Legal · version 2026-08-03
PRIVACY POLICY FOR CALICOACH
Last updated: August 3, 2026
1. Controller
The controller responsible for data processing related to the CaliCoach app is:
Jim Riediger
Mühlenstr. 40
53879 Euskirchen
Germany
2. Purpose of the app
CaliCoach provides calisthenics technique feedback, Coach Chat, local progress views, optional body calibration, and subscription management. Most attempt data stays on the user's device. CaliCoach processes personal data only when it is necessary for a requested feature, for security and abuse prevention, or when the user has given consent.
3. Data stored locally on your device
By default, CaliCoach stores recorded or selected attempt videos, generated feedback, attempt titles and prompts, coach-chat conversations, metric history, calibration values, settings, and language preferences locally on your device. Full attempt videos remain local and are not sent to OpenAI for the current AI-analysis flow.
4. Camera, microphone, and voice input
CaliCoach accesses the camera and microphone only after you grant the relevant system permission and use the recording or voice-input feature. If you choose voice input, the current version uses Apple's system speech recognition. Apple may process audio, transcription, and technical information under Apple's privacy terms. CaliCoach uses the resulting text only to provide the requested chat-input function.
5. Optional analytics and crash diagnostics
Firebase Analytics and Firebase Crashlytics by Google are disabled until you explicitly opt in during legal onboarding or later under Privacy & Data. If enabled, they process technical and product-usage events, such as onboarding completion, analysis started/completed/blocked/failed, feedback viewed, chat opened, calibration completed/failed, language changed, paywall viewed, and purchase or restore events. Crashlytics may process crash reports, device and operating-system information, app version, time of error, and technical diagnostics. CaliCoach does not intentionally send raw videos, keyframes, chat content, free-text prompts, names, or health diagnoses to Firebase. You can withdraw this optional consent at any time under Privacy & Data.
6. AI analysis and Coach Chat: data, recipient, and purpose
CaliCoach uses the OpenAI API as a third-party AI service provider only after you explicitly consent in the app. Before the first AI analysis or Coach Chat request, CaliCoach displays a feature-specific consent screen that identifies OpenAI and lists the exact data for that request. The data is collected from the content you choose to submit, from on-device pose detection, and from locally stored attempt context.
For an AI technique analysis, CaliCoach sends to OpenAI through the CaliCoach API up to three selected keyframes from the current video, not the full video; the skill title and any optional prompt; and locally extracted pose and biomechanical metrics. The purpose is solely to generate the technique feedback you requested.
For Coach Chat, CaliCoach sends the message you choose to send, up to the last 18 messages in that chat, and summaries of linked attempts and up to five recent attempts. Those summaries may include a title, skill, date, your prompt, generated feedback, quality/confidence information, and coaching context. Full videos and video keyframes are not sent for Coach Chat. The purpose is solely to generate the requested coaching reply or automatic chat title.
CaliCoach's server relays these data to OpenAI and does not persist raw videos, keyframes, prompts, or chat content. CaliCoach does not opt in to use OpenAI API inputs or outputs for model training. Under OpenAI's API data controls, API inputs and outputs are not used to train OpenAI models by default. OpenAI may retain limited API content or metadata for abuse monitoring and legal obligations under its applicable terms and retention controls. You can withdraw consent for future AI requests under Privacy & Data; withdrawal stops new requests but cannot retract data already processed by OpenAI.
7. Other recipients, Cloudflare, and safeguards
Hetzner hosts the CaliCoach API and its pseudonymous operational database. Cloudflare provides DNS, TLS termination, a secure outbound tunnel, reverse-proxy routing, availability, and abuse and network-security protection for the public website and the CaliCoach API. When a website or API request passes through Cloudflare, Cloudflare may process the source IP address, time, requested hostname and path, protocol and HTTP headers, routing and security signals, request and response size or status, and the content carried in the request as technically necessary to transmit and protect it. For an AI request, that transiting content can include the data described in section 6. CaliCoach does not use Cloudflare to intentionally persist raw AI payloads.
Apple processes App Store payments and, when chosen, system speech recognition. Google/Firebase processes optional analytics and crash diagnostics only after consent. Payment data is processed by Apple; CaliCoach receives only transaction and entitlement information required to provide Premium. Data is encrypted in transit from the app to Cloudflare and through the Cloudflare Tunnel to the CaliCoach API. CaliCoach only engages providers under contractual and technical safeguards requiring protection of personal data that is the same as or equivalent to the protection described in this Privacy Policy and required by applicable data-protection law.
8. Server-side operational data, retention, and deletion
CaliCoach does not require a traditional user account. To protect the service and enforce the free offer and Premium entitlement, the server stores pseudonymous operational metadata: an installation identifier derived with a server-side secret, a hashed IP address, task type, result status, token or duration values, technical error codes, consent evidence, App Attest records, and entitlement events. Raw videos, keyframes, prompts, and chat content are not stored by the CaliCoach server. Usage events are deleted after 60 days and entitlement events after 180 days. Active installation, consent, security, trial, and entitlement records remain only as long as necessary for the service or until you choose Delete All App Data, subject to the exceptions below.
