Privacy Policy - Darwinci
Last Updated: April 2026
1. Data Controller
Responsible for data processing according to Art. 4(7) GDPR:
human form+ UG (haftungsbeschränkt)
König-Heinrich-Straße 11
06217 Merseburg
Germany
Data Protection Contact:
Email: privacy@darwinci.de
Web: https://darwinci.de/privacy
2. General Information About Data Processing
We process personal data according to the EU General Data Protection Regulation (GDPR) and applicable German data protection laws.
This privacy policy informs you about what data we collect, how we process it, and what rights you have as a data subject.
3. Categories of Personal Data
The Darwinci app processes the following categories of personal data:
3.1 Identity Data
- First name, last name
- Email address
- Password (encrypted)
- Profile picture / Avatar (optional)
3.2 Training Data (Health/Fitness Data)
- Heart rate (HR) / Pulse measurements
- Training type (running, cycling, swimming, etc.)
- Duration and date of training sessions
- Training route and distance
- Speed / Cadence
- Wattage (for cycling)
- Performance Level (PL) and Training Load (TL)
- Chronic Training Stress Index (CTSI)
- HR zone distribution and zone duration
- Calorie expenditure (calculated)
3.3 Device Data
- Device ID
- Device manufacturer and operating system
- App version
- Language and time settings
3.4 Location Data (Optional)
- GPS coordinates during outdoor training (running, cycling)
- Altitude profile and elevation changes
- Location is NOT continuously collected, only during active training sessions with user consent
3.5 Usage and Interaction Data
- Login times and frequency
- Features the user utilizes
- In-app interactions (challenges, coach panel, etc.)
- Error and crash reports (with opt-out option)
3.6 Payment Data
- Transaction IDs
- Payment timestamp
- In-app purchases and subscription status
- NOT: Credit card or bank data (processed by RevenueCat integration, see Section 9)
4. Legal Bases for Data Processing
4.1 Contract Performance (Art. 6(1)(b) GDPR)
Processing of identity data and basic training data is necessary for: - Account creation and management - Provision of app functionality - Personalization of training plans - Cloud synchronization
Without this data, the app cannot be provided.
4.2 Explicit Consent (Art. 6(1)(a) GDPR)
For processing of health data (specifically heart rate data), we require explicit consent according to Art. 9(2)(a) GDPR.
This consent is: - Obtained at first use of HR measurement functionality - Revocable at any time - Presented clearly and comprehensibly
Without consent, HR-based features cannot be used.
4.3 Legitimate Interests (Art. 6(1)(f) GDPR)
For the following processing, we rely on legitimate interests: - Security and fraud prevention - System optimization and bug fixes - Analytics and service improvement (when anonymized or anonymizable) - Legal compliance and enforcement
5. Processing of Health Data (Art. 9 GDPR)
5.1 Special Protection for Health Data
Heart rate data and derived values (HR zones, training load, performance level) are health data according to Art. 4(15) GDPR.
We process this data only under the conditions of Art. 9(2) GDPR:
Legal Basis: Art. 9(2)(a) GDPR — Explicit Consent
Users must actively and consciously consent to use HR measurement features.
5.2 Security Measures for Health Data
- Encryption: All health data encrypted with AES-256
- Separated Storage: Training data is spatially and logically separated from identity data (ADR-011 architecture)
- Minimal Processing: Only data required for training algorithms is processed
- Anonymization: Analytics conducted only with anonymized/aggregated data
- Access Control: Only authorized backend services can access health data
6. Data Processing and Architecture (Dual-DB System)
6.1 Separation of Identity and Training Data (ADR-011)
Darwinci uses a Dual-Database Architecture:
Database 1 (Identity DB): - Stores identity data (email, name, password hash) - Separately encrypted - Only for authentication and user management
Database 2 (Training/Health DB): - Stores all training and health data - References Identity DB only through anonymous user IDs - No retrievability of identities without additional authorization
Benefits: - Enhanced protection of health data - Reduced abuse risk - Compliance with privacy-by-design principles
6.2 Data Storage
- Server Location: EU-hosted (Render, Frankfurt)
- Availability: 99.9% SLA
- Backups: Daily encrypted backups
- Data Retention Periods:
- Active users: Unlimited (as long as user maintains active account)
- After account deletion: 30-day retention (for dispute resolution), then complete deletion
- Log data: Maximum 90 days
- Error reports: Maximum 30 days
7. Third Parties and Data Transfers
7.1 RevenueCat (In-App Payments)
Purpose: Processing in-app purchases and
subscriptions
Data Transfer: - Payment metadata (transaction ID,
timestamp, subscription status) - Anonymous device ID (no relation to
email/identity) - NOT: Credit card or bank data (RevenueCat and App
Store/Google Play process these directly)
Data Protection: RevenueCat complies with GDPR and
Standard Contractual Clauses
Link: https://www.revenuecat.com/privacy
7.2 Firebase / FCM (Push Notifications)
Purpose: Sending push notifications (training
reminders, challenges, updates)
Data Transfer: - Device token - Anonymous user ID -
NOT: Heart rate or sensitive training data
Data Protection: Google complies with GDPR and
Standard Contractual Clauses (SCCs)
Link: https://policies.google.com/privacy
7.3 Apple HealthKit (iOS)
Purpose: Optional integration for syncing with iOS
Health app
Data Flow: - App reads HR data from HealthKit (with
user consent) - App writes training sessions to HealthKit (with user
consent) - HealthKit data remains on user device and is NOT transferred
to Darwinci servers
Data Protection: Apple HealthKit subject to Apple’s
privacy policy
User Control: Users can disable HealthKit permissions
anytime in iOS Settings
7.4 Google Health Connect (Android)
Purpose: Optional integration for syncing with
Android health apps
Data Flow: - App reads HR data from Health Connect
(with user consent) - App writes training sessions to Health Connect
(with user consent) - Health Connect data remains on user device and is
NOT transferred to Darwinci servers
Data Protection: Google Health Connect subject to
Google’s privacy policy
User Control: Users can disable Health Connect
permissions anytime in Android Settings
7.5 Other Third Parties
Analytics (if enabled): - Aggregated, anonymized usage metrics - NO personal data - Opt-out available in app settings
Crash Reporting (if enabled): - Error logs and stack traces - NO health data - Automatically disabled in production, only enabled in beta/debug
8. International Data Transfers
8.1 Primary Data Location
All data is primarily hosted in the EU (Render, Frankfurt).
