1. Controller and contact
Paul Jaeger
Am Bach 6
87439 Kempten
Germany
Email: support@olicoach.app
Phone: +49 1556 1255019
No data protection officer has currently been appointed. This policy will be updated if an appointment becomes legally required or a data protection officer is designated.
2. Scope and development status
Oli is a fitness and training application. It supports training plans, workout execution and logging, progress views, and conversations with the AI-powered coach “Ask Oli”. This policy covers the website, iOS and watchOS apps, and the Oli backend.
Pre-launch boundary: The marketing website is available while the app is being prepared for public launch. App processing described here applies only when the relevant feature is active. Health-data and AI processing must not be enabled publicly until the separate consent, recipient agreements, transfer safeguards, and deletion and export processes described here have been fully implemented.
Oli is not a doctor, physiotherapist or emergency service. It does not diagnose medical conditions and does not replace medical examination, treatment or therapy.
3. Categories of personal data
Depending on the features used, Oli may process:
- Account and contact data: email address, internal user ID, display name, authentication and session data.
- Profile and planning data: year of birth, gender entry, height, weight, target weight, experience, goals, training days and duration, sport, position, external training load, equipment, preferences and limitations.
- Health and fitness data: injuries, pain, symptoms, medical clearance, body metrics, strength values, training load and perceived exertion, plus optional Apple Health workouts, heart rate and energy.
- Training data: plans, scheduled and completed workouts, exercises, sets, repetitions, weights, RPE, timing, status, notes, streaks and estimated personal records.
- Communication data: onboarding messages, chat messages, AI responses, change requests and derived profile or plan proposals.
- Voice data: a first name and short workout phrases used for text-to-speech, generated audio files and local cache information.
- Purchase and entitlement data: product identifiers, entitlement and subscription status, transaction identifiers, expiry and renewal status when purchases are enabled.
- Device and log data: IP address, user agent, URL, timestamp, response status, app version, platform, country or locale, and error or security events.
- Consent and rights-request data: type, version, status and timestamp of declarations, export requests, deletion requests and withdrawals.
4. Marketing website, server logs and local assets
When the website is accessed, the hosting or web server processes connection data required to deliver it. This may include IP address, date and time, requested address, response status, transferred data volume, referrer, browser and operating-system information.
This processing supports secure and stable delivery, troubleshooting and abuse prevention. The legal basis is Art. 6(1)(f) GDPR. Logs are deleted when they are no longer required for these purposes; data relating to a specific security incident may be retained for investigation and legal enforcement.
Fonts, images, stylesheets and scripts are served by Oli. At the time of this policy, the website uses no advertising or analytics cookies, external web fonts or advertising-profile identifiers. Any future change will be reviewed before deployment and consent will be requested where required.
If you contact us by email or phone, contact details and message content are processed to answer the request. The legal basis is Art. 6(1)(b) GDPR for contract-related requests and otherwise Art. 6(1)(f) GDPR.
5. Account, registration and session management
Oli uses Supabase Auth for registration, email confirmation, sign-in, password recovery and session management. Email address, internal user ID, authentication and session data are processed under Art. 6(1)(b) GDPR. Security logs may additionally be processed under Art. 6(1)(f) GDPR to protect accounts and infrastructure.
Access and refresh tokens are stored in the iOS Keychain. Non-sensitive preferences may be stored in UserDefaults. Sign-in methods that are only prepared in code but not verified as live are not represented as currently available.
6. Onboarding, training profile and health data
During onboarding, Oli may process goals, daily routine, experience, availability, equipment, preferences, body data and limitations in order to prepare a plan. Guest onboarding can begin before an account is created. Inputs, the current onboarding step and a preliminary profile may be sent through the Oli gateway to the selected AI service.
General non-health information is processed under Art. 6(1)(b) GDPR where necessary for pre-contractual steps or a requested feature. Health-related information, including injuries, symptoms, body, strength and load data, may be processed only after explicit consent under Art. 9(2)(a) GDPR.
Required launch gate: Accepting terms and a privacy policy together is not explicit health-data consent. A separate, freely given, informed, versioned and revocable consent step is required before health-related guest onboarding, personalization or disclosure to AI providers is enabled publicly.
7. Training plans, workouts and progress
Depending on use, Oli stores profiles, strength baselines, plans, scheduled workouts, completed workouts, sets, repetitions, weights, perceived exertion, notes, streaks and progress values. The purposes are to provide the training service, show progress and suggest future sessions.
The legal basis is Art. 6(1)(b) GDPR and, where health data is involved, Art. 9(2)(a) GDPR. Supported plan changes made from chat or profile information are presented for confirmation before being saved.
Workout drafts, profile data and history may be stored locally. Signed-in use may synchronize data online. Oli does not promise conflict-free real-time synchronization or an indefinite retry queue for every failed upload.
8. AI coach, plan generation and plan changes
Ask Oli is an AI system. Onboarding responses, training-plan drafts, chat responses and certain plan changes are sent through the Oli gateway to OpenRouter and a selected downstream model provider.
Depending on the feature, the necessary context may include display name, derived age, gender entry, height, weight, goals, sport, availability, equipment, injury or symptom information, strength values, the current plan, recent saved workouts and parts of the chat history. This data is not anonymous merely because the email address is omitted.
The legal basis for a requested AI feature is Art. 6(1)(b) GDPR. Explicit consent under Art. 9(2)(a) GDPR is additionally required whenever health data is included. AI output may be wrong and is not medical diagnosis or treatment.
