Diese Seite auf Deutsch

Privacy Policy

1. Controller

The controller within the meaning of the GDPR is:

ARK85 UG (haftungsbeschränkt)

Oeverseestraße 25, c/o Kraschewski

22769 Hamburg, Germany

Managing Director: Alessandro Kraschewski

HRB 192872, Amtsgericht Hamburg

Contact for data protection matters: info@ark85.org

2. General information about our processing

We take your privacy seriously. This privacy policy tells you which personal data we process, for what purpose, and on what legal basis this happens.

The connection between your device and the services we use is encrypted with TLS according to the current state of the art. This does not apply in the same way to email, see section 5.

3. Hosting and data storage

3.1 Vercel (hosting provider)

Our website is hosted on servers of Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA.

Data processed:

  • Visitor's IP address
  • Browser and device information
  • Time and duration of access
  • Pages visited and referrer
  • Server log files (automatically)

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing this website in a technically stable and secure way)

Processing agreement: We have concluded a Data Processing Agreement (DPA) with Vercel. Vercel undertakes to process personal data only on our instructions.

Transfer to the USA: Vercel stores data in the USA. The transfer rests on standard contractual clauses (SCC) and the EU-US Data Privacy Framework.

Vercel privacy policy: https://vercel.com/legal/privacy

Retention: How long the server log files are kept is governed by Vercel. We do not evaluate them and keep no copies of our own.

3.2 Vercel Web Analytics (reach measurement)

We measure the use of this website with Vercel Web Analytics. Recorded are the pages you open, the referrer, an approximate region of origin, and your browser and device type. From this Vercel derives an identifier that is calculated from the data of the request, changes regularly and is not stored permanently. No cookies are set for this.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in learning which content is read). Because no cookies are set and no information is read from your device, § 25 TDDDG does not apply and consent is not required for this.

Objection: You can object to the measurement at any time, using the button in the notice at the edge of the page. We remember your decision locally in your browser, see section 6. From then on you are no longer counted.

Transfer to the USA: Processing takes place in the USA. The basis is the standard contractual clauses of the EU Commission.

3.3 Sanity (content and images)

We maintain the content of this website in Sanity, a service of Sanity AS, Oslo, Norway. Images in our blog posts are loaded directly from Sanity's servers. Your IP address is transmitted to Sanity in the process. This is technically necessary for the image to be delivered to your browser. We pass on no further data.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in fast and stable delivery of content). Norway is part of the European Economic Area.

4. Website newsletter – Kit (ConvertKit)

4.1 Sending the newsletter

This section concerns only the newsletter you subscribe to through a form on this website. The app contains no newsletter signup. If you create an account in the app, your email address is not transmitted to Kit, and you receive no newsletter.

To send our newsletter we use ConvertKit, a newsletter service of ConvertKit LLC, 2121 N California Blvd STE 290, Walnut Creek, CA 94596, USA.

Data collected when you subscribe:

When you subscribe to our newsletter, the following data is collected:

  • Email address
  • Name (optional)
  • Timestamp of your signup and of your confirmation

Legal basis: Art. 6(1)(a) GDPR (consent). For signups through the forms on this website we use the double opt-in procedure: you receive a confirmation email, and your subscription becomes active only after you confirm. Without that confirmation we send no newsletter to your address.

Processing by ConvertKit:

ConvertKit processes the data named above to send the newsletter and to record usage data such as:

  • Email open rates
  • Clicks on links
  • Unsubscribes

This data helps us improve the newsletter and make it more relevant to you.

Processing agreement: We have concluded a Data Processing Agreement with Kit. Within its scope Kit processes the data on our instructions.

Transfer to the USA: ConvertKit is a US company. Your data is stored on servers in the USA. The transfer rests on standard contractual clauses (SCC) of the EU Commission.

Embedded script: On individual pages of this website, for example the waitlist, we embed a signup form directly from Kit. Your browser then loads a script from Kit's servers, and your IP address is transmitted to Kit as soon as the page loads, whether or not you submit the form. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing the form).

Retention: We store your subscription data until you unsubscribe. After that we keep your email address and the record of your consent, so that we can honour your unsubscribe permanently and prove the consent in case of dispute. The legal basis is Art. 6(1)(f) GDPR. On your request we delete this record too.

Right of withdrawal (Art. 7(3) GDPR): You can withdraw your consent at any time with effect for the future. The lawfulness of the processing carried out until then is unaffected. Every newsletter contains an "unsubscribe" link.

ConvertKit privacy policy: https://convertkit.com/privacy

ConvertKit contact: privacy@convertkit.com

5. Contacting us

5.1 Contact by email

On our website you can reach us by email at info@ark85.org.

