← Back to home

Last updated: 2026-07-04

Privacy Policy

This policy explains what data Breach handles, how, and why. It is written to be readable. If something is unclear, use our contact form and choose Privacy.

1. Who we are

Breach is operated by Fortymark, registered in the Netherlands.

We are the data controller for the personal data described below.

2. Scope: website vs app

getbreach.app (this website) and the Breach iOS app collect different data for different purposes. Sections below label which surface applies.

The App Store privacy label describes data collected by the iOS app. This policy also covers the website, support forms, waitlist, and other direct messages you send to us.

3. What we collect

Providing your account and profile data is necessary to use the app; without it we cannot create or sync your account. Waitlist email, feedback, and optional profile fields are voluntary.

A. Website (getbreach.app)

Waitlist email: When you join the waitlist, we collect your email address. It is stored in our EU-hosted waitlist database. We use a transactional email provider to send the confirmation email.

Contact and feedback forms: If you use /contact or /feedback, we collect what you submit: name, email, message, and topic/type. We deliver those messages by email to our team. We do not store contact or feedback messages in a website database.

Website analytics: We use anonymous aggregate traffic statistics without cookies. With your cookie consent, we also use first-party analytics cookies and local storage to understand page views, button clicks, waitlist submissions, and form reliability. For waitlist analytics, we identify signups with a SHA-256 hash of your email, not your raw email. Website analytics is not used for advertising or cross-app tracking.

Hosting and bot protection: When you browse the site or submit a form, our hosting and anti-abuse providers may process technical data such as IP address, user agent, timestamps, request logs, and form security signals.

B. iOS app

Sign in with Apple: To use the app you sign in with Apple. Apple provides an identifier and may provide your name and email, including Apple's private relay address if you choose Hide My Email. We store the account record so the app can authenticate you and restore your data.

Profile and preferences: After sign-in we maintain an app profile, including for example: display name, chosen program template, training frequency, preferred days, equipment, units, goal, experience, optional gender and date of birth, and technical context such as locale, region, language, device model, OS/app version, and capture time.

Workout data (device + EU backup): Workouts, sets, reps, weights, RPE, programs, PRs, and history are stored locally on your device. They are also synced to our EU-hosted backend under your account with per-account access controls. Sign in with Apple links your account so you can restore your log on a new device. The adaptation engine runs on your device using your local workout data. We do not sell your training data.

App analytics: The app sends behavioural events to our EU analytics project, for example session start, screen views, conversion-related events, and app reliability events. The distinct identifier is your app user ID. We may flag internal/test accounts. We do not send workout content, email, or advertising identifiers in app analytics. We do not use Apple's App Tracking Transparency framework because we do not track you across other companies' apps or websites.

Subscriptions: Paid Adaptive subscriptions are sold through the App Store. Apple processes payment. We use subscription-status infrastructure to verify whether Adaptive features should be active. We do not receive your card details.

4. How we use it

5. Who we share with

We use a small number of service providers to run Breach. They process data only for the purposes described in this policy and under appropriate contractual safeguards, and are required to protect it to at least the standard described in this policy. We do not sell personal data or share it with advertisers.

Website processor categories

iOS app processor categories

Apple services

Apple is an independent controller for Sign in with Apple, App Store billing, payment processing, refunds, and Apple account settings.

6. International transfers

Our app account, workout backup, and app analytics infrastructure are configured for processing in the European Economic Area where available.

Some website hosting, email delivery, anti-abuse, analytics, or subscription-status providers may process data outside the EEA. Where this happens, we rely on safeguards recognised by the GDPR, such as an EU adequacy decision or the European Commission's Standard Contractual Clauses (SCCs). You can request more information about these safeguards via our contact form (choose Privacy).

7. Security

We apply technical and organisational measures proportionate to the risk, including TLS in transit, encryption at rest on managed databases, access controls, and secrets kept out of source code. No system is perfectly secure. Report issues via our contact form and choose Other.

8. Data breach notification

If a personal data breach is likely to pose a risk to your rights, we will notify the Dutch Data Protection Authority without undue delay and, where feasible, within 72 hours where required, and notify you without undue delay when the breach is likely to result in a high risk to you (Articles 33-34 GDPR).

9. Retention

10. Your rights and account deletion

Under the GDPR (Articles 15-22) you may request access, rectification, erasure, restriction, portability, or object to certain processing. Withdraw consent where processing is consent-based. Use our contact form, choose Privacy, and we respond within one month (longer only where the GDPR permits, with notice).

Delete your app account: In the app: Settings > Delete account. This deletes your app account and profile, erases your synced workout backup on our servers, wipes local workout data on the device, logs out subscription-status services, and resets the analytics client on the device. Deleting your account does not cancel an App Store subscription; cancel that separately via your Apple ID settings (see our Terms). As noted in §9, past app analytics events under your pseudonymous user ID may still exist until they expire under analytics retention.

Workout data: Export via the app. To remove data without deleting your account, use the contact form with Privacy.

Waitlist: Use the contact form with Privacy to be removed from the waitlist.

We may ask for reasonable proof of identity before acting on a request.

11. Automated decisions

The adaptation engine adjusts your weekly program from what you logged. That logic runs on your device using your local workout data. Server backup supports restore and service reliability; it is not used for automated marketing or scoring decisions. We do not make automated decisions about you that produce legal or similarly significant effects (Article 22 GDPR).

12. Children

Breach is not directed at people under 16. We do not knowingly collect data from under-16s. If we learn that a user is under 16, we will delete their account data.

13. Cookies (website only)

The website uses anonymous aggregate traffic statistics without cookies. If you accept analytics cookies, we also use a first-party analytics cookie and local storage for website product analytics. Analytics is gated by the consent banner; you can change your choice via Cookies in the footer. We do not use advertising cookies.

14. Changes

We will post updates here and change the "Last updated" date. For material changes, continued use 30 days after notice may count as acceptance where permitted by law.

15. Contact and complaints

You may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.