Privacy Policy (App)
Quick note: This Privacy Policy explains how Nico Ettlinger – Digital Solutions (“we”, “us”, or the “Service Provider”) processes personal data when you use the TRAININGG mobile application for iOS or Android (“App”).
TRAININGG handles workout and body data, optional Apple HealthKit or Health Connect data, and—when you choose AI Coach—information sent to Google to generate AI responses. Please read this Policy before using those features.
- 1. Scope and Data Sources
- 2. Data We Process
- 3. Purposes and Legal Bases (GDPR / UK GDPR)
- 4. AI Coach and Google Gemini
- 5. Health Data Safeguards
- 6. Cloud and On-Device Storage
- 7. Analytics and Choices
- 8. Recipients and Service Providers
- 9. International Transfers
- 10. Retention
- 11. Your Privacy Rights
- 12. Account and Data Deletion
- 13. California Privacy (CCPA / CPRA)
- 14. Children
- 15. Security
- 16. Changes to This Policy
- 17. Contact, DPO, and Representatives
Controller: Nico Ettlinger – Digital Solutions (sole proprietorship)
Address: Am Seeacker 19, 93326 Abensberg, Germany
Email: [email protected]
Effective Date: 16 July 2026
1. Scope and Data Sources
(1) This Policy applies to data processed through the App and related support. It does not govern Apple, Google, RevenueCat, or other third parties acting for their own purposes.
(2) We receive data:
- from you, when you create an account, enter profile or training information, use AI Coach, or contact us;
- from your device and the App, such as technical, usage, security, and local feature data;
- from services you connect, including Sign in with Apple, Google Sign-In, Apple HealthKit, and Health Connect, with the permissions you grant; and
- from subscription platforms, including Apple, Google Play, and RevenueCat, about purchases and Pro entitlement status. We do not receive your full payment-card details.
2. Data We Process
2.1 Account and identifiers
- Email address, name or display name, and Firebase user ID
- Authentication-provider IDs and sign-in method
- Authentication and security information needed for email/password, Google Sign-In, or Sign in with Apple
- RevenueCat app-user or subscription identifiers and entitlement status
Authentication credentials are handled by Firebase and the applicable sign-in provider. We do not receive your Google or Apple account password or full payment-card details.
2.2 Profile, body, and training data
- Age or birthday, height, weight, body-fat percentage, gender where provided, measurement system, and other profile preferences
- Goals, training experience, schedule, equipment, favorite exercises, and workout preferences
- Workout plans, custom exercises, workout history, sets, repetitions, loads, duration, personal records, progress goals, statistics, and related app settings
Depending on context, body metrics, training history, goals, and fitness preferences may be health data or otherwise sensitive personal data.
2.3 Apple HealthKit and Health Connect data
If you enable a health integration, the App may read and write the health and fitness categories for which you grant permission. These can include completed workouts and body metrics such as height, weight, body-fat percentage and, on iOS where available and permitted, date of birth and biological sex. The exact permissions are shown by Apple Health or Health Connect. See § 5 for the special rules that apply.
2.4 AI Coach data
- Messages, intake answers, and instructions you submit
- Relevant profile, body, workout, plan, history, goal, preference, recovery, personal-record, and statistics data selected by the feature to answer your request
- AI-generated responses, workout-plan drafts, safety signals, usage counts, and technical request data
Relevant body or profile values may originate from Apple HealthKit or Health Connect after you import them into TRAININGG. See § 4 before using AI Coach.
2.5 Analytics, usage, device, and security data
- App-instance and device information, operating system, language, country or coarse region derived by the service, app version, and session information
- Screen views, feature interactions, onboarding choices, workout start/completion events, durations, aggregate counts, subscription/paywall interactions, and AI feature success/error events
- IP address and request metadata processed by service providers for delivery, security, diagnostics, and abuse prevention
- Firebase App Check attestation or integrity signals used to help confirm requests come from the authentic App on a valid device
We do not intend to send AI message text or complete workout-plan content to Firebase Analytics. Some analytics events relate to training behavior and preferences and may therefore be sensitive depending on context.
2.6 Support and operating-system features
If you contact us, we process your contact details, message, attachments, and the information needed to respond. Rest-timer notifications, Live Activities, and home-screen widgets may display workout information selected by you; their working data is generally handled on your device and by the operating system.
