Privacy Policy
How we collect, use, and protect your personal data
Last updated: September 21, 2026
This Privacy Policy explains how N+One UG (haftungsbeschränkt) i.G. (“N+One”, “we”) processes personal data when you use nplusone.app and related services. Special-category data (including health-related metrics) is processed only with your explicit consent (GDPR Art. 9(2)(a)), not merely by agreeing to Terms or using the service.
We comply with the EU General Data Protection Regulation (GDPR) and other applicable privacy laws.
1. Data Controller & Contact Information
The data controller responsible for your personal data is:
N+One UG (haftungsbeschränkt) i.G.
Dürener Straße 341
50935 Köln
Germany
Managing Director: Hans-Christian Reinl
Seat: Köln
Privacy Inquiries: For questions about your personal data or this privacy policy, please contact us at hi@nplusone.app
Support: For general support, visit Settings > Help & Support in the app or email hi@nplusone.app
2. Types of Data We Collect
2.1 Account Information
- Email address (for login and communication)
- Password (encrypted with bcrypt, never stored in plain text)
- Full name (optional, for personalization)
- Profile photo/avatar (optional, stored securely)
2.2 Athlete Profile Data
- Date of birth (for age-based recommendations)
- Weight and height (for power-to-weight calculations)
- Resting heart rate and maximum heart rate
- Functional Threshold Power (FTP)
- Sport type and experience level
- Training goals and preferences
2.3 Training & Activity Data
- Activity records from connected devices and services
- GPS data, routes, and location information
- Power output, heart rate, cadence, and speed data
- Activity duration, distance, and elevation gain
- Lap times and split data
- Training load and stress calculations (TSS, CTL, ATL)
2.4 Health & Recovery Data
When you connect health tracking services (like Whoop):
- Sleep duration and quality metrics
- Recovery scores and readiness indicators
- Heart rate variability (HRV)
- Strain and exertion metrics
2.5 AI Coach Interactions
- Chat conversation messages with the AI coach
- Training questions and coaching responses
- Uploaded images (e.g., power files, bike fit photos, training screenshots)
- Training plan requests and generated proposals
2.6 Technical & Usage Data
- Server log files (IP address, browser type, operating system, timestamps)
- Cookie data (authentication tokens, user preferences, and — with your consent — analytics cookies)
- Page views and feature usage statistics (via Google Analytics 4 with your consent, and Vercel Analytics)
- API usage patterns and error logs
- Device information (screen size, device type)
2.7 Job & freelance applications
When you apply for a role with N+One (for example by email to an address we publish), we use what you send—contact details, portfolio links, attachments, and message content—only to evaluate your application and to reply to you; we do not use it for unrelated marketing and we do not sell it. If you are not engaged for the role, we delete application data within twelve months of the decision unless the law requires otherwise or you become our contractor or employee. You may request earlier deletion at hi@nplusone.app.
3. Legal bases (GDPR Art. 6 and Art. 9)
We only process personal data when a legal basis applies. Contract performance (Art. 6(1)(b)) alone cannot authorize processing of health data. Where we process health-related or other special-category data, we rely on explicit consent under Art. 9(2)(a) together with Art. 6(1)(a).
3.1 Contract performance — Art. 6(1)(b)
Necessary to operate your account and paid subscription (not for health/AI coaching content):
- Creating and managing your account and authentication
- Providing billing metadata and fulfilling Pro subscriptions (via Stripe)
- Customer support about account/billing that does not require health metrics
3.2 Explicit consent — Art. 6(1)(a) and Art. 9(2)(a)
Collected via our in-app consent gateway (versioned and logged) before the relevant processing starts. Withdrawal is available in Settings and is as easy as giving consent.
- Importing and storing health-related metrics from connected services (e.g. heart rate, HRV, sleep, recovery, readiness from Whoop, Garmin, Apple Health, and similar)
- GPS tracks / activity polylines and precise location from activity streams
- Generating personalized training plans, session recommendations, and coach chat that use the above data
- Transferring minimized athlete context to AI/LLM processors used to deliver coaching (named in §5 / Trust; currently including OpenAI and other processors disclosed there)
- Connecting third-party integrations (Strava, Whoop, Wahoo, Garmin, intervals.icu, Zwift, Apple Health) after the required purpose consents above
- Optional: AI quality evaluation using live athlete context (default off; not required to use the coach)
- Analytics cookies (Google Analytics 4) — TDDDG § 25 / Art. 6(1)(a); managed via Cookie Settings (not Art. 9)
- Newsletter / marketing email — Art. 6(1)(a) only
We do not rely on Art. 9(2)(h) (healthcare). N+One is not a medical device and does not provide medical treatment.
