Legal

Privacy Policy

Version 1.0 — the first published version of this policy.
Effective date: 5 September 2026
Last updated: 5 September 2026, 10:11 CEST

01In short

Traksta is a strength-training log. You write down what you lifted; Traksta tells you what it means.

  • Your training data is yours. We do not sell it, rent it, or share it with advertisers. We never will.
  • We show no ads and use no advertising identifiers.
  • We do not track your location or read your contacts. The camera and photo library are used only when you attach a screenshot to feedback or build a share card, and those images never leave your device.
  • Traksta currently runs no analytics and no crash-reporting software at all. When we add them, they will be off until you turn them on.
  • All data we control is stored in the European Union.
  • You can export everything, at any time, in a plain format. You can delete everything, permanently.

This summary is not the whole policy. The sections below are.

02Who is responsible for your data

The controller of your personal data under the General Data Protection Regulation (GDPR) is:

Krishanu Roy
Weidmanngasse 15/45
1170 Wien, Austria

  • Legal form: Einzelunternehmen (sole proprietorship), registered in Austria
  • Business registration (GISA): 40074153
  • Trade: Dienstleistungen in der automatischen Datenverarbeitung und Informationstechnik (freies Gewerbe), registered 31 August 2026
  • Competent trade authority: Magistratisches Bezirksamt für den 9. und 17. Bezirk, Magistrat der Stadt Wien

Email: privacy@traksta.app
Website: https://traksta.app

All data protection enquiries reach us directly at the address above, and we answer them ourselves.

Our Impressum (disclosure obligations under §5 E-Commerce-Gesetz and §24 Mediengesetz) is a separate document, available at https://traksta.app/impressum.

03What this policy covers

This policy covers:

  • the Traksta mobile applications for iOS and Android;
  • the website at traksta.app, including the waitlist, which is a website feature and has no equivalent in the app;
  • support correspondence and in-app feedback.

It does not cover the App Store or Google Play themselves. When you buy a subscription, Apple or Google is the seller. They process your payment under their own privacy policies, and we never see your payment details. It also does not cover any third-party service you choose to connect to Traksta, which remains governed by that service’s own terms.

04What we collect

4.1 Account data

Collected when you create an account.

DataSourceRequired
Email addressYou, or Sign in with Apple / Sign in with GoogleYes
Display nameYou, or your Apple/Google accountYes
Password (stored only as a salted hash; we never see or store the password itself)YouOnly for email sign-up
Account creation dateAutomaticYes
Authentication provider identifierApple or GoogleOnly for social sign-in
IP address and browser/device user agent at each sign-in, stored against the session for security purposesAutomaticYes

If you use Sign in with Apple and choose Apple’s private relay, we receive a relay address and never learn your real email address. That is fine. Everything works.

4.2 Training data

This is the core of the product. It is created by you, in the app.

  • Exercises performed, and the date and time performed
  • Sets, repetitions, and load
  • Rest intervals and session duration
  • Personal records and derived progress metrics
  • Free-text notes you attach to a session or exercise
  • Routines, plans, and programme structures you build or follow

Free-text notes are stored as you write them. Please do not put information in them that you would not want stored, such as details of an injury, a medical condition, or a medication.

4.3 Body and profile data

  • Bodyweight. Optional. Used for bodyweight-exercise tracking and relative-strength statistics. You can leave it blank, and you can delete it at any time; the app works without it.
  • Height. Optional. Used alongside bodyweight for relative-strength and body-composition context. Also optional, also deletable.
  • Unit preference (kg or lb), default rest timer, weekly training-goal target, notification preference, appearance preference
  • Self-reported training experience level

4.4 Apple Health / Health Connect data (not yet active)

This integration is not built yet. Nothing described here is happening today. It is documented in advance so you know what to expect; we will announce it before it ships.

When it launches, it will run only if you explicitly connect it, and only for the data types you approve.

  • Read: bodyweight, where you allow it, so you do not have to enter it twice.
  • Write: completed strength-training workouts, where you allow it, so your training appears alongside the rest of your health record.

Health platform data is exchanged on your device between Traksta and Apple Health or Health Connect. Data read from a health platform is used solely to provide features you asked for. It is never used for marketing, never shared with any third party, never sold, and never disclosed to data brokers. You can revoke these permissions at any time in your device settings, and Traksta will stop reading and writing immediately.

4.5 Subscription data

If you subscribe to Traksta Pro, we receive from Apple or Google, via our subscription-management processor:

  • an anonymised transaction and subscription identifier;
  • your plan, its status, renewal date, trial status, and country of purchase.

We do not receive or store your card number, bank details, billing address, or full name from the store.

