Privacy Policy
Last updated: 23 May 2026
This Privacy Policy ("Policy") explains how Joshua Kraft, sole proprietor (Einzelunternehmer), Alte Eppelheimer Str. 16, 69115 Heidelberg, Germany, doing business as Temple ("we", "us", or "our"), processes your personal data when you use our Services.
This Policy applies when you:
download and use our mobile application;
interact with our AI training agent via our iMessage channel;
visit any current or future Temple website that links to this Policy; or
otherwise engage with us, including for support, feedback, surveys, or events (together, the "Services").
About Temple. Temple is an AI-powered training companion that helps athletes and fitness-focused users plan and adapt training programs. After onboarding, Temple creates a personalized training plan that you can refine through an ongoing conversation with an AI agent — in the app or via iMessage. The agent can suggest adjustments and, with your confirmation, apply them. Temple is designed to support your training; it is not a medical device and does not provide medical advice.
This Policy is provided in accordance with Articles 13 and 14 of the EU General Data Protection Regulation ("GDPR") and the German Federal Data Protection Act ("BDSG"). If you do not agree with this Policy, please do not use the Services. Questions can be sent to joshua.kraft@cdtm.com.
Summary of Key Points
Who we are. Temple is operated by Joshua Kraft, a sole proprietor based in Germany. The controller under GDPR Art. 4(7) is Joshua Kraft.
What we process. Account data, profile and onboarding data (e.g., birth date, height, weight, goals, equipment), optional health data (injuries, medical conditions, data from connected health devices), chat content exchanged with the AI agent, phone number (if you use iMessage), subscription metadata, and technical usage data.
Sensitive data. Some information is "special category" personal data under GDPR Art. 9 — in particular health data. We process such data only with your explicit consent and only to deliver the Services.
Where data is stored. Our backend and database are hosted in the EU (Frankfurt, Germany). Some service providers are located outside the EU; in those cases we rely on appropriate safeguards under GDPR Chapter V.
AI processing. Your messages and relevant context are sent to AI service providers to generate responses. We do not use your personal data, chat content, or health data to train AI models, and we contractually require the same of our AI providers where this option is available.
Your rights. You have rights of access, rectification, erasure, restriction, portability, and objection under GDPR Articles 15–22, and the right to lodge a complaint with a supervisory authority. US residents have additional rights described in Section 13.
Minimum age. The Services are intended for users aged 16 or older.
Table of Contents
Controller and Contact
What Personal Data We Process
How We Use Your Information
Legal Bases for Processing
Special Categories of Personal Data (Art. 9 GDPR)
AI Processing and Automated Decisions
Recipients and Service Providers
International Data Transfers
Retention
Security
Your Rights
Minimum Age
US Residents
Cookies, Analytics, and Communications
Changes to this Policy
How to Contact Us
Supervisory Authority
1. Controller and Contact
In Short: Joshua Kraft (Temple) is the data controller. You can reach us by email or post.
The data controller under Art. 4(7) GDPR is:
Joshua Kraft Einzelunternehmer (sole proprietor) Alte Eppelheimer Str. 16 69115 Heidelberg, Germany Email: joshua.kraft@cdtm.com
We have not appointed a Data Protection Officer because we are not required to do so under Art. 37 GDPR or §38 BDSG.
2. What Personal Data We Process
In Short: We process the data you give us, data your device provides, and data we receive from sign-in and connected-service providers you choose to use.
Depending on how you use the Services, we may process the following categories of personal data:
Account and identification data: name, email address, profile picture (if you upload one), and unique account identifiers from your sign-in provider (Apple or Google).
Profile and onboarding data: date of birth, gender, height, weight, training experience, fitness goals, sport preferences, available equipment, planned training frequency, and similar information you provide.
Health and wellness inputs (special category data — see Section 5): injuries, medical conditions, recovery status, and other health information you voluntarily share with the AI agent or include in your profile.
Imported biometric and activity data (special category data): information from third-party health and fitness platforms you choose to connect (such as Apple HealthKit, Garmin, Whoop, or Oura), which may include heart rate, sleep, workouts, training load, recovery, and similar metrics.
