Datenschutz
GingR ist ein Trainingstagebuch der ly-webstudio UG (haftungsbeschränkt). Hier steht, welche Daten die App verarbeitet, wer sie sieht und wie du sie wieder löschst.
Auf dem Gerät
Alles, was du einträgst, speichert die App zuerst auf deinem Telefon. Sie funktioniert komplett offline.
Ohne Konto
Deine Trainings- und Körperdaten bleiben auf dem Gerät. Technisch geht trotzdem etwas raus: Absturz- und Sitzungsberichte an Sentry und die Abfrage nach App-Updates bei Expo (mit IP-Adresse, App-Version und einer zufälligen Gerätekennung).
Mit Konto
Mit der Anmeldung synchronisiert GingR über Supabase, Server in Irland (EU). In der App kann deine Daten nur dein eigenes Konto lesen. Bei jeder Anmeldung protokolliert Supabase zur Sicherheit die IP-Adresse und die technische Kennung der App.
Synchronisiert werden: Workouts mit Sätzen, Übungen und Equipment-Varianten, Routinen und ihre Ordner, Gyms und ihr Equipment, Körpereinträge mit Gewicht, Körpermaßen, Körperfett und Notiz, Ziele, Importe und dein Profil (etwa Anzeigename, Profilbild, Größe und Geschlecht, wenn du sie angibst).
Auf dem Gerät bleiben: Fotos zu Körpereinträgen (synchronisiert wird nur ihr Speicherort auf dem Telefon, nie das Bild) und Geräteeinstellungen. Rekorde und Trophäen rechnet jedes Gerät selbst; was Freunde davon sehen, steht unter „Freunde“.
Anmeldung: Mit E-Mail und Passwort, mit Apple oder mit Google. Von Apple bekommt GingR eine Kennung, eine E-Mail-Adresse (auf Wunsch eine anonyme Weiterleitungsadresse) und beim ersten Mal deinen Namen, den die App nur als Vorschlag für deinen Anzeigenamen nutzt. Von Google bekommt GingR eine Kennung, deine E-Mail-Adresse, deinen Namen und den Link zu deinem Google-Profilbild; Supabase speichert diese Angaben beim Konto.
Freunde
Teilen ist nach der ersten Anmeldung eingeschaltet, und die App legt dann eine Kopie für Freunde auf dem Server an. Lesen kann sie niemand, bis du eine Freundschaft eingehst: Befreundet seid ihr erst, wenn jemand einen Einladungscode von dir einlöst oder du seinen. Mit dem Verschicken oder Einlösen eines Codes willigst du ins Teilen ein. Ausschalten kannst du es jederzeit unter Mehr → Account; dann wird die Kopie auf dem Server gelöscht.
Deine Freunde sehen: deinen Anzeigenamen und dein Profilbild, pro Training eine Zusammenfassung (Datum, Dauer, Sätze, Tonnage, Schwerpunkt) und auf Antippen die einzelnen Sätze (Übung, Gewicht, Wiederholungen, Dauer, Seite), pro Übung deinen Bestwert (schwerstes Gewicht und geschätztes Maximalgewicht) und pro Woche Einheiten, Tonnage, Veränderung und relative Stärke. Benannte Rekorde (Übung, Zahl, Datum) haben einen eigenen Schalter, der ebenfalls eingeschaltet startet.
Schickst du einem Freund eine Routine, bekommt nur er ihren Namen und ihre Übungen mit Vorgaben. Bei einem gemeinsamen Wochenziel sehen alle Beteiligten, dass du mitmachst und was du zum Ziel beiträgst.
Nicht geteilt werden: Aufwärmsätze, Notizen, Gyms, Körperfotos und selbst angelegte Übungen (ihre Sätze zählen aber in Sätze und Tonnage der Zusammenfassung mit). Dein Körpergewicht wird nicht als Zahl geteilt. Weil relative Stärke und Bestwerte geteilt werden, können Freunde es aber ungefähr zurückrechnen.
Schaltest du Teilen aus, bleiben verschickte Routinen, gemeinsame Ziele und deine Kommentare und Likes bei anderen, bis du sie selbst entfernst.
