Privacy Policy
Last updated: August 31, 2026
1. Introduction
This policy explains what Tahto does with your personal data when you use the mobile app, this website and the related services (together, the "Service"). Tahto is the new name of the service previously offered as Cortex Athletics; neither the controller nor the processing changes with it.
The controller responsible for your data is:
Taskero UG (haftungsbeschränkt)
Graben 2, 55116 Mainz, Germany
Email: contact@taskero.de
2. Data we collect
2.1 Data you provide
- Account data: email address, first name and last name (required to register). If you sign in with Apple or Google, the provider supplies this instead of you typing it (see section 5.5).
- Profile data: date of birth, gender, weight and height (optional, used to personalise training plans), and your timezone (read from your device or set in the app, used only to send reminders at the right local time).
- Health data: active injuries and illnesses, with title, description and start and end dates. Voluntary, and special category data under Art. 9 GDPR.
- Training data: sports, experience levels, training configuration (splits, schedules, goals), available equipment, and workout logs (exercises, sets, reps, weights, pace, distance and, where logged or imported, duration, calories and average heart rate).
- Nutrition data: meal photos, typed meal descriptions and voice notes you record to describe a meal. Voice recordings are processed transiently for transcription and analysis and are not stored; only the resulting transcript is kept, along with the calorie and macronutrient estimates and your supplement choices.
- Coach chat: the messages you exchange with the in-app AI coach, typed or as voice notes. Voice notes are not stored; only the transcript and the conversation are kept, until you clear the chat or delete your account.
- Feedback and feature requests: the text you submit, an optional screenshot attached to feedback, and feature-request descriptions.
- Support messages: the messages you exchange with our support team in the in-app support chat. These are read and answered by people, not by an AI, and are kept until you delete your account.
- Subscription data: if you take out a paid subscription, the tier you bought, its status, the start and end of the billing period, and the App Store transaction identifiers. Apple handles the payment; card details, payment methods and billing addresses never reach us (section 5.7).
- Credentials: your password is hashed with PBKDF2 and is never stored in plain text.
2.2 Data collected automatically
We use no analytics, tracking or advertising technology. We do not build profiles from your IP address, browser or usage patterns. The only automatic handling is through the strictly necessary cookies the website needs to work, listed in the cookie policy.
Like every web server, ours records the requests that reach it. We log your IP address, the date and time, the address requested, the status code, the amount of data transferred and the identifier your browser or the app sends along. We need this to keep the service running, to track down faults and to fend off attacks. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is secure and stable operation. For the same reason our server temporarily blocks addresses that attack patterns come from. We do not combine these logs with your account, and we do not evaluate them for your behaviour. They are deleted automatically after 15 days at the latest, and temporary blocks expire on their own after a week at the latest.
2.3 Apple Health (HealthKit)
On iOS you can connect the app to Apple Health. If, and only if, you grant the HealthKit permission, the app reads:
- Active energy burned, used to show your real daily activity calories and to keep your nutrition target current.
- Completed workouts, including duration, distance, calories and average heart rate, used to log the sessions you actually trained.
Access is read-only; we never write to Apple Health. What is read is transmitted to and stored on our servers as part of your workout history and used solely to provide the Service, including as recent history for plan generation (section 5.1). You can revoke access at any time in the iOS Settings or Health app, and we stop reading immediately. Apple Health data, like all health data here, is never used for advertising or marketing and never shared for those purposes.
2.4 Activity imports from other platforms (Garmin Connect)
You can log a workout by sharing a Garmin Connect activity link with the app, from Garmin's share sheet or by pasting the link into the coach chat. This happens only when you actively share a link. Nothing is imported automatically and no ongoing connection to Garmin is established.
Our server then reads the publicly shared activity page that link points to and imports the activity's workout data: date, sport type, name, duration, distance, pace or speed, calories, average heart rate, and the individual laps or segments.
You do not connect a Garmin account and we never receive your Garmin credentials. We hold no account link and no access token, and we cannot read anything you have not made public: a private activity simply fails to import. We transmit no personal data to Garmin — the request carries only the activity identifier from the link you shared (see section 5.6). Imported data is stored as part of your workout history on the same basis as an Apple Health import (section 4.1), and you can delete an imported workout at any time.
