Privacy Policy
1. Data Controller
BEHNARO ("we", "us", "our") is operated by Dominik Boryczko. If you have any questions about this Privacy Policy or our data practices, you can reach us at: dboryczko@gmail.com.
2. What Data We Collect
We collect the following categories of personal data:
- Account information — name, email address, profile photo, role (student or coach).
- Profile data — sport disciplines, certifications, hourly rates, city/location (optional).
- Usage data — app interactions, session logs, feature usage, device type, OS version.
- Health & fitness data — workout logs, goal progress, training plans (stored only on your device via Apple HealthKit unless you explicitly share).
- Payment data — processed securely by Stripe; we do not store card numbers.
- Communications — messages sent through in-app chat.
- Location data — approximate city (if provided by you); precise GPS only if you grant permission to find nearby coaches.
3. How We Use Your Data
- To provide and maintain the BEHNARO service.
- To match students with coaches based on location and preferences.
- To process bookings and payments.
- To generate AI training plans personalised to you.
- To send transactional notifications (booking confirmations, reminders).
- To improve app performance and fix bugs (anonymised analytics).
- To comply with legal obligations.
4. Legal Basis (GDPR)
For users in the European Economic Area, we rely on the following legal bases:
- Contract performance — to deliver the service you signed up for.
- Legitimate interests — to improve BEHNARO and prevent fraud.
- Consent — for marketing emails and optional location sharing (you may withdraw at any time).
- Legal obligation — where required by law.
5. Data Sharing
We do not sell your personal data. We share data only with:
- Firebase (Google) — authentication, database, storage, and hosting.
- Stripe — payment processing.
- Google Maps — map display and geocoding.
- OpenAI — AI training plan generation (prompts do not include personally identifiable information).
- Other users — your public profile is visible to other BEHNARO users according to your privacy settings.
6. Data Retention
We retain your personal data for as long as your account is active. After account deletion, we remove personal data within 30 days, except where retention is required by law (e.g., payment records for 7 years under EU tax law).
7. Your Rights (GDPR)
If you are in the EEA, you have the right to:
- Access — request a copy of your personal data.
- Rectification — correct inaccurate data.
- Erasure — request deletion ("right to be forgotten").
- Portability — receive your data in a machine-readable format.
- Objection — object to processing based on legitimate interests.
- Restriction — request limited processing in certain circumstances.
- Withdraw consent — at any time, without affecting prior processing.
To exercise any right, email dboryczko@gmail.com. We will respond within 30 days.
8. Cookies & Tracking
The BEHNARO mobile app does not use cookies. Our landing website (behnaro.com) uses only essential cookies required for the site to function. No third-party advertising or tracking cookies are used.
9. Children's Privacy
BEHNARO is not directed to children under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us immediately and we will delete it.
10. International Transfers
Your data is processed on servers located in the EU/EEA (Firebase europe-west region). Where data is transferred outside the EEA, we ensure adequate safeguards are in place (e.g., Standard Contractual Clauses).
11. Security
We implement industry-standard security measures including encryption in transit (TLS), Firebase Security Rules for database access control, and regular security reviews. No system is 100% secure; please use a strong password and enable two-factor authentication where available.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or an in-app notification at least 14 days before the change takes effect. Continued use of BEHNARO after that date constitutes acceptance.
13. Contact
Dominik Boryczko
Email: dboryczko@gmail.com
BEHNARO — behnaro.com
You also have the right to lodge a complaint with your local Data Protection Authority (DPA).