Privacy Policy
Last updated: 21 September 2026
Operator and controller
Christian Nagel (sole proprietor)Ingling 67
4784 Schardenberg
Österreich
hello@kadence-app.com
Draft. This text has been prepared but not yet reviewed by a lawyer. Items in square brackets will be completed before launch. The German version is legally binding; this translation is provided for convenience.
1. The short version
Kadence is built so that your training and health data stays on your device. There is no server holding it unless you turn on cloud backup yourself. The app contains no third-party analytics or advertising software, no crash reporting and no tracking identifiers. Apart from checking your subscription (3.12), the only thing it sends us on its own is a set of anonymous usage counts once a day, without any identifier — daily counters that cannot be attributed to a device or a person and that you can turn off in the app (see 3.9). This website sets no cookies and loads nothing from third parties; it counts visits anonymously with a tool we run ourselves (see 2.2). Where we have to limit abuse — when sharing, when reporting and in feedback without an account — we process pseudonymised technical values, never your contents (see 2.3, 3.6, 3.7).
A few features still need a connection to our servers. We name each of these exceptions individually below: the optional account, the optional cloud backup, food search, the feedback form, sharing by link, fetching the exercise catalogue, the version check at launch (3.8), the anonymous usage counts (3.9) and checking your subscription (3.12). Everything else happens exclusively on your device.
The controller within the meaning of the General Data Protection Regulation (GDPR) is the operator named above. No data protection officer needs to be appointed. For privacy questions, contact us at the e-mail address given.
2. This website
2.1 Hosting and server logs
The website runs on our own infrastructure (data centre: Hetzner Online GmbH, Germany). When you open a page, the web server necessarily processes your device’s IP address, date and time, the requested address, the browser type and the referring page if your browser sends it. This data goes into server logs and serves only secure operation and troubleshooting. It is deleted after 7 days and not combined with other data.
The legal basis is our legitimate interest in secure and stable operation (Art. 6(1)(f) GDPR).
The website sets no cookies and embeds no external fonts, scripts or content. A cookie notice is therefore not required. For visitor statistics, see 2.2.
2.2 Visitor statistics
To know how many people visit this website, we use the open-source software Umami. It runs on our own servers; no data is sent to third parties. Umami sets no cookies and does not store your IP address. It records the page viewed, the referring page, country, browser, operating system, device type and screen size. To group the page views of one visit, Umami derives a pseudonymous hash from technical attributes such as IP address and browser signature using a secret that changes daily; the attributes cannot be recovered from the hash, and the attributes themselves are not stored. Data is only evaluated in aggregate. If your browser sends the “Do Not Track” setting, your visit is not counted. Shared pages (2.3) are never counted.
The legal basis is our legitimate interest in learning whether and how this website is used (Art. 6(1)(f) GDPR). You can object to being counted at any time, most easily via your browser’s Do Not Track setting.
2.3 Shared content and reports
Sharing a link from the app creates a page under kadence-app.com/s/…. Opening such a page is subject to the server logs described in 2.1. The page shows a preview of the shared content and a sender card if the sender created one. What appears there was chosen by the sender (see 3.7).
On every shared page you can report the content. We store the time, the reason you chose, your optional note and a pseudonymised hash of your IP address (derived with a secret key) to limit abuse of the reporting function. The IP address itself is not stored. The report is deleted together with the shared content, at the latest six months after receipt. The legal basis is our legitimate interest in a working reporting mechanism (Art. 6(1)(f) GDPR).
3. The app
3.1 Data on your device
Everything you record in the app is stored in a local database on your device: workouts and training history, strength values and sets, your own exercises, workouts and units, goals, food diary, your own foods and meals, supplements, body data such as weight, age, height and heart-rate limits, and your settings.
We have no access to this data. It leaves your device only when you deliberately use one of the features described below. You can export or completely delete it at any time (see 3.11).
3.2 Apple Health
If you allow it, the app reads your current heart rate, body weight, date of birth, height and biological sex from Apple Health to calculate heart-rate zones and calorie values. It writes completed workouts back to Apple Health with duration, calories and heart-rate history so they appear alongside your other activities.
