Last updated
Privacy Policy
This policy explains what personal data we collect when you use the website kneepainrecovery.com and the Knee Pain Recovery Workouts app, why we collect it, and what rights you have.
1. Who is responsible
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Kiedrowski Management UG (haftungsbeschränkt)
Dresselndorfer Str. 25
57299 Burbach, Germany
Email: luca@yourstrength.com
We have not appointed a data protection officer because we are not legally required to do so. For any privacy question or request, write to the email address above.
2. What this policy covers
This policy applies to:
- The website at kneepainrecovery.com, including the blog (Part A).
- The app “Knee Pain Recovery Workouts” for iOS, available on the Apple App Store (Part B).
Part C applies to both.
3. The short version
- The website sets no cookies and loads no tracking scripts until you consent via the cookie banner. Without consent, only technically necessary server logs are processed.
- The app creates an anonymous account for you. You do not have to give us your name or email address to use it.
- The app asks you about your knee pain to build your plan. This is health data. We only process it with your explicit consent, which you give during onboarding and can withdraw at any time by deleting your account.
- We never sell your data. We share it only with the service providers listed in this policy, who process it on our behalf.
- You can delete your account and all associated data from within the app at any time.
Part A — Website
4. Hosting and server logs
The website is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. When you visit the website, Vercel’s servers automatically record technical data in server logs: your IP address, the date and time of the request, the page requested, the referring URL, and your browser type and operating system. This data is needed to deliver the website, keep it secure and diagnose problems.
Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in operating a secure and reliable website). Server logs are deleted after a short period, typically within 30 days. We have concluded a data processing agreement with Vercel; transfers to the USA are based on the EU Standard Contractual Clauses and Vercel’s certification under the EU-US Data Privacy Framework.
5. Blog
Blog articles are fetched from our content system on the server before the page is sent to you. Your browser does not connect to the content system, and no personal data is transferred to it.
6. Analytics and marketing tools on the website
We use the following tools to understand how the website is used and to measure our advertising. Tools that store information on your device or read information from it (cookies, local storage, identifiers) are only loaded after you have given consent via the cookie banner (§ 25(1) TDDDG, Art. 6(1)(a) GDPR). You can withdraw your consent at any time with effect for the future via the cookie settings link in the footer.
PostHog
With your consent we use PostHog (PostHog Inc., 2810 N Church St PMB 119886, Wilmington, Delaware 19802, USA) for product analytics: which pages are viewed, which buttons are clicked, and how visitors move through the site. Data is stored on PostHog’s EU servers. Legal basis: Art. 6(1)(a) GDPR. Data is deleted after at most 12 months. More information: posthog.com/privacy.
Datafast
We use Datafast, a privacy-friendly analytics service that works without cookies and without storing personal data or tracking you across devices. It gives us aggregated statistics such as page views and referrers. Because it does not access your device storage and does not identify you, it runs without consent. Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in understanding how the website is used).
Meta Pixel
With your consent we use the Meta Pixel of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland, to measure whether visitors who saw our ads on Facebook or Instagram come to the website or download the app, and to show ads to people with similar interests. The pixel sets a cookie and transmits your IP address, browser information, the pages you visit and events such as clicking the download button to Meta. Meta can link this data to your Facebook or Instagram account. We and Meta are joint controllers for the collection of this data (Art. 26 GDPR); Meta is solely responsible for the subsequent processing. Legal basis: Art. 6(1)(a) GDPR. Data may be transferred to Meta Platforms, Inc. in the USA on the basis of the EU-US Data Privacy Framework and Standard Contractual Clauses. More information: facebook.com/privacy/policy.
7. Links to the App Store
The website links to the Apple App Store. When you follow such a link, Apple processes your data under its own privacy policy. We receive no personal data from Apple about who followed the link.
Part B — The app
8. Your account
When you first open the app, we create an anonymous account for you using Firebase Authentication (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). The account consists of a randomly generated user ID stored on your device. You do not need to provide a name, email address or password. Your user ID is used to link your plan, progress and purchases to you.
If you choose to tell us your first name during onboarding, we store it with your account so the app can address you by name. This is optional.
Legal basis: Art. 6(1)(b) GDPR (performance of the contract to provide the app).
Because the account is tied to your device, deleting the app or switching devices may cause you to lose access to your account and progress. Purchases can be restored through Apple.
