Vitalkultur · Effective: 30 May 2026 · Version 2.0 — portfolio-wide (all iOS apps + vitalkultur.com)
This is the English version. The German version at vitalkultur.com/privacy.html is the legally binding master document under EU/GDPR jurisdiction.
This privacy policy applies to all software products and online services offered by Vitalkultur (Jan Rohwedder, sole proprietor — address in the legal notice / Impressum):
/breathwork/, /carlon-equine/,
/rrloggerpro/, etc.)
Vitalkultur (sole proprietorship)
Owner: Jan Rohwedder
Kapellenstraße 9
76473 Iffezheim, Germany
Email: jan@vitalkultur.com
Website: https://vitalkultur.com
All three apps and the web viewer are built on Privacy by Design and Privacy by Default (Art. 25 GDPR). The default is: data stays on your devices. There are no Vitalkultur-operated servers, databases or cloud services. No personal data is transmitted to Vitalkultur or third parties without your explicit action (export / share sheet).
We do NOT collect (portfolio-wide):
Location exception — CARLON Breathwork: If you grant location permission, the app determines your position once at the start of a session (accuracy approx. 100 m) in order to store altitude, temperature, barometric pressure and humidity as environmental context for that session — relevant for altitude training and weather correlation. The request goes to Apple WeatherKit; only the position is transmitted, no health data. No movement profile and no GPS trace are stored. If you decline the permission, the app remains fully functional — the environmental context simply stays empty. Vitalkultur never receives this data.
Note: If iCloud Backup is enabled on your device, app data (not HealthKit data) may be backed up to your personal iCloud storage. Apple acts as independent controller in that case.
HealthKit data (Art. 9 GDPR):
| Data type | Direction | Purpose | Legal basis |
|---|---|---|---|
| Heart rate (HR) | Read | Live feedback during breathing exercises, Cold-/Heat-Exposure, Iron-Mode strain monitoring | Art. 9(2)(a) + Art. 6(1)(a) GDPR |
| Heart rate variability (HRV / RMSSD) | Read | Vagal-tone trend, recovery score, Iron-Mode ANS strain | Art. 9(2)(a) + Art. 6(1)(a) GDPR |
| Oxygen saturation (SpO₂) | Read | Nightly curve in the sleep and health data export | Art. 9(2)(a) + Art. 6(1)(a) GDPR |
| Mindful minutes | Write | Logging completed sessions | Art. 6(1)(a) GDPR |
Mode-specific data (local, no server):
All mode data stays exclusively on iPhone and Apple Watch. HealthKit permissions can be revoked any time at iOS Settings → Privacy & Security → Health → CARLON Breathwork.
Sensor data (local, no server):
Subject/horse metadata (local):
GDPR note on personal data: Horse data per se is not personal data under GDPR. However, as soon as owner or veterinarian names, addresses or contact details are entered into notes or subject profile, this becomes personal data under Art. 4(1) GDPR. These fields stay exclusively on your device; when exporting JSON, owner names and veterinarian contacts are excluded by Privacy-by-Design from the export (data minimisation, Art. 5(1)(c) GDPR).
Web viewer at vitalkultur.com/carlon-equine/: JSON exports can be opened locally in the browser (drag-drop or file picker). No transmission to Vitalkultur occurs — the viewer is a static HTML application running exclusively client-side (zero-upload architecture).
This statement covers opening and viewing your own files
in the viewer. It does not cover the measuring station at
/carlon-equine/app/messen.html, which lets you hand a recording
over to a veterinary practice in encrypted form on your own
initiative — see section 3.4.
SHA-256 integrity hash: every export carries an integrity hash and a W3C-PROV provenance chain for reproducibility and audit-grade documentation.
Local data:
CARLON Research has no HealthKit integration and does not write to Apple Health. There are no Vitalkultur servers. All data and exports stay under your control.
Measuring station (the horse owner's browser):
Handover to the practice — as a file, without us:
The measuring station turns the recording into a file on the owner's device. The owner passes that file on herself, over a route she chooses (messenger, email, direct transfer). We do not process this file. It never reaches us, we do not store it and do not forward it; we learn neither its content nor its recipient. There is no relay at Vitalkultur for it.
