Privacy Policy
This describes what the STARKOS code actually does with your data, not what would be customary. As at 17 August 2026. The German Datenschutzerklärung covers the same ground and is the authoritative version for German-speaking users.
1. Controller
Timo Hölscher
Leopoldstraße 33
82140 Olching
Germany
Email: founder.starkos.io@gmail.com
Telephone: +49 170 2697692
No data protection officer has been appointed; the thresholds of § 38 BDSG are not met.
2. What is processed
2.1 Your account
An email address and an access code you choose. The code is never stored in clear text: Firebase Authentication stores a hash and nobody at STARKOS can read it.
2.2 Your questionnaire answers
What you type in: name or nickname, date of birth, height, weight, training goal, experience, available equipment, training days, sleep and recovery, and, where you choose to give them, injuries, pre-existing conditions and substances taken.
Health data, and the explicit consent behind it. Body fat, injuries, conditions and substances are health data within the meaning of Article 9 GDPR. They are processed only on your explicit consent under Article 9(2)(a), which you give on a separate screen before the questionnaire opens: three individual confirmations, none of them pre-ticked, none of them bundled. Every one is recorded with the exact time and the version of the wording you were shown. You can withdraw at any time in your account settings, and withdrawing takes the same one tap that giving it did. All of these fields are voluntary.
2.3 Training logs
Logged sets (weight, repetitions, date, exercise), weight history and body-fat history, stored in your own account-bound record.
2.4 The photo in the body-fat scan
Your photo is never stored. It is sent to the analysis endpoint, used to produce the estimate, and then discarded. It is not written to the database, not archived, and not used to train AI models. Only the result is stored: the estimated figure with its range.
Technically this rests on an allowlist: the save path names exactly five permitted fields, the image is not one of them, and it therefore cannot reach the database even if a caller passed it. The same allowlist is enforced a second time in the database's own security rules, so it does not depend on the browser behaving.
2.5 Server logs and abuse protection
Loading a page causes the host to process technically necessary data (IP address, time, requested resource, user agent). For the publicly accessible features (body-fat estimate, QR workout) a salted hash of the IP address is additionally stored to limit abuse; the IP address itself is not stored in clear text. Legal basis: Article 6(1)(f) GDPR (legitimate interest in a functioning, un-abused service).
2.6 Analytics
No analytics are currently running. No analytics service is loaded, no events are collected and no cookie is set for that purpose. If that changes, this section and the German version are updated at the same time as the change.
When analytics are switched on, the intention is to record named funnel events only, for example "landing page seen", "signup started", "questionnaire section 3", capturing the event name, a section index or count, and the referring domain.
What would never be transmitted: email address, name, date of birth, photo, body weight, body-fat figure, injuries, medication or substances, or any free text. Signed-in users would be identified only by the technical account id (Firebase UID), never by email address. Automatic click and content capture ("autocapture") and session recording are disabled.
2.7 Consent records
Each consent you give or withdraw is written to your own account record as a separate, append-only entry: which consent, your account id, the exact server-side timestamp, and the version of the text you were shown. A withdrawal adds a new entry; it does not erase the original. That history is the evidence that the processing was lawful, and it is kept for as long as it may be needed to demonstrate that, which is why withdrawing consent does not delete it. Deleting your account deletes it with everything else.
3. Recipients and processors
| Service | Purpose | Place of processing |
|---|---|---|
| Netlify, Inc. | Website hosting, serverless functions, Netlify Blobs (counters, rate limits) | USA. EU-U.S. Data Privacy Framework / standard contractual clauses |
| Google (Firebase Authentication, Cloud Firestore) | Your account and the storage of your data | Firestore database: europe-west1 (Belgium). Authentication by Google, possibly USA |
| PostHog (not currently active) | Analytics (see 2.6). Prepared but not switched on: no data is transmitted today. | EU cloud (eu.i.posthog.com). The US endpoint is not used |
| Anthropic PBC (Claude API) | Building training plans, estimating body fat, recognising equipment in the QR photo | USA. Standard contractual clauses |
Fonts. The typefaces (Unbounded, DM Sans) are served exclusively from our own server. Loading a page makes no connection to Google Fonts (fonts.googleapis.com, fonts.gstatic.com); your IP address is not transmitted to Google for them.
The Firebase library. Account features (registration, sign-in, saving your data) load the Firebase library from a Google server (www.gstatic.com), which transmits your IP address to Google. This is technically necessary for sign-in and storage to work at all. This page, the Terms, the Impressum and the German Datenschutzerklärung do not load it.
Your training details are transmitted to the Claude API to build a plan, including the voluntary information about injuries and substances where it is relevant to the plan. Your email address is not transmitted. The data is not used to train AI models.
4. Legal bases
- Article 6(1)(b) GDPR: account, plan generation and training logs: performance of the user relationship.
- Article 6(1)(a) and Article 9(2)(a) GDPR: health data and analytics: consent.
- Article 6(1)(f) GDPR: abuse protection and technical server logs: legitimate interest.
- Article 6(1)(c) GDPR: statutory cancellation and withdrawal declarations, which must be recorded and retained.
5. Retention
Account and training data are stored for as long as the account exists. Deleting the account removes the associated data. Photos are not stored (see 2.4). Hashed IP values for abuse protection are overwritten automatically after a short time.
Two things outlive a deletion request, and they are named rather than glossed. Statutory cancellation and withdrawal declarations must be retained. And the early-access lead record keyed to your email address cannot be deleted by any client, including you. The database rules refuse it to every browser, so it is removed by hand on administrator credentials. Mail founder.starkos.io@gmail.com and it is done.
6. Your rights, and where the buttons are
You have the right of access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20) and objection (Article 21 GDPR). Consent once given can be withdrawn at any time with effect for the future (Article 7(3)).
These are not only promises here. They are controls in the product:
- Access and portability (Art. 15, 20): Download my data produces one JSON file containing everything stored about you, plus a list of every location it read, so you can see what was covered.
- Erasure (Art. 17): Delete my account, one confirmation, with a plain statement of what is removed and what is retained.
- Withdrawing consent (Art. 7(3)): in your account settings, one tap and one confirmation.
- Rectification (Art. 16): your answers are editable in the dashboard; anything else, mail us.
For anything else an informal message to founder.starkos.io@gmail.com is enough.
You also have the right to complain to a data protection supervisory authority (Article 77 GDPR).
7. Cookies and local storage
STARKOS stores technically necessary values in your browser to keep you
signed in and to avoid losing a set you are part-way through logging
(localStorage). These are required for operation and are not
evaluated for advertising. If analytics are switched on, an additional
identifier is set.
8. Automated decisions
Your plan is generated by an AI model from the answers you gave. It is a suggestion, it has no legal effect and it does not decide anything about you: no eligibility, no price, no access. You can regenerate it, change it, or ignore it. There is no automated decision-making within the meaning of Article 22 GDPR.
9. Not medical advice
The plans and estimates STARKOS produces are not medical advice and do not replace a medical assessment. The body-fat figure is an estimate with a stated range, not a measurement.