Deutsch · English

Datenschutz

GingR · Stand: 25. September 2026

GingR ist ein Trainingstagebuch der ly-webstudio UG (haftungsbeschränkt). Hier steht, welche Daten die App verarbeitet, wer sie sieht und wie du sie wieder löschst.

Auf dem Gerät

Alles, was du einträgst, speichert die App zuerst auf deinem Telefon. Sie funktioniert komplett offline.

Ohne Konto

Deine Trainings- und Körperdaten bleiben auf dem Gerät. Technisch geht trotzdem etwas raus: Absturz- und Sitzungsberichte an Sentry und die Abfrage nach App-Updates bei Expo (mit IP-Adresse, App-Version und einer zufälligen Gerätekennung).

Mit Konto

Mit der Anmeldung synchronisiert GingR über Supabase, Server in Irland (EU). In der App kann deine Daten nur dein eigenes Konto lesen. Bei jeder Anmeldung protokolliert Supabase zur Sicherheit die IP-Adresse und die technische Kennung der App.

Synchronisiert werden: Workouts mit Sätzen, Übungen und Equipment-Varianten, Routinen und ihre Ordner, Gyms und ihr Equipment, Körpereinträge mit Gewicht, Körpermaßen, Körperfett und Notiz, Ziele, Importe und dein Profil (etwa Anzeigename, Profilbild, Größe und Geschlecht, wenn du sie angibst).

Auf dem Gerät bleiben: Fotos zu Körpereinträgen (synchronisiert wird nur ihr Speicherort auf dem Telefon, nie das Bild) und Geräteeinstellungen. Rekorde und Trophäen rechnet jedes Gerät selbst; was Freunde davon sehen, steht unter „Freunde“.

Anmeldung: Mit E-Mail und Passwort, mit Apple oder mit Google. Von Apple bekommt GingR eine Kennung, eine E-Mail-Adresse (auf Wunsch eine anonyme Weiterleitungsadresse) und beim ersten Mal deinen Namen, den die App nur als Vorschlag für deinen Anzeigenamen nutzt. Von Google bekommt GingR eine Kennung, deine E-Mail-Adresse, deinen Namen und den Link zu deinem Google-Profilbild; Supabase speichert diese Angaben beim Konto.

Freunde

Teilen ist nach der ersten Anmeldung eingeschaltet, und die App legt dann eine Kopie für Freunde auf dem Server an. Lesen kann sie niemand, bis du eine Freundschaft eingehst: Befreundet seid ihr erst, wenn jemand einen Einladungscode von dir einlöst oder du seinen. Mit dem Verschicken oder Einlösen eines Codes willigst du ins Teilen ein. Ausschalten kannst du es jederzeit unter Mehr → Account; dann wird die Kopie auf dem Server gelöscht.

Deine Freunde sehen: deinen Anzeigenamen und dein Profilbild, pro Training eine Zusammenfassung (Datum, Dauer, Sätze, Tonnage, Schwerpunkt) und auf Antippen die einzelnen Sätze (Übung, Gewicht, Wiederholungen, Dauer, Seite), pro Übung deinen Bestwert (schwerstes Gewicht und geschätztes Maximalgewicht) und pro Woche Einheiten, Tonnage, Veränderung und relative Stärke. Benannte Rekorde (Übung, Zahl, Datum) haben einen eigenen Schalter, der ebenfalls eingeschaltet startet.

Schickst du einem Freund eine Routine, bekommt nur er ihren Namen und ihre Übungen mit Vorgaben. Bei einem gemeinsamen Wochenziel sehen alle Beteiligten, dass du mitmachst und was du zum Ziel beiträgst.

Nicht geteilt werden: Aufwärmsätze, Notizen, Gyms, Körperfotos und selbst angelegte Übungen (ihre Sätze zählen aber in Sätze und Tonnage der Zusammenfassung mit). Dein Körpergewicht wird nicht als Zahl geteilt. Weil relative Stärke und Bestwerte geteilt werden, können Freunde es aber ungefähr zurückrechnen.

Schaltest du Teilen aus, bleiben verschickte Routinen, gemeinsame Ziele und deine Kommentare und Likes bei anderen, bis du sie selbst entfernst.