With a practice key (poster or invitation scanned): the file is encrypted on the owner's device against the practice's public key (ECIES over P-256, HKDF-SHA-256, AES-GCM-256). The corresponding private key is created in the practice's browser and never leaves it. In transit the file is therefore unreadable even to the operator of the route chosen by the owner.
Without a practice key: encryption is then impossible — one cannot encrypt against a key that does not exist. Instead the file is limited to a reduced dataset: beat-to-beat intervals, the metrics derived from them, signal quality, sensor designation, time and duration, and the freely chosen name of the animal. It contains no details about any person and no identifier of the device — in particular no browser identifier. By choosing the route, the owner decides to whom she identifies herself.
So that this is more than a promise: an automated check
(t-dateiweg) blocks release if any field or value pointing
to a person appears in that reduced dataset.
Practice cockpit “CARLON Equine Visite”:
Roles under Art. 4 GDPR: for the data of its clients and patients the veterinary practice is the controller. Vitalkultur provides the tool and has no access to the content. Where an owner hands a recording of her own horse to her own vet, Art. 2(2)(c) GDPR applies in addition: she is acting for purely personal purposes.
Licence service lizenz.carlon.app:
n: + truncated SHA-256 of the Stripe customer number, without any name) to detect active use — Art. 6(1)(f) GDPR; deleted after 400 days at the latestInfrastructure behind the licence service — Cloudflare:
The licence service runs on Cloudflare Workers KV (Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA). Cloudflare is therefore a recipient within the meaning of Art. 13(1)(e) GDPR. Recordings do not travel through it — they reach neither Cloudflare nor us.
Storage location: according to the vendor's own documentation, Workers KV cannot be confined to the EU — unlike other Cloudflare services it offers no jurisdiction switch. A transfer to a third country therefore cannot be ruled out. It is based on the EU Standard Contractual Clauses pursuant to Implementing Decision (EU) 2021/914 (Art. 46(2)(c) GDPR).
What is stored there: nothing but the hashed usage marker of a practice described above — no health data, no horse data, no names. Cloudflare additionally encrypts stored values at rest (AES-256-GCM); transport runs over TLS.
All three apps and the web viewer let you export your data as JSON/CSV/Kubios files directly to your device via iOS share sheet or browser download. The exported files stay exclusively under your control.
Note: When exporting health data (HR, HRV, SpO₂, ECG), the responsibility for safe storage of the exported files lies with the user. They should not be stored unencrypted in cloud services.
Purchase of the iOS apps takes place via the Apple App Store. Apple Inc. acts as independent controller. Vitalkultur receives no payment data from Apple — only anonymised purchase statistics.
Apple processes data in the USA based on EU Standard Contractual Clauses under Implementing Decision (EU) 2021/914 (Art. 46(2)(c) GDPR). Apple's privacy policy: apple.com/legal/privacy/en-ww
Session data and settings sync between Apple Watch and iPhone via Apple's WatchConnectivity framework. Transfer is encrypted via Bluetooth or Wi-Fi directly between your own devices. No transmission via internet or external servers.
CARLON Equine and CARLON Research use Bluetooth Low Energy (BLE) to connect to Polar H10 chest straps. The BLE permission is requested on first app launch. No Bluetooth connection data is transmitted to Vitalkultur. Polar Electro Oy is the manufacturer of the H10 and independent controller for any Polar-operated cloud services (Polar Flow). Vitalkultur apps use no Polar cloud — the H10 connection is exclusively direct between sensor and iPhone.
This website is hosted on GitHub Pages (GitHub, Inc., USA). GitHub may collect technical access data (IP addresses, access times) in server logs. Processing of these server logs is the responsibility of GitHub. Vitalkultur does not systematically access this log data. GitHub may use CDN services; technical access data is processed under GitHub's privacy policy.
GitHub is certified under the EU-US Data Privacy Framework (DPF) (Commission adequacy decision of 10 July 2023, Art. 45 GDPR). Details: GitHub Privacy Statement.
The website uses no cookies and no Google Analytics.
We use GoatCounter (goatcounter.com), a privacy-friendly open-source web-analytics service. GoatCounter sets no cookies, stores nothing on your device (no localStorage, no cache), performs no browser fingerprinting and builds no cross-device profiles.