9. Onboarding and your health data
During onboarding the app asks questions to build your recovery plan. Depending on the version of the onboarding you see, these are: how long you have had knee pain, how severe it is, where it is located, how you would describe it, your age, your exercise experience and frequency, and what has kept you from exercising. Answers about your pain and injury are health data within the meaning of Art. 9 GDPR.
We store these answers in your account record in our database (Google Firebase, see section 18) and use them for one purpose only: to select and adapt your exercise routine and estimate a recovery timeline. We do not use your health data for advertising, we do not share it with advertising partners, and we do not sell it.
Legal basis: Art. 9(2)(a) and Art. 6(1)(a) GDPR — your explicit consent, which you give at the end of the onboarding assessment before your answers are submitted. You can withdraw this consent at any time by deleting your account in the app (menu on the home screen → Delete account) or by emailing us. Withdrawal does not affect the lawfulness of processing before the withdrawal. Without this data we cannot build a personalised plan, but you can still use the general content of the app.
10. Check-ins, workouts and progress
Every few days the app asks you to rate your knee pain and whether you noticed changes. The app also records which workout sessions you completed and your streak. We store this in your account so you can see your progress over time and so the app can adjust your plan. Pain ratings are health data and are processed on the same legal basis as section 9 (Art. 9(2)(a) GDPR, your explicit consent). Session and streak data is processed under Art. 6(1)(b) GDPR.
11. Purchases
The app offers a one-time purchase that unlocks full access. Purchases are made through Apple’s in-app purchase system and are processed by Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. Apple handles payment; we never receive your payment card or bank details.
To check whether your account is entitled to full access and to restore purchases, we use RevenueCat, Inc., 1000 Brannan Street, Suite 300, San Francisco, CA 94103, USA. RevenueCat receives your anonymous user ID, an app-specific identifier, the product purchased, the price, currency and transaction date, and your device platform. Legal basis: Art. 6(1)(b) GDPR (performance of the purchase contract). Transaction records are kept for as long as required by tax and commercial law (up to ten years, § 147 AO / § 257 HGB).
12. Push notifications
If you allow notifications, the app sends you workout reminders through Firebase Cloud Messaging (Google). For this, a push token identifying your device is stored with your account. Legal basis: Art. 6(1)(a) GDPR — your consent, which you give via the iOS permission prompt and can withdraw at any time in your device’s notification settings.
13. Usage analytics in the app
We measure how the app is used — which screens are opened, which exercises are started and completed, where people drop out of onboarding, and whether a purchase was made — so we can fix problems and improve the app. For this we use:
- Mixpanel (Mixpanel, Inc., One Front Street, 28th Floor, San Francisco, CA 94111, USA). Data is sent to and stored on Mixpanel’s EU servers.
- PostHog (PostHog Inc., see section 6). Data is stored on PostHog’s EU servers.
These tools receive your anonymous user ID, device type and operating system, app version, language, coarse location derived from your IP address, and the events described above, including whether you hold full access. We do not send your onboarding answers, pain ratings or any other health data to these tools. Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in understanding and improving the app). You can object to this processing at any time by emailing us; we will then exclude your user ID from analytics. Analytics data is deleted after at most 24 months.
14. Advertising attribution
We advertise the app on Facebook and Instagram. To know whether our advertising works, we would like to learn whether people who installed the app did so after seeing one of our ads. This requires linking your device to activity on other apps and websites, so it only happens if you allow tracking in the iOS “Allow this app to track your activity” prompt (App Tracking Transparency). If you tap “Ask App Not to Track”, no data is shared for this purpose.
If you allow tracking, we use:
- Meta SDK / Meta App Events (Meta Platforms Ireland Limited, see section 6). Meta receives your advertising identifier (IDFA), device information and app events such as app installs, completed onboarding and purchases, and matches them to its ad campaigns. Meta may use this data under its own responsibility as described in its privacy policy.
- AppSprint (getappsprint.com), a mobile attribution service that receives your anonymous user ID, an app-specific identifier and purchase events in order to attribute installs and purchases to advertising campaigns.
Legal basis: Art. 6(1)(a) GDPR — your consent via the iOS tracking prompt, which you can withdraw at any time under Settings → Privacy & Security → Tracking on your device.
15. Support chat
The app includes a support chat provided by Crisp IM SAS, 2 Boulevard de Launay, 44100 Nantes, France. When you open the chat, Crisp processes the messages you send, your anonymous user ID, device and app version and, if you enter it, your email address so we can reply. Chat transcripts are stored on Crisp’s servers in the EU. Legal basis: Art. 6(1)(b) GDPR (answering your support request) and Art. 6(1)(f) GDPR (our legitimate interest in offering support). Transcripts are deleted after 12 months.
