Privacy Policy

Last Updated: August 6, 2026

1. Introduction

Cortex Athletics ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, our mobile applications for iOS and Android, and related services (together, the "Service").

The data controller responsible for your personal data is:
Taskero UG (haftungsbeschränkt)
Graben 2, 55116 Mainz, Germany
Email: contact@taskero.de

2. Information We Collect

2.1 Information You Provide

We collect personal information that you voluntarily provide when using our Service:

  • Account data: Email address, first name, and last name (required for registration). If you sign in with Apple or Google, this data is provided to us by the respective provider instead of being typed in (see Section 5.5)
  • Profile data: Date of birth, gender, weight (kg), and height (cm) (optional — used to personalize training plans), and your timezone (read from your device's settings, or set manually in the app — used only to deliver reminders and notifications at the correct local time)
  • Health data: Information about active injuries and illnesses (sick days) — including title, description, and start/end dates (voluntary — this constitutes special category data under GDPR Article 9)
  • Training data: Sport preferences, experience levels, training configurations (splits, schedules, goals), available equipment, and workout logs (exercises, sets, reps, weights, running pace, distances, and — where you log or import them — duration, calories, and average heart rate)
  • Nutrition data: Meal photos you take or select for food logging, text descriptions of meals you type, and voice notes you record to describe meals. Voice recordings are processed transiently for transcription and nutrition analysis and are not stored — only the resulting text transcript is retained. We also store the nutrition estimates (calories and macronutrients) generated from these inputs, and your supplement choices
  • Coach chat: Messages you exchange with the in-app AI coach to discuss and adjust your training — text you type and optional voice notes you record. Voice notes are processed transiently for transcription and are not stored — only the resulting text transcript and the conversation are retained, until you clear the chat or delete your account
  • Feedback and feature requests: Feedback text you submit, an optional screenshot you attach to feedback, and feature-request descriptions
  • Support messages: Messages you exchange with our support team through the in-app support chat (text only). These are read and answered by our staff — not by an AI — and are retained with the conversation until you delete your account
  • Account credentials: Your password is hashed using PBKDF2 and is never stored in plaintext

2.2 Automatically Collected Information

We do not use analytics, tracking, or advertising technologies. We do not collect your IP address, browser type, device information, or usage patterns. The only data automatically handled is through essential cookies required for the website to function (see our Cookie Policy).

2.3 Apple Health (HealthKit)

On iOS, you can optionally connect the Cortex Athletics app to Apple Health. If — and only if — you grant the corresponding HealthKit permission, the app reads the following data from Apple Health:

  • Active energy burned (calories), used to show your real daily activity calories and refine your nutrition targets
  • Completed workouts, including their duration, distance, calories, and average heart rate, used to automatically log the sessions you actually trained

Access is read-only — we never write data to Apple Health. The data read from Apple Health is transmitted to and stored on our servers as part of your activity and workout history, where it is used solely to provide the Service (activity-calorie calculation, workout logging, and as part of the recent workout history used for AI training plan generation — see Section 5.1). You can revoke the app's Apple Health access at any time in the iOS Settings or Health app; we stop reading new data immediately. We never use Apple Health data (or any other health data) for advertising or marketing, and we never share it with third parties for advertising purposes.

2.4 Activity Imports from Other Platforms (Garmin Connect)

You can log a workout by sharing a Garmin Connect activity link with the Cortex Athletics app — from Garmin Connect's share sheet, or by pasting the link into the AI coach chat. This happens only when you actively share a link; nothing is imported automatically and no ongoing connection to Garmin is established.

When you share such a link, our server reads the publicly shared activity page it points to and imports the following data into your workout history:

  • The activity's workout data — its date, sport type, name, duration, distance, pace or speed, calories, average heart rate, and the individual laps or segments it consists of

You do not connect a Garmin account and we never receive your Garmin credentials. We do not log in to Garmin, we hold no Garmin account link or access token, and we cannot read anything you have not shared. Only activities you have set to be shared publicly in Garmin Connect can be read; a private activity simply fails to import. We do not transmit your name, email address, account identifier, or any other personal data to Garmin — the request contains only the activity identifier taken from the link you shared (see also Section 5.6). The imported data is stored on our servers as part of your activity and workout history and used solely to provide the Service, on the same basis as an Apple Health import (see Section 4.1). You can delete an imported workout in the app at any time.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • To create and manage your user account
  • To generate personalized AI-powered training plans using your profile data, sport preferences, injuries, and workout history
  • To send email verification codes during registration
  • To send password reset emails when requested
  • To display your training history, workout logs, and progress
  • To estimate the calories and macronutrients of meals you log — by photo, typed description, or voice note — and to generate personalized nutrition guidance
  • To power the in-app AI coach chat — answering your questions and making targeted adjustments to your training plan through conversation (by text or voice note)
  • To calculate your daily activity calories from data you choose to import from Apple Health
  • To respond to and act on feedback and feature requests you submit
  • To answer your questions and resolve issues through the in-app support chat
  • To deliver reminders and notifications at the correct local time, based on your timezone
  • To improve the quality of our AI-generated training plans
  • To comply with legal obligations