3.3 Legitimate interests — Art. 6(1)(f)
- Security, fraud prevention, abuse detection
- Aggregated / anonymized product analytics where no Art. 9 data is required
- Technical troubleshooting that can be done without special-category data
3.4 Legal obligations — Art. 6(1)(c)
- Tax and accounting records
- Lawful requests from authorities
4. How We Use Your Data
4.1 Providing Core Services
- Authenticating your access to the platform
- Synchronizing activities from connected devices and services
- Calculating training load, readiness scores, and performance metrics
- Generating personalized AI coaching responses
- Creating and adapting training plans based on your goals and fitness
- Displaying performance analytics, trends, and progress charts
4.2 AI Coaching Model Providers
Important Information About AI Processing
Our Dynamic Coach may use OpenAI, Google (Gemini), or Anthropic models depending on whether it is classifying a message, answering a coach question, or generating a plan.
- Relevant profile data, training history, and chat messages may be sent to OpenAI, Google (Gemini), or Anthropic for processing, depending on the coaching task
- These providers process that data to classify messages, generate personalized coaching responses, or synthesize training plans
- Under our enterprise agreement, your data is NOT used to train OpenAI's models
- OpenAI's data processing terms: https://openai.com/enterprise-privacy
- We do NOT send: passwords, payment information, or authentication tokens
4.3 Service Improvements
- Analyzing usage patterns to identify popular and underused features
- Identifying and fixing technical issues and bugs
- Understanding which features provide the most value to users
- Planning new features and integrations based on user needs
- Optimizing performance and loading times
4.4 Communication
- Sending account-related notifications (password resets, security alerts)
- Providing customer support responses
- Sending newsletter updates and feature announcements (with consent)
- Notifying you about service changes, maintenance, or issues
5. Data Sharing & Third-Party Processors
We share your data only as necessary to provide our services. We do not sell your personal data to third parties.
5.1 Essential Service Providers
We use trusted third-party service providers to operate our platform. All providers have Data Processing Agreements (DPAs) in place:
Supabase (Database & Authentication)
Hosts our PostgreSQL database and manages user authentication. Database hosted in EU data centers.
Vercel (Hosting & CDN)
Hosts our application functions in EU data centers, provides CDN services, and handles file storage for avatars. Global CDN with EU-based compute.
OpenAI (AI Processing)
Processes many coach responses and default plan-generation tasks using GPT models. US-based with enterprise privacy agreement.
Google (Gemini AI Processing)
Processes message classification and some simple coach turns via Gemini models.
Anthropic (AI Processing)
May process multi-week and race-plan synthesis when Claude routing is enabled.
5.2 Integration Services (With Your Consent)
When you connect third-party fitness services, we access only the data you authorize via OAuth:
- Strava: Activities, athlete profile, activity streams (power, heart rate, GPS)
- Whoop: Recovery scores, sleep data, workout data
- Wahoo: Activities and workout data
- Garmin: Activities, health metrics (sleep, HRV, resting HR) for readiness, and workout upload to devices
- intervals.icu: Planned workout calendar sync, optional completed-activity import, and optional wellness/recovery metrics you authorize
- Zwift: Indoor ride / activity sync and optional scheduling of planned bike workouts to Zwift
We store access tokens securely and only access data necessary for providing coaching services. You can disconnect integrations at any time via Settings > Integrations.