3. Purposes and Legal Bases (GDPR / UK GDPR)
| Purpose | Data | Legal basis |
|---|---|---|
| Provide accounts, cloud sync, workouts, plans, statistics, and settings | Account, profile, training, and device data | Art. 6(1)(b) — perform our contract |
| Read/write Apple HealthKit or Health Connect data and process health data for the requested feature | Health, body, and fitness data | Art. 6(1)(a) and Art. 9(2)(a) — explicit consent |
| Send AI inputs to Google and generate AI Coach responses | Messages and relevant training/fitness data | Art. 6(1)(a) and, where health data is included, Art. 9(2)(a) — explicit consent |
| Verify and manage Pro access | Subscription identifiers, product, transaction, and entitlement data | Art. 6(1)(b) — perform our contract |
| Measure and improve use, reliability, and feature performance | Analytics, usage, and device data | Art. 6(1)(f) — legitimate interests in improving and operating the App, or Art. 6(1)(a) consent where required by local law |
| Protect the App and prevent fraud, abuse, and unauthorized AI/API use | Authentication, App Check, IP, device, and request data | Art. 6(1)(f) — legitimate interests in security and abuse prevention |
| Respond to support and rights requests | Contact, account, and request data | Art. 6(1)(b), Art. 6(1)(c), or Art. 6(1)(f), depending on the request |
| Meet tax, accounting, legal, and regulatory duties and establish or defend claims | Relevant account, subscription, and communications data | Art. 6(1)(c) and Art. 6(1)(f) |
Where we ask for consent, it is voluntary and can be withdrawn for the future. Withdrawal does not affect processing already carried out lawfully. Refusing health or AI consent prevents only the relevant optional feature, not unrelated core functions.
Before the first AI Coach transmission on a device, the App displays a separate consent prompt that names Google and states that your messages and relevant training data are sent to Google. Nothing is sent to Gemini unless you select Agree. Health-platform access is requested separately through Apple Health or Health Connect. You may decline either choice without losing unrelated core features.
4. AI Coach and Google Gemini
(1) AI Coach uses Gemini models through Firebase AI Logic. When you use the feature, your messages and relevant training data are sent to Google to provide the AI Coach response or workout-plan generation you requested. Google processes the input, technical request data, and generated output.
(2) Relevant training data can include the categories in § 2.4. Because imported HealthKit or Health Connect values can become part of your TRAININGG profile, those values may also be included when relevant. The pre-send disclosure and Agree action cover messages and relevant training data, including health-derived body values when relevant; you may decline and not use AI Coach.
(3) Your visible AI chat history and local AI usage counters are stored in MMKV on your device, not in our Firebase Realtime Database. Chat history remains until you delete it in the App, clear App data, uninstall the App, or the App applies its local conversation limit. Local storage does not prevent a message from being transmitted to Google when you send it.
(4) TRAININGG uses Gemini as a paid service through a Cloud project associated with an active billing account. Under Google’s current terms, Google does not use paid-service prompts or responses to improve its products. Google retains prompts, supplied context, and outputs for 55 days for abuse monitoring, safety, security, and required legal or regulatory disclosures; authorized personnel may review flagged content.
(5) AI Coach is unavailable if the production project does not have active Cloud Billing and the applicable Google data-processing terms in place. TRAININGG does not transmit personal or health data through an unpaid Gemini service tier.
(6) Learn more in Firebase AI Logic data governance, the Gemini API Additional Terms, Google’s Privacy Policy, and the Google data-processing terms.
AI output may be wrong and is not medical or professional advice. See the Disclaimer.
5. Health Data Safeguards
(1) Health integrations are optional. The App asks for operating-system permission before accessing Apple HealthKit or Health Connect. You may grant access by data category and revoke it in Apple Health or Health Connect settings.
(2) We use health and fitness data only to provide or improve user-facing health, fitness, workout, progress, sync, or—where separately and explicitly authorized—AI Coach features that you request.
(3) We do not use data obtained through HealthKit or Health Connect for advertising, marketing, credit decisions, or unrelated use-based data mining. We do not sell it, transfer it to data brokers or information resellers, or share it with third parties without your explicit consent except where strictly required by law.
(4) Data imported from a health platform into your TRAININGG profile can be stored locally and, for signed-in users, synced to the account-bound Firebase Realtime Database. It can also be sent to Google for AI Coach if relevant, but only after the separate explicit consent described in § 4.
