Privacy Policy
Last Updated: August 6, 2026
Cortex Athletics ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, our mobile applications for iOS and Android, and related services (together, the "Service").
The data controller responsible for your personal data is:
Taskero UG (haftungsbeschränkt)
Graben 2, 55116 Mainz, Germany
Email: contact@taskero.de
We collect personal information that you voluntarily provide when using our Service:
We do not use analytics, tracking, or advertising technologies. We do not collect your IP address, browser type, device information, or usage patterns. The only data automatically handled is through essential cookies required for the website to function (see our Cookie Policy).
On iOS, you can optionally connect the Cortex Athletics app to Apple Health. If — and only if — you grant the corresponding HealthKit permission, the app reads the following data from Apple Health:
Access is read-only — we never write data to Apple Health. The data read from Apple Health is transmitted to and stored on our servers as part of your activity and workout history, where it is used solely to provide the Service (activity-calorie calculation, workout logging, and as part of the recent workout history used for AI training plan generation — see Section 5.1). You can revoke the app's Apple Health access at any time in the iOS Settings or Health app; we stop reading new data immediately. We never use Apple Health data (or any other health data) for advertising or marketing, and we never share it with third parties for advertising purposes.
You can log a workout by sharing a Garmin Connect activity link with the Cortex Athletics app — from Garmin Connect's share sheet, or by pasting the link into the AI coach chat. This happens only when you actively share a link; nothing is imported automatically and no ongoing connection to Garmin is established.
When you share such a link, our server reads the publicly shared activity page it points to and imports the following data into your workout history:
You do not connect a Garmin account and we never receive your Garmin credentials. We do not log in to Garmin, we hold no Garmin account link or access token, and we cannot read anything you have not shared. Only activities you have set to be shared publicly in Garmin Connect can be read; a private activity simply fails to import. We do not transmit your name, email address, account identifier, or any other personal data to Garmin — the request contains only the activity identifier taken from the link you shared (see also Section 5.6). The imported data is stored on our servers as part of your activity and workout history and used solely to provide the Service, on the same basis as an Apple Health import (see Section 4.1). You can delete an imported workout in the app at any time.
We use the information we collect for the following purposes:
We process your personal data based on the following legal grounds:
We process the following special categories of personal data based on your explicit consent:
This data is used exclusively to provide the Service — above all to generate safe and appropriate training plans that account for your physical condition. It is never used for advertising or marketing.
Before you can use the features that process this data, the app asks for your explicit consent, separately for each of the following purposes:
Each choice is voluntary and independent of the others: you can decline any or all of them and still use the rest of the Service — only the feature you declined becomes unavailable. Your decisions, the version of the consent text they were given against, and their timestamps are recorded so we can demonstrate consent as required by Art. 7(1) GDPR. You can change any of these choices at any time (see Section 8), and you can update or delete the underlying data at any time in the app.
When you request an AI-generated training plan, we transmit the following data to Google via the Gemini API:
When you log a meal, we also transmit the inputs you provide — meal photos, typed descriptions, and voice recordings (together with relevant nutrition context) — to Google via the Gemini API so the meal's calories and macronutrients can be estimated and your voice notes transcribed. Voice recordings are used only for this processing: they are never written to our storage, and once processing completes only the text transcript is kept (shown alongside your food-log entry until you delete it).
When you message the in-app AI coach, we transmit your conversation — the text you type and any voice notes, together with relevant training context — to Google via the Gemini API so the coach can respond and propose adjustments to your plan. Voice notes are used only to produce a transcript: the raw recording is never written to our storage, and only the transcript is kept as part of the conversation (until you clear the chat or delete your account).
Google processes this data — including the health-related data listed above — with its Gemini AI service to generate your training plan and nutrition estimates; it is not used for advertising. Google's privacy policy applies to their processing of this data: https://policies.google.com/privacy. We send this data based on the explicit consent you give in the app for the corresponding purpose — AI training plans, the AI coach chat, or AI meal analysis — before that feature can be used (see Section 4.1); if you withdraw a consent, we stop sending the data for that purpose. Google acts as a processor on our behalf under a data processing agreement and does not use your prompts to train its models. The AI processing runs on Google Cloud's EU multi-region infrastructure, so the machine-learning processing of this data takes place within the European Union (see Section 10).
We use Resend (operated by Resend, Inc. in the United States) to send transactional emails such as account verification and password resets. Only your email address and name are shared with this provider, solely for the purpose of delivering these emails — never for advertising or marketing. Resend acts as a processor on our behalf under a data processing agreement and does not use your data for its own purposes. Resend's privacy policy applies to its processing of this data: https://resend.com/legal/privacy-policy. Because this provider is located in the United States, your email address and name may be transferred outside the European Economic Area (see Section 10).
Our servers and database are hosted by Hetzner Online GmbH in Germany. Photos you upload (meal photos and optional feedback screenshots) are stored in a private, access-controlled bucket on Hetzner Object Storage in Germany and are only accessible through short-lived, signed links. Hetzner acts as a processor on our behalf and does not use your data for its own purposes.
