Hardgainer Rats — Privacy Policy
STATUS: DRAFT (v0.1, 2026-07-28) — English version of the Polish Privacy
Policy (POLITYKA-PRYWATNOSCI.md), to be reviewed by legal counsel before
publication. In case of any discrepancy, the Polish version prevails for
users residing in Poland. Fields marked[TO BE COMPLETED]require a decision.
1. Who is the controller of your personal data?
The controller of the personal data of users of the Hardgainer Rats
application (the App) is MPR spółka z ograniczoną odpowiedzialnością,
with its registered office in Warsaw, ul. Floriańska 6/02, 03-707 Warsaw,
Poland, entered in the register of entrepreneurs of the National Court Register
kept by the District Court for the Capital City of Warsaw, 12th Commercial
Division, under KRS 0000788188, NIP (VAT ID) 5783137225, share capital
PLN 10,000 (the Controller, "we").
Hardgainer Rats is a product separate from the Calendesk platform — this policy
applies to the App only.
2. Contact regarding personal data
For all matters relating to personal data you may contact us at:
[TO BE COMPLETED — e.g. support@hardgainerrats.com].
We have not appointed a Data Protection Officer, as this is not mandatory in
our situation.
3. What data do we process and why?
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| E-mail address, password (stored only as a cryptographic hash) | Account creation and operation, sign-in | Art. 6(1)(b) GDPR (contract) | for the lifetime of the Account |
| Training data: exercises, sets, weights, repetitions, dates and durations of workouts, your own exercise and category lists | Providing the service — keeping a training log, statistics and charts | Art. 6(1)(b) GDPR (contract) | for the lifetime of the Account |
| Technical session data: session identifier (hashed), browser/device string (User-Agent), sign-in timestamps | Account security, keeping you signed in across devices | Art. 6(1)(f) GDPR (legitimate interest — security) | max. 90 days from sign-in (session validity) |
| Correspondence with us (e.g. complaints, enquiries) | Handling requests, complaints and claims | Art. 6(1)(b), (c) and (f) GDPR | until the matter is closed, then until claims become time-barred |
| Billing data — only once paid features are introduced | Settling purchases, tax obligations | Art. 6(1)(b) and (c) GDPR | 5 years from the end of the tax year |
A note on training data: your workout data may indirectly indicate your
physical condition. We treat it with the care appropriate to sensitive data: it
is visible only to you (strict account isolation enforced server-side — which
applies to administrator accounts as well), it is never shared, and it is not
used for any purpose other than providing the service.
4. What we do NOT do
- We do not collect your name, location, contacts or advertising identifiers.
- We do not use third-party analytics or marketing tools (no Google Analytics, no advertising pixels).
- We do not profile you and do not take decisions based solely on automated processing (Art. 22 GDPR).
- We do not sell or share your data for marketing purposes.
5. How do we protect your data?
- All communication with the App is encrypted (HTTPS/TLS, HSTS).
- Data is stored on Cloudflare infrastructure with encryption at rest.
- Passwords are never stored in plain text — only as a PBKDF2-SHA256 hash with an individual salt.
- Session tokens are stored only as a SHA-256 hash — even in the event of a database leak, an active session cannot be reconstructed from them.
- Every user can access their own data only; this isolation is enforced by the server and applies to administrator accounts as well.
- Additional safeguards: sign-in rate limiting, the ability to review active devices and sign out everywhere, session invalidation on password change, and security headers (Content-Security-Policy, anti-clickjacking).
6. Recipients of the data (processors)
Your data is processed on our behalf by:
| Entity | Role | Location |
|---|---|---|
| Cloudflare, Inc. (USA) | Application and database hosting | USA / global network; transfers based on Standard Contractual Clauses and Cloudflare's participation in the EU–US Data Privacy Framework |
| Apple Inc. / Google LLC — after release in the stores | App distribution, in-app payments | in accordance with the App Store / Google Play terms (Apple and Google act as separate controllers of billing data) |
| [TO BE COMPLETED once implemented — transactional e-mail provider, e.g. Resend, for address verification and password reset] | Transactional e-mail delivery | — |
Data may also be disclosed to competent authorities (courts, prosecutors, tax
authorities) where required by law.
7. Your rights
You have the right to:
- access your data and obtain a copy (Art. 15 GDPR) — in the App: Settings › Export backup;
- rectification (Art. 16) — you can edit your training data yourself;
- erasure (Art. 17) — in the App: Settings › Account › "Delete account & all data"; deletion is immediate and covers the account, workouts, exercises and sign-in sessions. Infrastructure backups expire automatically within a maximum of 30 days;
- restriction of processing (Art. 18);
- data portability (Art. 20) — export in JSON format;
- object to processing based on legitimate interest (Art. 21);
- **lodge a complaint with the President of the Personal Data Protection Office** (ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl), or with your local supervisory authority, if you consider that we process your data unlawfully.
We handle requests without undue delay and no later than within one month.
8. Cookies and local storage
The App does not use tracking or marketing cookies. We use only the local
storage of your browser/device to the extent necessary to provide the service:
- your sign-in token (keeping you signed in),
- a local copy of your workouts (offline use),
- appearance and language settings.
As these are strictly necessary for the service, they do not require separate
consent (we do not display a cookie banner). Clearing the App's data in your
browser or device will sign you out.
9. Changes to this Privacy Policy
We may amend this policy in response to technological or legal changes. We will
inform you of changes in the App or by e-mail. Changes take effect no earlier
than 7 days after notification. Archived versions will be available at the
address of publication.
*Version 0.1 (draft) — [PUBLICATION DATE TO BE COMPLETED]*