(5) Revoking an operating-system permission stops future access but does not automatically delete data already imported into TRAININGG, stored in your account, or lawfully processed. Use the deletion controls in § 12 to remove that data.
(6) Apple HealthKit and Health Connect are operated by Apple and Google respectively. Their handling of data in the platform health store is governed by their own policies.
6. Cloud and On-Device Storage
(1) When you are signed in, account-bound data—including profile, body metrics, workout plans, workout history, goals, statistics, settings, and custom exercises—syncs to Google Firebase Realtime Database. Firebase Authentication keeps the account linked to your Firebase user ID.
(2) Some information is intentionally device-only in MMKV, including AI chat history, AI usage counters, current device health-sync state, and certain temporary App state. It does not sync through our Firebase Realtime Database. Device-only data may still be transmitted for a feature at the moment you use it—for example, a message sent to Google for AI Coach.
(3) Clearing App data or uninstalling generally removes device-only data from that device, but does not delete your cloud account, Firebase data, store subscription, or data retained independently by third parties.
7. Analytics and Choices
(1) We use Firebase Analytics to understand feature use, onboarding, subscriptions, workout interactions, and technical performance. Firebase Analytics receives usage and device data described in § 2.5. It should not receive raw AI conversations or complete workout-plan content.
(2) Analytics is used to improve the App and is not used by us for third-party behavioral advertising. We do not sell or share analytics data for cross-context behavioral advertising.
(3) Analytics collection is currently enabled when the App starts and the current App does not provide an in-app analytics switch. You may object by contacting [email protected]; uninstalling stops future App collection but does not erase data already retained by Firebase.
(4) On supported iOS versions, RevenueCat may receive an Apple AdServices attribution token to measure which Apple Search Ads campaign led to a subscription. This is used for first-party acquisition and subscription attribution, not to sell personal data.
8. Recipients and Service Providers
We disclose data only as needed to provide, secure, and support the App, comply with law, or complete a business transfer subject to appropriate safeguards.
| Recipient | Role and data/purpose |
|---|---|
| Google / Firebase | Processor or service provider for Authentication, Realtime Database, Analytics, App Check, and Firebase AI Logic/Gemini; receives the data required for each enabled service. Firebase privacy information |
| Google Sign-In and Google Play | Independent platform functions for authentication, app distribution, billing, subscription management, and Health Connect. Google Privacy Policy |
| Apple | Independent platform functions for Sign in with Apple, HealthKit, App Store distribution/billing, device features, and Apple Search Ads attribution. Apple Privacy Policy |
| RevenueCat | Processor/service provider for subscription identifiers, purchase validation, entitlement status, offers, and subscription attribution. RevenueCat privacy information |
We may also disclose the minimum necessary data to authorities where legally required, to professional advisers under confidentiality, or in connection with a merger, acquisition, financing, or sale after appropriate notice and safeguards.
We do not sell personal data. We do not share personal data for cross-context behavioral advertising.
9. International Transfers
Google/Firebase and RevenueCat may process data in the United States and other countries outside the EEA, UK, or your country. Google states that certified US entities participate in the EU–US Data Privacy Framework, its UK Extension, and the Swiss–US framework; its Firebase and paid Gemini processor terms also incorporate applicable contractual safeguards. RevenueCat’s Data Processing Addendum incorporates the European Commission’s Standard Contractual Clauses and the UK Addendum for restricted transfers. Where a framework does not apply, we rely on these contractual safeguards and supplementary measures as required. You may contact us for information or a copy of applicable safeguards.
10. Retention
We keep personal data only as long as necessary for the stated purpose, legal obligations, security, or claims. Current retention is:
| Data | Retention |
|---|---|
| Firebase Authentication account and account-bound Realtime Database data | Until account deletion, unless a legal exception requires limited retention |
| Device-only AI chat history | Until you delete it, clear App data, uninstall, or the App’s local conversation limit removes older history |
| Device-only AI usage counters | Stored locally and rolled over for the applicable usage period; removed by clearing App data or uninstalling |
| Google Gemini prompts, supplied context, and responses | 55 days for Google abuse monitoring, safety, security, and required legal or regulatory disclosures |
| Firebase Analytics user- and event-level data | Up to 14 months under Google Analytics retention controls; standard aggregated reports may remain longer |
| RevenueCat subscription and entitlement data | While needed to administer entitlements and the service relationship; deletion is requested when covered account data is deleted, subject to backups and legal records |
| Support and privacy requests | Up to three years after the request is closed, or longer where required for legal obligations or claims |
| Backups and deletion logs | Residual processor backups are removed through ordinary overwrite cycles; a minimal deletion-request record may be retained for up to three years |
At the end of the relevant period, data is deleted or irreversibly anonymized where feasible.
