Legal

Privacy Policy

Last updated: 2026-06-02 · This is the launch version (English only). A German translation will follow.

1. Who we are (Controller)

The data controller under Article 4(7) GDPR is Ole Fiegenbaum, Schledehauser Weg 75C, 49086 Osnabrück, Deutschland. For any question about this policy or about your personal data, contact us at olefiegenbaum@gmx.de. We do not have a designated Data Protection Officer (Art. 37 GDPR is not triggered by our current scale of processing).

2. What data we collect

When you create an account and use the app, we store the following data on our servers:

  • Profile: name, email, age, training goal, event date, training frequency, focus.
  • Biometric (optional): max heart rate, resting heart rate, heart-rate zones, pace zones, tracking-mode (chest strap / watch / none), 5K target time.
  • Training history: sessions you complete, duration, intensity, perceived difficulty, session-RPE, post-session notes, and (when you connect Strava) activity GPS, distance, duration, and average heart rate.
  • Wellness checkins: sleep quality, motivation level, readiness rating, perceived difficulty.
  • Apple Health (optional, iOS only): when you grant the in-app HealthKit permission, we read and store one daily snapshot per category that you have authorised on your device. The snapshot can include: resting heart rate, heart-rate variability (SDNN), total sleep duration, sleep stages (Deep / REM / Core / Awake), respiratory rate, blood-oxygen saturation (SpO₂), wrist skin-temperature deviation, VO₂max estimate, step count, distance walked / run, flights climbed, active and basal energy, exercise minutes, and stand hours. We do not store the raw second-by-second heart-rate time series. You can revoke the HealthKit permission at any time in iOS Settings → Privacy & Security → Health → Hybrid Training Coach, and you can disconnect the integration entirely in the app’s Settings.
  • Coach conversations: questions you ask the AI coach and the assistant’s replies. The most recent 20 turns are kept to provide context for follow-up questions.
  • Subscription state: your current tier, renewal status, and expiration date, synced from RevenueCat / Apple StoreKit.
  • Technical logs: limited diagnostic logs (timestamps, error traces, anonymous request IDs) for debugging. No IP-based tracking, no advertising identifiers.

2a. Special category data (Art. 9 GDPR)

Apple Health signals (resting HR, HRV-SDNN, sleep duration and stages, respiratory rate, SpO₂, wrist skin-temperature, VO₂max) qualify as data concerning health under Article 9(1) GDPR. We process this data only on the legal basis of your explicit consent under Art. 9(2)(a) GDPR, which you grant by enabling the HealthKit integration in the app and confirming the iOS permission dialog. Without this consent, no health data leaves your device.

We use Apple Health data exclusively to (i) personalise your daily training recommendation and recovery cap, (ii) display your own recovery and fitness trends inside the app, and (iii) inform the AI coach so its replies reflect your current readiness. We do not share Apple Health data with any third party, do not use it for advertising, do not use it to train any AI model, and do not combine it with data from other users. You can withdraw consent at any time (see Section 10); withdrawal does not affect the lawfulness of processing before withdrawal.

3. Legal basis for processing (Art. 6 & 9 GDPR)

We process your personal data on the following legal bases:

  • Performance of a contract (Art. 6(1)(b)), account creation, training history, daily decisions, subscription handling. Without these we cannot deliver the service you signed up for.
  • Consent (Art. 6(1)(a)), optional integrations such as Strava activity sync and persisting your coach conversation history. You can withdraw consent at any time in settings; this does not affect the lawfulness of processing before withdrawal.
  • Explicit consent for health data (Art. 9(2)(a)), the Apple Health integration (see Section 2a) requires explicit consent on top of the general lawful-basis under Art. 6 because the data falls under Art. 9 special category. Consent is granted by enabling the integration in the app and confirming the iOS HealthKit permission dialog, and can be revoked at any time.
  • Legitimate interest (Art. 6(1)(f)), debug logs, error diagnostics, fraud prevention on the subscription path. We balance this against your rights; if you object (Art. 21 GDPR), email us at the address above.

4. Automated decision-making & AI coach (Art. 22, 13(2)(f))

HybridOS uses two automated components: a deterministic decision engine that generates daily training recommendations from your session history and profile, and an AI coach (Anthropic Claude) that answers free-form questions with context drawn from your training data.

These are not decisions with legal or similarly significant effect under Article 22 GDPR. Recommendations are advisory, you decide whether to follow them, modify them, or ignore them entirely. The coach’s replies are guidance, not medical or contractual decisions. You always retain the right to a human review of any output by emailing olefiegenbaum@gmx.de.

4a. Service improvement & analysis by the operator

Beyond running the app, we (the operator named in Section 1) analyse how real users move through the product so we can improve it, in particular to refine the onboarding flow, the recommendation engine, and the AI coach. This means we may look at your training data and how it lines up with the recommendations you were given, to judge whether the product is actually serving you.

