Privacy Policy
Last updated: 29 September 2026 · Version 1.4 (draft)This policy explains what personal data Vollkraaft processes, why, on what legal basis, and the rights you have under the EU General Data Protection Regulation (GDPR).
1. Controller
The controller responsible for your data is:
- Controller
- Vollkraaft Timon Seul
- Address
- 11A An Uerbech, L-7418 Buschdorf, Luxembourg
- timon@vollkraaft.com
- Data protection
- [DPO contact, or "no DPO is required" with a brief reason]
2. Who this covers
Vollkraaft has three kinds of user: personal users who train themselves, clients who are coached by a trainer, and coaches who program for clients. Where a coach and a client are linked, each is a separate controller for the data they themselves enter; Vollkraaft provides the platform that lets them share it with each other on the client's consent.
3. What data we process
| Category | Examples | Special category? |
|---|---|---|
| Account | Email, password hash, role (personal / client / coach), display name, avatar, and your gender and phone number if you give them | No |
| Consent records | Which versions of the Terms, Privacy Policy, Health Disclaimer and health-data consent you accepted, and when you turned AI features on or off | No |
| Training & health | Programs, logged sets, reps and loads, RPE, bodyweight, injuries and pain reports, self-reports, achievements, progress graphs | Yes, Art. 9 |
| Nutrition | Diet plan inputs (bodyweight, height, age, sex, activity level, goal), calorie and macro targets, meals and macros, daily water intake and step counts you enter, barcode/food-database lookups, meal descriptions you submit for analysis | Can reveal health data |
| Messages | Chat between coach and client, per-day notes, exercise questions and achievements you share with your coach | May contain health data |
| AI assistant (only with AI features on) | Messages you send to Thor, the training and diet summary the app sends with them (see §5), meal descriptions you submit for analysis, and the replies | Yes, Art. 9 |
| Location | GPS route, distance and time of an outdoor run, only while you actively record one | No |
| Payment | Subscription plan and status, Stripe customer and subscription IDs. Card details and the billing address you enter at checkout go to Stripe; we never see or store card details | No |
| Support | Emails you send us and messages from our contact or cancellation forms | Only if you include it |
| Technical | IP address, device/browser type, timestamps and security logs, and the small browser-storage entries listed in our Cookie Policy | No |
The camera form-check runs entirely on your device. The video and the body-position estimates never leave your phone or computer and we do not store them. A clip is only kept if you choose to save it to your own device. Your date of birth is checked on your device at sign-up to confirm you are 16 or older; it is never sent to us or stored.
4. Why we process it, and our legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Create and run your account and deliver the app's core features | Art. 6(1)(b), performance of a contract |
| Store and display your training, health, pain and diet data, and share it with a coach you have linked | Art. 9(2)(a), your explicit consent: given when you create your account and, for sharing with a coach, again when you accept that coach. Also Art. 6(1)(b) |
| Thor AI chat, Thor check-ins, Thor Detective and AI meal analysis (see §5) | Art. 9(2)(a), a separate, optional explicit consent: AI features stay off until you turn them on (at sign-up, the first time you use Thor, or in Account, AI features) and you can turn them off at any time. Also Art. 6(1)(b) |
| Take payment and manage subscriptions | Art. 6(1)(b), contract; Art. 6(1)(c), legal (tax/accounting) retention |
| Keep proof of the consents you gave | Art. 6(1)(c), legal obligation (Art. 7(1) GDPR) |
| Keep the service secure and prevent abuse | Art. 6(1)(f), legitimate interest in a secure service |
| Answer support and legal enquiries | Art. 6(1)(b)/(f) and, for a contact form, Art. 6(1)(a) |
You can withdraw any consent at any time (see §9). Withdrawing does not affect processing that already happened, but it stops it from then on. Removing your coach withdraws your consent to share health data with them from that moment. Turning AI features off stops all AI processing from then on, and the rest of the app keeps working. Because health data is what the app is built on, withdrawing your health-data consent means deleting your account, which erases that data (see §8).
5. AI features
Thor, the in-app assistant, and the AI meal analyser use an AI model from Anthropic (USA, see §6). They only run if you have turned on AI features; with them off, nothing is sent to Anthropic. With them on, content is sent in these cases:
- Thor chat: when you send Thor a message, the app sends it together with a summary of your recent training, pain reports, self-reports, strength scores, bodyweight and diet, so the reply fits you.
- Thor check-ins: when you open the app (at most once every three hours) and after you complete a session, save a session log or log food, the app sends the same kind of summary so Thor can decide whether to show you a tip or a warning, for example about pain that keeps coming back.