IP address and user agent are processed for at most 8 hours, in memory only, to recognise repeat visits within a day; all that reaches the database is a randomly generated string that cannot be traced back. The IP address and user agent themselves are not stored persistently.
What is evaluated are aggregated page views: page URL, referrer domain, browser type, operating system, screen width, language and the country, which GoatCounter derives from the IP address — the IP address itself is not stored. Identification of individual visitors is therefore not possible.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is
data-minimal reach measurement in order to improve the site. As GoatCounter
neither recognises visitors persistently nor builds profiles, visitors’
interests do not override ours.
Service provider: GoatCounter is operated by Martin Tournoij
(Ireland, EU); its servers are located at Hetzner Online GmbH in Germany
and Finland. No third-country transfer. According to the provider, neither
IP addresses nor the full User-Agent header are stored.
Retention: Only aggregated, non-personal metrics are kept; the
attributes used for session recognition expire after 8 hours at most. According
to the provider, data may remain in backups for up to 30 days.
Opt-out: If your browser sends Do Not Track (DNT)
or Global Privacy Control (GPC), the analytics script is
not loaded at all — no data whatsoever is collected.
Right to object under Art. 21(1) GDPR: You may object to this legitimate-interest processing at any time — informally by e-mail to jan@vitalkultur.com, or with immediate technical effect by enabling DNT or GPC in your browser. We will then stop the processing unless we can demonstrate compelling legitimate grounds.
When contacting us by email (e.g. CARLON Equine beta inquiries), we process your email address and message content to handle your request.
Legal basis: Art. 6(1)(b)/(f) GDPR
Storage period: Until your request is closed, then
typically 3 years from end of the year the request was closed
(§§ 195, 199 German Civil Code).
Vitalkultur does not share personal data with third parties, except with Apple Inc. as part of the App Store purchase process and as legally required (Art. 6(1)(c) GDPR, e.g. by official order).
| Data category | Storage location | Storage period |
|---|---|---|
| HealthKit data (Breathwork) | Local (Apple HealthKit) | Until manual deletion in iOS "Health" app |
| App session data (all 3 apps) | Local (device) | Until app uninstall or manual deletion |
| Custom presets / horse profiles / device roster | Local (device) | Until deletion or app uninstall |
| Iron-Mode / Cold-/Heat-Exposure session logs | Local (device) | Until deletion or app uninstall |
| Safety notice confirmation | Local (UserDefaults) | Until app uninstall |
| Email correspondence | Email inbox | Until resolved, then max. 3 years (§§ 195, 199 BGB) |
When you uninstall an app, all locally stored data of that app is automatically deleted. HealthKit data stays in Apple Health until manually deleted there.
To exercise your rights, contact us at the email address above any time.
| Right | Implementation |
|---|---|
| Access (Art. 15) | Email request to jan@vitalkultur.com |
| Rectification (Art. 16) | Direct in the respective app |
| Erasure (Art. 17) | Uninstall app; HealthKit: iOS "Health" app → Data Access & Devices |
| Restriction (Art. 18) | We do not process measurement or patient data server-side — for those the right has no object. For the data we do process (licence, sign-up form, email correspondence): by email request. |
| Portability (Art. 20) | JSON/CSV/Kubios export directly in the app / web viewer |
| Objection (Art. 21) | Objection against processing based on Art. 6(1)(f) GDPR by email any time |
| Withdrawal of consent (Art. 7(3)) | HealthKit: iOS Settings → Health → respective app |
You have the right to lodge a complaint with the competent data protection supervisory authority:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit
Baden-Württemberg
Heilbronner Straße 35, 70191 Stuttgart, Germany
www.baden-wuerttemberg.datenschutz.de
Heart rate, HRV, SpO₂ and ECG raw data are health data of the special category under Art. 9(1) GDPR. Processing is based on your explicit consent (Art. 9(2)(a) GDPR) via:
All consents are voluntary and revocable any time.
The Vitalkultur apps are not directed at persons under 16 (Art. 8 GDPR in conjunction with German law). The provider knowingly collects no data from minors under 16.
For material changes, users will be informed in the app. The current version is always available at: vitalkultur.com/privacy-en.html