PL8

PL8 Privacy Policy

Version: 1.0 Effective date: 29 August 2026 Language: English

This policy describes the PL8 release offered in Germany. The German version is used when PL8 presents the German legal flow; this English version is used when PL8 presents the English legal flow.

1. Controller and contact

The controller is:

Burlis Management GmbH Philippstraße 27 52349 Düren Germany

Managing Director: Alexander Burlis Commercial Register: HRB 7595, Local Court of Düren VAT identification number: DE316238171 Telephone: +49 177 6436530 Email: support@burlis.de

For a privacy request, put “PL8 privacy” in the subject line. For a safety or moderation matter, put “PL8 safety” in the subject line. You can also write to the postal address above. No data protection officer contact is published.

2. What is available in this release

PL8 provides a local workout log, manual food and water logging, progress views, optional Apple Health or Health Connect integration, and an optional Friends account with a two-week leaderboard.

The release does not provide remote AI Coach replies, food-photo analysis, paid offers or subscriptions, over-the-air Expo updates, or Sign in with Apple. Those functions cannot be enabled merely by adding an environment variable. This policy must be reviewed before any of them is introduced.

PL8 has no advertising SDK, behavioural analytics SDK, cross-app tracking, session recording, remote push notification service, or location permission. The legal website sets no cookies and loads no scripts, analytics, web fonts, images, or embeds from third parties.

3. Data that stays on your device

The following data are stored in PL8's local database:

Burlis Management GmbH cannot remotely view this database. You can use these local functions without a PL8 account. The Friends server never receives individual exercises, sets, per-set weights, meals, water, body weight, plans, or records read from Apple Health or Health Connect.

For ordinary local functions requested by you, the legal basis is Article 6(1)(b) GDPR. Fitness, nutrition, body-weight and Health-platform information may be data concerning health. Where Article 9 GDPR applies, PL8 relies in addition on your explicit consent under Article 9(2)(a) GDPR.

4. Apple Health and Health Connect

Health access is optional. Before the operating system asks for permission, PL8 separately asks for explicit consent for the precise categories involved: reading steps, body mass and workouts, and writing completed workouts. The local receipt records policy version 1.0, the language shown, the categories and the time of consent. The receipt stays on your device.

You may refuse without losing the ordinary workout or manual food log. You can withdraw through PL8 settings at any time. Withdrawal stops PL8 from reading or writing Health data, invalidates the consent receipt and removes PL8's Health-derived step cache and matching/export links. It does not delete an ordinary workout that you logged yourself, and it does not remove a workout already written to Apple Health or Health Connect. You can also revoke the operating-system permission in device settings. Withdrawal does not affect the lawfulness of processing before withdrawal.

Apple or Google controls the copy already held in its Health service. Its own terms and privacy information apply to that service.

5. Local storage and backups

PL8 stores its database in the app sandbox. The device's access controls and encryption protect that sandbox; PL8 does not separately encrypt every database field.

On iOS, PL8 marks its SQLite data directory as excluded from automatic device backup before opening the database and reapplies that setting when the app opens the database again. A portable PL8 backup is created only when you choose to export one. You control where an exported file is stored or shared.

Android system backup can include PL8 app data according to your device and Google account settings. Burlis does not receive that backup. Review the backup settings of your device if you do not want the operating-system provider to store app data.

Removing PL8 from your device removes its live sandbox subject to any copy you or the operating system previously made. Deleting a Friends account does not delete the local database, because the two are separate.

6. Friends account and email authentication

Friends is optional and is available only to people aged 18 or older. You sign in with an email address and a six-digit one-time code. PL8 processes:

This processing is necessary to create and operate the Friends account under Article 6(1)(b) GDPR. Without an email address, authentication is not possible. One-time codes expire after 10 minutes. Sessions expire after 90 days or earlier when you sign out or delete the account. Account and legal-evidence records are kept until account deletion, subject to the report rules below.

The email address and one-time code are sent to Plus Five Five, Inc. (Resend) to deliver the authentication email. Email is dispatched from the provider's \eu-west-1\ region in Ireland. Resend stores account data, email metadata, logs and API records in the United States. Its DPA incorporates the EU Standard Contractual Clauses, Module Two, for transfers to a processor and also identifies the EU-U.S. Data Privacy Framework. On Resend's Free, Pro and Scale plans, email and log data are retained for 30 days. Enterprise accounts use the retention period configured for that account. Backups are retained for 7 days; remaining customer data are deleted within 90 days after account termination. PL8 does not enable email open or link tracking for sign-in codes.

7. Friends, invitations and leaderboard

The server stores friend invitations, friendships and blocks. An invite code expires after seven days and is removed after successful acceptance or account deletion. A block applies in both directions. You may lift it yourself, but lifting a block does not recreate a friendship.

If you separately give explicit fitness-leaderboard consent, PL8 automatically uploads three totals for the current and previous ISO week when the app enters the foreground and after a completed workout:

The totals can reveal physical activity and are treated conservatively as data concerning health. The purpose is to show the two-week leaderboard to Friends you have accepted. The legal bases are your consent under Article 6(1)(a) GDPR and your explicit consent under Article 9(2)(a) GDPR. The consent is optional: you can create and use a Friends account without giving it, in which case PL8 does not upload your totals or display a leaderboard row for you. Refusal does not affect the local workout log, your Friends account or friendships.