4.6 Usage analytics (not yet active, and consent-gated when it is)

Traksta currently collects no usage analytics. No analytics software is present in the app. Neither the analytics tooling nor the consent control that would govern it has been built.

When analytics ship, they will be disabled by default. The analytics software development kit will not be initialised, and no event will be recorded, unless and until you give consent through a control in Privacy settings. If you decline, none of the following is collected.

If you consent, we will collect product-usage events such as: screens opened, features used, workouts logged, whether a paywall was shown or dismissed, and subscription lifecycle events. Each event carries a pseudonymous identifier, your device model, operating system version, app version, and coarse country-level location derived from your IP address. The IP address is not retained on analytics events. This is specific to analytics, and does not affect the session security record described in 4.1, which does store it.

We will not send your training content, your notes, your bodyweight, your height, your email address, or your name into analytics.

4.7 Diagnostic and crash data (not yet active)

Traksta currently runs no crash-reporting or error-monitoring software.

When it ships: on a crash or error, we will collect a technical report: the error, a stack trace, device model, operating system version, app version, and the sequence of screens leading to the failure. It will be used only to fix defects.

4.8 Camera and photo library

Traksta asks for camera or photo library access in exactly two places:

  • Feedback screenshots, if you attach an image to a feedback report.
  • Share cards, if you choose a background image for a card showing a personal record or a completed session.

In both cases the image is handled entirely on your device. Feedback attachments are not uploaded to our servers, and share cards are composed and saved locally. We do not receive, store, or transmit your photos, and we never browse your library. The system picker shows you only what you select.

4.9 Support and feedback

If you email us, we hold your message, your email address, and our reply.

If you use the in-app feedback form, we hold the category you selected, your message, whether you asked for a reply, and the email address you gave for that purpose, if you asked for one. Any screenshot you attach stays on your device, as described in 4.8.

4.10 Marketing and waitlist (website only)

This section describes the traksta.app website, not the app. The app sends no marketing email and has no waitlist.

If you join the website waitlist or subscribe to product updates, we hold your email address, the date and time of your confirmed opt-in, and the IP address from which it was made. The last two are held solely as proof of consent, as Austrian and German law require. Sign-up uses double opt-in: you are not added until you click the confirmation link.

4.11 Account deletion feedback

If you delete your account, we ask why. This is optional. You can skip it and delete anyway. Any reason you give is separated from your identity and kept only in aggregate.

05What we deliberately do not collect

This list is a commitment, not a description of a current limitation.

  • Precise or background location
  • Contacts, calendar, or microphone
  • Your photo library. We access the camera and photo picker only for the two purposes in 4.8, and those images never leave your device
  • Advertising identifiers (IDFA, GAID). We run no advertising SDK of any kind
  • Cross-app or cross-site tracking
  • Nutrition or dietary intake
  • Menstrual, reproductive, or fertility data
  • Heart rate, sleep, or continuous biometric data
  • Social graph, friends, or followers. Traksta has no social feed
  • Racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric identifiers, or data concerning your sex life or sexual orientation

06Why we process it, and on what legal basis

PurposeDataLegal basis
Create and maintain your account; authenticate youAccount data (4.1)Art. 6(1)(b): performance of our contract with you
Store, sync, and display your training log; compute descriptive statisticsTraining data (4.2), profile data (4.3)Art. 6(1)(b): performance of contract, and Art. 9(2)(a): your explicit consent (see section 7)
Provide Pro analytics: plateau detection, PR forecasting, strength standards, volume balance, weekly review, exercise deep diveTraining data (4.2), bodyweight and height (4.3)Art. 6(1)(b) and Art. 9(2)(a)
Sync with Apple Health or Health ConnectHealth platform data (4.4), not yet activeArt. 6(1)(a) and Art. 9(2)(a): your explicit consent, given at the platform permission prompt
Manage subscriptions, entitlements, trials, and refundsSubscription data (4.5)Art. 6(1)(b): performance of contract
Comply with tax and accounting lawSubscription and transaction recordsArt. 6(1)(c): legal obligation (§132 Bundesabgabenordnung, §212 UGB)
Keep your account secure; detect suspicious sign-insSession IP address and user agent (4.1)Art. 6(1)(f): our legitimate interest in account security
Understand product usage and improve TrakstaAnalytics (4.6), not yet activeArt. 6(1)(a): your consent
Detect, diagnose, and fix defects; keep the service secure and availableDiagnostic data (4.7), not yet activeArt. 6(1)(f): our legitimate interest in a working, secure product
Answer your support requests and in-app feedbackCorrespondence and feedback (4.9)Art. 6(1)(b), or Art. 6(1)(f) where you are not yet a customer
Send product updates you asked forMarketing data (4.10)Art. 6(1)(a): your consent
Improve the product using deletion feedbackDeletion reasons (4.11), aggregatedArt. 6(1)(a): your consent
Establish, exercise, or defend legal claimsAs relevantArt. 6(1)(f), and Art. 9(2)(f) where special category data is involved

Where we rely on legitimate interest, we have carried out and documented a balancing test. You can ask us for a summary of it.

