Privacy Policy
General Notice and Mandatory Information
The responsible entity for data processing in this app and on this website is: physiopass.eu Friederike Dethleff Am Schellbruch 34 23568 Lübeck The responsible entity decides alone or jointly with others on the purposes and means of processing personal data (e.g., names, contact details, etc.).
Revocation of Your Consent to Data Processing
Certain data processing operations are only possible with your express consent. You may revoke your previously granted consent at any time. An informal notification by email is sufficient for the revocation. The lawfulness of the data processing carried out until the revocation remains unaffected by the revocation. Right to lodge a complaint with the competent supervisory authority: As a data subject, you have the right to lodge a complaint with the competent supervisory authority in the event of a data protection violation. The competent supervisory authority regarding data protection matters is the State Data Protection Officer of the federal state in which our company is based. The following link provides a list of data protection officers and their contact details: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html.
Your Rights (Art. 15–22 GDPR)
Within the framework of applicable legal provisions, you have the following rights regarding your personal data: Right of access (Art. 15 GDPR): You may request free information about your stored personal data, their origin, recipients, and the purpose of processing at any time. Right to rectification (Art. 16 GDPR): You may request the correction of inaccurate or the completion of your personal data stored with us. Right to erasure (Art. 17 GDPR): You may request the deletion of your stored personal data, unless processing is required for exercising the right of freedom of expression, for compliance with a legal obligation, or for reasons of public interest. Right to restriction of processing (Art. 18 GDPR): You may request the restriction of processing of your personal data if you contest the accuracy of the data, the processing is unlawful, we no longer need the data, or you have objected to the processing. Right to data portability (Art. 20 GDPR): You have the right to receive data that we process automatically on the basis of your consent or in fulfilment of a contract, in a machine-readable format, for yourself or for a third party. Right to object (Art. 21 GDPR): If your personal data is processed on the basis of legitimate interests pursuant to Art. 6(1)(f) GDPR, you have the right to object to the processing pursuant to Art. 21 GDPR, providing grounds relating to your particular situation. Automated decision-making (Art. 22 GDPR): No automated decision-making, including profiling, takes place that produces legal effects concerning you or similarly significantly affects you. For this purpose and for further questions on the subject of personal data, you may contact us at any time via the contact options listed in the legal notice.
SSL/TLS Encryption
For security reasons and to protect the transmission of confidential content that you send to us, our app and website use SSL or TLS encryption. This means that data you transmit via this app or website cannot be read by third parties. You can recognise an encrypted connection by the "https://" address line of your browser and the lock icon in the browser bar.
Server Log Files
The website provider automatically collects and stores information in server log files that your browser automatically transmits to us. These are: pages visited on our domain, date and time of the server request, browser type and browser version, operating system used, referrer URL, hostname of the accessing computer, and IP address. This data is not merged with other data sources. The basis for data processing is Art. 6(1)(b) GDPR, which permits the processing of data for the fulfilment of a contract or pre-contractual measures.
Contact Form
Data transmitted via the contact form, including your contact details, is stored in order to process your enquiry or to be available for follow-up questions. This data will not be disclosed without your consent. The processing of data entered in the contact form is carried out exclusively on the basis of your consent (Art. 6(1)(a) GDPR). You may revoke your previously granted consent at any time. An informal notification by email is sufficient for the revocation. The lawfulness of data processing operations carried out until the revocation remains unaffected by the revocation. Data transmitted via the contact form will remain with us until you request deletion, revoke your consent to storage, or the purpose for data storage no longer applies. Mandatory statutory provisions — in particular retention periods — remain unaffected.
Cookies and local storage
Neither the website nor the app sets any cookies. The website embeds no analytics, tracking or marketing services and no third-party content. Cookies are a web browser technology and are not used in the app. Nor does the app read any advertising or tracking identifier provided by the operating system (such as the IDFA on iOS or the Advertising ID on Android), and no cross-device tracking takes place.
The website stores only three entries in the browser's local web storage. This data remains on the user's device and is transmitted neither to us nor to any third party. physiopass_lang (localStorage, retained until the user deletes it) stores the language the user has explicitly selected via the language switcher or a ?lang= parameter, so that the site appears in that language on a return visit; a language merely detected from browser settings is not stored. physiopass_lang_redirected (sessionStorage, deleted when the browser tab is closed) records that a one-off redirect to a language version has already taken place in this tab and prevents repeated redirects. physiopass_consent (localStorage, retained until the user deletes it) stores the date and time at which the information banner was acknowledged, so that it is not displayed again on every visit.
