Vindofit logoVindofit

Privacy Policy

How we collect, use, share, and protect your personal and health information when you use the Vindofit app and related services.

Effective date: 19 June 2026  ·  Last updated: 19 June 2026  ·  Version 1.1

Your privacy matters to us. Vindofit is a health and fitness application, which means some of the information we handle is sensitive. This policy explains, in plain language, what we collect, why, and the control you have over it. It is designed to comply with the EU General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG), and the health-data requirements of Apple and Google.

1.Who we are

The controller responsible for processing your personal data under the GDPR is:

Toan Le — sole proprietor, trading as “Vindofit”
Schnirchgasse 9, 1030 Vienna, Austria
Contact: [email protected]

2.Scope of this policy

This policy applies to the Vindofit mobile applications (iOS, iPadOS, watchOS, and Android), our websites at vindofit.com, and our backend services (the "Services"). It does not apply to third-party products, platforms, devices, or websites that we link to or integrate with — including Apple Health, Google Health Connect, Bluetooth heart-rate monitors, and the app stores — which are governed by their own privacy policies.

3.Data we collect

CategoryExamples
Account & identityName, email address, the identifier from your Apple or Google sign-in, profile photo, city, date of birth or age, sex/gender, time zone, and language. We do not store passwords — you sign in with Apple or Google.
Health & fitnessWorkouts, exercises, sets/reps/weights, personal records, running and activity data, steps, distance, floors, heart rate (including live heart rate from connected monitors), heart-rate variability, resting and respiratory rate, oxygen saturation, skin temperature, blood pressure, VO₂ max, energy/calories, basal metabolic rate, sleep, body weight, body fat, lean body mass, body measurements, recovery/readiness scores, training load, streaks, and — only if you opt in — menstrual-cycle data. See sections 4–5.
Nutrition & hydrationFoods and meals you log, calories and macronutrients, scanned product barcodes, and hydration entries.
Location & routesGPS routes of runs and other outdoor activities, used to draw your activity on a map. See section 7.
Photos & mediaProfile photo, workout photos, and body/progress photos you capture or import. Body/progress photos stay on your device — see section 5.
Connected devicesIdentifiers of Bluetooth heart-rate monitors and wearables you pair, and the data they stream during a workout.
SocialGroups, friends, leagues, challenges, messages with coaches, shared workout templates, comments and reactions you choose to post.
Device & technicalDevice model, operating system, app version, language, time zone, IP address, crash logs, push-notification token, and diagnostic identifiers.
UsageFeatures used, screens viewed, in-app events, and aggregate interaction metrics.
SupportCorrespondence you send us and the contents of support requests.
BillingSubscription status and transaction identifiers. Payments are processed by the Apple App Store or Google Play; we do not receive or store your full card details.

4.Health & fitness data — special category

Health and fitness data is treated as a special category of personal data under Article 9 GDPR and is given heightened protection. We process it only on the basis of your explicit consent, which you give when you connect a health source, pair a device, or enable a feature, and which you can withdraw at any time.

Where you grant permission, Vindofit reads health data from Apple Health and Google Health Connect strictly to power the features you use — for example displaying your activity, calculating recovery and readiness, showing personalised vitals ranges, syncing your workouts, or drawing your runs on a map. We request the narrowest set of data types necessary for the features you enable, which may include: steps, distance, floors climbed, active and total energy, basal metabolic rate, workouts and workout routes, heart rate, resting and respiratory rate, heart-rate variability, oxygen saturation, skin temperature, blood pressure, VO₂ max, sleep, body weight, body fat, lean body mass, and hydration. With your separate opt-in, we also read menstrual-cycle data (see section 5).

If you connect a Bluetooth heart-rate monitor (a chest strap, watch in broadcast mode, or similar), we read its live heart-rate stream during a workout to show your real-time heart rate and training zone.

With your permission we may sync health data in the background so your information stays current without opening the app, including real-time updates from Google Health Connect. You can turn this off at any time in your device settings.

We never sell your health data.

Health and fitness data obtained from Apple Health, Google Health Connect, or connected devices is used only to provide app functionality to you. It is not used for advertising or marketing, not sold, and not shared with data brokers, consistent with Apple and Google platform requirements. You can revoke health access at any time in Apple Health or Google Health Connect, and you can delete the data we hold by deleting your account.

5.Data that stays on your device

Some of the most sensitive features are designed to keep data on your device only. Unless you explicitly choose to share it, this information is not uploaded to our servers:

If a future feature requires any of this data to leave your device, we will ask for your separate, explicit consent first.

6.Device permissions

The app asks for the following device permissions only when you use a feature that needs them. Each is optional, and you can grant or revoke it at any time in your device settings.

