Skip to content
Plaivra logoPlaivra
Create account

Privacy

Privacy Policy

Last updated:

Version 2026-07-11. This policy explains what Plaivra processes, why it is processed, how optional ChatGPT access works, and the controls available to you.

Pre-launch legal draft. Professional legal and privacy review is required before public launch. This notice is not a claim of legal approval.

1. Controller and contact

Plaivra is operated by Ahmed Mohamed as an individual operator. The controller responsible for Plaivra is:

Ahmed Mohamed
Untere Himmelreichstraße 10
94469 Deggendorf
Germany
Email: Ahmed.Mohamed04@outlook.de

Use the same address for privacy, support, or security reports. Add “Privacy” or “Security” to the subject so the request can be prioritized.

2. Scope of this policy

This policy covers the Plaivra website, web application, accounts, tracking and planning features, private file storage, support communications, and the optional connection that lets ChatGPT use authorized Plaivra tools. It does not govern ChatGPT itself or third-party websites you choose to visit.

3. Data categories

  • Account and eligibility: user ID, email, name, sign-in provider, account state, age declaration, and versioned 16+ eligibility confirmation.
  • Profile and preferences: goals, schedule, training experience, equipment, optional height, weight, target weight, gender, lifestyle preferences, app settings, and consent history.
  • Training: plans, days, exercises, sets, repetitions, loads, sessions, history, alternatives, favorites, and user-authored notes.
  • Nutrition and hydration: foods, meals, recipes, meal plans, groceries, calories, macronutrients, targets, preferences, water logs, and related notes.
  • Progress and wellness: body measurements, weight, progress entries and photos, records, habits, tasks, sleep, recovery, supplements, and daily check-ins.
  • Functional constraints: optional user-authored movements, areas, foods, or practical limitations that an authorized planning task should respect. Plaivra does not infer a diagnosis.
  • ChatGPT connection: connection label and status, permitted scopes, OAuth client/resource metadata, grant/revocation timestamps, and redacted tool activity.
  • Security and operations: authentication events, short-lived authorization data, rate-limit records, idempotency hashes, error events, release/version data, and minimized audit records.
  • Privacy and support: export/deletion requests, support messages, delivery status, and minimized processing evidence.

Plaivra does not need payment-card credentials for its current unpaid launch scope and does not collect payment credentials through ChatGPT tools.

4. Sensitive fitness and body data

Fitness, nutrition, body, progress-photo, wellness, and functional-constraint information may be sensitive and may reveal information about physical condition. Plaivra treats it as highly protected user-provided data. Where Article 9 GDPR applies, processing relies on the separate explicit consent collected during registration. You may withdraw that consent for future processing, but affected features may then be unavailable.

Plaivra is not a medical application. It does not diagnose, infer a diagnosis, prescribe, or treat. Stored text is treated as user-provided data, not as instructions for the system or verified medical fact.

5. Purposes and legal bases

  • Provide the account and requested features: performance of a contract under Article 6(1)(b) GDPR.
  • Process voluntarily provided sensitive fitness/body data: Article 6(1)(b) and, where required, explicit consent under Article 9(2)(a) GDPR.
  • Connect ChatGPT and apply permissions: your consent under Article 6(1)(a), plus Article 9(2)(a) where special-category data is involved.
  • Security, fraud prevention, rate limiting, debugging, and accountable audit: legitimate interests under Article 6(1)(f), balanced against data minimization and your rights.
  • Support and privacy requests: Article 6(1)(b), (c), or (f), depending on the request and applicable obligation.
  • Legal obligations and claims: Article 6(1)(c) or (f), where applicable.

The precise legal-basis analysis, especially for sensitive data and international transfers, requires professional legal review before launch.

6. Optional ChatGPT and Plaivra tools

The ChatGPT connection is optional and off until you initiate it in ChatGPT, authenticate, and grant limited scopes. For a declared task, Plaivra maps required scopes, retrieves only whitelisted task-relevant fields, and rejects missing, expired, revoked, wrong-resource, or cross-user authorization.

When an authorized Plaivra tool succeeds, the structured result is stored directly in Plaivra and remains visible, editable, and correctable. Plaivra does not add a generic second approval/import queue. Explicit confirmation is still required for destructive or materially consequential actions.