If you enable notifications, we use Expo's push notification service (operated by Expo, Inc. in the United States) to deliver notifications to your device — for example, to let you know when your AI training plan is ready. When you grant notification permission, your device generates a push token (an identifier for the app installation on your device); we store this token on your account and transmit it to Expo so it can route notifications to you via Apple Push Notification service (on iOS) or Firebase Cloud Messaging (on Android). The token carries no message content and is used solely to deliver these notifications — never for advertising or cross-app tracking. Expo's privacy policy applies to its processing of this data: https://expo.dev/privacy. You can stop this at any time by disabling notifications for Cortex in your device settings; we remove the token when you log out or delete your account.
You can optionally create your account and log in with your Apple account (on iOS) or your Google account instead of an email address and password. If you choose one of these methods, the provider confirms your identity to us and shares your email address and name with us to create and secure your Cortex Athletics account — we never receive your Apple or Google password, and no other data from your Apple or Google account is shared with us. To verify the sign-in (and, when you delete your Cortex Athletics account, to revoke the connection between your Apple or Google account and our app), authentication tokens are exchanged with the respective provider. For the sign-in itself, Apple (Apple Distribution International Ltd., Ireland) and Google (Google Ireland Limited / Google LLC) each act as an independent controller under their own privacy policy: https://www.apple.com/legal/privacy/ and https://policies.google.com/privacy. These sign-in methods are entirely optional, and neither provider is used for analytics, advertising, or tracking through our app.
If you share a Garmin Connect activity link with the app (see Section 2.4), our server sends a request to Garmin Connect (operated by Garmin Ltd. and its affiliates) to read the publicly shared activity page that link points to. This request is anonymous and contains no personal data about you — no name, no email address, no account identifier, and no Cortex Athletics account reference; only the numeric activity identifier taken from the link you shared. We hold no Garmin account connection, credentials, or access token, so this is a one-off read of content you have already made public, not an account integration. Garmin receives no data about you from us, and we send nothing to Garmin unless you actively share a link. Garmin's own privacy policy governs its operation of Garmin Connect: https://www.garmin.com/privacy/global/policy/.
Beyond the service providers and third parties described in this section (AI processing, email delivery, hosting, push-notification delivery, optional sign-in, and the activity-link reads you initiate), we do not sell, rent, or share your personal data with any other third parties. We do not use analytics services, advertising networks, or social media plugins. In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction, and we will notify you before your data becomes subject to a different privacy policy. We may also disclose your data when required by law or to protect our rights.
We implement appropriate technical and organizational security measures to protect your personal information, including:
However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
We retain your personal data as follows:
Upon account deletion, all associated data is permanently removed from our database. You can delete your account and all associated data at any time directly in the mobile app under More → Account → Delete account, or by contacting us at contact@taskero.de.
Under the General Data Protection Regulation, you have the following rights:
Withdrawing a consent is as easy as giving it, and takes effect immediately. In the mobile app under More → Privacy you can switch each of the AI purposes (training plans, coach chat, meal analysis) off and on again with a single tap; the corresponding feature simply stops working while it is off. The Apple Health import is withdrawn by disconnecting Apple Health in the app under More → Connections → Apple Health, which also stops any further reading of Apple Health data.
To exercise any of these rights, contact us at contact@taskero.de. We will respond within 30 days.
You also have the right to lodge a complaint with your local data protection supervisory authority. Our competent authority is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz
Hintere Bleiche 34, 55116 Mainz
Email: poststelle@datenschutz.rlp.de
Our services are not intended for individuals under the age of 16. Registration therefore requires your date of birth, and we refuse registrations from anyone under 16 — no account is created and no data is stored. We do not knowingly collect personal information from children under 16. If you believe we have collected information from a child under 16, please contact us immediately at contact@taskero.de, and we will take steps to delete such information.
The AI features (training plans, nutrition analysis, and the AI coach) are processed on Google Cloud's EU multi-region infrastructure, meaning the machine-learning processing of your data takes place within the European Union; residual transfers outside the EEA (for example Google support operations) are safeguarded by Standard Contractual Clauses. Your data may be transferred to servers outside the EEA in the following cases: when we send you a transactional email, your email address and name are processed by Resend, Inc.; when you receive push notifications, your push token is processed by Expo, Inc.; and when you sign in with Apple or Google, authentication tokens are exchanged with the respective provider (see Section 5.5). These recipients may be located in the United States or other countries. The transfers are safeguarded by Standard Contractual Clauses (SCCs) and/or EU adequacy decisions (including the EU–US Data Privacy Framework where applicable), in accordance with GDPR Article 46.
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date.
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at:
Email: contact@taskero.de
Address: Taskero UG (haftungsbeschränkt), Graben 2, 55116 Mainz, Germany
Taskero UG is not required to appoint a Data Protection Officer under GDPR Article 37. For all privacy-related inquiries, please contact us at the email address above.
Product
Company
CORTEX ATHLETICS
We only use essential cookies required for the website to function (login session and security). No analytics, marketing, or tracking cookies are used. Learn more
These cookies are strictly necessary and cannot be disabled.
Login session and security protection