Kommentare, Likes und Meldungen
Freunde können geteilte Trainings liken und kommentieren. Kommentare liegen auf dem Server und sind für alle lesbar, die die Karte sehen, also für alle Freunde der Person, deren Training es ist, auch wenn sie nicht mit dir befreundet sind. Deinen Namen sehen dabei nur deine eigenen Freunde. Löschst du einen Kommentar, ist er weg. Nach einer Blockierung seht ihr beide die Kommentare und Likes des anderen nicht mehr.
Kommentare, Anzeigenamen und Namen geteilter Routinen prüft beim Absenden ein automatischer Wortfilter.
Du kannst Kommentare, Freunde und Übungsvorschläge melden und Freunde blockieren. Eine Meldung speichert, wer gemeldet hat, was oder wen, warum und wann, bei einem Übungsvorschlag auch die angezeigte Übungsliste. Auch eine Blockierung kommt bei uns als Meldung an. Gemeldetes sehen wir uns an und entfernen es innerhalb von 24 Stunden, wenn es gegen die Nutzungsbedingungen verstößt.
Benachrichtigungen
Erlaubst du Push-Benachrichtigungen, speichert der Server eine Gerätekennung für dein Telefon, dazu Betriebssystem, App-Sprache und welche Arten von Benachrichtigungen du willst. Zugestellt wird über den Push-Dienst von Expo und dann über Apple bzw. Google. Expo sieht dabei den Text der Benachrichtigung, zum Beispiel „Anna hat gerade ein Workout beendet“. Der Server merkt sich, welche Benachrichtigung du wann ausgelöst hast, damit keine doppelt kommt und es nicht zu viele werden.
Apple Health
Die Verbindung ist standardmäßig aus. Erst wenn du sie in der App einschaltest, fragt iOS um Erlaubnis.
GingR schreibt nach Health: abgeschlossene Workouts (Beginn, Ende, Dauer), eine geschätzte verbrauchte Energie, wenn dein Körpergewicht bekannt ist, und Körpergewichts-Einträge aus GingR.
GingR liest aus Health: nur dein Körpergewicht. GingR speichert es als Körpereintrag. Mit Konto wird es wie jeder Körpereintrag synchronisiert, und solange Teilen an ist, geht es in die relative Stärke ein, die deine Freunde sehen.
Gesundheitsdaten nutzen wir nie für Werbung, Marketing oder Data-Mining, sie landen nicht in Absturzberichten, und darüber hinaus geben wir sie nicht weiter.
Löschst du einen Eintrag in GingR, bleibt die Kopie in Health. Die entfernst du in der Health-App.
Absturzberichte
Veröffentlichte Versionen melden an Sentry (Server in Frankfurt): Abstürze und Fehler mit der Fehlermeldung und dem Weg dorthin (Bildschirme, Sync-Schritte, Adressen von Serveranfragen) sowie Sitzungen (Beginn, Ende, abgestürzt ja oder nein). Dazu App-Version, Betriebssystem, Gerätedaten wie Modell und Sprache, eine zufällige Installationskennung und die IP-Adresse der Verbindung. Keine Trainingseinträge und kein Name. Adressen von Serveranfragen können deine zufällige Konto-ID enthalten. Sentry löscht die Berichte spätestens nach 90 Tagen.
Übungsvorschläge
Nur auf Knopfdruck und erst nach einmaliger Zustimmung schickt GingR über unseren Server bei Supabase eine Anfrage an Googles KI-Dienst Gemini.
Geschickt werden: die gewählten Muskelgruppen, passende Übungen aus dem Katalog, was in der Routine oder im Training schon drin ist, pro Katalogübung ein Ja oder Nein, ob du sie regelmäßig trainierst, und mitten im Training die Zahl der Sätze pro Muskelgruppe in diesem Training.
Nicht geschickt werden: Gewichte, Rekorde, Körperdaten, dein Name, dein Konto, Notizen und selbst angelegte Übungen.
Google speichert Anfrage und Antwort bis zu 55 Tage, nur um Missbrauch zu erkennen, und nutzt sie nicht zum Training seiner Modelle. Unser Server speichert pro Vorschlag Zeitpunkt und Umfang, um das Kontingent zu zählen, bis du dein Konto löschst. Abschalten kannst du die Vorschläge in den Einstellungen.
