AnklePath • Last updated: 12 August 2026
This Privacy Policy explains what information the AnklePath mobile application ("AnklePath", "the app", "we", "us") collects, how we use it, and the choices you have.
The controller responsible for your data under the GDPR is:
Timothy Wasswa
Dachauer Straße 109
80335 München
Germany
E-mail: 24.stom.wasswatimothy@gmail.com
See also our Impressum.
| Category | Examples | Why |
|---|---|---|
| Account information | Email address and name when you sign in with Apple, Google, or email. Guest sign-in uses an anonymous identifier with no email. | To create and secure your account and sync your data. |
| Health data you provide | Injury type and timing, symptoms, walking ability, recovery goals, pain check-ins, free-text notes, and completed exercises. | To generate and adjust your recovery plan and show your progress. |
| Profile photo (optional) | An image you choose from your photo library. It stays on your device and is not uploaded to our servers. | Shown only as your in-app profile picture. |
| Consent records | Whether you granted or withdrew health-data and analytics consent, the version of this policy, and the time. | To demonstrate that we obtained consent, as the GDPR requires. |
| Product analytics | App events such as screens viewed and features used, linked to a pseudonymous account identifier. We do not send your name, email, or photo to our analytics provider. | To understand usage and improve the app. |
| Diagnostics & crash data | Crash reports, error messages, app version, device model, and operating system. | To find and fix bugs and keep the app stable. |
| Subscription data | Anonymised purchase and entitlement status from the App Store or Google Play. We never see your card details. | To unlock and restore premium features you have paid for. |
We do not sell your personal information. We do not use your free-text health notes for advertising, and we avoid sending detailed health notes to our diagnostics tools.
Health data is a special category under Article 9 GDPR and receives extra protection. We rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Processing your injury, symptoms, pain scores and notes to build your recovery plan | Your explicit consent — Art. 9(2)(a) GDPR, given on the consent screen before onboarding. You may withdraw it at any time. |
| Creating and running your account, and providing the app's core features | Performance of a contract — Art. 6(1)(b) GDPR. |
| Product analytics | Your consent — Art. 6(1)(a) GDPR. Optional, off by default, and revocable in Profile at any time. |
| Crash and error diagnostics, and keeping the service secure | Our legitimate interest in a stable, secure app — Art. 6(1)(f) GDPR. |
| Subscriptions and billing | Performance of a contract — Art. 6(1)(b) GDPR — and our legal record-keeping obligations, Art. 6(1)(c). |
Open Profile → Health data consent to withdraw your health-data consent, or Profile → Product analytics to turn analytics off. Withdrawal takes effect immediately and does not affect the lawfulness of processing carried out beforehand. Because the recovery plan cannot be personalised without health data, withdrawing consent stops that personalisation; to remove the data already stored, delete your account (below).
We share limited information with trusted providers who process it on our behalf under data processing agreements:
Some of these providers process data outside the European Economic Area, including in the United States. Where that happens, the transfer is covered by the European Commission's Standard Contractual Clauses together with the provider's supplementary technical measures. You may request a copy of the safeguards that apply by contacting us.
| Data | Kept for |
|---|---|
| Account and health data (plan answers, pain logs, notes) | Until you delete your account. Deletion is immediate and irreversible. |
| Data on your device | Until you sign out or delete the app. |
| Consent records | Up to 3 years after your account ends, as evidence that consent was obtained. |
| Crash diagnostics | 90 days. |
| Analytics events | Up to 12 months. |
| Purchase and invoice records | As required by tax and commercial law, typically up to 10 years. |
Under the GDPR you have the right to access, rectify, erase, restrict, and port your data, to object to processing based on legitimate interests, and to withdraw consent at any time. In the app:
If you believe we have handled your data unlawfully, you may lodge a complaint with a supervisory authority — either the one where you live or work, or the one responsible for us:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany
www.lda.bayern.de
AnklePath is not directed to children under 16 (or the minimum age required in your country), and we do not knowingly collect their personal information. If you believe a child has provided us data, contact us and we will delete it.
All communication with our providers is encrypted in transit using TLS. Your data is stored in Google Firebase with access restricted to your own account, and access on our side is limited to what is needed to operate and support the app. No method of transmission or storage is completely secure, but we work to safeguard your data.
AnklePath provides educational guidance and general recovery information. It is not medical advice and does not replace assessment, diagnosis, or treatment by a qualified clinician.
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above, and where the change affects what you consented to, we will ask for your consent again in the app.
Questions or requests: 24.stom.wasswatimothy@gmail.com