer safeguard
SupabaseDatabase, authentication, file storageEU (Ireland); SCCs for any access from outside the EEA
NetlifyWebsite and serverless hosting, contact and cancellation formsUSA, [SCCs / DPF]
StripePayment processing (as an independent controller for payment data)USA/EU, SCCs / EU-US DPF
AnthropicThor AI chat, check-ins and Detective, AI meal analysisUSA, EU-US DPF / SCCs
ResendAccount emails: sign-up confirmation, password reset, account deletion linkUSA, [SCCs / DPF]
ImprovMX, Brevo and Google (Gmail)Receiving, storing and answering the emails you send to timon@vollkraaft.comImprovMX [location, safeguard]; Brevo EU (France); Google USA, EU-US DPF

Our fonts and code libraries are hosted on our own servers, so loading a page contacts no font or code provider. The one exception is the payment page, which loads Stripe's checkout code from Stripe, as Stripe requires.

Your device also contacts these services directly while you use the app. They receive your IP address and the request, which they process under their own privacy terms:

ServiceWhen, and what it receivesLocation
YouTube (Google)When an exercise has a video: its thumbnail. The privacy-enhanced player (youtube-nocookie.com) loads only after you agree to play a videoUSA, EU-US DPF
CARTOWhen the run tracker or a route map is open: map tiles for the area on screen, which reveals roughly where you are[Spain/USA, safeguard]
Open Food FactsWhen you scan a barcode: the barcode numberEU (France)

Our server also asks USDA FoodData Central (USA) for nutrient values when you search for a food or use the AI meal analyser. It receives only the food names, never anything that identifies you.

We do not sell your data or share it for advertising. A coach only ever sees a client's data after that client has linked to them and given consent, and loses access the moment the client withdraws. Your diet section (plan, meals, bodyweight log, water and steps) is never shown to a coach.

7. International transfers

Where a processor is outside the European Economic Area, the transfer relies on an EU adequacy decision, on Standard Contractual Clauses, or on your explicit consent under Art. 49(1)(a) GDPR. See the safeguards column in §6. You can ask us for a copy of the relevant safeguard.

8. How long we keep it

  • Account and app data: for as long as your account is open. When you delete your account we erase your account and all app data at once, end any subscription immediately and delete your customer record at Stripe. Copies in our database provider's backups disappear when those backups expire [backup period, e.g. 7 days].
  • Payment and invoice records: 10 years, as Luxembourg accounting law requires. They stay in Stripe even after your account is deleted.
  • Consent records: for as long as your account is open. They are deleted with your account.
  • Support messages: deleted once the enquiry is closed and any limitation period has passed.
  • Security logs: [e.g. up to 90 days].

9. Your rights

Under the GDPR you have the right to: access your data; rectify inaccurate data; erase data ("right to be forgotten"); restrict or object to processing; data portability; and withdraw consent at any time. You also have the right to lodge a complaint with a supervisory authority, in particular the one in your country of residence.

To exercise any of these, email timon@vollkraaft.com. We answer within one month. Removing your coach, turning AI features on or off, and deleting your account (which also withdraws your health-data consent) are available directly in the app.

Supervisory authority: the lead authority for the operator is Commission nationale pour la protection des données (CNPD), Luxembourg (https://cnpd.public.lu). You may also complain to the authority where you live or work.

10. Security

Access to your data is enforced at the database with row-level security, so users can only reach their own rows (and, for a linked coach, the client rows the client has shared). Passwords are hashed by the authentication provider, card data never touches our servers, and traffic is encrypted in transit. No system is perfectly secure, but we take appropriate technical and organisational measures under Art. 32 GDPR.

11. Children

Vollkraaft is not intended for anyone under 16, and signing up requires you to confirm that you are 16 or older. We do not knowingly process children's data. If you believe a child has given us data, contact us and we will remove it.

12. Changes

We may update this policy. We will post the new version here with a fresh "last updated" date and, for material changes, notify you in the app or by email.

© 2026 Vollkraaft
Privacy Terms Cookies Health Withdrawal Cancel a contract Legal Notice