Privacy Policy
Introduction & Updates
Last updated: 23 August 2026
We are pleased about your interest in our website and our app. Protecting your privacy is our highest priority. In this privacy policy, we inform you comprehensively about how we process your personal data in connection with the use of our website, our app, and our newsletter.
Because our offerings may evolve, or because legal requirements may change, this privacy policy may be updated from time to time. We ask that you check back periodically to stay informed of the current version.
Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws is:
Robin Meis
Charlottenstraße 2
52070 Aachen
Germany
Email: hello@gravitygate.app
Phone: +49 241 9138508-0
No separate data protection officer is legally required or appointed. If you have any questions about data protection, you can contact us directly at any time using the contact details listed above.
General Principles of Processing
Location of processing: Your data is processed exclusively on dedicated hardware located in Germany. We do not use external hosting providers or foreign data processors for our core systems.
No transfer of data to third parties: Aside from services you explicitly choose and consent to (such as Single Sign-On, Amazon affiliate links, or dontkillmyapp.com in the Android app, see below), we do not transfer your data to other companies, and in particular not to third countries (such as the USA).
Legal basis: The general legal basis for processing your data in our app and on our website is your consent (Art. 6(1)(a) GDPR), which you give us in the course of using our services or registering.
Retention period: We process and store your personal data only for as long as is necessary to achieve the purpose of storage. Where statutory retention periods apply (e.g. under tax or commercial law), we must retain the relevant data for the duration of that legal period. After that, it is routinely deleted.
Security Measures
To protect your data against accidental or intentional manipulation, partial or complete loss, destruction, or unauthorized access by third parties, we implement appropriate technical and organizational security measures:
Encryption: Data transmission between your device and our servers (both web and app) is generally encrypted using current TLS/SSL protocols (HTTPS).
Password security: Passwords are never stored in plain text, but only as cryptographic hash values.
Dedicated hardware: Our systems run on dedicated hardware that we operate ourselves, with restricted access, in Germany.
Your Rights as a Data Subject
If your personal data is processed, you have, among others, the following rights:
Right to access: You have the right to obtain, free of charge and at any time, information about the personal data we have stored about you.
Right to rectification: You may request the correction of inaccurate data or the completion of your data.
Right to erasure: You have the right to request the deletion of your data (the "right to be forgotten"), provided no statutory retention obligations apply. In the app, you can delete your account yourself at any time.
Right to restriction of processing: Under certain conditions, you may request the restriction of processing.
Right to data portability: You have the right to receive data you have provided to us in a structured, commonly used, machine-readable format.
Right to withdraw consent: You may withdraw consent you have previously given for data processing (e.g. for the newsletter) at any time, with effect for the future.
To exercise your rights, an informal message to the contact details listed under Section 2 is sufficient.
Data Processing on the Website and in the App
6.1 Server log files (access data)
When you use our website or app purely for informational purposes, we collect access data in the form of so-called server log files. Purpose: this data is used exclusively to ensure the security of our systems, to troubleshoot errors, and to maintain operations. Data collected: date and time of access, page/function accessed, operating system and browser used, IP address. Cookies: we do not use any cookies on our website. There is no covert tracking of your browsing behavior.
