Privacy Policy
Last updated: 1 August 2026 · Version 1.0 (draft)This policy explains what personal data Vollkraaft processes, why, on what legal basis, and the rights you have under the EU General Data Protection Regulation (GDPR).
1. Controller
The controller responsible for your data is:
- Controller
- [Legal entity name]
- Address
- [Street, postcode, city, country]
- timonseul@icloud.com
- Data protection
- [DPO contact, or "no DPO is required" with a brief reason]
2. Who this covers
Vollkraaft has three kinds of user: personal users who train themselves, clients who are coached by a trainer, and coaches who program for clients. Where a coach and a client are linked, each is a separate controller for the data they themselves enter; Vollkraaft provides the platform that lets them share it with each other on the client's consent.
3. What data we process
| Category | Examples | Special category? |
|---|---|---|
| Account | Email, password hash, role (personal / client / coach), display name, avatar | No |
| Training & health | Programs, logged sets/reps/loads, RPE, bodyweight, injuries and pain reports, progress graphs, camera-based movement estimates | Yes — Art. 9 |
| Nutrition | Meals, macros, barcode/food-database lookups, meal descriptions you submit for analysis | Can reveal health data |
| Messages | Chat between coach and client, per-day notes | May contain health data |
| AI assistant | Prompts and content you send to Thor and to the meal analyser, and the generated replies | May contain health data |
| Location | GPS track of an outdoor run, only while you actively record one | No |
| Payment | Subscription plan, status, Stripe customer and subscription IDs. Card details go directly to Stripe — we never see or store them | No |
| Technical | IP address, device/browser type, timestamps and security logs | No |
4. Why we process it, and our legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Create and run your account and deliver the app's core features | Art. 6(1)(b) — performance of a contract |
| Store and display your training, health and pain data, and share it with a coach you have linked | Art. 9(2)(a) — your explicit consent, on top of Art. 6(1)(b) |
| Thor AI chat, camera form-check and AI meal analysis | Art. 6(1)(a) / 9(2)(a) — your consent (you choose to use these; the Free plan works without them) |
| Take payment and manage subscriptions | Art. 6(1)(b) — contract; Art. 6(1)(c) — legal (tax/accounting) retention |
| Keep the service secure and prevent abuse | Art. 6(1)(f) — legitimate interest in a secure service |
| Answer support and legal enquiries | Art. 6(1)(b)/(f) and, for a contact form, Art. 6(1)(a) |
You can withdraw any consent at any time (see §9). Withdrawing does not affect processing that already happened, but it stops the feature going forward — for example, removing your coach withdraws your Art. 9 consent to share health data with them from that moment.
5. AI features
Thor (the in-app assistant) and the camera form-check send the content you choose to share to an AI provider to generate a reply or an estimate. The AI meal analyser sends the meal text you enter to an AI provider to estimate macros. These features are optional and are only used when you use them.
AI output is assistive only and can be wrong. We do not use it to make any decision that produces a legal or similarly significant effect about you (no automated decision-making under Art. 22 GDPR).
6. Who we share data with (processors)
We use the following service providers as processors under Art. 28 GDPR. They act only on our instructions.
| Provider | Purpose | Location / transfer safeguard |
|---|---|---|
| Supabase | Database, authentication, file storage | [Region — confirm; SCCs if outside EEA] |
| Netlify | Website & serverless hosting | USA — [SCCs / DPF] |
| Stripe | Payment processing (as an independent controller for payment data) | USA/EU — SCCs / EU-US DPF |
| Anthropic | Thor AI assistant, camera form-check & AI meal/macro analysis | USA — EU-US DPF / SCCs |
| Map tiles (CARTO/OpenStreetMap) | Displaying the run-tracker map | EU — no personal data sent beyond map tile requests |
We do not sell your data or share it for advertising. A coach only ever sees a client's data after that client has linked to them and given consent, and loses access the moment the client withdraws.
7. International transfers
Where a processor is outside the European Economic Area, the transfer relies on an EU adequacy decision, on Standard Contractual Clauses, or on your explicit consent under Art. 49(1)(a) GDPR. See the safeguards column in §6. You can ask us for a copy of the relevant safeguard.
8. How long we keep it
- Account and training data: for as long as your account is open. When you delete your account we delete or irreversibly anonymise it within [e.g. 30 days], except where the law requires us to keep something longer.
- Payment and invoice records: kept for the statutory retention period ([e.g. 6–10 years] for tax/accounting).
- Support messages: deleted once the enquiry is closed and any limitation period has passed.
- Security logs: [e.g. up to 90 days].
9. Your rights
Under the GDPR you have the right to: access your data; rectify inaccurate data; erase data ("right to be forgotten"); restrict or object to processing; data portability; and withdraw consent at any time. You also have the right to lodge a complaint with a supervisory authority — in particular the one in your country of residence.
To exercise any of these, email timonseul@icloud.com. We answer within one month. Withdrawing your coach link, or deleting your account, are also available directly in the app.
10. Security
Access to your data is enforced at the database with row-level security, so users can only reach their own rows (and, for a linked coach, the client rows the client has shared). Passwords are hashed by the authentication provider, card data never touches our servers, and traffic is encrypted in transit. No system is perfectly secure, but we take appropriate technical and organisational measures under Art. 32 GDPR.
11. Children
Vollkraaft is not intended for children under [16 — adjust to your Member State's age of digital consent]. We do not knowingly process their data. If you believe a child has given us data, contact us and we will remove it.
12. Changes
We may update this policy. We will post the new version here with a fresh "last updated" date and, for material changes, notify you in the app or by email.
Vollkraaft
← Back to plans