Calisty collects only what it needs to run your training plan. It never sells your data and never shows ads. This page explains what is collected, why, for how long, and what your rights are.
Last updated: 10 September 2026
Article 1
Who is responsible for your data
In shortCalisty is published by [Registered company name], a company established in Belgium. It is the data controller.
Calisty (the Android app and the website calisty.app) is published by [Registered company name], whose registered office is at [Registered office address].
For the purposes of the General Data Protection Regulation (GDPR) and Belgian data protection law, [Registered company name] is the data controller. This means we decide what personal data is collected and why.
In shortThis policy applies to the Calisty Android app and to the calisty.app website.
This policy describes how we handle personal data in two places:
The website (calisty.app), which presents the app.
The Android app, which you install from Google Play.
It does not cover Google Play, Google Sign-In or any other Google service. Those are governed by Google’s own privacy policy.
Article 3
Data collected on the website
In shortThe website collects nothing about you. Only standard server logs exist, and they are kept by our hosting provider.
The website is a set of static pages. It has no account, no form, no analytics and no tracking pixel. It sets no cookies. Fonts are served from our own domain, so no request is made to Google when you open a page.
Our hosting provider keeps standard server logs: the address of the page requested, the date and time, a truncated IP address and the browser’s user-agent string. These logs are used only to keep the site running and to detect abuse. They are deleted automatically according to the provider’s retention schedule.
In shortThe app stores your account, your training history and basic device information. Nothing else.
The Android app processes three categories of data:
Account data. Your email address and a password, which we store only in hashed form. If you sign in with Google, we receive your email address and a Google account identifier, and nothing else from your Google account.
Training data. The goal you chose, where you train, the exercises you have completed, your hold times and repetition counts, and the dates of your sessions. This is what the app uses to build your next session.
Technical data. The app version, the Android version, the device model, and crash reports when the app fails. This helps us identify and fix bugs.
We do not collect your name, date of birth, location, contacts or photos. The app does not access any health platform, does not read your step count and does not connect to a wearable device.
Article 5
Why we process your data
In shortWe process your data to provide the service (contract), to keep the app working (legitimate interest) and, for anything optional, with your consent.
Under the GDPR, every processing operation needs a legal basis. Ours are:
Performance of a contract (Article 6(1)(b) GDPR) for your account and training data. Without them, the app cannot provide the service you signed up for.
Legitimate interest (Article 6(1)(f) GDPR) for technical data and crash reports. Our interest is to provide an app that works reliably, and we believe this interest is shared by our users.
Consent (Article 6(1)(a) GDPR) for anything optional, such as product news by email. You can withdraw your consent at any time from the app settings.
Article 6
Who has access to your data
In shortWe never sell your data and never share it with advertisers. A small number of service providers process it on our behalf.
We do not sell personal data, do not share it with advertisers and do not display advertising in the app.
The following service providers (processors) handle data on our behalf, under contracts that limit them to our instructions:
Our hosting and database provider, which stores account and training data on servers located in the European Union.
Google (Google Play and Google Sign-In), which handles app distribution, sign-in with a Google account, and payments. We never see your payment details.
Our crash reporting provider, which receives the technical data described in Article 4.
We may also disclose data where the law requires it, for example in response to a valid request from a public authority. Where permitted, we will inform you.
Article 7
How long we keep your data
In shortYour data is kept while your account is open. After deletion, it is erased within 30 days.
We apply the following retention periods:
Account and training data: for as long as your account is open. When you delete your account, this data is erased within 30 days.
Crash reports: 90 days.
Backups: overwritten within 35 days.
Records we are legally required to keep (for example invoices): for the period required by law.
Article 8
Where your data is stored
In shortYour data is stored in the European Union.
Account and training data are stored on servers located in the European Union.
Some of our service providers, in particular Google, may process data outside the European Economic Area. Any such transfer is covered by the safeguards provided for by the GDPR, such as the European Commission’s standard contractual clauses or an adequacy decision.
Article 9
Your rights
In shortYou can access, correct, delete or export your data, and object to its processing. Just email us. We reply within 30 days.
Under the GDPR, you have the right to:
Access your personal data and obtain a copy of it.
Rectify data that is inaccurate or incomplete.
Erase your data (“right to be forgotten”).
Restrict the processing of your data in certain cases.
Receive your data in a portable format (data portability).
Object to processing based on our legitimate interest.
Withdraw your consent at any time, where processing is based on consent.
To exercise any of these rights, email privacy@calisty.app. We will respond within 30 days. Exercising your rights is free of charge and you do not need to give a reason. You can also delete your account directly from the app settings.
If you believe we have not handled your data correctly, please contact us first so we can put it right. You also have the right to lodge a complaint with the Belgian supervisory authority, the Data Protection Authority (APD/GBA), or with the supervisory authority of the country where you live.
Article 10
Children
In shortYou must be at least 16 years old to use Calisty.
Calisty is not intended for children. You must be at least 16 years old to create an account. We do not knowingly collect data from anyone younger.
If you believe a child has created an account, contact us at privacy@calisty.app and we will delete it.
Article 11
Security
In shortWe protect your data with appropriate technical and organisational measures.
We take reasonable technical and organisational measures to protect your data against loss, unauthorised access and misuse. Passwords are stored only in hashed form, data travels over encrypted connections, and access to production systems is restricted.
No system is perfectly secure. If a data breach affects you, we will inform you and the supervisory authority as required by the GDPR.
Article 12
Changes to this policy
In shortWe will notify you in the app before any significant change takes effect.
We may update this policy from time to time. If a change affects you significantly, we will notify you in the app before it takes effect. The date at the top of this page always shows when the current version came into force.
For any question about this policy or about your personal data, write to privacy@calisty.app or by post to [Registered company name], [Registered office address].