Privacy Policy
Last updated: 6 August 2026
How Roarer processes personal data.
Controller
The controller within the meaning of Article 4(7) GDPR is the provider named above. Contact: [email protected].
A data protection officer is not required under Article 37 GDPR and has not been appointed.
Data we process
This policy covers roarer.app and the Roarer app.
- Account: email address, hashed password, username, one time sign in codes.
- Profile: name, gender, date of birth, height, body weight, app settings.
- Training: programs, workouts, exercises, sets, repetitions, weights, notes, session history.
- Body measurements you enter.
- Support: your messages and any attachments.
- Technical: session records and device data needed to keep you signed in.
- Website: aggregate usage statistics and standard server logs.
Purposes and legal bases
- Providing the account and the service, Article 6(1)(b) GDPR.
- Body weight, measurements and training history, which may reveal health data, Article 9(2)(a) GDPR (consent), withdrawable at any time.
- Sign in codes and service email, Article 6(1)(b) GDPR.
- Security and abuse prevention, Article 6(1)(f) GDPR.
- Website usage statistics, only after your consent, § 25(1) TDDDG and Article 6(1)(a) GDPR, withdrawable at any time.
- Support requests, Article 6(1)(b) and 6(1)(f) GDPR.
- Push notifications, Article 6(1)(a) GDPR (consent).
Cookies
Two cookies are strictly necessary for the service you requested and therefore need no consent under § 25(2) TDDDG: one keeps your chosen language, the other records your decision about statistics.
Usage statistics are optional. Only if you accept do we store a visitor identifier in your browser session and count your page views; the legal basis is your consent under § 25(1) TDDDG and Article 6(1)(a) GDPR. You can change the decision at any time through the cookie settings link in the footer. No advertising or tracking cookies are used.
Recipients
Personal data is not sold and is not shared for advertising. Processors act on our documented instructions under a contract pursuant to Article 28 GDPR: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, for hosting and databases; an email delivery provider for sign in codes and service messages; and, for the app, Apple and Google.
International transfers
Servers are located in the European Union. Where a processor operates outside the EU or the UK, the transfer is based on the European Commission's standard contractual clauses pursuant to Article 46(2)(c) GDPR.
Retention
- Account and training data: while the account exists.
- Deleted accounts: access ends immediately; data is erased or anonymised at the latest one year after deletion.
- Sign in codes: minutes.
- Support: while the case is open and for a limited period afterwards.
- Website statistics: aggregates without personal data.
- Server logs: a short period set by the hosting provider.
- Statutory retention obligations, in particular under commercial and tax law, remain unaffected.
Your rights
You have the right of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20) and objection (Article 21), and you may withdraw consent at any time with effect for the future (Article 7(3) GDPR). Requests: [email protected].
You may lodge a complaint with a supervisory authority (Article 77 GDPR). The authority responsible for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59-61, 10555 Berlin. You may also contact the authority where you live.
Children
Roarer is not intended for children under 16 and accounts are not knowingly created for them.
Security
Passwords are stored as salted hashes. Sessions use rotating tokens with reuse detection. Traffic is encrypted in transit.
Changes
Material changes are published on this page with a new date and, where they affect you directly, notified in the app or by email.