1. Controller and Contact
The controller for the Oli Coach app and the website olicoach.app is:
Paul Jaeger
Am Bach 6
87439 Kempten
Germany
E-mail: support@olicoach.app
Phone: +49 1556 1255019
Privacy Policy
As of September 2026
The controller for the Oli Coach app and the website olicoach.app is:
Paul Jaeger
Am Bach 6
87439 Kempten
Germany
E-mail: support@olicoach.app
Phone: +49 1556 1255019
Account and contact: For the currently available e-mail-and-password sign-in, Oli Coach processes the chosen display name, e-mail address, a Supabase account ID, and necessary authentication records and acknowledged product notices. Sign in with Apple and Google is not available in the current app version. Passwords are processed by Supabase Auth and are not stored in plain text in Oli's product database.
Profile, plan and training: Depending on the user's input, Oli Coach processes data including year of birth, gender, height and weight, goals, training experience, sport, available days and equipment, exercise and plan preferences, strength and training-load values, planned and completed sessions, sets, repetitions, weights, perceived effort, streaks and training notes. This can include health information about injuries, pain, illness, medical clearance or physical limitations.
Coach chat and free-form content: Questions, answers, chat titles and workout or feedback notes entered by the user are stored with the account so that history, coaching and requested plan changes work. Oli Coach uses this content and the profile, plan and training context needed for a personalized response and plan feature.
Optional response feedback: Users can rate an individual answer with thumbs up or thumbs down. A rating does not initially submit any additional chat content. For a thumbs-down rating, the user may separately and voluntarily allow the current question, the rated answer and no more than two preceding conversation pairs to be displayed for quality review before submitting. Profile fields, internal system instructions, tool payloads and raw user identifiers are not provided.
Dictation: Optional dictation in Ask Oli and workout feedback enforces on-device speech recognition. Oli does not transmit or store an audio recording; only text visibly accepted by the user is processed like a normal chat or feedback entry.
Account and core features are processed to provide the service requested by the user (Art. 6(1)(b) GDPR). Voluntary sharing of a feedback excerpt is based on consent.
Oli Coach uses Supabase Inc. for database and authentication services. Operational user data is stored encrypted in an EU region in Frankfurt, Germany.
The account record includes the account, profile, plan, workout and chat data described above, as well as technical operation metadata such as random request and operation IDs, timestamps, processing status, quota counters and acknowledged product notices. This metadata is used for secure and idempotent processing, quota enforcement and history delivery.
Active chat histories remain available until the user deletes or archives them, or requests account deletion. Archived chats are automatically deleted after 30 days. Plan, profile and workout data is generally retained until the user changes it or the account is deleted; shorter periods for feedback, operational metrics and access logs are set out in section 6.
Because the current app offers neither paid subscriptions nor in-app purchases, Oli Coach currently collects no payment data and no new purchase or subscription transaction data.
Infrastructure and API: The website and API are hosted in the EU by Hostinger Operations SIA, Frankfurt.
AI model responses: Chat inputs and training parameters required for a particular response may be transmitted through OpenRouter Inc., USA, to a selected model provider. The Oli gateway explicitly requests Zero Data Retention for every model request. In this mode, request data is processed transiently by the model provider only to generate the response, is not used for model training and is not retained.
Oli Voice: The app retrieves only a pre-generated catalog of general, non-personalized training prompts. In the current version, profile names, free text and individual workout details are neither sent to a speech-model provider at runtime nor stored as public audio files. Catalog generation likewise explicitly requests Zero Data Retention from OpenRouter.
Optional web sources: The prepared web-search feature is currently disabled in production. Accordingly, Oli currently sends no search queries or chat, profile, plan, workout or health data to Exa. A later activation requires a separate privacy and contractual review and an update to this policy.
Subscriptions: No paid subscription or in-app purchase is available in the current app version. The prepared LinkFive account link is disabled in the released product. Oli therefore currently sends no account, device, health or chat data to LinkFive. Before any later activation, the actual data flows and terms must be reviewed and this policy updated.
Exercise Media: Exercise demonstrations and media are served from the self-hosted Oli exercise catalog on our VPS. No personal data is sent to RapidAPI at runtime for this purpose.
International transfers: OpenRouter is based in the United States; depending on the selected model, another model provider outside the European Economic Area may participate. The specific complete model-provider chain depends on the selected model. The published contractual documents of Supabase and OpenRouter provide for EU Standard Contractual Clauses where international transfers require them. Users can request a copy of or reference to the applicable safeguards at support@olicoach.app.
Apple HealthKit integration is optional. If the user grants permission, Oli Coach may read and write selected HealthKit data such as workouts, heart rate, active energy, height and weight.
If a user saves imported body measurements to their Oli profile or synchronizes a workout with Oli, the selected values are processed as account, health or fitness data under the sections above. HealthKit permission can be changed at any time in Apple's settings.
HealthKit data is used only to optimize training guidance. It is never used for marketing, never sold and never shared for advertising purposes.
Oli Coach currently does not use external tracking SDKs, marketing tracking or hidden crash-reporting SDKs that create user profiles in the background.
Oli Coach processes minimal usage and operational metrics for security, reliability, capacity planning and abuse prevention, such as the activity type and number of app or feature requests and provider, model, token and cost values for AI requests. Activity is stored under daily rotating HMAC pseudonyms for no more than 7 days. Provider, model, token and cost values are aggregated hourly under a separate versioned HMAC pseudonym and retained for no more than 31 days. No coach-chat content, training content, e-mail address or raw user identifier is stored in these metrics. Small cohorts are not released and visible values are additionally coarsened.
Response feedback is processed separately from these content-free operational metrics. Shared chat excerpts are visible only to an active owner account in the specially protected Admin area after second-factor authentication; every access is audited without message content. The rating and any sharing permission are erased no later than 30 days after submission, and earlier if the related chat or account is deleted. Users can remove a rating in the app and thereby withdraw the sharing permission.
Before sign-up, the app creates a random installation identifier in the iOS Keychain. It is sent only on unauthenticated gateway calls for the version-compatibility check, onboarding, exercise media and plan generation. For rate-limited guest features, it is combined with IP address and user agent to produce an HMAC-pseudonymized abuse-prevention and quota identifier. The guest identifier contains no name, e-mail address, health content or chat content.
When an account is deleted, account-related operational pseudonyms are erased before final Auth deletion and tombstoned against delayed technical retries. Necessary server access logs may contain IP address, timestamp, host and path, HTTP status, user agent, app platform, version and build and, for guest requests, the random installation identifier. They contain no request bodies and are separated by service and retained for no more than 30 days. The legal basis for abuse prevention, operational metrics and access logs is Art. 6(1)(f) GDPR; the legitimate interest is the secure, stable and economical operation of the service.
If additional analytics, marketing cookies or app tracking are introduced later, this policy will be updated and consent will be requested where required.
Users have the right to request access, correction, portability and erasure of their personal data and to object to processing based on legitimate interests. Account deletion can be requested inside the app and is executed after a 14-day security period.
Users may also lodge a complaint with the competent supervisory authority. For the provider's location in Bavaria, this is the Bavarian Data Protection Authority (BayLDA).