Privacy Policy
Last updated: 20 September 2026 (draft version)
Draft version — not yet legally binding
This privacy policy is currently under legal review. Until a qualified data-protection lawyer has approved it, treat it as a technical draft and not as legally binding text. The final applicable version will be published before the platform's public launch.
1. Privacy at a glance
This privacy policy explains how we collect, use and protect your personal data when you use our Pilates platform. The controller for the data processing is the person or entity listed in the imprint.
We process personal data strictly on the basis of the EU General Data Protection Regulation (GDPR) and applicable German data-protection law. The database and the file storage are located exclusively in Frankfurt, and that is also where signed-in pages are rendered. Exceptions to processing within the European Union concern, in particular, transfers to our AI providers in the United States and a routing layer in front of the platform that checks your session cookie, on every page request, at whichever location is closest to your internet connection; they are described in sections 4 and 5.
You have the right at any time to access, rectification, erasure, restriction of processing, data portability and objection — see section 6. You can request a machine-readable export of your stored data from your account settings at any time.
2. Controller and legal bases
The controller within the meaning of Art. 4 no. 7 GDPR is the person listed in the imprint. You can reach us through the contact details provided there.
We have not appointed a data protection officer because the statutory thresholds under § 38 BDSG (at least 20 persons permanently engaged in automated processing) are not met. Please direct any data-protection enquiries to the email address shown in the imprint.
Processing of your account data, training content and all data required to provide the platform is carried out on the basis of Art. 6(1)(b) GDPR for the performance of our terms of service with you.
Technical safeguards such as IP-based rate limiting, abuse detection and security logging are based on Art. 6(1)(f) GDPR; our legitimate interest is the secure and abuse-free operation of the platform. On the same basis we log technical errors — for example a failed request or an interrupted plan generation — so that we can find and fix faults, and we measure reach and loading performance in the cookieless form described in section 4. You can object to processing based on legitimate interest at any time; see section 6.
Optional processing activities — in particular marketing emails — are carried out exclusively on the basis of Art. 6(1)(a) GDPR, following your prior, freely given and revocable consent. You can manage your consents in your account settings.
Where we are required by law to retain records — for example tax and commercial bookkeeping documents — the legal basis is Art. 6(1)(c) GDPR.
3. Categories of personal data
Account data: email address, sign-up and last-sign-in timestamps, and a display name of your choice. Signing in works exclusively through a one-time sign-in code or link, generated by our auth provider Supabase and sent to you by email (delivered via Resend, see section 4). A password is never set and therefore never stored — so there is no password that could be stolen, guessed or reused on other sites.
Profile data: language preference, first and last name (optional), role within your studio and training preferences such as preferred modalities, difficulty levels and teaching style.
Profile photo: you can optionally upload a profile photo; it is never required. We store the image file with our processor Supabase (see section 4) at an address that contains your internal user ID and a timestamp, but neither your name nor your email address. That address is not access-protected: anyone who knows it can retrieve the image without being signed in. We do not publish the address, and within the application your photo is shown only to you. You can remove the photo at any time from your profile page; we then delete the image file from storage. If you delete your account, it is removed together with the rest of your data (see section 6).
Training content: class plans, personal exercise cues, favourites and ratings you create. Personal exercise cues are classified as confidential and are never transmitted to any AI provider — see section 4.
Calendar data: your appointments, class times, optional notes and links to class plans. Appointments marked as private are visible only to you and, where applicable, authorised studio administrators.
Workflow and audit data: review decisions, plan handoffs between teachers and teaching logs. This data is required to make approval and handoff processes in your studio traceable.
GDPR records: granted consents, deletion requests and their timestamps. This processing is strictly necessary to fulfil our accountability obligations under Art. 5(2) GDPR.
Technical access data: on every request our processors (see section 4) briefly log IP address, user-agent string and timestamp for security monitoring and rate limiting. These logs are deleted on each provider's own deletion schedule for operational and security logs; our rate-limiting counters expire automatically when their time window ends. We do not use this data for profiling.
