Lufa

Privacy Policy

Last updated 10 September 2026

Lufa has no accounts and no user database. The plan you build on this website is calculated in your browser and handed to the app through the link you open; your runs are recorded on your phone and stay there. This policy says exactly what leaves the device, who receives it, and why.

1. Who is responsible

Ralf Pitter, Siechenstrasse 60, 96052 Bamberg, Germany — contact hi@pitterapps.com. Full details are in the legal notice.

This policy covers the website lufa.run and the Lufa app for iOS and Android.

2. The short version

  • No account. You never create one, so there is nothing to sign in to and nothing for us to look up.
  • No user database. The funnel on this website stores your answers in your own browser. Our servers keep no copy.
  • Your runs stay on your phone. Times, distances, feedback and your plan are stored in the app's own storage on the device.
  • Your route is never recorded. GPS is used to measure how far you have gone. Coordinates are not saved and never leave the phone.
  • What does leave is a payment (handled by Stripe), an optional email address (for the activation link), and anonymous usage statistics.

3. This website: the plan funnel

The questions you answer at /plan are held in your browser's sessionStorage and are never sent to us. The plan shown at the end is computed in your browser from the same tables the app uses.

When you buy, those answers are encoded into the activation link so the app can rebuild the plan without asking you again. The link is a URL — it travels to you, not to a database. It is valid for 60 minutes.

If you enter your email address, it is used for two things: Stripe needs it to issue a receipt and manage the subscription, and we send you the activation link so a purchase made on a computer can be opened on your phone. Where the email address is attached to a measurement event, it is hashed with SHA-256 in your browser first; the plain address is not part of that event.

4. Payment

Payment on this website runs through RevenueCat and Stripe. Stripe acts as the merchant of record: the contract for the subscription is with Stripe, Stripe takes the payment, issues the invoice and handles VAT.

We never see or receive your card details. What we receive back is that a subscription exists and which one.

If you subscribe inside the app instead, the payment runs through Apple's App Store or Google Play under their terms, and we receive no payment data at all.

5. Email

The activation mail is sent through Resend (Resend, Inc.). Your address is passed to Resend for that one message and is not stored by us afterwards — the route that sends it holds no database and writes nothing. Resend retains delivery logs under its own policy.

We do not run a newsletter and will not email you for marketing.

6. The app: what is stored on your phone

Everything the app knows about you is written to the app's private storage on the device: your onboarding answers, your plan, every completed session with its duration, distance and pace, the feedback you give after a run, and your settings.

None of this is uploaded. There is no server to upload it to. It is included in your device backup (iCloud or Google), which is your backup, not ours. Deleting the app deletes the data.

7. Location

While a run is in progress, the app reads your position to measure distance and pace. It keeps the most recent fix in memory to calculate the step from the previous one, and adds that to a running total. Coordinates are not written to storage, not drawn on a map, and never transmitted. There is no route feature in Lufa, and this is why.

Location continues in the background so the measurement survives a locked screen or a switch to your music app. You can decline the permission — the session then runs on time alone, and the app says so rather than pretending to measure.

8. Apple Health / Health Connect

If you allow it, a finished run is written to Apple Health (or Health Connect on Android) as a workout with its start, end, duration and distance. Access is write-only: Lufa requests no permission to read anything from Health and cannot see your health data. This is optional and off unless you grant it.

9. Notifications

Reminders are scheduled locally on the device. There is no push server, and no notification content passes through us.

10. Analytics and measurement

Aptabase (EU-hosted) tells us which screens are used and where people stop. Events are anonymous, contain no personal data, and set no cookie — Aptabase cannot follow anyone across sites or apps, which is why it runs without asking.

Meta pixel and Conversions API measure whether an advert led to a subscription. On this website they run only after you agree, and only where consent is required (see section 11). The Conversions API is the server-side copy of the same event, paired with the browser event through a shared identifier so one purchase counts once rather than twice.

In the app, Meta's SDK reports aggregated events (install, purchase). Lufa does not show the App Tracking Transparency prompt and therefore has no advertising identifier to attach; these events cannot be linked to you across other apps or websites.

11. Cookies and consent

Lufa's own pages set no advertising cookies. The consent banner exists for the Meta pixel alone.

It is shown where the law requires a choice: the EU/EEA, the United Kingdom, Switzerland, and the US states with their own privacy statutes. Elsewhere the pixel loads without asking. The region is determined from the country your request arrives with, at the edge; if there is no such signal, you are asked.

Declining costs you nothing — the funnel, the plan and the purchase all work identically.

12. Who processes data for us

  • Vercel Inc. — hosting of lufa.run. Server logs, including IP address, are kept briefly for security and operation.
  • RevenueCat, Inc. — subscription state. Receives a pseudonymous identifier and purchase information.
  • Stripe, Inc. / Stripe Payments Europe, Ltd. — merchant of record for web purchases; payment, invoice, VAT.
  • Resend, Inc. — sends the activation email.
  • Aptabase — anonymous, EU-hosted product analytics.
  • Meta Platforms Ireland Ltd. — advertising measurement, subject to consent as described above.
  • Apple Inc. and Google Ireland Ltd. — app distribution and, for in-app purchases, payment.

Some of these process data outside the European Economic Area, in particular in the United States. Those transfers rely on the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

13. Legal bases (GDPR)

  • Providing the website, the funnel and the app, and giving you access to what you paid for: Art. 6(1)(b) GDPR (performance of a contract and steps taken at your request).
  • The activation email: Art. 6(1)(b) GDPR.
  • Anonymous product analytics and the security of our systems: Art. 6(1)(f) GDPR (legitimate interest in a working, unbroken product).
  • The Meta pixel and Conversions API on this website: Art. 6(1)(a) GDPR (your consent), which you may withdraw at any time with effect for the future.
  • Complying with tax and commercial law: Art. 6(1)(c) GDPR.

14. How long anything is kept

  • Your plan and your runs — on your device, until you delete the app or reset the plan in Settings.
  • Funnel answers — in your browser's session storage; gone when you close the tab.
  • The activation link — valid for 60 minutes, stored nowhere.
  • Email address — used for the one message, not retained by us.
  • Purchase and invoice records — held by Stripe or the app store for as long as tax and commercial law require (in Germany, generally up to ten years).
  • Server logs — short-term, at the hosting provider.
  • Analytics events — anonymous and not linked to a person, so there is nothing to delete on request.

15. Your rights

Under the GDPR you have the right of access, rectification, erasure, restriction, data portability, and to object to processing based on legitimate interest.

In practice: deleting the app removes everything we could ever have shown you, because it is all on the device. For anything held by Stripe, Apple or Google — your invoices and subscription — use their account settings, or write to us and we will point you to the right place.

You may also lodge a complaint with a supervisory authority. Ours is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Ansbach, Germany.

16. Children

Lufa is intended for people aged 16 and over. We do not knowingly process data from children under 16.

17. Not medical advice

Lufa is a training plan, not medical advice, and not a medical device. It does not diagnose anything and does not know your medical history. See the terms for what that means before you start running.

18. Changes

We may update this policy. Material changes are reflected in the date at the top of this page.

19. Contact

Questions about this policy or about your data: hi@pitterapps.com.

Back to Lufa