MaGymus Logo ← Back to Home
Europa
🇩🇪 Deutsch
🇬🇧 English
🇪🇸 Español
🇫🇷 Français
🇮🇹 Italiano
🇵🇱 Polski
🇳🇱 Nederlands
Amerika
🇧🇷 Português
Asien-Pazifik
🇯🇵 日本語
🇰🇷 한국어
🇹🇼 繁體中文

Privacy Policy

Last Updated: July 2026

1. Privacy at a Glance

Responsible Entity

The data controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws is:

Markus Rohling
c/o POSTFLEX PFX-452-617
Emsdettener Straße 10
48268 Greven
Germany

Phone: +49 155 10033522
Email: support@marrohstudio.com

Further details can be found in the Legal Notice (Impressum).

General Notes about the App (Privacy-First)

MaGymus is an offline training app developed according to the "Privacy by Design" principle. All your workouts and health data (Art. 9 GDPR) remain exclusively local on your device. An internet connection is only required by the app at the moment you make in-app purchases or the validity of your subscription is verified via the secure servers of the app stores (as well as our service provider RevenueCat).

Data Collection on this Website

This website is designed as a static page. We use no cookies, no analytics tools, and no external tracking scripts.

To protect your privacy, all resources (fonts, icons, images) are loaded directly from our own web server. There are no connections to third-party servers (e.g., Google Fonts).

Local Storage (localStorage)

This website uses the localStorage feature of your browser solely to store your selected language preference (German/English). This storage serves a function explicitly requested by the user pursuant to § 25 (2) No. 2 TDDDG (German Telecommunications-Telemedia Data Protection Act) and therefore does not require consent. The stored data does not leave your browser and is not transmitted to any server.

2. Data Collection and Use

Basic Usage (Without Account)

MaGymus operates on an "Offline-First" principle. You do not need to create a user account to use the app. No email address, password, or login is required.

Hosting (IONOS) and Server Log Files

We host our website with IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. When you visit our website (e.g., to read this privacy policy), IONOS automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These include: IP address, browser type/version, operating system used, referrer URL, time of the server request. This data is not merged with other data sources. The collection of this data is based on Art. 6(1)(f) GDPR for the error-free provision and security of the website. We have concluded a Data Processing Agreement (DPA) with IONOS.

3. Data Processing in the App

Local Data Storage & Backups

Your training data, body metrics, and settings remain in the local database of the app on your smartphone. If you delete the app, all data contained therein is irrevocably deleted from your device. We do not synchronize or store anything on external cloud servers.

Personal Responsibility for Backups: Since we do not store any data on our servers, you are solely responsible for backing up your data. Please note that local app data may be backed up in the automatic cloud backups of your operating system (Apple iCloud), unless you have deactivated this in your device settings. We as the provider have no access to these system backups.

No AI Training

All algorithmic calculations and progression recommendations take place exclusively locally on your end device (on-device processing). We guarantee that your personal training and health data will never be used to train Artificial Intelligence (AI) or machine learning models of third parties or transmitted to such services.

Sensitive Health & Body Data (Art. 9 GDPR)

The app processes information about your age, biological sex, body weight, and height to calculate sports science metrics (such as Wilks Score, RFM, FFMI) and to optimally adjust the coaching system to you. Because these are particularly sensitive health data according to Art. 9 GDPR, we apply the highest protection standards: this data never leaves your device. There is no transmission to the cloud, no profiling on servers, and no disclosure to third parties (such as insurance companies or advertising networks).

Device Permissions (Camera, Biometrics & Notifications)

To use features like the progress photo vault, the app requires access to your camera and/or local photo gallery. The captured images remain in the secure sandbox of the app and are never uploaded to our servers. If you secure the app using biometric features (Face ID / Touch ID), the matching is performed exclusively encrypted via the operating system. The app has no access to your raw biometric data at any time.

Push Notifications: If you grant the app permission to send you notifications (e.g., for set rest timers), these are exclusively "Local Notifications" generated directly by your device. We do not use external cloud push servers (like APNs or Firebase Cloud Messaging) for marketing purposes.

In-App Purchases (RevenueCat & App Stores)

If you choose the "Pro" version, payment processing is handled exclusively via the Apple App Store. Apple acts as an independent data controller for the payment process.

