fin Privacy

Your data
is yours

Version: 12 August 2026 · Applies to the fin app and the web version

This is a translation for your convenience. The legally binding version is the German one at datenschutz.html. In case of any discrepancy, the German text prevails.

In short

  • Your training data is health data. We only process it with your explicit consent.
  • You decide for every single session whether it stays private or appears in your feed.
  • You can delete your account and all its data directly in the app — immediately and permanently.
  • No advertising in the app, no tracking, no selling data to brokers.
  • Weight, heart rate and sleep from Apple Health stay on your device.
  • Sessions from other apps are imported one by one, deliberately.
  • Notifications go through Apple and can be switched off at any time.
  • Health data is never used for advertising.

Controller

The controller for the processing of personal data in the fin app is:

Tim Bodon · gymmittim
Benzstraße 5
48683 Ahaus, Germany
Email: support@fin-tracker.de
VAT ID: DE355247617

No data protection officer has been appointed; the conditions of § 38 BDSG (German Federal Data Protection Act) are not met.

Overview

fin records and analyses your strength training. In doing so we process data that qualifies as a special category of personal data under Art. 9 GDPR – in particular your training and body data.

For this data we obtain explicit, separate consent. Without it, the core function of the app cannot be used.

Values we read from Apple Health are processed exclusively on your device. The one exception is workouts from other apps that you deliberately import into your history and share. See section 6.

We do not run advertising, we do not track for advertising purposes, and we do not sell data. No third-party analytics or advertising SDKs are embedded.

User account

Data
Email address, password (stored only as a cryptographic hash), username, time of registration and confirmation, optionally profile picture and bio
Purpose
Setting up and managing your account, authentication, associating your data, syncing between your devices
Basis
Art. 6(1)(b) GDPR – performance of the contract of use
Retention
Until the account is deleted – the data is then removed immediately and in full

Confirming your email address

After registration we send you an email with a confirmation link. Until you confirm, the account cannot be used fully. This prevents anyone from registering someone else’s address. Legal basis: Art. 6(1)(b) and (f) GDPR.

Sex, height and weight during setup

During setup you may voluntarily provide your sex, your height and your current weight. We use sex to show you the correct additional weights in competition formats such as Hyrox; weight forms the starting point of your weight history. All three are visible only to you and appear neither in the feed nor on share cards.

Legal basis: Art. 6(1)(b) GDPR, for body measurements in conjunction with Art. 9(2)(a) GDPR. All entries are voluntary and can be skipped; without them we show default values. You can change or remove them in your profile at any time.

Profile picture and bio

Both are voluntary and visible to anyone who opens your profile or follows you. Legal basis is Art. 6(1)(a) GDPR – you give consent by uploading. You can change or remove both in the app at any time.

Promotional emails to subscribers

If you have taken out a subscription, we inform you by email about new features in fin and about our own similar offerings related to the app.

Data
Email address, username, time the contract was concluded, and a note of any objection
Purpose
Direct marketing for our own services similar to the subscription
Basis
Art. 6(1)(f) GDPR in conjunction with § 7(3) UWG (German Act Against Unfair Competition) – legitimate interest in direct marketing to existing customers
Retention
For as long as your account exists. A record of an objection is kept beyond that so we do not contact you again

We obtained your address in connection with your subscription. Users without a subscription do not receive promotional emails.

You can object to the use of your address for advertising at any time – via the unsubscribe link at the end of every email, in the app settings, or informally to support@fin-tracker.de. This costs you nothing beyond basic transmission rates.

After an objection you will receive no further promotional emails. Messages required to use the app – such as confirming your address or resetting your password – are not affected.

Sending is handled by the same provider as our other emails, see section 12. Your address is not passed to third parties for advertising purposes.

Training data

Data
Training plans with name, focus and colour; exercises including ones you create yourself; weight, repetitions and sets; session duration, rest times and date; calculated volume; personal records; rest days and sick days; streak history
Purpose
Core function of the app – recording, analysing and displaying your training over time
Basis
Art. 6(1)(b) in conjunction with Art. 9(2)(a) GDPR – explicit consent to the processing of health data
Retention
Until you delete the entry or your account

Workouts imported from Apple Health become ordinary entries and are subject to the same rules; see section 6.

Training data allows conclusions to be drawn about your physical condition and is therefore health data within the meaning of Art. 4(15) GDPR.

