Privacy policy
Last updated: 9 September 2026
This is an English translation provided for convenience. In case of any discrepancy, the German version is the legally binding one.
This privacy policy explains, in accordance with the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (revFADP), which personal data the Gradevo app processes.
1. Controller
Talha Sen, c/o JL Consulting Group GmbH#837, Zürcherstrasse 84, 8852 Altendorf, Switzerland
Email: hello@gradevo.app
2. First things first: local-first
Gradevo works entirely without an account. Without signing in, Gradevo stores all training data in local app storage and does not transmit it to Gradevo/Supabase. Any operating-system backups follow your device and cloud settings. Only when you voluntarily create an account is your training data transferred to the cloud for synchronisation.
The app contains no advertising, no advertising SDKs and no tracking or analytics services. No data is processed for advertising purposes or sold to third parties.
3. Data when using the app without an account
All entries (workouts, sets, training weights, plans, custom exercises, settings, onboarding answers as well as optional body weights, body measurements and private progress photos) are stored only in the app's local storage on your device. You delete them by deleting the data in the app or by uninstalling. No transfer to us takes place.
Android Health Connect: if you actively set up Health Connect in your profile and grant the corresponding Android permission, Gradevo can write your own finished workouts and — where available — estimated active calories to Health Connect.
The separate import function can, after your explicit approval, read workouts, associated active calories and body weight from the last 30 days. Data found is first shown in a local inbox. External activities are only stored as source-labelled activities after your confirmation; body weight is only taken into “Measurements & history” after your confirmation. Gradevo does not invent sets, reps or personal records from an external activity.
Health Connect data that has been read, and the local import status, are not transmitted to Supabase or any Gradevo cloud. You can manage access at any time in Health Connect. When you sign out or delete your account, the locally imported external activities and the inbox status are removed from this device.
4. Data when using the app with an account
If you create an account, we process the following in order to provide cloud synchronisation (Art. 6(1)(b) GDPR — performance of a contract):
- Account data: email address, password (exclusively as a cryptographic hash), technical account IDs, registration and sign-in timestamps.
- Training data: workouts with timestamps, exercises, sets, reps, weights, rest times, personal records, workout plans, custom exercises, skill stages as well as profile settings (e.g. unit kg/lb, training focus, default rest time).
- Feedback: improvement suggestions you submit, their category, language, processing status and timestamps, as well as your votes, content reports and hidden anonymous authors. Account name, email address and technical account ID are not shown on the public idea board.
- Optional sign-in with Google or Apple: we receive from your provider the data required to create the account (email address, technical ID). The privacy notices of Google or Apple apply in addition.
When moving from account-free use to an account, the training data stored locally up to that point is uploaded once into your account.
Exception, body & progress: optional body weights, body measurements and private progress photos remain in local app storage even with an account and are not synchronised with Gradevo/Supabase. On Android, the folder holding progress photos is excluded from cloud backups and from Android device transfer; for other local data, any operating-system backups follow your device and cloud settings. Body values as well as the date, perspective and capture source of the photos are included in the deliberately triggered JSON data export; the photo files themselves are exported individually via the system share menu. When you sign out or delete your account, Gradevo removes this local body data, the progress photos and the profile picture, so that shared devices stay safe to use.
5. Hosting / processors
For accounts and cloud synchronisation we use Supabase (Supabase Inc.) as a processor. The data is stored in the EU-West (Ireland, AWS) region. A data processing agreement is in place with Supabase. Further information: supabase.com/privacy
6. Notifications
Reminders (e.g. “rest is over”) are scheduled and displayed locally on your device. There are no push servers; no data is transmitted for this. You can revoke the permission at any time in your system settings.
7. Error and crash reports (Sentry)
For stability and troubleshooting we use Sentry (Functional Software, Inc.) as a processor. In the event of a crash or a handled error, technical error data is transmitted — essentially: the error message including its call stack, app version, operating system and device type, plus a technical event ID. No training content, no email address and no advertising or tracking identifiers are transmitted; no performance tracking takes place. The legal basis is our legitimate interest in a stable, error-free app (Art. 6(1)(f) GDPR). The data transfer may involve a US provider; a data processing agreement with standard contractual clauses is in place with Sentry. Further information: sentry.io/privacy
7a. Anonymous usage statistics (PostHog)
To understand how Gradevo is used and where people stop, we use PostHog (PostHog Inc.) as a processor with servers in the EU. Only anonymous usage events are transmitted: which screens are opened, which onboarding steps are reached, the number and duration of workouts, whether the Pro page was seen or a purchase completed, and the sign-in method — together with app version, operating system and device type. No training content, no email address, no user ID and no advertising or tracking identifiers are transmitted; location lookup by IP address is disabled. Events are keyed by a random, on-device installation ID that is never linked to your account. The legal basis is our legitimate interest in improving the app (Art. 6(1)(f) GDPR). You can switch usage statistics off at any time in the app under Profile → Usage statistics; after that no event leaves your device. More information: posthog.com/privacy
Beyond this, Gradevo integrates no advertising services. The purchase-limited analysis by RevenueCat is described in the following section.
