DE
Privacy Notice — Herkulis Training App
As of: August 18, 2026
This app is operated by the coaching staff of the Herkulis climbing team to build training plans, log training sessions, and share training videos for technique review. There is no public sign-up — accounts are created exclusively by the coaching staff.
What data is collected
- Basic data: name, email address, birth year (for automatic age category), role (trainer/athlete).
- Credentials: password, stored as an Argon2id hash — the plaintext password is never stored.
- Training data: training plans, logged sessions (climbing moves, intensity, notes), simplified log formats for younger athletes depending on age category.
- Training videos: optionally uploaded by athletes for technique review, including timestamped comments from coaches.
- Device tokens: for push notifications (e.g. "new week published").
- Crash reports: technical diagnostics (Apple MetricKit) when the app crashes — no training content, stored on our own EU servers.
- Access requests (since 9 October 2026): anyone requesting access on herkulis.slawomirbabicz.com sends their name, email address, club or practice, approximate size and an optional message. These details are used only to answer the request.
Purpose
Exclusively for organizing climbing training: training planning, progress tracking, communication between coaches and athletes.
Where data is stored
All data (database, training videos) is stored exclusively in data centers within the EU (Cloudflare, "Western Europe" region and an EU-jurisdiction R2 bucket).
Who else has access (data processors)
- Cloudflare (hosting, database, video storage, email delivery for notifications, EU region)
- Apple (push notifications via APNs — device delivery only, no access to training content)
No data is sold, used for advertising, or shared with any other third party.
Retention
- Training videos: kept for up to 4 years after upload (to preserve a record across a multi-year training arc), then automatically deleted. Can be deleted earlier at any time by the trainer or the athlete.
- Training logs and plans: kept for as long as the account is active, or until deleted by the coaching staff.
- Accounts: can be deactivated or deleted by the coaching staff at any time.
- Access requests: automatically deleted 12 months after they arrive.
Confidentiality and data security
Training progress, injury information, and training videos are sensitive, sometimes health-related data. They are protected accordingly:
- Encryption in transit: every connection to the app runs exclusively over TLS — unencrypted connections are rejected.
- Encryption at rest: the database and video storage are encrypted server-side (Cloudflare's platform-level "at rest" encryption). Passwords are never stored in plaintext, only as an Argon2id hash.
- Role-based access control: athletes only ever see their own data. Parent/guardian accounts can only see explicitly linked children — that link is the single trust boundary in the system and is maintained by the coaching staff. Coaches can be scoped to specific age categories.
- Extra protection for the most sensitive fields: free-text notes in training logs — the day note, per-entry notes, and the risk/injury feedback note — plus the trainer's injury-log notes are additionally field-level encrypted with a separate key kept apart from the database — a stolen database export alone does not make these notes readable.
- Two-factor authentication for coach accounts, access control and rate limiting at the infrastructure level, automatic lockout after repeated failed sign-in attempts.
- No sharing with third parties beyond the technically necessary data processors listed below — no ad networks, no data sales, no third-party analytics or tracking.
A note on "end-to-end encryption": training data is not currently end-to-end encrypted in the sense that only the athlete and their coach could decrypt it. Reason: the coaching staff needs team-wide visibility into training progress and injury risk to respond to safety concerns in time — an encryption scheme that hid this from coaches would work against athlete safety. Instead: server-side encryption in transit and at rest, plus additional field-level encryption for the most sensitive free-text entries (see above).
What happens if data is exposed
Should a data loss or unauthorized access occur despite the measures above:
- Affected accounts are locked immediately, credentials and keys are rotated.
- Affected athletes or their parents/guardians are informed without undue delay once the scope of the incident is understood.
- Where required, the incident is reported to the competent data protection authority within the legal deadline (72 hours of becoming aware, GDPR Art. 33).
- Short retention periods (see above) limit upfront how much historical data could ever be affected.
Your rights
Access, correction, deletion, or restriction of processing of your own data can be requested from the coaching staff at any time (contact below).
Minor athletes
For athletes under 18, a parent or guardian's consent is required before the account is actively used. The coaching staff collects this consent in person (e.g. when training starts) and records it in the internal member-management system.
Contact
For privacy questions: [email protected]