Back

Privacy Policy / Datenschutzerklärung

1. Controller / Verantwortlicher

The controller responsible for data processing on this website and app is:

MR Digital Solutions UG (haftungsbeschränkt)

Düsseldorfer Str. 26

51379 Leverkusen, Germany

Email: [email protected]

The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data (e.g., names, email addresses, etc.).

2. General Information on Data Processing

2.1 Scope of Processing

We process personal data of our users only to the extent necessary to provide a functional website and app, as well as our content and services. Processing of personal data occurs regularly only with user consent. An exception applies in cases where prior consent cannot be obtained for factual reasons and data processing is permitted by law.

2.2 Legal Basis (GDPR)

Data processing is based on:

  • Art. 6(1)(a) GDPR - Processing with your explicit consent
  • Art. 6(1)(b) GDPR - Processing for contract performance (subscription)
  • Art. 6(1)(f) GDPR - Processing based on legitimate interests (service improvement, security)

2.3 Data Deletion and Storage Duration

We retain data only for as long as needed for the purpose described or for legal obligations. The criteria differ by category:

  • Workout logs remain on your device until you delete them, reset the app data, or delete the app.
  • Account, preference, access and music-interaction data is retained while the account is active. An in-app deletion request immediately invalidates access and removes or tombstones direct account identifiers; residual technical records are retained only as needed to complete deletion, prevent misuse, meet legal duties or defend legal claims, and are then deleted or anonymized.
  • Contact messages are kept for the time required to answer and document the request, plus any applicable statutory retention period.
  • Security logs, cookieless analytics and error reports are retained for limited, configured operational periods and are deleted or aggregated when no longer needed.
  • Transaction and tax records may be retained for statutory commercial and tax retention periods.

3. Data We Collect

3.1 Anonymous User Data

When you use GymDJ, we collect:

  • A pseudonymous, app-generated stable identifier used to recognize your installation across sessions. Apple may synchronize this identifier across your devices through iCloud Key-Value Storage when iCloud is enabled.
  • A coarse device descriptor — operating system version and device model (e.g. "iOS 18 / iPhone") — used only to prevent abuse of free trials and promotional offers
  • Music-session and trial/demo-session data (such as duration)
  • Music preferences and listening history
  • Track interactions (plays, skips, likes)

3.2 Workout Tracker Data Stored on Your Device

Workout details such as selected exercises, plans and plan edits, sets, repetitions, weights, rest times and workout history are currently stored locally on your device. They are not uploaded to GymDJ's servers. You can remove this local data through the app's reset/delete functions or by deleting the app. The exercise catalog and built-in plans are downloaded as read-only app content and may be cached on your device.

3.3 Sign in with Apple (Optional)

You can optionally link your account using Sign in with Apple (e.g., to keep your preferences across devices). If you do, we process:

  • Your Apple user identifier (to link your account)
  • Your name and email address, if you choose to share them with Apple's prompt (you can also hide your email via Apple's private relay)

Sign in with Apple is never required — GymDJ works fully anonymously without it.

3.4 Subscription Data (iOS App)

When you purchase a subscription through Apple:

  • Apple ID (processed by Apple, not stored by us)
  • Subscription status and expiration date
  • Purchase receipts (validated via Apple servers)
  • Payment is processed entirely by Apple - we never see your credit card data

3.5 Technical Data

  • Device type and operating system version
  • App version
  • IP address (for security and fraud prevention)
  • Access times and dates

3.6 Website: Contact Form

If you contact us through the form on our website, we process:

  • Contact form: the name, email address, and message contents you submit, solely to receive and respond to your request (legal basis: Art. 6(1)(b) and (f) GDPR). Your message is delivered to us by email through our email provider Resend (see Section 5.4).

3.7 No Health Data

GymDJ does not access Apple Health, HealthKit, motion, location, contacts, photos, microphone or camera data. Workout entries are fitness logs you enter yourself and remain on your device as described above.

4. How We Use Your Data

We process data for the following purposes:

  • Provide and improve our music streaming service
  • Provide the read-only exercise catalog and built-in workout plans
  • Personalize workout music recommendations
  • Manage free trials, subscriptions, and Premium access
  • Prevent abuse of free trials and promotional offers
  • Ensure service security and prevent fraud
  • Analyze usage patterns to enhance user experience (aggregated, anonymized)
  • Comply with legal obligations

5. Data Sharing and Third Parties

We do not sell your personal data. We share data only with:

5.1 Apple Inc. (Subscription Processing)

Subscription payments are processed entirely through Apple's App Store. Apple's privacy policy applies: https://www.apple.com/legal/privacy/

5.2 RevenueCat (Subscription Management)

We use RevenueCat to manage subscriptions and in-app purchases. RevenueCat processes subscription data on our behalf. Their privacy policy applies: https://www.revenuecat.com/privacy

5.3 Sentry (Error and Crash Monitoring)

We use Sentry (Functional Software, Inc.) to detect crashes and technical errors in our app, website, and backend. Sentry processes error data on our behalf and stores it on servers in the European Union (see Section 8.2). We configure the SDK not to attach default personal information. Development builds of the website and backend do not send events to Sentry. Their privacy policy applies: https://sentry.io/privacy/

5.4 Resend (Email Delivery)

When you use our website contact form, we use Resend (Resend, Inc., USA) to deliver your message to us by email. Resend processes the name, email address, and message you submit, on our behalf and under a data processing agreement. Data may be processed in the USA on the basis of the EU Standard Contractual Clauses (see Section 10). Their privacy policy applies: https://resend.com/legal/privacy-policy

5.5 Hosting Provider

Our core backend and self-hosted website analytics are hosted in Germany. We use contractual data-processing arrangements where required by Art. 28 GDPR.