Part of this analysis is AI-assisted: we use Anthropic Claude (the same processor listed in Section 6, under the same commercial terms that prohibit training models on the data) as a tool to help us interpret usage patterns. When we do this, we work on a pseudonymised basis, keyed to an internal user identifier, not your name or email, and transmit only the data needed for the specific question.

Legal basis: our legitimate interest in operating and improving the service (Art. 6(1)(f) GDPR). You can object to this processing at any time (Art. 21 GDPR) by emailing olefiegenbaum@gmx.de; we will then exclude your data from product-improvement analysis without affecting your use of the app.

Health and special-category data (Section 2a) is excluded from this operator analysis unless you have given separate explicit consent under Art. 9(2)(a) GDPR. During the current closed testing phase, any analysis that touches health-related data is performed only on test users who have given that consent to us directly.

5. Where we store it

All user data is stored in Supabase (PostgreSQL), region eu-west-1 (Ireland). Backups are encrypted at rest and retained according to Supabase’s standard policy. Production runtime logs are kept by Vercel (Frankfurt region where available) under their standard retention.

6. Data processors & sub-processors (Art. 28 GDPR)

We use the following processors under written Data Processing Agreements (DPAs). A current list with DPA references is available on request:

  • Supabase Inc., managed PostgreSQL hosting and authentication. Region: EU (Ireland).
  • Vercel Inc., application hosting, edge runtime, log retention.
  • Anthropic PBC, Claude API for the AI coach. Anthropic does not train models on API inputs per their commercial terms.
  • Apple Inc. & RevenueCat Inc., subscription receipts and entitlement state. They receive only your Apple-anonymous transaction identifier and product ID, never your name or training data.
  • Strava Inc., only if you explicitly connect Strava in settings. We then read your activity history (with your token) to keep training history in sync.

Apple Health (HealthKit) note: HealthKit data is read directly from your iPhone or iCloud Health store using Apple’s on-device API. No third party sits between Apple and our server. We transmit the daily snapshots described in Section 2 from your device to our Supabase database over TLS. Apple is therefore not a sub-processor of HybridOS for HealthKit purposes, you are the data subject, your device is the source, and our server is the destination.

We do not use any third-party analytics SDKs (no Google Analytics, no Mixpanel, no PostHog, no Sentry, no Meta Pixel) inside the iOS app.

7. International data transfers (Art. 44-50 GDPR)

Some of our processors are based in the United States. Where personal data is transferred outside the EU/EEA, we rely on the following safeguards:

  • EU Standard Contractual Clauses (SCCs) as adopted by the European Commission (2021/914) with all US-based processors listed above.
  • EU–U.S. Data Privacy Framework certification of the receiving organisation, where applicable (currently Apple Inc.; we monitor Anthropic and other processors as their certifications evolve).
  • Supplementary technical measures: TLS in transit, processor-side encryption at rest, data minimisation (we transmit only the context strictly needed for each API call).

You have the right to request a copy of the relevant transfer safeguards by emailing the address above.

8. Data retention

We keep your data for as long as your account is active. After account deletion, data is removed from our live database within 7 days and from our encrypted backups within 30 days. Diagnostic logs are retained for a maximum of 30 days and then rotated.

9. Security measures (Art. 32 GDPR)

We protect your data with industry-standard measures appropriate to the risk:

  • TLS 1.2+ for all data in transit between your device, our APIs, and our processors.
  • AES-256 encryption at rest for the primary database and backups (Supabase-managed).
  • Row-Level Security (RLS) enabled on every user-scoped table. For Art. 9 health data (Apple Health snapshots), tables are additionally locked down: client-side roles (`anon`, `authenticated`) have no SELECT/INSERT/UPDATE/DELETE grants, only the server-side service role can access them, ensuring no client-side query can read another user’s biometric data even if their public anon key were misused.
  • Principle of least privilege for admin access, with audit logs on privileged operations.
  • Regular dependency updates and automated security advisories.

10. Your rights (GDPR & CCPA)

You have the right to:

  • Access a copy of the personal data we hold about you (Art. 15 GDPR).
  • Correct inaccurate or incomplete data (Art. 16 GDPR).
  • Delete your account and associated data (Art. 17 GDPR).
  • Restrict or object to processing (Art. 18 & 21 GDPR).
  • Export your data in a machine-readable format (Art. 20 GDPR).
  • Withdraw consent for any optional integration (e.g. Strava) at any time in settings (Art. 7(3) GDPR).
  • Not be subject to a decision based solely on automated processing (Art. 22 GDPR), see Section 4.

To exercise any of these rights, email olefiegenbaum@gmx.de. We respond within 30 days.

You also have the right to lodge a complaint with a supervisory authority. For users in Germany, our competent authority is: Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, lfd.niedersachsen.de. Users in other EU member states may complain to their local data-protection authority.

11. Children's privacy

HybridOS is intended for users aged 13 and older (the minimum age for an Apple ID). We do not knowingly collect data from children under 13. If we learn that we have, we will delete it.

12. Changes to this policy

We may update this policy as the app evolves (new integrations, new features, regional requirements). When we do, we update the “Last updated” date at the top and notify you in-app on the next launch if the changes are material.