6.2 App registration and user profiles
Registration is required to use certain features of our app. Data collected: to register, we need an email address, a password (stored as a hash), and a display name. Real names are not required; you can use the app entirely under a pseudonym. Optionally, you may also provide your gender; this is voluntary, is used to personalize your profile and, where applicable, for gender-specific evaluations (e.g. leaderboards), and can be changed or removed at any time. Also optionally, you may provide your date of birth; this is voluntary and is used to calculate your age and to compare your results with other users in the same age group (e.g. age-specific leaderboards), and can be changed or removed at any time. Profile visibility: in the app's settings, you can set your profile to private. Even with a private profile, your profile picture and the name you have set remain visible to other users, and other users can still send you friend requests. For your confirmed friends, your data remains fully visible regardless of this setting. With a private profile, however, you no longer take part in public leaderboards, and your ridden trails and the associated details (including times, splits, cadence, and speed data, see 6.11) are visible only to your friends; heart rate data is additionally subject to the separate, independent visibility setting described in 6.11. Exception for race mode: if you actively take part in a race, the details of your results and rides are visible, for the duration of that race, to all other participants — regardless of your other profile setting; the legal basis for this is your consent, which you give by actively taking part in the respective race (Art. 6(1)(a) GDPR). You have control over your visibility settings at any time. Deletion: you have the right and the technical ability to delete your account in the app at any time. When your account is deleted, your profile data is deleted without delay. We are not subject to any statutory retention obligations for this user-generated profile data. Device recognition at login: at every login, we additionally collect the manufacturer, model, and operating system version of the device used. Purpose: this information makes your logged-in devices recognizable in your session/device overview, so you can identify unfamiliar or no-longer-used logins and end the corresponding sessions. Legal basis: this processing is necessary to provide this account security feature under the usage agreement (Art. 6(1)(b) GDPR).
6.3 Location and movement data (trail tracking)
A core feature of our app is recording and evaluating mountain bike trails. Data collected: when you create a new trail or ride an existing one, the app records your location as a GPS movement track for the duration of that ride. Purpose: this data is needed to determine the course of the trail (or match it against existing trails) and to calculate your times and speeds (timing feature). Legal basis: location recording only occurs when you actively start a recording and have granted the app the corresponding location permission at the operating-system level; the legal basis is your consent (Art. 6(1)(a) GDPR). Visibility: whether recorded movement data, and the trails and times derived from it, are visible to other users depends on your profile settings (see 6.2). Deletion: you can delete individual, not-yet-published recordings as well as your entire private movement history in the app at any time. When your account is deleted, your personal location data is removed; trails you have already published are not deleted but are instead anonymized by irreversibly removing the link to your user account, so that they can no longer be attributed to you.
6.4 Single Sign-On (Apple & Google)
In the app, we offer you the option to register and sign in using Single Sign-On based on OpenID Connect (OIDC) via Apple ("Sign in with Apple") or Google ("Sign in with Google"). If you use this voluntary feature, Apple or Google will, after your authorization there, transmit to us the data required for registration (e.g. your email address). The legal basis for this is your consent. Please note that clicking the sign-in button establishes a connection to Apple's or Google's servers (potentially located in the USA), and their respective privacy policies apply.
6.5 App stores and test programs (Apple TestFlight / Google Play Console)
To make our app available to you, we use the infrastructure of Apple (App Store / TestFlight) and Google (Google Play Store). If you download our app or take part in beta test programs, these providers process data (e.g. crash reports or device data) under their own responsibility. This occurs on the basis of your consent to Apple or Google. You can opt out of the respective test programs at any time via your device settings or the app store.
6.6 Contact form
If you send us inquiries via a contact form, the information you provide (name, email address, and the text of your inquiry) is stored by us for the purpose of processing your inquiry and in case of follow-up questions. We do not share this data without your consent.
6.7 Newsletter and tracking beacons
You have the option to subscribe to our newsletter. Data and consent: for this, we need your email address and your explicit consent (opt-in). Double opt-in procedure: after you sign up, we first send you a confirmation email containing a link. Only once you click this link and thereby confirm your registration is your email address added to our newsletter distribution list. This procedure ensures that only the actual owner of the email address subscribes and prevents misuse by third parties. Tracking: in our newsletter, we use so-called tracking beacons (small, invisible graphics). These allow us to statistically evaluate whether and when a newsletter was opened and which links were clicked, in order to optimize our content for you. By signing up for the newsletter, you consent to this tracking. Withdrawal: you can withdraw your consent to receive the newsletter and to this tracking at any time (e.g. via the "unsubscribe" link at the end of each newsletter).
