Privacy Policy
Effective from 1 January 2026 · Last updated 13 September 2026
This Privacy Policy explains how RND20 ("RND20", "we", "us", or "our") collects, uses, stores, and shares information when you use the RND20 mobile application and related services (the "Service").
1. Data Controller
The data controller for the Service is:
DynAgro s.r.o.
IČO: 284 606 77
Address: Lesní 100, 252 28 Vonoklasy, Czech Republic
Email: hello@webnik.cz
Website: rnd20.eu
2. Information We Collect
We collect only the information necessary to provide and improve the Service:
- Account information: name, email address, username, and profile details you provide when registering.
- Workout data: workout identifiers, Standard or Scaled mode, rounds and partial reps, start and finish times, completed-round timestamps, and personal-best records. Workouts saved while signed in are synchronized with your account; the basic workout can also be used without an account.
- On-device HealthKit data: with your permission, the Apple Watch reads heart rate during a workout. The app holds a bounded heart-rate timeline in memory to display workout charts and removes it when the app process ends. It is not included in persisted workout history or uploaded to RND20, PostgreSQL, or analytics.
- Social data: friend connections, blocks, challenges sent and received, reactions, and visibility settings.
- Safety reports: reporter and reported-account identifiers, selected reason, a copy of the reported name/handle and optional workout result, and moderation decisions. Reports are private and used to investigate abuse and enforce safety restrictions; they are not sent to analytics.
- Subscription and Watch linking data: Apple product and transaction identifiers, an account correlation identifier, subscription status and expiry, and linked Watch installation identifiers, optional device name, app version and connection status. We use these to verify Pro access and synchronize your devices. We do not receive your payment-card details or Apple Account password.
- Notification data: preferences for workout reminders, friend requests and reactions; device notification tokens and installation identifiers; timezone; delivery attempts and results; notification opens; and reminder-related workout engagement. These records are linked to your RND20 account.
- Administrative audit records: the affected account identifier, operator identifier, action, time, reason, and limited before-and-after profile or account-status details. These records document account changes and moderation actions and can remain after account deletion.
- Device and usage data: page or screen visits, predefined interaction events, screen dimensions, language, platform, and app/build version where analytics is enabled.
- Operational logs: connection and request information such as IP address, client type, endpoint and access time, together with diagnostic events used to operate and secure the Service. Notification diagnostics include account and notification identifiers, event type, delivery provider, response status, timing and provider request identifiers. Notification tokens, notification text and HealthKit samples are excluded from these notification diagnostic events.
Heart rate is health data and may constitute special-category personal data under Article 9 GDPR. RND20 processes it only on your Apple devices, for the workout feature you explicitly enable, and does not receive it on RND20 servers.
3. How We Use Information and Legal Basis
We use your information for the following purposes and on the following legal bases:
- Performance of a contract (Art. 6(1)(b) GDPR) – to provide the Service, process your workouts, enable social features, and respond to your requests.
- Legitimate interest (Art. 6(1)(f) GDPR) – to secure the Service, investigate reports, prevent abuse, document administrative actions, diagnose delivery problems, maintain server stability, and improve performance.
- Consent (Art. 6(1)(a) GDPR) – where required, for sending marketing communications or enabling optional features. You may withdraw consent at any time.
- Explicit consent for health data (Art. 9(2)(a) GDPR) – to read workout heart rate after you enable the HealthKit feature. You can revoke Health access in Apple system settings.
- Legal obligation (Art. 6(1)(c) GDPR) – where we are required to disclose data by law or to protect our rights.
4. Analytics and Notifications
Our website and, where enabled, our mobile and web app use our self-hosted Umami analytics service at s.ventosi.com to understand page visits and product usage. Events describe actions such as starting a workout or opening the Pro screen. App event properties are limited to platform, app surface, app version and build number; screen dimensions and language are also sent. We do not include your RND20 account identifiers, name, email, workout scores, friend identities, payment transaction identifiers or HealthKit samples in these analytics payloads.
The analytics service receives network requests and their connection information. We do not use it for advertising profiles or cross-company advertising tracking. Our website and web-app trackers respect the browser's Do Not Track signal. Notification engagement described below is recorded separately from Umami and is linked to your account.
RND20 offers workout reminders, friend-request alerts and workout-reaction alerts. The app requests your device's notification permission; new accounts have all three in-app notification preferences enabled by default. Device permission is still required for alerts. Change each category independently in Profile → Notifications, or turn off notifications in your device settings. Reminder timing uses your timezone and recent workout times, not GPS location.
