Protokoll ← Back to site
Legal · Privacy

Privacy Policy

App: ProtokollLast updated: 16 July 2026Effective: 16 July 2026

This Privacy Policy explains what personal data the Protokoll mobile app (“Protokoll”, “the app”, “we”, “us”) processes, why, on what legal basis, and what rights you have. It is written to be read, not to hide things — the short version below is accurate, and the detailed sections expand on it.

The short version
  • Protokoll is local-first. Your training data — workouts, exercises, plans, check-ins, notes and the analytics derived from them — lives on your device, and (if you choose) in a backup file in your own cloud storage. It is not sent to us. We operate no server, no account system and no hosted copy of your workout data, and we cannot read it.
  • There is no login and no user account. The app creates a random installation identifier on your device. It is not your name, email or phone number, but it is shared with RevenueCat when purchase services are enabled.
  • We do not track you, show ads, or sell or share your data for advertising. There is no analytics SDK and no advertising identifier. The app does not ask for App Tracking Transparency permission because it does not track you.
  • Data leaves your device only for narrow purposes: purchase and entitlement services (Apple and RevenueCat when you use them), optional pseudonymous crash diagnostics (Firebase Crashlytics — off by default and sent only if you opt in), a basic internet-reachability check, and anything you choose to export, back up or share.

1 · Who is responsible (Controller)

The controller responsible for processing personal data under the EU General Data Protection Regulation (GDPR) is the provider of the Protokoll app, based in Germany. You can reach the controller for any privacy matter at:

Protokoll provider · Germany
Email: protokoll.fitness@gmail.com

During the TestFlight beta, privacy contact is by email. A deliverable postal address will be added here, in the Legal Notice, and in the store's trader information before public App Store distribution.

We have not appointed a Data Protection Officer because we are not legally required to (Art. 37 GDPR); you can reach us about any privacy matter at the email above.

2 · How Protokoll handles your data

Protokoll is designed so that we hold as little of your data as technically possible:

  • Your training data stays on your device. Sets, loads, reps, RPE, holds, readiness check-ins, plans, notes, labels and all analytics computed from them are stored locally in an on-device database. We have no access to it and no copy of it.
  • No account, no sign-in, no server-side profile. The app uses a random local installation identifier to keep the installation consistent and connect it to RevenueCat purchase entitlements. The identifier is pseudonymous: it contains no name or contact details, but it can distinguish one installation from another.
  • Your backups go to storage you choose. If you create a backup, the app writes an encrypted backup file to a folder you pick (iCloud Drive, Google Drive, OneDrive, or local). We never receive that file.
  • iOS may back up the app as part of iCloud Backup or a device-to-device transfer. That backup is governed by Apple's terms, not ours.

3 · What data we process, why, and on what basis

The following are the only processing activities that involve a third party or that we are involved in at all.

3.1 Purchases and subscription (Pro)

What: Whether you hold an active Pro subscription or lifetime purchase; the product identifier purchased; purchase, renewal and expiry status; and the random installation identifier passed to RevenueCat so your entitlement can be associated with the app installation. We do not receive your Apple ID, name or payment-card details.

Why: To provide Pro, validate purchases, unlock paid features, restore purchases, and enforce expiry. Seller of record for the current iPhone beta: Apple. Purchase infrastructure: RevenueCat, Inc. Legal basis: Art. 6(1)(b) GDPR — performance of the contract.

3.2 Crash diagnostics (pseudonymous and opt-in)

What: When the app malfunctions, Firebase Crashlytics may receive a technical stack trace, crash timestamp, app identifier and version, device model and technical state, operating-system details, and installation or session identifiers. We do not set a Crashlytics user ID or intentionally attach workout data, names, email addresses, or notes to reports. The identifiers are pseudonymous and are not linked by us to your real-world identity.

Default state: Off. On first run, the app asks whether you want to share crash reports. Nothing is collected unless you choose Share crash reports. You can withdraw consent at any time in Profile → Settings, which stops all future collection immediately. Processor: Google (Firebase Crashlytics). Legal basis: Art. 6(1)(a) GDPR — your consent. Consent is optional and may be withdrawn at any time (Art. 7(3) GDPR) without affecting processing that occurred before withdrawal.

3.3 Backups and exports you create

Encrypted backup files (.protokollbkp) and PDF/text exports — including “AI-ready” text you generate to paste into an AI assistant of your choice — are created only when you initiate them, and go only where you send them. We never receive them. When you paste an AI export into a third-party assistant, that assistant's provider — not us — processes it under their terms. Backup files are encrypted at rest but are not end-to-end encrypted or zero-knowledge — keep them somewhere you control. Legal basis: Art. 6(1)(b)/(f) GDPR.

