Polityka prywatności aplikacji GSP APP
Wersja polska
Aplikacja mobilna GSP APP
Ta część polityki prywatności dotyczy aplikacji mobilnej GSP APP na Androida i iPhone'a. Opisuje, jakie dane zbiera aplikacja, gdzie je trzyma, kto je widzi i co możesz z nimi zrobić. Opis dotyczy wersji 125 aplikacji i nowszych; tam, gdzie starsze wersje działają inaczej, piszemy to wprost. W sprawach aplikacji ta część ma pierwszeństwo przed pozostałymi postanowieniami polityki prywatności. Publikujemy ją jako osobną stronę: https://www.globalsystempatterns.pl/gsp-app-polityka-prywatnosci.
Aplikacja działa tylko w języku polskim. Nazwy przycisków i ekranów podajemy tak, jak widać je w aplikacji.
Obowiązuje od: 19 września 2026 r.
1. Kto odpowiada za Twoje dane
Administratorem danych w aplikacji jest GSP CLINIC PROKOPOWICZ sp. z o.o., ul. Kostrzyńska 12, 66-400 Gorzów Wielkopolski, NIP 5993255712, REGON 388639359, KRS 0001072367. Te same dane (nazwa, adres, e-mail, telefon) pokazują App Store i Google Play jako dane wydawcy aplikacji. W tej części polityki słowa „my” i „GSP” oznaczają tę spółkę.
Kontakt w sprawach danych osobowych: [email protected], tel. +48 791 671 531. Ten sam adres jest kontaktem w aplikacji (przy kodzie z maila i przy usuwaniu konta), na stronie „Usuń konto w GSP app”, adresem odpowiedzi na maile z aplikacji oraz kontaktem podanym w Google Play i App Store.
Nie wyznaczyliśmy inspektora ochrony danych (nie mamy takiego obowiązku — art. 37 RODO). W sprawach danych osobowych kontaktuj się z nami: [email protected], +48 791 671 531.
Kto odpowiada za które dane.
- My (GSP) odpowiadamy za Twoje konto w aplikacji (profil, logowanie, zapis Twoich zgód), za podsumowania wysyłane automatycznie z Twojej karty „To ja”, za wyzwania prywatne, za wspólne normy i za dane trenera jako naszego klienta (konto, abonament).
- Trener odpowiada za dane, które powstają we współpracy z nim: kartotekę w swoim telefonie, plany i ich przypisanie, dziennik wykonania planu i notatki do planu, podsumowania, które wysyła ręcznie, grupę swojej kadry i wyzwania w niej oraz — od wersji 123 — Waszą rozmowę. W tym zakresie przetwarzamy dane w imieniu trenera i na jego polecenie, jako podmiot przetwarzający. Wnioski w sprawie tych danych kieruj do trenera; jeśli napiszesz do nas, przekażemy je trenerowi i pomożemy je załatwić.
- Po usunięciu konta trenera dane z jego zakresu, które zostają na Twoim koncie (archiwum serii, podsumowania — pkt 15), przechodzą pod naszą odpowiedzialność.
Jeśli trener prowadzi Twoje dane w swoim telefonie. Trener może zapisywać w swoim telefonie dane zawodników — zarówno tych z kontem w aplikacji, jak i tych bez konta: imię i nazwisko, rok urodzenia, płeć, sport, grupy treningowe, wymiary, wyniki i notatki (także o zdrowiu). Tak prowadzi też zawodników poniżej 16 lat, którzy nie mogą mieć własnego konta (pkt 16). Może też pobrać do telefonu dane z aplikacji VBT, jeśli ma do nich dostęp jako Twój trener (pkt 5).
- Za dane zapisane w telefonie trenera odpowiada trener. GSP ich nie widzi.
- Osobom bez konta trener przekazuje informację o przetwarzaniu ich danych najpóźniej w ciągu miesiąca od ich zapisania. Na prośbę trenera przekazujemy mu gotowy wzór takiej informacji.
- Jeśli chcesz wiedzieć, co trener o Tobie zapisał, zapytaj trenera.
2. W skrócie: cztery miejsca, w których mogą być dane
- Telefon. Większość danych (kartoteka, pomiary, wideo) zostaje w telefonie osoby, która korzysta z aplikacji.
- Chmura GSP APP. Konto, połączenia trener–zawodnik, podsumowania pomiarów, plany, wiadomości, wyzwania i wyniki do wspólnych norm zapisujemy w bazie Supabase w Unii Europejskiej (Frankfurt, Niemcy).
- Aplikacja VBT. Jeśli zalogujesz się kontem z osobnej aplikacji VBT, GSP APP może pobrać z niej dane do telefonu. Nie zapisuje tam danych treningowych.
- Stripe. Dane o abonamencie trenera dostajemy od operatora płatności Stripe. Danych karty nie widzimy.
W aplikacji nie ma reklam, narzędzi analitycznych ani własnego systemu raportowania awarii. Aplikację rozdajemy przez Google Play, jako plik instalacyjny ze strony GSP (Android) oraz przez Apple TestFlight i App Store (iPhone). Apple przekazuje nam raporty awarii i opinie z TestFlight, a Google — zbiorcze statystyki instalacji i awarii z Google Play (pkt 11). Nie sprzedajemy danych. Nie wysyłamy ich do zewnętrznych modeli sztucznej inteligencji.
3. Dane w telefonie
Aplikacja zapisuje te dane w pamięci telefonu. Niektóre z nich trafiają też do chmury GSP APP: podsumowanie pomiarów (także automatycznie), dni z pomiarem w wyzwaniach, plan treningowy zaimportowany z pliku CSV lub XLSX i — jeśli zawodnik włączy to na swoim koncie — wyniki do wspólnych norm. Opisujemy to w pkt 4.
- Kartoteka zawodników: imię i nazwisko, rok urodzenia, płeć, sport, grupy treningowe (zawodnik może być w kilku), tag RFID, masa ciała, wzrost, długość nóg i inne wymiary potrzebne w protokołach skoku.
- Notatki trenera o zawodniku (do 4000 znaków). Mogą zawierać informacje o kontuzjach i zdrowiu.
- Pomiary skoków: sesje, próby, surowe odczyty maty i wyniki (np. wysokość, czas lotu, moc, RSI — wskaźnik siły reaktywnej).
- Trening z pomiarem prędkości sztangi (VBT): serie, powtórzenia, ciężar, prędkość, RPE (Twoja ocena, jak ciężki był wysiłek).
- Gotowość: HRV (zmienność rytmu serca), sen, „body battery”, tętno spoczynkowe, samopoczucie, RPE z poprzedniego dnia i wyliczony wskaźnik gotowości. Wpisujesz je ręcznie albo importujesz z pliku. Aplikacja nie łączy się z Apple Zdrowie ani z Health Connect.
- Maksymalne ciężary, pomiary atletyczne (np. tętno spoczynkowe, VO2max — wydolność tlenowa, sprint, skok w dal, test MAS — bieg 5 minut, z którego aplikacja liczy tempo biegu) i odznaki. Imienia „gościa na dziś” w kalkulatorze MAS aplikacja nie zapisuje.
- Pomiary ciała: masa oraz obwody talii, bioder, klatki piersiowej, ramion, ud i łydek (obwody ramion, ud i łydek osobno dla lewej i prawej strony).
- Wideo (GSP Vision): nagrania techniki (z aparatu, do 2 minut, albo z galerii), miniatury, rysunki na nagraniu, komentarz głosowy trenera i filmy z analizy. Tor sztangi liczy telefon. Nagrania nie trafiają na nasz serwer.
- Zdjęcie profilowe użytkownika (zmniejszone do 512 px).
- Ustawienia i pamięć podręczna: ustawienia zgód, rola, godzina przypomnień, ostatni sprawdzony stan abonamentu, powiązanie konta z kartą „To ja”, kopia ostatnio wysłanego podsumowania, sesja połączenia z aplikacją VBT, opisy nagrań (m.in. wpisane imię zawodnika), ostatnio sprawdzony stan dostępu („zapis wstrzymany” lub nie) z licznikiem uruchomień aplikacji oraz znacznik przerwanego usuwania konta.
- Sesja logowania: aplikacja pamięta sesję, żeby nie trzeba było logować się przy każdym uruchomieniu. Hasła nie zapisuje.
- Importy z plików (ChronoJump, Vitruve, dziennik VBT): plik jest czytany w telefonie, bez wysyłania.
Przypomnienia planuje sam telefon, bez serwera. Mogą zawierać imiona zawodników, u których brakuje danych. Zależnie od ustawień powiadomień w telefonie imiona mogą być widoczne także na zablokowanym ekranie.
Kiedy dane z telefonu mogą go opuścić. Poza sytuacjami z pkt 4 — tylko wtedy, gdy to wybierzesz:
- Kopia zapasowa („Kopia zapasowa — cała baza do pliku”, a na ekranie dla osoby bez dostępu — „Pobierz dane z telefonu”):
- co zawiera: całą kartotekę, notatki i pomiary w jednym pliku;
- czego nie zawiera: wideo, zdjęcia profilowego ani ustawień;
- uwaga: plik nie jest szyfrowany i trafia tam, gdzie go wyślesz (np. do komunikatora, na dysk w chmurze, e-mailem);
- kto odpowiada: od chwili wysłania — osoba, która go wysłała, i wybrana przez nią usługa.
- Wideo: „Udostępnij” (nagranie, klatka, film z analizy) albo „Zapisz w galerii” (album „GSP Vision”). Z galerii nagranie może trafić do chmury zdjęć, jeśli masz ją włączoną w telefonie (np. Zdjęcia Google, Zdjęcia iCloud).
Po udostępnieniu kopia pliku zostaje w pamięci podręcznej telefonu, dopóki system jej nie wyczyści.
Kopie systemowe. Na Androidzie aplikacja wyłącza automatyczną kopię na koncie Google, ale przy przenoszeniu danych kablem lub bezpośrednio ze starego telefonu dane mogą przejść na nowy telefon. Na iPhonie dane aplikacji są wyłączone z kopii iCloud.
Odinstalowanie aplikacji usuwa dane z telefonu. Bez wcześniejszej kopii nie da się ich odzyskać, bo nie mamy ich na serwerze.
4. Dane w chmurze GSP APP (UE, Frankfurt)
Chmura to baza Supabase we Frankfurcie (Niemcy). Reguły bazy ograniczają, kto widzi dane w aplikacji. Szczegóły są w pkt 9.
Konto
- Do korzystania z aplikacji potrzebne jest konto. Konto trenera zakłada się „Pierwszym logowaniem” na adres e-mail, na który opłacono abonament. Konto zawodnika zakłada się kodem od trenera.
- Zapis wstrzymany. Trener bez ważnego abonamentu i zawodnik bez połączenia z trenerem, który go opłaca, widzą swoje dane, mogą je pobrać i usunąć konto, ale nie zapiszą nowych danych. Zawodnicy trenera, który usunął konto albo przestał płacić, mogą zapisywać jeszcze przez 30 dni (pkt 15).
- Wiek. Przy zakładaniu konta zawodnika aplikacja pyta o datę urodzenia, żeby sprawdzić, czy masz ukończone 16 lat (pkt 16). Daty urodzenia nie zapisujemy — ani w telefonie, ani w chmurze.
- E-mail i hasło (hasło zapisane w postaci, z której nie da się go odczytać), data założenia i ostatniego logowania.
- Przy logowaniu zapisujemy adres IP i informację o urządzeniu lub przeglądarce. Przy innych połączeniach aplikacji z chmurą (synchronizacja, sprawdzenie kodu, wysyłka norm, kod z maila, usunięcie konta) serwery mogą zapisywać te informacje w logach technicznych (pkt 13). Używamy ich tylko do ochrony kont i usuwania awarii.
- Po wybraniu „Nie pamiętam hasła” wysyłamy e-mailem jednorazowy kod. Kto ma dostęp do skrzynki przypisanej do konta, ten po zmianie hasła przejmuje konto razem z jego historią, w tym rozmowami — tak jak przy odzyskiwaniu hasła w innych usługach. Dbaj o bezpieczeństwo swojej skrzynki. Przy zakładaniu konta zawodnika nie wysyłamy e-maila z prośbą o potwierdzenie adresu.