Wer die Daten erhält
- Supabase: Konto, Synchronisierung, Freunde, Meldungen, Push-Kennungen und der Zähler für Übungsvorschläge. Server in Irland.
- Sentry: Absturz- und Sitzungsberichte. Server in Frankfurt.
- Expo: App-Updates und Zustellung von Benachrichtigungen.
- Apple und Google: Anmeldung, wenn du sie nutzt, und Zustellung von Benachrichtigungen.
- Google: Übungsvorschläge, nur auf Knopfdruck.
- GitHub: Hosting dieser Webseite (Server-Protokolle mit IP-Adresse).
- Polizei und Staatsanwaltschaft: nur wenn wir strafbare Inhalte melden, dann der Inhalt und die Kontodaten der Person dahinter.
Es gibt keine Werbenetzwerke, keine Analyse-SDKs und keinen Verkauf von Daten.
Übermittlung in Drittländer
Supabase, Sentry, Expo, Apple, Google und GitHub sind Unternehmen mit Sitz in den USA. Auch wenn die Daten in der EU liegen, ist ein Zugriff aus den USA möglich. Grundlage ist das EU-US Data Privacy Framework (Apple, Google, Sentry, GitHub) bzw. die EU-Standardvertragsklauseln (Supabase, Expo), Art. 45 und 46 DSGVO.
Rechtsgrundlagen
- Vertrag (Art. 6 Abs. 1 lit. b DSGVO): Konto und Synchronisierung. Für Trainings- und Körperdaten, die Gesundheitsdaten sind, zusätzlich deine Einwilligung (Art. 9 Abs. 2 lit. a DSGVO), die du beim Anlegen des Kontos mit deiner Zustimmung zu dieser Erklärung gibst.
- Einwilligung (Art. 6 Abs. 1 lit. a und Art. 9 Abs. 2 lit. a DSGVO): Teilen mit Freunden (mit dem Verschicken oder Einlösen eines Einladungscodes), Apple Health, Übungsvorschläge und Push-Benachrichtigungen (jeweils beim Einschalten bzw. Erlauben). Du kannst sie jederzeit widerrufen, indem du die Funktion ausschaltest oder dein Konto löschst. Das wirkt für die Zukunft.
- Berechtigtes Interesse (Art. 6 Abs. 1 lit. f DSGVO): Absturz- und Sitzungsberichte, die Abfrage nach App-Updates, das Hosting dieser Webseite, der Wortfilter und Meldungen aus der App, um Fehler zu finden und den Dienst sicher zu halten; außerdem eine Auswertung, welche Funktionen genutzt werden, nur als Zählwerte über alle Konten.
- Rechtliche Pflicht (Art. 6 Abs. 1 lit. c DSGVO mit Art. 16 und 18 DSA): Meldungen rechtswidriger Inhalte per E-Mail und Hinweise an Behörden.
Aufbewahrung und Löschung
Kontodaten und das Protokoll gesendeter Benachrichtigungen bleiben, solange das Konto besteht. Sentry löscht Berichte spätestens nach 90 Tagen, Google Anfragen an die KI spätestens nach 55 Tagen. Meldungen bewahren wir auf, solange wir sie für die Moderation brauchen, höchstens zwei Jahre; nach einer Kontolöschung bleiben sie bis dahin ohne Bezug zu deiner Person.
- Alles exportieren: Mehr → Import & Export (CSV und JSON)
- Konto und Serverdaten löschen: Mehr → Account → Konto löschen, siehe Konto löschen
- Gerät leeren: Einstellungen → Alle Daten auf diesem Gerät löschen
Alter
Ein Konto darfst du ab 16 anlegen. Bist du jünger, brauchst du die Zustimmung deiner Eltern (Art. 8 DSGVO).
Deine Rechte
Du hast das Recht auf Auskunft, Berichtigung, Löschung, Einschränkung und Datenübertragbarkeit (Art. 15 bis 18 und 20 DSGVO) und kannst jede Einwilligung widerrufen.
Widerspruch (Art. 21 DSGVO): Der Verarbeitung aus berechtigtem Interesse kannst du jederzeit widersprechen; schreib uns. Absturzberichte sind keinem Konto zugeordnet. Einzeln abstellen lassen sie sich deshalb erst mit einem Schalter in der App, den wir gerade einbauen.