16. Exercise videos and content
Exercise videos and images are delivered from Firebase Storage (Google). When the app loads a video, Google’s servers receive your IP address and technical request data in order to deliver the file. Legal basis: Art. 6(1)(b) GDPR.
17. Ratings and crash reports
The app may occasionally ask you to rate it using Apple’s built-in rating dialog. Ratings are handled entirely by Apple. If you have opted in to sharing analytics with app developers in your iOS settings, Apple may share anonymised crash reports and usage statistics with us; we cannot identify you from this data.
Part C — General information
18. Service providers and international transfers
We use the following companies to run the website and the app. Each of them processes personal data on our behalf under a data processing agreement (Art. 28 GDPR), or — where stated — under its own responsibility.
| Provider | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Vercel Inc. | Hosting of the website and our backend | USA (EU edge servers) | EU-US Data Privacy Framework, SCCs |
| Google Ireland Ltd. (Firebase) | Authentication, database, file storage, push notifications | EU / USA | EU-US Data Privacy Framework, SCCs |
| Apple Distribution International Ltd. | App distribution and in-app purchases (own responsibility) | Ireland | — |
| RevenueCat, Inc. | Purchase validation | USA | SCCs |
| Mixpanel, Inc. | App analytics | EU data residency | SCCs for support access |
| PostHog Inc. | Website and app analytics | EU data residency | SCCs for support access |
| Datafast | Cookieless website statistics | EU | — |
| Meta Platforms Ireland Ltd. | Advertising measurement (joint control / own responsibility) | Ireland / USA | EU-US Data Privacy Framework, SCCs |
| AppSprint | Install attribution | USA | SCCs |
| Crisp IM SAS | Support chat | France | — |
Where data is transferred to the USA, this is based on an adequacy decision (EU-US Data Privacy Framework) for certified providers and on the European Commission’s Standard Contractual Clauses (Art. 46(2)(c) GDPR) otherwise. You can request a copy of the relevant safeguards by emailing us.
19. How long we keep your data
- Account, onboarding answers, check-ins and progress: for as long as your account exists. When you delete your account, this data is deleted immediately from our database and from backups within 30 days.
- Purchase records: up to ten years after the end of the year of purchase, as required by tax and commercial law.
- Analytics events: at most 24 months (app) or 12 months (website).
- Support chats: 12 months after the last message.
- Server logs: typically 30 days.
- Emails you send us: for as long as needed to handle your request and for up to three years afterwards to document it (limitation period, § 195 BGB).
20. Deleting your account
You can delete your account and all data linked to it at any time in the app via the menu on the home screen → Delete account. This removes your account record including your onboarding answers, check-ins and progress. Purchase records that we must retain by law are kept separately in anonymised form. You can also email us at luca@yourstrength.com and we will delete your account for you. Because we do not know your name or email, we will ask you for details that let us find your account, such as your Apple purchase receipt or the approximate date you installed the app.
21. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you (Art. 15).
- Rectification of inaccurate data (Art. 16).
- Erasure of your data (Art. 17).
- Restriction of processing (Art. 18).
- Data portability — receive the data you provided in a machine-readable format (Art. 20).
- Object to processing based on legitimate interests, such as analytics, at any time (Art. 21). We will then stop unless we have compelling legitimate grounds.
- Withdraw consent at any time with effect for the future (Art. 7(3)), for example by deleting your account, changing your device’s notification or tracking settings, or updating your cookie preferences on the website.
To exercise these rights, email luca@yourstrength.com. Because we do not know who you are, we may ask you for details that let us locate your account. We respond within one month.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the EU member state of your residence or place of work. The authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, ldi.nrw.de.
22. Automated decision-making
The app selects your exercise routine and estimates a recovery timeline automatically based on your onboarding answers and check-ins, using fixed rules. This is what the app is for; it produces no legal effects and does not similarly significantly affect you within the meaning of Art. 22 GDPR. We do not use profiling for advertising.
23. Children
The website and the app are intended for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with data, please contact us and we will delete it.
24. Security
We protect your data with technical and organisational measures appropriate to the risk, including encryption in transit, access controls on our database, and the principle of collecting as little data as possible. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
25. Changes to this policy
We will update this policy when the website, the app or the law changes. The current version is always available at kneepainrecovery.com/privacy-policy and in the app. If a change materially affects how we process your health data, we will ask for your consent again in the app.