Skip to content
Tahto

Privacy Policy

Last updated: August 31, 2026

1. Introduction

This policy explains what Tahto does with your personal data when you use the mobile app, this website and the related services (together, the "Service"). Tahto is the new name of the service previously offered as Cortex Athletics; neither the controller nor the processing changes with it.

The controller responsible for your data is:
Taskero UG (haftungsbeschränkt)
Graben 2, 55116 Mainz, Germany
Email: contact@taskero.de

2. Data we collect

2.1 Data you provide

  • Account data: email address, first name and last name (required to register). If you sign in with Apple or Google, the provider supplies this instead of you typing it (see section 5.5).
  • Profile data: date of birth, gender, weight and height (optional, used to personalise training plans), and your timezone (read from your device or set in the app, used only to send reminders at the right local time).
  • Health data: active injuries and illnesses, with title, description and start and end dates. Voluntary, and special category data under Art. 9 GDPR.
  • Training data: sports, experience levels, training configuration (splits, schedules, goals), available equipment, and workout logs (exercises, sets, reps, weights, pace, distance and, where logged or imported, duration, calories and average heart rate).
  • Nutrition data: meal photos, typed meal descriptions and voice notes you record to describe a meal. Voice recordings are processed transiently for transcription and analysis and are not stored; only the resulting transcript is kept, along with the calorie and macronutrient estimates and your supplement choices.
  • Coach chat: the messages you exchange with the in-app AI coach, typed or as voice notes. Voice notes are not stored; only the transcript and the conversation are kept, until you clear the chat or delete your account.
  • Feedback and feature requests: the text you submit, an optional screenshot attached to feedback, and feature-request descriptions.
  • Support messages: the messages you exchange with our support team in the in-app support chat. These are read and answered by people, not by an AI, and are kept until you delete your account.
  • Subscription data: if you take out a paid subscription, the tier you bought, its status, the start and end of the billing period, and the App Store transaction identifiers. Apple handles the payment; card details, payment methods and billing addresses never reach us (section 5.7).
  • Credentials: your password is hashed with PBKDF2 and is never stored in plain text.

2.2 Data collected automatically

We use no analytics, tracking or advertising technology. We do not build profiles from your IP address, browser or usage patterns. The only automatic handling is through the strictly necessary cookies the website needs to work, listed in the cookie policy.

Like every web server, ours records the requests that reach it. We log your IP address, the date and time, the address requested, the status code, the amount of data transferred and the identifier your browser or the app sends along. We need this to keep the service running, to track down faults and to fend off attacks. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is secure and stable operation. For the same reason our server temporarily blocks addresses that attack patterns come from. We do not combine these logs with your account, and we do not evaluate them for your behaviour. They are deleted automatically after 15 days at the latest, and temporary blocks expire on their own after a week at the latest.

2.3 Apple Health (HealthKit)

On iOS you can connect the app to Apple Health. If, and only if, you grant the HealthKit permission, the app reads:

  • Active energy burned, used to show your real daily activity calories and to keep your nutrition target current.
  • Completed workouts, including duration, distance, calories and average heart rate, used to log the sessions you actually trained.

Access is read-only; we never write to Apple Health. What is read is transmitted to and stored on our servers as part of your workout history and used solely to provide the Service, including as recent history for plan generation (section 5.1). You can revoke access at any time in the iOS Settings or Health app, and we stop reading immediately. Apple Health data, like all health data here, is never used for advertising or marketing and never shared for those purposes.

2.4 Activity imports from other platforms (Garmin Connect)

You can log a workout by sharing a Garmin Connect activity link with the app, from Garmin's share sheet or by pasting the link into the coach chat. This happens only when you actively share a link. Nothing is imported automatically and no ongoing connection to Garmin is established.

Our server then reads the publicly shared activity page that link points to and imports the activity's workout data: date, sport type, name, duration, distance, pace or speed, calories, average heart rate, and the individual laps or segments.

You do not connect a Garmin account and we never receive your Garmin credentials. We hold no account link and no access token, and we cannot read anything you have not made public: a private activity simply fails to import. We transmit no personal data to Garmin — the request carries only the activity identifier from the link you shared (see section 5.6). Imported data is stored as part of your workout history on the same basis as an Apple Health import (section 4.1), and you can delete an imported workout at any time.

3. What we use it for

  • Creating and managing your account.
  • Generating personalised training plans from your profile, sports, injuries and workout history.
  • Sending verification codes at registration and password reset emails when you ask for one.
  • Showing your training history, workout logs and progress.
  • Estimating calories and macronutrients for meals you log by photo, text or voice note, and producing nutrition guidance.
  • Running the in-app AI coach chat: answering questions and making targeted adjustments to your plan.
  • Calculating your daily activity calories from data you choose to import from Apple Health.
  • Acting on the feedback and feature requests you submit.
  • Answering your questions in the in-app support chat.
  • Delivering reminders and notifications at the right local time.
  • Handling subscriptions and unlocking the features they include.
  • Improving the quality of the generated plans.
  • Meeting legal obligations.