Training and lifestyle logs: workout history, plan adherence, scheduled and completed sessions, notes, and similar entries.
Chat content: messages exchanged with the AI agent in the app and via iMessage, confirmations you give before the agent takes action, and related context.
iMessage data: your phone number (if you use the iMessage channel), message content routed through our messaging provider, and delivery metadata.
Subscription metadata: subscription status, plan, renewal/expiry, and anonymous Apple transaction identifiers. We do not receive, store, or process your payment card data.
Device and technical data: device type, operating system and version, app version, language, time zone, authentication tokens, crash diagnostics, and in-app usage events.
Communications: any information you provide when you contact us (e.g., support requests, feedback, survey responses).
We may also receive information from third parties you choose to connect: sign-in providers (Apple, Google), connected health and fitness platforms, and our service providers (e.g., authentication, AI, analytics).
3. How We Use Your Information
In Short: We use your data to run the Services, power the AI agent, communicate with you, keep things secure, improve the product, and comply with law.
We process your personal data to:
create and authenticate your account;
generate and adapt your personalized training plan;
operate the AI agent in the app and via iMessage, and let it propose actions you confirm;
route messages through the iMessage channel;
manage your subscription and meet related tax and accounting obligations;
send you service-related and transactional communications (e.g., training reminders, agent responses, account or policy updates);
where you have given consent, send you optional re-engagement, product update, or promotional communications, which you can opt out of at any time;
respond to your inquiries, support requests, and feedback;
monitor, secure, and debug the Services and prevent abuse;
analyze aggregated or pseudonymized usage data to understand how the Services are used and to improve features, performance, and reliability; and
comply with applicable legal obligations.
No AI model training on your data. We do not use your personal data, chat content, or health data to train AI models, whether our own or those of third parties. Where AI providers offer a "do not train" setting, we use it.
4. Legal Bases for Processing
In Short: We process your data only where we have a valid legal basis under Art. 6 GDPR (and Art. 9 for sensitive data).
PurposeLegal basisProviding the core Services (account, training plan, AI agent, iMessage, subscription)Art. 6(1)(b) — performance of contractProcessing health and biometric dataArt. 9(2)(a) — explicit consentTax, accounting, and other legal obligationsArt. 6(1)(c) — legal obligationSecurity, abuse prevention, debugging, aggregated analytics, product improvementArt. 6(1)(f) — legitimate interestsOptional marketing or re-engagement communicationsArt. 6(1)(a) — consentResponding to inquiriesArt. 6(1)(b) or (f), depending on the request
You can withdraw consent at any time with effect for the future (see Section 11). Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
5. Special Categories of Personal Data (Art. 9 GDPR)
In Short: We treat your health data with extra care and only process it with your explicit consent.
The following data are "special category" personal data under Art. 9 GDPR because they concern your health:
injuries and medical conditions you disclose;
biometric and physiological data from connected devices; and
inferences about your physical condition derived from training and health data.
We process this data only on the basis of your explicit consent under Art. 9(2)(a) GDPR. Consent is requested separately and unambiguously — for example, through a dedicated toggle when you connect a health device, or a clear notice before sensitive health information is processed.
You can withdraw your consent at any time by disconnecting the relevant integration in the app or contacting us at joshua.kraft@cdtm.com.
Temple is not a medical device. Information provided by the AI agent does not constitute medical advice. Always consult a qualified healthcare professional for medical matters.
6. AI Processing and Automated Decisions
In Short: Your messages and context are sent to AI service providers to generate responses. The agent never takes consequential actions without your confirmation.
How the AI agent works. When you interact with Temple, your messages and relevant profile context are sent to one of our AI service providers (currently including OpenAI, Anthropic, and Google) to generate a response. The specific provider used may vary based on availability, performance, and task type. Each provider acts as a processor on our behalf.
Actions taken by the agent. The AI agent can propose changes to your training plan. Such actions are always subject to your explicit confirmation in the app before they take effect. We do not make legally or similarly significantly affecting decisions about you solely on the basis of automated processing within the meaning of Art. 22 GDPR.