6.8 Amazon Associates Program (affiliate)
Our website and app participate in the Amazon Associates Program. We include affiliate links through which we may earn advertising commission if users make purchases through them. If you click on such a link, Amazon records that you clicked the link on our site. This may result in data being transmitted to Amazon. Use of these links is entirely voluntary.
6.9 dontkillmyapp.com (Android app only)
Because manufacturer-specific power management on some Android devices can terminate background trail recording prematurely, we optionally offer you, in the Android app, guidance with device-specific instructions on how to prevent this. If you actively open this guidance, the app uses the API of dontkillmyapp.com; your device then establishes a connection to this third-party provider's servers and transmits technical device data (e.g. your smartphone's manufacturer and model) as well as your IP address. The server location of dontkillmyapp.com is outside our control and may be outside the EU (e.g. in the USA). Use of this feature is voluntary; the legal basis is your consent (Art. 6(1)(a) GDPR). This feature exists only in the Android app and is not linked to personal user data such as your name or email address.
6.10 Measurement sensor (Bluetooth)
Timing a run requires the app to pair, via Bluetooth, with the sensor needed for this measurement. Data collected: together with the measurement data supplied by the sensor, we transmit its unique device identifier (MAC address) to our servers. Purpose: the MAC address is used to uniquely match the measurements to the respective sensor and for technical diagnostics, e.g. to identify and resolve sensor-specific connection or measurement errors. Legal basis: transmission only occurs when you actively start a recording with the sensor paired; the legal basis is your consent (Art. 6(1)(a) GDPR). Deletion: the sensor identifier is deleted or anonymized together with the associated recordings (see 6.3).
6.11 Additional sensors (heart rate, cadence, speed)
In addition to the sensor described in section 6.10 that is required for timing, you can optionally pair further sensors with the app via Bluetooth. If such a sensor is paired during a recording, its measurement data is stored together with the respective ride. Legal basis: this additional data is only collected if you actively pair the respective sensor, and the legal basis is your consent (Art. 6(1)(a) GDPR).
Heart rate: If you pair a heart rate sensor, your heart rate is recorded during the ride. Visibility: because heart rate data is health data, it is not publicly visible by default. In the app's privacy settings, you can decide whether your heart rate data should be visible to other users. Deletion: you can delete your heart rate data yourself in the app at any time — either globally for all recordings or individually for a specific ride.
Cadence: If you pair a cadence sensor, your cadence is recorded during the ride. Visibility: cadence data is visible to other users if a cadence sensor was paired during the respective recording and your profile is not set to private (see 6.2).
Speed: As described in section 6.3, your speed is generally determined from your GPS location data and, as part of the timing feature, is technically necessary. You can optionally pair an external sensor to capture your speed more precisely. Visibility: speed data is visible to other users unless your profile is set to private (see 6.2).
Glossary (Definitions)
To make this privacy policy transparent and understandable, we explain the key terms below:
Personal data: Any information relating to an identified or identifiable natural person (e.g. name, email address, IP address).
Data subject / user: The person whose personal data is processed.
Processing: Any operation performed on personal data (e.g. collecting, recording, storing, altering, or deleting it).
Controller: The natural or legal person who determines the purposes and means of the processing of personal data.
Pseudonymization: Processing data in such a way that it can no longer be attributed to a specific person without additional information (example: using a made-up name instead of your real name in the app).
Hashing: A one-way encryption method. A password is converted into an unreadable string of characters (a hash value). The original password cannot be recovered from the hash value.
Single Sign-On (SSO): An authentication method that lets a user sign in to different services using a single existing account (e.g. Google or Apple), without creating a new password.
OpenID Connect (OIDC): A standardized technical protocol on which Single Sign-On logins (e.g. "Sign in with Apple/Google") are built.
Location/movement data: Geographic position data determined via GPS which, when recorded over time, reconstructs a path traveled (e.g. a ridden trail).
Tracking beacons (pixel tags): An invisible mini-graphic (usually 1×1 pixel) embedded in emails. When the email is opened, the pixel is loaded from the server, which allows it to be recorded that the message was opened.