Waiting list signup: if you join our waiting list without an invite code, we store your email address, the category you selected (independent teacher or studio), your language preference, the exact wording of the consent statement shown to you, and the timestamp and IP address of both your signup and your confirmation. The legal basis is your consent under Art. 6(1)(a) GDPR. We use double opt-in: your signup only takes effect once you have explicitly confirmed it via a link in a confirmation email; the timestamp and IP address serve solely as evidence of that consent. We use this data only to send you an invite code once a place opens up — not for marketing on other topics. You can withdraw your consent at any time with effect for the future by sending an informal email to info@mypilatesflows.com; we will delete your entry without delay. Otherwise we delete your entry at the latest twelve months after the end of the closed beta.
Quality assurance of AI plan generation: a class plan you have published may be copied by our administrators into an internal reference corpus that we use to measure the quality of AI-generated plans over time. The copy contains the plan title, its description and its exercise sequence; teacher notes, personal exercise cues, client data and structured personal identifiers are never copied. Title and description are free text that you write yourself, so please do not enter client names there. Because the corpus is our record of quality over time, a copy is retained even after you delete the original plan. It is visible only to platform administrators and is never published or passed on to third parties. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is being able to tell whether our AI results are getting better or worse. You can object at any time under section 6. We then take your plans out of the corpus, so they are no longer used for any measurement, and we delete the stored copy if you ask us to.
Contact enquiries: when you write to us through the contact form, we process your name, your email address, the role you select and your message if you write one — the message is optional. We use these details solely to answer your enquiry. The legal basis is Art. 6(1)(b) GDPR where your enquiry is aimed at entering into a contract with us, and otherwise Art. 6(1)(f) GDPR; our legitimate interest is answering your enquiry. Your details are not stored in our database: we receive them as an email sent through our processor Resend (see section 4), which stores email content and delivery logs in the USA and deletes them on its own retention schedule. We keep your enquiry in our email inbox for twelve months after receipt and then delete it. We carry out this deletion by hand; there is no automated deletion process. In addition, our email provider files every message in an archive we have no delete access to: a copy of your enquiry stays there for eleven years, including after we have removed it from the inbox. You can object to processing based on legitimate interest under section 6.
4. Processors and service providers
We rely on carefully selected processors to operate the platform. We have entered into a data processing agreement (DPA) pursuant to Art. 28 GDPR with each of them.
Supabase (Supabase Pte. Ltd, 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513) — database, authentication and file storage. The instance we use is hosted exclusively in the eu-central-1 region (Frankfurt); no replication outside the European Union takes place.
Anthropic Ireland, Limited (counterparty for customers in the European Economic Area; parent company: Anthropic, PBC, USA) — AI-assisted plan generation (Claude language models). We use Anthropic under a contractual training opt-out: your inputs are not used to train or improve any model.
Upstash, Inc. (Delaware, USA) — Redis-based rate limiting to protect against abusive use. The database we use is hosted exclusively in the eu-central-1 region (Frankfurt); no replication outside the European Union takes place.
Resend (Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA) — delivery of transactional email (e.g. signup confirmations, review notifications, contact enquiries). Data transmitted is processed solely for the purpose of delivering the relevant email and logging that delivery. Email is dispatched from the eu-west-1 region (Ireland); message content, delivery logs and account records are, however, stored on servers in the USA, as Resend does not offer data residency in the European Union.
Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA — hosting and content delivery. Server-side processing — API calls, the rendering of signed-in pages and all scheduled jobs — takes place exclusively in the fra1 region (Frankfurt). In front of it sits a routing layer that, on every page request, handles language redirection and checks your session cookie — renewing it when it has expired; it runs on the global Vercel edge network, at whichever location is closest to your internet connection. If you use the platform from outside the European Union, your session tokens are processed at that location; we do not store them there, but pass them to our Supabase instance in Frankfurt for validation. This routing layer reads no content: class plans, exercises and client data are processed exclusively in Frankfurt. Access logs are generated at the location that handles the request — for visits from outside the European Union, that includes locations outside the EU — and are deleted on Vercel's own schedule for operational and security logs; we set no retention period of our own for these logs. For anonymous audience measurement we also use Vercel Web Analytics, and for measuring loading performance in real browsers we use Vercel Speed Insights. Neither sets cookies and neither reads data stored on your device. Both transmit a pseudonymous device identifier that Vercel derives from request data and rotates regularly; it is not used to identify you personally and is not combined across websites. The legal basis for both is legitimate interest under Art. 6(1)(f) GDPR — you can object under section 6.