11. Your Privacy Rights
Subject to applicable law and exceptions, you may:
- request access to and a copy of your data;
- request correction of inaccurate or incomplete data;
- request deletion;
- request restriction of processing;
- receive data you provided in a portable format and, where applicable, have it transmitted to another controller;
- object to processing based on legitimate interests;
- withdraw consent at any time for future processing;
- object to or request information about applicable automated processing; and
- complain to a competent data-protection authority, including the Bavarian Data Protection Authority for the Private Sector or the authority where you live or work.
Send requests to [email protected]. We may request proportionate verification. GDPR/UK GDPR requests are generally answered within one month, subject to lawful extensions.
Health permissions can also be withdrawn in Apple Health or Health Connect settings. Not using AI Coach stops future AI requests. Because the AI consent record is device-only, clearing the App’s data or reinstalling resets it and requires a new agreement before another AI request; you may also contact us to withdraw consent or object to future processing.
12. Account and Data Deletion
(1) You may request account deletion through Account & Data Deletion or by emailing [email protected].
(2) Deletion covers the Firebase Authentication account and account-bound Firebase Realtime Database data, subject to lawful exceptions. If you used Sign in with Apple, associated authorization tokens must also be revoked as required by Apple.
(3) Delete device-only AI history through the App’s data-management controls. Clearing App data or uninstalling removes other device-only data. Deleting your account does not cancel a Pro subscription; cancel separately through Apple or Google Play.
(4) Apple, Google, RevenueCat, and other recipients may retain records under their own legal or contractual duties. We will instruct our processors to delete covered data where required.
13. California Privacy (CCPA / CPRA)
To the extent the CCPA/CPRA applies, California residents may request that we:
- disclose the categories, sources, purposes, specific pieces, and recipients of personal information collected;
- correct inaccurate personal information;
- delete personal information, subject to exceptions;
- provide portable access to covered information; and
- not discriminate for exercising privacy rights.
We do not sell personal information and do not share it for cross-context behavioral advertising, so there is no sale or sharing to opt out of. We do not use or disclose sensitive personal information for purposes that trigger a right to limit under the CCPA/CPRA. Authorized agents may submit requests with proof of authority. Submit a “California Privacy Request” to [email protected]; we will verify and respond as required by law.
14. Children
TRAININGG and AI Coach are not directed to anyone under 18, and users must be at least 18. We do not knowingly collect personal data from minors. If you believe a minor has used the App or provided data, contact [email protected] so we can investigate and delete it as appropriate.
15. Security
We use safeguards appropriate to the nature of the service, including TLS-encrypted transmission, Firebase Authentication, account-scoped database access rules, access controls, and Firebase App Check for anti-abuse and authentic-App verification. AI chat history is kept in app-local MMKV rather than our cloud database. We limit access to people and providers who need it for their role.
No method is completely secure. You should protect your device and credentials and contact [email protected] if you suspect unauthorized access. We will make legally required breach notifications.
16. Changes to This Policy
We may update this Policy when the App, providers, or law changes. The current version is available at https://www.trainin.gg/app/privacy. We will provide additional in-app or email notice of material changes where required and request new consent where a changed purpose requires it.
17. Contact, DPO, and Representatives
For privacy questions or requests:
Nico Ettlinger – Digital Solutions
Am Seeacker 19
93326 Abensberg
Germany
Email: [email protected]
Because the controller is established in Germany, an EU representative under GDPR Article 27 is not required. No Data Protection Officer has been appointed because the current organization and documented processing scale do not meet the appointment thresholds. We reassess this if the nature or scale of processing changes; privacy questions may be sent directly to the controller above.
If TRAININGG actively offers the App to people in the UK without a UK establishment, a UK representative may be required. The UK release must therefore remain unavailable until a representative is appointed or a documented legal assessment confirms that an Article 27 exception applies.