5.6 Legal Obligations

We may disclose data if required by German or EU law, court orders, or government requests.

6. Data Security

We implement state-of-the-art technical and organizational measures to protect your data:

  • Encryption in transit (HTTPS/TLS)
  • Pseudonymous identifiers instead of real names wherever possible
  • Secure JWT token authentication
  • Regular security audits and updates
  • Access controls and logging
  • Data minimization principle (we collect only what's necessary)

7. Your Rights Under GDPR

Under the EU General Data Protection Regulation, you have the following rights:

7.1 Right of Access (Art. 15 GDPR)

Request information about your stored personal data, processing purposes, and recipients.

7.2 Right to Rectification (Art. 16 GDPR)

Request correction of inaccurate personal data.

7.3 Right to Erasure (Art. 17 GDPR)

Request deletion of your data when no longer needed or processing is unlawful. You can also delete your account and associated data directly in the app at any time via Settings → Delete Account.

7.4 Right to Restriction (Art. 18 GDPR)

Request restriction of processing under certain conditions.

7.5 Right to Data Portability (Art. 20 GDPR)

Receive your data in a structured, machine-readable format.

7.6 Right to Object (Art. 21 GDPR)

Object to processing based on legitimate interests (Art. 6(1)(f) GDPR).

7.7 Right to Withdraw Consent (Art. 7(3) GDPR)

Withdraw consent at any time without affecting prior lawful processing.

7.8 Right to Lodge a Complaint

File a complaint with a supervisory authority. The authority responsible for our establishment is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW). You may also contact another competent authority under Art. 77 GDPR. Information about complaints is available at ldi.nrw.de.

To exercise your rights, contact us via:
our contact form

8. Analytics and Tracking

We use privacy-focused analytics to improve our service. We do not use advertising cookies or sell data to third parties.

8.1 Rybbit (Self-Hosted)

We use Rybbit for privacy-friendly, cookieless website analytics. Rybbit is self-hosted on our own servers in Germany, giving us full control over the data.

  • Data processed: Page views, referrers, browser and device information, approximate country derived from the request, and limited product events such as an App Store redirect
  • Data location: Germany (our servers)
  • Cookies: None - Rybbit is cookie-free
  • IP addresses: Processed transiently to deliver the request and derive coarse location; not retained in the analytics record
  • No advertising identifiers and no cross-site advertising profiles
  • Purpose: Understanding usage patterns and improving the service
  • Legal basis: Art. 6(1)(f) GDPR (legitimate interest)

8.2 Sentry (Error and Crash Monitoring)

In the iOS app, on this website, and in our backend we use Sentry to capture crashes and technical errors so we can find and fix problems quickly. Sentry processes this data on our behalf on servers in the European Union.

  • Data processed: Crash and error reports (including stack traces and relevant technical context), request or screen location, device type and OS version, app version, and pseudonymous identifiers needed to group related errors
  • Default personal information is disabled. Network services necessarily process an IP address transiently when receiving an event, but we do not intentionally attach it to the error report.
  • Data location: European Union (Sentry EU data residency)
  • No advertising tracking, no cross-app tracking, no sale of data
  • Purpose: Stability, error diagnosis, and service improvement
  • Legal basis: Art. 6(1)(f) GDPR (legitimate interest)
  • Sentry privacy policy: https://sentry.io/privacy/

8.3 iOS App Cookies

Our iOS app does not use cookies.

8.4 Automated Decisions

Music recommendations use listening signals to choose suitable tracks. They do not produce legal or similarly significant effects, and we do not use solely automated decision-making within the meaning of Art. 22 GDPR.

9. Children's Privacy

GymDJ is not intended for users under 13 years old, and we do not knowingly collect data from children. In the European Union, where a higher minimum age applies to consent-based processing (16 in Germany under Art. 8 GDPR), users below that age should use GymDJ only with the involvement of a parent or guardian. If you believe a child has provided us with data, contact us immediately and we will delete it.

10. Data Transfers Outside the EU

Our core backend and self-hosted website analytics are operated in Germany. Some providers are based outside the EEA or may provide support from outside the EEA: Sentry stores our error data in the European Union, while Functional Software, Inc. is based in the USA; Resend, Inc. may process contact-form data in the USA; Apple and RevenueCat may process account and subscription data internationally. Where required, transfers rely on an adequacy decision or appropriate safeguards such as the EU Standard Contractual Clauses.

11. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. Updates will be posted with a new "Last updated" date. Where a change requires notice or consent, we will provide it separately. Merely continuing to use GymDJ does not replace consent where the law requires consent.

12. Contact

For questions, concerns, or to exercise your rights, contact us via:
our contact form

Last updated: July 24, 2026