07Training and body data: special category data

We take a deliberately protective position. Your training history and your bodyweight can support inferences about your physical condition. We therefore treat them as data concerning health under Article 9 GDPR, and we do not process them without your explicit consent under Article 9(2)(a), even where a contractual basis alone might arguably suffice.

What this means in practice:

  • You are asked for this consent separately at sign-up, in clear terms. It is a distinct action, not a pre-ticked box, and not bundled into acceptance of our Terms.
  • You can withdraw it at any time, in Account settings or by emailing privacy@traksta.app. Withdrawal is as easy as giving consent.
  • Withdrawal does not affect the lawfulness of processing carried out before you withdrew.
  • Because your training log is the service, withdrawing this consent means we can no longer operate your account. We will tell you this clearly before you confirm. You will be offered a full export of your data first, and your account will then be closed and your data erased under section 10.

Consent to analytics (4.6), to marketing (4.10), and to health-platform sync (4.4) are separate from this consent. You can refuse or withdraw any of them and keep using Traksta normally.

08Who we share it with

We use a small number of service providers, each acting as a processor on our documented instructions under a data processing agreement meeting Article 28 GDPR. We do not sell personal data. We do not share it with advertisers, data brokers, or analytics networks that combine it with data from other sources.

Processors

ProviderRoleDataLocationStatus
Amazon Web ServicesApplication hosting, database, backupsAccount, training, profile dataFrankfurt, Germany (eu-central-1)Active
HostingerTransactional email for sign-up and password-reset codesYour email address and the one-time code itselfEUActive
RevenueCat, Inc.Subscription and entitlement managementPlan, status, renewal date, trial status, country of purchase, a pseudonymous user identifierUnited StatesNot yet active
PostHog, Inc.Product analytics, only after you consentPseudonymous usage events, device model, OS and app version, coarse country from IP (IP itself not retained)EU Cloud (Frankfurt)Not yet active
Functional Software, Inc. (Sentry)Crash and error reportingError, stack trace, device model, OS and app version, recent screen sequenceEU (Frankfurt)Not yet active

Providers marked Not yet active are documented in advance. No data reaches them today, because the integration does not exist yet. We will update this table when each one ships.

Independent controllers

Apple and Google are not our processors. They set their own purposes and are independently responsible under their own privacy policies. We have no Article 28 control over their handling of payment data, and we do not claim any.

PartyRoleWhat they see
Apple Inc.App Store distribution; payment as merchant of record; optional Sign in with AppleYour payment details, which we never see; your Apple ID email, or a private relay address if you use Sign in with Apple
Google LLCPlay distribution; Play Billing as merchant of record; optional Sign in with GoogleYour payment details, which we never see; your Google account email if you use Sign in with Google

We will also disclose personal data where we are legally required to, for example to a competent Austrian authority acting on a valid legal basis. We will resist overbroad requests and, where we are lawfully permitted to tell you, we will.

If Traksta is ever sold or transferred, your data may move with it. You will be told beforehand, and the protections in this policy will continue to apply.

09Transfers outside the European Economic Area

Everything we store (your account, your training log, your profile) sits on servers in Frankfurt, Germany. It does not leave the EU.

No transfer outside the EEA takes place today. One is planned.

United States (not yet active). RevenueCat, and the US parent companies behind PostHog and Sentry. When these ship, transfers will rely on the European Commission’s Standard Contractual Clauses (Decision 2021/914), supported by a transfer impact assessment and supplementary measures including encryption in transit and at rest, pseudonymisation, and data minimisation. PostHog and Sentry will be configured to store data in EU regions.

A note on where we work from. Traksta is run by one person, who is not always physically in the EU. Administrative access to our systems therefore sometimes originates outside the EEA. This is not a transfer of your data to anyone, since no second party receives it, but we mention it because it is true, and because section 13 describes how that access is controlled.

You can request a copy of the safeguards in place by emailing privacy@traksta.app.