5.3 Payment Processing
We use Stripe for subscription billing (including Checkout and the customer portal):
- Stripe processes Pro subscription payments and related billing events
- We do NOT store your credit card information on our servers
- Stripe maintains PCI-DSS Level 1 compliance (highest security standard)
- We receive only payment confirmation, invoice metadata, and subscription status needed to provision Pro access
5.4 Analytics
Google Analytics 4: With your consent (TDDDG § 25 / GDPR Art. 6(1)(a)), we use Google Analytics 4 (Google Ireland Ltd. / Google LLC) for usage analytics — for example page views, navigation, and feature usage that help us improve the Dynamic Coach experience. Measurement cookies and IDs (such as _ga and _ga_*) load only after you accept analytics in Cookie Settings. Consent Mode defaults keep analytics storage denied until then. Transfers to the USA use Google's applicable transfer mechanism; further details are in Cookie Settings, section 6 below, and Google's privacy documentation. You can withdraw analytics consent at any time via Cookie Settings in the footer.
Vercel Analytics: We also use Vercel Analytics for privacy-friendly, aggregated usage statistics. It does not set analytics cookies or track personal identifiers across sites.
5.5 We Will NEVER:
- Sell your personal data to third parties
- Share your data with advertisers or marketing companies
- Use your health data for purposes other than providing coaching services
- Transfer your data outside our approved service providers
- Share your training data publicly without your explicit permission
6. International Data Transfers
Primary database and app compute are in the EU; some processors are outside the EU with safeguards (same posture as our Trust Center). We do not claim exclusive Europe-only processing or that coaching models run only in the EU. We ensure your data is protected through appropriate safeguards:
Supabase (EU)
Database and authentication services hosted in EU data centers. No international data transfers for core data storage.
Vercel (EU)
Application functions hosted in EU data centers. Global CDN with EU-based compute reduces data transfer needs.
OpenAI (United States)
Standard Contractual Clauses (SCCs) approved by the European Commission are in place. Enterprise privacy agreement ensures data protection.
Google (Gemini AI Processing)
Depending on the coaching task, relevant coach context may also be processed by Google's Gemini models. These flows may involve processing outside the EU under the provider's applicable contractual safeguards.
Anthropic (AI Processing)
Depending on the coaching task, relevant coach context may also be processed by Anthropic. These flows may involve processing outside the EU under the provider's applicable contractual safeguards.
Google Analytics (Google Ireland Ltd. / Google LLC)
With your analytics consent, usage data may be processed by Google and transferred to the USA under Google's applicable transfer mechanism (including SCCs / other lawful mechanisms as documented by Google). See Cookie Settings and Google's documentation for details.
Stripe (payments)
Subscription Checkout and billing may involve Stripe entities outside the EU under Stripe's applicable contractual safeguards. We do not store full card numbers on our servers.
Protection Measures:
- EU-based hosting for core services (database, application functions)
- Standard Contractual Clauses (SCCs) and other applicable transfer safeguards for AI and analytics providers where applicable (e.g. OpenAI, Google, Anthropic)
- Contractual obligations requiring equivalent data protection standards
- Your rights to access, rectify, and delete data apply regardless of location
- Regular audits and assessments of data protection measures
7. Data Retention Periods
We retain your data only as long as necessary to provide our services and comply with legal obligations:
7.1 Active Account
- Profile data: Retained while your account is active
- Training sessions / detailed activity history:
- Free tier: 90 days
- Pro tier: 2 years while the subscription is active; after Pro ends, retain under Free-tier rules unless you delete the account sooner
- Advanced tier: not offered yet — no Advanced retention applies
- Chat conversations: Retained while account is active
- Activity logs: Server logs retained for 90 days for security purposes
- Google Analytics 4: Event and identifier data retained according to our GA4 property retention settings (typically up to 14 months) and Google's product terms; you can stop further collection via Cookie Settings
7.2 After Account Deletion
- All personal data permanently deleted within 30 days of account deletion request
- Aggregated, anonymized statistics may be retained for business analytics
- Legally required records (e.g., tax, accounting): Retained for 7 years as required by German law
- Backup systems purged within 90 days
7.3 Inactive Accounts
- Accounts inactive for 3 years will receive notification email
- Data will be deleted 90 days after notification if no response
- You can reactivate your account by logging in before deletion
8. Your Rights Under GDPR
As a data subject under GDPR, you have the following rights regarding your personal data:
8.1 Right of Access (Art. 15)
You have the right to request a copy of all personal data we hold about you, including:
- Profile information and account details
- Training sessions and activity data
- Chat conversations with the AI coach
- Integration connections and sync history
- Goals, training plans, and readiness scores
How to exercise: Go to Settings > Privacy > Export Data. Your data will be provided in JSON format for easy portability.
