Privacy Policy
1. Data Controller
The party responsible for data processing on this website and in the hitPR app is:
Christian GeißlerAm Weigelsgarten 29
60433 Frankfurt am Main, Germany
E-Mail: info@hitpr.app
2. What data is collected?
hitPR works without a user account. There is no registration and no sign-in with us; we store neither your name nor your email address. Your training data (exercises, sets, weights, repetitions, personal records, plans and settings) is created by your input and lives in a database on your device. We do not operate a server on which it is stored, and we do not receive it. It is processed by the app on your device in order to provide hitPR to you — the legal basis for this is Art. 6(1)(b) GDPR (performance of our usage contract with you). If you choose your own cover image for a plan, hitPR receives exactly that one image through your operating system's picker. The app does not read your photo library. The image is copied into the app folder and stays there. Acceptance of the legal texts: when you complete onboarding, we record which version of the terms of service and the privacy policy you accepted — version, time and where. This record stays exclusively on your device. Where data can nevertheless go is described in the sections “Storage and deletion”, “Third-party services”, “Crash reports”, “Feedback feature” and “Tracking and analytics”. The principle behind it: we do not see your training data.
3. Purpose of data processing
• Local data: functionality of the app — recording training, evaluating progress, suggesting training weights • Data backup: protection against data loss and moving to a new device • Crash reports: troubleshooting and app stability • Feedback feature: processing and answering your message • Anonymous usage statistics: aggregated, unlinked signals used to improve the app and the plan catalog • Purchase handling: unlocking the features you have bought
4. Storage and deletion
Your training data lives in the app on your device and is deleted when you uninstall it. We keep no copy of it — there is nothing on our side that we could keep for you or delete on request. Data backup (hitPR Pro): if you switch on automatic backup, hitPR places a single backup file in your own cloud storage — on Android in your Google Drive, on iOS in your iCloud. That storage belongs to you, not to us; Google's or Apple's terms apply to it. The file is encrypted on your device with AES-256-GCM before it is transferred. The key is generated on your device and exists only there and in your recovery code. We do not know it and cannot read the backup. Each new backup replaces the previous one. If you switch backup off, the last file written stays in your cloud storage until you delete it. The backup contains your training data, but not image files you have chosen yourself: of a plan cover image, only the reference is backed up, not the image. It is therefore missing on a new device. The backup is created and transferred by the app on your device — the legal basis for this is Art. 6(1)(b) GDPR (performance of our usage contract with you). Manual export: under Settings → “Data” you can export your data yourself at any time — encrypted, or as an unencrypted JSON or CSV file. The export goes through your operating system's share sheet and can therefore end up in any folder and with any service you select there. You decide where it goes; once handed over, we no longer have any influence on it. An unencrypted export file can be read by anyone who obtains it. Deletion: “Delete All Data” in the settings removes all local data and also deletes the backup file in your cloud storage. Only the bundled exercise catalog remains. Export files you have passed on yourself, and copies in an operating system backup, are not covered by this. What is stored on our side is limited to the sections “Feedback feature” and “Tracking and analytics”; the retention periods stated there apply.
5. Third-party services
• Cloudflare (Cloudflare, Inc., USA) – operation of hitpr.app: delivery of the plan catalog and the exercise images, and receipt of the anonymous usage statistics and the feedback messages. The database for this is created with EU jurisdiction. Data processing agreement (DPA) in place. Data transfers on the basis of the EU-US Data Privacy Framework, additionally safeguarded by Standard Contractual Clauses (SCC). • Google Drive (Google Ireland Limited, Ireland) – only if you switch on the data backup on Android. hitPR asks for your Google sign-in for this and receives, for Drive, only the right to manage files the app itself created (the “drive.file” scope); the app has no access to your other Drive files. In doing so, Google also passes the email address of the selected account to the app; we show it to you in the settings, it stays on your device and is not transmitted to us. The backup lies in your own storage — here Google is your provider, not our processor. • Apple iCloud (Apple Distribution International Ltd., Ireland) – only if you switch on the data backup on iOS. The backup lies in your own iCloud storage, which your device has already set up; the app performs no separate sign-in with Apple. Here Apple is your provider, not our processor. • Google Firebase Crashlytics (Google Ireland Limited, Ireland) – crash reports, only after your explicit consent. Details in the section “Crash reports”. Data transfers on the basis of the EU-US Data Privacy Framework; where it is not available, Standard Contractual Clauses apply. • RevenueCat (RevenueCat, Inc., USA) – management of purchases and subscriptions. Processes purchase receipts, purchase and subscription status, and an anonymous app user ID assigned by RevenueCat that is not linked to any account with us. No payment data is transmitted; training data does not reach RevenueCat. Data transfers on the basis of Standard Contractual Clauses. • Google Play services (Google Ireland Limited, Ireland) – on Android, for the connection to the Wear OS Watch Companion, see the section “Watch Companion”. There is no sign-in with Google or Apple as an identity service (“Sign in with Google/Apple”) — hitPR has no user account. We provide a copy of the Standard Contractual Clauses on request (info@hitpr.app).
