Privacy Policy
1. Privacy at a glance
The following information provides a simple overview of what happens to your personal data when you visit this website or use the hitPR app.
2. Responsible party
The party responsible for data processing on this website and in the hitPR app is:
Christian GeißlerAm Weigelsgarten 29
60433 Frankfurt am Main, Germany
E-Mail: [email protected]
3. Hosting
This website is hosted by Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA). Cloudflare is a CDN and security provider. The use is based on Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in the most reliable presentation of our website. A data processing agreement (DPA) has been concluded with Cloudflare. In doing so, Cloudflare processes technically necessary connection data (including IP address, date/time of the request, requested resource, user agent) to deliver and secure the website (Art. 6(1)(f) GDPR). This data is not combined with other data sources.
4. Analytics
This website uses Cloudflare Web Analytics, a privacy-friendly analytics tool. No cookies are set and no personal data is stored. Only aggregated metrics such as page views, visitor countries, referrer, browser/device type and performance data (load times) are collected. Processing is based on Art. 6 para. 1 lit. f GDPR.
5. Cookies and Local Storage
This website does not set any cookies and does not use tracking technologies. When you actively use certain features, the website stores settings locally in your browser (localStorage): your chosen accent color and the weight unit (kg/lbs) in the training tools. This data remains exclusively on your device, is never transmitted to us or third parties, and can be deleted at any time via your browser settings. This storage is strictly necessary for a feature you explicitly request (Section 25 (2) No. 2 of the German TDDDG); a consent banner is therefore not required.
Waitlist (launch notification)
When you join the waitlist on our website, we process your email address and — as proof of your consent (double opt-in) — the time of signup and confirmation together with the IP address used. The sole purpose is to notify you once, as soon as the app is available. The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time with effect for the future — for example via the unsubscribe link in the email or the contact details listed above under “Controller”. We use Supabase (Supabase Inc.) to store the data; it is stored in a data centre in the EU (Frankfurt). We use Resend (Plus Five Five, Inc.) to send the confirmation and notification email; both process the data as processors on our behalf. Where data is transferred to the USA — in particular for sending the email — we base this on the EU Standard Contractual Clauses. We delete unconfirmed signups no later than 30 days after signup; confirmed entries are deleted once the launch notification has been sent or you unsubscribe. The signup form is protected against automated abuse by Cloudflare Turnstile (Cloudflare, Inc.); this processes technical data such as your IP address. The legal basis is our legitimate interest in preventing spam and automated signups (Art. 6(1)(f) GDPR).
6. hitPR App — Data processing
The hitPR app works completely offline (offline-first). All training data (exercises, sets, weights, personal records) is stored exclusively on your device. Legal basis: Art. 6(1)(b) GDPR (contract performance). No training data is transmitted to servers unless you activate cloud backup. An account is not required.
Cloud backup (optional)
If you voluntarily register for a cloud backup, your training data is encrypted with AES-256-GCM (individual key per user) and stored on Cloudflare R2 (via Supabase, EU region Frankfurt). Progress photos are excluded from cloud backup and remain exclusively on your device. Legal basis: Art. 6(1)(b) GDPR (contract performance). You can delete your account and all cloud data at any time. For health data (body data), Art. 9(2)(a) GDPR (explicit consent) additionally applies (see „Health-related data“).
Sign-in and third-party services
When signing in with Google Sign-In, Google shares your name and email address with hitPR. There is no sharing with advertising partners and no profiling. Anonymous usage statistics and crash reports in the app are optional and disabled by default. Legal basis: Art. 6(1)(b) GDPR (contract performance). Alternatively, you can register and sign in with an email address and password (legal basis likewise Art. 6(1)(b) GDPR). When you register or reset your password, we send transactional emails (e.g. confirmation and reset links) via our email provider Resend (Plus Five Five, Inc., USA); your email address is processed in the course of this. Transfers to the USA are based on Standard Contractual Clauses (SCC).
Crash reports (Firebase Crashlytics)
When you enable crash reports in the app (opt-in, disabled by default), the following data is sent to Google Firebase (Google Ireland Ltd.) in the event of a crash: installation identifier (pseudonymous), device model, operating system version, IP address (not permanently stored by Google), and error logs. Legal basis: consent (Art. 6(1)(a) GDPR). You can withdraw consent at any time in the app settings. Data is retained for 90 days.
