Privacy Policy
Last updated: 2026-08-13
This Privacy Policy explains what personal data Arrow Lab collects, why we collect it, who we share it with, and how you can exercise your rights under the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
This policy applies to the Arrow Lab mobile app (Android, iOS) and the Arrow Lab backend reachable at https://api.arrowlab.pott.dev.
1. Controller
Controller in the sense of Art. 4 (7) GDPR and § 18 (2) MStV:
Johannes Ptaszyk
Gladbecker Str. 291
46240 Bottrop, Germany
E-Mail: contact@pott.dev
There is no statutory data protection officer — the controller's role is below the threshold of § 38 (1) BDSG. For all privacy-related questions, contact the address above.
2. What data we process
| Category | What is included | Source | |---|---|---| | Account data | E-mail, display name | Identity provider (Zitadel Cloud) when you sign in | | Training data | Training sessions, scores, bows, sight marks, equipment notes, weather readings you record | Data you enter in the app | | Billing data | App Store / Google Play purchase receipts, Pro subscription state, expiry | Apple App Store / Google Play (via RevenueCat) | | Telemetry | Crash reports, performance traces, error breadcrumbs | Generated automatically by the app and backend | | Push tokens | Firebase Cloud Messaging registration token | Issued by Firebase on first app launch | | Device locale + region | Language code, country code | Operating system, when the app starts | | Approximate location | Latitude / longitude, truncated to 4 decimals (about 11 m precision) | Only when you tap "Fetch weather automatically" | | Server logs | IP address, request path, timestamp, user agent | Generated automatically when the app talks to the backend | | Backend telemetry | Request traces, performance metrics, application logs | Generated automatically by the backend; secrets and personal data are stripped before the payload leaves our server | | Anonymous usage analytics | Screen views, live-user count, OS / app version / language, feature events | Only if you enable Analytics in the consent screen. Carries no identifier of any kind, so it cannot be linked back to you | | Data shared with clubs and coaches | Whatever categories you explicitly grant, e.g. training sessions, scores, personal bests | Only on an access grant you create yourself (see section 13) |
We do not process special categories of personal data (Art. 9 GDPR — health, biometric, religion, political opinion).
Is providing this data required? Account data and the training data you enter are needed to perform the contract: without them we cannot provide an account or sync. You are not legally obliged to provide them, but the Service cannot be used without an account. Everything marked as consent-based in section 3 — analytics, enhanced logging, weather, push, sharing with clubs and coaches — is entirely voluntary, and declining it has no consequence beyond that feature not working.
Automated decision-making. We do not use automated decision-making producing legal effects concerning you or similarly significantly affecting you (Art. 22 GDPR), and we do not profile you. The statistics the app shows you are calculated from your own entries and have no legal effect.
3. Why we process it — purposes and legal bases
| Purpose | Legal basis | Notes | |---|---|---| | Provide the core training-log functionality (signup, sync, account) | Art. 6 (1) lit. b GDPR (contract) | Without this we cannot deliver the service you signed up for | | Process Pro subscription payments and entitlements | Art. 6 (1) lit. b GDPR (contract) | Receipts flow through Apple / Google → RevenueCat → us | | Detect crashes and operational errors | Art. 6 (1) lit. f GDPR (legitimate interest) | Our interest in a stable service outweighs the minimal data attached to error reports; no identifiers are sent unless you opt in to enhanced logging | | Send transactional push notifications (training reminders, sync events) | Art. 6 (1) lit. a GDPR (consent) | You can revoke notification permission in the OS settings at any time | | Fetch weather data for a training session | Art. 6 (1) lit. a GDPR (consent) | Only fires when you actively tap "Fetch automatically" | | Optional anonymous usage analytics and enhanced error logging | Art. 6 (1) lit. a GDPR (consent) | Toggleable in the in-app Cookie settings screen; default is off | | Share training data with a club or coach you granted access to | Art. 6 (1) lit. a GDPR (consent) | Only the categories you selected, only for as long as the grant lasts — see section 13 | | Operate the backend reliably (traces, metrics, application logs) | Art. 6 (1) lit. f GDPR (legitimate interest) | Our interest in an operable service; payloads are stripped of secrets and personal data before leaving our server | | Keep the service secure: server access logs, defence against attacks and abuse, troubleshooting | Art. 6 (1) lit. f GDPR (legitimate interest) | Our interest in the integrity and availability of the backend and in the security of your data. Logs are kept only as long as needed for that purpose (section 6) and are not used to build a profile of you | | Comply with statutory bookkeeping obligations on billing data | Art. 6 (1) lit. c GDPR (legal obligation) | § 257 HGB and § 147 AO require 10-year retention of invoice data |
4. Processors and recipients
4.1 Processors (Art. 28 GDPR)
These providers process data only on our instructions. A Data Processing Agreement is in place with each of them.
