Your privacy matters to us. Vindofit is a health and fitness application, which means some of the information we handle is sensitive. This policy explains, in plain language, what we collect, why, and the control you have over it. It is designed to comply with the EU General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG), and the health-data requirements of Apple and Google.
1.Who we are
The controller responsible for processing your personal data under the GDPR is:
2.Scope of this policy
This policy applies to the Vindofit mobile applications (iOS, iPadOS, watchOS, and Android), our websites at vindofit.com, and our backend services (the "Services"). It does not apply to third-party products, platforms, devices, or websites that we link to or integrate with — including Apple Health, Google Health Connect, Bluetooth heart-rate monitors, and the app stores — which are governed by their own privacy policies.
3.Data we collect
| Category | Examples |
|---|---|
| Account & identity | Name, email address, the identifier from your Apple or Google sign-in, profile photo, city, date of birth or age, sex/gender, time zone, and language. We do not store passwords — you sign in with Apple or Google. |
| Health & fitness | Workouts, exercises, sets/reps/weights, personal records, running and activity data, steps, distance, floors, heart rate (including live heart rate from connected monitors), heart-rate variability, resting and respiratory rate, oxygen saturation, skin temperature, blood pressure, VO₂ max, energy/calories, basal metabolic rate, sleep, body weight, body fat, lean body mass, body measurements, recovery/readiness scores, training load, streaks, and — only if you opt in — menstrual-cycle data. See sections 4–5. |
| Nutrition & hydration | Foods and meals you log, calories and macronutrients, scanned product barcodes, and hydration entries. |
| Location & routes | GPS routes of runs and other outdoor activities, used to draw your activity on a map. See section 7. |
| Photos & media | Profile photo, workout photos, and body/progress photos you capture or import. Body/progress photos stay on your device — see section 5. |
| Connected devices | Identifiers of Bluetooth heart-rate monitors and wearables you pair, and the data they stream during a workout. |
| Social | Groups, friends, leagues, challenges, messages with coaches, shared workout templates, comments and reactions you choose to post. |
| Device & technical | Device model, operating system, app version, language, time zone, IP address, crash logs, push-notification token, and diagnostic identifiers. |
| Usage | Features used, screens viewed, in-app events, and aggregate interaction metrics. |
| Support | Correspondence you send us and the contents of support requests. |
| Billing | Subscription status and transaction identifiers. Payments are processed by the Apple App Store or Google Play; we do not receive or store your full card details. |
4.Health & fitness data — special category
Health and fitness data is treated as a special category of personal data under Article 9 GDPR and is given heightened protection. We process it only on the basis of your explicit consent, which you give when you connect a health source, pair a device, or enable a feature, and which you can withdraw at any time.
Where you grant permission, Vindofit reads health data from Apple Health and Google Health Connect strictly to power the features you use — for example displaying your activity, calculating recovery and readiness, showing personalised vitals ranges, syncing your workouts, or drawing your runs on a map. We request the narrowest set of data types necessary for the features you enable, which may include: steps, distance, floors climbed, active and total energy, basal metabolic rate, workouts and workout routes, heart rate, resting and respiratory rate, heart-rate variability, oxygen saturation, skin temperature, blood pressure, VO₂ max, sleep, body weight, body fat, lean body mass, and hydration. With your separate opt-in, we also read menstrual-cycle data (see section 5).
If you connect a Bluetooth heart-rate monitor (a chest strap, watch in broadcast mode, or similar), we read its live heart-rate stream during a workout to show your real-time heart rate and training zone.
With your permission we may sync health data in the background so your information stays current without opening the app, including real-time updates from Google Health Connect. You can turn this off at any time in your device settings.
Health and fitness data obtained from Apple Health, Google Health Connect, or connected devices is used only to provide app functionality to you. It is not used for advertising or marketing, not sold, and not shared with data brokers, consistent with Apple and Google platform requirements. You can revoke health access at any time in Apple Health or Google Health Connect, and you can delete the data we hold by deleting your account.
5.Data that stays on your device
Some of the most sensitive features are designed to keep data on your device only. Unless you explicitly choose to share it, this information is not uploaded to our servers:
- Body & progress photos. Photos in your private body-photo diary are stored locally on your device. You may optionally protect them with Face ID, Touch ID, or your device biometrics — the biometric check happens on your device and we never receive your biometric data.
- Menstrual-cycle data. If you opt in to cycle insights, this data is read from your health store and processed on your device to adapt your training and show cycle-phase insights. It is not uploaded to our servers.
- Body measurements. Manual body measurements you capture are stored on your device.
If a future feature requires any of this data to leave your device, we will ask for your separate, explicit consent first.
6.Device permissions
The app asks for the following device permissions only when you use a feature that needs them. Each is optional, and you can grant or revoke it at any time in your device settings.
| Permission | Why we ask |
|---|---|
| Health (Apple Health / Health Connect) | To read your activity, heart, sleep, body, and — if you opt in — cycle data, and to save logged workouts back. |
| Bluetooth | To connect to heart-rate monitors and wearables for live heart rate during workouts. |
| Camera | To take progress photos, scan group-invite QR codes, and scan food barcodes. |
| Photo library | To add progress photos from your library. |
| Face ID / biometrics | To unlock your private body-photo diary on your device. |
| Motion & fitness / activity recognition | To count steps and recognise activity for your fitness metrics. |
| Notifications | To send reminders, streak and recovery alerts, and social updates. |
7.Location & route data
Vindofit does not continuously track your location in the background. Route and GPS data is obtained from the workout routes recorded by Apple Health or Google Health Connect (with your permission) and is used solely to display your runs and outdoor activities on a map within the app. You can disable route access at any time in your health-store or device settings, and routes are deleted when you delete the associated activity or your account.