8.2 US Data Transfers (Firebase/RevenueCat)
For Firebase and RevenueCat, data may be transferred to the US under: - Standard Contractual Clauses (SCCs) (Art. 46 GDPR) - Google Data Processing Amendment with EU standard clauses - These clauses ensure adequate protection level
Opt-out: Users can disable Firebase/push notifications.
9. Data Subject Rights (Art. 15–22 GDPR)
Users have the following rights:
9.1 Right of Access (Art. 15 GDPR)
Users can request information about what data is processed about them at any time.
Submit Request To: privacy@darwinci.de
Response Deadline: 30 days
9.2 Right to Rectification (Art. 16 GDPR)
Users can correct incorrect or incomplete data.
In-App: Name and email can be edited in
settings
By Request: Other data can be requested at
privacy@darwinci.de
9.3 Right to Erasure (Art. 17 GDPR)
Users can request complete deletion of their account:
Self-service (recommended): https://darwinci.de/delete-account/ — enter your email, click the confirmation link, and your account is deactivated immediately. Works even without the app installed.
Alternatively via email to:
privacy@darwinci.de
Process: 1. Request is verified 2. User account is
deactivated 3. All training data is deleted 4. Identity data deleted
after 30 days (for dispute resolution) 5. Confirmation sent via
email
Exceptions: - Data required by tax or legal obligations cannot be immediately deleted - These are deleted after applicable retention periods
9.4 Right to Restrict Processing (Art. 18 GDPR)
Users can request that their data be stored but not processed (e.g., during a complaint).
Submit Request To: privacy@darwinci.de
9.5 Right to Data Portability (Art. 20 GDPR)
Users can export their training data in a structured, standard format (e.g., CSV, JSON).
In-App: Data export function in settings
Or By Request: privacy@darwinci.de
9.6 Right to Object (Art. 21 GDPR)
Users can object to processing of their data for direct marketing or analytics.
Email: privacy@darwinci.de
9.7 Right to Withdraw Consent
Users can withdraw consent for health data processing at any time:
In-App: Disable HR measurement in settings
Or By Request: privacy@darwinci.de
Processing of previous data remains lawful.
10. Data Security
10.1 Technical Measures
- Encryption: TLS 1.3 for data transmission, AES-256 at rest
- Authentication: OAuth 2.0 / JWT-based
- Access Control: Role-based access control (RBAC)
- Firewalls & WAF: Network security and web application firewall
- Intrusion Detection: Automated threat detection
- Penetration Testing: Regular external security audits
10.2 Organizational Measures
- Data Protection Impact Assessments (DPIA): Conducted for high-risk processing
- Data Processing Agreements (DPAs): Concluded with all service providers (RevenueCat, Google, etc.)
- Staff Training: Regular GDPR and security training
- Incident Response Plan: Procedures for data breaches established
- Reporting: Breach notification to authority and users within 72 hours (Art. 33, 34 GDPR)
11. Automated Decision-Making & Profiling
The app uses automated algorithms for: - Training Plan Adaptive Adjustment (PL/TL-based): Calculation of next planned training - Performance Analysis: Calculation of performance metrics based on HR data
These are NOT automated decisions with legal consequences. Users can manually adjust training plans or disable algorithms.
12. Data Protection Contact / Complaints
12.1 Privacy Contact
Privacy inquiries:
Email: privacy@darwinci.de
Web: https://darwinci.de/privacy
12.2 Complaint to Supervisory Authority
Users have the right to lodge a complaint with the competent Data Protection Authority if they suspect data protection violations:
EU Authorities: https://edpb.ec.europa.eu/about-edpb/board/members_en
Germany (examples): - Federal: Bundesbeauftragte für Datenschutz und Informationsfreiheit (BfDI) - States: Respective state data protection authorities
13. Changes to This Privacy Policy
We may update this privacy policy to reflect changed laws or processes.
Material changes will be: - Announced 30 days in advance (in-app notification) - Users must accept new terms before further use
Last Updated: April 2026
14. Summary of Privacy Principles
Darwinci processes data according to these principles:
✓ Data Minimization: Collect only necessary
data
✓ Purpose Limitation: Use data only for stated
purposes
✓ Storage Limitation: Delete data when no longer
needed
✓ Transparency: Fully inform users
✓ User Control: Users control their data
✓ Security: Maintain highest security standards
✓ EU-First: Store data primarily in the EU
Contact for Questions:
privacy@darwinci.de
https://darwinci.de/privacy