Privacy Policy
- Version
- privacy-2026-06-11-v1
- Published
- 2026-06-11
- Effective
- 2026-06-11
Controller And Contacts
The controller details and privacy contact are listed below.
- Responsible operator
- Raffael Kaas
- Postal address
- Irisstr. 8, 88097, Eriskirch, Germany
- Legal contact email
- mail@rkaas.de
- Phone number
- +4915779722125
- VAT ID or tax status
- No VAT ID; private person; no business registered
- Trade or business registration
- Private person; no trade registration; no commercial register entry
- Support or privacy contact
- mail@rkaas.de
Data Categories
- User accounts: email address, password hash, display name if provided, registration date, email verification status, account access status, and active sign-in session metadata.
- Training data: workout sessions, dates, exercises, set weights, repetitions, warm-up markers, training plans, custom exercises, and optional session or set notes.
- Body metrics: current body weight, height, optional gender selection, body-weight update timestamps and source, one-time post-session body-weight prompt state, plus historical body-weight entries attached to saved sessions.
- Email data: confirmation and operational emails needed for registration, verification, account access, and operator notifications.
- Payment data: Liftlytics does not process payment data in the current product phase.
- Server logs and security logs: technical request metadata, authentication events, rate-limit events, and security-relevant account actions needed to operate and protect the service.
Hosting And Processors
Liftlytics is intended to run on IONOS-hosted infrastructure and uses Brevo SMTP for transactional email delivery.
- Hosting provider
- IONOS
- Hosting server location
- Europe (IONOS, VPS)
- IONOS AVV status
- IONOS AVV accepted on 2026-06-05
- Email delivery provider
- Missing required legal value
- Email delivery data flow
- Missing required legal value
Cookies And Local Storage
The current release uses only technically necessary account/session cookies and browser storage needed for product behavior, such as local session drafts, rest timer state, dismissed onboarding state, and saved cookie choices. Liftlytics does not use tracking, advertising, or analytics cookies in the current release. If non-essential cookies or similar technologies are added later, they will be activated only after a separate consent and notice flow is available.
Users can review the current storage inventory and optional-storage controls at Cookie settings.
Payment Processing
Liftlytics does not process payment data in the current product phase. Any future monetization path must be documented before payment processing is activated, including the provider, data flow, price, billing interval, and cancellation path where applicable.
- Payment processing status
- No Payment Processing
- Payment provider status
- No Payment Processing
- Payment provider data flow
- No Payment Processing
Purposes And Legal Bases
- Account registration, email verification, sign-in, and account administration are processed to provide the requested Liftlytics account and product access.
- Training sessions, plans, exercise history, analytics, Coach recommendations, and body metrics are processed to provide workout logging, progress tracking, plan management, and related product features. Training and body metrics processing also uses the separate consent recorded during registration or consent remediation.
- Transactional emails are processed to verify accounts, support secure access, deliver account-related messages, and notify the operator where configured.
- Server logs, security logs, rate limits, troubleshooting data, and backups are processed to operate, monitor, secure, and maintain the service.
- Necessary cookies and browser storage are used to provide requested product functionality, preserve local workout continuity, maintain account sessions, and remember storage choices.
Where GDPR applies, Liftlytics relies on contract performance for account and product functionality, consent for the separate training and body metrics processing choice, legitimate interests for service security and reliability, and legal obligations where a law requires retention or disclosure. Consent records store the current Privacy Policy version, Terms of Service version, separate training/body metrics consent version, user ID, consent type, and server timestamp.
Deletion Periods
Self-service account deletion immediately removes active account and product data from the application database. Operator-supported deletion requests have a maximum active-data deletion window of 30 days, and backups expire or are overwritten within a maximum of 90 days. Minimized consent and account-rights security evidence may be retained for up to 180 days after account deletion unless a longer legal requirement applies.
- Deletion period status
- Active data deleted immediately; backups expire within 90 days
User Rights
Signed-in users can open Account → Body metrics to correct current body metrics and Account → Data & privacy to export account and training data as JSON or session/set CSV, correct training records where they were entered, and review account deletion. Users can also request access, correction, deletion, restriction of processing, data portability, objection where applicable, and complaint review by a supervisory authority through the privacy/support contact listed above. Operator-supported requests are handled within one month unless GDPR permits an extension because of request complexity or volume.
Data Not Stored
Liftlytics must not store raw credit-card numbers, bank account details, health diagnoses, or medical records. Fitness and body metrics data may still be sensitive and must be handled with appropriate care.