PermissionWhy we ask
Health (Apple Health / Health Connect)To read your activity, heart, sleep, body, and — if you opt in — cycle data, and to save logged workouts back.
BluetoothTo connect to heart-rate monitors and wearables for live heart rate during workouts.
CameraTo take progress photos, scan group-invite QR codes, and scan food barcodes.
Photo libraryTo add progress photos from your library.
Face ID / biometricsTo unlock your private body-photo diary on your device.
Motion & fitness / activity recognitionTo count steps and recognise activity for your fitness metrics.
NotificationsTo send reminders, streak and recovery alerts, and social updates.

7.Location & route data

Vindofit does not continuously track your location in the background. Route and GPS data is obtained from the workout routes recorded by Apple Health or Google Health Connect (with your permission) and is used solely to display your runs and outdoor activities on a map within the app. You can disable route access at any time in your health-store or device settings, and routes are deleted when you delete the associated activity or your account.

8.How we obtain your data

9.Why we use your data

10.Legal bases for processing

ProcessingLegal basis (GDPR)
Providing the core app and accountPerformance of a contract — Art. 6(1)(b)
Health, fitness, nutrition & route dataExplicit consent — Art. 9(2)(a) & Art. 6(1)(a)
Security, fraud prevention, product improvementLegitimate interests — Art. 6(1)(f)
Service emails & legal complianceLegal obligation / legitimate interest — Art. 6(1)(c)/(f)
Optional analytics & marketingConsent — Art. 6(1)(a)

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

11.Sharing & recipients

We share personal data only as described here:

We do not sell your personal data, and we do not use your health data for advertising.

12.Coaches & social features

If you connect with a coach inside the app, the coach can see the workout, training, and health-related data you choose to share with them, along with the messages you exchange. Coaches may be independent third parties; where they decide how to use the data you share with them, they act as separate controllers under their own responsibility. Only share what you are comfortable sharing, and you can stop sharing or disconnect at any time.

Content you post in groups, leagues, challenges, or comments is visible to other participants. Please be mindful of the health information you reveal in shared spaces.

13.Service providers (processors)

We use carefully selected providers under data processing agreements that meet Article 28 GDPR. These may include cloud hosting and database providers, crash reporting and analytics, authentication and push-notification infrastructure (e.g. Google Firebase), and customer support tools. A current list is available on request at [email protected].

14.International data transfers

Where data is transferred outside the European Economic Area, we rely on appropriate safeguards under Chapter V GDPR — typically the European Commission's Standard Contractual Clauses and, where applicable, adequacy decisions. You may request a copy of the relevant safeguards.

15.How long we keep data

We keep personal data only as long as necessary for the purposes set out above. Account and health data are retained while your account is active and deleted (or anonymised) within a reasonable period after account closure, unless a longer period is required to comply with legal obligations, resolve disputes, or enforce agreements. Data kept only on your device (section 5) is removed when you delete it or uninstall the app. You can delete your account at any time from within the app or by contacting us.

16.Security

We apply appropriate technical and organisational measures to protect your data, including encryption in transit (TLS), access controls, least-privilege practices, and on-device-only storage for the most sensitive data. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work continuously to protect your information and will notify you and the competent supervisory authority of a personal data breach where legally required.

17.Your rights

Subject to applicable law, you have the right to:

To exercise any right, email [email protected]. We respond within the statutory time limit (generally one month). You also have the right to complain to the Austrian Data Protection Authority (Österreichische Datenschutzbehörde, dsb.gv.at) or your local authority.

18.Children

Vindofit is not directed to children under 16. We do not knowingly collect personal data from anyone under 16 (or the higher minimum age set by your country). If you believe a child has provided us data, contact us and we will delete it.

19.Cookies & our website

Our marketing and legal web pages may use strictly necessary cookies and, with your consent, analytics cookies. The mobile app does not use advertising cookies. Where consent is required, we ask for it via a cookie banner and honour your choices.

20.Analytics & tracking

We do not track you across other companies' apps or websites for advertising, and we do not show third-party ads. Any analytics we use is limited to understanding and improving how Vindofit works, in aggregated or pseudonymised form, and — where required — only with your consent. We will not request App Tracking Transparency permission unless a feature genuinely requires it, and you may decline without losing functionality.

21.Automated decision-making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Personalised training, recovery, vitals, and nutrition insights are suggestions only and do not constitute such decisions.

22.Changes to this policy

We may update this policy to reflect changes in our practices or the law. We will post the updated version here with a new effective date and, for material changes, provide notice in the app. Continued use after an update constitutes acceptance of the revised policy.

23.Contact us

Questions or requests about privacy?
Email [email protected]
Or write to us at the address in section 1.