These accesses happen exclusively on your device. Apple Health data is not transferred to our servers unless it is part of a workout you transfer via cloud backup (3.4). We never use health data for advertising and do not pass it on to third parties. You manage what the app may read or write in the Health app under “Data Access & Devices”.
3.3 Account (optional)
The app is fully usable without an account. You only need one to turn on cloud backup or to send feedback with a reply.
There are two ways to sign in:
- Magic link by e-mail. You enter your e-mail address and receive a one-time code. We process your e-mail address, the time of sign-in and the first and last name you provide.
- Sign in with Apple. Apple sends us an identifier, your e-mail address or a relay address generated by Apple, and your name the first time. We never see a password.
The account is managed by our sign-in service. A sign-in token remains in your device’s protected keychain only if you choose “Stay signed in”. The legal basis is performance of the user relationship (Art. 6(1)(b) GDPR).
You can delete your account at any time in the app under Profile → Account. This deletes the account with the sign-in service and all backed-up data (3.4). Data on your device is unaffected.
3.4 Cloud backup (optional, explicit consent only)
Training and nutrition data are health data within the meaning of Art. 9 GDPR. They are transferred to our servers only if you explicitly turn on backup in the app. An account alone transfers nothing. The switch is off when the app ships.
If you consent, the app transfers your own exercises, workouts and units, your training history with sets and results, your goals, your food diary, your own foods and meals, supplements and intakes, and selected settings such as body weight and nutrition goal. Catalogue content and cached third-party products from food search are not transferred.
The content is stored on our servers (location: data centre of Hetzner Online GmbH, Germany) encrypted with a separate key per account (AES-256-GCM). The server holds the content only as ciphertext and does not analyse it. This is not end-to-end encryption: the key is held on our side so you can restore your data after losing a device. If you delete your account, or turn off backup and choose “Delete server data”, we destroy your account’s key. This makes previously taken backup copies permanently unreadable as well.
The legal basis is your explicit consent (Art. 9(2)(a) in conjunction with Art. 6(1)(a) GDPR). We log the time and the version of the consent text you agreed to. You can withdraw consent at any time by turning off backup. After that nothing leaves your device. The lawfulness of processing up to that point is unaffected.
3.5 Food search and barcode scanning
When you search for a food or scan a barcode, the app sends the search term or article number to our food service. This service queries the databases of Open Food Facts, the German Federal Food Code (BLS) of the Max Rubner-Institut and, only if nothing is found there, the FatSecret Platform. No account data, device identifier or diary entries are transmitted; technically the service sees your IP address (server logs as in 2.1).
The camera is evaluated exclusively on the device when scanning barcodes. No photos are stored or transmitted.
The legal basis is performance of the user relationship (Art. 6(1)(b) GDPR). FatSecret is based in Australia and the USA; see section 5.
3.6 Feedback and bug reports
Under Profile → Feedback you can report bugs and wishes. There are two ways:
- Anonymously, without an account: we receive your text, the chosen category and a technical context (app version, operating system and version, device model, affected screen, language). Your IP address is processed only briefly to limit the number of reports per sender. Screenshots are not possible this way.
- With an account: we additionally link the report to your account so we can reply, and you can attach screenshots. Screenshots from the app may show health data; the app points this out before you select them. We strip metadata (EXIF) on receipt. Screenshots are stored unencrypted on our server and are deleted together with the report.
Reports you write offline are sent later. We keep reports and attachments for six months after closure. The legal basis is our legitimate interest in fixing bugs and improving the app (Art. 6(1)(f) GDPR) or, for account tickets, performance of the user relationship (Art. 6(1)(b) GDPR).
3.7 Sharing by link and QR code
When you share an exercise, workout, plan or unit, the app stores a copy of the content on our server and generates a link. The content is reachable only via this link, is not indexed by search engines and is deleted after a fixed period.
For this we store pseudonymised hashes of your device identifier and of your IP address, each derived with a secret key, to limit the number of shared items per device and to trace abuse. Neither the device identifier nor the IP address is stored in plain text; the hashes are deleted together with the shared content.
Optionally you can create a sender card with a display name, description and picture. It is voluntary, not linked to your account name and shown only on your shared pages. You can change or remove it at any time.