Processing:

When you send us an email, the following data is processed:

  • Your email address
  • The content of your message
  • All data transmitted with it

Legal basis: Art. 6(1)(b) GDPR (performance of a contract) or Art. 6(1)(f) GDPR (legitimate interest)

Retention: Your data is stored only for as long as it is needed to handle your enquiry. After that it is deleted, unless statutory retention obligations apply.

Important note: Emails are transmitted unencrypted. We recommend not sending confidential or sensitive data by email.

6. Cookies and your choice

This website sets no advertising or tracking cookies. The reach measurement described in section 3.2 also works without cookies.

If you object to the reach measurement, we store that decision in your browser's local storage, so that we honour it on every further visit. That entry does not leave your device.

Legal basis: § 25(2)(2) TDDDG. Storing your objection is technically necessary in order to honour it.

7. The the25percent app

Sections 7.1 to 7.7 concern our mobile app only. Sections 3 to 6 concern this website only and do not apply to app users. Sections 1, 2 and 8 to 12 apply to both.

7.1 Firebase Authentication (signup and login)

For signup and login we use Firebase Authentication, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Data processed:

  • Email address
  • Your password, stored in an encrypted form it cannot be reversed from. We cannot read it either.
  • User ID
  • Time of account creation and of the last login. Firebase writes these timestamps for technical reasons, they serve account security and we do not evaluate them for usage statistics.

Login works with email address and password only. We offer no login through Apple, Google or any other third party.

Legal basis: Art. 6(1)(b) GDPR (performance of the user agreement)

Whether you have to provide this: We need email address and password to create an account. There is no statutory or contractual obligation to provide them, but without them the app cannot be used.

Processing agreement: The Google Cloud Data Processing Addendum applies. Within its scope Google processes the data on our instructions. For a few of its own purposes, such as billing and abuse prevention, Google is an independent controller.

Storage location: For login data Firebase allows no choice of region. Processing in the USA is therefore possible. Your training data, by contrast, stays in the EU, see 7.2. For the USA the standard contractual clauses of the EU Commission apply.

Retention: Until you delete your account, see 7.6.

7.2 Cloud Firestore (profile and training data)

We store your profile and training data in Cloud Firestore, also a service of Google Ireland Limited.

Needed to use the app:

  • First name or display name
  • Date of birth, sex and height
  • Onboarding answers: training experience, goals, units of measurement
  • Training history: completed resistance sessions, Zone 2 minutes, high-intensity sessions with your own intensity rating, mindfulness sessions
  • Streaks and personal records
  • The time of your training reminder

We collect date of birth, sex and height solely to put your training and body values in context, for example for age- and sex-dependent reference ranges. No evaluation for demographic or advertising purposes takes place.

Legal basis: Art. 6(1)(b) GDPR. We need these entries to keep the training record that you use the app for.

Voluntary entries:

Body weight and body fat percentage are processed only if you enter them. They improve how your values are put in context but are not required to use the app. You can skip them during onboarding and change or remove them in your profile at any time.

How this is categorised: Body weight, body fat percentage and mindfulness sessions are health data. Training history, streaks, personal records and your training experience are fitness data. We process both solely to keep your training record and do not pass them on.

You enter all of this yourself. The app reads no data from Apple Health, Google Fit, a watch, a chest strap or any other interface.

Storage location: Your profile and training data are held in data centres in the Netherlands and in Belgium, not in the USA (Google region eur3). For maintenance and support, Google staff may also access them from outside the EU, for example from the USA. The standard contractual clauses of the EU Commission apply to that.

No further use by Google: Google may not use your data for its own other products. We have switched that setting off in Firebase.

Retention: Until you delete your account. There is no automatic deletion after a fixed period.

Google privacy policy: https://firebase.google.com/support/privacy

7.3 RevenueCat (subscription management)

To manage subscriptions we use RevenueCat, Inc., 1032 E Brandon Blvd #3003, Brandon, FL 33511, USA.

Data processed:

  • User ID (the same identifier as in Firebase Authentication)
  • Subscription status: active, cancelled, expired, renewal date
  • Subscription purchase history

Legal basis: Art. 6(1)(b) GDPR (performance of the user agreement)

Aggregated analysis: RevenueCat provides us with a dashboard of summarised metrics on the subscription business, such as the number of active subscriptions, renewals and churn rate. It is based on the purchase and status data named above. No tracking across third-party apps or websites takes place. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in running the business).

Processing agreement: The RevenueCat Data Processing Addendum applies to the processing, which forms part of their terms of service.

Transfer to the USA: RevenueCat processes data in the USA. The basis is the standard contractual clauses of the EU Commission.

Retention: The subscription record stays with RevenueCat for as long as the subscription exists. For deletion after you close your account, see 7.6.

