This Privacy Policy explains what personal data the Protokoll mobile app (“Protokoll”, “the app”, “we”, “us”) processes, why, on what legal basis, and what rights you have. It is written to be read, not to hide things — the short version below is accurate, and the detailed sections expand on it.
The controller responsible for processing personal data under the EU General Data Protection Regulation (GDPR) is the provider of the Protokoll app, based in Germany. You can reach the controller for any privacy matter at:
During the TestFlight beta, privacy contact is by email. A deliverable postal address will be added here, in the Legal Notice, and in the store's trader information before public App Store distribution.
We have not appointed a Data Protection Officer because we are not legally required to (Art. 37 GDPR); you can reach us about any privacy matter at the email above.
Protokoll is designed so that we hold as little of your data as technically possible:
The following are the only processing activities that involve a third party or that we are involved in at all.
What: Whether you hold an active Pro subscription or lifetime purchase; the product identifier purchased; purchase, renewal and expiry status; and the random installation identifier passed to RevenueCat so your entitlement can be associated with the app installation. We do not receive your Apple ID, name or payment-card details.
Why: To provide Pro, validate purchases, unlock paid features, restore purchases, and enforce expiry. Seller of record for the current iPhone beta: Apple. Purchase infrastructure: RevenueCat, Inc. Legal basis: Art. 6(1)(b) GDPR — performance of the contract.
What: When the app malfunctions, Firebase Crashlytics may receive a technical stack trace, crash timestamp, app identifier and version, device model and technical state, operating-system details, and installation or session identifiers. We do not set a Crashlytics user ID or intentionally attach workout data, names, email addresses, or notes to reports. The identifiers are pseudonymous and are not linked by us to your real-world identity.
Default state: Off. On first run, the app asks whether you want to share crash reports. Nothing is collected unless you choose Share crash reports. You can withdraw consent at any time in Profile → Settings, which stops all future collection immediately. Processor: Google (Firebase Crashlytics). Legal basis: Art. 6(1)(a) GDPR — your consent. Consent is optional and may be withdrawn at any time (Art. 7(3) GDPR) without affecting processing that occurred before withdrawal.
Encrypted backup files (.protokollbkp) and PDF/text exports — including “AI-ready” text you generate to paste into an AI assistant of your choice — are created only when you initiate them, and go only where you send them. We never receive them. When you paste an AI export into a third-party assistant, that assistant's provider — not us — processes it under their terms. Backup files are encrypted at rest but are not end-to-end encrypted or zero-knowledge — keep them somewhere you control. Legal basis: Art. 6(1)(b)/(f) GDPR.
To know whether a purchase or restore can proceed, the app attempts to resolve Cloudflare's public one.one.one.one hostname through the device's configured DNS service. No workout data or app installation identifier is included, but the network or DNS provider may process standard connection metadata such as the device's IP address. Legal basis: Art. 6(1)(f) GDPR.
If you email us, we process your email address and whatever you write, to answer you. Legal basis: Art. 6(1)(f) GDPR (and 6(1)(b) where your message concerns your purchase).
These legal pages are served as static pages by Cloudflare, whose infrastructure processes visitors' IP address and standard request metadata to deliver the page and protect against attacks. The pages contain no cookies, no analytics and no third-party trackers (the fonts are served from this same site, not from a third party). Legal basis: Art. 6(1)(f) GDPR.
We keep the list of third parties deliberately short. We do not sell personal data, and we use no advertising or analytics networks.
These providers process data under their applicable service and privacy terms. Beyond these recipients, we may disclose data only where legally required. We do not otherwise sell, rent or share personal data.
RevenueCat, Google/Firebase, and Cloudflare are based in the United States or may process data there or in other countries where they operate. Their applicable data-processing terms use legally recognized transfer safeguards, such as the EU Standard Contractual Clauses and, where applicable, participation in the EU–US Data Privacy Framework. You can request more information at the contact address in Section 1.
Because Protokoll is local-first, you are in direct control of deletion: delete individual records in the app, use the data-reset function, or uninstall (which removes the on-device database — but not a backup file you placed in your own cloud, nor any OS-level device backup). Delete backup files yourself where you saved them. Leave crash diagnostics off, or switch them off in Settings to withdraw consent and stop all future collection; existing reports follow Firebase's retention process described above. For purchase data held by Apple or RevenueCat, request erasure from those providers or contact us to forward your request (note statutory retention of some tax/purchase records).
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20 — the app's backup feature gives you a portable copy of your training data), to object to processing based on legitimate interest (Art. 21), and to withdraw consent (Art. 7(3)) at any time. Crash diagnostics rely on consent: they remain off unless you opt in, and you can withdraw consent in Settings. For other requests, email us; we respond within the statutory time limit (normally one month).
If you believe our processing infringes the GDPR, you may lodge a complaint with a data protection supervisory authority, in particular in the EU Member State of your residence, place of work, or the place of the alleged infringement.
We do not carry out automated decision-making with legal or similarly significant effects, and we do not profile you (Art. 22 GDPR). The analytics and “training state” the app shows are computed on your device, from your own data, for you.
Protokoll is not directed at children and is intended for users who can lawfully enter into a subscription (generally 16+ in the EU, or the minimum age set by your app store). We do not knowingly process data from children below the applicable age of consent.
Crash diagnostics, when enabled, are transmitted over encrypted connections. Backup files are encrypted at rest (see 3.3 for limits). Sensitive on-device values such as entitlement state use the OS secure storage (iOS Keychain / Android Keystore). No method is perfectly secure, but because we hold none of your training data on a server, there is no central store for an attacker to reach.
We may update this policy as the app evolves or the law changes; the “Last updated” date reflects the current version, and material changes are surfaced in the app or on this page beforehand. For any question or request:
This policy describes the Protokoll TestFlight beta as of the effective date above. It will be updated if the app's data practices change.