arrowdex
HomeAboutLegal
languageEN
EnglishENDeutschDEEspañolESFrançaisFRItalianoITPortuguês (Brasil)PTTürkçeTR日本語JA한국어KOहिन्दीHI
Get the app
badgeImprintshieldPrivacy PolicygavelTerms of Useperson_removeDelete account
Contents1. Controller2. What data we process3. Why we process it — purposes and legal bases4. Processors and recipients5. Third-country transfers6. How long we store data7. Your rights8. Consent management and device storage9. Push notifications10. Cookies and tracking11. Security12. Minors13. Sharing with clubs and coaches14. Changes to this policy
Available inEN·DE·ES·FR·IT·PT

Privacy Policy

Last updated: 2026-08-27

This Privacy Policy explains what personal data Arrowdex collects, why we collect it, who we share it with, and how you can exercise your rights under the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

This policy applies to the Arrowdex mobile app (Android, iOS) and the Arrowdex backend reachable at https://api.arrowlab.pott.dev.

1. Controller

Controller in the sense of Art. 4 (7) GDPR and § 18 (2) MStV:

Johannes Ptaszyk
Gladbecker Str. 291
46240 Bottrop, Germany
E-Mail: contact@pott.dev

There is no statutory data protection officer — the controller's role is below the threshold of § 38 (1) BDSG. For all privacy-related questions, contact the address above.

2. What data we process

CategoryWhat is includedSource
Account dataE-mail, display nameIdentity provider (Zitadel Cloud) when you sign in
Training dataTraining sessions, scores, bows, sight marks, equipment notes, weather readings you recordData you enter in the app
Billing dataApp Store / Google Play purchase receipts, Pro subscription state, expiryApple App Store / Google Play (via RevenueCat)
TelemetryCrash reports, performance traces, error breadcrumbsGenerated automatically by the app and backend
Push tokensFirebase Cloud Messaging registration tokenIssued by Firebase on first app launch
Device locale + regionLanguage code, country codeOperating system, when the app starts
Approximate locationLatitude / longitude, truncated to 4 decimals (about 11 m precision)Only when you tap "Fetch weather automatically"
Server logsIP address, request path, timestamp, user agentGenerated automatically when the app talks to the backend
Backend telemetryRequest traces, performance metrics, application logsGenerated automatically by the backend; secrets and personal data are stripped before the payload leaves our server
Anonymous usage analyticsScreen views, live-user count, OS / app version / language, feature eventsOnly if you enable Analytics in the consent screen. Carries no identifier of any kind, so it cannot be linked back to you
Data shared with clubs and coachesWhatever categories you explicitly grant, e.g. training sessions, scores, personal bestsOnly on an access grant you create yourself (see section 13)

We do not process special categories of personal data (Art. 9 GDPR — health, biometric, religion, political opinion).

Is providing this data required? Account data and the training data you enter are needed to perform the contract: without them we cannot provide an account or sync. You are not legally obliged to provide them, but the Service cannot be used without an account. Everything marked as consent-based in section 3 — analytics, enhanced logging, weather, push, sharing with clubs and coaches — is entirely voluntary, and declining it has no consequence beyond that feature not working.

Automated decision-making. We do not use automated decision-making producing legal effects concerning you or similarly significantly affecting you (Art. 22 GDPR), and we do not profile you. The statistics the app shows you are calculated from your own entries and have no legal effect.

3. Why we process it — purposes and legal bases

PurposeLegal basisNotes
Provide the core training-log functionality (signup, sync, account)Art. 6 (1) lit. b GDPR (contract)Without this we cannot deliver the service you signed up for
Process Pro subscription payments and entitlementsArt. 6 (1) lit. b GDPR (contract)Receipts flow through Apple / Google → RevenueCat → us
Detect crashes and operational errorsArt. 6 (1) lit. f GDPR (legitimate interest)Our interest in a stable service outweighs the minimal data attached to error reports; no identifiers are sent unless you opt in to enhanced logging
Send transactional push notifications (training reminders, sync events)Art. 6 (1) lit. a GDPR (consent)You can revoke notification permission in the OS settings at any time
Fetch weather data for a training sessionArt. 6 (1) lit. a GDPR (consent)Only fires when you actively tap "Fetch automatically"
Optional anonymous usage analytics and enhanced error loggingArt. 6 (1) lit. a GDPR (consent)Toggleable in the in-app Privacy settings screen; default is off
Share training data with a club or coach you granted access toArt. 6 (1) lit. a GDPR (consent)Only the categories you selected, only for as long as the grant lasts — see section 13
Operate the backend reliably (traces, metrics, application logs)Art. 6 (1) lit. f GDPR (legitimate interest)Our interest in an operable service; payloads are stripped of secrets and personal data before leaving our server
Keep the service secure: server access logs, defence against attacks and abuse, troubleshootingArt. 6 (1) lit. f GDPR (legitimate interest)Our interest in the integrity and availability of the backend and in the security of your data. Logs are kept only as long as needed for that purpose (section 6) and are not used to build a profile of you
Comply with statutory bookkeeping obligations on billing dataArt. 6 (1) lit. c GDPR (legal obligation)§ 257 HGB and § 147 AO require 10-year retention of invoice data

4. Processors and recipients

4.1 Processors (Art. 28 GDPR)

These providers process data only on our instructions. A Data Processing Agreement is in place with each of them.