Chat messages and coach responses may be stored with the account to provide history. Model identifiers, token usage, thread IDs and quota information may also be stored. Operational and security logs are limited to what is necessary and must follow the applicable retention concept.
9. “Oli Voice” text-to-speech
Oli Voice is text output, not voice input, and does not record the microphone. When enabled, the app downloads a voice catalogue and may request individually generated short audio. A first name, exercise name, set or repetition count, weight or short workout prompt may be sent through the gateway to OpenRouter and the selected speech-model provider.
Generated audio may be stored in the gateway’s voice-media area and in the local app cache. The legal basis is Art. 6(1)(b) GDPR and, where an announcement reveals health or performance data, Art. 9(2)(a) GDPR.
A binding retention period for individual audio and its inclusion in account deletion must be implemented before public activation. Complete automatic deletion is not promised until that process has been verified.
10. Apple Health, Apple Watch, notifications and widgets
Apple Health and Apple Watch features are optional and used only after system permission. Depending on permission, Oli may read workouts, heart rate, active and resting energy, height and weight, and may write workouts, active energy, height and weight. During supported workouts, measurements may be transferred between the paired Apple Watch and iPhone.
Permissions can be changed in iOS or watchOS. Apple system permission does not replace consent required toward Oli. Health data is not used for advertising and is not sold. Data stored in Apple Health is separate from the Oli database and is not automatically removed by deleting an Oli account.
With operating-system permission, Oli may show local reminders, rest timers, motivational notices, widgets and Live Activities. These features can be disabled and may reveal fitness information on a visible device.
11. Apple App Store, subscriptions and LinkFive
Paid products are prepared in the reviewed version but are not represented here as publicly released. Purchases and payments, once enabled, are handled through the Apple App Store under Apple’s own privacy information.
LinkFive is prepared for entitlement assignment. The code may send an internal Supabase user ID, platform, country or locale, app version, environment and a LinkFive identifier. This data is pseudonymous, not anonymous; health data and chat content are not necessary for entitlement management.
Art. 6(1)(b) GDPR may apply to active subscriptions and Art. 6(1)(c) GDPR to legally required transaction records. The necessity and legal basis of transfers without an active purchase must be assessed separately.
12. Recipients, processors and international transfers
Supabase
Supabase is used for authentication, PostgreSQL database services and edge functions. Account, profile, training, chat, plan, consent, audit, subscription, export and deletion-request data may be processed there. The repository configures the project for the Frankfurt region, but this alone does not prove that all processing occurs exclusively in Germany.
Hosting and the Oli gateway
The website, API gateway, exercise media, logs and voice media are served through commissioned server infrastructure. Hosting contracts, data-centre locations, subprocessors, backups and log locations are maintained in the internal processing documentation.
OpenRouter and model providers
OpenRouter processes AI and speech requests and sends them to the selected downstream model provider. Processing outside the European Economic Area, particularly in the United States, may occur. Public use requires appropriate processor terms, a documented provider chain, safeguards under Art. 44 et seq. GDPR, and technically enforced storage and training settings.
Apple and LinkFive
LinkFive processes the identity and entitlement data described above. Apple processes data for the App Store, HealthKit, Apple Watch, notifications, widgets and Live Activities under the applicable Apple terms.
Oli does not claim that all data is hosted exclusively in Germany. An EU database region alone also does not establish full GDPR compliance.
13. Security and retention
The codebase provides for encrypted transport, iOS Keychain storage for session tokens, server-side secrets, authenticated gateway routes and Row Level Security to separate user-owned data. Privileged database, AI and server credentials are not intended to be stored in the app.
Personal data is retained only for as long as necessary for its purpose or for legal obligations and legal claims. Account, profile, plan, workout and chat data are generally needed while the account exists unless a shorter period or deletion applies. Consent evidence may be retained for accountability; purchase records may be subject to statutory retention. Backups are overwritten under the documented backup cycle and blocked from normal production use until then.
The reviewed codebase does not yet provide a fully verified retention matrix for chat, training, voice files, logs and backups. No universal automatic deletion period is therefore claimed.
14. Consent, export and account deletion
Consent is voluntary and may be withdrawn at any time for future processing through the relevant privacy settings or by emailing support@olicoach.app. Withdrawal does not affect prior lawful processing. Withdrawing health-data or related AI consent requires affected features to stop and data that is no longer needed to be deleted or restricted.
An export request can be created in the app. The reviewed backend currently records the request; a complete export file and secure download route have not yet been verified. Access and portability requests can therefore also be made directly by email.
An account deletion request may be scheduled with a 14-day cancellation period. The reviewed code does not yet prove a complete automated deletion across Supabase Auth, all tables, audit records, voice files, LinkFive, logs and backups. Until this is verified, requests are additionally handled through the support address and a scheduled request is not represented as an already completed deletion.
15. Your rights, objection and complaints
Subject to the legal requirements, you have rights of access under Art. 15 GDPR, rectification under Art. 16, erasure under Art. 17, restriction under Art. 18 and data portability under Art. 20. You may object to processing based on Art. 6(1)(e) or (f) GDPR for reasons arising from your particular situation. Consent may be withdrawn under Art. 7(3) GDPR.
To exercise these rights, contact support@olicoach.app. Reasonable identity verification may be required before sensitive data is disclosed.
You may lodge a complaint with a competent supervisory authority. For the controller’s location, this includes the Bavarian Data Protection Authority, Promenade 18, 91522 Ansbach, Germany.
This policy is updated when features, recipients or applicable law change. Where a new consent is required, the related processing will not begin until that consent has been obtained.
Read the German privacy policy.