- Thor Detective: when a coach asks for a weekly analysis of a client who has turned on AI features, the training data that client shares with the coach is sent.
- AI meal analyser: the meal text you enter is sent to estimate its macros. The food names are then looked up in USDA FoodData Central from our server, without anything that identifies you.
We send only what a feature needs: your display name and the data above, never your email address or password. [confirm Anthropic data terms]
AI output is assistive only and can be wrong. We do not use it to make any decision that produces a legal or similarly significant effect about you (no automated decision-making under Art. 22 GDPR).
6. Who we share data with
These service providers process data for us as processors under Art. 28 GDPR and act only on our instructions (Stripe acts as an independent controller for payment data):
| Provider | Purpose | Location / transfer safeguard |
|---|---|---|
| Supabase | Database, authentication, file storage | EU (Ireland); SCCs for any access from outside the EEA |
| Netlify | Website and serverless hosting, contact and cancellation forms | USA, [SCCs / DPF] |
| Stripe | Payment processing (as an independent controller for payment data) | USA/EU, SCCs / EU-US DPF |
| Anthropic | Thor AI chat, check-ins and Detective, AI meal analysis | USA, EU-US DPF / SCCs |
| Resend | Account emails: sign-up confirmation, password reset, account deletion link | USA, [SCCs / DPF] |
| ImprovMX, Brevo and Google (Gmail) | Receiving, storing and answering the emails you send to timon@vollkraaft.com | ImprovMX [location, safeguard]; Brevo EU (France); Google USA, EU-US DPF |
Our fonts and code libraries are hosted on our own servers, so loading a page contacts no font or code provider. The one exception is the payment page, which loads Stripe's checkout code from Stripe, as Stripe requires.
Your device also contacts these services directly while you use the app. They receive your IP address and the request, which they process under their own privacy terms:
| Service | When, and what it receives | Location |
|---|---|---|
| YouTube (Google) | When an exercise has a video: its thumbnail. The privacy-enhanced player (youtube-nocookie.com) loads only after you agree to play a video | USA, EU-US DPF |
| CARTO | When the run tracker or a route map is open: map tiles for the area on screen, which reveals roughly where you are | [Spain/USA, safeguard] |
| Open Food Facts | When you scan a barcode: the barcode number | EU (France) |
Our server also asks USDA FoodData Central (USA) for nutrient values when you search for a food or use the AI meal analyser. It receives only the food names, never anything that identifies you.
We do not sell your data or share it for advertising. A coach only ever sees a client's data after that client has linked to them and given consent, and loses access the moment the client withdraws. Your diet section (plan, meals, bodyweight log, water and steps) is never shown to a coach.
7. International transfers
Where a processor is outside the European Economic Area, the transfer relies on an EU adequacy decision, on Standard Contractual Clauses, or on your explicit consent under Art. 49(1)(a) GDPR. See the safeguards column in §6. You can ask us for a copy of the relevant safeguard.
8. How long we keep it
- Account and app data: for as long as your account is open. When you delete your account we erase your account and all app data at once, end any subscription immediately and delete your customer record at Stripe. Copies in our database provider's backups disappear when those backups expire [backup period, e.g. 7 days].
- Payment and invoice records: 10 years, as Luxembourg accounting law requires. They stay in Stripe even after your account is deleted.
- Consent records: for as long as your account is open. They are deleted with your account.
- Support messages: deleted once the enquiry is closed and any limitation period has passed.
- Security logs: [e.g. up to 90 days].
9. Your rights
Under the GDPR you have the right to: access your data; rectify inaccurate data; erase data ("right to be forgotten"); restrict or object to processing; data portability; and withdraw consent at any time. You also have the right to lodge a complaint with a supervisory authority, in particular the one in your country of residence.
To exercise any of these, email timon@vollkraaft.com. We answer within one month. Removing your coach, turning AI features on or off, and deleting your account (which also withdraws your health-data consent) are available directly in the app.
10. Security
Access to your data is enforced at the database with row-level security, so users can only reach their own rows (and, for a linked coach, the client rows the client has shared). Passwords are hashed by the authentication provider, card data never touches our servers, and traffic is encrypted in transit. No system is perfectly secure, but we take appropriate technical and organisational measures under Art. 32 GDPR.
11. Children
Vollkraaft is not intended for anyone under 16, and signing up requires you to confirm that you are 16 or older. We do not knowingly process children's data. If you believe a child has given us data, contact us and we will remove it.
12. Changes
We may update this policy. We will post the new version here with a fresh "last updated" date and, for material changes, notify you in the app or by email.
Vollkraaft
Back to plans