Legal
Privacy Policy
How WODIQ handles workout, activity, analytics, and app usage data.
Overview
WODIQ is a workout planning app. It helps you choose a training type, configure the session, generate a workout, save picked workouts, and optionally use connected training data.
This policy explains what data is used, why it is used, the legal bases WODIQ relies on, and what choices and rights you have.
Controller and contact
WODIQ is operated by Tuinstra.DEV in Dronten, Netherlands. For privacy questions, access requests, deletion requests, or other data protection requests, contact marcel@tuinstra.dev.
WODIQ is a product of Tuinstra.DEV. This page will be updated if the responsible controller details change.
Data we process
Account and session data: WODIQ may create an anonymous device session so the app can remember picked workouts, feedback, preferences, and usage limits. If you later link Apple or Google sign-in, account identifiers may be linked to the same app user.
Workout data: selected sport, duration preference, warm-up and cooldown choices, goal text and parsed goal details, optional guidance notes, generated workout content, picked workouts, public share links, execution notes, coach-style reviews, and workout feedback.
Manual log data: if supported in your build, WODIQ may process text or an optional training-log image you submit and create structured activity context from completed training. Review extracted fields before saving.
Connected provider data: if you connect Garmin or another enabled provider, WODIQ may sync recent activities and related training context such as activity type, duration, distance, heart-rate summaries, recovery, sleep, stress, HRV, or similar metrics when available from the provider.
Apple Health data: in the native iOS app, WODIQ can import workout summaries after you grant Apple Health read permission. WODIQ imports normalized workout fields such as type, date, duration, distance, calories, and heart-rate summaries when available.
AI content reports: if you report AI-generated content in the app, WODIQ stores the content reference, content type, reason, source surface, locale, status, timestamps, user or session ownership, and any optional capped note you submit.
Diagnostics and product events: WODIQ may collect technical diagnostics and first-party product events such as errors, app version, device/platform information, sync status, usage/access events, deletion-request status, and AI-report status. Product events use an allowlist and minimal metadata.
Legal bases and purposes
WODIQ processes app and session data to provide the app experience, remember selected workouts, enforce usage limits, and keep your training history available. The legal basis is performance of the service you request or WODIQ’s legitimate interest in operating the app.
WODIQ processes connected provider and Apple Health data only after you choose to connect that source or grant the relevant platform permission. The legal basis is your consent and the service request you make by connecting the provider.
WODIQ processes goal text, optional notes, coach-review inputs, execution notes, and optional training-log images only to provide the app features you request, such as goal parsing, workout generation, manual activity logging, or coach-style review.
WODIQ processes AI content reports so support can review reported generated workouts, reviews, or manual analysis results and limit abuse of the reporting flow.
WODIQ processes diagnostics and security logs based on legitimate interests in reliability, abuse prevention, and service security.
WODIQ processes website analytics only after you consent to analytics cookies or similar storage on wodiq.nl. You can reject analytics and still use the website.
AI workout generation
WODIQ may send structured workout context to an AI provider to parse goals, generate workouts, analyze supported manual training logs, or create coach-style reviews. This context can include selected workout settings, goal text, optional guidance notes, execution notes, optional training-log images, and normalized training summaries when those are needed for the requested output.
Raw provider payloads should not be sent directly to the AI provider; WODIQ uses normalized summaries and app context. Optional guidance notes that you type into the app may be included because they are part of the workout instructions.
If you report AI-generated content, the report stores a content reference and reason rather than the full generated content, prompt, raw provider payload, cookies, session token, or full health record. Optional report notes are capped and should not contain sensitive details.
Do not submit sensitive medical information, secrets, or information you do not have permission to use. WODIQ uses AI output for training guidance only, not for medical advice.
Providers and integrations
Garmin is optional and available where configured. You can use WODIQ without connecting Garmin or another provider. If you connect Garmin, WODIQ uses the connection only for provider sync and workout context.