For the secure processing, verification, and management of purchases, we use the service RevenueCat (as a data processor). The following data is processed:

  • Purchase and Transaction Data: The "receipt" from Apple, the selected package, time of purchase, expiration date, and status.
  • Anonymous App User ID: A randomly generated ID tied to the purchase.
  • Metadata: Country (for taxes/currency), operating system version, and app version.

The legal basis for this data processing is Art. 6(1)(b) GDPR (performance of a contract to provide Pro features). We have concluded a Data Processing Agreement (DPA) with RevenueCat. RevenueCat is based in the USA. Data transfer to the USA takes place on the basis of the EU-US Data Privacy Framework (adequacy decision according to Art. 45 GDPR) or the Standard Contractual Clauses (SCC) of the EU Commission to guarantee a European level of data protection.

IMPORTANT: Absolutely NO training data, body weights, muscle analyses, or personal profile information is sent to RevenueCat or Apple.

App Store Telemetry Data (Crash Reporting & Analytics)

MaGymus itself does not integrate any hidden tracking SDKs (like Firebase Analytics, Facebook Pixel, etc.). However, if you download and use the app via the Apple App Store, Apple collects its own standard telemetry data (e.g., download statistics or anonymous crash reports), provided you have agreed to tracking in your operating system settings. We have no influence on this basic data collection by the platform operator.

Data Export & Sharing of Content (e.g., iOS Share Sheet)

The app offers functions to export your training data (as CSV/JSON) as well as to share content such as progress photos via the native iOS interfaces (e.g., iOS Share Sheet).

As soon as you export data or transfer it to third-party apps (such as WhatsApp, Instagram, email clients), the data leaves our protected area. From the moment of sharing, the privacy policies of the respective third-party providers apply. You are solely responsible for the security and further processing of the shared data.

Outgoing Internet Connections (When the App Communicates Online)

Although MaGymus is designed as an offline-first app and stores your training data exclusively locally, the app establishes outgoing internet connections in the following situations:

  • Subscription & Purchase Verification: Upon app startup and when managing Pro features, a connection is established to the app store servers (Apple) and our billing service provider RevenueCat to verify license validity.
  • Accessing Web Pages (Legal Documents): Clicking on links to terms of service, privacy policies, or the legal notice opens your device's system browser to load the pages from our website (marrohstudio.com/magymus). Note: The check for updated terms in the app is performed purely offline via internal version comparison; a connection is only established when clicking the link to read the document.
  • External Links & Support: Tapping links to the Instagram channel or launching an email (e.g., support requests / feedback) redirects you to the respective external apps/services.
  • App Store Ratings: Launching an in-app rating dialog communicates directly with the servers of the platform operator (Apple).

Protection of Minors

The use of our app is only permitted for individuals aged 16 and over. We do not knowingly process personal data from children under 16. Should we discover that we have unintentionally processed data of a minor (e.g., through email contact), this data will be deleted immediately.

4. Contacting us via Email

If you contact us via email (e.g., support requests), your email address, your IP address, and the content of your message will be stored to process and answer your request.

The processing of this data is based on Art. 6(1)(b) GDPR (if your request is related to the fulfillment of a contract) or Art. 6(1)(f) GDPR (legitimate interest in the effective processing of inquiries addressed to us). We do not share this data without your consent. We have concluded a Data Processing Agreement (DPA) with our email provider (IONOS SE).

5. Your Rights

Since we do not store any identifiable personal data on servers, traditional data subject requests (information, correction, deletion according to Art. 15-17 GDPR) effectively run into a void with us. You have full control over your data:

  • Right to Information: You can view all stored data at any time in the app (e.g., via the export function).
  • Right to Rectification: You can correct erroneous workouts or body metrics directly in the app.
  • Right to Erasure (Art. 17 GDPR): You exercise your right to erasure by simply uninstalling the app from your device. This completely and irrevocably destroys the local database. To additionally request the deletion of any server-side transaction data (purchase history at RevenueCat/Apple), please contact us informally via email at support@marrohstudio.com.
  • Right to Object (Art. 21 GDPR): To the extent we process data on the basis of our legitimate interest (Art. 6(1)(f) GDPR) (e.g., website server log files), you have the right to object to this. However, since the server logs are strictly necessary for the operation of the website, there is a compelling legitimate interest on our part.
  • Right to Lodge a Complaint (Art. 77 GDPR): You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your data violates the GDPR.

Contact

For questions regarding data protection, please contact the address provided in the Legal Notice.