ProcessorLocationPurpose
Zitadel Cloud (CAOS AG)Switzerland (Zurich)Identity provider — sign-in, e-mail + display name
RevenueCat Inc.USA (California)Subscription management — maps Apple/Google receipts to your account
Google LLC (Firebase Cloud Messaging)USA / IrelandDelivery of push notifications to your device
Functional Software, Inc. (Sentry)EU region (Frankfurt)Client crash reporting, EU data residency
Grafana LabsEU (Frankfurt)Backend telemetry — traces, metrics and application logs from our server
AptabaseGermanyAnonymous usage analytics — only if you enable Analytics; receives no identifier
Hetzner Online GmbHGermany (Nuremberg)Virtual server hosting, the PostgreSQL database that stores your training data, and encrypted object storage backups

4.2 Independent controllers

The following parties are not our processors. They decide on their own purposes and means, are responsible for that processing themselves, and their own privacy policies apply to it. We have no control over it and cannot answer data-subject requests on their behalf.

PartyRoleTheir privacy policy
Apple Inc.App Store distribution, in-app purchase and payment processing as sellerhttps://www.apple.com/legal/privacy/
Google Ireland Ltd. / Google LLCGoogle Play distribution, Google Play Billing as sellerhttps://policies.google.com/privacy
Clubs and coaches you grant access toWhatever they do with the data outside Arrowdex (see section 13)Provided by them

4.3 Not a personal-data transfer

The MET Norway weather request is neither an Art. 28 processor relationship nor a transfer of personal data: no personal identifier is sent — only an opaque 4-decimal latitude/longitude pair and a generic User-Agent. MET Norway cannot link the request to your account or device.

5. Third-country transfers

Some processors are located outside the European Economic Area:

  • Switzerland (Zitadel Cloud) — the European Commission has recognised Switzerland as providing an adequate level of data protection (Art. 45 GDPR).
  • United States (RevenueCat, Apple, Google) — transfers rely on the EU-U.S. Data Privacy Framework (Art. 45 GDPR adequacy decision of 2023-07-10) where the recipient is certified, or on Standard Contractual Clauses (SCCs) under Art. 46 (2) lit. c GDPR as a fallback.
  • Grafana Labs is a US-incorporated company, but the stack we use is hosted in the EU (Frankfurt) and the data stays there. The same DPF / SCC safeguards as above cover any access from the parent company.

You can request a copy of the SCCs by writing to the controller address in section 1.

6. How long we store data

DataRetention
Account, training data, bows, sight marksUntil you delete your account, plus a 30-day grace period during which you can restore by signing back in
Backups containing the aboveGrace period + an additional 30 days in encrypted backups on Hetzner Object Storage
Billing receipts (invoice data)10 years as required by § 257 HGB and § 147 AO
Crash and error reports90 days rolling window
Server access logs, traces and metricsUp to 30 days for logs and traces; aggregated metrics that contain no personal data are kept longer
Anonymous usage analyticsKept as aggregate counts. Carries no identifier, so there is nothing that could be traced back to you or deleted individually
Push tokensRefreshed on each app start; deleted when you revoke notification permission, and pruned once the platform reports the token as no longer deliverable (for example after you uninstall)
Weather readings linked to a training sessionSame lifetime as the parent training

7. Your rights

Under Articles 15–22 GDPR you have the following rights. To exercise any of them, write to contact@pott.dev or use the in-app paths noted below. We respond within one month (Art. 12 (3) GDPR).

  • Right of access (Art. 15) — request a copy of your data. In-app: Profile → Export account data.
  • Right to rectification (Art. 16) — correct inaccurate data. In-app: Profile → Edit display name; for other fields write to us.
  • Right to erasure (Art. 17) — In-app: Profile → Delete account (typed e-mail confirmation).
  • Right to restriction (Art. 18) — limit processing while a dispute is open.
  • Right to data portability (Art. 20) — receive your data in a machine-readable format (JSON). In-app: Profile → Export.
  • Right to object (Art. 21) — object to processing based on legitimate interest. In-app: revoke consent via Profile → Privacy settings, or write to us.
  • Right to withdraw consent (Art. 7 (3)) — for any consent-based processing. In-app: Profile → Privacy settings. Withdrawal does not affect the lawfulness of processing before the withdrawal.
  • Right to lodge a complaint with a supervisory authority (Art. 77) — the competent authority for the controller is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestraße 2–4
40213 Düsseldorf, Germany
poststelle@ldi.nrw.de

Your right to object — please read

You have the right to object at any time, on grounds relating to your particular situation, to processing of your personal data based on Art. 6 (1) lit. f GDPR (legitimate interest). That covers crash and error detection, backend telemetry, and our security and access logs.
If you object, we will stop processing your data for those purposes unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
An objection is informal and free of charge. Send it to contact@pott.dev.