5. Who else sees your data

5.1 AI processing (Google Cloud Vertex AI)

The AI features run on Google Cloud Vertex AI in Google's EU multi-region. When you request a training plan, we transmit:

  • profile data: age (derived from your date of birth), gender, weight, height;
  • your sports and training configuration;
  • your active injuries and illnesses (health data);
  • your workout history from the last 30 days, including workouts imported from Apple Health;
  • your day preferences and time limits.

When you log a meal, we transmit the inputs you provide — photos, typed descriptions and voice recordings, with the relevant nutrition context — so the meal can be estimated and voice notes transcribed. Recordings are used only for that: they are never written to our storage, and only the transcript is kept, next to your food-log entry until you delete it.

When you message the coach, we transmit the conversation and the relevant training context so the coach can reply and propose changes. Voice notes are again used only to produce a transcript.

Google acts as our processor under a data processing agreement, does not use your prompts to train its models, and does not use this data for advertising. Google's privacy policy applies to its processing: policies.google.com/privacy. We send the data on the explicit consent you gave for that purpose (section 4.1); withdraw it and we stop sending. The machine-learning processing itself takes place inside the European Union (section 10).

5.2 Email delivery

We use Resend (Resend, Inc., United States) for transactional email such as verification codes and password resets. Only your email address and name are shared, only to deliver those messages, never for advertising. Resend acts as our processor under a data processing agreement. Resend's privacy policy. Because the provider is US-based, this may involve a transfer outside the EEA (section 10).

5.3 Hosting and storage

Our servers and database are hosted by Hetzner Online GmbH in Germany. Photos you upload (meal photos, optional feedback screenshots) are stored in a private, access-controlled bucket on Hetzner Object Storage in Germany, reachable only through short-lived signed links. Hetzner acts as our processor and does not use your data for its own purposes.

5.4 Push notifications

If you enable notifications, we use Expo's push service (Expo, Inc., United States) to deliver them, for example when your plan is ready. Your device generates a push token, an identifier for the app installation; we store it on your account and pass it to Expo so it can route notifications via Apple Push Notification service or Firebase Cloud Messaging. The token carries no message content and is never used for advertising or cross-app tracking. The content of a notification, such as the name of a supplement in an intake reminder, passes through Expo for delivery; Expo states that it deletes it right after handing it to the delivery service. Expo's privacy policy. Disable notifications in your device settings to stop this; we remove the token when you log out or delete your account.

5.5 Sign-in providers (Sign in with Apple, Sign in with Google)

You can create your account and sign in with your Apple account (on iOS) or your Google account instead of an email address and password. The provider then confirms your identity and shares your email address and name so we can create and secure your account. We never receive your Apple or Google password, and nothing else from those accounts is shared with us. Authentication tokens are exchanged with the provider to verify the sign-in and, when you delete your Tahto account, to revoke the connection. For the sign-in itself, Apple (Apple Distribution International Ltd., Ireland) and Google (Google Ireland Limited / Google LLC) each act as an independent controller under their own policies: Apple, Google. Both methods are optional, and neither provider is used for analytics, advertising or tracking through our app.

5.6 Garmin Connect (activity link imports)

If you share a Garmin Connect activity link (section 2.4), our server requests the publicly shared activity page it points to from Garmin Connect (Garmin Ltd. and its affiliates). That request is anonymous and contains no personal data about you: no name, no email address, no account identifier, no reference to your Tahto account, only the numeric activity identifier from the link. We hold no Garmin account connection, credentials or token, so this is a one-off read of content you have already made public, not an account integration. Garmin receives no data about you from us, and we send nothing unless you share a link. Garmin's privacy policy governs its own operation of Garmin Connect.

5.7 Subscription handling (Apple App Store, RevenueCat)

Paid subscriptions are bought through the Apple App Store. For the payment, Apple (Apple Distribution International Ltd., Ireland) is your contracting party, processes the payment and acts as an independent controller under its own policy: Apple. Card details, payment methods and billing addresses stay with Apple and are never visible to us.

To make your subscription effective in the app we use RevenueCat, Inc. (Brandon, Florida, USA) as a processor. RevenueCat validates the purchase receipt with the App Store and tells us which tier is active for you. The only things transmitted are a pseudonymous identifier for your account and the purchase itself, meaning tier, status and period. Your email address, your name and your training, nutrition and health data never reach RevenueCat. The basis is a data processing agreement incorporating Standard Contractual Clauses under Art. 46 GDPR (section 10). RevenueCat is not used for analytics, advertising or tracking. RevenueCat's privacy policy.

5.8 Nobody else

Beyond the processors and third parties named in this section, we do not sell, rent or share your personal data. We use no analytics services, no advertising networks and no social media plugins. In the event of a merger, acquisition or sale of assets your data may be transferred as part of that transaction, and we will tell you before it becomes subject to a different privacy policy. We may also disclose data where the law requires it or to protect our rights.