10How long we keep it

DataRetention
Account, profile, and training dataFor as long as your account is open
After you request deletionErased from live systems within 30 days
Encrypted backupsPurged on a rolling cycle, no later than 35 days after deletion
Session security records (IP, user agent)90 days from the session
One-time sign-in and password-reset codesUntil used or expired, and no longer than 24 hours
Analytics events12 months from collection, then deleted. Applies from the date analytics launch
Diagnostic and crash data90 days. Applies from the date crash reporting launches
Subscription and transaction records7 years from the end of the relevant financial year (§132 Bundesabgabenordnung)
Support correspondence and in-app feedback3 years from last contact
Marketing consent recordsUntil withdrawal, plus 3 years as proof of lawful consent
Deletion-reason feedbackAggregated and de-identified on receipt

Where we are legally required to keep records, chiefly tax records, those records are restricted from all other processing and used only for the purpose that requires them.

11Your rights

Under Articles 15 to 22 GDPR, you have the right to:

  • Access. Obtain confirmation of whether we process your data, and a copy of it.
  • Rectification. Have inaccurate data corrected.
  • Erasure. Have your data deleted. Traksta has a self-service Delete Account function that erases it permanently.
  • Restriction. Have processing paused while a dispute is resolved.
  • Portability. Receive your data in a structured, commonly used, machine-readable format, or have it sent to another controller. Traksta has a self-service export that is free, unlimited, and available on the free tier.
  • Object. Object to processing based on legitimate interest, on grounds relating to your situation.
  • Withdraw consent. At any time, without affecting processing carried out beforehand.
  • Not be subject to automated decisions producing legal or similarly significant effects. See section 12.

To exercise any of these, email privacy@traksta.app. We will respond within one month. If a request is complex, we may extend that by up to two further months, and we will tell you why within the first month. Exercising your rights is free; we will only charge for a request that is manifestly unfounded or excessive, and we will explain if we consider one to be.

We may ask you to confirm your identity, but only where we have a genuine doubt about who is making the request, and only for what we actually need.

Right to complain. If you believe we are handling your data unlawfully, you can complain to the Austrian data protection authority:

Österreichische Datenschutzbehörde
Barichgasse 40–42, 1030 Wien, Austria
dsb@dsb.gv.at
https://www.dsb.gv.at

You may also complain to the supervisory authority in your own country of residence or workplace. We would rather you came to us first, but you are under no obligation to.

12Automated processing

Traksta’s Pro tier analyses your training history automatically. It detects stalls and plateaus, forecasts personal records, benchmarks you against published strength standards, and compares your training volume against target bands.

These are informational. They do not produce legal effects concerning you and do not similarly significantly affect you within the meaning of Article 22 GDPR. Traksta does not decide anything about you. It reads what you logged and tells you what it appears to mean. Every output is a suggestion, and you remain free to ignore it.

Traksta is not a medical device. It does not diagnose, treat, or prevent any condition, and it gives no medical advice. If something hurts, see a doctor, not an app.

13Security

We apply technical and organisational measures appropriate to the risk, as required by Article 32 GDPR:

  • Encryption in transit (TLS 1.2 or higher) and encryption at rest.
  • Passwords stored only as salted hashes using a modern key-derivation function. We cannot read your password.
  • Access to production data on a least-privilege basis, restricted to the minimum number of people, with multi-factor authentication and access logging.
  • Administrative access to our systems sometimes originates from outside the EU/EEA, because Traksta is operated by one person who travels. That access is logged, multi-factor protected, and limited to what an operational task requires.
  • When analytics ship, identifiers will be pseudonymised and held separately from account data, and the tooling will initialise only after consent, so no data flows before you allow it.
  • EU data residency for all systems under our control.
  • Regular dependency and vulnerability patching.
  • Encrypted, access-controlled backups with tested restoration.

No system is perfectly secure, and we will not pretend otherwise. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Datenschutzbehörde within 72 hours, and we will tell you directly where the risk is high.

14Children

Traksta is not intended for anyone under 16. We do not knowingly collect data from children under 16. If you believe a child has given us personal data, email privacy@traksta.app and we will delete it.

15Website and cookies

The Traksta website uses only strictly necessary cookies, which do not require consent. It runs no advertising trackers, no social plugins, and no third-party analytics without your prior consent given through the consent banner.

Our hosting provider processes server logs, including IP addresses, for security and operational purposes on the basis of Article 6(1)(f), and deletes them after 7 days.

16Changes to this policy

We may update this policy. If a change materially affects how we handle your data, we will tell you in the app and by email at least 14 days before it takes effect, and, where the change requires it, we will ask for fresh consent rather than assume it.

Previous versions are archived at https://traksta.app/privacy/archive.

17Contact

Krishanu Roy
Weidmanngasse 15/45, 1170 Wien, Austria
privacy@traksta.app

We read every message. We do not use a ticket wall.

Traksta — Privacy Policy · v1.0← Back to site