Important notice regarding personal exercise cues: the personal cues stored in your account are never transmitted to Anthropic or any other AI provider at any stage. They are resolved server-side and inserted into the final result only after plan generation has completed — a property that is permanently enforced at the architectural level.
Stripe Payments Europe, Limited — payment processing for paid tiers via Stripe's hosted Checkout page. When you purchase a paid tier, we transmit the paying user's email address and the name of the relevant workspace to Stripe; your payment details (e.g. card details) are captured by Stripe itself and never reach our servers. Because we, as the provider, are established in Germany, Stripe Payments Europe, Limited is our counterparty within the Stripe corporate group for this data processing agreement; it also transfers data in the course of providing the service to Stripe, LLC (USA) and other group companies and sub-processors.
IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany — operates the mailbox that receives messages sent to our product addresses info@mypilatesflows.com, tanya@mypilatesflows.com and datenschutz@mypilatesflows.com. These include, in particular, objections under section 6 and withdrawal of waiting-list consent under section 3. According to IONOS's product information, email data is kept in data centres in Germany; we do not yet hold a contractual assurance of the place of processing. Messages received by this mailbox are additionally stored in IONOS's email archive; the retention period configured there is eleven years. The data processing agreement has been part of the IONOS contractual terms since 19 July 2022.
Sentry (Functional Software, Inc. d/b/a Sentry, 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA) — error and performance monitoring. When a technical error occurs in the application, we send an error report to Sentry: the error message and stack trace, the path that was called without its query parameters, the time, the browser or server environment, and the version of our application. The Sentry SDK is configured so that IP addresses, cookies and the contents of form and API requests are not transmitted, and so that the query parameters of an address are removed before sending — in the error report, in the page-load measurements, in the recorded intermediate steps, and in the address of the referring page as well, so that a one-time sign-in link can never reach Sentry. Of the HTTP headers we transmit only the browser identification (User-Agent); without it an error cannot be attributed to a browser or an operating system. Error reports from your browser do not go to Sentry directly but to an address on our own domain, and from there on to Sentry's EU region; that forwarding is done by the Vercel routing layer described in section 4. We do not transmit your IP address ourselves, and Sentry is configured not to store IP addresses. The application's console output is not sent to Sentry. We use Sentry's EU region: error events, traces and source map files are stored exclusively in Frankfurt, Germany. All that remains in the USA is the administrative data of our own Sentry access (account, organisation and project settings, access tokens, usage statistics). We do not use session replay. The legal basis is our legitimate interest in the secure and error-free operation of the platform under Art. 6(1)(f) GDPR — you can object under section 6.
5. International data transfers
The majority of our processing takes place within the European Union. Transfers to third countries are limited to the providers listed in section 4 that process data in the USA (Anthropic, Resend, Vercel, Stripe). For Vercel, the routing layer described in section 4 is additional: it runs at whichever edge-network location is closest to your internet connection and processes your session tokens there. If you use the platform from outside the European Union, that may — depending on where you are — be a third country other than the USA. Upstash, Inc. and Supabase Pte. Ltd are domiciled outside the European Union but process and store personal data exclusively in the eu-central-1 region (Frankfurt). Sentry (Functional Software, Inc., USA) stores error events exclusively in its EU region (Frankfurt); all that remains in the USA is the administrative data of our own access.