The legal basis is performance of the user relationship (Art. 6(1)(b) GDPR); for the sender card, your consent by creating it (Art. 6(1)(a) GDPR).
3.8 Exercise catalogue, images and version check
The app fetches new and updated exercises, workouts and illustrations from our content service. No account data or device identifier is transmitted; the server logs from 2.1 apply. The legal basis is performance of the user relationship (Art. 6(1)(b) GDPR).
On a cold start the app also asks our configuration service whether a newer app version is available or maintenance is scheduled. Only the app identifier, operating system, app version and language are transmitted — no device identifier, no account, no sign-in token; the request is not stored. The legal basis is performance of the user relationship (Art. 6(1)(b) GDPR).
3.9 Anonymous usage counts
To improve the workout catalogue, the app counts a few things per calendar day on your device and sends these counters to our own server once a day, at the earliest on the following day. We want to know which catalogue workouts are started, completed or aborted, how many own workouts and exercises are created and which timer formats are used — not who is training.
What is sent: per catalogue workout, the day’s number of starts, completions and aborts; the number of your own workouts and exercises (numbers only, no names and no contents) and the starts, completions and aborts of your own or shared workouts as a total; timer starts per format (interval, Tabata, AMRAP, EMOM, for time); app version, platform (iOS or Android) and language; a rough install age in four buckets (up to 7 days, up to 30 days, up to 90 days, older); the calendar day; and a random value generated afresh for each day, which only prevents the same day from being counted twice and establishes no link from one day to the next.
What is never sent: no user, device, account or Kadence ID, no sign-in data and no sign-in token, no times of day (only the calendar day), no training contents (no exercises, sets, reps, weights or results), no health or body data, no nutrition data, no location. The server processes your IP address only transiently as a hash with a short expiry to limit the number of submissions per sender; it is neither stored with the counters nor retained in any other way.
Legal basis: The counters contain nothing that identifies you or your device, and they cannot be combined with each other or with other data to point to a person. In our assessment they are therefore not personal data within the meaning of Art. 4(1) GDPR (Recital 26). Should individual items nevertheless be regarded as personal data, we base the processing on our legitimate interest in improving the workout catalogue (Art. 6(1)(f) GDPR); the switch in the app then acts as your objection. In any case we describe the counters in full because you should know what your device sends.
Turning it off: Under Profile → Data → Usage counts you can turn off sending at any time. After that the app counts nothing, deletes the counters not yet sent from the device and sends nothing. The app points out the counting when you first launch it. Daily counters already sent cannot be recalled — they carry no identifier and therefore cannot be attributed to a device, not even by us.
Recipients and retention: The only recipient is us; the counters are stored on our own servers (hosting, section 4) and go to no third party. We delete the received daily snapshots after 90 days; after that only aggregated daily totals without personal reference remain, indefinitely. Data is only evaluated in aggregate.
3.10 Notifications
Supplement reminders and the rest-timer display are local notifications generated by the app on your device. There is no push service and no transfer to our servers.
3.11 Export and deletion
Under Profile → Export the app creates a file with all your data in JSON and CSV format (right to data portability, Art. 20 GDPR). The file is unencrypted and contains health data; store it accordingly. It is passed on via your device’s share menu, not via our servers.
You delete all local data completely by removing the app from your device; the local database is deleted with it. A deletion function inside the app (Profile → Data) is coming. You delete the account and backed-up data separately under Profile → Account (3.3).
3.12 App Store and subscription
Apple handles the download and the subscription via the App Store. Apple is independently responsible for this; Apple’s privacy policy applies. We receive no payment data and no personal data about you from Apple, in particular neither your Apple ID nor your payment method.
Kadence ID. When you first launch the app, it generates a random, pseudonymous identifier (Kadence ID). It is kept in your device’s protected keychain and therefore survives reinstalling the app; it is not exported, not shared with others and contains nothing that points to you. Because we do associate it with the trial, the subscription status and, with an account, your account, we treat it as personal data. Its sole purpose is to associate the trial and the subscription status with an installation; it is not used for advertising or tracking.