RevenueCat privacy policy: https://www.revenuecat.com/privacy

7.4 Payment through Apple and Google

You take out your subscription in Apple's App Store or on Google Play. It is billed there as well. The payment contract is between you and Apple or Google, not with us.

We never receive your payment details. Card number, bank details and billing address lie with Apple or Google alone. All we learn is whether a valid subscription exists.

Legal basis: Art. 6(1)(b) GDPR. We check the receipt passed to us in order to unlock the paid features for you.

Cancellations and refunds are handled by Apple and Google as well. Their own privacy policies apply to the processing there.

7.5 Training reminders

If you set up a training reminder, the time you choose is stored in your profile. The reminder is scheduled and triggered on your device. The legal basis is Art. 6(1)(b) GDPR, see 7.2.

7.6 Deleting your account and your data

You can delete your account at any time, in the app under Profile → Settings → Delete account. Without the app installed, an email to support@the25percent.app is enough.

Deletion removes your login credentials, your profile and onboarding answers, your training history including streaks, and your reminder setting.

With our subscription provider RevenueCat (see 7.3) a record with your user ID and subscription status remains at first. We arrange for its deletion, unless commercial or tax retention obligations stand in the way.

Processing time: We handle email requests by hand, without undue delay and in any case within one month of receipt. Where a request is exceptionally complex, that period may be extended by up to two further months under Art. 12(3) GDPR. We will tell you about that within the first month. Deleting directly in the app takes effect immediately.

Verifying your identity: Where there are reasonable doubts that a request comes from you, we may ask for further information about your identity (Art. 12(6) GDPR). This protects your account from being deleted by someone else.

This does not cancel your subscription. It continues with Apple or Google and has to be cancelled there separately. Invoices and accounting records must be kept by law for up to ten years, so those documents remain.

You will find detailed guidance at the25percent.app/support.

7.7 What the app does not collect

As things stand today, and this is unusual for fitness apps:

  • No analytics or tracking SDKs in the app. We use neither Firebase Analytics nor any comparable tool that records your behaviour in the app. The only analysis concerns aggregated subscription metrics at RevenueCat, see 7.3.
  • We embed no service for automatic crash reports.
  • No advertising and no advertising identifiers. Not Apple's advertising ID (IDFA) either, nor Android's.
  • No passing of data to data brokers.
  • No location data.
  • No photo or video uploads and no free note or diary fields. The only free text you choose is your display name.
  • No connection to wearables or other fitness apps.

No automated decision-making: There is no automated decision in an individual case, including profiling, within the meaning of Art. 22 GDPR. The app evaluates your entries to display your streak, weekly progress and personal records. No decision follows from that which produces legal effects concerning you.

8. Your rights as a data subject

Under the GDPR you have the following rights:

  • Right of access (Art. 15 GDPR): You can request information about the processing of your personal data.
  • Right to rectification (Art. 16 GDPR): You can have inaccurate data corrected.
  • Right to erasure (Art. 17 GDPR): You can request the deletion of your data. The fastest way to delete your app account and training data is to do it yourself, see section 7.6. Records we are required by law to keep are excepted.
  • Restriction of processing (Art. 18 GDPR): You can have the processing of your data restricted.
  • Right to object (Art. 21 GDPR): You can object to processing on grounds relating to your particular situation, where we base it on Art. 6(1)(f) GDPR. Against direct marketing the objection applies without exception.
  • Data portability (Art. 20 GDPR): You can request your data as a file and take it to another provider.

To exercise these rights, write to info@ark85.org. For anything concerning the app you can also reach us at support@the25percent.app.

9. Objecting to advertising and marketing

This objection concerns the newsletter and other marketing communication you signed up for on this website. To do so, send an email to info@ark85.org. We do not use data from the app for advertising or marketing, and we do not pass it on for that purpose either.

10. Lodging a data protection complaint

You have the right to lodge a complaint with a supervisory authority. You may approach the authority of your residence, your place of work, or the place of the alleged infringement. The authority responsible for us is:

Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit

Ludwig-Erhard-Straße 22, 20459 Hamburg, Germany

Phone: +49 40 428 54-4040

Email: mailbox@datenschutz.hamburg.de

11. Currency of this privacy policy

We update this privacy policy as soon as the processing described here changes. The version currently published on this page is the one that applies.

This English version is a translation provided for convenience. In case of any discrepancy between the language versions, the German version prevails.

Last updated: 5 August 2026. Section 7 on the mobile app has been added.

12. Contact

If you have questions about data protection, please contact us at:

Email: info@ark85.org

Postal address:

ARK85 UG (haftungsbeschränkt)

Oeverseestraße 25, c/o Kraschewski

22769 Hamburg, Germany