6. Crash reports
Crash reports are switched off by default. If you enable them, the following data is transmitted to Google Firebase (Google Ireland Ltd.) when the app crashes: • Installation identifier (pseudonymous) • Device model and operating system version • IP address (not permanently stored by Google) • Error logs (stack traces) Legal basis: consent (Art. 6(1)(a) GDPR). You can withdraw your consent at any time in the settings. Data is retained for 90 days. More information: https://firebase.google.com/support/privacy
7. Feedback feature
When you use the feedback function, your message, a randomly generated device identifier (UUID), the name and version of your operating system and the app version are transmitted to our service at hitpr.app and stored there with Cloudflare in a database with EU jurisdiction. If your message concerns a plan from the catalog, which plan it is about is transmitted as well. The device identifier is generated randomly on first launch, is not linked to any account and serves solely to prevent spam (limiting the number of messages per device). It is also transmitted in the preliminary check with which the app determines whether you can currently send a message. Feedback entries are deleted no later than 24 months after receipt. Legal basis: legitimate interest in improving the product (Art. 6(1)(f) GDPR). Please do not include any health details in your message — we do not need them to process it. Optionally you can provide an email address if you would like a reply. It is used solely to answer your message, is not passed on, and is removed from the entry after 12 months at the latest. Legal basis: consent (Art. 6(1)(a) GDPR), revocable at any time.
8. Tracking and analytics
hitPR uses no advertising, tracking or third-party analytics SDKs. There is no user tracking: no cross-device or cross-app tracking, no advertising IDs, no usage profiles, no sharing with advertising partners. Anonymous usage statistics: to improve the app we collect anonymous, aggregated usage signals (for example which screens are opened, whether a workout is started or finished, which catalog plans are imported, and general settings such as language and unit system). These events contain no training content and no personal details. They are sent without a device or user identifier and without a timestamp from your device, and cannot be combined into a history or traced to a person. The recipient is our service at hitpr.app hosted by Cloudflare (database with EU jurisdiction). There, each event is folded into a daily counter the moment it arrives; individual events are not stored and IP addresses are not recorded. The daily figures are deleted after 12 months at the latest. Collection only takes place with your explicit consent — you can enable it during onboarding or at any time in the settings (default: off). Crash reports, too, are only sent with your explicit consent (default: off). We ask for this consent also because reading and accessing information on your device requires consent under § 25 of the German TDDDG — regardless of whether personal data is involved.
9. Payment data
hitPR does not process payment data directly. Purchases are handled exclusively through the Apple App Store or Google Play. The stores' respective privacy policies apply. To manage purchases and subscriptions we use RevenueCat; details in the section “Third-party services”.
10. App store download
When you download the app, your device transmits the information required for this to the respective app store (Apple App Store or Google Play Store) — in particular your store user ID, the time of download, a device identifier and, for paid purchases, payment information. We have no influence over this data collection by the store operator; it takes place under their sole responsibility. The privacy policies of Apple and Google apply.
11. Your rights
You have the right at any time to:
- Access to your stored data (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing (Art. 21 GDPR)
- Withdrawal of consent you have given, with effect for the future (Art. 7(3) GDPR)
Because hitPR works without a user account, your training data rests with you alone. You therefore exercise these rights largely yourself, without going through us: • Access and data portability: the export under Settings → “Data” — it outputs your stored data in a machine-readable format. • Rectification: directly in the app. • Erasure: “Delete All Data” in the settings; this also covers the backup file in your cloud storage. • Withdrawing consent to crash reports and to the anonymous usage statistics: the switches in the settings.
For the few pieces of data that do sit with us — your feedback messages including any email address given there — a message to info@hitpr.app is enough; we will then delete them. Independently of this, they are deleted anyway within the periods stated in the section “Feedback feature”. The anonymous usage statistics contain no identifier that would allow events to be attributed to you; we can therefore neither provide access from them nor delete specific entries.