We store delivery scheduling, related friend-request or reaction identifiers, provider responses and notification opens to deliver alerts, troubleshoot failures and understand engagement. Social delivery records can be created when a request or reaction occurs, before checking whether an alert will be sent. Turning off alerts does not delete your underlying social activity or existing records.
For workout reminders, we also record a workout start within two hours after opening a reminder and completion of that workout. This helps assess reminder engagement; it does not establish that a reminder caused a workout. We do not use this attribution for friend-request or reaction alerts. Operational test notifications are identified separately from ordinary engagement measurements.
Turning off a category cancels its pending alerts and prevents ordinary future alerts in that category. Turning off all three categories deactivates registered notification devices. An alert already handed to Apple may still arrive. Notification payloads contain generic text, a random notification identifier and an app destination; they do not contain sender identities, workout scores, round counts, heart rate or HealthKit samples. Device tokens are encrypted in our database and are not sent to Umami.
5. Sharing of Information
We do not sell your personal information. We may share information with:
- Service providers – hosting providers and other processors who help us operate the Service, under data processing agreements.
- Public authorities – when required by law or necessary to protect our rights.
- Other users – Friends Only shares your full profile and workout results with accepted friends. Private hides them from other users, including existing friends and challenge-link recipients. Save changes in Profile to apply the setting. Your basic name and username remain discoverable by signed-in users under either setting. Blocking hides your identities and shared content from one another. Deleted accounts are removed from social results. Exported images outside RND20 cannot be recalled.
For iOS notifications, RND20 sends your device notification token, generic alert text and a random notification identifier directly to Apple's Apple Push Notification service (APNs). Expo is not a notification delivery provider. Android push delivery is not enabled in the current release. Apple may process notification information outside the European Economic Area. Contact us at hello@webnik.cz for information about the processing locations and international-transfer arrangements applicable to your data.
6. Data Retention
We retain your information for as long as your account is active or as needed to provide the Service. Specifically:
- Account and workout data are kept until you delete your account or request deletion.
- The phone app retains details for the 50 most recent locally saved workouts. Local app workout data is cleared on logout or account deletion. Workouts already saved to Apple Health remain under your control in Apple Health; deleting your RND20 account does not automatically erase them.
- Safety reports and captured evidence older than 90 days are deleted during hourly cleanup, with catch-up when the server restarts. Deleting a referenced account or workout also deletes its report evidence. Safety restrictions retain account/workout identifiers and the operator decision until the referenced account or workout is deleted.
- Notification delivery and engagement records, including social alerts and operational test deliveries, are deleted after 90 days by recurring cleanup. Device registrations are deleted after 90 days without contact. Notification preferences are kept until account deletion. Deleting an account removes its notification database records; deleting a reaction also removes its associated delivery records. Cleanup catches up after service downtime.
- Administrative audit records are kept separately from account data and are not automatically deleted when an account is removed. They retain the affected account identifier, operator, action, time, reason and limited before-and-after details for security investigations and accountability. They are not anonymous records. The current application does not apply an automatic expiry to this audit history.
- Operational logs are managed separately from account records and are not automatically erased by deleting your account. Contact us for the applicable retention period and to request access or erasure of retained logs or audit records.
- Records required by accounting or tax law may be retained for up to 10 years.
- You may withdraw permission for optional features at any time. Existing notification database records expire according to the retention period above; withdrawing notification permission does not erase them immediately.
7. Your Rights
Under the GDPR and applicable data protection laws, you have the right to:
- Access your personal data and receive confirmation of processing.
- Rectify inaccurate or incomplete personal data.
- Erasure ("right to be forgotten") under the conditions set out in Article 17 GDPR.
- Restrict processing under the conditions set out in Article 18 GDPR.
- Data portability – receive your data in a structured, commonly used, and machine-readable format.
- Object to processing based on legitimate interests.
- Lodge a complaint with the supervisory authority, in the Czech Republic the Office for Personal Data Protection (uoou.cz).
8. How to Exercise Your Rights
You may exercise any of the above rights by emailing us at hello@webnik.cz. We will respond without undue delay and no later than 30 days after receiving your request. In complex cases, we may extend this period by two months and will inform you accordingly.
9. Children's Privacy
The Service is not directed to children under the age of 16, and we do not knowingly collect personal information from children under that age. If you believe we have collected data from a child, please contact us so we can delete it.
10. Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the internet is completely secure.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The current version is always available on this page with the date of the last update. For material changes, we will notify you via email if you have provided one.
12. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at hello@webnik.cz