3. What we use it for
- Creating and managing your account.
- Generating personalised training plans from your profile, sports, injuries and workout history.
- Sending verification codes at registration and password reset emails when you ask for one.
- Showing your training history, workout logs and progress.
- Estimating calories and macronutrients for meals you log by photo, text or voice note, and producing nutrition guidance.
- Running the in-app AI coach chat: answering questions and making targeted adjustments to your plan.
- Calculating your daily activity calories from data you choose to import from Apple Health.
- Acting on the feedback and feature requests you submit.
- Answering your questions in the in-app support chat.
- Delivering reminders and notifications at the right local time.
- Handling subscriptions and unlocking the features they include.
- Improving the quality of the generated plans.
- Meeting legal obligations.
4. Legal basis (GDPR)
- Performance of a contract (Art. 6(1)(b)): account creation, workout logging, the core functionality that does not involve health data, and entering into and handling a paid subscription.
- Explicit consent (Art. 9(2)(a) with Art. 6(1)(a)): all processing of health data — plan generation, the coach chat, meal analysis, and workout imports from Apple Health or from activity links you share. We ask for this in the app, separately per purpose, before the feature can be used, and you can withdraw it at any time (sections 4.1 and 8).
- Legal obligation (Art. 6(1)(c)): compliance with applicable law, including the retention of billing records required by German commercial and tax law (§ 147 AO, § 257 HGB).
- Legitimate interests (Art. 6(1)(f)): security of the Service, abuse prevention and service improvement.
4.1 Special categories of data (Art. 9 GDPR)
We process the following special categories on the basis of your explicit consent:
- Health data: your active injuries and illnesses.
- Health-related data: weight and height, provided in a fitness context.
- Apple Health data: active energy and completed workouts, including average heart rate, that you authorise the iOS app to read (section 2.3).
- Imported activity data: workout data, including average heart rate, from activity links you share with the app (section 2.4).
This data is used exclusively to provide the Service, above all to produce training plans that suit your physical condition. It is never used for advertising or marketing.
The app asks for consent separately for each of these purposes:
- AI training plans: generating your plan from profile, sports, schedule, injuries, illnesses and workout history, and the short coach note you get after logging a session.
- AI coach chat: answering questions and adjusting the plan in conversation.
- AI meal analysis: estimating calories and nutrients from photos, descriptions and voice notes.
- Workout imports: storing and processing activity data from Apple Health and from shared activity links. This consent is given when you connect Apple Health or confirm your first shared import, and withdrawn when you disconnect Apple Health or switch the permission off under More → Privacy.
Each choice is voluntary and independent: decline any of them and the rest of the Service still works, only the declined feature becomes unavailable. Your decisions, the version of the consent text they were given against and their timestamps are recorded, because Art. 7(1) GDPR requires us to be able to demonstrate consent. You can change any choice at any time (section 8) and update or delete the underlying data in the app.
6. Security
We take appropriate technical and organisational measures, among them:
- HTTPS enforced site-wide with HSTS;
- passwords hashed with PBKDF2, never stored in plain text;
- session cookies set Secure, HttpOnly and SameSite=Lax;
- CSRF protection on all forms;
- clickjacking protection via X-Frame-Options;
- uploaded files scanned for malware before they are stored;
- encrypted, access-controlled backups with point-in-time recovery.
No transmission over the internet is completely secure, so we cannot guarantee absolute security.
7. How long we keep it
- Account and profile data: for the life of your account.
- Training data and workout logs, including Apple Health imports: for the life of your account.
- Meal photos, descriptions, transcripts and nutrition logs: until you delete the entry or your account. Raw voice recordings are not retained at all; they are discarded right after transcription and analysis.
- Coach chat conversations: until you clear the day's chat or delete your account. Raw voice notes are not retained.
- Feedback and feature requests, including screenshots: as long as needed to act on them, at most for the life of your account.