8.2 Right to Rectification (Art. 16)
You have the right to correct inaccurate or incomplete personal data.
How to exercise: Update your information directly via Settings > Profile, or contact support for assistance.
8.3 Right to Erasure / "Right to be Forgotten" (Art. 17)
You have the right to request deletion of your personal data. We will permanently delete your data within 30 days, except where:
- We are legally required to retain certain records (e.g., tax records for 7 years)
- Data is needed to complete an ongoing transaction
- Data is needed to comply with legal obligations
How to exercise: Go to Settings > Privacy > Delete Account. This action is permanent and cannot be undone.
8.4 Right to Restriction of Processing (Art. 18)
You have the right to request that we limit processing of your data in certain circumstances:
- When you contest the accuracy of the data
- When processing is unlawful but you don't want data deleted
- When we no longer need the data but you need it for legal claims
- While we verify legitimate grounds following your objection
How to exercise: Contact us at hi@nplusone.app
8.5 Right to Data Portability (Art. 20)
You have the right to receive your personal data in a structured, commonly used, machine-readable format (JSON) and transfer it to another service.
How to exercise: Use the Export Data feature in Settings > Privacy to download your complete data archive.
8.6 Right to Object (Art. 21)
You have the right to object to processing based on legitimate interests or for direct marketing purposes:
- Object to direct marketing at any time (unsubscribe links in all marketing emails)
- Object to processing based on legitimate interests
- Object to automated decision-making and profiling
We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests.
8.7 Right to Withdraw Consent (Art. 7(3))
Where processing is based on consent, you have the right to withdraw it at any time:
- Disconnect integrations via Settings > Integrations
- Manage cookie preferences via Cookie Settings
- Unsubscribe from newsletters using links in emails
- Withdraw explicit consent for health-data import and AI coaching via Settings → Privacy (the Art. 9 purpose toggles). That does not affect other withdrawals listed here.
Withdrawal does not affect the lawfulness of processing before withdrawal.
8.8 Right to Lodge a Complaint
If you believe we are not complying with GDPR, you have the right to file a complaint with your local Data Protection Authority:
Supervisory authority for our Köln-based private controller (NRW):
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Postfach 20 04 44
40102 Düsseldorf
Website: www.ldi.nrw.de
Federal reference (BfDI):
Der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI) publishes general GDPR guidance and directs private entities to the competent Land authority (for us, typically LDI NRW).
Graurheindorfer Str. 153
53117 Bonn
Website: www.bfdi.bund.de
You may also lodge a complaint with the supervisory authority in your place of residence or workplace in the EEA. We encourage you to contact us first so we can address your concerns directly.
Exercising Your Rights
- • Most rights can be exercised directly through your Settings interface
- • For special requests, contact us at hi@nplusone.app
- • We respond to all requests within 30 days (GDPR requirement)
- • Identity verification may be required to protect your data
- • There is no charge for exercising your rights (unless requests are excessive)
9. Data Security Measures
We implement industry-standard security measures to protect your personal data from unauthorized access, alteration, disclosure, or destruction:
9.1 Technical Measures
- Encryption in transit: TLS/SSL encryption (HTTPS) for all data transmission
- Encryption at rest: Database encryption for stored data
- Password security: Passwords hashed using bcrypt (never stored in plain text)
- Encrypted database connections: All database queries use encrypted connections
- OAuth 2.0: Secure authorization for third-party integrations
- Token management: Access tokens encrypted at rest, expire automatically
- Regular security updates: Dependencies and systems kept up to date
9.2 Organizational Measures
- Access controls: Least privilege principle for system access
- Security training: Regular security awareness and best practices
- Incident response: Procedures for detecting and responding to security incidents
- Secure development: Security-first development practices and code reviews
- Third-party assessments: Regular security audits of service providers
9.3 Infrastructure Security
- Databases hosted in secure, ISO-certified data centers
- Automated encrypted backups
- DDoS protection and rate limiting
- Intrusion detection and prevention systems
- Regular security monitoring and logging
9.4 Security Limitations
While we implement strong security measures, please be aware:
- No data transmission over the internet is 100% secure
- You are responsible for maintaining the security of your password
- Do not share your login credentials with anyone
- Report any security concerns immediately to hi@nplusone.app
11. Children's Privacy
Our service is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16.
