1. Controller
The controller for wucht.app, account.wucht.app and the WUCHT app is Leon Koopmann, In den Fuhren 20, 29646 Bispingen, Germany. Email: wuchtapp@gmail.com.
For privacy requests, contact wuchtapp@gmail.com.
2. Overview
This policy distinguishes visits to our website from use of the app and optional online features. The app is in development. Available optional features depend on your platform and app version.
The local training core works without an account. Training, nutrition and health data is kept on your device. An optional account enables encrypted backup and other online features, which require an internet connection.
3. Website delivery and hosting
The wucht.app website is delivered through OpenAI Sites on Cloudflare infrastructure. The providers involved process technically necessary connection data, in particular IP address, time, requested address, browser/device information and, where available, the referring page. This enables delivery, availability, troubleshooting and abuse prevention.
Providers include OpenAI for Sites and Cloudflare, Inc. for infrastructure and security. See the OpenAI privacy policy and Cloudflare privacy policy. Our website maintains no visitor database of its own and embeds no advertising pixel or social-media feed.
Technical access data is processed for delivery and, where necessary, security and troubleshooting. The scope and retention of provider-level logs depend on the service and security purpose. WUCHT does not keep it indefinitely for its own advertising profiles. Contact us for information about a specific access.
4. Cookies and external links
Cloudflare may set the technically necessary __cf_bm bot-protection cookie. It helps identify automated traffic and, according to Cloudflare, expires after 30 minutes of inactivity. It is not an advertising or analytics cookie placed by WUCHT. See Cloudflare cookies.
Where cookies are strictly necessary to securely provide the service expressly requested, storage and access rely on Section 25(2)(2) TDDDG. Subsequent processing of personal data relies on the legitimate interest in security and availability described above. This policy does not activate any marketing technology requiring consent.
Instagram and app-store pages are ordinary external links. Opening a link takes you to that service, where its privacy policy applies. Website images and fonts are delivered with this website, without an embedded Instagram feed.
5. Contact and early-test enquiries
If you contact us by email, we process your sender address, message and information you include to answer your enquiry. This also applies to personal enquiries about an early test phase. Such an enquiry does not automatically subscribe you to a newsletter and does not guarantee access.
Our contact mailbox wuchtapp@gmail.com uses Gmail (Google). Do not send passwords, recovery codes or complete health records. For technical questions, your platform, app version and a short error description will usually suffice.
Correspondence is retained as long as necessary to handle and document the resolution of your enquiry. It is then deleted unless legal retention obligations or specific legal claims require longer retention.
6. Data we process
Account data: email address, display name and password (stored only as a scrypt hash) plus session data (valid for 30 days). For email verification, we store only a hashed one-time code for no more than 8 hours; for password resets no more than 15 minutes.
Sync data: a client-side AES-256-GCM encrypted envelope. The server cannot read its content (zero-knowledge principle).
Billing data: store purchase receipts, subscription status and entitlements, plus store events (Google Play RTDN / App Store Server Notifications) for server-side receipt validation.
Push: device tokens for optional notifications (Android: Firebase Cloud Messaging).
Support: the content of your support requests (in the app or by email).
Health Connect / Apple Health: only after your explicit permission. WUCHT can read weight, steps and active energy; write confirmed weight plus completed workouts with estimated active energy; and, after a separate opt-in, read HRV, sleep and resting heart rate for cautious plan adjustments. Data is processed locally and, when sync is enabled, transferred only inside the client-encrypted envelope.
Voice input: after you visibly start it, microphone audio and the transcript are processed temporarily on the device. They are not stored or transmitted; only set values you confirm are saved.
Local AI explanation: on compatible devices, a local model can rephrase an already rule-based weekly decision in a labelled additional sentence. No data is sent to an AI cloud provider for this, and the static rule basis remains authoritative.
7. Legal bases
Website delivery and technical abuse prevention: Art. 6(1)(f) GDPR. Our legitimate interest is a secure and reliably accessible website.
Accounts and online services you request: Art. 6(1)(b) GDPR. Optional consent-based features, in particular health connections, push and optional telemetry: Art. 6(1)(a) GDPR. Where special categories of personal data are processed, we rely on your explicit consent under Art. 9(2)(a) GDPR. You can withdraw consent at any time with effect for the future.
Contact and support: Art. 6(1)(b) GDPR for contract-related requests; otherwise Art. 6(1)(f) based on our interest in answering enquiries. Legally required retention is based on Art. 6(1)(c) GDPR.
8. Recipients
Hosting: Hetzner Online GmbH, EU (region FSN1) – server operations. Transactional account email: Resend, Inc. (email verification, password resets and security confirmations). Payments: Google Ireland Ltd. (Google Play) or Apple Distribution International (App Store). Push: Google Firebase Cloud Messaging. Store events: Google Cloud Pub/Sub. Only with separate consent and when configured in the build: Sentry (error diagnostics) and TelemetryDeck (product usage).
We do not sell personal data or share training data for advertising. Optional error diagnostics and product analytics are described in the “Optional telemetry” section.
9. International transfers
Our account server is hosted by Hetzner in Germany. Website, email, platform and other providers may also process data outside the EU/EEA, particularly in the United States. We therefore do not promise exclusively European processing.
Transfers are subject to Articles 44 et seq. GDPR, such as an applicable adequacy decision or appropriate safeguards including EU Standard Contractual Clauses. You can request information and copies of the safeguards used for a service at wuchtapp@gmail.com. The linked website-provider policies below explain their international transfers.
10. Retention
Account: until deletion. Sessions: 30 days. Server backups: currently retained locally for up to 14 days. Encrypted off-site replication is planned but not yet active; this policy will be updated before it is enabled. Store events: as long as required for subscription management and legal obligations.
After account deletion, the account, sync data, entitlements and push registrations are deleted – usually immediately, at the latest within 30 days.
11. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR). Send requests to wuchtapp@gmail.com.
You also have the right to lodge a complaint with a data protection supervisory authority.
You can withdraw consent in the relevant settings or by email without affecting the lawfulness of earlier processing. You may object to processing based on legitimate interests on grounds relating to your particular situation, and to direct marketing at any time. The regional authority for our registered address is the Lower Saxony data protection authority.
12. Account deletion
You can delete your account at any time in the app (Profile → Account → “Delete account”) or via the public instructions at /account/delete. Active subscriptions must be cancelled separately in the respective store.
13. Optional telemetry
WUCHT contains no advertising or advertising tracking. Error diagnostics and product analytics are off by default and require your separate consent. If provider identifiers are not configured in the build, nothing is transmitted even after consent.
With error diagnostics enabled, Sentry may receive technical error, stack, app and operating-system information; WUCHT does not send account identifiers, training, body, health or nutrition values, or console/HTTP content. With product analytics enabled, TelemetryDeck may receive a randomly generated anonymous installation identifier, app interactions, platform and app version. Withdrawal stops new analytics signals; fully ending native error collection requires an app restart.
14. Medical disclaimer
WUCHT is a training companion, not a medical device and not a substitute for medical advice. If you have health concerns or pre-existing conditions, consult a doctor before starting training.
15. Status
6 September 2026. Changes will be published on this page.