Beschweren kannst du dich bei der Berliner Beauftragten für Datenschutz und Informationsfreiheit oder bei der Aufsichtsbehörde an deinem Wohnort.
Verantwortlich
ly-webstudio UG (haftungsbeschränkt), vertreten durch Leon Brodersen, Buchfinkweg 50, 12351 Berlin. E-Mail: brodersen2006@gmail.com. Weitere Angaben im Impressum. Einen Datenschutzbeauftragten müssen wir nicht bestellen (Art. 37 DSGVO, § 38 BDSG).
Änderungen
Ändert sich etwas Wesentliches, ändern wir das Datum oben.
Privacy
GingR is a training log made by ly-webstudio UG (haftungsbeschränkt). This page explains what data the app handles, who can see it and how to delete it.
On the device
Everything you log is stored on your phone first. The app works completely offline.
Without an account
Your training and body data stay on the device. Some things still go out: crash and session reports to Sentry and the check for app updates with Expo (with IP address, app version and a random device ID).
With an account
Signing in turns on sync through Supabase, servers in Ireland (EU). Inside the app only your own account can read your data. For security, Supabase logs the IP address and the app's technical identifier with each sign-in.
Synced: workouts and their sets, exercises and equipment variants, routines and their folders, gyms and their equipment, body entries with weight, body measurements, body fat and note, goals, imports and your profile (such as display name, profile picture, height and sex if you enter them).
Stays on the device: photos attached to body entries (only their location on the phone is synced, never the image) and device settings. Records and trophies are computed by every device itself; what friends see of them is under "Friends".
Sign-in: with email and password, with Apple or with Google. From Apple, GingR receives an identifier, an email address (a private relay address if you choose) and, the first time only, your name, which the app only uses to suggest your display name. From Google, GingR receives an identifier, your email address, your name and a link to your Google profile picture; Supabase stores these with your account.
Friends
Sharing is on after your first sign-in, and the app then puts a copy for friends on the server. Nobody can read it until you become friends with someone: you are friends only once someone redeems an invite code from you, or you redeem theirs. By sending or redeeming a code you agree to sharing. You can switch it off at any time under More → Account, which deletes the copy on the server.
Your friends see: your display name and profile picture, one summary per workout (date, duration, sets, tonnage, focus) and, on tap, the individual sets (exercise, weight, reps, duration, side), per exercise your best (heaviest weight and estimated one-rep max), and per week your sessions, tonnage, change and relative strength. Named records (exercise, number, date) have a switch of their own, which also starts switched on.
If you send a routine to a friend, only that friend receives its name and its exercises with targets. In a joint weekly goal, everyone taking part sees that you are in it and what you contribute.
Not shared: warm-up sets, notes, gyms, body photos and exercises you created yourself (their sets still count towards the sets and tonnage in the summary). Your body weight is not shared as a number. Because relative strength and your bests are shared, friends can roughly work it out.
If you switch sharing off, routines you sent, joint goals and your comments and likes on other people's workouts stay until you remove them.
Comments, likes and reports
Friends can like and comment on shared workouts. Comments live on the server and can be read by everyone who can see the card, meaning all friends of the person whose workout it is, even if they are not your friends. Only your own friends see your name. Delete a comment and it is gone. After a block, neither of you sees the other's comments and likes.
Comments, display names and the names of shared routines pass an automatic word filter when you send them.
You can report comments, friends and exercise suggestions, and block friends. A report stores who reported, what or whom, why and when, and for a suggestion also the list that was shown. A block also reaches us as a report. We look at reports and remove anything that breaks the terms of use within 24 hours.
Notifications
If you allow push notifications, the server stores a device token for your phone, along with the operating system, app language and which kinds of notifications you want. Delivery runs through Expo's push service and then through Apple or Google. Expo sees the text of the notification, for example "Anna just finished a workout". The server records which notification you triggered and when, so none arrives twice and there are never too many.
Apple Health
The connection is off by default. iOS asks for permission only once you switch it on in the app.
GingR writes to Health: finished workouts (start, end, duration), an estimate of energy burned when your body weight is known, and body weight entries made in GingR.
GingR reads from Health: your body weight only. GingR saves it as a body entry. With an account it is synced like any body entry, and while sharing is on it goes into the relative strength your friends see.