No model training on your data. As stated in Section 3.
Changes to AI providers. The set of AI providers may evolve. If we materially change them, we will update this Policy.
7. Recipients and Service Providers
In Short: We rely on a small set of service providers to run the Services. We do not sell your personal data.
We share personal data only with service providers that help us operate the Services, and only as needed for them to perform their role. Categories of service providers we currently use include:
Hosting and infrastructure (EU region)
Authentication (sign-in with Apple and Google)
Subscription management (working with Apple's In-App Purchase system)
iMessage routing and delivery
AI service providers for generating agent responses
Product analytics and crash reporting (EU region)
Each engagement is governed by a written data processing agreement under Art. 28 GDPR where applicable. We may add, replace, or remove service providers from time to time as the Services evolve.
We may also disclose personal data to:
public authorities, courts, or law enforcement where legally required;
professional advisors (e.g., tax advisor, accountant, legal counsel) where necessary and subject to confidentiality; and
a successor entity, in the event of a business transfer, merger, or sale of assets — you will be informed before such a transfer takes place.
We do not sell your personal data, and we do not share it with third parties for their own advertising purposes.
8. International Data Transfers
In Short: Our infrastructure is in the EU. Some service providers are located outside the EU, and we use appropriate safeguards in those cases.
Our primary database and backend infrastructure are located in the European Union (Frankfurt, Germany). Some service providers — in particular AI, authentication, iMessage routing, and subscription-management providers — are located in the United States or operate globally.
Where personal data is transferred outside the EEA to a country not recognized as providing an adequate level of data protection, we rely on appropriate safeguards under Art. 46 GDPR, in particular:
the EU Standard Contractual Clauses (SCCs) adopted by the European Commission; and/or
where applicable, the EU–U.S. Data Privacy Framework for certified U.S. recipients.
We also apply supplementary technical and organizational measures (such as transport encryption, access controls, and data minimization). You may request a summary of the safeguards in place at joshua.kraft@cdtm.com.
9. Retention
In Short: We keep your data only as long as needed for the purposes in this Policy, or as required by law.
Data categoryRetentionAccount, profile, and onboarding dataFor the duration of your accountHealth and sensitive dataFor the duration of your account, or until you withdraw consent or disconnect the relevant integrationChat messagesFor the duration of your account, unless you delete individual messages or your chat history in the appPhone number (iMessage)While the iMessage channel remains active for your accountSubscription and billing metadataFor the duration of your account, plus up to 10 years for tax/invoicing obligations under §147 AO and §257 HGBTechnical logs and crash reportsUp to 90 daysProduct analytics eventsUp to 24 months in identifiable form, then aggregated or deleted
When you delete your account, we delete or anonymize your personal data without undue delay, except where retention is required by law. Backups are overwritten on a regular rolling cycle.
10. Security
In Short: We use appropriate technical and organizational measures to protect your data — but no system is 100% secure.
We implement measures under Art. 32 GDPR, including encryption in transit (TLS) and at rest, access controls, the principle of least privilege, regular software updates and dependency monitoring, and logging and monitoring through our analytics and error-reporting providers. We also impose contractual security obligations on our service providers.
If we become aware of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours where required by Art. 33 GDPR and inform you where required by Art. 34 GDPR.
11. Your Rights
In Short: Under the GDPR you have a range of rights over your personal data. The easiest way to use most of them is to email us.
Under the GDPR you have the following rights:
Access (Art. 15) — confirmation of whether we process data about you, and a copy.
Rectification (Art. 16) — correction of inaccurate or incomplete data.
Erasure (Art. 17) — deletion of your data where one of the grounds applies.
Restriction (Art. 18) — restriction of processing in certain cases.
Portability (Art. 20) — a copy of the data you provided in a structured, machine-readable format.
Objection (Art. 21) — in particular against processing based on legitimate interests.
Withdraw consent (Art. 7(3)) — at any time, with effect for the future.
Not be subject to a solely automated decision (Art. 22) — as noted in Section 6, we do not take such decisions.
