Privacy Policy
Last updated: 18 August 2026
This Policy explains what personal data the Ognik app (the “App”) processes, why, and on what legal basis, in accordance with Regulation (EU) 2016/679 (GDPR).
In case of any discrepancy between the Polish and English versions of this document, the Polish version prevails.
01Who controls your data
Paweł Król, a sole proprietor trading as Paweł Król (Polish NIP 6891217542, REGON 364232607) (“we”). Data-protection questions: support@ognik.app.
02What we collect
- Account: email address, display name, optional avatar.
- Training: your workouts, plans, calendar, activity history and recorded rides (power, cadence, speed, time, distance).
- Health and measurements (special category): weight, height, maximum heart rate, FTP and sensor readings captured during training.
- Strava: access token and activities (only if you connect your account).
- Technical: device type, app/OS version, server logs, IP address.
03Why, and on what basis
We process health and measurement data solely on your explicit consent; withdraw it anytime by deleting measurements or your account, without affecting the lawfulness of earlier processing.
- Providing the Service (account, workouts, plans, sync): performance of a contract, Art. 6(1)(b) GDPR.
- Health and measurements: your explicit consent, Art. 9(2)(a) GDPR.
- Strava integration: your consent, Art. 6(1)(a) GDPR.
- Security and abuse prevention: our legitimate interest, Art. 6(1)(f) GDPR.
- Account-related email (password reset, address verification): performance of a contract, Art. 6(1)(b) GDPR.
04Who we share data with
- Our server (VPS) hosting provider running the backend.
- Cloudflare: network layer and traffic protection.
- Apple (App Store) and Google (Google Play): App distribution.
- Strava: only once you connect your account.
- A transactional email provider.
- Bugsink: crash reporting (EU-based infrastructure, reports contain no health data or email).
05Data outside the EEA
Some providers (including Apple, Google, Cloudflare) may process data outside the European Economic Area, relying on GDPR transfer mechanisms (Standard Contractual Clauses or an adequacy decision).
06How long we keep data
For as long as you have an account. After deletion, we delete or anonymise it, except what we must retain by law (e.g. accounting obligations) or to pursue claims, for the period the law requires.
An account unused for 12 consecutive months is deleted automatically along with all its data — permanently and irreversibly. We warn you by email 30 days and 7 days before the deadline; signing in before it restarts the period. See the Terms for details.
07Your rights
You can access your data and get a copy, rectify it, erase it (delete your account yourself in the App: Profile → “Delete account”), restrict processing, object, port your data, and withdraw consent anytime. You can also complain to the Polish supervisory authority (President of the Personal Data Protection Office, UODO, ul. Stawki 2, 00-193 Warsaw).
08Age of users
The Service is for people aged 16 and over. If we learn that data of someone younger has reached us, we'll delete it.
09Changes to this Policy
We'll notify you of material changes to this Policy in the App or by email. The latest-update date is at the top of this document.