You have the right to lodge a complaint with a data protection supervisory authority — in particular in the EU member state of your habitual residence, your place of work or the place of the alleged infringement (Art. 77 GDPR). The authority responsible for us is: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany https://datenschutz.hessen.de
12. Objection to processing based on legitimate interests
You can object at any time to the processing of your data insofar as we base it on a legitimate interest (Art. 6(1)(f) GDPR). This concerns the handling of your feedback message, the delivery and security of our website, the website analytics and the spam protection of the waitlist form. An informal note to info@hitpr.app is enough. You object to the website analytics yourself: at the end of this page you switch it off for the browser you are using. To do this, the objection is stored locally in your browser and applies only there — if you delete the site data, you have to set it again. This one objection does not go through us: the measurement works with a daily-changing, irreversible value and does not attribute visits to any person; we could not find you there in order to exempt you.
13. Automated decision-making
There is no automated decision-making or profiling within the meaning of Art. 22 GDPR: no decision with legal effect or similarly significant impact is made about you. The app does, however, calculate automatically. From your training history it derives training weights, repetition ranges and values such as Training Max or Estimated 1RM, and the Plan Finder suggests a plan based on your inputs. These are computed results under fixed rules that are the same for everyone — suggestions you can override at any time, not an assessment of you as a person. The calculation runs on your device.
14. Minimum age
Under our terms of service, use is permitted from the age of 16. Where we ask for consent — for the anonymous usage statistics, for crash reports and for an optionally provided email address — under Art. 8 GDPR it can only be given effectively by you from the age of 16; below that, the consent of a parent or guardian is required.
15. Changes to this privacy policy
We update this privacy policy when the app or the legal requirements change. The current version can be found in the app and at https://hitpr.app.
16. Contact
If you have questions about privacy, contact: info@hitpr.app
17. Website hosting
This website is hosted by Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA). Cloudflare is a CDN and security provider. Use is based on Art. 6(1)(f) GDPR. We have a legitimate interest in presenting our website as reliably as possible. A data processing agreement (DPA) has been concluded with Cloudflare. In the process, Cloudflare processes technically necessary connection data (including IP address, date/time of the request, requested resource, user agent) to deliver and secure the website. This data is not combined with other data sources.
18. Website analytics
This website uses a self-hosted, cookie-free analytics setup. No cookies are set and nothing is stored on your device. Only aggregated metrics are collected, such as page views, an approximate visitor count, referrer, country and browser/device type. To count returning visitors within a single day, a daily-rotating, irreversible hash is derived from IP address and browser signature; the IP address itself is not stored and the key changes every day, so visitors cannot be recognised across days. Processing takes place within the same Cloudflare infrastructure that hosts this website — no data is passed to any additional third party. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in privacy-friendly analytics); no cookie banner is required.
19. Cookies and local storage
This website does not set any cookies when you visit and does not use tracking technologies. When you actively use certain features, the website stores settings locally in your browser (localStorage): the weight unit (kg/lbs) you choose in the training tools and, if you have set it, your objection to the website analytics. This data remains exclusively on your device, is not transmitted to us or third parties, and can be deleted at any time via your browser settings. The storage is strictly necessary for the feature you explicitly request (§ 25 (2) no. 2 of the German TDDDG); a consent banner is therefore not required.
20. Fonts
This website uses self-hosted fonts (DM Sans, DM Mono). There is no connection to external servers such as Google Fonts. The fonts are loaded directly from our server.
21. Waitlist
When you join the waitlist on our website, we process your email address and — as proof of your consent (double opt-in) — the time of signup and confirmation together with the IP address used. The sole purpose is to notify you once, as soon as the app is available. The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time with effect for the future — for example via the unsubscribe link in the email or the contact details listed above under “Data Controller”. We use Cloudflare D1 (Cloudflare, Inc.) to store the data; the database is provisioned with EU jurisdiction, so the data is stored exclusively in the EU. We use Resend (Plus Five Five, Inc.) to send the confirmation and notification email; both process the data as processors on our behalf. Where data is transferred to the USA — in particular for sending the email — we base this on the EU Standard Contractual Clauses and additionally on the EU-US Data Privacy Framework. We delete unconfirmed signups no later than 30 days after signup; confirmed entries are deleted once the launch notification has been sent or you unsubscribe. The signup form is protected against automated abuse by Cloudflare Turnstile (Cloudflare, Inc.); this processes technical data such as your IP address. The legal basis is our legitimate interest in preventing spam and automated signups (Art. 6(1)(f) GDPR).
22. Additional recipients on the website
• Resend (Plus Five Five, Inc., USA) – sending the confirmation and notification emails for this website's waitlist. Data transfers on the basis of Standard Contractual Clauses and additionally on the basis of the EU-US Data Privacy Framework.
Last updated: August 2026
Traffic measurement
We count anonymously which pages are opened. You can object — this browser will then stop sending anything.
The objection is stored in this browser and applies here only. If you clear the site data, you have to set it again.
Measurement is on.