Last updated: 2026-07-04
Privacy Policy
This policy explains what data Breach handles, how, and why. It is written to be readable. If something is unclear, use our contact form and choose Privacy.
1. Who we are
Breach is operated by Fortymark, registered in the Netherlands.
- Contact: getbreach.app/contact (choose Privacy for GDPR requests)
We are the data controller for the personal data described below.
2. Scope: website vs app
getbreach.app (this website) and the Breach iOS app collect different data for different purposes. Sections below label which surface applies.
The App Store privacy label describes data collected by the iOS app. This policy also covers the website, support forms, waitlist, and other direct messages you send to us.
3. What we collect
Providing your account and profile data is necessary to use the app; without it we cannot create or sync your account. Waitlist email, feedback, and optional profile fields are voluntary.
A. Website (getbreach.app)
Waitlist email: When you join the waitlist, we collect your email address. It is stored in our EU-hosted waitlist database. We use a transactional email provider to send the confirmation email.
Contact and feedback forms: If you use /contact or /feedback, we collect what you submit: name, email, message, and topic/type. We deliver those messages by email to our team. We do not store contact or feedback messages in a website database.
Website analytics: We use anonymous aggregate traffic statistics without cookies. With your cookie consent, we also use first-party analytics cookies and local storage to understand page views, button clicks, waitlist submissions, and form reliability. For waitlist analytics, we identify signups with a SHA-256 hash of your email, not your raw email. Website analytics is not used for advertising or cross-app tracking.
Hosting and bot protection: When you browse the site or submit a form, our hosting and anti-abuse providers may process technical data such as IP address, user agent, timestamps, request logs, and form security signals.
B. iOS app
Sign in with Apple: To use the app you sign in with Apple. Apple provides an identifier and may provide your name and email, including Apple's private relay address if you choose Hide My Email. We store the account record so the app can authenticate you and restore your data.
Profile and preferences: After sign-in we maintain an app profile, including for example: display name, chosen program template, training frequency, preferred days, equipment, units, goal, experience, optional gender and date of birth, and technical context such as locale, region, language, device model, OS/app version, and capture time.
Workout data (device + EU backup): Workouts, sets, reps, weights, RPE, programs, PRs, and history are stored locally on your device. They are also synced to our EU-hosted backend under your account with per-account access controls. Sign in with Apple links your account so you can restore your log on a new device. The adaptation engine runs on your device using your local workout data. We do not sell your training data.
App analytics: The app sends behavioural events to our EU analytics project, for example session start, screen views, conversion-related events, and app reliability events. The distinct identifier is your app user ID. We may flag internal/test accounts. We do not send workout content, email, or advertising identifiers in app analytics. We do not use Apple's App Tracking Transparency framework because we do not track you across other companies' apps or websites.
Subscriptions: Paid Adaptive subscriptions are sold through the App Store. Apple processes payment. We use subscription-status infrastructure to verify whether Adaptive features should be active. We do not receive your card details.
4. How we use it
- Waitlist email: notify you about launch / TestFlight. Lawful basis: consent.
- Contact / feedback: respond to your message. Lawful basis: legitimate interest / pre-contractual steps.
- Anonymous website statistics: understand aggregate traffic. Lawful basis: legitimate interest.
- Consent-based website analytics: improve the marketing site and form reliability after you accept analytics cookies. Lawful basis: consent.
- Hosting and bot protection: serve the site, prevent abuse, and keep forms reliable. Lawful basis: legitimate interest.
- Account & profile: provide the app, store preferences, and support. Lawful basis: contract.
- Workout data (device): logging, adaptation, and history. Lawful basis: contract (performance on your device).
- Workout backup (EU): backup, cross-device restore, sync, service reliability, support, and account deletion. Lawful basis: contract.
- App analytics: understand product usage and fix drop-off. Lawful basis: legitimate interest (limited, no workout content).
- Subscription status: deliver Adaptive features. Lawful basis: contract.
- Legal / tax: where required. Lawful basis: legal obligation.
5. Who we share with
We use a small number of service providers to run Breach. They process data only for the purposes described in this policy and under appropriate contractual safeguards, and are required to protect it to at least the standard described in this policy. We do not sell personal data or share it with advertisers.
