Privacy first
Privacy
Clear information about which data stays local on your device and how export and import work.
1. Controller
,
Email:
2. Local app data
The core features of BALQ work locally on your device. This can include workout data, exercises, weights, reps, sets, daily notes, personal records, plans, body measurements, profile name, goal, profile photo, as well as language and design settings. This content is stored in your device's browser storage. The operator cannot see this local content.
Local storage is technically necessary to provide the tracker function you explicitly requested (Section 165(3) of the Austrian Telecommunications Act 2021, TKG 2021). To the extent the operator processes data in this context, this is done to provide the app (Art. 6(1)(b) GDPR).
Local data remains stored until you delete it in the app, clear the website/app storage in your browser, or uninstall the app.
3. Backup, export and import
With “Export Backup” you can create a portable JSON file. This file contains the app data stored on your device and may also include your profile photo, body measurements or other sensitive fitness information.
The export file is saved and transferred by you. BALQ does not automatically upload this file to a server. If you share it, store it online or copy it to another device, you are responsible for protecting it.
With “Import Backup” you can restore a BALQ backup file. Importing replaces the current local app data on this device.
4. Hosting and technical access data
The public website is currently provided via . When you access it, technically necessary connection data such as IP address, date and time, requested file, browser/device information and referrer may be processed. The purpose is the secure and reliable delivery of the app. The legal basis is our legitimate interest in operation, stability and security (Art. 6(1)(f) GDPR).
The retention period depends on the security and operational periods required by the hosting provider. Further information is available in the Netlify privacy policy. For transfers to third countries, the safeguards offered by the provider are used, in particular adequacy decisions or standard contractual clauses.
BALQ currently contains no advertising, marketing or audience analytics and does not create usage profiles.
5. Purchase and license validation via Lemon Squeezy
The one-time purchase is handled by Lemon Squeezy (Lemon Squeezy, LLC), which acts as Merchant of Record. For the order, payment, invoice, tax handling and delivery of the license key, Lemon Squeezy processes the data you enter at checkout in accordance with the privacy information provided there.
When you enter a license key in BALQ, the key and a technical device label are sent to the Lemon Squeezy License API. BALQ receives information about validity, product assignment and device activation. The purpose is to verify and permanently unlock your license. The legal basis is performance of a contract (Art. 6(1)(b) GDPR).
Premium status, license key and the technical instance ID are stored locally on your device. Workout data, plans, PRs, measurements, profile picture and settings are not transmitted to Lemon Squeezy. You can find more information in the Lemon Squeezy privacy policy.
6. Device storage, cookies and PWA cache
BALQ uses local browser storage for the app data and settings you explicitly enter. The service worker stores only app files for offline use. This storage is necessary for the requested functions. No tracking or advertising cookies are set; therefore, this version does not include a consent banner for marketing or analytics.
If analytics, advertising, accounts or other non-essential third-party services are added later, they must request appropriate consent before activation and this policy must be updated.
7. Deletion and your rights
You can delete your local data via “Settings → Backup & Restore → Delete Local Data”. You can also clear your browser's website/app storage or remove the PWA.
Under the GDPR you have, in particular, the rights of access, rectification, erasure, restriction, data portability and objection. You can also lodge a complaint with the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna.
8. Recipients, security and changes
Recipients are only the processors used for hosting and, where a legal obligation exists, public authorities. No automated decision-making, including profiling, takes place. Data is not sold.
Appropriate technical and organisational measures are used. Nevertheless, no internet-based service can guarantee absolute security. Do not share sensitive data that is not necessary for your training progress.
This policy will be updated if features, providers or legal bases change significantly.