Body weight

Data
Weight values with timestamps that you record during setup or later in the app; optionally your height
Purpose
Showing how your weight develops over time and in charts
Basis
Art. 9(2)(a) GDPR – explicit consent
Retention
Until you delete the entry or remove your account

Weight data is visible only to you. It does not appear in the activity feed, in friends’ views, or on share cards.

Apple Health

fin can work together with Apple Health if you want it to. This connection is voluntary; without it the app works fully, but certain analyses remain empty.

What fin reads from Health

Only if you enable the connection in settings and grant permission in the iOS authorisation dialog:

Data typeUsed for
Heart rate, resting heart rate, heart rate variability Calculating your training readiness on the home screen
Sleep data
Steps and active energyPutting your daily activity in context
Body weightImporting into your weight history
Workouts recorded by other apps Displayed for selection in the history view – see below

What happens to this data

Body weight, heart rate, sleep, steps and energy never leave your device. They are processed locally only, serve to display your recovery values and your weight curve, and are not transmitted to our servers.

A special rule applies to workouts from other apps, which we want to point out explicitly:

fin shows you a list of these sessions in the history view. Nothing is imported automatically – you decide for each individual session, by tapping it, whether it is added to your fin history. Workouts already recorded by fin itself do not appear in this list.

A session you import becomes an ordinary fin entry. The same rules apply as for any workout recorded in fin: by default it is visible only to you. Only when you explicitly share it is it stored on our servers and made visible to the audience you choose.

In that case the following is transmitted: sport type, start, duration, distance where applicable, and the name of the app that recorded the session. Heart rate, sleep and weight data are not transmitted.

What fin writes to Health

If you allow it, fin stores the workouts you record in the app, along with the active calories burned, as sessions in Health so that your activity there is complete. You can revoke this permission at any time.

Legal basis

Health data is processed solely on the basis of your explicit consent (Art. 6(1)(a) in conjunction with Art. 9(2)(a) GDPR). You give this consent in two steps: once through the iOS authorisation dialog, and a second time for every session you import into fin and share.

Withdrawal

  • You withdraw the Health permission in the iOS settings under Privacy & Security → Health → fin. fin will then read no further data.
  • You delete sessions you have already imported in fin like any other workout. If a session was shared, it is thereby also deleted from our servers.
  • Withdrawal does not affect the lawfulness of processing carried out up to that point.

We use Health data exclusively within the app. It is not used for advertising, marketing or data mining – this is additionally prohibited by Apple’s App Review Guideline 5.1.3. Health data is not stored in iCloud.

If we later extend the scope of permissions, we will ask for your explicit consent again.

Social features

fin includes features that let you connect with other people.

Search and following

Others can find you via your username and follow you. We process username, profile picture, bio and the following relationships. Legal basis: Art. 6(1)(b) GDPR.

Activity feed

People who follow you see completed workouts with name, duration, number of sets and exercises, and the names of the exercises included – provided you have shared the session.

Visibility per session

SettingVisible to
Privateonly you
Sharedpeople who follow you

Because training data is health data, passing it on to third parties is a separate act of processing. By sharing a session you explicitly consent to this – legal basis: Art. 9(2)(a) GDPR. You can set a shared session back to private at any time; it then disappears from the feed.

Anything that was once visible in the feed may have been copied or saved by others. We have no influence over such copies.

Comments and reactions

Data processed: the text of your comments, reactions given, the time, and the association with your account and the session in question.

Comments and reactions are visible to everyone who can see the session concerned. They are shown with your username and profile picture. Legal basis: Art. 6(1)(b) GDPR.

You can delete your own comments at any time. If the associated session is deleted or set to private, the comments on it disappear as well.

Follow requests

If you want to follow someone, a request is stored and shown to that person – with your username, your profile picture and the time. We store accepted, declined and pending requests until the relationship ends or one of the two accounts is deleted. Legal basis: Art. 6(1)(b) GDPR.

In-app notifications

We store records that someone has followed you, commented on your session or reacted to it, so that we can show them to you in the app. Read notifications are removed after 90 days at the latest. Legal basis: Art. 6(1)(b) GDPR.

Reporting and blocking

You can report content and block accounts. We store the report with the time, the reported content and your account, in order to review it. Blocks are stored as a relationship between the two accounts. Legal basis: Art. 6(1)(f) GDPR – legitimate interest in a safe platform, and Art. 6(1)(c) GDPR where legal obligations apply.

Sharing content

The share function creates graphics summarising your workout, your volume or the muscle groups you trained.

The graphics are created on your device. They are not transmitted to us. As soon as you share a graphic in another app or on a social network, that provider’s privacy terms apply. Since the graphics contain training data, consider the audience before sharing.