8. Purchases and entitlements (RevenueCat)
Gradevo includes the RevenueCat service (RevenueCat Inc.) to display store offers, validate purchases, and restore and manage Pro access. The service is only started in builds with an active store configuration; in the closed test without store keys, this transmission does not take place.
When activated, RevenueCat first generates a random app user ID. When you sign in to Gradevo, your random Supabase account ID (UUID) is used instead of — or in addition to — it for cross-device attribution; your email address and name are not transmitted to RevenueCat. Processed data includes purchase history, product identifier, purchase/subscription and entitlement status, the store receipt or Google purchase token, as well as necessary technical details such as device type and operating system. This serves purchase processing, fraud prevention, unlocking and purchase-related product analysis (Art. 6(1)(b) and (f) GDPR). Neither Gradevo nor RevenueCat receives payment details such as credit card information; these remain with the Apple App Store or Google Play.
RevenueCat acts as a processor. Processing in the USA cannot be ruled out; the intended data-protection safeguards, in particular standard contractual clauses, are used for this. Further information: revenuecat.com/privacy
9. Data export and account deletion
- Export: in the app (Profile → “Export data”) you can obtain a copy of your data at any time, including the locally stored body-progress values and photo metadata, in JSON format. Private photo files are exported deliberately and individually in the “Progress photos” area (Art. 20 GDPR).
- Deletion: in the app (Profile → Account → “Delete account”) you can delete your account together with all cloud data immediately and irreversibly (Art. 17 GDPR). Without the app, you can request deletion by email to hello@gradevo.app. Local data on your device is deleted through the app or by uninstalling. Detailed instructions are available under delete your account and data.
10. Retention period
We store account-related data for as long as your account exists. When the account is deleted, all associated data is removed from the production database without delay; technical backups held by the hosting provider expire within the retention periods customary there.
11. Your rights
Under the GDPR and the revFADP you have the right of access (Art. 15), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20) and to object (Art. 21), as well as the right to lodge a complaint with a data-protection supervisory authority (in Switzerland: the FDPIC; in the EU: the supervisory authority of your country of residence). Simply contact us at the address given above.
12. Data security
Transmission is encrypted (TLS). Access to cloud data is restricted to your own account by account-based access controls (row level security).
13. Website and iOS waiting list
Hosting: our website is hosted by Vercel (Vercel Inc., USA). When you visit, Vercel processes technical access data as a processor (IP address, time, page requested, browser identifier) in server logs, to the extent required to provide and secure the service (Art. 6(1)(f) GDPR — legitimate interest). A data processing agreement with EU standard contractual clauses is in place with Vercel. The website uses no cookies and loads fonts from our own server (no request to Google).
For audience measurement we use Vercel Web Analytics (Vercel Inc., USA) as a processor. The service works without cookies. Visits are grouped via a hash derived from the request, which is discarded after 24 hours; your IP address is not stored in the process. Recorded are the time, page requested, referring page, country or region, device type as well as operating system and browser, each with version. No cross-site recognition takes place, and we cannot identify individual people from the aggregated reports. The legal basis is our legitimate interest in data-minimising audience measurement (Art. 6(1)(f) GDPR).
iOS waiting list: if you sign up for the iOS waiting list on the website, we store your email address with our processor Supabase (EU-West region, Ireland — see section 5), solely in order to inform you once about the iOS launch of Gradevo (Art. 6(1)(a) GDPR — consent). No newsletter, no disclosure to third parties. You can withdraw your consent at any time and request deletion — an email to the contact address above is sufficient. The list is deleted at the latest after the launch notification has been sent.
14. Feedback and the public idea board
The idea board on the website shows exclusively suggestions that we have reviewed and approved, together with category, status and vote count. When it loads, your browser requests this public content from Supabase; the technically necessary connection data such as IP address and time arises in the process.
You can only submit suggestions and vote while signed in to the Gradevo app. In doing so we store the suggestion content, category, language, status and timestamps as well as the technical link to your account. A vote is stored as a link between your account and an idea so that each account can vote only once. This processing serves product improvement, fair prioritisation and abuse prevention (Art. 6(1)(b) and (f) GDPR). New suggestions are initially visible only to you and appear publicly only after review; your name, email address and account ID are never published.
You can remove a vote again in the app, report problematic content privately and hide all ideas by an anonymous author for your account. That author's account ID is never released to your client. When your account is deleted, your suggestions, votes, reports and blocks are deleted along with the rest of your cloud data. Problems and support cases are not published on the idea board but handled privately via support@gradevo.app. Please do not send health data or other sensitive details that are not necessary for handling your request.
15. Changes
We adapt this policy when the app or the legal situation changes. The version published in the app or on the website at the time applies; the date at the top shows the most recent change.