8.How we obtain your data
- Directly from you — when you create an account, log workouts and meals, capture photos, message a coach, or contact support.
- Automatically — through your use of the app, including device and usage data.
- From platform health stores — Apple Health and Google Health Connect, only with your explicit permission.
- From connected devices — Bluetooth heart-rate monitors and wearables you pair.
- From app stores — subscription and purchase status from Apple and Google.
9.Why we use your data
- To provide, operate, and personalise the Services and your training, recovery, and nutrition experience.
- To sync, store, and display your workouts, health metrics, routes, and progress.
- To enable social features you opt into (groups, leagues, challenges, coaching).
- To send you reminders and notifications you have enabled.
- To maintain security, prevent fraud and abuse, and debug issues.
- To communicate with you about service updates and support.
- To comply with legal obligations and enforce our terms.
- To analyse, in aggregated or pseudonymised form, how the app is used so we can improve it.
10.Legal bases for processing
| Processing | Legal basis (GDPR) |
|---|---|
| Providing the core app and account | Performance of a contract — Art. 6(1)(b) |
| Health, fitness, nutrition & route data | Explicit consent — Art. 9(2)(a) & Art. 6(1)(a) |
| Security, fraud prevention, product improvement | Legitimate interests — Art. 6(1)(f) |
| Service emails & legal compliance | Legal obligation / legitimate interest — Art. 6(1)(c)/(f) |
| Optional analytics & marketing | Consent — Art. 6(1)(a) |
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
11.Sharing & recipients
We share personal data only as described here:
- Other users — content you choose to make visible (profile, group and league activity, comments, shared templates).
- Coaches — see section 12.
- Service providers — processors acting on our instructions (section 13).
- App stores & payment platforms — Apple and Google, for distribution and billing.
- Legal & safety — authorities or third parties where required by law, to enforce our terms, or to protect rights and safety.
- Business transfers — in connection with a merger, acquisition, or asset sale, subject to this policy.
We do not sell your personal data, and we do not use your health data for advertising.
12.Coaches & social features
If you connect with a coach inside the app, the coach can see the workout, training, and health-related data you choose to share with them, along with the messages you exchange. Coaches may be independent third parties; where they decide how to use the data you share with them, they act as separate controllers under their own responsibility. Only share what you are comfortable sharing, and you can stop sharing or disconnect at any time.
Content you post in groups, leagues, challenges, or comments is visible to other participants. Please be mindful of the health information you reveal in shared spaces.
13.Service providers (processors)
We use carefully selected providers under data processing agreements that meet Article 28 GDPR. These may include cloud hosting and database providers, crash reporting and analytics, authentication and push-notification infrastructure (e.g. Google Firebase), and customer support tools. A current list is available on request at [email protected].
14.International data transfers
Where data is transferred outside the European Economic Area, we rely on appropriate safeguards under Chapter V GDPR — typically the European Commission's Standard Contractual Clauses and, where applicable, adequacy decisions. You may request a copy of the relevant safeguards.
15.How long we keep data
We keep personal data only as long as necessary for the purposes set out above. Account and health data are retained while your account is active and deleted (or anonymised) within a reasonable period after account closure, unless a longer period is required to comply with legal obligations, resolve disputes, or enforce agreements. Data kept only on your device (section 5) is removed when you delete it or uninstall the app. You can delete your account at any time from within the app or by contacting us.
16.Security
We apply appropriate technical and organisational measures to protect your data, including encryption in transit (TLS), access controls, least-privilege practices, and on-device-only storage for the most sensitive data. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work continuously to protect your information and will notify you and the competent supervisory authority of a personal data breach where legally required.
17.Your rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data ("right to be forgotten");
- Restrict or object to certain processing;
- Data portability — receive your data in a structured, machine-readable format;
- Withdraw consent at any time where processing is based on consent;
- Lodge a complaint with a supervisory authority.
To exercise any right, email [email protected]. We respond within the statutory time limit (generally one month). You also have the right to complain to the Austrian Data Protection Authority (Österreichische Datenschutzbehörde, dsb.gv.at) or your local authority.
18.Children
Vindofit is not directed to children under 16. We do not knowingly collect personal data from anyone under 16 (or the higher minimum age set by your country). If you believe a child has provided us data, contact us and we will delete it.
19.Cookies & our website
Our marketing and legal web pages may use strictly necessary cookies and, with your consent, analytics cookies. The mobile app does not use advertising cookies. Where consent is required, we ask for it via a cookie banner and honour your choices.
20.Analytics & tracking
We do not track you across other companies' apps or websites for advertising, and we do not show third-party ads. Any analytics we use is limited to understanding and improving how Vindofit works, in aggregated or pseudonymised form, and — where required — only with your consent. We will not request App Tracking Transparency permission unless a feature genuinely requires it, and you may decline without losing functionality.
21.Automated decision-making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Personalised training, recovery, vitals, and nutrition insights are suggestions only and do not constitute such decisions.
22.Changes to this policy
We may update this policy to reflect changes in our practices or the law. We will post the updated version here with a new effective date and, for material changes, provide notice in the app. Continued use after an update constitutes acceptance of the revised policy.
