DE EN
This is a courtesy translation. The German version is legally binding.
Privacy Policy
Last updated: July 2026 · in accordance with the GDPR and the Austrian Data Protection Act (DSG)
1. Controller
Oliver Schwarzbauer
Pohn 11, 4841 Ungenach, Österreich
UID: ATU83281379
E-Mail: support@peakora.at
2. This website (peakora.at)
This website provides information about the Peakora app. It uses no cookies, no tracking and no analytics tools.
- Server log files: When you visit, the web server (Hetzner Online GmbH, Germany) necessarily processes your IP address, date/time, the requested file and the user agent in server logs. Legal basis: legitimate interest (operation and security, Art. 6(1)(f) GDPR). Logs are not combined with other data and are deleted regularly.
- Photos and graphics on this website are served entirely from our own server — no content is loaded from third-party CDNs.
- AI-generated content: The photos on this website were created with an AI image model and are labelled as such (Art. 50 EU AI Act).
3. The Peakora app (app.peakora.at)
The app stores training profiles, plans, goals and performance data entirely locally on your device (localStorage or app storage). Unless you actively use the optional services, your data does not leave your device.
3.1 Account (registration)
When you register, we store your email address and a secure password hash (Argon2id) on our server in the EU (Hetzner, Germany). Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
3.2 AI coach (optional)
- The coach chat uses an AI language model from Mistral AI (France, EU).
- We have a data processing agreement (Data Processing Addendum) with Mistral AI pursuant to Art. 28 GDPR — all processing takes place within the EU and your data is not used to train AI models.
- All requests run through our EU proxy server, which automatically removes names, places, addresses, email addresses, phone numbers and location data before transmission. The AI never receives your personal data.
- No chat content is logged permanently.
- AI-generated answers are labelled as such in the app (Art. 50 AI Act).
- Legal basis: consent through active use (Art. 6(1)(a) GDPR).
3.3 Strava connection (optional, with consent)
- By connecting, you consent to us reading your Strava activities (scope: read activities).
- Access tokens are stored exclusively on our EU server.
- You can withdraw consent at any time via "Disconnect" in the settings — your tokens are deleted immediately (Art. 17 GDPR).
- Recipient: Strava Inc., USA (standard contractual clauses pursuant to Art. 46 GDPR).
3.4 Location for route suggestions (optional)
Your location is only queried with your consent, stored exclusively locally and only sent to our EU server to calculate loop routes. Coordinates are neither stored nor logged there. Map tiles come from OpenStreetMap (external service: OpenStreetMap Foundation, UK).
3.5 Payment processing
Payments are processed via Stripe (Stripe Inc., USA/EU subsidiary). Stripe's privacy policy applies; we do not receive any credit card details, only the payment status.
4. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). Since your training data is stored locally on your device, you can delete it completely yourself at any time (reset app data / uninstall). You have the right to lodge a complaint with the Austrian Data Protection Authority (dsb.gv.at).
5. Hosting
The website, app and API are hosted by Hetzner Online GmbH (Germany, EU). A data processing agreement pursuant to Art. 28 GDPR is in place.