Kommentare, Likes und Meldungen

Freunde können geteilte Trainings liken und kommentieren. Kommentare liegen auf dem Server und sind für alle lesbar, die die Karte sehen, also für alle Freunde der Person, deren Training es ist, auch wenn sie nicht mit dir befreundet sind. Deinen Namen sehen dabei nur deine eigenen Freunde. Löschst du einen Kommentar, ist er weg. Nach einer Blockierung seht ihr beide die Kommentare und Likes des anderen nicht mehr.

Kommentare, Anzeigenamen und Namen geteilter Routinen prüft beim Absenden ein automatischer Wortfilter.

Du kannst Kommentare, Freunde und Übungsvorschläge melden und Freunde blockieren. Eine Meldung speichert, wer gemeldet hat, was oder wen, warum und wann, bei einem Übungsvorschlag auch die angezeigte Übungsliste. Auch eine Blockierung kommt bei uns als Meldung an. Gemeldetes sehen wir uns an und entfernen es innerhalb von 24 Stunden, wenn es gegen die Nutzungsbedingungen verstößt.

Benachrichtigungen

Erlaubst du Push-Benachrichtigungen, speichert der Server eine Gerätekennung für dein Telefon, dazu Betriebssystem, App-Sprache und welche Arten von Benachrichtigungen du willst. Zugestellt wird über den Push-Dienst von Expo und dann über Apple bzw. Google. Expo sieht dabei den Text der Benachrichtigung, zum Beispiel „Anna hat gerade ein Workout beendet“. Der Server merkt sich, welche Benachrichtigung du wann ausgelöst hast, damit keine doppelt kommt und es nicht zu viele werden.

Apple Health

Die Verbindung ist standardmäßig aus. Erst wenn du sie in der App einschaltest, fragt iOS um Erlaubnis.

GingR schreibt nach Health: abgeschlossene Workouts (Beginn, Ende, Dauer), eine geschätzte verbrauchte Energie, wenn dein Körpergewicht bekannt ist, und Körpergewichts-Einträge aus GingR.

GingR liest aus Health: nur dein Körpergewicht. GingR speichert es als Körpereintrag. Mit Konto wird es wie jeder Körpereintrag synchronisiert, und solange Teilen an ist, geht es in die relative Stärke ein, die deine Freunde sehen.

Gesundheitsdaten nutzen wir nie für Werbung, Marketing oder Data-Mining, sie landen nicht in Absturzberichten, und darüber hinaus geben wir sie nicht weiter.

Löschst du einen Eintrag in GingR, bleibt die Kopie in Health. Die entfernst du in der Health-App.

Absturzberichte

Veröffentlichte Versionen melden an Sentry (Server in Frankfurt): Abstürze und Fehler mit der Fehlermeldung und dem Weg dorthin (Bildschirme, Sync-Schritte, Adressen von Serveranfragen) sowie Sitzungen (Beginn, Ende, abgestürzt ja oder nein). Dazu App-Version, Betriebssystem, Gerätedaten wie Modell und Sprache, eine zufällige Installationskennung und die IP-Adresse der Verbindung. Keine Trainingseinträge und kein Name. Adressen von Serveranfragen können deine zufällige Konto-ID enthalten. Sentry löscht die Berichte spätestens nach 90 Tagen.

Übungsvorschläge

Nur auf Knopfdruck und erst nach einmaliger Zustimmung schickt GingR über unseren Server bei Supabase eine Anfrage an Googles KI-Dienst Gemini.

Geschickt werden: die gewählten Muskelgruppen, passende Übungen aus dem Katalog, was in der Routine oder im Training schon drin ist, pro Katalogübung ein Ja oder Nein, ob du sie regelmäßig trainierst, und mitten im Training die Zahl der Sätze pro Muskelgruppe in diesem Training.

Nicht geschickt werden: Gewichte, Rekorde, Körperdaten, dein Name, dein Konto, Notizen und selbst angelegte Übungen.

Google speichert Anfrage und Antwort bis zu 55 Tage, nur um Missbrauch zu erkennen, und nutzt sie nicht zum Training seiner Modelle. Unser Server speichert pro Vorschlag Zeitpunkt und Umfang, um das Kontingent zu zählen, bis du dein Konto löschst. Abschalten kannst du die Vorschläge in den Einstellungen.

Wer die Daten erhält

Es gibt keine Werbenetzwerke, keine Analyse-SDKs und keinen Verkauf von Daten.

