Skip to main content

Privacy Policy

Last updated: May 2026

1. Responsible Party

The responsible party for data processing on this website is:

Stefan Pasch

Alte Bäckerei 9, 19057 Schwerin

Email: stefan.pasch@gmail.com

A data protection officer is not required under § 38 BDSG, as the statutory thresholds are not met.

2. Overview of Data Processing

We process the following categories of personal data:

  • Account data: Name, email address, hashed password
  • Session data: Session tokens, IP address, device information
  • Workout logs: Exercises, sets, reps, weights, timestamps
  • Technical data: Browser type, operating system, access times
  • Security data: TOTP secret (encrypted at rest), backup codes (hashed), email verification tokens (time-limited).
  • Audit log: Records of security-relevant events (login, 2FA activation, password change) for abuse prevention — retained for 90 days.

3. Legal Basis

We process your data on two legal bases:

  • Account and workout data: Art. 6(1)(b) GDPR (performance of a contract). The provision of the training tracking service requires processing of this data.
  • Technical log data (IP addresses, browser and OS identifiers, access times): Art. 6(1)(f) GDPR (legitimate interest — security, stability, abuse prevention). You may object to this processing pursuant to Art. 21 GDPR.

4. Cookies

We use only a technically necessary session cookie to maintain your login state. This cookie is exempt from the consent requirement under § 25(2) No. 2 TTDSG (technically necessary to deliver the service requested by the user); see also Art. 5(3) of the ePrivacy Directive.

9. Analytics and Tracking

REPPPS does not use analytics, advertising, or non-essential cookies. The only persistent storage on your device is your authenticated session and the workout data you create. No tracking pixels, no third-party analytics scripts, no cross-site identifiers. If this changes in the future, a consent UI will be added before any new storage is set, and this policy will be updated.

10. Subprocessors

A full list of subprocessors and their data transfer mechanisms is available on our subprocessors page.

5. Third-Party Services

We use the following third-party services for operating this application:

  • Vercel (Vercel Inc., USA) -- Hosting and deployment. Data transfer to the USA is covered by the EU-US Data Privacy Framework (DPF).
  • Turso (Chiselstrike Inc., USA) -- Database hosting. Data transfer secured via Standard Contractual Clauses (SCCs).
  • Resend (Resend Inc., USA) -- Transactional emails. Data transfer secured via SCCs.
  • Upstash (Upstash Inc., USA) -- Rate limiting and caching. Data transfer secured via SCCs.

6. Data Retention

We retain your data for the following periods:

  • Account data: Until account deletion
  • Session data: 30 days after last activity
  • Workout data: Until account deletion
  • Technical logs: 90 days

7. Your Rights

Under the GDPR, you have the following rights:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)

To exercise your rights, please contact us at the email address listed above.

8. Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data violates the GDPR. The competent supervisory authority is the data protection authority of the state in which you reside.