How to exercise your rights:
Account deletion: delete your account directly in the app at any time. This is the simplest way to exercise your right to erasure.
Other rights: email joshua.kraft@cdtm.com. We will respond without undue delay and in any case within one month (Art. 12(3) GDPR).
We may need to verify your identity before fulfilling a request in order to protect your data against unauthorized disclosure. You will not be discriminated against for exercising any of your rights.
Opting out of marketing or re-engagement communications: if you have given consent to optional marketing, re-engagement, or product update communications, you can withdraw it at any time in the app's notification settings, via any unsubscribe link in the relevant message, or by contacting us. We may still send you service-related messages (e.g., training reminders, security or policy updates).
12. Minimum Age
In Short: Temple is for users aged 16 and older.
The Services are intended for users aged 16 or older, in line with Art. 8(1) GDPR and German national rules. In jurisdictions that require a higher minimum age, you must meet that age.
We do not knowingly collect data from anyone under 16. If you believe a child under 16 has used the Services, contact us at joshua.kraft@cdtm.com and we will delete the account and associated data.
13. US Residents
In Short: If you live in the US, you have additional rights under your state's privacy laws.
If you are a resident of a US state with a comprehensive privacy law (including, depending on the state, California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia), you may have the right to:
know whether we process your personal information and access a copy;
correct inaccuracies;
request deletion;
obtain a portable copy;
opt out of targeted advertising, the sale of personal information, or profiling that has legal or similarly significant effects;
limit the use and disclosure of sensitive personal information (where applicable, e.g., under California law); and
not be discriminated against for exercising your rights.
We do not sell your personal information, do not share it for cross-context behavioral advertising, and do not engage in targeted advertising. We honor opt-out preferences signaled via the Global Privacy Control (GPC) where applicable.
To exercise these rights, email joshua.kraft@cdtm.com. You may designate an authorized agent, subject to verification. If we decline a request, you may appeal by replying to our response.
14. Cookies, Analytics, and Communications
In Short: The app doesn't use browser cookies. We use lightweight analytics and crash reporting, and we send service messages (plus optional marketing if you opt in).
Cookies. The Temple mobile app does not use browser cookies. The app stores technical identifiers locally on your device (e.g., authentication tokens, session identifiers, preference settings) that are strictly necessary to operate the Services. If we launch a website that uses cookies, a separate cookie banner and notice will apply, in compliance with §25 TDDDG.
Analytics and crash reporting. We use product analytics and crash-reporting tools (currently hosted in the EU) to understand how the Services are used and to improve stability and usability. These tools collect pseudonymized usage events, performance and crash diagnostics, a randomly generated installation identifier, and device metadata. This processing is based on our legitimate interest under Art. 6(1)(f) GDPR. We may also run A/B tests and feature experiments. You can object at any time at joshua.kraft@cdtm.com.
Push notifications. The app may send transactional and service-related push notifications (e.g., training reminders, agent responses, plan changes) via the Apple Push Notification Service. These are part of the Services you signed up for. Optional re-engagement or promotional notifications will only be sent with your prior consent and can be turned off at any time in the app or your device settings.
Email and other communications. We may send you transactional and service-related emails (e.g., account, subscription, security, or policy updates). With your consent, we may also send optional product updates, re-engagement messages, or promotional communications. You can withdraw consent at any time.
15. Changes to this Policy
We may update this Policy from time to time to reflect changes in our processing activities or in applicable law. The "Last updated" date at the top of this Policy indicates when it was last revised. For material changes, we will notify you in advance through the app or by another appropriate means.
16. How to Contact Us
For any question about this Policy or how we process your personal data, please contact:
Joshua Kraft Alte Eppelheimer Str. 16 69115 Heidelberg, Germany Email: joshua.kraft@cdtm.com
17. Supervisory Authority
You have the right to lodge a complaint with a data-protection supervisory authority — in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement (Art. 77 GDPR).
The competent supervisory authority for the controller is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg Lautenschlagerstraße 20 70173 Stuttgart, Germany Website: https://www.baden-wuerttemberg.datenschutz.de