wyll
Last updated: 29 September 2026
Controller: WYN GmbH, Retzdorffpromenade 3a, 12161 Berlin, Germany
Email: support@wyll.app
English translation for convenience. The German version is the legally authoritative one.
The controller within the meaning of the GDPR is:
WYN GmbH
Retzdorffpromenade 3a
12161 Berlin
Germany
Email: support@wyll.app
No data protection officer has been appointed, as the requirements of Art. 37 GDPR and § 38 German Federal Data Protection Act (BDSG) are not met (in particular, fewer than 20 employees are permanently engaged in the automated processing of personal data).
Purpose: Account creation, login, password reset, communication.
Retention: Until account deletion, followed by anonymisation within 30 days.
Purpose: Personalisation of training plans and recommendations.
Gender: We use this information for three things: to classify your strength, to estimate starting weights for exercises and – if you use the Arena – to form your comparison group. We calculate starting weights on our own server. For workout creation, the information is part of the training details sent to our AI provider (section 2.3). “Prefer not to say” is always an option. For “diverse” and “prefer not to say” we estimate starting weights more conservatively; they adjust once you log your first sets. You can change this information in your profile at any time.
Age: We calculate your age from the date of birth you enter when you register. We use it for the age check (18 and over), for figures we calculate on our own server (e.g. estimated maximum heart rate, fitness scores) and – if you use the Arena – for your comparison group. Our AI provider receives your age only as an age band (“under 40”, “40–54”, “55–64” or “65+”), never your exact age or date of birth.
What of this goes to the AI provider: For workout creation we send the training details from your profile (e.g. goal, fitness level, equipment), your body weight (if provided), your gender and your age band – without direct identifiers (section 2.3). Height is not sent.
Retention: For the term of the user agreement; thereafter deletion or anonymisation, subject to statutory retention obligations.
Where voluntarily provided, we collect:
Points of collection: During onboarding (limitations) and when creating an AI workout ("What should we go easy on today?"). Daily readiness and the selection of injuries/limitations (body regions) are available across all tiers — including free access and without an account (anonymously). Medical notes in the free-text field are available as part of the Premium features.
Legal basis: Explicit consent pursuant to Art. 9 (2) (a) GDPR. Consent is obtained at the point of entry: selected health information first remains locally on the device and is processed or transmitted only after consent has been given (confirmed on submission). This consent is separate from acceptance of the Terms and Privacy Policy and from the safety disclaimer, and — for the same purpose — continues to apply to future entries until withdrawn. It is voluntary; the app remains usable without health information (the workout is then created without it).
Anonymous users: Consent can also be given without an account; it is then stored on the device. For accountability purposes (Art. 5 (2) GDPR) we log the timestamp, the version and a hashed device identifier on the server — no plain-text identifiers.
Purpose: Exclusively to adapt training suggestions (avoiding contraindicated exercises, calibrating load). No use for advertising or any other purpose.
Transfer to the AI provider: The information required to create a workout (including daily readiness and injury selection) is transmitted to our AI provider (Anthropic PBC, USA) for generation — across all tiers (including free and anonymous use). Medical free-text notes are included as part of Premium personalisation.
No identifiers in the transfer: Only the training and health information required to create the workout is transmitted. Direct identifiers — name, email address, user ID and device identifier — are not part of the transfer; the AI provider cannot attribute the information to a specific person on its own. It nevertheless remains personal data, because we can establish that link — which is why consent under Art. 9 (2) (a) GDPR is required.
Data minimisation: A central HealthFreeTextPolicy applies (length and list limits, removal of control characters, no content logging). Free-text session feedback (TrainingSession.notes) is not passed to AI interfaces.
Retention: Injury, limitation and medical information until consent is withdrawn or the account is deleted. Persisted daily readiness entries (for logged-in users) are additionally deleted on a rolling basis after 90 days; upon withdrawal, health-related readiness entries (other than the neutral entry "normal") are deleted immediately. Consent can be withdrawn at any time in the settings. After withdrawal, stored injury and limitation information is deleted and no further health information is transmitted.
Purpose: Progress evaluation, adjustment of future training plans.
Retention: For the term of the user agreement; thereafter deletion or anonymisation.
