Legal
Privacy Policy
Last updated 15 July 2026
The short version
- Raw Apple Health data and precise route series remain on your device; Hytive syncs necessary summaries and derived values.
- Health processing and optional social sharing require separate consent and are not used for advertising or cross-company tracking.
- The website uses no analytics, advertising pixels, cookies or browser storage. Hosting still requires ordinary request and security logs.
- The app provides export, consent withdrawal, connector disconnection and account deletion controls.
1 · Controller and contact
The controller is Bent Eisheuer, Freisinger Landstraße 47a, 85748 Garching, Germany. Privacy requests: privacy@hytive.app. No data-protection officer has been appointed. You may complain to a supervisory authority; our competent authority is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach.
2 · Website requests and shared workout links
Vercel hosts this website. To deliver and secure it, Vercel processes request data such as IP address, date and time, requested address, response status, referrer, browser and device information. The basis is Art. 6(1)(f) GDPR: our legitimate interest in secure, reliable delivery. We use no website analytics, advertising pixels, cookies, local storage or comparable device identifiers.
This website renders a shared-workout summary from the address fragment after the # marker. Browsers do not send that fragment to this server; the recipient's device renders it locally. The page is marked no-index/no-cache, does not put workout details into social-preview metadata, and sends a no-referrer policy. A link generated in the earlier query format makes one request containing those parameters before this website redirects to the fragment format; hosting security logs may therefore retain that first request for their short rolling cycle. Hytive does not copy either payload into an application database. The basis is Art. 6(1)(b) GDPR for the sharing feature requested by the account holder and, for any health-derived fields, the account holder's explicit Art. 9(2)(a) consent. Recipients should not republish a private link without the account holder's permission.
3 · Account, profile and activity data
Depending on the features you use, Hytive processes:
- Apple sign-in identifier, email or relay email, account ID and session data;
- name, handle, goals, sports, work pattern and optional body or fitness details;
- workout summaries, plans, notes, daily recovery values and derived load, readiness and fatigue results;
- optional avatar, social graph, reactions and the visibility choices you make;
- connector authorization metadata and purchase or entitlement status when those features are active.
Account and requested service operations rely on Art. 6(1)(b) GDPR. Health and fitness processing begins only after separate consent under Arts. 6(1)(a), 7 and 9(2)(a) GDPR. You can refuse or withdraw that consent without losing your account, but health-dependent features cannot operate without it.
4 · Data that stays on the device
Raw Apple Health data remains in Apple Health. Raw GPS routes and timed heart-rate, power and cadence series remain protected on your device and are excluded from device backup. Hytive syncs necessary summaries and derived values. Voice workout capture runs only when Apple's on-device recognition is available; audio is not uploaded. Workout-photo recognition runs on device; the photo is not uploaded. A confirmed summary is stored only if you save it.
5 · Apple Health, recording and notifications
After Hytive consent and Apple's permission screen, Hytive reads the categories shown there for workout and recovery features and writes a recorded workout only when you ask. Precise location is used during an outdoor recording you start. You can change Health and location permissions in iOS Settings. Optional reminders are generated on device. Health data is not used for advertising or sold.
6 · Optional social and connected services
Social starts off and requires separate consent. New activities remain private unless you choose another visibility. Depending on that choice, other Hytive members may see your profile, selected workout summary, a place-free route shape and selected readiness context. Turning Social off makes existing activities private and removes the social graph and avatar according to the in-app flow.
If you connect a supported fitness provider, Hytive requests the scopes needed for the selected import or export. OAuth tokens are stored server-side. Disconnecting or withdrawing attempts provider revocation and removes Hytive's token; where remote revocation cannot be confirmed, the app tells you how to revoke at that provider. Connected providers process data independently under their own privacy terms.
7 · Recipients and international transfers
- Supabase: EU-region authentication, database, storage and server functions as processor.
- Vercel: global website hosting and request/security metadata as processor.
- Apple: sign-in, on-device frameworks, Apple Health and App Store purchases under Apple's terms.
- RevenueCat: entitlement and purchase status if in-app billing is configured.
- Lemon Squeezy: independent merchant of record only if a web checkout is activated; no web checkout is currently live.
- Any fitness provider you deliberately connect, as an independent controller.
Providers can involve access from outside the EEA. Depending on the receiving entity and location, transfers rely on an EU adequacy decision, including the EU–US Data Privacy Framework for certified recipients, and/or EU Standard Contractual Clauses. Contact us for information about the applicable safeguard. We review processor, subprocessor and transfer terms when a provider or data flow changes.
8 · Retention and security
Account and profile data lasts until account deletion. Hytive health data lasts until you delete it, withdraw health consent or delete the account. OAuth state expires after ten minutes; tokens last only while connected. Social data and the avatar are removed on Social withdrawal or account deletion. Temporary exports follow the share flow and operating-system cleanup. Provider logs and backups use short rolling cycles under the current account and processor terms. Transaction records controlled by Apple or a merchant of record can remain for their statutory accounting and fraud duties. Support mail is retained only while needed for the request or a legal claim.
Controls include TLS, managed encryption at rest, Apple Keychain, row-level access rules, least-privilege access, server-only secrets, protected local files and private defaults. No online service can eliminate every security risk.
9 · Export, deletion and your rights
In-app Settings provides export, consent withdrawal, connector disconnection and account deletion. You also have rights of access, rectification, erasure, restriction, portability, objection and withdrawal without affecting earlier lawful processing, plus the right to complain to a supervisory authority (Arts. 15–21 and 77 GDPR). Contact privacy@hytive.app.
10 · Automated outputs, children and changes
Hytive's deterministic training recommendations do not produce legal or similarly significant effects under Art. 22 GDPR and are not medical diagnosis or treatment. Hytive is for people aged 16 or older. Material purpose or processing changes require an updated notice and, where consent is the basis, renewed consent before processing.
Contact
Privacy questions: privacy@hytive.app. Provider details are in the Imprint.