Notifications

Training reminders

fin schedules training reminders locally on your device. No data is transmitted to us or to third parties for this.

Legal basis: Art. 6(1)(a) GDPR – you give consent via the iOS system dialog.

Alerts about social events

For alerts about social events – new followers, follow requests, likes, comments and cheers during a running workout – fin uses Apple’s push service.

Data
A device token that your device receives from the operating system and that we store together with your account; the content of the respective message
Purpose
Delivering the notification to your device
Basis
Art. 6(1)(a) GDPR – consent via the iOS system dialog
Retention
The token is deleted as soon as you sign out or delete your account

The message contains the name of the person who triggered it and, where applicable, the name of the workout concerned. To deliver it we transmit the token and the message to the Apple Push Notification service (Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA). Where data is transferred to the USA, this is based on the European Commission’s standard contractual clauses under Art. 46(2)(c) GDPR or on an adequacy decision under the EU-US Data Privacy Framework.

Depending on your settings, notifications also appear on the lock screen. If you do not want others to be able to read the content, set Notifications → Show Previews in the iOS settings to When Unlocked.

You can switch notifications off at any time in the iOS settings under Notifications. We do not use them for advertising.

Sync and technical log data

Your data is synchronised between your devices. Where versions conflict, we merge the records rather than overwriting them.

When you access our servers we process technically necessary data: IP address, time of the request, endpoint called, status code, amount of data transferred, and the type and version of the client. The purpose is providing the service, defending against attacks and analysing errors. Legal basis: Art. 6(1)(f) GDPR. Server logs are deleted automatically by our hosting provider after seven days at the latest.

Use in a browser

fin can also be used as a web app. In that case we store only technically necessary information in your browser’s local storage – in particular your sign-in token and settings such as light or dark appearance.

Legal basis: § 25(2)(2) TDDDG in conjunction with Art. 6(1)(b) GDPR. Consent is not required because we do not use any analytics or marketing technologies. We do not use cookies for analytics or advertising.

Recipients and processors

Hosting, database and authentication

Supabase – server location: European Union. Supabase provides hosting, database operation, authentication and storage of uploaded files on our behalf. A data processing agreement under Art. 28 GDPR is in place.

Data is stored on servers within the European Union. Where access from a third country occurs exceptionally in the course of support or maintenance, this is based on the European Commission’s standard contractual clauses under Art. 46(2)(c) GDPR.

Sending system emails

Confirmation and password emails are sent via the infrastructure of Supabase. The same data processing agreement under Art. 28 GDPR applies as for hosting.

Apple

The app is obtained through the App Store. Apple processes data there as its own controller; we have no influence over this.

In addition, we transmit notifications via the Apple Push Notification service, see section 9.

Beyond this we do not pass data to third parties unless we are legally required to do so or you have explicitly consented.

Deleting your account

You can delete your account at any time directly in the app: Profile → Settings → Delete account.

The following is removed: account data, username, profile picture, bio and sex, all training data and training plans, body weight data, following relationships and pending follow requests, your entries in the activity feed, your comments and reactions, your notifications, and reports and blocks you have submitted.

Deletion is immediate and complete: all associated records are deleted in the same transaction, leaving no remnant in another table. Backups, where they exist, are overwritten after seven days at the latest. Excepted is data we are required to retain under statutory retention obligations; we block that data for all other purposes. Alternatively, an informal message to support@fin-tracker.de is sufficient.

Minimum age

Use of fin is permitted from the age of 16. Processing health data requires explicit consent, which in Germany can be validly given by the person themselves from the age of 16.

If we become aware that an account is held by a younger person, we will delete it.

Your rights

You have the right at any time to:

  • Access the data stored about you (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability in a structured, commonly used and machine-readable format (Art. 20 GDPR)
  • Object to processing based on legitimate interests (Art. 21 GDPR) – for direct marketing at any time and without giving reasons
  • Withdraw consent with effect for the future (Art. 7(3) GDPR)

Send requests to support@fin-tracker.de. We respond within one month.

Right to complain

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2–4
40213 Düsseldorf, Germany

Data security

Transmission between the app and the server is encrypted exclusively via TLS. We never store passwords in plain text, only as a salted hash.

Access to the database is restricted on all tables by row level security. Every user can access only their own data and content that has been shared with them.

Changes to this policy

We adapt this privacy policy when the legal situation or the scope of the app changes. We inform you in the app about significant changes. For extensions affecting additional categories of health data, we obtain fresh explicit consent.