Training you log yourself: You can log training you did outside the app, for example a run or a class. The entry is used to adapt your next workout (after a hard, longer session it comes out lighter and the body regions you loaded are spared) and to calculate your weekly training load. For creating your workout, only the sport, the focus, the number of days since the session and the duration and effort levels of the last seven days are sent to the AI provider (section 2.3), without direct identifiers. The entries do not count towards the Arena, leaderboards, badges or streaks. You can change or delete any entry in the app at any time; all entries are deleted together with your account. They are part of your data export (section 6).
When using the community features (Arena, leaderboards, challenges, badges, creating training locations), certain information becomes visible to other users, in particular username and avatar as well as aggregated performance values (e.g. ranking, XP, streak).
Purpose: Provision of the community/competition features (performance of a contract); protection and improvement of those features (legitimate interest).
Note: Users themselves control which information is visible through their choice of username and avatar. Unlawful content or misuse can be reported by email to support@wyll.app.
Retention: Until account deletion or removal of the relevant content.
Premium subscriptions and in-app purchases are processed through the app stores (Apple, Google); subscription status is managed via RevenueCat. The provider has no access to full payment details (e.g. credit card numbers).
The provider processes and stores: app user ID (pseudonymous identifier), subscription status, product/plan, billing period, purchase and renewal timestamps, and the associated device/transaction identifiers used to synchronise Premium status.
Purpose: Activation and management of Premium features, subscription synchronisation, fraud prevention, invoicing and accounting records.
Retention: Subscription-related data for the term of the contract; invoicing and tax-relevant data for 10 years (§ 147 German Fiscal Code). During the statutory retention period, processing is restricted to the retention purpose (Art. 18 GDPR) instead of the data being deleted.
Purpose: System security, troubleshooting, fraud prevention.
To limit free AI workout generations, wyll processes a pseudonymous device ID (UUID) generated on the device, stored locally and transmitted to the server when an AI workout is created.
Purpose: Limiting free generations per day/device or account, abuse prevention.
Linkage: No linkage with IP address or advertising ID; no quota evaluation for Premium users.
Retention: Anonymous generation logs are deleted automatically after 90 days; entries linked to an account may be kept longer for statistics/support.
The app can send push notifications (e.g. training reminders, challenge/streak status). A device-side push token is processed for this purpose and delivered via the respective platform service: the Apple Push Notification service (APNs) on iOS and Firebase Cloud Messaging (FCM) of Google LLC on Android. Firebase is used solely for this push delivery — not for analytics, Crashlytics, authentication or file storage.
Delivery via Expo: Delivery is technically routed through the push service of 650 Industries, Inc. (Expo), USA. The push token and the content of each notification are transmitted to Expo and forwarded from there to Apple (APNs) or Google (FCM). Expo processes this data as a processor solely for delivery.
Notification content: The texts may contain training-related information — such as the title of a completed workout, the name of an unlocked achievement, the training plan week, or the length of a current training streak. They contain no health information from the profile (injuries, pre-existing conditions), no name, no email address and no payment data. Because notifications can appear on the lock screen, they are visible to anyone with access to the device.
Legal basis: Functional notifications for the performance of the contract ((b)); purely promotional notifications only on the basis of consent ((a)).
Control: Push notifications can be disabled at any time in the device or app settings. After withdrawal, the stored push token is deactivated.
Retention: The push token is deleted or deactivated as soon as notifications are switched off, the platform service reports the token as invalid, or the account is deleted. We log sent notifications (type, title, text, time, delivery status) for troubleshooting and so that you do not receive the same reminder twice; this log is deleted automatically after 90 days, and immediately when the account is deleted.
After explicit consent we store pseudonymous first-party events (no third-party SDK): opening the app, starting and completing registration (including the method chosen: email, Apple or Google), which onboarding steps are completed, whether a workout generation starts, succeeds or fails (with a technical error cause, e.g. timeout or network error), whether a workout is created, started, abandoned or completed, when a Premium prompt appears, and the start of a trial period and completion of a purchase (with plan identifier, without payment data) — each with timestamp, app version, platform and user ID. Via the user ID the events are attributable to the account (pseudonymous, not anonymous). We do not collect training notes or other free text, health information, name, email address, location or advertising IDs.
Legal basis: Art. 6 (1) (a) GDPR (consent). Consent is voluntary; the app works fully without it.
Storage / recipients: our own servers at Hetzner Online GmbH in Germany as processor. These events are not disclosed to third parties, not used for advertising and not combined with data from other apps.
