ARNGCOR APP PRIVACY POLICY

Document version: 2026-07-09

1. Who is the data controller

The controller of your personal data is Konrad Sowinski, operating a sole proprietorship under the business name "Konrad Sowinski" (hereinafter: "Controller", "we"), creator of the ARNGCOR mobile application.

Controller contact details for privacy and GDPR matters:

2. What this policy covers

This policy describes how we process personal data in the ARNGCOR mobile application (iOS / Android) - including when creating an account, using workouts, subscriptions, in-app purchases, and privacy settings.

This policy has been prepared with regard to Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR; in Poland commonly referred to as RODO) and Polish personal data protection laws.

3. What data we collect

Depending on how you use the application, we may process:

3.1. Account and login data

3.2. Profile and workout personalization

3.3. Health and fitness data (special category under GDPR Art. 9)

3.4. Progress and in-app activity

3.5. Consents and legal audit

3.6. Bug reports

3.7. Payments and entitlements (Apple In-App Purchase)

3.8. Local notifications

These settings are stored mainly on your device.

3.9. Optional Apple Health / Health Connect integration

3.10. Technical data necessary for the service to operate

We do not run behavioral advertising, we do not sell personal data to third parties for marketing purposes, and we do not use external tracking analytics tools (e.g. Firebase Analytics, advertising SDKs).

4. Where the data comes from

5. Purposes and legal bases for processing

We do not send marketing newsletters based on your training account. We do not profile you for external advertising.

6. Automated processing

The app automatically selects exercises and session parameters (e.g. difficulty) based on your profile, flexibility level, and responses. This does not result in decisions producing legal effects within the meaning of GDPR Art. 22 (e.g. refusal of healthcare) - it serves only to personalize in-app content.

7. Who we share data with (recipients / processors)

7.1. Supabase (database hosting, authentication, and server functions)

7.2. Apple (Sign in with Apple, App Store, optionally HealthKit)

7.3. Google (Google sign-in)

7.4. Google Fonts (Poppins font download on first launch)

Only authorized persons on the Controller's side (technical support) and infrastructure providers have access to database data, to the extent necessary to provide the service.

8. Transfers of data outside the European Economic Area

Cloud infrastructure (Supabase), Apple, and Google may process data on servers outside the EEA (e.g. in the USA). We aim to use a European database hosting region where available in the project configuration. In each case, mechanisms provided for under the GDPR are applied (e.g. EU Standard Contractual Clauses, adequacy decisions, or provider policies).

9. How long we retain data

After successful account deletion, we delete or anonymize data linked to the account in the database (profiles, consents, progress, billing entitlements, trial period, reports linked to the user identifier) according to database mechanisms (cascade deletion of related records).

10. Your rights

You have the rights provided under the GDPR:

To exercise your rights, write to the contact address in section 1. In the app you can also:

You have the right to lodge a complaint with a supervisory authority: President of the Personal Data Protection Office (Prezes Urzedu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl).

11. Obligation to provide data

Providing an e-mail and password (or OAuth sign-in) is voluntary, but without an account you cannot sync profile and progress across devices.

Providing profile data and consent to health / fitness data is voluntary, but without them the app cannot provide full workout personalization as intended by the product.

Using paid features requires an active internet connection and server-side purchase verification.

12. Security

We apply measures appropriate to the risk, including:

No system is 100% immune to incidents - in the event of a personal data breach, we will inform you if the GDPR requires it.

13. Children

The app is not directed at children under 16. If you learn that a child provided us data without a guardian's consent, contact us - we will delete the account and data.

14. Changes to this policy

We may update this policy (e.g. after adding a new feature). We will inform you of material changes in the app or at your next sign-in. The version date at the top of this document indicates the current edition. At registration we record the policy version you accepted.

15. Final provisions

Matters not regulated herein are governed by Polish law and the GDPR.

The ARNGCOR app does not replace medical advice. In case of pain or illness, consult a specialist.