Health-related data (Art. 9 GDPR)
The app processes health-related data within the meaning of Art. 9 GDPR: training performance (weights, repetitions, distances), body weight, body fat percentage, and body measurements. This data is stored locally on your device and only transmitted in encrypted form if you activate cloud backup (optional). Legal basis: explicit consent (Art. 9(2)(a) GDPR). No data is shared with third parties.
Progress photos
Progress photos are stored exclusively on your device and encrypted with AES-256-GCM. The encryption key is stored in the operating system keystore (iOS Keychain / Android EncryptedSharedPreferences). GPS and device metadata (EXIF) are removed before storage. Photos are not included in cloud backup and never leave your device.
Subscription management (RevenueCat)
For managing premium purchases (subscriptions and one-time purchase), we use RevenueCat, Inc. (USA). RevenueCat processes purchase receipts, purchase/subscription status, and a pseudonymous app user ID. No training data or personal content is shared with RevenueCat. Legal basis: Art. 6(1)(b) GDPR (contract performance). Data transfer to the USA is based on Standard Contractual Clauses (SCC).
Feedback feature
When you use the feedback feature in the app, your message, a pseudonymous device identifier (UUID), device information, and the app version are transmitted to Supabase (EU region Frankfurt). The device identifier is used solely for spam prevention (rate limiting). No user account is required. Legal basis: legitimate interest in product improvement (Art. 6(1)(f) GDPR). You may optionally provide an email address if you would like a reply to your feedback. This is voluntary; the address is used solely to respond to your message, is not shared, and is deleted after 12 months at the latest. Legal basis: your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time.
Anonymous usage signals
To improve the app and the program catalog, we collect anonymous, aggregated usage signals — e.g., which screens are opened, whether a workout is started/finished, which catalog programs are imported, as well as general app settings (language, unit system, color scheme). No training content, body data, or personal data is transmitted, and no behavioral profiles are created. The events are sent without any stable device or user identifier, cannot be combined into a history or linked to a person, are aggregated by day on our Supabase instance (EU, Frankfurt), and deleted after 12 months at the latest. Collection only takes place with explicit consent — it can be enabled during onboarding or at any time in the settings (default: off). IP addresses are not stored.
App stores (Apple / Google)
When you download and install the app via the Apple App Store or Google Play Store, the respective store operator collects its own data (e.g. store user ID, time of download, device identifier and, for paid purchases, payment information). We have no influence over this processing; it takes place under the sole responsibility of Apple Inc. or Google LLC in accordance with their respective privacy policies.
7. Fonts
This website uses self-hosted fonts (DM Sans, DM Mono). There is no connection to external servers such as Google Fonts. The fonts are loaded directly from our server.
8. Your rights
You have the right at any time to:
- Access your stored data (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Deletion of your data (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing (Art. 21 GDPR)
- Withdraw consent you have given, with effect for the future (Art. 7(3) GDPR)
Contact us at: [email protected]
You have the right to lodge a complaint with the competent supervisory authority: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany (https://datenschutz.hessen.de).
9. Data processing agreements
We have concluded data processing agreements (DPA) with our service providers (Cloudflare, Supabase, Resend, Google Firebase, RevenueCat) to ensure the protection of your data. Transfers to the USA are based on the EU-US Data Privacy Framework for Cloudflare and Google, additionally safeguarded by Standard Contractual Clauses (SCC); for Supabase, Resend and RevenueCat they are based on Standard Contractual Clauses (SCC). We provide a copy of the SCC on request.
10. Automated decision-making
There is no automated decision-making or profiling within the meaning of Art. 22 GDPR. Training suggestions and calculated values in the app (e.g. Training Max, Estimated 1RM) are general estimates and not individual recommendations.
11. Minimum age
Use of hitPR is permitted from age 16 (Art. 8 GDPR). Persons under 16 require the consent of a parent or legal guardian.
12. Changes
We reserve the right to update this privacy policy to comply with current legal requirements. The current version is always available on this page.
Last updated: July 2026