Public tools use strict input/output contracts. Redacted activity records may contain tool name, outcome, time, and a safe reason code. They exclude raw prompts, tokens, authorization codes, private notes, measurements, photo paths, and internal exception details.

7. OAuth, tokens, permissions, and revocation

Plaivra uses authorization code flow with PKCE and resource-bound access. Reusable access tokens and authorization codes are stored as hashes, not reusable plaintext. Server-side checks cover issuer, audience/resource, expiry, not-before time, scope, connection ownership, saved permissions, and revocation.

You can review or revoke a connection and reduce permissions in Settings. Revocation stops future ChatGPT access. A deletion request revokes active ChatGPT connections, OAuth access tokens, and Supabase refresh sessions when accepted.

8. Recipients and processors

  • Supabase: database, authentication, private file storage, and related platform services.
  • Production hosting/deployment provider: application delivery, server execution, and operational logs.
  • Resend: only when an email function or deletion-completion notification is configured and used.
  • OpenAI/ChatGPT: only when you activate the connection or otherwise use ChatGPT; OpenAI processes data within its own product and contractual context.
  • Public food/exercise data sources: product or exercise queries may be sent without Plaivra account data when those functions are used.

Processor agreements, roles, sub-processors, hosting configuration, and transfer safeguards must be verified and documented before launch. Plaivra does not claim endorsement or approval by OpenAI or any provider.

9. International transfers

Some providers may process data outside the EU/EEA. A transfer may occur only with a lawful transfer mechanism, such as an adequacy decision or appropriate safeguards including Standard Contractual Clauses, plus supplementary measures where required. The final provider-by-provider transfer assessment is a launch-blocking professional-review item.

10. Storage, security, and access control

Implemented safeguards include HTTPS in production, owner-scoped Row Level Security, server-only service credentials, private owner-folder photo storage, signed URLs, hashed OAuth artifacts, scoped authorization, rate limits, strict schemas, redacted logs, replay protection, and cross-user tests. No system can guarantee absolute security.

Do not send credentials, medical records, or unnecessary sensitive information to support. Report suspected unauthorized access promptly to Ahmed.Mohamed04@outlook.de.

11. Retention

Account content is retained while the account is active and until you delete individual records or a verified account deletion completes, unless a legal obligation or active legal hold requires limited retention. Completion evidence is minimized and separated from deleted account content.

OAuth codes/tokens, redacted MCP activity, operational security logs, completed privacy requests, idempotency records, and deletion evidence have bounded cleanup mechanisms with dry-run metrics and batching. Concrete periods have not yet been owner/legal approved and must remain unconfigured until that review is complete. Public launch is blocked until the final periods, purposes, alerts, and recovery process are approved and published. No unapproved period is represented here as final.

12. Export and account deletion

Settings provide an authenticated ZIP export containing canonical JSON, per-domain CSV files, and a storage-object manifest. Credentials, reusable tokens, idempotency hashes, and internal security telemetry are excluded.

Account deletion requires recent reauthentication, a detailed impact summary, and exact confirmation. The lifecycle revokes connections, checks legal holds and provider cleanup, disables access, removes private objects through the Storage API, removes or anonymizes dependent records, deletes the Auth user, and sends a completion notification when configured. Failures retry safely and expose a non-sensitive status.

13. Your rights

Subject to applicable conditions, you may request access, correction, erasure, restriction, portability, or object to processing, and may withdraw consent for the future. Use Plaivra Settings or email Ahmed.Mohamed04@outlook.de. Identity verification may be required.

You may complain to a competent supervisory authority, including the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany.

14. Cookies, local storage, and analytics

Plaivra uses necessary browser storage and authentication/session technologies for sign-in, security, language, and user-selected preferences. The audited launch code does not include advertising or marketing trackers. Privacy-aware product analytics may be introduced only after purpose, provider, data fields, retention, and consent requirements are approved and disclosed. Non-essential analytics will not be enabled before any required consent.

15. Age eligibility

The initial EU launch is limited to people aged 16 or older. Registration and onboarding enforce the same threshold. Accounts with missing or conflicting historical evidence are reviewed and are not silently deleted. Plaivra has not implemented a parental-consent architecture.

16. Changes and versions

Material changes receive a new version and, where required, a renewed consent. The current policy version and effective date appear at the top of this page. Earlier consent records remain versioned for accountability.