- Support conversations: for the life of your account.
- Push tokens: deleted when you log out or delete your account; tokens that stop working (after an uninstall, for example) are removed within 30 days.
- AI processing logs: the content of prompts and responses, including the internal processing trace, is kept for 90 days for debugging and abuse prevention and then permanently removed. Delete a chat conversation or a food-log entry and the associated content is removed immediately. Content-free metering records (token counts, model name, timing) are kept for the life of your account for cost and capacity planning. We also keep permanently anonymous technical statistics that contain no personal data and no free text.
- Coach memory: facts the coach saves about your training are kept while active; archived or superseded entries are removed after 90 days.
- Activity link imports: the technical import record is removed within 90 days; an unconfirmed parsed preview after 7 days, or as soon as the import completes or fails.
- Consent records: purpose, decision, text version and timestamp, kept for the life of your account as the proof Art. 7(1) GDPR requires, and deleted with it.
- Subscription data: tier, status, period and the App Store transaction identifiers are kept after you delete your account, from then on without any link to your account and solely as a billing record. German commercial and tax law require this for six to ten years (§ 147 AO, § 257 HGB), so erasure is excluded to that extent under Art. 17(3)(b) GDPR, and we process these records for no other purpose during that time.
- Email verification codes: expire after 15 minutes.
When you delete your account, the associated data is permanently removed, except for the billing records we are required to keep under the point above. You can do that yourself in the app under More → Account → Delete account, or by writing to contact@taskero.de.
8. Your rights
- Access (Art. 15): ask what data we hold and how it is processed.
- Rectification (Art. 16): have inaccurate or incomplete data corrected.
- Erasure (Art. 17): have your data deleted.
- Restriction (Art. 18): have processing restricted in certain cases.
- Portability (Art. 20): receive your data in a structured, machine-readable format.
- Objection (Art. 21): object to processing based on legitimate interests.
- Withdrawal of consent (Art. 7(3)): withdraw consent for health-data processing at any time, without affecting the lawfulness of what happened before.
Withdrawing consent is as easy as giving it and takes effect immediately. Under More → Privacy in the app you can switch each AI purpose (training plans, coach chat, meal analysis) off and on with one tap; the feature simply stops working while it is off. The Apple Health import is withdrawn by disconnecting Apple Health under More → Connections → Apple Health, which also stops any further reading.
To exercise a right, write to contact@taskero.de. We answer within 30 days.
You can also lodge a complaint with a data protection supervisory
authority. Ours is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz
Hintere Bleiche 34, 55116 Mainz, Germany
Email: poststelle@datenschutz.rlp.de
9. Children
The Service is not intended for anyone under 16. Registration therefore asks for your date of birth, and registrations from anyone under 16 are refused: no account is created and no data is stored. If you believe we hold data from a child under 16, write to contact@taskero.de and we will delete it.
10. International transfers
The AI features run on Google Cloud's EU multi-region, so the machine-learning processing of your data happens inside the European Union; residual transfers outside the EEA, such as Google support operations, are covered by Standard Contractual Clauses. Data may reach servers outside the EEA in these cases: transactional email, where your address and name are processed by Resend, Inc.; push notifications, where your token is processed by Expo, Inc.; subscription handling, where RevenueCat, Inc. processes the pseudonymous account identifier and the purchase (section 5.7); and signing in with Apple or Google, where authentication tokens are exchanged with the provider (section 5.5). Those recipients may be in the United States or elsewhere. The transfers are safeguarded by Standard Contractual Clauses and, where applicable, an adequacy decision including the EU–US Data Privacy Framework, in line with Art. 46 GDPR.
11. Changes to this policy
We update this policy when the processing changes. The current version is always on this page, with the date at the top. For material changes that affect you, we also tell you in the app or by email.
12. Contact
For questions about this policy or to exercise your rights:
Email: contact@taskero.de
Address: Taskero UG (haftungsbeschränkt), Graben 2, 55116 Mainz, Germany
Every data protection request reaches us at that address and is handled there.
This English text is a courtesy translation. In case of any discrepancy, the German version applies.