Übermittlung in Drittländer

Supabase, Sentry, Expo, Apple, Google und GitHub sind Unternehmen mit Sitz in den USA. Auch wenn die Daten in der EU liegen, ist ein Zugriff aus den USA möglich. Grundlage ist das EU-US Data Privacy Framework (Apple, Google, Sentry, GitHub) bzw. die EU-Standardvertragsklauseln (Supabase, Expo), Art. 45 und 46 DSGVO.

Rechtsgrundlagen

Aufbewahrung und Löschung

Kontodaten und das Protokoll gesendeter Benachrichtigungen bleiben, solange das Konto besteht. Sentry löscht Berichte spätestens nach 90 Tagen, Google Anfragen an die KI spätestens nach 55 Tagen. Meldungen bewahren wir auf, solange wir sie für die Moderation brauchen, höchstens zwei Jahre; nach einer Kontolöschung bleiben sie bis dahin ohne Bezug zu deiner Person.

Alter

Ein Konto darfst du ab 16 anlegen. Bist du jünger, brauchst du die Zustimmung deiner Eltern (Art. 8 DSGVO).

Deine Rechte

Du hast das Recht auf Auskunft, Berichtigung, Löschung, Einschränkung und Datenübertragbarkeit (Art. 15 bis 18 und 20 DSGVO) und kannst jede Einwilligung widerrufen.

Widerspruch (Art. 21 DSGVO): Der Verarbeitung aus berechtigtem Interesse kannst du jederzeit widersprechen; schreib uns. Absturzberichte sind keinem Konto zugeordnet. Einzeln abstellen lassen sie sich deshalb erst mit einem Schalter in der App, den wir gerade einbauen.

Beschweren kannst du dich bei der Berliner Beauftragten für Datenschutz und Informationsfreiheit oder bei der Aufsichtsbehörde an deinem Wohnort.

Verantwortlich

ly-webstudio UG (haftungsbeschränkt), vertreten durch Leon Brodersen, Buchfinkweg 50, 12351 Berlin. E-Mail: brodersen2006@gmail.com. Weitere Angaben im Impressum. Einen Datenschutzbeauftragten müssen wir nicht bestellen (Art. 37 DSGVO, § 38 BDSG).

Änderungen

Ändert sich etwas Wesentliches, ändern wir das Datum oben.

Privacy

GingR · Last updated: 25 September 2026

GingR is a training log made by ly-webstudio UG (haftungsbeschränkt). This page explains what data the app handles, who can see it and how to delete it.

On the device

Everything you log is stored on your phone first. The app works completely offline.

Without an account

Your training and body data stay on the device. Some things still go out: crash and session reports to Sentry and the check for app updates with Expo (with IP address, app version and a random device ID).

With an account

Signing in turns on sync through Supabase, servers in Ireland (EU). Inside the app only your own account can read your data. For security, Supabase logs the IP address and the app's technical identifier with each sign-in.

Synced: workouts and their sets, exercises and equipment variants, routines and their folders, gyms and their equipment, body entries with weight, body measurements, body fat and note, goals, imports and your profile (such as display name, profile picture, height and sex if you enter them).

Stays on the device: photos attached to body entries (only their location on the phone is synced, never the image) and device settings. Records and trophies are computed by every device itself; what friends see of them is under "Friends".

Sign-in: with email and password, with Apple or with Google. From Apple, GingR receives an identifier, an email address (a private relay address if you choose) and, the first time only, your name, which the app only uses to suggest your display name. From Google, GingR receives an identifier, your email address, your name and a link to your Google profile picture; Supabase stores these with your account.

Friends

Sharing is on after your first sign-in, and the app then puts a copy for friends on the server. Nobody can read it until you become friends with someone: you are friends only once someone redeems an invite code from you, or you redeem theirs. By sending or redeeming a code you agree to sharing. You can switch it off at any time under More → Account, which deletes the copy on the server.

Your friends see: your display name and profile picture, one summary per workout (date, duration, sets, tonnage, focus) and, on tap, the individual sets (exercise, weight, reps, duration, side), per exercise your best (heaviest weight and estimated one-rep max), and per week your sessions, tonnage, change and relative strength. Named records (exercise, number, date) have a switch of their own, which also starts switched on.

If you send a routine to a friend, only that friend receives its name and its exercises with targets. In a joint weekly goal, everyone taking part sees that you are in it and what you contribute.