- Kod z maila („Pierwsze logowanie” i „Potwierdź adres e-mail”). Tym kodem trener ustawia hasło do swojego konta trenera (konto powstaje wtedy, gdy go jeszcze nie było) albo potwierdza, że adres konta należy do niego. Kod ma 8 cyfr i działa 30 minut, tylko raz. W chmurze nie przechowujemy samego kodu, tylko jego skrót, którego nie da się odwrócić. Żeby liczyć prośby i próby, zapisujemy skróty HMAC adresu e-mail i adresu IP — to dane pseudonimowe. Kody, skróty i zapisy prób usuwamy najpóźniej przy pierwszym porządkowaniu po upływie doby (pkt 13). Wpisy, które te funkcje same dodają do dziennika, nie zawierają adresu e-mail, kodu, hasła ani adresu IP. Jeśli na tym adresie było już konto zawodnika, „Pierwsze logowanie” zamienia je w konto trenera: konto i jego dane zostają, ale kasujemy jego połączenia z trenerami (zgodę na połączenie mógł dać ktoś inny) oraz — od wersji 123 — jego wiadomości, u obu stron rozmowy, i wylogowujemy wszystkie telefony. Aplikacja mówi o tym na ekranie „Pierwszego logowania” — po ustawieniu hasła, zanim wejdziesz do aplikacji.
- Potwierdzony adres. Po kodzie z maila zapisujemy, że adres konta został potwierdzony: konto, adres, datę i sposób potwierdzenia. Konta, które miały abonament przed wprowadzeniem kodów, i konta założycieli GSP oznaczyliśmy tak jednorazowo. Abonament trenera działa tylko na koncie z potwierdzonym adresem (pkt 6). Zapis usuwamy razem z kontem.
- Profil: imię i nazwisko (jedno pole, tak jak je wpiszesz) oraz sport — możesz je zmienić w aplikacji — a także rola (zawodnik, trener albo założyciel GSP) i rodzaj konta.
Połączenie z trenerem (kod zaproszenia)
- Trener generuje kod: GSP- i 8 losowych znaków w dwóch czwórkach. Kod nie ma terminu ważności i można go użyć wiele razy, dopóki trener nie wygeneruje nowego — wtedy poprzednie kody trenera przestają działać. Kody w dawnym formacie (4 znaki po GSP-) działają jeszcze przez okres przejściowy, po którym wygasną. Każdy, kto zna aktywny kod, może połączyć się z trenerem (po wyrażeniu zgody z pkt 8) i wejść do grupy jego kadry.
- Trener może wysłać zaproszenie (kod, swoje imię i link do strony GSP z aplikacją) wybranym przez siebie komunikatorem. Aplikacja nie zbiera numerów telefonów ani kontaktów.
- Po 5 błędnych kodach w ciągu 15 minut sprawdzanie kodu blokuje się na 15 minut. Żeby liczyć próby, zapisujemy skrót HMAC identyfikatora konta albo — bez logowania — adresu IP (dane pseudonimowe, bez samego adresu). Zapisy prób usuwamy po dobie.
- Imię i nazwisko trenera, który wydał kod, sprawdzi każdy, kto zna kod, także bez logowania. Aplikacja pokazuje je przed połączeniem, żebyś wiedział, z kim się łączysz; trener bez wpisanego imienia nie utworzy kodu.
- Po wpisaniu kodu i wyrażeniu zgody (pkt 8) zapisujemy połączenie: kto z kim, status i datę połączenia, a w historii zgód — zgodę z wersją jej treści i czasem według serwera. Dołączasz też do grupy kadry trenera (nazwa grupy zawiera imię trenera).
Podsumowanie pomiarów (zapisywane na Twoim koncie w chmurze; widzi je połączony trener)
- skoki: najlepszy i ostatni wynik CMJ (skok pionowy z zamachem), liczba dni ze skokami;
- ostatni wpis gotowości: data, samopoczucie, sen, HRV, „body battery”, tętno spoczynkowe, RPE z poprzedniego dnia;
- ostatnia seria VBT: ćwiczenie, ciężar, najlepsza prędkość, liczba powtórzeń, łączna liczba serii, data.
Nie wysyłamy notatek trenera, masy ciała, obwodów ani wideo.
Kiedy wysyłamy podsumowanie
- Jeśli wskażesz w aplikacji swoją kartę w kartotece (sekcja „TO JA — mierz siebie”: „Wskaż mnie w kartotece” albo „Nie ma mnie tam — załóż nową kartę”), aplikacja sama wysyła podsumowanie na Twoje konto w chmurze: po założeniu nowej karty, przy uruchomieniu i przy każdym powrocie do aplikacji, gdy dane się zmieniły. Dzieje się tak tylko wtedy, gdy masz aktywne połączenie z trenerem. Bez połączenia i po rozłączeniu podsumowanie nie wychodzi z telefonu; baza odrzuca takie podsumowania także ze starszych wersji aplikacji. Po aktualizacji do wersji 125 podsumowania nie są wysyłane, dopóki nie odpowiesz na kartkę zgody (pkt 8). Podsumowanie wyślesz od razu przyciskiem „Synchronizuj teraz”, a wysyłkę zatrzymasz przyciskiem „To nie moja karta — odepnij”.
- Połączony trener, który sam mierzy zawodnika, może wysłać podsumowanie ręcznie (przyciski „Mierzę go sam — powiąż lokalny rekord” i „Wyślij mój pomiar do chmury” na karcie zawodnika).
Plany i rozmowy
- Plany treningowe (nazwa, opis, ćwiczenia, serie, tempo, przerwy) i ich przypisanie zawodnikowi, także plany zaimportowane z pliku CSV lub XLSX.
- Dziennik wykonania: odhaczone serie, ciężar, RPE (nieobowiązkowe).
- Notatki do dnia planu (wolny tekst).
- Wiadomości trener–zawodnik (od wersji 123): treść (1–4000 znaków), nadawca i odbiorca, czas wysłania i czas przeczytania przez odbiorcę (oba według serwera), opcjonalnie powiązanie z planem (znika, gdy plan zostanie usunięty) i wspólny znacznik kopii jednej wiadomości do grupy. Rozmowa jest tylko w chmurze — telefon nie trzyma jej kopii. Imię rozmówcy aplikacja pokazuje z jego profilu, tylko osobom, z którymi ma wspólne wiadomości.
- Pisać można tylko do osoby, z którą masz aktywne połączenie. Wiadomość trenera do grupy trafia do każdego zawodnika osobno, do jego rozmowy z trenerem — zawodnicy nie widzą się nawzajem ani swoich odpowiedzi.
- Po rozłączeniu rozmowa zostaje u obu stron do odczytu, ale nie da się pisać. Przy wstrzymanym zapisie (pkt 4) możesz czytać, nie możesz pisać.
- Ochrona przed nadużyciem: najwyżej 300 wiadomości z konta na 10 minut i 100 odbiorców naraz.
- Powiadomień na telefon o nowych wiadomościach w tej wersji nie ma.
- W wersjach starszych niż 123 wiadomości nie da się wysłać.
W notatce lub wiadomości możesz napisać coś o zdrowiu. Pisz tylko to, co potrzebne.
Wyzwania
- Nazwa, zasady, dziedzina pomiaru, daty, uczestnicy, wynik startowy (np. aktualny wynik skoku z telefonu), data dołączenia i odhaczone dni. Dni z pomiarem aplikacja dopisuje sama przy otwarciu wyzwania.
- Tablica wyzwania w grupie: oś dni, reakcje, gotowe komentarze, zdarzenia tablicy i krótkie zdania trenera.
- Wyzwanie powstaje w grupie kadry trenera i widzą je tylko osoby z tej grupy. Kto nie ma grupy, zakłada wyzwanie prywatne, widoczne tylko dla siebie. Wyzwań otwartych dla wszystkich użytkowników nie ma.
- Autor może usunąć wyzwanie. Znikają wtedy odhaczenia, reakcje i tablica wszystkich uczestników.
Wspólne normy wyników (dobrowolne)
Udział w normach to osobna, dobrowolna zgoda samego zawodnika: przełącznik „Udział w normach GSP” na jego koncie, domyślnie wyłączony. Włączając go, potwierdzasz, że masz ukończone 16 lat. Trener nie może wyrazić tej zgody za zawodnika, ale widzi, czy zawodnik ma ją włączoną. Po każdej poprawnej próbie (skok z maty, skok w dal) wysyłamy wynik tylko zawodnika, który ma konto i włączoną zgodę — także gdy mierzy go trener na swoim telefonie. Przed wysyłką telefon pyta chmurę, czy zgoda jest włączona, podając identyfikator konta (bez wyniku). Wyników zawodników bez konta i osób poniżej 16 lat nie wysyłamy.
Do norm zapisujemy: rodzaj testu, wynik (zaokrąglony do 0,5 cm), miesiąc pomiaru, płeć, przedział wieku i sport — bez identyfikatora konta i telefonu. Nie przechowujemy powiązania rekordu z kontem. Z jednego konta przyjmujemy najwyżej 30 wyników na dobę; żeby to liczyć, trzymamy dzienny licznik z identyfikatorem konta najwyżej do następnej doby. Wysyłka odbywa się w ramach Twojej sesji logowania, więc serwer może ją zanotować w logach technicznych (pkt 13).
W bazie norm jest też 12 starszych wyników, wysłanych przed tą zmianą, gdy o udziale decydował przełącznik w telefonie trenera: mają pełną datę i niezaokrąglony wynik, a 6 z nich nie ma przedziału wieku; nie da się ich powiązać z kontem.
Z tych danych liczymy normy, np. percentyl (jaka część wyników w tej samej grupie jest równa danemu wynikowi lub niższa). Zestawień norm dziś w aplikacji nie udostępniamy.
Ponieważ nie przechowujemy powiązania rekordu z kontem, nie możemy wskazać ani usunąć Twoich rekordów na wniosek. Mimo to chronimy je jak dane osobowe.
5. Dane pobierane z aplikacji VBT
GSP APP może połączyć się z osobną aplikacją VBT (jej baza też jest we Frankfurcie).
- Logujesz się e-mailem i hasłem z tamtej aplikacji. Dane logowania trafiają tylko do niej. GSP APP nie zapisuje hasła, pamięta w telefonie tylko sesję.
- GSP APP pobiera do telefonu dane, do których Twoje konto VBT ma dostęp: imię, rola, sport, masa ciała, data urodzenia, płeć, sesje (z RPE i notatką), serie, powtórzenia, gotowość dnia (sen, HRV, „body battery”, tętno spoczynkowe, RPE, samopoczucie), maksymalne ciężary, bloki i plany, dodatkowe jednostki treningowe oraz pomiary atletyczne.
- Jeśli zalogujesz się kontem trenera z aplikacji VBT, GSP APP pobierze do telefonu także dane jego podopiecznych, do których to konto ma dostęp.
- GSP APP nie zapisuje w aplikacji VBT żadnych danych treningowych. Logowanie tworzy tam jedynie sesję (jak przy każdym logowaniu).
- Pobrane dane zostają w telefonie tak jak w pkt 3. Jeśli profil zawodnika jest powiązany z kontem GSP APP, ostatnia gotowość i ostatnia seria VBT mogą trafić do podsumowania opisanego w pkt 4.
Za dane w samej aplikacji VBT odpowiada jej operator, zgodnie z polityką prywatności tamtej aplikacji.
6. Abonament trenera
- Stripe przekazuje nam: e-mail płacącego, identyfikator klienta i abonamentu w Stripe, status i datę ważności. Zapisujemy je w chmurze GSP APP.
- Abonament przypisujemy do konta po adresie e-mail. Działa on — a wpis o abonamencie (status, data ważności, identyfikatory Stripe) widzi osoba zalogowana na to konto — tylko wtedy, gdy adres konta jest potwierdzony kodem z maila (pkt 4). Jeśli adres e-mail konta się zmieni, napisz do nas, żeby zachować powiązanie.
- Usunięcie konta nie anuluje abonamentu w Stripe (pkt 15).
