Privacy policy
Privacy information for Training App
Last updated October 2026. This is a product-specific draft that must be reviewed legally and technically before release.
Controller
Tobias Koch
[Postanschrift vor Veröffentlichung ergänzen]
Privacy contact: tobias@mmsetc.de
Website: https://qa.ningkit.com
Data we process
Depending on the functions you use, we process:
- account and login data such as name, email, encrypted password, language, session and security data;
- training plans, workouts, exercises, sets, repetitions, weights, rests, notes, goals and training history;
- imported activities with time, duration, sport and route, plus heart rate when available and permitted;
- optional nutrition data such as products, meals, amounts, nutrients, estimates and notes;
- optional body measurements, weight, goals and progress information;
- permissions and assignments used to share selected information with a coach;
- support messages and technical logs such as IP address, time, device, browser, app version, error and security data.
Purposes and legal bases
We process data to provide the account and functions you request, perform a contract under Article 6(1)(b) GDPR, and maintain security, diagnose errors and prevent abuse under Article 6(1)(f) GDPR. Where required, voluntary device permissions and optional processing rely on consent under Article 6(1)(a) GDPR.
Apple Health and Health Connect
After explicit permission, the mobile app can read workouts and heart rate from Apple Health or Health Connect. The current direction is read-only import. We do not currently write training, nutrition or body data back. Change permissions in the operating system. Revoking permission prevents new imports; information already imported remains in storage until you delete it or delete your account.
Intervals.icu and other integrations
When you connect Intervals.icu, we process the access, account and activity data required for the import. Recognisable duplicate activities may be reconciled into one shared record and missing metrics may enrich it. Other direct connections become part of this policy only when they are actually offered.
Coaching and sharing
Coaching functions process only training and progress data intended for the collaboration and shared by the user. Users decide what they share. When collaboration ends, the user retains their own history unless they delete it.
Hosting, email and technical providers
The website, app, API, database, backups and technical email may be operated by processors. The final hosting, email, analytics, payment and AI providers must be confirmed in the release checklist and this policy updated where necessary.
Cookies and local storage
We use necessary cookies and local storage for login, sessions, CSRF protection, security, language and requested functions. Optional analytics or comfort services may only be enabled after a valid choice. See the cookie settings for details.
Retention and deletion
Account, training, nutrition, body measurement and coaching data are generally retained until users delete the data or their account. Technical logs are retained only as long as required for operation, security and diagnosis. Contract and billing information may be subject to legal retention periods. Backups are overwritten under the technical deletion cycle, which must be documented before release.
Recipients and international transfers
Recipients may include hosting, email, support, analytics, payment and integration providers, and authorised public bodies. Transfers outside the European Economic Area use a legally recognised safeguard where required. We do not sell personal data or provide health or training data to data brokers for personalised advertising.
Automated processing and estimates
Optional AI or estimation features may prepare nutrition entries or other suggestions. Results remain editable and are not medical diagnoses or decisions with legal effect. Providers and data flows must be documented before activation.
Your rights
Subject to legal requirements, data subjects have rights of access, rectification, deletion, restriction, data portability and objection. Consent may be withdrawn for the future. Send requests to tobias@mmsetc.de. You may also lodge a complaint with a data protection authority.
Changes
We update this policy when functions, recipients, data categories, retention periods or integrations change materially.