Website processor categories
- Waitlist database hosting
- Transactional email delivery
- Consent-based website analytics
- Website hosting and edge infrastructure
- Bot protection and rate limiting
iOS app processor categories
- Authentication and account database
- EU workout backup and sync infrastructure
- App behavioural analytics
- Subscription status verification
Apple services
Apple is an independent controller for Sign in with Apple, App Store billing, payment processing, refunds, and Apple account settings.
6. International transfers
Our app account, workout backup, and app analytics infrastructure are configured for processing in the European Economic Area where available.
Some website hosting, email delivery, anti-abuse, analytics, or subscription-status providers may process data outside the EEA. Where this happens, we rely on safeguards recognised by the GDPR, such as an EU adequacy decision or the European Commission's Standard Contractual Clauses (SCCs). You can request more information about these safeguards via our contact form (choose Privacy).
7. Security
We apply technical and organisational measures proportionate to the risk, including TLS in transit, encryption at rest on managed databases, access controls, and secrets kept out of source code. No system is perfectly secure. Report issues via our contact form and choose Other.
8. Data breach notification
If a personal data breach is likely to pose a risk to your rights, we will notify the Dutch Data Protection Authority without undue delay and, where feasible, within 72 hours where required, and notify you without undue delay when the breach is likely to result in a high risk to you (Articles 33-34 GDPR).
9. Retention
- Waitlist email: Until your invite is sent or you ask us to remove it, whichever comes first.
- Contact / feedback: As long as needed to handle the request, then deleted or anonymised unless we must keep it for legal reasons.
- Profile & auth: While you have an account. On deletion, live account/profile rows are removed immediately (see §10). Encrypted database backups may still contain deleted data for a limited rolling period before they are overwritten.
- App analytics: Behavioural events are kept only as long as we need them to understand product usage and fix problems, then deleted or aggregated. After you delete your account: we reset the analytics identifier on your device, but historical events already stored under your pseudonymous user ID are not automatically erased and may remain until that retention period expires.
- Website analytics: Kept for a limited period and then deleted or aggregated. Your consent choice and analytics cookies persist until you change them via Cookies in the footer.
- Workout data: On your device while you use the app, and in your EU backup while you have an account. On deletion, live workout rows are removed from our backend (see §10); encrypted database backups may still contain deleted data for a limited rolling period before they are overwritten.
- Subscription / tax records: As required by Dutch law (currently up to 7 years for relevant records).
10. Your rights and account deletion
Under the GDPR (Articles 15-22) you may request access, rectification, erasure, restriction, portability, or object to certain processing. Withdraw consent where processing is consent-based. Use our contact form, choose Privacy, and we respond within one month (longer only where the GDPR permits, with notice).
Delete your app account: In the app: Settings > Delete account. This deletes your app account and profile, erases your synced workout backup on our servers, wipes local workout data on the device, logs out subscription-status services, and resets the analytics client on the device. Deleting your account does not cancel an App Store subscription; cancel that separately via your Apple ID settings (see our Terms). As noted in §9, past app analytics events under your pseudonymous user ID may still exist until they expire under analytics retention.
Workout data: Export via the app. To remove data without deleting your account, use the contact form with Privacy.
Waitlist: Use the contact form with Privacy to be removed from the waitlist.
We may ask for reasonable proof of identity before acting on a request.
11. Automated decisions
The adaptation engine adjusts your weekly program from what you logged. That logic runs on your device using your local workout data. Server backup supports restore and service reliability; it is not used for automated marketing or scoring decisions. We do not make automated decisions about you that produce legal or similarly significant effects (Article 22 GDPR).
12. Children
Breach is not directed at people under 16. We do not knowingly collect data from under-16s. If we learn that a user is under 16, we will delete their account data.
13. Cookies (website only)
The website uses anonymous aggregate traffic statistics without cookies. If you accept analytics cookies, we also use a first-party analytics cookie and local storage for website product analytics. Analytics is gated by the consent banner; you can change your choice via Cookies in the footer. We do not use advertising cookies.
14. Changes
We will post updates here and change the "Last updated" date. For material changes, continued use 30 days after notice may count as acceptance where permitted by law.
15. Contact and complaints
- Contact form - choose Privacy for GDPR requests, Support for general help, or Other for anything else
You may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.