- Aplikacja sprawdza tylko, czy abonament jest ważny i do kiedy. Ostatni wynik zapamiętuje w telefonie, żeby działać przez krótki czas bez internetu.
- Dane, które podajesz w formularzu płatności (np. dane karty i adres e-mail), przetwarza Stripe. Dla danych płatniczych Stripe jest odrębnym administratorem (pkt 11). Polityka prywatności Stripe: https://stripe.com/privacy
- Faktury: wystawia księgowość GSP na prośbę trenera. Dane do faktury (w tym NIP) trener podaje e-mailem na [email protected].
Zawodnik nie podaje w aplikacji danych płatniczych.
7. Skąd pochodzą dane
- Od Ciebie: konto, profil, pomiary, wiadomości, notatki.
- Z Twojego telefonu, automatycznie: podsumowanie pomiarów i dni z pomiarem w wyzwaniach (pkt 4).
- Od trenera: kartoteka zawodnika, notatki i pomiary wpisane w jego telefonie, plany, podsumowania wysłane ręcznie.
- Z plików, które wybierzesz: ChronoJump, Vitruve, dziennik VBT, plan w CSV lub XLSX.
- Z aplikacji VBT: po zalogowaniu kontem z tamtej aplikacji (pkt 5).
- Ze Stripe: dane o abonamencie trenera (pkt 6).
- Od Apple i Google: raporty awarii i opinie testerów z TestFlight oraz zbiorcze statystyki instalacji i awarii z Google Play (pkt 11).
8. Dane o zdrowiu i sprawności
Część danych w aplikacji to dane o zdrowiu (art. 9 RODO): HRV, tętno spoczynkowe, sen, samopoczucie, RPE, VO2max, masa i obwody ciała, notatki o kontuzjach. Tak samo traktujemy wyniki skoków, treningu z pomiarem prędkości (VBT) i RPE — chronimy je jak dane o zdrowiu.
- Z tych danych do chmury trafia podsumowanie z pkt 4 (skoki, gotowość, ostatnia seria VBT) oraz to, co wpiszesz w dzienniku planu, notatkach, wiadomościach i wyzwaniach.
- Podsumowanie trafia do chmury tylko przy aktywnym połączeniu z trenerem: gdy powiążesz swoją kartę („To ja”) albo gdy połączony trener wyśle je ręcznie.
- Przy każdym łączeniu z trenerem aplikacja pokazuje kartkę „Zgoda na dane o zdrowiu” z imieniem i nazwiskiem trenera i z listą tego, co trener zobaczy: wyniki skoków i treningu z pomiarem prędkości, gotowość (HRV, sen, tętno spoczynkowe, Body Battery, samopoczucie, RPE), dziennik planu i notatki do planu, udział w wyzwaniach jego kadry oraz Waszą rozmowę. Pole zgody nie jest zaznaczone z góry, a przycisk „Połącz” działa dopiero po jego zaznaczeniu. Od wersji 125 bez zgody połączenie nie powstaje. Połączenia z wcześniejszych wersji potwierdzamy jednorazową kartką w nowej wersji aplikacji — do wyboru „Zgadzam się” albo „Rozłącz z trenerem”. Dopóki na nią nie odpowiesz, nowa wersja nie wysyła trenerowi podsumowań Twoich pomiarów. Dwa wyjątki, które zamkniemy w kolejnych wersjach: starsze wersje aplikacji (do 124) łączą się jeszcze bez kartki i wysyłają podsumowania bez pytania o zgodę, więc zaktualizuj aplikację; a jeśli trener mierzy Cię na swoim telefonie, w tym czasie może wysłać podsumowanie tego pomiaru pod Twoim kontem. Zgodę zapisujemy w historii zgód (rodzaj, wersja treści, czas według serwera), a treść każdej wersji zgody przechowujemy osobno. To Twoja wyraźna zgoda na przetwarzanie danych o zdrowiu (art. 9 ust. 2 lit. a RODO).
- Co jest wymagane, a co dobrowolne. Zgoda z ekranu łączenia obejmuje tylko to, bez czego aplikacja nie działa: wgląd połączonego trenera w Twoje wyniki, bo po to się z nim łączysz. Wszystko ponad to wyrażasz osobno i możesz odmówić bez żadnych skutków dla korzystania z aplikacji: udział w normach (pkt 4) i ewentualne przyszłe użycie danych w innym celu, np. w badaniach.
- Konto zawodnika zakłada się kodem od trenera i od 16 lat. Obecnie nie da się zacząć korzystać z aplikacji jako zawodnik bez połączenia z trenerem.
- Używamy tych danych tylko do świadczenia usługi Tobie i Twojemu trenerowi. Nie używamy danych o zdrowiu i sprawności do reklamy, marketingu, profilowania komercyjnego ani eksploracji danych w celach niezwiązanych z usługą. Nie sprzedajemy ich. Jedyne zbiorcze wykorzystanie to wspólne normy (pkt 4), za zgodą samego zawodnika. Na każde inne wykorzystanie, w tym badania, poprosimy o osobną zgodę.
9. Kto widzi dane w chmurze
- Ty: swoje konto, profil, podsumowania, plany, wiadomości, a jako trener także wpis o swoim abonamencie.
- Trener, z którym się połączysz: Twój profil (imię i nazwisko, sport, rola, rodzaj konta) oraz wszystkie podsumowania zapisane na Twoim koncie — także te z czasu połączenia z innym trenerem. Połączony trener może je też zmieniać i usuwać. Widzi też Twój dziennik planu, notatki do planu, Waszą rozmowę (od wersji 123) i to, czy masz włączony udział w normach GSP. Po rozłączeniu jego dostęp do tych danych znika od razu.
- Zawodnik: profil swojego trenera (imię i nazwisko, sport, rola i rodzaj konta).
- Członkowie grupy kadry (każdy, kto wpisał aktywny kod trenera): nazwę grupy (z imieniem trenera), jej skład (identyfikatory kont), a w wyzwaniach tej grupy: Twój wynik startowy, datę dołączenia, odhaczone dni, reakcje, wybrane gotowe komentarze oraz zdarzenia tablicy (np. dzień zbiorczy, rekord z wynikiem). Po rozłączeniu z trenerem zostajesz w grupie jego kadry, dopóki sam z niej nie wyjdziesz albo trener Cię nie usunie; Twój udział w wyzwaniach tej grupy jest wtedy nadal widoczny dla grupy.
- Wyzwanie prywatne (gdy nie masz grupy kadry) widzisz tylko Ty.
- Założyciele GSP nie mają w aplikacji wglądu w Twoje dane ani w listę połączeń, chyba że są Twoim połączonym trenerem. Baza przewiduje wgląd założycieli w profil i podsumowania zawodnika, który udzieli na to osobnej zgody; obecna aplikacja takiej zgody nie oferuje.
- Administratorzy techniczni GSP (osoby z dostępem do panelu bazy) mają techniczny dostęp do wszystkich danych w chmurze, w tym wiadomości i podsumowań. Korzystają z niego tylko do utrzymania usługi, usuwania awarii i realizacji Twoich wniosków. Dostęp do panelu bazy mają dwie osoby — założyciele GSP.
- Wiadomości: w aplikacji widzą je tylko nadawca i odbiorca. Nie czytamy rozmów; dostęp techniczny ma tylko administrator bazy (patrz wyżej).
- Każdy, także bez konta: imię i nazwisko trenera, jeśli zna jego kod.
- Normy: zestawień norm dziś w aplikacji nikomu nie udostępniamy (pkt 4).
- Dostawcy z pkt 11, w zakresie potrzebnym do działania usługi.
- Organy publiczne, gdy wymagają tego przepisy.
10. Zgody i jak je cofnąć
Zgoda na dane o zdrowiu i połączenie z trenerem. Jak cofnąć: ikona „Rozłącz” przy trenerze — cofnięcie zgody oznacza rozłączenie. Rozłączyć może też trener. Co się stanie: trener od razu traci dostęp do Twoich danych w chmurze i nie dostaje nowych podsumowań. Zapisujemy datę cofnięcia zgody. To, co trener już zapisał w swojej kartotece w telefonie, u niego zostanie (za te dane odpowiada trener, pkt 1). Wcześniej wysłane podsumowania zostają na Twoim koncie i zobaczy je także kolejny trener, z którym się połączysz; usuniemy je na Twoją prośbę (pkt 14). Po rozłączeniu zostajesz w grupie kadry trenera, dopóki sam z niej nie wyjdziesz albo trener Cię nie usunie; Twój udział w wyzwaniach jest wtedy widoczny dla grupy. Historię swoich zgód znajdziesz w pliku „Pobierz swoje dane”. Uwaga: bez połączenia z trenerem, który opłaca dostęp, zapis w aplikacji zostaje wstrzymany (pkt 4).
Automatyczna wysyłka podsumowań („To ja”). Jak zatrzymać: przycisk „To nie moja karta — odepnij”. Co się stanie: aplikacja przestaje wysyłać podsumowania. Rozłączenie z trenerem też zatrzymuje wysyłkę.
Wspólne normy. Jak cofnąć: wyłącz przełącznik „Udział w normach GSP” na swoim koncie. Co się stanie: nowe wyniki nie są wysyłane; wcześniej wysłane zostają, bo nie da się ich wskazać (pkt 4).
Udział w wyzwaniu. Jak zrezygnować: przycisk „Rezygnuj” przy wyzwaniu. Co się stanie: znikasz z listy uczestników, a Twoje odhaczone dni i wpisy tablicy w tym wyzwaniu są usuwane. Dzisiejsze odhaczenie możesz cofnąć także bez rezygnacji.
Cofnięcie zgody nie zmienia tego, że przetwarzanie przed cofnięciem było zgodne z prawem.
11. Dostawcy i przekazywanie danych poza EOG
Dostawcy, którzy działają jako podmioty przetwarzające, przetwarzają dane wyłącznie na nasze polecenie, na podstawie standardowych umów powierzenia tych dostawców, i muszą je chronić co najmniej tak, jak opisuje ta polityka.
Supabase Inc.
- Rola: podmiot przetwarzający.
- Po co: baza danych, logowanie i funkcje serwera: kod z maila („Pierwsze logowanie”, „Potwierdź adres e-mail”), sprawdzanie kodów zaproszeń, usunięcie konta i przyjmowanie powiadomień o płatnościach.
- Dane: wszystkie dane w chmurze GSP APP.
- Gdzie: baza we Frankfurcie (UE). Funkcje serwera wywoływane z aplikacji wykonują się w regionie eu-central-1 (Frankfurt). Funkcja, która przyjmuje powiadomienia o płatnościach od Stripe, może wykonać się w innym regionie Supabase, także poza EOG — dotyczy to wtedy danych o abonamencie (pkt 6). Podwykonawcy Supabase działają m.in. w USA.
- Podstawa transferu: standardowe klauzule umowne w umowie powierzenia.
Resend Inc. (wysyłka przez Amazon SES)
- Rola: podmiot przetwarzający.
- Po co: wiadomości systemowe — kod do zmiany hasła („Nie pamiętam hasła”), kod do „Pierwszego logowania” i do „Potwierdź adres e-mail” oraz potwierdzenie usunięcia konta.
- Dane: adres e-mail odbiorcy, treść wiadomości (kod; przy usunięciu konta — data, rodzaj konta, co usunęliśmy i co zostało, a u trenera stan abonamentu i jego data), logi wysyłki. Wiadomości nie zawierają danych o zdrowiu, imion zawodników ani numerów ze Stripe.
- Gdzie: wysyłka z Irlandii, firma z USA.
- Podstawa transferu: EU-US Data Privacy Framework i standardowe klauzule umowne.
Stripe (Stripe Payments Europe, Irlandia; grupa z USA)
- Rola: odrębny administrator danych płatniczych (dane karty, zapobieganie oszustwom, obowiązki prawne Stripe); dla danych o abonamencie, które przekazuje nam — podmiot przetwarzający. Polityka Stripe: https://stripe.com/privacy
- Po co: płatność abonamentu trenera.
- Dane: dane płatności i abonamentu.
- Gdzie: Irlandia i USA.
- Podstawa transferu: EU-US Data Privacy Framework lub standardowe klauzule umowne.