3.4 Connectivity check

To know whether a purchase or restore can proceed, the app attempts to resolve Cloudflare's public one.one.one.one hostname through the device's configured DNS service. No workout data or app installation identifier is included, but the network or DNS provider may process standard connection metadata such as the device's IP address. Legal basis: Art. 6(1)(f) GDPR.

3.5 Support correspondence

If you email us, we process your email address and whatever you write, to answer you. Legal basis: Art. 6(1)(f) GDPR (and 6(1)(b) where your message concerns your purchase).

3.6 Our website

These legal pages are served as static pages by Cloudflare, whose infrastructure processes visitors' IP address and standard request metadata to deliver the page and protect against attacks. The pages contain no cookies, no analytics and no third-party trackers (the fonts are served from this same site, not from a third party). Legal basis: Art. 6(1)(f) GDPR.

We do not knowingly process any special-category data (Art. 9 GDPR). Although a training log can reflect your physical activity, that data stays on your device and is never transmitted to us.

4 · Recipients and processors

We keep the list of third parties deliberately short. We do not sell personal data, and we use no advertising or analytics networks.

Recipient
Role
What they receive
Apple
Seller of record for current iPhone in-app purchases
Your payment & store-account data (we do not see it); purchase metadata
RevenueCat, Inc.
Purchase validation and entitlement infrastructure
Pseudonymous installation ID, product IDs, purchase/entitlement status
Firebase Crashlytics
Processor — optional crash diagnostics (off by default; sent only after opt-in)
Stack trace, device model, OS & app version, Firebase install ID
Cloudflare, Inc.
Processor — static hosting of legal pages
Visitor IP address and request metadata

These providers process data under their applicable service and privacy terms. Beyond these recipients, we may disclose data only where legally required. We do not otherwise sell, rent or share personal data.

5 · International data transfers

RevenueCat, Google/Firebase, and Cloudflare are based in the United States or may process data there or in other countries where they operate. Their applicable data-processing terms use legally recognized transfer safeguards, such as the EU Standard Contractual Clauses and, where applicable, participation in the EU–US Data Privacy Framework. You can request more information at the contact address in Section 1.

6 · Retention

  • Local training data is kept until you delete it, reset the app, restore over it, or uninstall. We hold no copy and set no retention period.
  • Backup files remain wherever you stored them until you delete them.
  • Crash reports (if enabled): Firebase states that crash stack traces and associated installation identifiers are retained for 90 days before removal from live and backup systems begins.
  • Purchase/entitlement metadata is retained by Apple and RevenueCat under their policies.
  • Support emails are kept only as long as needed, then deleted.

7 · How to delete your data

Because Protokoll is local-first, you are in direct control of deletion: delete individual records in the app, use the data-reset function, or uninstall (which removes the on-device database — but not a backup file you placed in your own cloud, nor any OS-level device backup). Delete backup files yourself where you saved them. Leave crash diagnostics off, or switch them off in Settings to withdraw consent and stop all future collection; existing reports follow Firebase's retention process described above. For purchase data held by Apple or RevenueCat, request erasure from those providers or contact us to forward your request (note statutory retention of some tax/purchase records).

8 · Your rights

Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20 — the app's backup feature gives you a portable copy of your training data), to object to processing based on legitimate interest (Art. 21), and to withdraw consent (Art. 7(3)) at any time. Crash diagnostics rely on consent: they remain off unless you opt in, and you can withdraw consent in Settings. For other requests, email us; we respond within the statutory time limit (normally one month).

9 · Right to lodge a complaint

If you believe our processing infringes the GDPR, you may lodge a complaint with a data protection supervisory authority, in particular in the EU Member State of your residence, place of work, or the place of the alleged infringement.

10 · Automated decision-making

We do not carry out automated decision-making with legal or similarly significant effects, and we do not profile you (Art. 22 GDPR). The analytics and “training state” the app shows are computed on your device, from your own data, for you.

11 · Children

Protokoll is not directed at children and is intended for users who can lawfully enter into a subscription (generally 16+ in the EU, or the minimum age set by your app store). We do not knowingly process data from children below the applicable age of consent.

12 · Security

Crash diagnostics, when enabled, are transmitted over encrypted connections. Backup files are encrypted at rest (see 3.3 for limits). Sensitive on-device values such as entitlement state use the OS secure storage (iOS Keychain / Android Keystore). No method is perfectly secure, but because we hold none of your training data on a server, there is no central store for an attacker to reach.

13 · Changes & contact

We may update this policy as the app evolves or the law changes; the “Last updated” date reflects the current version, and material changes are surfaced in the app or on this page beforehand. For any question or request:

Protokoll provider
Email: protokoll.fitness@gmail.com

This policy describes the Protokoll TestFlight beta as of the effective date above. It will be updated if the app's data practices change.