Provider credentials, tokens, and access data are sensitive. WODIQ uses them only to create or maintain the provider connection, stores provider access data with encryption where supported, and does not use them for marketing, website analytics, screenshots, or advertising.
Sign in with Apple and Apple Health are separate permissions. Apple login identifies your WODIQ account; Apple Health permission is requested locally on your iPhone before workouts are imported. WODIQ reads workout-related HealthKit data only and does not write to Apple Health in this release.
Provider accounts and platform permissions are also governed by the terms and privacy notices of the relevant provider or platform. Disconnecting a provider stops future sync where supported and removes associated imported provider data from WODIQ where the app supports removal.
Cookies and website analytics
The WODIQ marketing website uses necessary local storage to remember cookie preferences. This storage is required to respect your choice and does not require analytics consent.
WODIQ loads Google Analytics 4 on wodiq.nl only after you accept analytics cookies. Analytics helps understand aggregate website traffic, page usage, language choice, and TestFlight or web-app CTA clicks.
Google Analytics may process technical information such as page URL, referrer, approximate location, device/browser information, and interaction events. WODIQ configures IP anonymization where supported. CTA analytics events must not include free-text notes, workout prompts, health data, provider payloads, or sensitive app content. You can reject analytics in the cookie banner or reopen cookie preferences later.
The WODIQ app does not currently use third-party product analytics, fingerprinting, ad pixels, or cross-site tracking identifiers.
Sharing and recipients
If you create a share link, the workout linked to that URL can be viewed by anyone with the link. Treat share links as public URLs and do not create or share a link for a workout you want to keep private. Shared workout pages should not include your personal coach review.
WODIQ may use service providers for hosting, analytics after consent, diagnostics, provider sync, app-store handling, payment processing only if paid plans are later active, and AI generation. These providers process data only for the relevant service purpose.
International transfers
Some providers used for hosting, analytics, diagnostics, or AI generation may process data outside the European Economic Area. Where required, WODIQ relies on appropriate safeguards such as data processing agreements, standard contractual clauses, or provider transfer mechanisms.
WODIQ aims to minimize the data sent to external providers and to avoid sending raw connected-provider payloads to AI providers.
Retention and deletion
WODIQ keeps app data for as long as needed to provide the app experience, maintain workout history, operate the service, handle deletion or support requests, and meet security or legal obligations.
In Settings, WODIQ v1 offers an account and data deletion request flow. This records a request that support can review for the current account or anonymous device session; it is not an instant hard delete.
A deletion request covers the account or device session, app sessions, provider connections, imported activities, generated workouts, reviews, goals, and training context. Some records may be retained only where needed for legal, audit, fraud-prevention, or billing-evidence reasons.
Workout history, generated workouts, provider imports, and account-linked data are kept until they are removed in the app, disconnected where supported, or a deletion request is processed. Diagnostics, product events, AI content reports, and operational logs are kept only for the period needed for reliability, security, abuse prevention, support, or the limited evidence purposes above.
Backup copies may retain deleted data for up to 90 days before they expire through the normal backup cycle. Backups are isolated from normal product access; if disaster recovery restores an older copy, verified deletion requests must be reapplied. Shared links may remain available until the linked workout is removed or the link is otherwise disabled.
Your rights
Depending on your location and the data involved, you may have the right to access, correct, delete, restrict, object to, or receive a portable copy of your personal data. You may also withdraw consent where processing is based on consent.
To exercise these rights, contact marcel@tuinstra.dev. WODIQ may need to verify that the request relates to your account or device session before acting on it.
If you are in the European Union or the Netherlands and believe your request was not handled properly, you can lodge a complaint with your local data protection authority, including the Dutch Autoriteit Persoonsgegevens.
Changes
WODIQ may update this policy when the product, providers, analytics setup, or legal requirements change. Material changes will be reflected by updating the date on this page and, where appropriate, by additional notice in the app or website.
Contact
For privacy questions or deletion requests, contact marcel@tuinstra.dev.