Apple (TestFlight i App Store)
- Rola: odrębny administrator danych zbieranych przy pobieraniu aplikacji i w TestFlight. Polityka Apple: https://www.apple.com/legal/privacy/
- Po co: dystrybucja aplikacji na iPhone'a. W TestFlight Apple zbiera od testerów m.in. adres e-mail i imię, raporty awarii i opinie, a raporty i opinie przekazuje nam.
- Gdzie: Irlandia i USA.
- Podstawa transferu: EU-US Data Privacy Framework.
Google (Google Play)
- Rola: odrębny administrator danych zbieranych przy pobieraniu aplikacji z Google Play. Polityka Google: https://policies.google.com/privacy
- Po co: dystrybucja aplikacji na Androida. Google przekazuje nam zbiorcze statystyki instalacji oraz raporty awarii i stabilności (Android vitals) — bez imion i bez danych wpisanych w aplikacji.
- Gdzie: Irlandia i USA.
- Podstawa transferu: EU-US Data Privacy Framework.
Cloudflare
- Rola: podmiot przetwarzający.
- Po co: przechowuje plik instalacyjny na Androida.
- Dane: adres IP i informacja o urządzeniu przy pobraniu pliku.
- Gdzie: sieć serwerów Cloudflare, także poza EOG; firma z USA.
- Podstawa transferu: EU-US Data Privacy Framework.
Gdy dane trafiają poza EOG, opieramy się na mechanizmach z RODO wymienionych przy każdym dostawcy: decyzji Komisji Europejskiej (EU-US Data Privacy Framework) lub standardowych klauzulach umownych zawartych w umowach powierzenia dostawców. Na Twoją prośbę wyślemy informację o tych zabezpieczeniach prawnych (np. kopię klauzul umownych).
12. Podstawy prawne i czy musisz podać dane
Gdy przetwarzamy dane w imieniu trenera (pkt 1), podstawę prawną ma trener, a my działamy na jego polecenie jako podmiot przetwarzający. Nasze własne podstawy:
- Konto, logowanie, zmiana hasła: wykonanie umowy (art. 6 ust. 1 lit. b RODO).
- Plany, dziennik wykonania, notatki do planu, wyzwania w grupie kadry i rozmowa: przetwarzamy je w imieniu trenera (pkt 1). Trener opiera się na umowie z Tobą (art. 6 ust. 1 lit. b RODO), a przy danych o zdrowiu — na Twojej wyraźnej zgodzie z ekranu łączenia (art. 9 ust. 2 lit. a RODO, pkt 8), którą zbieramy w aplikacji także w jego imieniu.
- Podsumowania wysyłane automatycznie z karty „To ja” i wyzwania prywatne: wykonanie umowy (art. 6 ust. 1 lit. b RODO) oraz Twoja wyraźna zgoda z ekranu łączenia z trenerem (art. 9 ust. 2 lit. a RODO, pkt 8).
- Wspólne normy: osobna zgoda zawodnika (art. 6 ust. 1 lit. a i art. 9 ust. 2 lit. a RODO).
- Abonament trenera: umowa (art. 6 ust. 1 lit. b RODO) i obowiązki podatkowe (art. 6 ust. 1 lit. c RODO).
- Bezpieczeństwo kont, logi (adres IP, urządzenie) i liczenie prób kodów zaproszeń: nasz prawnie uzasadniony interes, czyli ochrona kont i usługi (art. 6 ust. 1 lit. f RODO).
- Sprawdzenie wieku przy zakładaniu konta zawodnika: wykonanie umowy i obowiązek z art. 8 RODO (art. 6 ust. 1 lit. b i c RODO); daty nie zapisujemy.
- Dochodzenie roszczeń i obrona przed nimi: nasz prawnie uzasadniony interes, czyli możliwość wykazania, jak świadczyliśmy usługę (art. 6 ust. 1 lit. f RODO, a przy danych o zdrowiu art. 9 ust. 2 lit. f RODO).
E-mail i hasło są potrzebne, żeby korzystać z aplikacji; trener potrzebuje też aktywnego abonamentu, a zawodnik — połączenia z trenerem i ukończonych 16 lat. Pozostałe dane (pomiary, notatki, wiadomości, zdjęcie) podajesz dobrowolnie.
13. Jak długo przechowujemy dane
Część danych pomocniczych chmura kasuje sama przy porządkowaniu — dlatego terminy niżej mówią „najpóźniej przy pierwszym porządkowaniu po upływie…”. Pełne porządki (informacja dla trenera o usuniętym koncie, termin zapisu dla zawodników usuniętego trenera, wpisy abonamentu bez konta oraz kody z maila i zapisy prób) uruchamia każde powiadomienie o płatności i każde usunięcie konta. Same kody z maila i zapisy prób czyści dodatkowo każda prośba o kod z maila. Porządkowanie uruchamia się też samo, codziennie. Pozostałych danych nie kasujemy automatycznie. Obecnie obowiązują takie zasady:
- Konto, profil, plany, wiadomości, wyzwania: do usunięcia konta.
- Podsumowania pomiarów: do usunięcia konta albo do usunięcia na Twoją prośbę. Rozłączenie z trenerem ich nie usuwa.
- Zapis połączenia: dopóki trwa połączenie.
- Historia zgód (zgoda na dane o zdrowiu i udział w normach: rodzaj, wersja treści, czas udzielenia i cofnięcia): do usunięcia konta. Treści kolejnych wersji zgód (bez danych osobowych) przechowujemy bez ograniczenia czasu.
- Kody zaproszeń: do usunięcia konta trenera.
- Wpis abonamentu w chmurze GSP APP (e-mail, identyfikatory Stripe, status, data ważności): dopóki istnieje konto z tym adresem. Wpis bez konta usuwamy przy końcu subskrypcji w Stripe, a najpóźniej przy pierwszym porządkowaniu po upływie 60 dni od końca okresu ważności.
- Faktury i dane płatności: w Stripe i w księgowości GSP przez okres wymagany przepisami podatkowymi i rachunkowymi — 5 lat od końca roku, w którym powstał obowiązek podatkowy.
- Kod z maila, jego skrót oraz zapisy próśb i prób (skróty HMAC adresu e-mail i adresu IP): najpóźniej przy pierwszym porządkowaniu po upływie doby.
- Zapis potwierdzonego adresu: do usunięcia konta.
- Zapisy nieudanych prób kodu zaproszenia (skróty HMAC konta albo adresu IP): do doby.
- Data urodzenia podana przy zakładaniu konta: nie jest zapisywana.
- Informacja dla trenera, że konto zawodnika zostało usunięte (bez imienia): najpóźniej przy pierwszym porządkowaniu po upływie 90 dni; trener może ją ukryć wcześniej.
- Termin, do którego zawodnicy usuniętego trenera mogą zapisywać nowe pomiary: najpóźniej przy pierwszym porządkowaniu po upływie 30 dni od tego terminu.
- Archiwum serii z planów usuniętego trenera: na koncie zawodnika, do usunięcia tego konta.
- Logi techniczne serwerów (adres IP, urządzenie): dostawca bazy usuwa je automatycznie, obecnie po około dobie. Dziennik zdarzeń logowania (m.in. adres IP) prowadzi system logowania dostawcy bazy; dziś nie usuwamy go automatycznie.
- Kopie zapasowe bazy: w obecnym planie usługi bazy nie korzystamy z kopii zapasowych bazy.
- Dzienny licznik wysyłek do norm (z identyfikatorem konta): najwyżej do następnej doby.
- Rekordy norm: bez okresu usunięcia (nie są powiązane z kontem).
- Dane w telefonie: do czasu usunięcia ich w aplikacji albo odinstalowania aplikacji.
14. Twoje prawa
Masz prawo:
- dowiedzieć się, jakie dane mamy, i dostać ich kopię;
- poprawić błędne dane;
- żądać usunięcia danych;
- żądać, żebyśmy wstrzymali korzystanie z danych (ograniczenie przetwarzania);
- dostać dane, które nam podałeś i które przetwarzamy na podstawie zgody lub umowy, w pliku, który możesz przekazać komuś innemu (przenoszenie danych);
- sprzeciwić się korzystaniu z danych w celach opisanych jako nasz prawnie uzasadniony interes (pkt 12);
- nie podlegać decyzji opartej wyłącznie na zautomatyzowanym przetwarzaniu (pkt 19);
- w każdej chwili cofnąć zgodę.
W aplikacji zmienisz imię i nazwisko oraz sport, ustawisz nowe hasło („Nie pamiętam hasła”), odepniesz swoją kartę „To ja” (zatrzymuje wysyłkę podsumowań), rozłączysz się z trenerem, zrezygnujesz z wyzwania, cofniesz dzisiejsze odhaczenie, wyłączysz udział w normach, zrobisz kopię danych z telefonu, pobierzesz swoje dane w plikach JSON i CSV („Pobierz swoje dane” — konto zawodnika; plik zawiera też historię Twoich zgód) i usuniesz konto („Usuń konto”, pkt 15).
- W pozostałych sprawach napisz na [email protected]. Wniosek wyślij z adresu e-mail przypisanego do konta; w razie wątpliwości poprosimy o dodatkowe potwierdzenie tożsamości.
- Odpowiemy w ciągu miesiąca. W trudnych sprawach termin może się wydłużyć o kolejne dwa miesiące — wtedy Cię o tym uprzedzimy.
- Na prośbę usuniemy Twoje podsumowania z chmury i przekażemy w plikach JSON lub CSV kopię danych z chmury, których nie ma w pliku „Pobierz swoje dane” (np. plany i wiadomości trenera, historię udostępnień Twoich danych założycielom GSP).
- Dane zapisane tylko w telefonie trenera przechowuje trener. W tej sprawie zwróć się do niego (pkt 1).
Skargę możesz złożyć do Prezesa Urzędu Ochrony Danych Osobowych (ul. Stanisława Moniuszki 1A, 00-014 Warszawa, także przez ePUAP lub biznes.gov.pl) albo do organu nadzorczego w państwie, w którym mieszkasz lub pracujesz.
15. Usunięcie konta
W aplikacji. Konto usuniesz samodzielnie: zawodnik — Konto → TWOJE DANE → „Usuń konto”; trener i założyciel GSP — Konto → TWOJE KONTO → „Usuń konto”. Trener bez aktywnego dostępu znajdzie „Usuń konto” także na ekranie, który po zalogowaniu pokazuje się zamiast aplikacji. Wpisujesz słowo USUWAM i stukasz „Usuń konto na zawsze”. Konto i dane w chmurze znikają od razu, a konta nie da się przywrócić. Usunięcie działa zawsze — także bez aktywnego abonamentu i przy wstrzymanym zapisie.
Opis usuwania konta jest też na stronie https://www.globalsystempatterns.pl/gsp-app-usun-konto.
Na prośbę. Możesz też napisać do nas (pkt 1) z adresu e-mail przypisanego do konta. Odpiszemy na adres konta z prośbą o potwierdzenie słowem USUWAM, a po potwierdzeniu usuniemy konto tak samo jak aplikacja — najpóźniej w ciągu miesiąca od prośby, zwykle od razu. Tak samo, gdy masz starszą wersję aplikacji bez „Usuń konto”.
Konto zawodnika — znika od razu:
- konto, zapis potwierdzonego adresu i profil;
- połączenia z trenerami i członkostwo w grupach;
- podsumowania pomiarów oraz przypisania planów z zapisanymi seriami i dziennikiem wykonania;
- wiadomości i notatki do planów — znikają też u trenera;
- udział, odhaczenia, wpisy i reakcje w wyzwaniach oraz założone przez Ciebie wyzwania bez innych uczestników;
- zapisy zgód, w tym dowody udzielenia i cofnięcia zgód;
- na telefonie, z którego usuwasz konto: Twoja karta z pomiarami (jeśli na telefonie nie ma innych kart), zdjęcie profilowe, dane logowania, połączenie z aplikacją VBT, przypomnienia i pliki z pobranymi danymi.