Retention: 90 days, then automatic deletion; earlier on withdrawal with a deletion option or on account deletion.
Withdrawal: Settings → Privacy → Usage data for product improvement. Withdrawal is as easy as giving consent (a switch plus confirmation). Processing until withdrawal remains lawful.
On the website wyll.app we measure reach with Matomo, an open-source analytics software. We run Matomo ourselves on our server at Hetzner Online GmbH in Germany. The data does not go to any analytics provider and is not combined with app accounts, waitlist addresses or health data.
Without cookies: Matomo sets no cookies and stores nothing in your browser. The script does not read characteristics such as screen resolution or installed plugins. Matomo groups the page views of one visit using a checksum. It is calculated on the server from the operating system, browser, browser language and the shortened IP address, together with a random key. Matomo discards this key after 24 hours at the latest and generates a new one. On the next day the same browser therefore yields a different checksum: Matomo does not recognise returning visitors and does not track you across other websites.
Data: pages viewed, time, duration of the visit, referring URL, browser, operating system, device type, language, the country derived from the shortened IP address, and events such as the waitlist signup (without the email address). The IP address is shortened by two bytes before it is stored (e.g. 192.168.0.0).
Purpose and legal basis: We want to know how many people visit the website, which pages they read and whether the waitlist signup works. The legal basis is our legitimate interest in data-minimising reach measurement (Art. 6 (1) (f) GDPR). Nothing is stored on your device for this. The script reads only what the measurement needs: page address, page title, referring URL, your device's local time and whether "Do Not Track" is enabled. Your browser sends its language and browser identifier with every page request anyway.
Retention: We automatically delete the raw data of individual visits after 14 months. After that, only aggregated statistics without personal reference remain.
Recipients: none. Hetzner Online GmbH hosts the server as a processor (section 3).
Objection: You can object to the measurement at any time (Art. 21 GDPR). If you enable "Do Not Track" in your browser, Matomo does not record your visits. Alternatively, an informal email to us is sufficient.
Premium status and the health/training profile can be attributed to the same user via the same app user ID. The legal bases nevertheless remain strictly separate:
Health data is not processed for payment purposes, nor vice versa. Health information is transmitted to the AI provider only where consent has been given (section 2.3); medical free-text notes are processed as part of Premium personalisation.
On the website you can leave an email address in order to be informed once about the launch of the app ("Early Access").
Data: Email address, the language of the form, time of signup, time of double opt-in confirmation, and the status of the signup (unconfirmed / confirmed / invited / rejected). For the first 200 confirmed signups, in addition: the promo code, stored only as a check value (hash), with the time it was issued and the time it expires. No further data is collected; signing up does not require an account.
Legal basis: Consent pursuant to Art. 6 (1) (a) GDPR. Consent becomes effective only when the confirmation link in the double opt-in email is opened (proof of consent also for the purposes of § 7 German Act Against Unfair Competition (UWG) regarding the later launch notification). The notice next to the form states the purpose and scope ("one-time launch notification, no newsletter, no sharing").
Purpose: Solely the launch notification or the invitation to the early access test. The first 200 confirmed signups (in order of confirmation) also receive a personal code for three months of Premium in this notification, redeemable for 30 days. Anyone who signs up after the launch receives the notification right after confirming. If someone requests a replacement for a lost code on wyll.app, we send it to the same address. No promotional use beyond this, no newsletter, no profiling and no merging with later app accounts or health data. Until a code is redeemed we know which entry holds which code; this link is deleted when the code is redeemed (section 2.13a).
Recipients: Hetzner Online GmbH (database hosting), Brevo SAS (sending the double opt-in confirmation, the launch notification and a requested replacement code) and Cloudflare, Inc. (website transport/protection) — each as a processor (section 3). No disclosure for any other purpose takes place.
Retention: Until withdrawal, but at most three months after the launch notification has been sent; the entry is deleted thereafter. If the app is not released before that point, we delete entries no later than 24 months after signup. Unconfirmed signups (without double opt-in) are deleted after at most 30 days.
Withdrawal and deletion: At any time, informally, by email to support@wyll.app — the address is then deleted from the list without undue delay. Withdrawal does not affect the lawfulness of processing carried out up to that point.
Note on reach measurement: We count a successful signup in Matomo as the event "waitlist_signup" (section 2.11), without the email address.
