Camera and workout data
| Data | Where and why | Who can see it | Retention |
|---|---|---|---|
| Live camera frames and pose points | Processed on your device to count repetitions. The app does not send raw frames or pose landmarks to the server for recognition. | You, on your screen. | Live processing only; discarded when the camera stops. |
| Short replay and preview | Created on your device after a set and uploaded to private Cloudflare R2 storage. | You, selected group members, and anyone who receives the unlisted replay URL. | Until account deletion or an earlier valid deletion action. |
| Unedited corrected-set evidence | Temporarily captured on-device; uploaded only when the automatic count is manually corrected, to evaluate the counter. | Authorized administrators only. Never shown in group timelines or through a replay URL. | Until account deletion or earlier administrative removal. |
| Workout record | Repetitions, recognized count, manual-correction flag, duration and times are stored in Cloudflare D1 to build personal and group progress. | You, relevant group members in aggregated views, and administrators. | Until account deletion. |
Account, device and communication data
| Data | Where and why | Visibility | Retention |
|---|---|---|---|
| Login and profile | Email and identity are managed with Firebase. Name, optional birth date and metadata-free profile images support your app profile. | Email is limited to you and administrators; name and photo are visible to your groups. | Until account deletion. |
| Groups and invitations | Cloudflare D1 stores names, memberships, owner roles, targets, progress and invite records. | Group participants and administrators, depending on the field. | Group history lasts until group or owner-account deletion. Expired invites are cleaned up; accepted invites after 30 days. |
| Country, region and device diagnostics | Cloudflare derives country and coarse region from the request. A completed set stores broad device, browser, screen, camera and counter-performance data for support and improvement. | Authorized administrators. | Workout-linked data lasts until account deletion. |
| Push subscription | Your push endpoint and encryption keys are stored only after opt-in so group notifications can reach this device. | Service infrastructure and administrators; other members cannot see the endpoint. | Until disabled, invalidated or account deletion. |
| Notification preferences and events | Your notification categories, timezone and quiet hours control delivery. We store minimal notification lifecycle events so permission and delivery flows can be measured. | Preferences are private to you and authorized administrators; event data is available to product administrators. | Until account deletion, subject to configured operational retention. |
| Campaign reminder and dismissal | A root-admin campaign can target people without their own group, people without a logged push-up, or everyone. An in-app reminder stores a campaign/user dismissal so it stays dismissed. | The targeted user sees the reminder; campaign content and publication state are available to authorized administrators. | Until account deletion, or campaign revocation for an active reminder. |
| Product analytics | Danno Events receives pseudonymous feature events, a random session ID and broad browser/device context. The app payload excludes account ID, email and raw invite tokens. | Product administrators and the analytics provider. | Provider retention must be confirmed before legal publication. |
| Feedback and payments | Feedback text and diagnostic context are stored in D1. Mollie handles payment details; the app keeps status, amount, currency and references. | Administrators and, for payments, Mollie. | Feedback lasts until deletion unless removed earlier. Financial records follow legal requirements. |
Deletion: what actually happens
Account deletion requires a fresh sign-in, the exact account email and a second confirmation. The server removes database records and media, recalculates shared totals, then deletes the Firebase login. A temporary retry marker prevents a partial failure from recreating already-deleted app data. The marker is removed after Firebase confirms deletion.
Deleting a group removes group settings, membership, progress, invitations and group links to sessions. Members keep their personal accounts and workout history. Deleting the owner's account also deletes every group that person owns.
Start in Profile & settings → Danger zone, or use the contact page if you cannot sign in.