Privacy Policy
Preamble
With the following privacy policy, we would like to inform you about the types of your personal data (hereinafter also referred to briefly as "data") we process, for what purposes, and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and, in particular, in the mobile application "GYMLOG. YOUR PROGRESS. YOUR RULES.", on our website, and within external online presences (hereinafter collectively referred to as "online offer").
LOCAL DATA SOVEREIGNTY AS A CORE ELEMENT:
Protecting your privacy is the fundamental concept of our app. All training-relevant data (such as exercises, sets, weights, progress, and notes) as well as your personal profile settings (age, height, weight) are stored exclusively locally in a secured database on your end device. We have no access to this content at any time. A transfer of data only occurs if you actively use features such as the auto-backup via Google Drive or if you contact us voluntarily.
The terms used are not gender-specific.
As of: July 10, 2026
Table of Contents
Controller
Michael Palm
bytes.for.individuals
Gartenweg 1
21521 Aumuehle
Germany
Email address: privacy@bytesforindividuals.com
Legal Notice: https://bytesforindividuals.com/legal-notice-en.html
Overview of Processing Activities
The following overview summarizes the types of processed data and the purposes of their processing.
Types of Processed Data
- Inventory and Content Data: (e.g., names, local profile information, training notes, photos).
- Payment Data: (confirmations of in-app purchases via the Google Play Store).
- Contact Data: (e.g., email, phone numbers in the event of support requests).
- Usage and Log Data: (e.g., access times to the website, technical logs when retrieving content).
- Meta and Communication Data: (e.g., IP addresses when loading background images).
Purposes of Processing
- Provision of the app functions and local training documentation.
- Processing of Pro upgrades via the Google Play Store.
- Responding to support requests and user communication.
- Marketing and public relations (via Instagram).
- Security measures and technical stability of the offering.
Relevant Legal Bases
We process personal data on the basis of the following legal grounds of the GDPR (General Data Protection Regulation):
- Performance of a Contract (Art. 6(1)(b) GDPR): Necessary to provide you with the app services and purchases.
- Consent (Art. 6(1)(a) GDPR): In the case of voluntarily submitted content for the community gallery.
- Legal Obligation (Art. 6(1)(c) GDPR): To comply with statutory retention requirements.
- Legitimate Interests (Art. 6(1)(f) GDPR): To ensure security and to respond to inquiries.
Security Measures
We take appropriate technical and organizational measures (TOMs) in accordance with the legal requirements, taking into account the state of the art, to ensure a level of protection appropriate to the risk. This includes, in particular, protecting the local database on your end device through system backups as well as the encrypted transmission of data between your device and our services (e.g., HTTPS when accessing our website, retrieving images, or via SSL encryption of our online offer).
Transfer of Personal Data
Your data will only be passed on if this is necessary for the performance of a contract (e.g., payment processing by Google) or if we use specialized IT service providers (e.g., Cloudflare for content delivery and hosting, STRATO for domain management, or Google for the email infrastructure). In all cases, we comply with statutory requirements and conclude corresponding agreements to protect your data.
International Data Transfers
Insofar as we transfer data to a third country outside the EU (e.g., USA or Canada), this is done on the basis of legal permissions. For the image provider Unsplash (Canada), we rely on the adequacy decision of the EU Commission. For Google (USA) and Cloudflare (USA), processing is based on the Data Privacy Framework (DPF).
General Information on Data Storage and Erasure
We delete personal data as soon as they are no longer required for their intended purpose. Since your training content is stored exclusively locally, you are responsible for deleting it yourself (e.g., by uninstalling the app). Contact data (emails) processed by us will be deleted after the inquiry has been resolved, provided that no legal archiving obligations stand in the way.
Rights of Data Subjects
As a data subject, you have the following rights under the GDPR:
- Right of Access: You can request confirmation as to whether your data is being processed.
- Right to Rectification/Erasure: You can request the correction or removal of your data.
- Right to Object: You can object to the processing of your data at any time.
- Right to Lodge a Complaint: You have the right to lodge a complaint with a data protection supervisory authority.
Specific Features of the GYMLOG. YOUR PROGRESS. YOUR RULES. Mobile App & Backup
Within the mobile application, data is processed as follows:
- Local SQLite Database: All training achievements are saved locally on your device. We have no access to this data.
- Auto-Backup (Google Drive): The app provides an interface to Google Drive (Google Ireland Limited) to store backup copies of your database. This transfer takes place exclusively at your request. The responsibility for the security of your cloud storage lies with the user.
- Offline Calculations: Motivation trends (BioAge, 1RM) are calculated locally; no biometric profiling takes place on our servers.
Payment Processing (In-App Purchases)
For the acquisition of the Pro version, we use the payment service of the platform:
- Google Play Billing: Processing of transactions by Google Ireland Limited, Dublin, Ireland. We only receive confirmation of the successful purchase; bank or credit card details of the user are not processed or stored by us.
Provision of the Online Offer, Hosting (Cloudflare) and Images (Unsplash)
To operate our website, secure connection transfers, and visually design the app, we use external services:
- Cloudflare: We use Cloudflare's services for hosting our website content (Cloudflare Pages) as well as for securing data transmission using an SSL certificate. When you access our website, technical connection data (such as your IP address) is routed through Cloudflare's servers as a matter of technical necessity in order to ensure fast website delivery and ward off cyberattacks. The service provider is Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA.
- STRATO: Our domain is registered with STRATO AG. We also use STRATO to provide a part of our email infrastructure. The service provider is STRATO AG, Otto-Ostrowski-Straße 43, 10249 Berlin, Germany.
- Google Email Infrastructure: We also use Google's infrastructure to handle email traffic and respond to support requests. The service provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
- Unsplash: The app downloads background images from the servers of Unsplash Inc. (Montreal, Canada). For technical reasons, the IP address of your end device is transmitted to Unsplash in order to transmit the image file.
Use of Cookies
Our website uses exclusively technically necessary cookies to provide basic functionalities. No tracking, web analysis, or marketing cookies are used on our website.
Social Media & Communication (Instagram / WhatsApp)
We use social networks and messengers for communication and marketing purposes:
- Instagram: Official presence to provide information about app updates. Service provider: Meta Platforms Ireland Limited, Dublin, Ireland.
- WhatsApp: We offer WhatsApp as a channel for support and for submitting community content. Service provider: Meta Platforms Ireland Limited, Dublin, Ireland.
- Community Photos: If you actively send us photos for publication in the app, we process this content on the basis of your consent. By sending them, you grant us the corresponding rights of use in accordance with the app instructions.
Amendments and Updates
We adjust this privacy policy as soon as changes in the data processing carried out by us or new legal requirements make this necessary. Please check back regularly to stay informed about the status of this policy.
Definitions of Terms
- Inventory Data: Information used to identify individuals (e.g., names, profile settings).
- Content Data: Data generated by use (e.g., workout entries, photos).
- Meta and Communication Data: Technical information about the connection (e.g., IP addresses, device IDs).
- Usage Data: Information about behavior within the offering (e.g., click paths, access times).
- Controller: The natural or legal person who determines the purposes and means of processing personal data.
- Processing: Any operation or set of operations performed on personal data (such as collection, storage, transfer, or erasure).