These transfers are covered by the Standard Contractual Clauses adopted by the European Commission pursuant to Art. 46(2)(c) GDPR and — where available — by certification under the EU-US Data Privacy Framework pursuant to Art. 45 GDPR. We will provide a copy of the safeguards in place on request.
No other third-country transfers take place. In particular, we do not use any advertising networks, tracking pixels or social-media plugins, and no analytics service that sets cookies, reads data from your device or follows you across websites. The cookieless reach and performance measurement described in section 4 is the only measurement we carry out.
6. Your rights as a data subject
Right of access (Art. 15 GDPR): you have the right at any time to obtain a full copy of the personal data we hold about you. You can trigger a machine-readable JSON export directly from your account settings.
Right to rectification (Art. 16 GDPR): you can update your profile data, preferences and account details at any time directly in your settings, or contact us otherwise.
Right to erasure (Art. 17 GDPR): you can request deletion of your account directly from your settings. The deletion request is executed automatically after a 30-day grace period. If you withdraw it in your settings within that period, the withdrawn request is kept, with the times it was made and withdrawn, for as long as your account exists; if your account is deleted later, its link to you is removed as well. Personal data is then removed completely, with two exceptions: in shared records such as sharing links and review entries we only anonymise your link to them, to the extent that their retention is required to preserve the traceability of business processes; and a plan copied into the quality-assurance corpus described in section 3 is retained, with the reference to your workspace removed. If you want that copy deleted as well, tell us and we will delete it.
Right to restriction of processing (Art. 18 GDPR): you can ask us to restrict processing of your data while disputed matters are being resolved.
Right to data portability (Art. 20 GDPR): you receive your data in a structured, commonly used and machine-readable format (JSON) via the account export mentioned above.
Right to object (Art. 21 GDPR): you can object at any time to processing of your data where we rely on Art. 6(1)(f) GDPR. This applies in particular to the cookieless reach and performance measurement described in section 4 and to the quality-assurance corpus described in section 3. An informal email to info@mypilatesflows.com is enough; you do not have to give a reason, and we will stop the processing concerned without delay.
Right to withdraw consent (Art. 7(3) GDPR): you can withdraw consents at any time with effect for the future. Processing carried out until withdrawal remains lawful.
Right to lodge a complaint (Art. 77 GDPR): you have the right to lodge a complaint with a data-protection supervisory authority about how we process your personal data. The authority responsible for us is Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg), Postfach 10 29 32, 70025 Stuttgart (street address: Heilbronner Straße 35, 70191 Stuttgart), phone 0711 615541-0, email poststelle@lfdi.bwl.de, https://www.baden-wuerttemberg.datenschutz.de. Independently of this, you may also lodge a complaint with the supervisory authority responsible for your place of residence, your place of work, or the place of the alleged infringement.
7. Third-party data in free-text fields
My Pilates Flows has no client management. There are no client records, no fields for a birthday, a contact number or health details, and no feature for recording the complaints, injuries or physical restrictions of another person. An earlier feature of that kind was removed in full; the database tables behind it no longer exist. No processing of special categories of personal data within the meaning of Art. 9 GDPR is therefore provided for.
Personal data about other people can nevertheless end up in free-text fields that you fill in yourself — in particular the title, description and notes of a class plan, the notes on an appointment, and the notes on a class diary entry. What you enter there is entirely your decision. These fields receive no special handling; they are processed as described in sections 3 and 4. Two points deserve particular attention: the notes on a class plan are never transmitted to our AI provider — neither on the first generation nor on a regeneration; and the title and description of a published plan may, by contrast, be copied into our internal reference corpus as described in section 3.
Please do not enter health data in these fields, and avoid entering the names of the people you teach wherever you can. This platform is not intended for health data within the meaning of Art. 9 GDPR: there is no feature for it, and we do not maintain the additional safeguards such processing would require.
Where you enter personal data about other people into these fields, you are the controller for that data within the meaning of Art. 4(7) GDPR; My Pilates Flows processes it on your behalf as a processor under Art. 28 GDPR. The data processing agreement is currently being drawn up and will be published on the AVV page; until then we provide it on request.