| Processor | Location | Purpose | |---|---|---| | Zitadel Cloud (CAOS AG) | Switzerland (Zurich) | Identity provider — sign-in, e-mail + display name | | RevenueCat Inc. | USA (California) | Subscription management — maps Apple/Google receipts to your account | | Google LLC (Firebase Cloud Messaging) | USA / Ireland | Delivery of push notifications to your device | | Functional Software, Inc. (Sentry) | EU region (Frankfurt) | Client crash reporting, EU data residency | | Grafana Labs | EU (Frankfurt) | Backend telemetry — traces, metrics and application logs from our server | | Aptabase | Germany | Anonymous usage analytics — only if you enable Analytics; receives no identifier | | Hetzner Online GmbH | Germany (Nuremberg) | Virtual server hosting, the PostgreSQL database that stores your training data, and encrypted object storage backups |
4.2 Independent controllers
The following parties are not our processors. They decide on their own purposes and means, are responsible for that processing themselves, and their own privacy policies apply to it. We have no control over it and cannot answer data-subject requests on their behalf.
| Party | Role | Their privacy policy | |---|---|---| | Apple Inc. | App Store distribution, in-app purchase and payment processing as seller | https://www.apple.com/legal/privacy/ | | Google Ireland Ltd. / Google LLC | Google Play distribution, Google Play Billing as seller | https://policies.google.com/privacy | | Clubs and coaches you grant access to | Whatever they do with the data outside Arrow Lab (see section 13) | Provided by them |
4.3 Not a personal-data transfer
The MET Norway weather request is neither an Art. 28 processor relationship nor a transfer of personal data: no personal identifier is sent — only an opaque 4-decimal latitude/longitude pair and a generic User-Agent. MET Norway cannot link the request to your account or device.
5. Third-country transfers
Some processors are located outside the European Economic Area:
- Switzerland (Zitadel Cloud) — the European Commission has recognised Switzerland as providing an adequate level of data protection (Art. 45 GDPR).
- United States (RevenueCat, Apple, Google) — transfers rely on the EU-U.S. Data Privacy Framework (Art. 45 GDPR adequacy decision of 2023-07-10) where the recipient is certified, or on Standard Contractual Clauses (SCCs) under Art. 46 (2) lit. c GDPR as a fallback.
- Grafana Labs is a US-incorporated company, but the stack we use is hosted in the EU (Frankfurt) and the data stays there. The same DPF / SCC safeguards as above cover any access from the parent company.
You can request a copy of the SCCs by writing to the controller address in section 1.
6. How long we store data
| Data | Retention | |---|---| | Account, training data, bows, sight marks | Until you delete your account, plus a 30-day grace period during which you can restore by signing back in | | Backups containing the above | Grace period + an additional 30 days in encrypted backups on Hetzner Object Storage | | Billing receipts (invoice data) | 10 years as required by § 257 HGB and § 147 AO | | Crash and error reports | 90 days rolling window | | Server access logs, traces and metrics | Up to 30 days for logs and traces; aggregated metrics that contain no personal data are kept longer | | Anonymous usage analytics | Kept as aggregate counts. Carries no identifier, so there is nothing that could be traced back to you or deleted individually | | Push tokens | Refreshed on each app start; deleted when you revoke notification permission, and pruned once the platform reports the token as no longer deliverable (for example after you uninstall) | | Weather readings linked to a training session | Same lifetime as the parent training |
7. Your rights
Under Articles 15–22 GDPR you have the following rights. To exercise any of them, write to contact@pott.dev or use the in-app paths noted below. We respond within one month (Art. 12 (3) GDPR).
- Right of access (Art. 15) — request a copy of your data. In-app: Profile → Export account data.
- Right to rectification (Art. 16) — correct inaccurate data. In-app: Profile → Edit display name; for other fields write to us.
- Right to erasure (Art. 17) — In-app: Profile → Delete account (typed e-mail confirmation).
- Right to restriction (Art. 18) — limit processing while a dispute is open.
- Right to data portability (Art. 20) — receive your data in a machine-readable format (JSON). In-app: Profile → Export.
- Right to object (Art. 21) — object to processing based on legitimate interest. In-app: revoke consent via Profile → Cookie settings, or write to us.
- Right to withdraw consent (Art. 7 (3)) — for any consent-based processing. In-app: Profile → Cookie settings. Withdrawal does not affect the lawfulness of processing before the withdrawal.
- Right to lodge a complaint with a supervisory authority (Art. 77) — the competent authority for the controller is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestraße 2–4
40213 Düsseldorf, Germany
poststelle@ldi.nrw.de
Your right to object — please read
You have the right to object at any time, on grounds relating to your particular situation, to processing of your personal data based on Art. 6 (1) lit. f GDPR (legitimate interest). That covers crash and error detection, backend telemetry, and our security and access logs.
If you object, we will stop processing your data for those purposes unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
An objection is informal and free of charge. Send it to contact@pott.dev.
8. Consent management and device storage
The app shows a consent dialog on first launch and after any material change to this policy. You can re-open it any time at Profile → Cookie settings.
Where a service stores information on your device or accesses information already stored there, that requires your consent under § 25 (1) TDDDG — unless the storage or access is strictly necessary to provide the service you expressly requested (§ 25 (2) no. 2 TDDDG). We rely on that exception only for the categories marked as required below. Consent given under § 25 TDDDG also serves as consent under Art. 6 (1) lit. a GDPR for the subsequent processing of that data.
Services are grouped into three categories:
- Required — strictly necessary to deliver the app itself: the local storage of your account session and your training data on the device, and the baseline crash capture without which we cannot keep the app usable. Registering for push messaging happens only after you grant the notification permission at operating-system level; if you do not, the app runs without it.
- Analytics — anonymous usage analytics. Default: off.
- Functional — enhanced error logging with additional diagnostic context. Default: off.
The current list of services in each category is shown in the consent dialog itself. Each toggle takes effect immediately, and withdrawing consent is as easy as giving it: the same screen, one tap.
9. Push notifications
If you grant notification permission at the OS level, we send transactional pushes via Firebase Cloud Messaging (Android) and Apple Push Notification service (iOS). Examples:
- Scheduled training reminders you opted into
- Sync events when changes from another device need attention
We do not use push for marketing. You can revoke notification permission at any time in your device settings; the app continues to work without push.
10. Cookies and tracking
The Arrow Lab mobile app does not use cookies — it is a native app. § 25 TDDDG is not limited to cookies, though: it covers any storage of or access to information on your device. The SDK toggles described in section 8 are therefore the mechanism through which you control that, and "Cookie settings" is simply the name the screen carries in the app.
The backend does not set any cookies for the app either. It uses bearer tokens issued by Zitadel in the Authorization header. The /admin backoffice, which only we use, sets a session cookie that is strictly necessary for logging in.
11. Security
- TLS 1.3 for every connection between the app and the backend, and between the backend and every processor.
- Bearer tokens are time-limited and rotated on every refresh.
- Database backups are encrypted at rest with SSE-C (server-side encryption with customer-supplied keys); the encryption key never leaves our infrastructure.
- Passwords are not handled by us — authentication is delegated to Zitadel.
12. Minors
Germany has not lowered the age limit in Art. 8 (1) GDPR, so consent to an information-society service is valid from the age of 16 here. If you are under 16, any processing we base on consent — analytics, enhanced logging, weather, push, sharing with a club or coach — requires the consent of the holder of parental responsibility, and the contract itself requires their agreement (section 3 of our Terms).
Arrow Lab is not directed at children under 13 and we do not knowingly allow them to register. If you become aware that a child has provided us with personal data without the required consent, contact us and we will delete it.
Club and coaching features mean youth squads are foreseeable. Where a minor is involved, an access grant to a coach or club should be made by, or with the agreement of, the holder of parental responsibility.
13. Sharing with clubs and coaches
Arrow Lab lets you connect with a club or a coach. Nothing is shared by default — every share is an access grant you create yourself, scoped to the data categories you pick.
- You choose which categories a coach or club can see. Categories you do not grant stay invisible to them.
- You can withdraw a grant at any time in the app. Withdrawal stops all further access; it does not undo what the recipient legitimately saw while the grant was active.
- Leaderboards inside a club show the personal bests of the members who joined that leaderboard. Leaving the club removes you from it.
- Coaches and club administrators are separate controllers for anything they record about you outside Arrow Lab. Within Arrow Lab, we remain the controller.
- Deleting your account withdraws every grant you issued.
14. Changes to this policy
We may update this policy as the app and its processors evolve. The version number at the top of the in-app screen increments on every material change. When that happens, the app re-opens the consent dialog on next launch so you can review the new version before continuing.
The version number shown at the top of the in-app privacy screen is the authoritative one; this document was last updated on 2026-08-13.