4. Legal Basis for Processing (GDPR)

We process your personal data based on the following legal grounds:

  • Contract performance (Art. 6(1)(b) GDPR): Account creation, workout logging, and providing the core Service functionality that does not involve health data
  • Explicit consent (Art. 9(2)(a) together with Art. 6(1)(a) GDPR): All processing of health data — AI training plan generation, the AI coach chat, AI meal analysis, and workout imports (from Apple Health and from activity links you share from other platforms). We ask for this consent in the app, separately for each of these purposes, before the corresponding feature can be used, and you can withdraw it at any time (see Sections 4.1 and 8)
  • Legal obligation (Art. 6(1)(c) GDPR): Compliance with applicable laws and regulations
  • Legitimate interests (Art. 6(1)(f) GDPR): Service security, abuse prevention, and service improvement

4.1 Special Categories of Data (Art. 9 GDPR)

We process the following special categories of personal data based on your explicit consent:

  • Health data: Information about your active injuries and illnesses (title, description, dates)
  • Health-related data: Weight and height measurements provided in the context of fitness training
  • Apple Health data: Active energy and completed-workout data (including average heart rate) that you explicitly authorize the iOS app to read via HealthKit (see Section 2.3)
  • Imported activity data: Workout data (including average heart rate) from activities you choose to share with the app as a link from another platform, such as Garmin Connect (see Section 2.4)

This data is used exclusively to provide the Service — above all to generate safe and appropriate training plans that account for your physical condition. It is never used for advertising or marketing.

Before you can use the features that process this data, the app asks for your explicit consent, separately for each of the following purposes:

  • AI training plans: Generating your personalized training plan from your profile data, sports, schedule, injuries, illnesses, and workout history
  • AI coach chat: Answering your questions and adjusting your plan through conversation
  • AI meal analysis: Estimating calories and nutrients from the meal photos, descriptions, and voice notes you log
  • Workout imports: Storing and processing the activity and workout data you import — from Apple Health, and from activity links you share with the app from another platform such as Garmin Connect. This consent is given when you connect Apple Health in the app, or when you confirm your first shared activity import, and it is withdrawn when you disconnect Apple Health or turn the permission off under More → Privacy

Each choice is voluntary and independent of the others: you can decline any or all of them and still use the rest of the Service — only the feature you declined becomes unavailable. Your decisions, the version of the consent text they were given against, and their timestamps are recorded so we can demonstrate consent as required by Art. 7(1) GDPR. You can change any of these choices at any time (see Section 8), and you can update or delete the underlying data at any time in the app.

5. Data Sharing and Disclosure

5.1 Google Gemini API (AI Plan Generation and Nutrition Analysis)

When you request an AI-generated training plan, we transmit the following data to Google via the Gemini API:

  • Your profile data: age (calculated from date of birth), gender, weight, height
  • Your sport preferences and training configuration
  • Your active injuries and illnesses (health data)
  • Your workout history from the last 30 days, including workouts imported from Apple Health
  • Your daily schedule preferences and time limits

When you log a meal, we also transmit the inputs you provide — meal photos, typed descriptions, and voice recordings (together with relevant nutrition context) — to Google via the Gemini API so the meal's calories and macronutrients can be estimated and your voice notes transcribed. Voice recordings are used only for this processing: they are never written to our storage, and once processing completes only the text transcript is kept (shown alongside your food-log entry until you delete it).

When you message the in-app AI coach, we transmit your conversation — the text you type and any voice notes, together with relevant training context — to Google via the Gemini API so the coach can respond and propose adjustments to your plan. Voice notes are used only to produce a transcript: the raw recording is never written to our storage, and only the transcript is kept as part of the conversation (until you clear the chat or delete your account).

Google processes this data — including the health-related data listed above — with its Gemini AI service to generate your training plan and nutrition estimates; it is not used for advertising. Google's privacy policy applies to their processing of this data: https://policies.google.com/privacy. We send this data based on the explicit consent you give in the app for the corresponding purpose — AI training plans, the AI coach chat, or AI meal analysis — before that feature can be used (see Section 4.1); if you withdraw a consent, we stop sending the data for that purpose. Google acts as a processor on our behalf under a data processing agreement and does not use your prompts to train its models. The AI processing runs on Google Cloud's EU multi-region infrastructure, so the machine-learning processing of this data takes place within the European Union (see Section 10).