Purchase processor. Taking out, verifying and restoring the subscription is handled for us by the service provider RevenueCat, Inc. (San Francisco, USA) as a processor. RevenueCat receives the Kadence ID, the purchase receipts issued by Apple and the subscription’s transaction data (product, times of purchase, renewal, cancellation and expiry, subscription state, platform and app version). No advertising or device identifiers are transmitted. If you restore your purchase on another device, that device’s Kadence ID is also sent to RevenueCat so the subscription can be assigned there.
Our servers. RevenueCat notifies us whether and until when a subscription exists for a Kadence ID (with an account: also for your account). We store this on our servers together with the Kadence ID, the relevant times and the subscription state; our servers also record when the trial started for each Kadence ID. The purpose is to check access after the trial and to carry the subscription over to further devices. We receive no payment data, Apple ID or invoices.
Account. If you sign in to the app with an account, we link your device’s Kadence ID to that account. The subscription then also applies on other devices where you are signed in. If you delete your account, we remove this link; the subscription records remain, without reference to the account, as contract data for the statutory retention period (section 6).
The legal basis is performance of the user relationship (Art. 6(1)(b) GDPR); for retaining contract data, our legal obligation (Art. 6(1)(c) GDPR). RevenueCat is based in the USA; see section 5.
4. Recipients and processors
We pass on personal data only as far as necessary for the purposes described:
- Hosting: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, operates the data centre running our servers as a processor under Art. 28 GDPR.
- E-mail delivery for magic links: via our own mail server on the same infrastructure; no external delivery provider is involved.
- Apple Inc. for Sign in with Apple, Apple Health and the App Store, each as an independent controller.
- RevenueCat, Inc., San Francisco, USA, for handling in-app subscriptions (purchase, verification, restore) as a processor under Art. 28 GDPR; receives the Kadence ID (with an account: also the account ID), the Apple purchase receipts and the subscription’s transaction data, no advertising or device identifiers (see 3.12).
- FatSecret (Secure Digital Solutions Pty Ltd, Australia / FatSecret Platform, USA) for food search, with the search term or article number only.
- Open Food Facts and Max Rubner-Institut for food search; no personal data is transmitted.
5. Transfers to third countries
Our servers are located in Germany; for the account, cloud backup, feedback, sharing and usage counts no data is transferred to third countries. During food search, a request may go to FatSecret in Australia or the USA. It is sent from our server and contains only the search term or article number — neither your IP address nor any identifier; in our assessment no personal data is transferred. To handle the subscription we transfer the data named in 3.12 to RevenueCat, Inc. in the USA; the basis is the European Commission’s standard contractual clauses (Art. 46(2)(c) GDPR) as part of our data processing agreement with RevenueCat. To our knowledge (September 2026) RevenueCat is not certified under the EU-US Data Privacy Framework. Apple processes data under its own rules, which you can review with Apple.
6. Retention
- Server logs: 7 days.
- Visitor statistics: aggregated figures without personal reference, indefinitely.
- Anonymous usage counts of the app (3.9): received daily snapshots 90 days; aggregated daily totals without personal reference indefinitely.
- Version check (3.8): nothing is stored.
- Account: until you delete it.
- Backed-up data (cloud): until withdrawal or account deletion, then immediate destruction of the key.
- Subscription status and trial start per Kadence ID: for the duration of the trial and the subscription, then as contract data for seven years (statutory retention period under § 132 of the Austrian Federal Fiscal Code, BAO). The link to your account ends when the account is deleted.
- Shared content including the hashes from 3.7: until the expiry shown when sharing, or until removal.
- Sender card: until you remove it.
- Feedback and attachments: six months after closure.
- Reports on shared content: together with the shared content, at the latest six months after receipt.
7. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interest (Art. 21). You can withdraw any consent at any time with effect for the future.
Much of this you can do directly in the app: export, local deletion, account deletion and withdrawing sync consent. For anything else, write to the e-mail address given.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Austrian Data Protection Authority (Datenschutzbehörde), Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at. In addition to the GDPR, the Austrian Data Protection Act (DSG) applies.
No automated decision-making or profiling takes place.
8. Changes
We update this policy when the app or the law changes. The current version is always available at this address; the date is shown above. For changes requiring new consent, the app will ask you again.
This policy is available in German and English. In case of discrepancies, the German version prevails.