Konto zawodnika — zostaje:
- Twoja karta w kartotece trenera, na jego telefonie — dopóki trener jej nie usunie; możesz go o to poprosić;
- informacja dla trenera, że konto zostało usunięte (bez imienia) — najpóźniej do pierwszego porządkowania po upływie 90 dni, a wcześniej, jeśli trener ją ukryje (pkt 13);
- założone przez Ciebie wyzwania z innymi uczestnikami — bez powiązania z Twoim kontem;
- na telefonie z innymi kartami — Twoja karta, odpięta od konta; usuwa ją właściciel telefonu.
Konto trenera i założyciela GSP — znika od razu:
- konto, zapis potwierdzonego adresu i profil;
- kody zaproszeń i połączenia z zawodnikami;
- plany z ćwiczeniami i przypisaniami, a z nimi dzienniki wykonania;
- notatki do planów i wiadomości — znikają też u zawodników;
- Twoje wyzwania i grupy bez innych osób;
- przy potwierdzonym adresie: wpis abonamentu przyznanego ręcznie albo już zakończonego.
Konto trenera i założyciela GSP — zostaje:
- serie i ciężary zapisane przez zawodników w Twoich planach — jako archiwum na ich kontach, w pliku „Pobierz swoje dane”;
- podsumowania wysłane przez Ciebie zawodnikom — na ich kontach, bez powiązania z Tobą;
- grupy i wyzwania z innymi osobami — grupa pod nazwą „Kadra”, bez Twojego imienia; wyzwania bez powiązania z Tobą;
- wpis abonamentu, który trwa w Stripe albo nie był przypisany do potwierdzonego adresu konta (pkt 13);
- na Twoim telefonie cała kartoteka i nagrania — to Ty za nie odpowiadasz.
Jeśli Twój dostęp był opłacony, Twoi zawodnicy mogą zapisywać nowe pomiary jeszcze do 30 dni po jego końcu (po usunięciu konta założyciela GSP — przez 30 dni). W tym czasie mogą połączyć się z innym trenerem.
W obu przypadkach zostają też:
- skrót HMAC adresu konta w zapisie wysyłek e-maila po usunięciu — dane pseudonimowe, z których nie da się odtworzyć adresu; potrzebne, żeby ten sam adres nie dostał więcej niż trzech takich e-maili na dobę. Kasujemy je najpóźniej przy pierwszym porządkowaniu po upływie doby (pkt 13);
- faktury i dane płatności — w Stripe i w księgowości GSP przez okres wymagany prawem podatkowym (5 lat od końca roku, w którym powstał obowiązek podatkowy);
- rekordy norm, bo nie są powiązane z kontem;
- zbiorcze wpisy tablic wyzwań;
- logi techniczne i dziennik zdarzeń logowania z adresem IP (pkt 13).
E-mail po usunięciu. Na adres konta wysyłamy e-mail z podsumowaniem: co usunęliśmy i co zostało, a u trenera — stan abonamentu. Jeśli dzienny limit wysyłek jest wyczerpany, konto i tak jest usuwane, tylko e-mail nie wychodzi.
Abonament. Usunięcie konta nie anuluje abonamentu w Stripe. W e-mailu po usunięciu konta piszemy, czy abonament się odnawia i jak go zakończyć samodzielnie w portalu klienta Stripe; możesz też napisać do nas (pkt 1).
16. Osoby niepełnoletnie
Kto może mieć konto. Własne konto zawodnika może założyć osoba, która ma ukończone 16 lat. Przy zakładaniu konta aplikacja pyta o datę urodzenia; nie zapisujemy jej. Jeśli masz mniej niż 16 lat, konto nie powstanie — trener może prowadzić Twoje wyniki w swojej kartotece w telefonie (pkt 1). Wiek sprawdzamy na podstawie Twojej deklaracji, bez dokumentów — tak jak inne aplikacje sportowe. Aplikacja nie pyta o wiek przy logowaniu na konto, które już istnieje, ani przy łączeniu się kodem z takiego konta. Osoba, która ukończyła 16 lat, sama wyraża w aplikacji zgody, w tym zgodę na dane o zdrowiu (art. 8 RODO).
Młodsi zawodnicy w kartotece trenera. Dane osób poniżej 16 lat zostają w telefonie trenera i za nie odpowiada trener, który powinien mieć zgodę rodzica lub opiekuna prawnego. Ich wyniki nie trafiają do wspólnych norm.
Konto założone przez osobę poniżej 16 lat. Jeśli się o tym dowiemy, usuniemy je.
Prawa rodzica. Rodzic lub opiekun prawny może w imieniu dziecka skorzystać z praw z pkt 14.
Krótko dla zawodników w wieku 16–17 lat. Twoje podsumowania widzi tylko trener, z którym się połączysz. Twoje wyniki w wyzwaniach widzą tylko osoby z Twojej grupy kadry. W każdej chwili możesz usunąć konto w aplikacji albo poprosić nas o usunięcie danych.
17. Bezpieczeństwo
Co robimy:
- połączenie aplikacji z serwerem jest szyfrowane (HTTPS);
- reguły bazy ograniczają dostęp do danych w chmurze;
- hasła przechowujemy w postaci, z której nie da się ich odczytać;
- wideo i zdjęcie profilowe nie trafiają na serwer;
- na Androidzie wyłączamy kopię danych na koncie Google, a na iPhonie wyłączamy dane aplikacji z kopii iCloud;
- kod zaproszenia ma 8 losowych znaków, a po 5 błędnych próbach w ciągu 15 minut sprawdzanie kodu blokuje się na 15 minut.
Na co musisz uważać:
- aplikacja nie szyfruje dodatkowo danych w telefonie, więc używaj blokady ekranu;
- plik kopii zapasowej nie jest szyfrowany, więc wysyłaj go tylko w bezpieczne miejsce;
- kod zaproszenia nie ma terminu ważności i działa wiele razy, więc przekazuj go tylko swoim zawodnikom; jeśli trafił do niewłaściwej osoby, wygeneruj nowy — poprzedni przestanie działać.
Naruszenia ochrony danych: mamy wewnętrzną procedurę. Naruszenie zgłaszamy Prezesowi UODO w ciągu 72 godzin od jego stwierdzenia, a jeśli może powodować wysokie ryzyko dla Ciebie — powiadamiamy także Ciebie.
18. Uprawnienia telefonu
- Aparat: nagrywanie techniki i zdjęcie profilowe.
- Mikrofon: dźwięk nagrania i komentarz głosowy trenera. Aplikacja nie rozpoznaje mowy i nie wysyła nagrań.
- Zdjęcia i galeria: wybór nagrania lub zdjęcia profilowego, zapis analizy do galerii.
- Zapis w pamięci (starsze wersje Androida): zapis analizy wideo do galerii.
- Powiadomienia: lokalne przypomnienia.
- Uruchamianie po restarcie (Android): żeby przypomnienia działały także po ponownym uruchomieniu telefonu. Aplikacja nie korzysta z dokładnych alarmów, więc przypomnienie może przyjść z kilkuminutowym opóźnieniem.
- Bluetooth i lokalizacja: aplikacja ich nie używa.
Każde uprawnienie wyłączysz w ustawieniach telefonu; przestanie wtedy działać funkcja, która go potrzebuje.
19. Automatyczne wyliczenia
Aplikacja wylicza w telefonie wskaźnik gotowości, wyniki skoków, tor sztangi i wskazówki z profilu skoków. W chmurze z wyników w normach liczymy zestawienia (np. percentyl); dziś nie udostępniamy ich w aplikacji. To podpowiedzi dla trenera i zawodnika. Aplikacja nie podejmuje automatycznie decyzji, które mają wobec Ciebie skutki prawne lub podobnie istotne.
- Wskaźnik gotowości porównuje wpisane lub zaimportowane wartości z Twoją własną linią bazową (średnia z ostatnich wpisów, najwyżej 14; potrzeba co najmniej 4) i łączy je według stałych wag w trzy grupy: wyniki nerwowo-mięśniowe (np. skok, prędkość), wskaźniki autonomiczne (np. HRV) i ocena subiektywna.
- Percentyl określa, jaka część wyników w tej samej grupie (test, płeć, przedział wieku, sport) jest równa Twojemu wynikowi lub niższa.
- Wysokość skoku z maty jest liczona z czasu lotu, więc wynik zależy od techniki lądowania i dokładności pomiaru.
Aplikacja zawiera model do analizy sylwetki na nagraniu, ale obecna wersja z niego nie korzysta.
20. To nie jest wyrób medyczny
GSP APP to narzędzie treningowe. Nie jest wyrobem medycznym, nie diagnozuje i nie leczy. Wskaźniki (gotowość, HRV, profil skoków, tempo MAS) są orientacyjne. W sprawach zdrowia skonsultuj się z lekarzem.
21. Zmiany
Zmiany tej części polityki publikujemy na tej stronie z nową datą. O istotnych zmianach poinformujemy Cię przed ich wejściem w życie — e-mailem na adres konta albo w aplikacji. Poprzednie wersje tej części polityki udostępnimy na prośbę. Jeśli zmiana dotyczy zakresu zgody albo zechcemy użyć danych w nowym celu, najpierw Cię o tym poinformujemy i, gdy będzie to potrzebne, poprosimy o zgodę.
English version
GSP APP mobile app
This part of the privacy policy covers the GSP APP mobile app for Android and iPhone. It explains what data the app collects, where it is kept, who can see it and what you can do with it. It describes version 125 of the app and later; where older versions work differently, we say so explicitly. For matters concerning the app, this part takes precedence over the other provisions of the privacy policy. We publish it as a separate page: https://www.globalsystempatterns.pl/gsp-app-polityka-prywatnosci.
The app is available in Polish only. Button and screen names are given as they appear in the app (in Polish), followed by an English translation in brackets.
Effective from: 19 September 2026
1. Who is responsible for your data
The controller of data in the app is GSP CLINIC PROKOPOWICZ sp. z o.o., ul. Kostrzyńska 12, 66-400 Gorzów Wielkopolski, Poland, NIP (tax ID) 5993255712, REGON 388639359, KRS 0001072367. The App Store and Google Play show the same details (name, address, e-mail, phone) as the app publisher's details. In this part of the policy, “we” and “GSP” mean this company.
Contact for personal data matters: [email protected], phone +48 791 671 531. The same address is the contact in the app (at the e-mail code and at account deletion), on the “Usuń konto w GSP app” (Delete account in GSP app) page, the reply address for e-mails from the app, and the contact listed in Google Play and the App Store.
We have not appointed a data protection officer (we are not required to — Article 37 GDPR). For personal data matters, contact us: [email protected], +48 791 671 531.
Who is responsible for which data.
- We (GSP) are responsible for your app account (profile, sign-in, record of your consents), for summaries sent automatically from your “To ja” (This is me) card, for private challenges, for shared norms and for the coach's data as our customer (account, subscription).
- The coach is responsible for data created in cooperation with them: the records on their phone, plans and their assignment, the plan log and plan notes, summaries they send manually, their squad group and its challenges and — from version 123 — your conversation. For this data we act on the coach's behalf and on the coach's instructions, as a processor. Direct requests about this data to the coach; if you write to us, we will pass them on to the coach and help handle them.
- After a coach's account is deleted, the data from the coach's scope that remains on your account (series archive, summaries — section 15) becomes our responsibility.
If a coach keeps your data on their phone. A coach can store, on their own phone, data about athletes — both those with an app account and those without one: first and last name, year of birth, sex, sport, training groups, body dimensions, results and notes (including about health). This is also how the coach keeps athletes under 16, who cannot have their own account (section 16). The coach can also download data from the VBT app to the phone, if they have access to it as your coach (section 5).
- The coach is responsible for data stored on the coach's phone. GSP cannot see it.
- The coach gives people without an account information about the processing of their data no later than one month after recording it. On the coach's request, we provide a ready-made template for this information.
- If you want to know what a coach has recorded about you, ask the coach.
2. In short: four places where data can be
- Phone. Most data (athlete records, measurements, video) stays on the phone of the person using the app.
- GSP APP cloud. Accounts, coach–athlete connections, measurement summaries, plans, messages, challenges and results for shared norms are stored in a Supabase database in the European Union (Frankfurt, Germany).
- VBT app. If you sign in with an account from the separate VBT app, GSP APP can download data from it to the phone. It does not write training data there.