Not shared: warm-up sets, notes, gyms, body photos and exercises you created yourself (their sets still count towards the sets and tonnage in the summary). Your body weight is not shared as a number. Because relative strength and your bests are shared, friends can roughly work it out.

If you switch sharing off, routines you sent, joint goals and your comments and likes on other people's workouts stay until you remove them.

Comments, likes and reports

Friends can like and comment on shared workouts. Comments live on the server and can be read by everyone who can see the card, meaning all friends of the person whose workout it is, even if they are not your friends. Only your own friends see your name. Delete a comment and it is gone. After a block, neither of you sees the other's comments and likes.

Comments, display names and the names of shared routines pass an automatic word filter when you send them.

You can report comments, friends and exercise suggestions, and block friends. A report stores who reported, what or whom, why and when, and for a suggestion also the list that was shown. A block also reaches us as a report. We look at reports and remove anything that breaks the terms of use within 24 hours.

Notifications

If you allow push notifications, the server stores a device token for your phone, along with the operating system, app language and which kinds of notifications you want. Delivery runs through Expo's push service and then through Apple or Google. Expo sees the text of the notification, for example "Anna just finished a workout". The server records which notification you triggered and when, so none arrives twice and there are never too many.

Apple Health

The connection is off by default. iOS asks for permission only once you switch it on in the app.

GingR writes to Health: finished workouts (start, end, duration), an estimate of energy burned when your body weight is known, and body weight entries made in GingR.

GingR reads from Health: your body weight only. GingR saves it as a body entry. With an account it is synced like any body entry, and while sharing is on it goes into the relative strength your friends see.

Health data is never used for advertising, marketing or data mining, never appears in crash reports, and is not passed on in any other way.

Deleting an entry in GingR leaves the copy in Health. Remove it in the Health app.

Crash reports

Released versions report to Sentry (servers in Frankfurt): crashes and errors with the error message and what led to it (screens, sync steps, server request addresses), and sessions (start, end, crashed or not). Also app version, operating system, device details such as model and language, a random installation ID and the IP address of the connection. No training entries and no name. Server request addresses can contain your random account ID. Sentry deletes the reports after 90 days at most.

Exercise suggestions

Only when you press the button, and only after you have agreed once, GingR sends a request through our server at Supabase to Google's AI service Gemini.

Sent: the muscle groups you picked, matching exercises from the catalogue, what the routine or workout already contains, a yes or no per catalogue exercise for whether you train it regularly, and during a workout the number of sets per muscle group in that workout.

Not sent: weights, records, body data, your name, your account, notes and exercises you created yourself.

Google keeps request and response for up to 55 days, only to detect abuse, and does not use them to train its models. Our server stores the time and size of each suggestion to count the allowance, until you delete your account. You can switch suggestions off in settings.

Who receives data

There are no ad networks, no analytics SDKs and no sale of data.

Transfers outside the EU

Supabase, Sentry, Expo, Apple, Google and GitHub are companies based in the USA. Even where data is stored in the EU, access from the USA is possible. The basis is the EU-US Data Privacy Framework (Apple, Google, Sentry, GitHub) or the EU standard contractual clauses (Supabase, Expo), Art. 45 and 46 GDPR.

Legal bases

Retention and deletion

Account data and the log of notifications sent are kept as long as the account exists. Sentry deletes reports after 90 days at most, Google deletes AI requests after 55 days at most. We keep reports as long as we need them for moderation, two years at most; after an account is deleted they are kept until then with nothing that links them to you.

Age

You may create an account from 16. If you are younger, you need a parent's consent (Art. 8 GDPR).

Your rights

You have the right of access, rectification, erasure, restriction and data portability (Art. 15 to 18 and 20 GDPR), and you can withdraw any consent.

Objection (Art. 21 GDPR): You can object at any time to processing based on legitimate interest; write to us. Crash reports are not linked to an account, so they can only be switched off for you individually with a switch in the app, which we are adding now.

You can complain to the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit) or to the authority where you live.

Controller

ly-webstudio UG (haftungsbeschränkt), represented by Leon Brodersen, Buchfinkweg 50, 12351 Berlin, Germany. Email: brodersen2006@gmail.com. More in the legal notice. We are not required to appoint a data protection officer (Art. 37 GDPR, § 38 BDSG).

Changes

If something material changes, we update the date at the top.