To redeem a promo code on wyll.app/einloesen, you enter the code and the email address of your wyll account. This address may differ from your waitlist address. If code and account match, we send a confirmation link (valid for 24 hours) to the account address. Only clicking it unlocks three months of Premium. Premium then ends on its own; no subscription is created. The page gives the same answer in every case and does not reveal whether a code or an account exists. In the link in the email, the code follows a "#" and is therefore not sent to our server when the page loads.
Data: Code (hash only), user ID of the account, time of redemption. We use the account's email address only to find the account and send the confirmation email; it is not stored again for the offer.
Purpose: Unlocking Premium for three months; making sure each code is used only once and each account uses the offer only once.
Recipients: RevenueCat, Inc. (unlocking the Premium period for the user ID, sections 2.6 and 3), Brevo SAS (confirmation email) and Hetzner Online GmbH (database), each as a processor.
Retention: We store which account redeemed a code for six months from redemption (three months of Premium and three months for queries); we then delete this link. What remains is only that the code was redeemed, without reference to a person. The Premium status itself follows section 2.6.
We are required to be able to demonstrate that consent was given. To that end we log every grant and every withdrawal of consent.
Data: account ID, timestamp, type of consent (e.g. usage events, marketing), whether it was granted or withdrawn, and for usage events the version of the consent text. No IP address and no browser/device identifier — neither is required for the proof and is therefore not stored.
Purpose: Solely the proof required by Art. 7 (1) GDPR. These data are not used for analytics, personalisation or advertising.
Retention: Three years from the logged event, then automatic deletion. On account deletion the entries are deleted as well.
With audio coaching enabled (a Premium feature), announcements are spoken during a workout. There are two paths:
What is transmitted: Only the announcement text and the identifiers of the selected voice and speech model. The announcement text consists of fixed app strings (e.g. "switch sides", rest duration, countdown), exercise names and technique cues from our exercise catalogue. Name, email address, user ID, health information and user-entered free text are not transmitted. No account reference is sent along; the speech provider cannot attribute the request to a specific person.
Caching: Generated audio files are cached on our server so that the same sentence does not have to be transmitted again. The cache key is derived solely from text, voice, model and audio format and contains no reference to a person or account.
Processing locations: According to ElevenLabs, requests are processed in the USA, the EU or Singapore.
Purpose: Providing the audio coaching feature.
Retention: The cached audio files contain no personal data. For the feature's usage limit see section 2.8.
| Provider | Purpose | Location | Role / basis |
|---|---|---|---|
| Hetzner Online GmbH | Server hosting (backend and website reach measurement with Matomo, section 2.11) and email mailboxes for support/contact mail (support@wyll.app and aliases) |
Germany | Processor, Art. 28 GDPR |
| Cloudflare, Inc. | CDN, DNS, WAF (website/API); Cloudflare Access for admin access | USA | Processor, Art. 28 GDPR; third-country transfer via SCC / EU-US Data Privacy Framework |
| Brevo SAS (formerly Sendinblue) | Transactional emails (registration, password reset, GDPR confirmations) and waitlist double opt-in, launch notification and promo code emails (sections 2.13, 2.13a) | France | Processor, Art. 28 GDPR |
| RevenueCat, Inc. | Management/synchronisation of subscriptions and purchase status; unlocking the Premium period from a promo code (section 2.13a) | USA | Processor, Art. 28 GDPR; third-country transfer via SCC / EU-US Data Privacy Framework |
| 650 Industries, Inc. (Expo) | Delivery of push notifications to APNs/FCM (push token and notification content) | USA | Processor, Art. 28 GDPR; third-country transfer via SCC / EU-US Data Privacy Framework |
| Apple Inc. (App Store / Apple Push Notification service, APNs) | Payment processing for in-app purchases, app delivery; push delivery on iOS | USA / Ireland | Independent controller (payment) or processor (push delivery) |
| Google Ireland Ltd. / Google LLC (Google Play / Firebase Cloud Messaging, FCM) | Payment processing for in-app purchases, app delivery; push delivery on Android (FCM only, no Firebase Analytics) | Ireland / USA | Independent controller (payment) or processor (push delivery) |
| Anthropic PBC | AI processing (workout generation, including health data where consent is given; without direct identifiers) | USA | Processor, Art. 28 GDPR; third-country transfer via SCC / EU-US Data Privacy Framework |
| Eleven Labs Inc. (ElevenLabs) | Speech synthesis for audio coaching (converting the announcement text to audio; without any account or person reference, see section 2.15) | USA (contracting party); processing in the USA, the EU or Singapore | Processor, Art. 28 GDPR; third-country transfer via SCC / EU-US Data Privacy Framework |
| Functional Software, Inc. (Sentry) | Error diagnosis (crash/error reports). Independent of consent to usage events; legal basis Art. 6 (1) (f) GDPR | USA (contracting party); storage in the EU data region (Germany) | Processor, Art. 28 GDPR; third-country transfer via SCC / EU-US Data Privacy Framework |
Note on roles: For payment processing, Apple and Google act predominantly as independent controllers under their own privacy terms — to that extent there is no processor relationship with the provider. RevenueCat, by contrast, processes on behalf of the provider (a data processing agreement is in place).
