Privacy Policy
Last Updated: April 18, 2026
Draft Out values your privacy. This Privacy Policy explains how we collect, use, and protect your personal information in compliance with the General Data Protection Regulation (GDPR) and other global privacy standards.
1. The Data Controller
The Data Controller for your information is Draft Out, based in Kraków, Poland. You can contact us regarding privacy matters at hello@draftout.app.
2. Information We Collect
We collect the minimum amount of data necessary to provide and improve our Service:
- Account Information: Email address and name provided during registration.
- Usage Data: Statistics on how you interact with the app (e.g., features used, login frequency) to help us improve the platform.
- Service Data: The workout plans you create and the client data you store within the app.
3. Payment Information
Draft Out does not collect or store your payment details. All subscription payments are processed securely by our designated Merchant of Record (e.g., Polar.sh or Paddle). The MoR handles your credit card data, billing address, and tax information directly. We only receive a secure token confirming your subscription status.
4. How We Use Your Data
- To create and manage your account.
- To provide customer support and send necessary service updates.
- To analyze usage trends and improve the Draft Out experience.
5. Your GDPR Rights
If you are a resident of the European Economic Area (EEA) or the UK, you have the following rights:
- The right to access, update, or delete the information we have on you.
- The right of rectification if your information is inaccurate.
- The right to object to our processing of your personal data.
- The right of restriction to request that we restrict the processing of your data.
- The right to data portability to receive a copy of your data in a structured, machine-readable format.
To exercise any of these rights, please contact us at hello@draftout.app.
6. Data Security and Retention
We implement industry-standard security measures to protect your data from unauthorized access. We retain your data only for as long as your account is active or as needed to provide you the Service. If you delete your account, your data will be permanently removed from our active databases within 30 days.