5.2 Email Service Provider

We use Resend (operated by Resend, Inc. in the United States) to send transactional emails such as account verification and password resets. Only your email address and name are shared with this provider, solely for the purpose of delivering these emails — never for advertising or marketing. Resend acts as a processor on our behalf under a data processing agreement and does not use your data for its own purposes. Resend's privacy policy applies to its processing of this data: https://resend.com/legal/privacy-policy. Because this provider is located in the United States, your email address and name may be transferred outside the European Economic Area (see Section 10).

5.3 Hosting and Storage Providers

Our servers and database are hosted by Hetzner Online GmbH in Germany. Photos you upload (meal photos and optional feedback screenshots) are stored in a private, access-controlled bucket on Hetzner Object Storage in Germany and are only accessible through short-lived, signed links. Hetzner acts as a processor on our behalf and does not use your data for its own purposes.

5.4 Push Notification Provider

If you enable notifications, we use Expo's push notification service (operated by Expo, Inc. in the United States) to deliver notifications to your device — for example, to let you know when your AI training plan is ready. When you grant notification permission, your device generates a push token (an identifier for the app installation on your device); we store this token on your account and transmit it to Expo so it can route notifications to you via Apple Push Notification service (on iOS) or Firebase Cloud Messaging (on Android). The token carries no message content and is used solely to deliver these notifications — never for advertising or cross-app tracking. Expo's privacy policy applies to its processing of this data: https://expo.dev/privacy. You can stop this at any time by disabling notifications for Cortex in your device settings; we remove the token when you log out or delete your account.

5.5 Sign-In Providers (Sign in with Apple and Sign in with Google)

You can optionally create your account and log in with your Apple account (on iOS) or your Google account instead of an email address and password. If you choose one of these methods, the provider confirms your identity to us and shares your email address and name with us to create and secure your Cortex Athletics account — we never receive your Apple or Google password, and no other data from your Apple or Google account is shared with us. To verify the sign-in (and, when you delete your Cortex Athletics account, to revoke the connection between your Apple or Google account and our app), authentication tokens are exchanged with the respective provider. For the sign-in itself, Apple (Apple Distribution International Ltd., Ireland) and Google (Google Ireland Limited / Google LLC) each act as an independent controller under their own privacy policy: https://www.apple.com/legal/privacy/ and https://policies.google.com/privacy. These sign-in methods are entirely optional, and neither provider is used for analytics, advertising, or tracking through our app.

5.6 Garmin Connect (Activity Link Imports)

If you share a Garmin Connect activity link with the app (see Section 2.4), our server sends a request to Garmin Connect (operated by Garmin Ltd. and its affiliates) to read the publicly shared activity page that link points to. This request is anonymous and contains no personal data about you — no name, no email address, no account identifier, and no Cortex Athletics account reference; only the numeric activity identifier taken from the link you shared. We hold no Garmin account connection, credentials, or access token, so this is a one-off read of content you have already made public, not an account integration. Garmin receives no data about you from us, and we send nothing to Garmin unless you actively share a link. Garmin's own privacy policy governs its operation of Garmin Connect: https://www.garmin.com/privacy/global/policy/.

5.7 No Other Sharing

Beyond the service providers and third parties described in this section (AI processing, email delivery, hosting, push-notification delivery, optional sign-in, and the activity-link reads you initiate), we do not sell, rent, or share your personal data with any other third parties. We do not use analytics services, advertising networks, or social media plugins. In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction, and we will notify you before your data becomes subject to a different privacy policy. We may also disclose your data when required by law or to protect our rights.

6. Data Security

We implement appropriate technical and organizational security measures to protect your personal information, including:

  • HTTPS encryption enforced site-wide with HSTS (HTTP Strict Transport Security)
  • Passwords hashed using the PBKDF2 algorithm — never stored in plaintext
  • Session cookies configured as Secure, HttpOnly, and SameSite=Lax
  • CSRF (Cross-Site Request Forgery) protection on all forms
  • Clickjacking protection via X-Frame-Options

However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.