When you choose Delete All App Data, CaliCoach first deletes the records linked to the current pseudonymous installation from its server, including usage, trial, beta-access, consent-session, App Attest, and entitlement records. Only after the server confirms deletion does the app erase its local attempts and media, chats, metric history, calibration and settings, consent state, installation identifier, App Attest key reference, analytics identifier, unsent crash reports, caches, and temporary files. If the server cannot confirm deletion, the app keeps the local identity so that deletion can be retried instead of orphaning server data.
This action does not cancel an Apple subscription and cannot delete Apple's purchase history, an Apple-managed DeviceCheck anti-abuse bit, data already processed under a provider's necessary retention or legal obligations, or an older device or iCloud backup controlled by the user and Apple. Previously submitted Firebase or OpenAI data cannot always be erased synchronously from the app. Future Firebase collection is stopped and local Firebase state is reset; broader access or deletion requests can be sent to [email protected]. Provider and statutory retention obligations remain applicable. Existing infrastructure backups may retain a historical copy until their scheduled rotation. They are not used in normal operation, access is limited to disaster recovery, and any restored data remains subject to the same deletion and retention rules.
9. Legal bases and your choices
Where applicable, processing is based on your explicit consent for AI sharing and optional Firebase analytics/crash diagnostics, on performance of the feature you request, and on legitimate interests in security, reliability, abuse prevention, and legal compliance. You can refuse the AI consent; in that case AI analysis and Coach Chat cannot be provided, while non-AI local app functions remain available. Depending on applicable law, you may have rights of access, correction, deletion, restriction, portability, and withdrawal of consent for future processing.
10. Health and training notice
CaliCoach provides training feedback only. It is not a medical device and does not provide diagnosis, treatment, therapy, rehabilitation, or injury advice. Results may be incomplete or inaccurate. Stop training if you experience pain or discomfort.
11. Minors
CaliCoach is not directed specifically at children. If you are a minor, use the app only with permission from a parent or legal guardian.
12. Contact
Privacy requests can be sent to:
13. Processors, international transfers, consent evidence, and app integrity
CaliCoach uses service providers only for defined operational purposes: Hetzner hosts the CaliCoach API and its pseudonymous operational database; OpenAI processes the content explicitly submitted for AI analysis or Coach Chat; Google/Firebase processes optional analytics and crash diagnostics only after opt-in; Cloudflare hosts and protects the public website and may also protect API traffic; and Apple processes App Store payments, DeviceCheck, App Attest, and optional system speech input.
Where a provider acts as a processor, CaliCoach relies on contractual and technical safeguards requiring confidentiality, purpose limitation, security, support for data-subject rights, deletion or return, and the same or equivalent protection for subprocessors. Cloudflare's Data Processing Addendum, including applicable EU Standard Contractual Clauses, is available at https://www.cloudflare.com/cloudflare-customer-dpa/; its Privacy Policy is available at https://www.cloudflare.com/policies/privacy/. OpenAI states that API inputs and outputs are not used to train its models by default unless the customer opts in. CaliCoach has not enabled that opt-in. For eligible API endpoints, OpenAI may retain abuse-monitoring content for up to 30 days by default unless a different approved retention control applies. Current information is available at https://developers.openai.com/api/docs/guides/your-data and https://openai.com/policies/privacy-policy/. OpenAI's Data Processing Addendum, including the EU Standard Contractual Clauses where applicable, is available at https://cdn.openai.com/pdf/openai-data-processing-addendum.pdf.
Processing may take place outside the European Economic Area. Where required, CaliCoach relies on an adequacy decision, the EU Standard Contractual Clauses, and supplementary technical and organisational safeguards. CaliCoach remains responsible for selecting and monitoring providers and does not treat a provider policy alone as an unconditional guarantee.
To prove and enforce AI consent without storing the submitted content, the CaliCoach server stores the pseudonymous installation hash, AI feature, legal or consent version, acceptance time, consent-session expiry, and, where App Attest is enabled, the associated App Attest key reference. App Attest also stores a public key, attestation receipt, assertion counter, and short-lived one-time challenges to verify legitimate app requests and prevent replay. It does not give CaliCoach a hardware identifier. These records are used only for consent evidence, security, abuse prevention, and deletion handling.
14. DeviceCheck and the one-time free offer
To enforce the one-time free offer technically, CaliCoach may use Apple's DeviceCheck service. It uses an Apple-managed, device-related anti-abuse state. CaliCoach does not receive a hardware identifier and does not store the DeviceCheck token. "Delete All App Data" deletes the associated CaliCoach server data and local app data, but cannot make a trial already marked by Apple available again.