6. Security

We take appropriate technical and organisational measures, among them:

  • HTTPS enforced site-wide with HSTS;
  • passwords hashed with PBKDF2, never stored in plain text;
  • session cookies set Secure, HttpOnly and SameSite=Lax;
  • CSRF protection on all forms;
  • clickjacking protection via X-Frame-Options;
  • uploaded files scanned for malware before they are stored;
  • encrypted, access-controlled backups with point-in-time recovery.

No transmission over the internet is completely secure, so we cannot guarantee absolute security.

7. How long we keep it

  • Account and profile data: for the life of your account.
  • Training data and workout logs, including Apple Health imports: for the life of your account.
  • Meal photos, descriptions, transcripts and nutrition logs: until you delete the entry or your account. Raw voice recordings are not retained at all; they are discarded right after transcription and analysis.
  • Coach chat conversations: until you clear the day's chat or delete your account. Raw voice notes are not retained.
  • Feedback and feature requests, including screenshots: as long as needed to act on them, at most for the life of your account.
  • Support conversations: for the life of your account.
  • Push tokens: deleted when you log out or delete your account; tokens that stop working (after an uninstall, for example) are removed within 30 days.
  • AI processing logs: the content of prompts and responses, including the internal processing trace, is kept for 90 days for debugging and abuse prevention and then permanently removed. Delete a chat conversation or a food-log entry and the associated content is removed immediately. Content-free metering records (token counts, model name, timing) are kept for the life of your account for cost and capacity planning. We also keep permanently anonymous technical statistics that contain no personal data and no free text.
  • Coach memory: facts the coach saves about your training are kept while active; archived or superseded entries are removed after 90 days.
  • Activity link imports: the technical import record is removed within 90 days; an unconfirmed parsed preview after 7 days, or as soon as the import completes or fails.
  • Consent records: purpose, decision, text version and timestamp, kept for the life of your account as the proof Art. 7(1) GDPR requires, and deleted with it.
  • Subscription data: tier, status, period and the App Store transaction identifiers are kept after you delete your account, from then on without any link to your account and solely as a billing record. German commercial and tax law require this for six to ten years (§ 147 AO, § 257 HGB), so erasure is excluded to that extent under Art. 17(3)(b) GDPR, and we process these records for no other purpose during that time.
  • Email verification codes: expire after 15 minutes.

When you delete your account, the associated data is permanently removed, except for the billing records we are required to keep under the point above. You can do that yourself in the app under More → Account → Delete account, or by writing to contact@taskero.de.

8. Your rights

  • Access (Art. 15): ask what data we hold and how it is processed.
  • Rectification (Art. 16): have inaccurate or incomplete data corrected.
  • Erasure (Art. 17): have your data deleted.
  • Restriction (Art. 18): have processing restricted in certain cases.
  • Portability (Art. 20): receive your data in a structured, machine-readable format.
  • Objection (Art. 21): object to processing based on legitimate interests.
  • Withdrawal of consent (Art. 7(3)): withdraw consent for health-data processing at any time, without affecting the lawfulness of what happened before.

Withdrawing consent is as easy as giving it and takes effect immediately. Under More → Privacy in the app you can switch each AI purpose (training plans, coach chat, meal analysis) off and on with one tap; the feature simply stops working while it is off. The Apple Health import is withdrawn by disconnecting Apple Health under More → Connections → Apple Health, which also stops any further reading.

To exercise a right, write to contact@taskero.de. We answer within 30 days.

You can also lodge a complaint with a data protection supervisory authority. Ours is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz
Hintere Bleiche 34, 55116 Mainz, Germany
Email: poststelle@datenschutz.rlp.de

9. Children

The Service is not intended for anyone under 16. Registration therefore asks for your date of birth, and registrations from anyone under 16 are refused: no account is created and no data is stored. If you believe we hold data from a child under 16, write to contact@taskero.de and we will delete it.

10. International transfers

The AI features run on Google Cloud's EU multi-region, so the machine-learning processing of your data happens inside the European Union; residual transfers outside the EEA, such as Google support operations, are covered by Standard Contractual Clauses. Data may reach servers outside the EEA in these cases: transactional email, where your address and name are processed by Resend, Inc.; push notifications, where your token is processed by Expo, Inc.; subscription handling, where RevenueCat, Inc. processes the pseudonymous account identifier and the purchase (section 5.7); and signing in with Apple or Google, where authentication tokens are exchanged with the provider (section 5.5). Those recipients may be in the United States or elsewhere. The transfers are safeguarded by Standard Contractual Clauses and, where applicable, an adequacy decision including the EU–US Data Privacy Framework, in line with Art. 46 GDPR.

11. Changes to this policy

We update this policy when the processing changes. The current version is always on this page, with the date at the top. For material changes that affect you, we also tell you in the app or by email.

12. Contact

For questions about this policy or to exercise your rights:
Email: contact@taskero.de
Address: Taskero UG (haftungsbeschränkt), Graben 2, 55116 Mainz, Germany

Every data protection request reaches us at that address and is handled there.

This English text is a courtesy translation. In case of any discrepancy, the German version applies.

↑ Back to top

Necessary cookies keep your language, your session and form protection working. They can't be switched off, because the site doesn't work without them. There are no other categories at the moment.