Privacy policy

Privacy policy for Troyan Studio — combat sports gym in Kraków (Wrocławska 41).

Last updated: 31 August 2026.

1. Who is responsible for your data

The data controller is Troian Oleksandr, ul. Wrocławska 41, 30-011 Kraków, Poland, NIP 6772491171, REGON 524548956.

All data protection matters are handled at [email protected].

This policy covers the Troyan Studio app (app.troyan.studio and the iOS and Android builds) and the troyan.studio website.

2. What we collect

We collect only what the app needs to work.

  • Account: email address, display name, interface language, role in the studio, account status, and the dates your address was confirmed and you last signed in. If you sign in with a password, we store only its irreversible hash — never the password itself.
  • Google or Apple sign-in: the identifier issued by the provider, plus the email address and name the provider passes to us; if you use Apple’s hidden relay address, that is the address we store. We keep an encrypted Apple token for one purpose only: to revoke the app’s access when you delete your account.
  • Athlete or coach profile: display name, and — if you provide them — email, phone, Telegram handle and Instagram handle.
  • Telegram: only if you connect our bot yourself — your Telegram user and chat identifiers, the version and date of your consent, the dates of the last exchange and delivery, and your language.
  • Sign-in sessions: one row per active sign-in — a coarse platform bucket (browser, iOS, Android), timestamps, and a hash of the refresh token. We do not record your IP address, we do not record browser details, and we do not build a device fingerprint.
  • Security event log: sign-ins, password and address changes, and additional identity confirmations — the fact of the event, its outcome, and the coarse client type.
  • Training data: memberships, sessions used, group class sign-ups, personal training and membership requests, movements of your session balance, and in-app notifications.
  • Operations log: a record of who changed the state of a membership, a balance or the schedule, and when. By design this log rejects fields that carry personal data — validation enforces it — so addresses, phone numbers and names never reach it.
  • Error diagnostics: when the app hits an error or stops responding, we send a technical report — the error message, the code trace, the app version, the platform and the release channel.
  • On your device: the app stores your sign-in session and view settings locally. That data stays on the device.
  • Running your account, the schedule, memberships, in-app notifications and account emails — Art. 6(1)(b) GDPR, performance of a contract.
  • Protecting accounts from takeover: the security event log and refresh-token reuse detection — Art. 6(1)(f) GDPR, our legitimate interest.
  • Error and crash diagnostics, so the app keeps working — Art. 6(1)(f) GDPR.
  • Telegram notifications — Art. 6(1)(a) GDPR, your consent; you can withdraw it at any time by disconnecting the bot.
  • The settlement records that remain after account deletion (section 7) — Art. 6(1)(f) read with Art. 17(3)(e) GDPR, establishment and defence of legal claims.

4. What we do not do

  • We show no advertising and use no ad networks.
  • We do not track you across other companies’ apps or websites and we pass nothing to data brokers — which is why the app never asks for tracking permission.
  • We run no traffic analytics: no Google Analytics, none of the alternatives.
  • We do not record what you do on screen.
  • Fonts are served from our own server, so no third-party font provider sees your visits.
  • We collect no location, photos, contacts, calendar or microphone data, and no health or training measurements.
  • We take no payments in the app: we hold no card or bank details. Prices are information only; settlement happens outside the app.
  • We pass nothing to artificial intelligence services, and we do not sell data.

5. Who processes data for us

We use only the providers the service needs to run:

  • Hetzner (Germany) — servers and database.
  • Brevo (France) — sending account emails: address confirmation, password reset, invitations, and the account deletion notice.
  • Sentry (USA) — error and crash diagnostics.
  • Cloudflare (USA) — domain names and traffic to our sites.
  • Telegram — only for people who connected the bot.
  • Google and Apple — only at the moment you sign in with them.

Sentry and Cloudflare operate outside the European Economic Area; those transfers rely on the European Commission’s standard contractual clauses as applied by those providers.

6. How long we keep data

  • Account and profile — for as long as the account exists.
  • Sign-in sessions — they expire after 30 days of disuse and after 90 days at the latest; the database clears expired rows itself.
  • One-time links (address confirmation, password reset, address change, invitations) — from tens of minutes to a few hours, then removed automatically.
  • Security event log — 24 months.
  • Training data and memberships — for as long as the account exists; after deletion only the records described in section 7 remain.
  • Error reports — for the standard retention period Sentry applies.

7. Deleting your account, and what remains

You delete the account yourself: Settings → Delete account. Deletion happens immediately, with no grace period. You can also write to [email protected].

We then delete:

  • the account and sign-in data, including the password hash;
  • the links to Google, Apple and Telegram — for Apple we also revoke the app’s access on Apple’s side;
  • the athlete or coach profile;
  • memberships, sessions used, and profile access grants;
  • in-app notifications;
  • every sign-in session and any unused one-time links.

Four kinds of record do not disappear entirely: command receipts, the operations log, session balance movements, and the security event log. In each of them we replace your identifiers with irreversible tombstones, so no such record can be traced back to who it was about. What remains is the history of numbers and states alone: how many sessions were settled, and when. We keep it so that membership settlements can be checked later and defended in a dispute.

8. Your rights

You have the right to:

  • access your data and receive a copy of it;
  • have inaccurate data corrected;
  • have your data erased;
  • restrict processing;
  • port your data to another controller;
  • object to processing based on our legitimate interest;
  • withdraw your consent to Telegram notifications.

We provide a copy of your data on request sent to [email protected] — there is no data download button in the app yet. We answer every request within one month.

If you believe we process your data unlawfully, you may lodge a complaint with the President of the Personal Data Protection Office in Poland (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa).

9. Children

Children train at the studio, and a child can have an account of their own. A guardian can be given access to the child’s profile — in the data that is a separate record marked as guardian access, and today a studio administrator grants it. We do not ask for a date of birth and store one nowhere, so age is not recorded in the data. We direct no advertising at children and collect nothing about them beyond what signing up for training requires.

10. Security

Traffic between the app and the server is encrypted. Passwords are stored only as an irreversible hash, and the Apple token is encrypted. Sessions expire, and every refresh rotates the token: using an old token invalidates the whole session family it came from. Error reports deliberately carry no cookies, no URL parameters, no request bodies and no variables from program memory.

11. Changes to this policy

The date of the last change is shown at the top of this page. We will announce material changes in the app or by email.

12. Contact

Questions, requests and complaints about personal data: [email protected]. We answer within one month.