8. Consent management and device storage

The app shows a consent dialog on first launch and after any material change to this policy. You can re-open it any time at Profile → Privacy settings.

Where a service stores information on your device or accesses information already stored there, that requires your consent under § 25 (1) TDDDG — unless the storage or access is strictly necessary to provide the service you expressly requested (§ 25 (2) no. 2 TDDDG). We rely on that exception only for the categories marked as required below. Consent given under § 25 TDDDG also serves as consent under Art. 6 (1) lit. a GDPR for the subsequent processing of that data.

Services are grouped into three categories:

  • Required — strictly necessary to deliver the app itself: the local storage of your account session and your training data on the device, and the baseline crash capture without which we cannot keep the app usable. Registering for push messaging happens only after you grant the notification permission at operating-system level; if you do not, the app runs without it.
  • Analytics — anonymous usage analytics. Default: off.
  • Functional — enhanced error logging with additional diagnostic context. Default: off.

The current list of services in each category is shown in the consent dialog itself. Each toggle takes effect immediately, and withdrawing consent is as easy as giving it: the same screen, one tap.

9. Push notifications

If you grant notification permission at the OS level, we send transactional pushes via Firebase Cloud Messaging (Android) and Apple Push Notification service (iOS). Examples:

  • Scheduled training reminders you opted into
  • Sync events when changes from another device need attention

We do not use push for marketing. You can revoke notification permission at any time in your device settings; the app continues to work without push.

10. Cookies and tracking

The Arrowdex mobile app does not use cookies — it is a native app — and it does not track you across other apps or websites. § 25 TDDDG is not limited to cookies, though: it covers any storage of or access to information on your device. The SDK toggles described in section 8 are therefore the mechanism through which you control that; the in-app screen for it is named Privacy settings.

The backend does not set any cookies for the app either. It uses bearer tokens issued by Zitadel in the Authorization header. The /admin backoffice, which only we use, sets a session cookie that is strictly necessary for logging in.

11. Security

  • TLS 1.3 for every connection between the app and the backend, and between the backend and every processor.
  • Bearer tokens are time-limited and rotated on every refresh.
  • Database backups are encrypted at rest with SSE-C (server-side encryption with customer-supplied keys); the encryption key never leaves our infrastructure.
  • Passwords are not handled by us — authentication is delegated to Zitadel.

12. Minors

Germany has not lowered the age limit in Art. 8 (1) GDPR, so consent to an information-society service is valid from the age of 16 here. If you are under 16, any processing we base on consent — analytics, enhanced logging, weather, push, sharing with a club or coach — requires the consent of the holder of parental responsibility, and the contract itself requires their agreement (section 3 of our Terms).

Arrowdex is not directed at children under 13 and we do not knowingly allow them to register. If you become aware that a child has provided us with personal data without the required consent, contact us and we will delete it.

Club and coaching features mean youth squads are foreseeable. Where a minor is involved, an access grant to a coach or club should be made by, or with the agreement of, the holder of parental responsibility.

13. Sharing with clubs and coaches

Arrowdex lets you connect with a club or a coach. Nothing is shared by default — every share is an access grant you create yourself, scoped to the data categories you pick.

  • You choose which categories a coach or club can see. Categories you do not grant stay invisible to them.
  • You can withdraw a grant at any time in the app. Withdrawal stops all further access; it does not undo what the recipient legitimately saw while the grant was active.
  • Leaderboards inside a club show the personal bests of the members who joined that leaderboard. Leaving the club removes you from it.
  • Coaches and club administrators are separate controllers for anything they record about you outside Arrowdex. Within Arrowdex, we remain the controller.
  • Deleting your account withdraws every grant you issued.

14. Changes to this policy

We may update this policy as the app and its processors evolve. The version number at the top of the in-app screen increments on every material change. When that happens, the app re-opens the consent dialog on next launch so you can review the new version before continuing.

The version number shown at the top of the in-app privacy screen is the authoritative one; this document was last updated on 2026-08-27.

arrowdex

Plan and track your archery training

ArrowdexHomeAboutGoogle Play ↗App Store ↗
LegalImprintPrivacy PolicyTerms of UseDelete account
Questions or feedback?contact@pott.devWe read everything.
© 2026 Johannes Ptaszyk · Made in Bottrop, Germanyglück auf

Apple and the Apple logo are trademarks of Apple Inc., registered in the U.S. and other countries. App Store is a service mark of Apple Inc. Google Play and the Google Play logo are trademarks of Google LLC.