Health data is never used for advertising, marketing or data mining, never appears in crash reports, and is not passed on in any other way.
Deleting an entry in GingR leaves the copy in Health. Remove it in the Health app.
Crash reports
Released versions report to Sentry (servers in Frankfurt): crashes and errors with the error message and what led to it (screens, sync steps, server request addresses), and sessions (start, end, crashed or not). Also app version, operating system, device details such as model and language, a random installation ID and the IP address of the connection. No training entries and no name. Server request addresses can contain your random account ID. Sentry deletes the reports after 90 days at most.
Exercise suggestions
Only when you press the button, and only after you have agreed once, GingR sends a request through our server at Supabase to Google's AI service Gemini.
Sent: the muscle groups you picked, matching exercises from the catalogue, what the routine or workout already contains, a yes or no per catalogue exercise for whether you train it regularly, and during a workout the number of sets per muscle group in that workout.
Not sent: weights, records, body data, your name, your account, notes and exercises you created yourself.
Google keeps request and response for up to 55 days, only to detect abuse, and does not use them to train its models. Our server stores the time and size of each suggestion to count the allowance, until you delete your account. You can switch suggestions off in settings.
Who receives data
- Supabase: account, sync, friends, reports, push tokens and the suggestion counter. Servers in Ireland.
- Sentry: crash and session reports. Servers in Frankfurt.
- Expo: app updates and delivery of notifications.
- Apple and Google: sign-in if you use them, and delivery of notifications.
- Google: exercise suggestions, only when you press the button.
- GitHub: hosting of this website (server logs with IP address).
- Police and prosecutors: only if we report criminal content, then the content and the account data of the person behind it.
There are no ad networks, no analytics SDKs and no sale of data.
Transfers outside the EU
Supabase, Sentry, Expo, Apple, Google and GitHub are companies based in the USA. Even where data is stored in the EU, access from the USA is possible. The basis is the EU-US Data Privacy Framework (Apple, Google, Sentry, GitHub) or the EU standard contractual clauses (Supabase, Expo), Art. 45 and 46 GDPR.
Legal bases
- Contract (Art. 6(1)(b) GDPR): account and sync. For training and body data, which are health data, also your consent (Art. 9(2)(a) GDPR), which you give when you create the account by agreeing to this policy.
- Consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR): sharing with friends (by sending or redeeming an invite code), Apple Health, exercise suggestions and push notifications (each when you switch it on or allow it). You can withdraw it at any time by switching the feature off or deleting your account. This applies going forward.
- Legitimate interest (Art. 6(1)(f) GDPR): crash and session reports, the check for app updates, hosting this website, the word filter and in-app reports, to find bugs and keep the service safe; also an analysis of which features are used, as counts across all accounts only.
- Legal obligation (Art. 6(1)(c) GDPR with Art. 16 and 18 DSA): reports of illegal content by email and notices to authorities.
Retention and deletion
Account data and the log of notifications sent are kept as long as the account exists. Sentry deletes reports after 90 days at most, Google deletes AI requests after 55 days at most. We keep reports as long as we need them for moderation, two years at most; after an account is deleted they are kept until then with nothing that links them to you.
- Export everything: More → Import & export (CSV and JSON)
- Delete account and server data: More → Account → Delete account, see Delete your account
- Clear the device: Settings → Delete all data on this device
Age
You may create an account from 16. If you are younger, you need a parent's consent (Art. 8 GDPR).
Your rights
You have the right of access, rectification, erasure, restriction and data portability (Art. 15 to 18 and 20 GDPR), and you can withdraw any consent.
Objection (Art. 21 GDPR): You can object at any time to processing based on legitimate interest; write to us. Crash reports are not linked to an account, so they can only be switched off for you individually with a switch in the app, which we are adding now.
You can complain to the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit) or to the authority where you live.
Controller
ly-webstudio UG (haftungsbeschränkt), represented by Leon Brodersen, Buchfinkweg 50, 12351 Berlin, Germany. Email: brodersen2006@gmail.com. More in the legal notice. We are not required to appoint a data protection officer (Art. 37 GDPR, § 38 BDSG).
Changes
If something material changes, we update the date at the top.