The app stores data in the protected app area of the device. This data remains on the device and is accessible only to the app. Specifically: (a) the sign-in session, meaning the access and refresh tokens issued by Supabase Auth, so that the user remains signed in after closing the app; (b) app settings and interface state, namely the selected language, the sound and autoplay setting, the training reminder settings (enabled yes/no, time of day, weekdays), the most recently used filters and list views, and a record of which one-off hints have already been shown; (c) the progress of a workout in progress, meaning the identifiers of the exercises it contains, the current position and the name of the training plan, so that an interrupted workout can be resumed; (d) a media cache in which already downloaded exercise images and videos are temporarily stored to reduce loading times and data usage; and (e) the local caches of the services used (see sections 10 to 12), such as error reports not yet transmitted and the last known subscription status.
Both on the website and in the app, this storage is strictly necessary in order to provide the digital service the user has explicitly requested and is therefore exempt from consent under Section 25(2) no. 2 TDDDG (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz; named TTDSG until 14 May 2024). The notice displayed on the website serves solely to inform under Art. 13 GDPR and does not collect consent. Product analytics in the app are the exception: the analytics function is disabled when the app starts and is activated only after explicit consent; that consent is obtained under Section 25(1) TDDDG and Art. 6(1)(a) GDPR and can be withdrawn at any time in the app settings (see section 11).
The browser's local storage can be inspected and cleared in any modern browser (settings, clear browsing or site data). If these entries are deleted or blocked, the website remains fully usable; the language simply has to be selected again and the notice reappears. In the app, the progress of a workout is deleted once it is completed or discarded, and the sign-in session is deleted on sign-out. All other locally stored data is removed when the app is uninstalled or its storage is cleared via the device's system settings; the media cache is additionally capped in size and pruned periodically. If this data is deleted, the app remains fully usable; the user then has to sign in again and set their preferences again.
Should cookies or services requiring consent be used in future, they will be described separately in this privacy policy and consent will be obtained beforehand.
Supabase (Database, Authentication, Storage)
Our app uses Supabase as its backend infrastructure. The provider is Supabase Inc., 970 Toa Payoh North #07-04, Singapore 318992 (infrastructure operated on Amazon Web Services, AWS). Purpose: Supabase is used for user authentication (email/password login), data storage (profiles, exercises, activities, workout plans, invitations), and file storage (videos, images). Data processed: email address, name, user role, exercise programs, health metrics (e.g., pain levels, weight), workout history, uploaded media files. Legal basis: Art. 6(1)(b) GDPR (contract performance — processing is necessary to provide the app's functionality). Data location: EU (Frankfurt, Germany, AWS eu-central-1). Further information: https://supabase.com/privacy.
Anthropic / Claude API (AI Assistant "Jana")
Our app offers an AI-powered physiotherapy assistant called "Jana". The provider is Anthropic, PBC, 548 Market St, PMB 90375, San Francisco, CA 94104-5401, USA. Purpose: Answering users' health-related questions using the AI model "Claude". Data processed: Only the text of your query is transmitted to the Claude API. Processing is stateless — no conversation history is stored at Anthropic. Anthropic does not use data submitted via the API for training its models. Legal basis: Art. 6(1)(a) GDPR (consent — you voluntarily initiate the use of the AI assistant). Third-country transfer: Data transfer to the USA is carried out on the basis of Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR. Further information: https://www.anthropic.com/privacy.
Sentry (Error and Crash Reporting)
We use Sentry for detecting and resolving errors in our app. The provider is Functional Software, Inc. (Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA. Purpose: Error detection, crash reporting, and improving app stability. Data processed: device information (model, operating system, app version), error logs (stack traces) and technical event trails (breadcrumbs) from immediately before the error. Screenshots and session replay (screen recordings) are disabled in the app; no screen content is transmitted to Sentry. No user identifier is sent to Sentry and no health data is transmitted. This data is used solely for debugging and is automatically deleted after 90 days. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the stability and security of the app). Third-country transfer: Data transfer to the USA is carried out on the basis of Standard Contractual Clauses (SCCs) and Sentry's certification under the EU-US Data Privacy Framework (DPF). Further information: https://sentry.io/privacy/.