7. Data Retention

We retain your personal data as follows:

  • Account and profile data: Retained for the duration of your account
  • Training data and workout logs (including data imported from Apple Health): Retained for the duration of your account
  • Meal photos, meal descriptions, voice-note transcripts, and nutrition logs: Retained until you delete the individual food-log entry or your account. Raw voice recordings are not retained at all — they are discarded immediately after transcription and analysis
  • Coach chat conversations: Retained until you clear the day's chat or delete your account. Raw voice notes recorded in chat are not retained — they are discarded immediately after transcription
  • Feedback and feature requests (including optional screenshots): Retained as long as needed to act on them, at most for the duration of your account
  • Support chat conversations: Retained for the duration of your account
  • Push notification tokens: Deleted immediately when you log out or delete your account; tokens that become unreachable (for example after you uninstall the app) are removed at the latest 30 days after they stop working
  • AI processing logs: The full content of prompts sent to and responses received from the AI service (including the internal processing trace) is retained for 90 days for debugging and abuse prevention, then permanently removed. When you delete a coach chat conversation or a food-log entry, the associated prompt and response content is removed immediately. Technical metering records without any content (token counts, model name, timing) are kept for the duration of your account for billing and capacity planning. We additionally keep permanently anonymous technical statistics about AI generations (for example which internal tools ran, durations, and token counts) that contain no personal data and no free text
  • Coach memory: Facts and coaching state the AI coach saves about your training are retained while they are active; entries that are archived or superseded are removed after 90 days
  • Wearable link imports (e.g. Garmin): The technical import record is removed at the latest 90 days after the import; a parsed activity preview you do not confirm is removed after 7 days, and the preview is removed as soon as the import completes or fails
  • Consent records: Each consent decision — the purpose, whether it was granted or withdrawn, the version of the text it referred to, and the time — is retained for the duration of your account as the proof of consent required by Art. 7(1) GDPR, and is deleted together with your account
  • Email verification codes: Automatically expire after 15 minutes

Upon account deletion, all associated data is permanently removed from our database. You can delete your account and all associated data at any time directly in the mobile app under More → Account → Delete account, or by contacting us at contact@taskero.de.

8. Your Rights (GDPR)

Under the General Data Protection Regulation, you have the following rights:

  • Access (Art. 15): Request access to your personal data and information about how it is processed
  • Rectification (Art. 16): Request correction of inaccurate or incomplete data
  • Erasure (Art. 17): Request deletion of your personal data
  • Restriction (Art. 18): Request restriction of processing in certain circumstances
  • Portability (Art. 20): Request transfer of your data in a structured, machine-readable format
  • Objection (Art. 21): Object to processing based on legitimate interests
  • Withdraw Consent (Art. 7(3)): Withdraw consent for processing of health data at any time, without affecting the lawfulness of processing based on consent before its withdrawal

Withdrawing a consent is as easy as giving it, and takes effect immediately. In the mobile app under More → Privacy you can switch each of the AI purposes (training plans, coach chat, meal analysis) off and on again with a single tap; the corresponding feature simply stops working while it is off. The Apple Health import is withdrawn by disconnecting Apple Health in the app under More → Connections → Apple Health, which also stops any further reading of Apple Health data.

To exercise any of these rights, contact us at contact@taskero.de. We will respond within 30 days.

You also have the right to lodge a complaint with your local data protection supervisory authority. Our competent authority is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz
Hintere Bleiche 34, 55116 Mainz
Email: poststelle@datenschutz.rlp.de

9. Children's Privacy

Our services are not intended for individuals under the age of 16. Registration therefore requires your date of birth, and we refuse registrations from anyone under 16 — no account is created and no data is stored. We do not knowingly collect personal information from children under 16. If you believe we have collected information from a child under 16, please contact us immediately at contact@taskero.de, and we will take steps to delete such information.

10. International Data Transfers

The AI features (training plans, nutrition analysis, and the AI coach) are processed on Google Cloud's EU multi-region infrastructure, meaning the machine-learning processing of your data takes place within the European Union; residual transfers outside the EEA (for example Google support operations) are safeguarded by Standard Contractual Clauses. Your data may be transferred to servers outside the EEA in the following cases: when we send you a transactional email, your email address and name are processed by Resend, Inc.; when you receive push notifications, your push token is processed by Expo, Inc.; and when you sign in with Apple or Google, authentication tokens are exchanged with the respective provider (see Section 5.5). These recipients may be located in the United States or other countries. The transfers are safeguarded by Standard Contractual Clauses (SCCs) and/or EU adequacy decisions (including the EU–US Data Privacy Framework where applicable), in accordance with GDPR Article 46.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date.

12. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at:

Email: contact@taskero.de
Address: Taskero UG (haftungsbeschränkt), Graben 2, 55116 Mainz, Germany

Taskero UG is not required to appoint a Data Protection Officer under GDPR Article 37. For all privacy-related inquiries, please contact us at the email address above.

logo-light

AI-powered training plans for hybrid athletes. Gym and running, one coach.

Company

CORTEX ATHLETICS