Third-country transfers: Where data is transferred to the USA (Cloudflare, RevenueCat, Sentry as contracting party with EU storage region, the AI provider where applicable, the speech synthesis provider, Expo and the push services), this is based on standard contractual clauses (SCC) and/or certification under the EU-US Data Privacy Framework.
AI-generated training plans and recommendations are suggestions that users can accept or reject. No automated decision producing legal effects or similarly significantly affecting the user within the meaning of Art. 22 GDPR takes place.
| Right | Basis | How to exercise it |
|---|---|---|
| Access | Art. 15 GDPR | In-app: Settings → Privacy → Export data |
| Rectification | Art. 16 GDPR | Edit profile or email us |
| Erasure | Art. 17 GDPR | In-app: Profile → Delete account |
| Restriction | Art. 18 GDPR | On request by email |
| Data portability | Art. 20 GDPR | In-app: Export data (JSON) |
| Objection | Art. 21 GDPR | By email; website reach measurement also via "Do Not Track" in the browser (section 2.11) |
| Withdrawal of consent | Art. 7 (3) GDPR | In-app: Settings → Privacy → Usage data for product improvement (section 2.10) and Health data consent (section 2.3); waitlist: informally by email (section 2.13) |
Data subject rights in layered processing: On request, we will inform you which data is held by us, by RevenueCat and by Apple/Google. For data that Apple/Google process as independent controllers, access and erasure must be asserted directly against the respective platform operator; we will assist with forwarding such requests.
Right to lodge a complaint: Users may lodge a complaint with a data protection supervisory authority. The competent authority for Berlin is the Berlin Commissioner for Data Protection and Freedom of Information.
Please address requests to: support@wyll.app.
The mobile app does not use browser cookies. The following are stored on the device: authentication token (secure device storage), app settings (local), offline training data (temporarily, until synchronised), pseudonymous device ID (section 2.8), push token (section 2.9), and — only after consent to usage events (section 2.10) — a local queue under the key analytics.pendingProductEvents in app storage (AsyncStorage). The queue holds permitted event names and numbers/booleans/enums until they are transmitted to our own server or discarded; without consent it is not written to.
The website sets no cookies and stores nothing in your browser. Reach measurement with Matomo works without cookies (section 2.11).
Until 29 September 2026 the website used Google Analytics 4 after consent. Entries from that time (the key wyn-consent and the cookies _ga and _ga_JZXHC1YXCG) are no longer read or set by the website. You can remove them by clearing the site data for wyll.app in your browser.
As a rule, we store personal data until the account is deleted or the relevant consent is withdrawn, unless longer statutory retention obligations apply.
Upon account deletion or withdrawal:
Backup copies are stored solely for disaster recovery and are deleted automatically and irretrievably after no more than 30 days (rolling rotation). Targeted deletion of individual records within existing backups is not technically possible. We ensure that backups are used only for restoration, that deletion requests made in the meantime are re-executed in the event of a restore, and that backups are stored encrypted (AES-256).
If you delete your account in the app, you receive the confirmation directly in the app. If you request deletion by email, we reply by email once the deletion has been carried out, at the latest within one month (Art. 12 (3) GDPR). We do not send a separate confirmation email after a deletion in the app, because doing so would require us to keep your email address beyond the deletion. The deletion is logged internally (date, hashed identifier — no plain-text email address) in order to meet the accountability obligation under Art. 5 (2) GDPR. The deletion log contains no personal data and is deleted after 36 months.
In the event of material changes we will inform you by email or in-app notification. The current version is available at https://wyll.app/privacy.