PostHog (Product Analytics)
We use PostHog to analyse app usage. The provider is PostHog, Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA. Data is processed on EU servers (eu.i.posthog.com, located in Frankfurt, Germany). Purpose: Understanding app usage to improve features and user experience. Data processed: pseudonymised user ID, user role, app version, platform, screen views, interactions with UI elements. No health data is collected. Legal basis: Art. 6(1)(a) GDPR (explicit consent — you are asked for your consent during onboarding). Consent can be revoked at any time in the app settings. Third-country transfer: No third-country transfer takes place — data remains on EU servers in Frankfurt. Retention period: 12 months. Further information: https://posthog.com/privacy.
RevenueCat (In-App Subscription Management)
We use RevenueCat to process and manage in-app subscriptions. The provider is RevenueCat, Inc., 1032 E Brandon Blvd #3003, Brandon, FL 33511, USA. Purpose: management of in-app subscriptions, validation of purchases against the App Store or Google Play, and synchronisation of entitlement status across your devices. Data processed: pseudonymised user ID (App User ID; it corresponds to the user ID of your Physiopass account but does not itself contain any plain-text personal details), device and store identifiers assigned by the platform, purchase and subscription status (product, start, expiry, renewal, cancellation, refund) and the country of the store account. Email address, name and health data are not transmitted to RevenueCat. Payment data (e.g. card details) is processed exclusively by Apple or Google; neither we nor RevenueCat receive it. RevenueCat sends subscription events back to us via an interface so that we can keep the subscription status in your account up to date. The SDK is initialised when the app starts so that an existing subscription can be recognised across devices. Legal basis: Art. 6(1)(b) GDPR (performance of a contract — the processing is necessary to provide and bill paid features and to restore purchases). Third-country transfer: The transfer of data to the USA takes place on the basis of Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR; there is no certification under the EU-US Data Privacy Framework (DPF). Retention: subscription and purchase data in our database until your account is deleted; at RevenueCat for the duration of the contractual relationship in accordance with the data processing agreement. Further information: https://www.revenuecat.com/privacy.
Fonts
Our website uses the Inter font for headings and individual highlighted text elements; it is hosted locally on our web server (self-hosting). Body text is rendered in the system font already present on your device; no font file is downloaded for this. Our app likewise uses your device's system font; the Lato font bundled locally within the app is used solely for generating PDF files (exercise export). In no case is a connection to external font servers (such as Google Fonts) established. Accordingly, no data is transmitted to third parties for font rendering.
Data Retention Periods
We store your personal data only for as long as necessary for the respective purposes: User account data (email, name, role): until account deletion. Exercise and workout data: until account deletion. Activity and health metrics: until account deletion. Sentry error data: 90 days (automatically deleted). PostHog analytics data: 12 months (EU servers). Subscription and purchase data (RevenueCat): until account deletion; at RevenueCat for the duration of the contractual relationship. AI queries (Anthropic): not stored (stateless processing). Server log files: 7 days. Contact form data: until the purpose is fulfilled or you request deletion. Account deletion: You can permanently remove your account and all associated data at any time directly in the app via the ‘Delete Account’ function. Deletion takes effect immediately and irreversibly: your account and all associated data (profile, exercises, programs, activity and progress data, and uploaded images and videos) are permanently deleted from our systems and cannot be restored. Alternatively, you can request deletion at any time informally by email. Any mandatory statutory retention obligations remain unaffected.
Sub-Processors and Data Protection Officer
The following sub-processors are used to provide our services: Supabase Inc. (database, authentication, storage) — EU (Frankfurt), AWS eu-central-1. Anthropic, PBC (AI assistant) — USA, Standard Contractual Clauses (SCCs). Functional Software, Inc. / Sentry (error reporting) — USA, SCCs + EU-US DPF. PostHog, Inc. (product analytics) — EU (Frankfurt), no third-country transfer. RevenueCat, Inc. (in-app subscription management) — USA, Standard Contractual Clauses (SCCs). Apple Inc. / Google LLC (app distribution via App Store / Google Play) — USA, platforms' own privacy policies. Data Protection Officer: The appointment of a Data Protection Officer is not mandatory for our operation pursuant to Art. 37 GDPR. For data protection enquiries, please contact the responsible entity named in section 1.
Last updated: July 2026