- Stripe. We receive coach subscription data from the payment operator Stripe. We do not see card details.
The app has no advertising, no analytics tools and no crash reporting service of its own. We distribute the app through Google Play, as an installation file from the GSP website (Android), and through Apple TestFlight and the App Store (iPhone). Apple passes us crash reports and feedback from TestFlight, and Google passes us aggregate install and crash statistics from Google Play (section 11). We do not sell data. We do not send it to external artificial intelligence models.
3. Data on the phone
The app stores this data on the phone. Some of it also goes to the GSP APP cloud: the measurement summary (including automatically), days with a measurement in challenges, a training plan imported from a CSV or XLSX file and — if the athlete turns it on in their account — results for shared norms. See section 4.
- Athlete records: first and last name, year of birth, sex, sport, training groups (an athlete can be in several), RFID tag, body mass, height, leg length and other dimensions used in jump protocols.
- Coach notes about an athlete (up to 4,000 characters). They may contain information about injuries and health.
- Jump measurements: sessions, trials, raw mat readings and results (e.g. height, flight time, power, RSI — reactive strength index).
- Velocity-based training (VBT, bar velocity measurement): sets, reps, load, velocity, RPE (rating of perceived exertion — your rating of how hard the effort was).
- Readiness: HRV (heart rate variability), sleep, “body battery”, resting heart rate, well-being, previous-day RPE and a calculated readiness score. You enter them manually or import them from a file. The app does not connect to Apple Health or Health Connect.
- Maximum lifts, athletic measurements (e.g. resting heart rate, VO2max — aerobic capacity, sprint, long jump, MAS test — a 5-minute run from which the app calculates running pace) and badges. The app does not store the name of a “gość na dziś” (guest for today) in the MAS calculator.
- Body measurements: body mass and waist, hip, chest, arm, thigh and calf circumferences (arm, thigh and calf circumferences measured separately for the left and right side).
- Video (GSP Vision): technique recordings (from the camera, up to 2 minutes, or from the gallery), thumbnails, drawings on the recording, the coach's voice commentary and analysis videos. The bar path is calculated on the phone. Recordings are not uploaded to our server.
- Profile photo of the user (resized to 512 px).
- Settings and cache: consent settings, role, reminder time, last checked subscription status, the link between the account and the “To ja” (This is me) card, a copy of the last summary sent, the session of the connection with the VBT app, recording descriptions (including an athlete name typed in), the last checked access status (“zapis wstrzymany” (saving paused) or not) with a count of app launches, and a marker of an interrupted account deletion.
- Sign-in session: the app remembers the session so you do not have to sign in every time. It does not store your password.
- File imports (ChronoJump, Vitruve, VBT log): the file is read on the phone and not uploaded.
Reminders are scheduled by the phone itself, without a server. They may contain names of athletes with missing data. Depending on the phone's notification settings, the names may also be visible on the lock screen.
When data can leave the phone. Apart from the cases in section 4 — only when you choose to:
- Backup (“Kopia zapasowa — cała baza do pliku” (Backup — whole database to a file), and on the screen for a person without access — “Pobierz dane z telefonu” (Download data from the phone)):
- what it contains: all athlete records, notes and measurements in a single file;
- what it does not contain: video, the profile photo or settings;
- note: the file is not encrypted and goes wherever you send it (e.g. to a messenger, a cloud drive, by e-mail);
- who is responsible: from the moment it is sent — the person who sent it and the service they chose.
- Video: “Udostępnij” (Share) (recording, frame, analysis video) or “Zapisz w galerii” (Save to gallery) (album “GSP Vision”). From the gallery, a recording may be synced to a photo cloud if you have it enabled on your phone (e.g. Google Photos, iCloud Photos).
After sharing, a copy of the file stays in the phone's cache until the system clears it.
System backups. On Android the app disables automatic backup to the Google account, but when data is transferred by cable or directly from an old phone, it may move to the new phone. On iPhone, the app's data is excluded from iCloud backup.
Uninstalling the app deletes data from the phone. Without a prior backup it cannot be recovered, because we do not have it on our server.
4. Data in the GSP APP cloud (EU, Frankfurt)
The cloud is a Supabase database in Frankfurt (Germany). Database rules limit who can see data in the app. Details are in section 9.
Account
- An account is required to use the app. A coach account is created with “Pierwsze logowanie” (First sign-in) at the e-mail address for which the subscription was paid. An athlete account is created with a code from a coach.
- Saving paused. A coach without a valid subscription and an athlete without a connection with a coach who pays for them can see their data, download it and delete the account, but cannot save new data. Athletes of a coach who has deleted their account or stopped paying can still save for 30 more days (section 15).
- Age. When an athlete account is created, the app asks for the date of birth to check that you are at least 16 (section 16). We do not store the date of birth — neither on the phone nor in the cloud.
- E-mail and password (the password is stored in a form from which it cannot be read), date created and date of last sign-in.
- At sign-in we record the IP address and device or browser information. During other connections between the app and the cloud (sync, code check, sending norms, e-mail code, account deletion) the servers may record this information in technical logs (section 13). We use them only to protect accounts and fix faults.
- When you choose “Nie pamiętam hasła” (Forgot password), we e-mail you a one-time code. Whoever has access to the mailbox linked to the account takes over the account after changing the password, together with its history, including conversations — as with password recovery in other services. Keep your mailbox secure. When an athlete account is created, we do not send an e-mail asking to confirm the address.
- E-mail code (“Pierwsze logowanie” (First sign-in) and “Potwierdź adres e-mail” (Confirm e-mail address)). With this code a coach sets the password for their coach account (the account is created if it did not exist yet) or confirms that the account's address belongs to them. The code has 8 digits and works for 30 minutes, once. We do not store the code itself in the cloud, only a hash of it that cannot be reversed. To count requests and attempts, we store HMAC hashes of the e-mail address and the IP address — this is pseudonymous data. Codes, hashes and attempt records are deleted at the latest at the first clean-up after one day has passed (section 13). Entries that these functions add to the log themselves do not contain the e-mail address, code, password or IP address. If an athlete account already existed at that address, “Pierwsze logowanie” (First sign-in) turns it into a coach account: the account and its data remain, but we delete its connections with coaches (someone else may have given the consent to connect) and — from version 123 — its messages, on both sides of each conversation, and sign out all phones. The app says so on the “Pierwsze logowanie” (First sign-in) screen — after you set the password and before you enter the app.
- Confirmed address. After the e-mail code we record that the account's address has been confirmed: the account, the address, the date and the method of confirmation. Accounts that had a subscription before the codes were introduced and GSP founder accounts were marked this way once. A coach subscription works only on an account with a confirmed address (section 6). The record is deleted together with the account.
- Profile: first and last name (a single field, as you enter it) and sport — you can change them in the app — as well as role (athlete, coach or GSP founder) and account type.
Connecting with a coach (invitation code)
- The coach generates a code: GSP- and 8 random characters in two groups of four. The code has no expiry date and can be used many times until the coach generates a new one — the coach's previous codes then stop working. Codes in the old format (4 characters after GSP-) still work for a transition period, after which they will expire. Anyone who knows an active code can connect with the coach (after giving the consent in section 8) and join the coach's squad group.
- The coach can send an invitation (the code, their name and a link to the GSP page with the app) via a messenger of their choice. The app does not collect phone numbers or contacts.
- After 5 wrong codes within 15 minutes, code checking is blocked for 15 minutes. To count attempts, we store an HMAC hash of the account identifier or — without signing in — of the IP address (pseudonymous data, without the address itself). Attempt records are deleted after one day.
- Anyone who knows the code can check the first and last name of the coach who issued it, even without signing in. The app shows it before connecting, so you know who you are connecting with; a coach without a name entered cannot create a code.
- When you enter the code and give consent (section 8), we store the connection: who with whom, status and date of connection, and in the consent history — the consent with the version of its text and the server time. You also join the coach's squad group (the group name contains the coach's name).
Measurement summary (stored on your account in the cloud; visible to a connected coach)
- jumps: best and latest CMJ result (countermovement jump), number of days with jumps;
- latest readiness entry: date, well-being, sleep, HRV, “body battery”, resting heart rate, previous-day RPE;
- latest VBT set: exercise, load, best velocity, number of reps, total number of sets, date.
We do not send coach notes, body mass, circumferences or video.
When we send the summary
- If you point to your card in the athlete records in the app (the “TO JA — mierz siebie” (THIS IS ME — measure yourself) section: “Wskaż mnie w kartotece” (Point to me in the records) or “Nie ma mnie tam — załóż nową kartę” (I'm not there — create a new card)), the app itself sends the summary to your account in the cloud: after a new card is created, when the app starts and every time you return to it, if the data has changed. This happens only when you have an active connection with a coach. Without a connection and after disconnecting, the summary does not leave the phone; the database also rejects such summaries from older app versions. After updating to version 125, summaries are not sent until you respond to the consent card (section 8). You can send a summary immediately with the “Synchronizuj teraz” (Sync now) button, and stop the sending with the “To nie moja karta — odepnij” (This is not my card — unlink) button.
- A connected coach who measures an athlete personally can send a summary manually (the “Mierzę go sam — powiąż lokalny rekord” (I measure them myself — link local record) and “Wyślij mój pomiar do chmury” (Send my measurement to the cloud) buttons on the athlete's card).
Plans and conversations
- Training plans (name, description, exercises, sets, tempo, rest) and their assignment to an athlete, including plans imported from a CSV or XLSX file.
- Workout log: ticked sets, load, RPE (optional).
- Notes for a plan day (free text).
- Coach–athlete messages (from version 123): content (1–4,000 characters), sender and recipient, time sent and time read by the recipient (both server time), optionally a link to a plan (removed when the plan is deleted) and a shared marker for copies of one group message. The conversation is stored only in the cloud — the phone keeps no copy. The app shows the other person's name from their profile, only to people who share messages with them.
- You can only write to a person you have an active connection with. A coach's message to a group reaches each athlete separately, in their own conversation with the coach — athletes cannot see each other or each other's replies.
- After disconnecting, the conversation stays readable for both sides, but no one can write. While saving is paused (section 4) you can read but not write.
- Abuse protection: at most 300 messages per account per 10 minutes and 100 recipients at once.
- This version sends no phone notifications about new messages.
- In versions older than 123 messages cannot be sent.
You might write something about health in a note or message. Write only what is necessary.
Challenges
- Name, rules, measurement area, dates, participants, starting result (e.g. current jump result from the phone), date joined and ticked days. The app adds days with a measurement automatically when a challenge is opened.
- Group challenge board: timeline of days, reactions, ready-made comments, board events and short messages from the coach.
- A challenge is created in the coach's squad group and only people in that group can see it. Someone without a group creates a private challenge, visible only to themselves. There are no challenges open to all users.
- The author can delete a challenge. The ticks, reactions and board of all participants then disappear.
Shared result norms (optional)
Taking part in norms is a separate, voluntary consent of the athlete themselves: the “Udział w normach GSP” (Take part in GSP norms) switch in their account, off by default. When turning it on, you confirm that you are at least 16. A coach cannot give this consent on the athlete's behalf, but can see whether the athlete has it turned on. After each valid trial (mat jump, long jump) we send the result only of an athlete who has an account and has the consent turned on — also when a coach measures them on the coach's phone. Before sending, the phone asks the cloud whether the consent is on, giving the account identifier (without the result). We do not send results of athletes without an account or of people under 16.
For norms we record: test type, result (rounded to 0.5 cm), month of measurement, sex, age band and sport — without the account or phone identifier. We do not keep a link between the record and the account. We accept at most 30 results per account per day; to count this, we keep a daily counter with the account identifier until the next day at the latest. The sending takes place within your sign-in session, so the server may note it in technical logs (section 13).
The norms database also contains 12 older results, sent before this change, when participation was decided by a switch on the coach's phone: they have the full date and an unrounded result, and 6 of them have no age band; they cannot be linked to an account.
We use this data to calculate norms, e.g. percentile (what share of results in the same group is equal to or lower than a given result). We do not currently make norm summaries available in the app.
Because we do not keep a link between the record and the account, we cannot identify or delete your records on request. Even so, we protect them as personal data.
5. Data downloaded from the VBT app
GSP APP can connect to the separate VBT app (its database is also in Frankfurt).
- You sign in with the e-mail and password from that app. Sign-in details go only to that app. GSP APP does not store the password; it keeps only the session on the phone.
- GSP APP downloads to the phone the data your VBT account has access to: name, role, sport, body mass, date of birth, sex, sessions (with RPE and note), sets, reps, daily readiness (sleep, HRV, “body battery”, resting heart rate, RPE, well-being), maximum lifts, blocks and plans, additional training units and athletic measurements.
- If you sign in with a coach account from the VBT app, GSP APP will also download to the phone the data of that coach's athletes that the account can access.
- GSP APP does not write any training data to the VBT app. Signing in only creates a session there (as with any sign-in).
- Downloaded data stays on the phone as described in section 3. If the athlete's profile is linked to a GSP APP account, the latest readiness entry and latest VBT set may be included in the summary described in section 4.
Data in the VBT app itself is the responsibility of that app's operator, under the privacy policy of that app.
6. Coach subscription
- Stripe sends us: the payer's e-mail, Stripe customer and subscription identifiers, status and expiry date. We store them in the GSP APP cloud.
- The subscription is matched to an account by e-mail address. It works — and the subscription entry (status, expiry date, Stripe identifiers) is visible to the person signed in to that account — only if the account's address has been confirmed with an e-mail code (section 4). If your account's e-mail address changes, write to us to keep the link.
- Deleting the account does not cancel the subscription in Stripe (section 15).
- The app only checks whether the subscription is valid and until when. It remembers the last result on the phone so it can work for a short time without internet.
- The data you enter in the payment form (e.g. card details and e-mail address) is processed by Stripe. For payment data, Stripe is a separate controller (section 11). Stripe privacy policy: https://stripe.com/privacy
- Invoices: issued by GSP's accounting on the coach's request. The coach sends the invoice details (including the tax ID) by e-mail to [email protected].
Athletes do not enter payment details in the app.
7. Where data comes from
- From you: account, profile, measurements, messages, notes.
- From your phone, automatically: the measurement summary and days with a measurement in challenges (section 4).
- From the coach: athlete records, notes and measurements entered on the coach's phone, plans, summaries sent manually.
- From files you choose: ChronoJump, Vitruve, VBT log, a plan in CSV or XLSX.
- From the VBT app: after signing in with an account from that app (section 5).
- From Stripe: coach subscription data (section 6).
- From Apple and Google: TestFlight testers' crash reports and feedback, and aggregate install and crash statistics from Google Play (section 11).
8. Health and fitness data
Some data in the app is health data (Article 9 GDPR): HRV, resting heart rate, sleep, well-being, RPE, VO2max, body mass and circumferences, notes about injuries. We treat jump results, velocity-based training (VBT) results and RPE the same way — we protect them as health data.
- Of this data, the cloud receives the summary from section 4 (jumps, readiness, latest VBT set) and whatever you enter in the plan log, notes, messages and challenges.
- The summary goes to the cloud only when you have an active connection with a coach: when you link your card (“To ja” (This is me)) or when a connected coach sends it manually.
- Every time you connect with a coach, the app shows the “Zgoda na dane o zdrowiu” (Consent to health data) card with the coach's first and last name and a list of what the coach will see: jump results and velocity-based training results, readiness (HRV, sleep, resting heart rate, Body Battery, well-being, RPE), plan log and plan notes, participation in the challenges of the coach's squad and your conversation. The consent box is not ticked in advance, and the “Połącz” (Connect) button works only after it is ticked. From version 125, the connection is not created without consent. Connections from earlier versions are confirmed with a one-time card in the new version of the app — with the choice “Zgadzam się” (I agree) or “Rozłącz z trenerem” (Disconnect from coach). Until you respond, the new version does not send your measurement summaries to the coach. Two exceptions, which we will close in later versions: older versions of the app (up to 124) still connect without the card and send summaries without asking for consent, so please update the app; and if the coach measures you on their own phone, in the meantime they can send a summary of that measurement under your account. We record the consent in the consent history (type, version of the text, server time) and keep the text of each consent version separately. This is your explicit consent to the processing of health data (Article 9(2)(a) GDPR).
- What is required and what is optional. The consent on the connection screen covers only what the app cannot work without: the connected coach's access to your results, because that is why you connect with them. Anything beyond that you give separately and can refuse without any effect on your use of the app: taking part in norms (section 4) and any future use of data for another purpose, e.g. research.
- An athlete account is created with a code from a coach and from the age of 16. At present it is not possible to start using the app as an athlete without a connection with a coach.
- We use this data only to provide the service to you and your coach. We do not use health and fitness data for advertising, marketing, commercial profiling or data mining for purposes unrelated to the service. We do not sell it. The only aggregate use is shared norms (section 4), with the consent of the athlete themselves. For any other use, including research, we will ask for separate consent.
9. Who can see data in the cloud
- You: your account, profile, summaries, plans, messages and, as a coach, your subscription entry.
- A coach you connect with: your profile (first and last name, sport, role, account type) and all summaries stored on your account — including those from a time when you were connected with another coach. A connected coach can also change and delete them. The coach also sees your plan log, plan notes, your conversation (from version 123) and whether you have taken part in GSP norms turned on. After disconnecting, the coach's access to this data ends immediately.
- An athlete: their coach's profile (first and last name, sport, role and account type).
- Members of the squad group (anyone who entered an active coach code): the group name (with the coach's name), its membership (account identifiers) and, in that group's challenges: your starting result, date joined, ticked days, reactions, chosen ready-made comments and board events (e.g. a group day, a record with a result). After you disconnect from the coach, you stay in the coach's squad group until you leave it yourself or the coach removes you; your participation in that group's challenges then remains visible to the group.
- A private challenge (when you have no squad group) is visible only to you.
- GSP founders have no access in the app to your data or to the list of connections, unless they are your connected coach. The database provides for founders to see the profile and summaries of an athlete who gives separate consent for this; the current app does not offer such consent.
- GSP technical administrators (people with access to the database dashboard) have technical access to all data in the cloud, including messages and summaries. They use it only to maintain the service, fix faults and handle your requests. Two people — the GSP founders — have access to the database dashboard.
- Messages: in the app they are visible only to the sender and the recipient. We do not read conversations; only the database administrator has technical access (see above).
- Anyone, even without an account: a coach's first and last name, if they know the coach's code.
- Norms: we do not currently make norm summaries available to anyone in the app (section 4).
- Providers listed in section 11, to the extent needed to run the service.
- Public authorities, when required by law.
10. Consents and how to withdraw them
Consent to health data and connection with a coach. How to withdraw: the “Rozłącz” (Disconnect) icon next to the coach — withdrawing consent means disconnecting. The coach can also disconnect. What happens: the coach immediately loses access to your data in the cloud and receives no new summaries. We record the date the consent was withdrawn. What the coach has already recorded in their own records on their phone stays with them (the coach is responsible for that data, section 1). Summaries sent earlier remain on your account and will also be visible to the next coach you connect with; we will delete them at your request (section 14). After disconnecting, you stay in the coach's squad group until you leave it yourself or the coach removes you; your participation in challenges then remains visible to the group. You will find your consent history in the “Pobierz swoje dane” (Download your data) file. Note: without a connection with a coach who pays for access, saving in the app is paused (section 4).
Automatic sending of summaries (“To ja” (This is me)). How to stop: the “To nie moja karta — odepnij” (This is not my card — unlink) button. What happens: the app stops sending summaries. Disconnecting from a coach also stops the sending.
Shared norms. How to withdraw: turn off the “Udział w normach GSP” (Take part in GSP norms) switch in your account. What happens: new results are not sent; results sent earlier remain, because they cannot be identified (section 4).
Taking part in a challenge. How to leave: the “Rezygnuj” (Leave) button next to the challenge. What happens: you are removed from the participant list, and your ticked days and board entries in that challenge are deleted. You can also undo today's tick without leaving.
Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
11. Providers and transfers outside the EEA
Providers acting as processors process data only on our instructions, under those providers' standard data processing agreements, and must protect it at least as well as described in this policy.
Supabase Inc.
- Role: processor.
- Purpose: database, sign-in and server functions: the e-mail code (“Pierwsze logowanie” (First sign-in), “Potwierdź adres e-mail” (Confirm e-mail address)), checking invitation codes, account deletion and receiving payment notifications.
- Data: all data in the GSP APP cloud.
- Location: database in Frankfurt (EU). Server functions called from the app run in the eu-central-1 region (Frankfurt). The function that receives payment notifications from Stripe may run in another Supabase region, including outside the EEA — this then concerns subscription data (section 6). Supabase sub-processors operate in locations including the USA.
- Transfer mechanism: standard contractual clauses in the data processing agreement.
Resend Inc. (sending via Amazon SES)
- Role: processor.
- Purpose: system messages — the password reset code (“Nie pamiętam hasła” (Forgot password)), the code for “Pierwsze logowanie” (First sign-in) and “Potwierdź adres e-mail” (Confirm e-mail address), and the account deletion confirmation.
- Data: recipient's e-mail address, message content (the code; for account deletion — the date, account type, what was deleted and what remains, and for a coach the subscription status and its date), sending logs. Messages do not contain health data, athlete names or Stripe numbers.
- Location: sent from Ireland, US company.
- Transfer mechanism: EU-US Data Privacy Framework and standard contractual clauses.
Stripe (Stripe Payments Europe, Ireland; US group)
- Role: separate controller of payment data (card data, fraud prevention, Stripe's legal obligations); for the subscription data it passes to us — processor. Stripe policy: https://stripe.com/privacy
- Purpose: coach subscription payment.
- Data: payment and subscription data.
- Location: Ireland and USA.
- Transfer mechanism: EU-US Data Privacy Framework or standard contractual clauses.
Apple (TestFlight and App Store)
- Role: separate controller of data collected when the app is downloaded and in TestFlight. Apple policy: https://www.apple.com/legal/privacy/
- Purpose: distribution of the app for iPhone. In TestFlight, Apple collects from testers e.g. e-mail address and name, crash reports and feedback, and passes the reports and feedback to us.
- Location: Ireland and USA.
- Transfer mechanism: EU-US Data Privacy Framework.
Google (Google Play)
- Role: separate controller of data collected when the app is downloaded from Google Play. Google policy: https://policies.google.com/privacy
- Purpose: distribution of the app for Android. Google passes us aggregate install statistics and crash and stability reports (Android vitals) — without names and without data entered in the app.
- Location: Ireland and USA.
- Transfer mechanism: EU-US Data Privacy Framework.
Cloudflare
- Role: processor.
- Purpose: hosts the Android installation file.
- Data: IP address and device information when the file is downloaded.
- Location: Cloudflare's server network, including outside the EEA; US company.
- Transfer mechanism: EU-US Data Privacy Framework.
When data is transferred outside the EEA, we rely on the GDPR mechanisms listed for each provider: a European Commission decision (EU-US Data Privacy Framework) or standard contractual clauses included in the providers' data processing agreements. On request, we will send you information about these legal safeguards (e.g. a copy of the contractual clauses).
12. Legal bases and whether you must provide data
When we process data on the coach's behalf (section 1), the legal basis is the coach's, and we act on the coach's instructions as a processor. Our own legal bases:
- Account, sign-in, password change: performance of a contract (Article 6(1)(b) GDPR).
- Plans, workout log, plan notes, challenges in the squad group and the conversation: we process them on the coach's behalf (section 1). The coach relies on the contract with you (Article 6(1)(b) GDPR) and, for health data, on your explicit consent from the connection screen (Article 9(2)(a) GDPR, section 8), which we also collect in the app on the coach's behalf.
- Summaries sent automatically from the “To ja” (This is me) card and private challenges: performance of a contract (Article 6(1)(b) GDPR) and your explicit consent from the screen for connecting with a coach (Article 9(2)(a) GDPR, section 8).
- Shared norms: separate consent of the athlete (Article 6(1)(a) and Article 9(2)(a) GDPR).
- Coach subscription: contract (Article 6(1)(b) GDPR) and tax obligations (Article 6(1)(c) GDPR).
- Account security, logs (IP address, device) and counting invitation code attempts: our legitimate interest in protecting accounts and the service (Article 6(1)(f) GDPR).
- Age check when an athlete account is created: performance of a contract and the obligation under Article 8 GDPR (Article 6(1)(b) and (c) GDPR); we do not store the date.
- Establishing and defending legal claims: our legitimate interest in being able to show how we provided the service (Article 6(1)(f) GDPR and, for health data, Article 9(2)(f) GDPR).
E-mail and password are required to use the app; a coach also needs an active subscription, and an athlete — a connection with a coach and being at least 16. All other data (measurements, notes, messages, photo) is provided voluntarily.
13. How long we keep data
The cloud deletes some auxiliary data itself during clean-up — which is why the periods below say “at the latest at the first clean-up after…”. A full clean-up (the information for a coach about a deleted account, the deadline for athletes of a deleted coach, subscription entries without an account, and e-mail codes and attempt records) runs on every payment notification and every account deletion. E-mail codes and attempt records alone are also cleared by every e-mail code request. Clean-up also runs on its own, every day. Other data is not deleted automatically. The following rules currently apply:
- Account, profile, plans, messages, challenges: until the account is deleted.
- Measurement summaries: until the account is deleted or until deleted at your request. Disconnecting from a coach does not delete them.
- Connection record: while the connection lasts.
- Consent history (consent to health data and to taking part in norms: type, version of the text, time given and withdrawn): until the account is deleted. The texts of successive consent versions (without personal data) are kept without a time limit.
- Invitation codes: until the coach's account is deleted.
- Subscription entry in the GSP APP cloud (e-mail, Stripe identifiers, status, expiry date): as long as an account with that address exists. An entry without an account is deleted when the Stripe subscription ends, and at the latest at the first clean-up after 60 days from the end of the validity period.
- Invoices and payment data: at Stripe and in GSP's accounting for the period required by tax and accounting law — 5 years from the end of the year in which the tax obligation arose.
- E-mail code, its hash and records of requests and attempts (HMAC hashes of the e-mail address and IP address): at the latest at the first clean-up after one day.
- Confirmed address record: until the account is deleted.
- Records of failed invitation code attempts (HMAC hashes of the account or IP address): up to one day.
- Date of birth given when creating an account: not stored.
- Information for a coach that an athlete's account has been deleted (without a name): at the latest at the first clean-up after 90 days; the coach can hide it earlier.
- The date until which athletes of a deleted coach can record new measurements: at the latest at the first clean-up after 30 days from that date.
- Archive of sets from a deleted coach's plans: on the athlete's account, until that account is deleted.
- Server technical logs (IP address, device): the database provider deletes them automatically, currently after about one day. The sign-in event log (including the IP address) is kept by the database provider's sign-in system; we do not currently delete it automatically.
- Database backups: in our current database service plan we do not use database backups.
- Daily counter of results sent to norms (with the account identifier): until the next day at the latest.
- Norm records: no deletion period (they are not linked to an account).
- Data on the phone: until deleted in the app or the app is uninstalled.
14. Your rights
You have the right to:
- find out what data we hold and get a copy;
- have incorrect data corrected;
- have data erased;
- ask us to stop using the data (restriction of processing);
- receive the data you provided to us and that we process on the basis of consent or a contract in a file you can pass on to someone else (data portability);
- object to the use of data for purposes described as our legitimate interest (section 12);
- not be subject to a decision based solely on automated processing (section 19);
- withdraw consent at any time.
In the app you can change your first and last name and sport, set a new password (“Nie pamiętam hasła” (Forgot password)), unlink your “To ja” (This is me) card (stops sending summaries), disconnect from a coach, leave a challenge, undo today's tick, turn off participation in norms, back up data from the phone, download your data as JSON and CSV files (“Pobierz swoje dane” (Download your data) — athlete account; the file also contains your consent history) and delete your account (“Usuń konto” (Delete account), section 15).
- For anything else, write to [email protected]. Send the request from the e-mail address linked to the account; if in doubt, we will ask for additional confirmation of identity.
- We will reply within one month. In complex cases this may be extended by a further two months — in that case we will tell you.
- On request, we will delete your summaries from the cloud and provide, as JSON or CSV files, a copy of cloud data not included in the “Pobierz swoje dane” (Download your data) file (e.g. the coach's plans and messages, the history of sharing your data with GSP founders).
- Data stored only on a coach's phone is kept by the coach. Contact the coach about it (section 1).
You can lodge a complaint with the President of the Personal Data Protection Office (UODO) (ul. Stanisława Moniuszki 1A, 00-014 Warsaw, Poland, also via ePUAP or biznes.gov.pl) or with the supervisory authority in the country where you live or work.
15. Account deletion
In the app. You can delete your account yourself: athlete — Konto (Account) → TWOJE DANE (YOUR DATA) → “Usuń konto” (Delete account); coach and GSP founder — Konto (Account) → TWOJE KONTO (YOUR ACCOUNT) → “Usuń konto” (Delete account). A coach without active access also finds “Usuń konto” (Delete account) on the screen shown instead of the app after signing in. You type the word USUWAM and tap “Usuń konto na zawsze” (Delete permanently). The account and cloud data are deleted immediately, and the account cannot be restored. Deletion always works — also without an active subscription and while saving is paused.
The account deletion process is also described at https://www.globalsystempatterns.pl/gsp-app-usun-konto.
On request. You can also write to us (section 1) from the e-mail address linked to the account. We will reply to the account's address asking you to confirm with the word USUWAM, and after confirmation we will delete the account in the same way as the app does — no later than one month after the request, usually immediately. The same applies if you have an older version of the app without “Usuń konto” (Delete account).
Athlete account — deleted immediately:
- the account, the confirmed address record and the profile;
- connections with coaches and group membership;
- measurement summaries and plan assignments with recorded sets and the workout log;
- messages and plan notes — they also disappear for the coach;
- participation, ticks, entries and reactions in challenges, and challenges you created without other participants;
- consent records, including proof of giving and withdrawing consent;
- on the phone from which you delete the account: your card with measurements (if there are no other cards on the phone), profile photo, sign-in data, the connection with the VBT app, reminders and files with downloaded data.
Athlete account — what remains:
- your card in the coach's records, on the coach's phone — until the coach deletes it; you can ask them to;
- information for the coach that the account has been deleted (without a name) — at the latest until the first clean-up after 90 days, or earlier if the coach hides it (section 13);
- challenges you created that have other participants — no longer linked to your account;
- on a phone with other cards — your card, unlinked from the account; the phone's owner deletes it.
Coach and GSP founder account — deleted immediately:
- the account, the confirmed address record and the profile;
- invitation codes and connections with athletes;
- plans with exercises and assignments, and with them workout logs;
- plan notes and messages — they also disappear for athletes;
- your challenges and groups without other people;
- with a confirmed address: a subscription entry granted manually or already ended.
Coach and GSP founder account — what remains:
- sets and loads recorded by athletes in your plans — as an archive on their accounts, in the “Pobierz swoje dane” (Download your data) file;
- summaries you sent to athletes — on their accounts, no longer linked to you;
- groups and challenges with other people — the group named “Kadra” (Squad), without your name; challenges no longer linked to you;
- a subscription entry that is ongoing in Stripe or was not linked to a confirmed account address (section 13);
- on your phone, all athlete records and recordings — you are responsible for them.
If your access was paid, your athletes can record new measurements for up to 30 more days after it ends (after a GSP founder account is deleted — for 30 days). During that time they can connect with another coach.
In both cases the following also remain:
- an HMAC hash of the account's address in the record of e-mails sent after deletion — pseudonymous data from which the address cannot be recovered; it is needed so that the same address does not receive more than three such e-mails a day. We delete it at the latest at the first clean-up after one day (section 13);
- invoices and payment data — at Stripe and in GSP's accounting for the period required by tax law (5 years from the end of the year in which the tax obligation arose);
- norm records, because they are not linked to the account;
- aggregate entries on challenge boards;
- technical logs and the sign-in event log with the IP address (section 13).
E-mail after deletion. We send an e-mail with a summary to the account's address: what we deleted and what remains, and for a coach the subscription status. If the daily sending limit has been reached, the account is still deleted; only the e-mail is not sent.
Subscription. Deleting the account does not cancel the subscription in Stripe. The e-mail sent after account deletion says whether the subscription renews and how to end it yourself in the Stripe customer portal; you can also write to us (section 1).
16. Minors
Who can have an account. A person who is at least 16 can create their own athlete account. When the account is created, the app asks for the date of birth; we do not store it. If you are under 16, the account will not be created — a coach can keep your results in their records on their phone (section 1). We check age based on your declaration, without documents — like other sports apps. The app does not ask for age when signing in to an existing account or when connecting with a code from such an account. A person who is at least 16 gives consents in the app on their own, including consent to health data (Article 8 GDPR).
Younger athletes in the coach's records. Data of people under 16 stays on the coach's phone and the coach is responsible for it; the coach should have the consent of a parent or legal guardian. Their results are not sent to shared norms.
An account created by a person under 16. If we learn about it, we will delete it.
Parent's rights. A parent or legal guardian may exercise the rights in section 14 on the child's behalf.
In short for athletes aged 16–17. Your summaries are seen only by the coach you connect with. Your challenge results are seen only by people in your squad group. You can delete your account in the app or ask us to delete your data at any time.
17. Security
What we do:
- the connection between the app and the server is encrypted (HTTPS);
- database rules limit access to data in the cloud;
- passwords are stored in a form from which they cannot be read;
- video and the profile photo are not uploaded to the server;
- on Android we disable data backup to the Google account, and on iPhone we exclude the app's data from iCloud backup;
- the invitation code has 8 random characters, and after 5 wrong attempts within 15 minutes code checking is blocked for 15 minutes.
What you need to watch out for:
- the app does not add its own encryption to data on the phone, so use a screen lock;
- the backup file is not encrypted, so send it only to a secure place;
- the invitation code has no expiry date and works many times, so give it only to your athletes; if it reached the wrong person, generate a new one — the previous one will stop working.
Personal data breaches: we have an internal procedure. We report a breach to the President of the Personal Data Protection Office (UODO) within 72 hours of becoming aware of it, and if it may pose a high risk to you, we also notify you.
18. Phone permissions
- Camera: recording technique and taking a profile photo.
- Microphone: sound of the recording and the coach's voice commentary. The app does not recognise speech and does not upload recordings.
- Photos and gallery: choosing a recording or profile photo, saving an analysis to the gallery.
- Storage write (older Android versions): saving a video analysis to the gallery.
- Notifications: local reminders.
- Start after reboot (Android): so that reminders also work after the phone is restarted. The app does not use exact alarms, so a reminder may arrive a few minutes late.
- Bluetooth and location: the app does not use them.
You can turn off each permission in your phone settings; the feature that needs it will then stop working.
19. Automated calculations
On the phone, the app calculates a readiness score, jump results, bar path and hints from the jump profile. In the cloud we calculate summaries from norm results (e.g. percentile); we do not currently make them available in the app. These are suggestions for the coach and the athlete. The app does not make automated decisions that have legal or similarly significant effects on you.
- The readiness score compares entered or imported values with your own baseline (the average of recent entries, at most 14; at least 4 are needed) and combines them using fixed weights in three groups: neuromuscular results (e.g. jump, velocity), autonomic indicators (e.g. HRV) and subjective rating.
- The percentile indicates what share of results in the same group (test, sex, age band, sport) is equal to or lower than your result.
- Mat jump height is calculated from flight time, so the result depends on landing technique and measurement accuracy.
The app contains a model for body posture analysis on recordings, but the current version does not use it.
20. Not a medical device
GSP APP is a training tool. It is not a medical device and does not diagnose or treat. Indicators (readiness, HRV, jump profile, MAS pace) are for guidance only. For health matters, consult a doctor.
21. Changes
We publish changes to this part of the policy on this page with a new date. We will inform you of significant changes before they take effect — by e-mail to the account address or in the app. Previous versions of this part of the policy are available on request. If a change concerns the scope of consent or we want to use data for a new purpose, we will inform you first and, where required, ask for your consent.