Last Updated: July 2026
The data controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws is:
Markus Rohling
c/o POSTFLEX PFX-452-617
Emsdettener Straße 10
48268 Greven
Germany
Phone: +49 155 10033522
Email: support@marrohstudio.com
Further details can be found in the Legal Notice (Impressum).
MaGymus is an offline training app developed according to the "Privacy by Design" principle. All your workouts and health data (Art. 9 GDPR) remain exclusively local on your device. An internet connection is only required by the app at the moment you make in-app purchases or the validity of your subscription is verified via the secure servers of the app stores (as well as our service provider RevenueCat).
This website is designed as a static page. We use no cookies, no analytics tools, and no external tracking scripts.
To protect your privacy, all resources (fonts, icons, images) are loaded directly from our own web server. There are no connections to third-party servers (e.g., Google Fonts).
This website uses the localStorage feature of your browser solely to store your selected language preference (German/English). This storage serves a function explicitly requested by the user pursuant to § 25 (2) No. 2 TDDDG (German Telecommunications-Telemedia Data Protection Act) and therefore does not require consent. The stored data does not leave your browser and is not transmitted to any server.
MaGymus operates on an "Offline-First" principle. You do not need to create a user account to use the app. No email address, password, or login is required.
We host our website with IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. When you visit our website (e.g., to read this privacy policy), IONOS automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These include: IP address, browser type/version, operating system used, referrer URL, time of the server request. This data is not merged with other data sources. The collection of this data is based on Art. 6(1)(f) GDPR for the error-free provision and security of the website. We have concluded a Data Processing Agreement (DPA) with IONOS.
Your training data, body metrics, and settings remain in the local database of the app on your smartphone. If you delete the app, all data contained therein is irrevocably deleted from your device. We do not synchronize or store anything on external cloud servers.
Personal Responsibility for Backups: Since we do not store any data on our servers, you are solely responsible for backing up your data. Please note that local app data may be backed up in the automatic cloud backups of your operating system (Apple iCloud), unless you have deactivated this in your device settings. We as the provider have no access to these system backups.
All algorithmic calculations and progression recommendations take place exclusively locally on your end device (on-device processing). We guarantee that your personal training and health data will never be used to train Artificial Intelligence (AI) or machine learning models of third parties or transmitted to such services.
The app processes information about your age, biological sex, body weight, and height to calculate sports science metrics (such as Wilks Score, RFM, FFMI) and to optimally adjust the coaching system to you. Because these are particularly sensitive health data according to Art. 9 GDPR, we apply the highest protection standards: this data never leaves your device. There is no transmission to the cloud, no profiling on servers, and no disclosure to third parties (such as insurance companies or advertising networks).
To use features like the progress photo vault, the app requires access to your camera and/or local photo gallery. The captured images remain in the secure sandbox of the app and are never uploaded to our servers. If you secure the app using biometric features (Face ID / Touch ID), the matching is performed exclusively encrypted via the operating system. The app has no access to your raw biometric data at any time.
Push Notifications: If you grant the app permission to send you notifications (e.g., for set rest timers), these are exclusively "Local Notifications" generated directly by your device. We do not use external cloud push servers (like APNs or Firebase Cloud Messaging) for marketing purposes.
If you choose the "Pro" version, payment processing is handled exclusively via the Apple App Store. Apple acts as an independent data controller for the payment process.
For the secure processing, verification, and management of purchases, we use the service RevenueCat (as a data processor). The following data is processed:
The legal basis for this data processing is Art. 6(1)(b) GDPR (performance of a contract to provide Pro features). We have concluded a Data Processing Agreement (DPA) with RevenueCat. RevenueCat is based in the USA. Data transfer to the USA takes place on the basis of the EU-US Data Privacy Framework (adequacy decision according to Art. 45 GDPR) or the Standard Contractual Clauses (SCC) of the EU Commission to guarantee a European level of data protection.
IMPORTANT: Absolutely NO training data, body weights, muscle analyses, or personal profile information is sent to RevenueCat or Apple.
MaGymus itself does not integrate any hidden tracking SDKs (like Firebase Analytics, Facebook Pixel, etc.). However, if you download and use the app via the Apple App Store, Apple collects its own standard telemetry data (e.g., download statistics or anonymous crash reports), provided you have agreed to tracking in your operating system settings. We have no influence on this basic data collection by the platform operator.
The app offers functions to export your training data (as CSV/JSON) as well as to share content such as progress photos via the native iOS interfaces (e.g., iOS Share Sheet).
As soon as you export data or transfer it to third-party apps (such as WhatsApp, Instagram, email clients), the data leaves our protected area. From the moment of sharing, the privacy policies of the respective third-party providers apply. You are solely responsible for the security and further processing of the shared data.
Although MaGymus is designed as an offline-first app and stores your training data exclusively locally, the app establishes outgoing internet connections in the following situations:
The use of our app is only permitted for individuals aged 16 and over. We do not knowingly process personal data from children under 16. Should we discover that we have unintentionally processed data of a minor (e.g., through email contact), this data will be deleted immediately.
If you contact us via email (e.g., support requests), your email address, your IP address, and the content of your message will be stored to process and answer your request.
The processing of this data is based on Art. 6(1)(b) GDPR (if your request is related to the fulfillment of a contract) or Art. 6(1)(f) GDPR (legitimate interest in the effective processing of inquiries addressed to us). We do not share this data without your consent. We have concluded a Data Processing Agreement (DPA) with our email provider (IONOS SE).
Since we do not store any identifiable personal data on servers, traditional data subject requests (information, correction, deletion according to Art. 15-17 GDPR) effectively run into a void with us. You have full control over your data:
For questions regarding data protection, please contact the address provided in the Legal Notice.