Privacy notice
Last updated: 18 September 2026 · portfolio / student demo — not a commercial shop, no company number
1. Controller
Lennaert De Schepper, natural person · student AI & Data Engineer. Flanders, Belgium. portfolio / student demo — not a commercial shop, no company number.
There is no company (KBO) or VAT number. Contact: lennaert.de.schepper@gmail.com
2. Data we process (minimum)
- Account (when you register): email, display name, password hash (Argon2)
- Training and recovery files you upload (for example a workout CSV, or sleep rows derived from an Apple Health export). These can be health-related data (GDPR Art. 9).
- Public demo: anonymous aggregates only — no session titles, no names, no set-by-set log.
- Sleep window and nights you log (bed, wake, optional quality). Browser notifications for wind-down / bedtime if you allow them. We do not record microphone audio.
We do not sell personal data. Insights are educational, not medical care or a medical device.
3. Purpose and legal basis
Running the demo (account, analysis, portfolio). Legal basis: contract for an account (Art. 6(1)(b) GDPR). For health-related uploads: explicit consent (Art. 9(2)(a)), given at registration before upload. Security of the demo: legitimate interest. No ad trackers.
4. Sharing and retention
Hosting is local or a later always-on platform (EU where possible). Your uploads and set-by-set history stay on your account. Demo aggregates are public and contain no identifiable workouts. Display names on the signed-in leaderboard are visible to other signed-in users. A private profile still appears on the board; the PR page is friends-only.
Delete account / export: signed-in users use Account (export JSON, delete). You can also email lennaert.de.schepper@gmail.com.
5. Your rights
Access, rectification, erasure, restriction, portability, and objection — via email. Complaint: Belgian Data Protection Authority (GBA), Drukpersstraat 35, 1000 Brussels.
6. Processors / third parties
- Railway — Optional always-on hosting when the hub is deployed. Prefer an EU region. Not used until G10.
- Sentry — Optional error reporting, only if NEXT_PUBLIC_SENTRY_DSN is set. No ad trackers; do not send tokens or health payloads in breadcrumbs.