If we discover that we have collected personal data from a child under 16 without verification of parental consent, we will delete that information immediately.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at hi@nplusone.app
Users aged 16-18: Parental consent is recommended but not legally required under GDPR.
12. Automated Decision-Making & Profiling
We use automated processing to provide personalized training recommendations. However, these do not constitute automated decision-making with legal or similarly significant effects as defined by GDPR Art. 22.
12.1 AI Coaching Recommendations
- Our AI coach provides training suggestions based on your profile and activity data
- These are recommendations only, not binding decisions
- You maintain full control over your training choices
- No decisions with legal or similarly significant effects are made automatically
- You can always override or ignore AI suggestions
12.2 Training Load Calculations
- Automated algorithms calculate training stress (TSS), fitness (CTL), and fatigue (ATL)
- Based on established sports science principles
- Calculations are transparent and use standard formulas
- You can view, question, and ignore these metrics at any time
12.3 Right to Human Review
You have the right to request human review of any AI-generated recommendations. Contact our support team at hi@nplusone.app if you have concerns about any automated processing or recommendations.
13. Third-Party Integrations
When you connect third-party fitness services to N+One, you authorize us to access specific data from those platforms via OAuth.
13.1 Your Responsibility
- Review the privacy policies of Strava, Whoop, Wahoo, Garmin, intervals.icu, and Zwift
- Understand what data you're authorizing us to access through OAuth permissions
- You can revoke access at any time via Settings > Integrations
- Disconnecting removes our access but doesn't delete data from the third-party platform
13.2 Our Responsibility
- Access only the data scopes you explicitly authorize
- Store access tokens securely with encryption
- Respect your data deletion requests
- Delete integration data when you disconnect a service
- Use accessed data only for providing coaching services
13.3 Data We Access from Integrations
Strava
Activities, athlete profile, activity streams (power, heart rate, GPS, cadence)
Whoop
Recovery scores, sleep data, workout data, physiological cycles
Wahoo
Activities, workout data, device information
Garmin
Activities and activity details; health metrics (sleep, HRV, resting heart rate) for readiness; planned workout upload to your Garmin devices. We do not sell this data.
intervals.icu
Planned workout calendar events; optional import of completed activities; optional wellness/recovery metrics (for example sleep, HRV, resting heart rate) when you enable those sync options. We do not sell this data.
Zwift
Indoor rides and related activity data; optional upload / scheduling of planned bike workouts to Zwift when you enable planned-workout upload. We do not sell this data.
14. Data Breach Notification
In the event of a data breach that affects your personal data:
Notification to Authorities
We will notify the relevant Data Protection Authority within 72 hours of becoming aware of a breach (as required by GDPR Art. 33).
Notification to You
If the breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay via email (GDPR Art. 34).
Information Provided
Our notification will include: nature of the breach, likely consequences, measures taken to address the breach, and recommendations for protecting yourself.
Remediation
We will take immediate steps to contain the breach, assess its impact, and implement measures to prevent future occurrences.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
How We Notify You:
- Material changes will be notified via email to your registered email address
- We will update the "Last updated" date at the top of this policy
- For significant changes, we may require you to review and accept the updated policy
- We may also display a notification banner in the app
Your Continued Use: Continued use of N+One after changes take effect constitutes acceptance of the updated policy. If you do not agree with changes, please discontinue use and delete your account.
Previous Versions: Previous versions of this Privacy Policy are available upon request by contacting us at hi@nplusone.app
Questions About Your Privacy?
We're committed to protecting your privacy and being transparent about our data practices. If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please don't hesitate to contact us.
Privacy Inquiries
For questions about your personal data or exercising your GDPR rights:
hi@nplusone.appResponse time: Within 30 days
General Support
For technical support or general inquiries:
hi@nplusone.appResponse time: Within 48 hours
Additional Resources:
