Cran · com.auzzhh.cran
Privacy Policy
Last updated: 22 September 2026
Language: English · Français · Español
This policy covers the Cran app (package
com.auzzhh.cran), published on Google Play by the developer
Auzzhh. It covers no other product, and no other app with a
similar name.
The short version
- No ads, no ad networks, no third-party trackers, no advertising ID.
- Your data is never sold, rented or traded, to anyone.
- A Google account is required to open the app: it exists so your sessions follow you to another phone, nothing else.
- Training data is hosted in the European Union (Ireland).
- The photos you add to programmes and WODs never leave your phone.
- You can erase everything from inside the app, in one action, without writing to us.
1. Who is responsible
Auzzhh, an independent developer, is the data controller under the GDPR.
- Contact: support@kaltech.work
There is no data protection officer: the app is built by one person, and that address is the one that answers.
2. What the app collects
a. Your account
When you sign in, Google passes us your email address, your name and the address of your profile picture (a link to Google's servers, not the file). We never receive your Google password. Inside the app, only your email address is shown, on the Settings screen.
| Why | To recognise your account and give you your data back on any phone. |
|---|---|
| Legal basis | Performance of a contract — the app does not work without an account. |
| Retention | Until you delete your account. |
b. Your training data
What you enter in the app is stored on your phone and synced to the server:
- your exercises and one-rep maxes, and the history of the loads you log;
- your body weight, if you log it;
- your WOD results, your own WODs and your favourites;
- generated programmes and your progress through them;
- your saved timers, your weekly goal and your settings.
| Why | This is the product: tracking your progress and finding it again on another phone. |
|---|---|
| Legal basis | Performance of a contract. For body weight and performance figures, which count as health data: your explicit consent, given by choosing to log them. Nothing requires you to, and the app works without. |
| Retention | Until you delete them, or until you delete your account. |
c. Anonymous usage measurement
To know which features actually get used, the app records technical events. How they are built makes it impossible to tie them back to you:
- a randomly generated installation identifier, specific to this install of the app, never your account;
- the event name, taken from a closed list (for example "a timer was started", "a programme was generated") — a name outside that list is rejected by the database;
- the date of the event.
The table that receives them has no account column at all: cross-referencing is not merely forbidden, it is technically impossible. No content is recorded — not your WOD's name, not your loads, not any text you wrote.
| Why | To decide what to improve, and to know whether a feature is useful to anyone. |
|---|---|
| Legal basis | Legitimate interest — the measurement is anonymous and allows neither profiling nor targeting. |
| Retention | 13 months, then automatic deletion. |
3. What the app does not collect
- No location: the app never asks for location access.
- No contacts, no address book, no SMS, no call logs.
- No advertising identifier, no ad SDK, no tracking pixel.
- No microphone, no camera: both permissions are explicitly disabled in the app.
- Your photos stay put. When you pick an image from your gallery for a programme or a WOD, it is resized and copied into the app's private folder on your phone. It is sent to no server and goes into no share code: whoever you share a plan with sees the default artwork.
- No remote notifications. Training and weigh-in reminders are scheduled locally by your phone. No notification token is created, and no server can push anything to you.
4. Who else sees this data
Two processors, and no others:
| Processor | Role | Where |
|---|---|---|
| Supabase | Database and authentication: where your account and training data live. | European Union — Ireland (AWS infrastructure) |
| Sign in with Google, and app distribution through Google Play. | Ireland, with processing in the United States |
No payment provider is connected today: nothing can be bought inside the app.
We pass data to nobody else, unless the law compels us to through a request from a competent authority.
5. Transfers outside the European Union
Your training data stays in Ireland. Signing in with Google involves Google LLC, some of whose processing happens in the United States; it is covered by the European Commission's standard contractual clauses and by the EU–US Data Privacy Framework.
6. Deleting your data
Two actions, both under Settings, inside the app:
- Reset all data empties your training data and keeps your account.
- Delete my account erases the account and everything attached to it, on the server and on the phone. It is permanent, and there is no backup to call back.
Anonymous usage measurement is not affected: attached to no account, it cannot be found in order to be deleted. It disappears on its own after 13 months.
Step-by-step instructions are on the Data deletion page.
7. Your rights
The GDPR gives you rights of access, rectification, erasure, portability, objection and restriction, and the right to withdraw your consent. The app gives you erasure in one action; for everything else, write to support@kaltech.work and we answer within one month.
If our answer does not satisfy you, you can complain to the French CNIL, or to the data protection authority of your own country.
8. Security
- All traffic goes over HTTPS.
- Every table on the server enforces row-level security: a request made with your account can only read your rows. That is not a rule in the app's code, it is a rule in the database — a modified app would change nothing about it.
- Your session is kept in the app's private storage, on your phone.
No system is invulnerable. In the event of a data breach likely to affect you, we notify the competent authority and the people concerned within the deadlines the GDPR sets.
9. Children
Cran is not aimed at children and has no content designed for them. We do not knowingly collect data about anyone under 16. If that has happened, write to us: the account and its data will be deleted.
10. Health
Cran is a training log, not a medical device. It makes no diagnosis and does not replace the advice of a health professional.
11. Changes
This page changes when the app does. The date at the top marks the latest version. A change to what we collect is announced inside the app, in the release notes.