Privacy Policy

Last updated: 2026-08-13

This Privacy Policy explains what personal data Arrow Lab collects, why we collect it, who we share it with, and how you can exercise your rights under the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

This policy applies to the Arrow Lab mobile app (Android, iOS) and the Arrow Lab backend reachable at https://api.arrowlab.pott.dev.

1. Controller

Controller in the sense of Art. 4 (7) GDPR and § 18 (2) MStV:

Johannes Ptaszyk
Gladbecker Str. 291
46240 Bottrop, Germany
E-Mail: contact@pott.dev

There is no statutory data protection officer — the controller's role is below the threshold of § 38 (1) BDSG. For all privacy-related questions, contact the address above.

2. What data we process

| Category | What is included | Source | |---|---|---| | Account data | E-mail, display name | Identity provider (Zitadel Cloud) when you sign in | | Training data | Training sessions, scores, bows, sight marks, equipment notes, weather readings you record | Data you enter in the app | | Billing data | App Store / Google Play purchase receipts, Pro subscription state, expiry | Apple App Store / Google Play (via RevenueCat) | | Telemetry | Crash reports, performance traces, error breadcrumbs | Generated automatically by the app and backend | | Push tokens | Firebase Cloud Messaging registration token | Issued by Firebase on first app launch | | Device locale + region | Language code, country code | Operating system, when the app starts | | Approximate location | Latitude / longitude, truncated to 4 decimals (about 11 m precision) | Only when you tap "Fetch weather automatically" | | Server logs | IP address, request path, timestamp, user agent | Generated automatically when the app talks to the backend | | Backend telemetry | Request traces, performance metrics, application logs | Generated automatically by the backend; secrets and personal data are stripped before the payload leaves our server | | Anonymous usage analytics | Screen views, live-user count, OS / app version / language, feature events | Only if you enable Analytics in the consent screen. Carries no identifier of any kind, so it cannot be linked back to you | | Data shared with clubs and coaches | Whatever categories you explicitly grant, e.g. training sessions, scores, personal bests | Only on an access grant you create yourself (see section 13) |

We do not process special categories of personal data (Art. 9 GDPR — health, biometric, religion, political opinion).

Is providing this data required? Account data and the training data you enter are needed to perform the contract: without them we cannot provide an account or sync. You are not legally obliged to provide them, but the Service cannot be used without an account. Everything marked as consent-based in section 3 — analytics, enhanced logging, weather, push, sharing with clubs and coaches — is entirely voluntary, and declining it has no consequence beyond that feature not working.

Automated decision-making. We do not use automated decision-making producing legal effects concerning you or similarly significantly affecting you (Art. 22 GDPR), and we do not profile you. The statistics the app shows you are calculated from your own entries and have no legal effect.

3. Why we process it — purposes and legal bases

| Purpose | Legal basis | Notes | |---|---|---| | Provide the core training-log functionality (signup, sync, account) | Art. 6 (1) lit. b GDPR (contract) | Without this we cannot deliver the service you signed up for | | Process Pro subscription payments and entitlements | Art. 6 (1) lit. b GDPR (contract) | Receipts flow through Apple / Google → RevenueCat → us | | Detect crashes and operational errors | Art. 6 (1) lit. f GDPR (legitimate interest) | Our interest in a stable service outweighs the minimal data attached to error reports; no identifiers are sent unless you opt in to enhanced logging | | Send transactional push notifications (training reminders, sync events) | Art. 6 (1) lit. a GDPR (consent) | You can revoke notification permission in the OS settings at any time | | Fetch weather data for a training session | Art. 6 (1) lit. a GDPR (consent) | Only fires when you actively tap "Fetch automatically" | | Optional anonymous usage analytics and enhanced error logging | Art. 6 (1) lit. a GDPR (consent) | Toggleable in the in-app Cookie settings screen; default is off | | Share training data with a club or coach you granted access to | Art. 6 (1) lit. a GDPR (consent) | Only the categories you selected, only for as long as the grant lasts — see section 13 | | Operate the backend reliably (traces, metrics, application logs) | Art. 6 (1) lit. f GDPR (legitimate interest) | Our interest in an operable service; payloads are stripped of secrets and personal data before leaving our server | | Keep the service secure: server access logs, defence against attacks and abuse, troubleshooting | Art. 6 (1) lit. f GDPR (legitimate interest) | Our interest in the integrity and availability of the backend and in the security of your data. Logs are kept only as long as needed for that purpose (section 6) and are not used to build a profile of you | | Comply with statutory bookkeeping obligations on billing data | Art. 6 (1) lit. c GDPR (legal obligation) | § 257 HGB and § 147 AO require 10-year retention of invoice data |

4. Processors and recipients

4.1 Processors (Art. 28 GDPR)

These providers process data only on our instructions. A Data Processing Agreement is in place with each of them.

| Processor | Location | Purpose | |---|---|---| | Zitadel Cloud (CAOS AG) | Switzerland (Zurich) | Identity provider — sign-in, e-mail + display name | | RevenueCat Inc. | USA (California) | Subscription management — maps Apple/Google receipts to your account | | Google LLC (Firebase Cloud Messaging) | USA / Ireland | Delivery of push notifications to your device | | Functional Software, Inc. (Sentry) | EU region (Frankfurt) | Client crash reporting, EU data residency | | Grafana Labs | EU (Frankfurt) | Backend telemetry — traces, metrics and application logs from our server | | Aptabase | Germany | Anonymous usage analytics — only if you enable Analytics; receives no identifier | | Hetzner Online GmbH | Germany (Nuremberg) | Virtual server hosting, the PostgreSQL database that stores your training data, and encrypted object storage backups |

4.2 Independent controllers

The following parties are not our processors. They decide on their own purposes and means, are responsible for that processing themselves, and their own privacy policies apply to it. We have no control over it and cannot answer data-subject requests on their behalf.

| Party | Role | Their privacy policy | |---|---|---| | Apple Inc. | App Store distribution, in-app purchase and payment processing as seller | https://www.apple.com/legal/privacy/ | | Google Ireland Ltd. / Google LLC | Google Play distribution, Google Play Billing as seller | https://policies.google.com/privacy | | Clubs and coaches you grant access to | Whatever they do with the data outside Arrow Lab (see section 13) | Provided by them |

4.3 Not a personal-data transfer

The MET Norway weather request is neither an Art. 28 processor relationship nor a transfer of personal data: no personal identifier is sent — only an opaque 4-decimal latitude/longitude pair and a generic User-Agent. MET Norway cannot link the request to your account or device.

5. Third-country transfers

Some processors are located outside the European Economic Area:

You can request a copy of the SCCs by writing to the controller address in section 1.

6. How long we store data

| Data | Retention | |---|---| | Account, training data, bows, sight marks | Until you delete your account, plus a 30-day grace period during which you can restore by signing back in | | Backups containing the above | Grace period + an additional 30 days in encrypted backups on Hetzner Object Storage | | Billing receipts (invoice data) | 10 years as required by § 257 HGB and § 147 AO | | Crash and error reports | 90 days rolling window | | Server access logs, traces and metrics | Up to 30 days for logs and traces; aggregated metrics that contain no personal data are kept longer | | Anonymous usage analytics | Kept as aggregate counts. Carries no identifier, so there is nothing that could be traced back to you or deleted individually | | Push tokens | Refreshed on each app start; deleted when you revoke notification permission, and pruned once the platform reports the token as no longer deliverable (for example after you uninstall) | | Weather readings linked to a training session | Same lifetime as the parent training |

7. Your rights

Under Articles 15–22 GDPR you have the following rights. To exercise any of them, write to contact@pott.dev or use the in-app paths noted below. We respond within one month (Art. 12 (3) GDPR).

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestraße 2–4
40213 Düsseldorf, Germany
poststelle@ldi.nrw.de

Your right to object — please read

You have the right to object at any time, on grounds relating to your particular situation, to processing of your personal data based on Art. 6 (1) lit. f GDPR (legitimate interest). That covers crash and error detection, backend telemetry, and our security and access logs.

If you object, we will stop processing your data for those purposes unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.

An objection is informal and free of charge. Send it to contact@pott.dev.

8. Consent management and device storage

The app shows a consent dialog on first launch and after any material change to this policy. You can re-open it any time at Profile → Cookie settings.

Where a service stores information on your device or accesses information already stored there, that requires your consent under § 25 (1) TDDDG — unless the storage or access is strictly necessary to provide the service you expressly requested (§ 25 (2) no. 2 TDDDG). We rely on that exception only for the categories marked as required below. Consent given under § 25 TDDDG also serves as consent under Art. 6 (1) lit. a GDPR for the subsequent processing of that data.

Services are grouped into three categories:

The current list of services in each category is shown in the consent dialog itself. Each toggle takes effect immediately, and withdrawing consent is as easy as giving it: the same screen, one tap.

9. Push notifications

If you grant notification permission at the OS level, we send transactional pushes via Firebase Cloud Messaging (Android) and Apple Push Notification service (iOS). Examples:

We do not use push for marketing. You can revoke notification permission at any time in your device settings; the app continues to work without push.

10. Cookies and tracking

The Arrow Lab mobile app does not use cookies — it is a native app. § 25 TDDDG is not limited to cookies, though: it covers any storage of or access to information on your device. The SDK toggles described in section 8 are therefore the mechanism through which you control that, and "Cookie settings" is simply the name the screen carries in the app.

The backend does not set any cookies for the app either. It uses bearer tokens issued by Zitadel in the Authorization header. The /admin backoffice, which only we use, sets a session cookie that is strictly necessary for logging in.

11. Security

12. Minors

Germany has not lowered the age limit in Art. 8 (1) GDPR, so consent to an information-society service is valid from the age of 16 here. If you are under 16, any processing we base on consent — analytics, enhanced logging, weather, push, sharing with a club or coach — requires the consent of the holder of parental responsibility, and the contract itself requires their agreement (section 3 of our Terms).

Arrow Lab is not directed at children under 13 and we do not knowingly allow them to register. If you become aware that a child has provided us with personal data without the required consent, contact us and we will delete it.

Club and coaching features mean youth squads are foreseeable. Where a minor is involved, an access grant to a coach or club should be made by, or with the agreement of, the holder of parental responsibility.

13. Sharing with clubs and coaches

Arrow Lab lets you connect with a club or a coach. Nothing is shared by default — every share is an access grant you create yourself, scoped to the data categories you pick.

14. Changes to this policy

We may update this policy as the app and its processors evolve. The version number at the top of the in-app screen increments on every material change. When that happens, the app re-opens the consent dialog on next launch so you can review the new version before continuing.

The version number shown at the top of the in-app privacy screen is the authoritative one; this document was last updated on 2026-08-13.