PL8 records the fitness-consent version, language and grant time on the server. You can withdraw the fitness consent in Friends settings at any time. Withdrawal stops future uploads and immediately deletes all of your stored leaderboard totals; it does not delete your Friends account, friendships or local workout data. Withdrawal does not affect the lawfulness of processing before withdrawal.

PL8 does not enrich the totals, use them to assess your health, or disclose them publicly. The server otherwise keeps only the current and previous ISO week and deletes older weekly rows. Your totals and friend graph are also deleted when you delete your account.

8. Reports, blocks and Article 14 information

You may report another Friends user. The report contains the reporter's account identifier, the reported account identifier where it still exists, the display name as shown when reported, one fixed reason code, and filing and handling times. There is no free-text report field. Filing a report also removes the friendship and creates a block. You may later lift the block; the friendship is not restored.

The purpose is user safety, review of display names and enforcement of the Friends rules. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are protecting users, investigating reports and operating the social feature responsibly. These interests are limited by fixed reason codes, no free text, restricted operator access, short review targets and finite retention.

The reported person did not provide the report data. The source is another Friends user. Reports are reviewed at least weekly with a target of 30 days. Unhandled reports are deleted after 90 days. Handled reports are deleted 12 months after handling.

For each report, Burlis assesses whether and when direct Article 14 notice can be given without exposing the reporter or creating a concrete risk. A notice is not withheld merely because the data came from a report. Any restriction relies on the circumstances of that case, including Section 29 BDSG and Article 14(5) GDPR, and the reason is recorded. The same case-specific approach applies to an access request: third-party information may be redacted or withheld only where their rights and freedoms require it under Article 15(4) GDPR or Section 29 BDSG. The remaining information is provided.

9. Account deletion

You can delete the Friends account inside the app. If deletion fails, PL8 keeps the local session and tells you so, allowing another attempt. If you cannot use the app, follow the instructions at https://www.pl8.burlis.de/delete-account. We may request proportionate proof that the account is yours.

Deletion removes the account, email address, display name, legal evidence, sessions, unused codes, invitations, friend graph, blocks and leaderboard totals. Reports filed by that account are removed. A report filed by another person about the deleted account may retain its fixed reason and filing and handling times for the period in Section 8; deletion removes the reported account identifier and display-name snapshot from that report.

10. Website, API operation and security

The Friends API and legal website run on a Cloud Server supplied by Hetzner Online GmbH in Nuremberg, Germany, and are administered through Coolify. The systems process connection information needed to answer a request and protect the service, such as IP address, time, request method, route template, status, duration and a random request identifier. The app rate limiter holds an IP address in memory for at most 10 minutes. Application logs use route templates, not invitation or session secrets. Operational logs are used under Article 6(1)(f) GDPR for reliable delivery, fault diagnosis and abuse prevention. Docker log retention is size-based rather than time-based: each container keeps at most three 10 MB files. A low-volume entry can therefore remain until the files roll over or the container is removed. A concrete security incident or legal obligation may require a longer documented copy.

Traefik access logging is disabled. Docker uses its json-file log driver with at most three 10 MB files per container, and no external log drain is configured. Sentinel retains infrastructure metric history for 7 days. The host system journal retains entries for at most 30 days and uses at most 500 MB.

The public legal site has nginx access logging disabled. It sets no cookie and contains no client-side script or tracker. The server and TLS proxy still process an IP address to deliver a page.

Cloudflare, Inc. provides authoritative DNS only. The PL8 records are not proxied by Cloudflare, so Cloudflare does not terminate PL8 HTTPS or receive API or site request bodies. DNS-query and service-security metadata may be handled on Cloudflare's global network under its own role and terms.

Hosting and security processing is based on Article 6(1)(f) GDPR. Our legitimate interests are secure, available and abuse-resistant services.

11. Communications

If you contact us, we process your contact details, message and related records to answer you. The basis is Article 6(1)(b) GDPR for a contractual or pre-contractual request, Article 6(1)(f) GDPR for other correspondence, or Article 6(1)(c) GDPR where a legal duty applies. Our legitimate interest is answering and documenting the request.

Company email is operated by Proton AG, Switzerland. Switzerland benefits from an EU adequacy decision; Proton's DPA also requires appropriate safeguards for onward transfers outside Switzerland, the EU or another adequate country. Ordinary correspondence is deleted when it is no longer needed, normally no later than 12 months after the final answer. Contract, tax, accounting, safety or legal-claim records are kept for the applicable statutory or claim period.

12. Recipients and transfers

Personal data are disclosed only where necessary to:

Resend processing in the United States and its safeguards are described in Section 6. Proton processing is covered by the adequacy decision for Switzerland, with contractual safeguards for non-adequate onward transfers. Cloudflare's DNS role is described in Section 10. PL8 does not sell personal data.

13. Your rights

Subject to the statutory conditions, you have rights to access, rectification, erasure, restriction, portability and objection. You may withdraw consent at any time for the future. Where processing relies on Article 6(1)(f) GDPR, you may object for reasons arising from your particular situation.

Send a request to the controller details in Section 1. We respond without undue delay and normally within one month. We may need information sufficient to verify that the request concerns you.

You may complain to a data-protection authority. The authority responsible for our establishment is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen Kavalleriestraße 2–4 40213 Düsseldorf Germany Telephone: +49 211 38424-0

14. Automated decisions and changes

PL8 performs no solely automated decision with legal or similarly significant effects and no profiling for advertising or eligibility.

We update this policy before a material processing change takes effect. The app records which version and language of the Friends notice was shown. A material change to Friends is presented before continued use where required. The current version is available at https://www.pl8.burlis.de/privacy.