Legal
Privacy Policy
Last updated: 7 July 2026
Nowhere is built privacy-first. The app keeps your data on your device by default, and this website collects as little as possible. This policy explains what we process, why, and the rights you have under the GDPR.
1. Who is responsible
The controller for the processing described here is:
Marcus Puchalla — Software DevelopmentGorkistraße 88, 04347 Leipzig, Germany
Email: support@nowhere.fitness
2. When you visit this website
Hosting & server logs
This website and our API are hosted by netcup GmbH, Karlsruhe, Germany (servers in the EU). To deliver and secure the site, the server automatically processes technical data in log files — including your IP address, the time of the request, the page requested, and your browser/OS type. Legal basis: our legitimate interest in operating a secure, functional website (Art. 6(1)(f) GDPR). A data-processing agreement is in place with the host.
Analytics
We use Umami, a privacy-friendly analytics tool that we self-host on our own server. It uses no cookies, does not track you across sites, and stores only aggregated, anonymised statistics (e.g. page views, referrer, country, device type). No personal profile is created and no data is shared with third parties. Legal basis: legitimate interest in understanding basic site usage (Art. 6(1)(f) GDPR).
3. Waitlist sign-up
If you join the pre-launch waitlist, we process the email address you enter (and which page you signed up from) for one purpose: to notify you when Nowhere launches.
- Double opt-in: we email you a confirmation link, and only store your address as active once you click it. If you never confirm, your address is not added.
- Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time via the unsubscribe option or by emailing us — with no effect on prior processing.
- Where: stored on our server at netcup (Germany).
- Retention: until launch plus a short notification period, or until you unsubscribe — whichever comes first.
4. Emails we send
Confirmation and notification emails are sent through our own mail server, operated for us by 1984 Hosting Company in Iceland (part of the EEA, so the GDPR applies). Every email includes an unsubscribe option.
5. Payments (when you buy Plus)
Purchases are processed by Paddle.com Market Limited (Judd House, 18–29 Mora Street, London EC1V 8BT, United Kingdom), which acts as our Merchant of Record. Paddle is the seller of record for the transaction: it collects and processes your payment and billing details as an independent controller, handles tax, and manages fraud and chargebacks. We never receive or store your full card details. From Paddle we receive only what we need to fulfil your order — confirmation of purchase, your licence/entitlement, and limited billing metadata such as country (for tax) and subscription status. See Paddle's privacy policy at paddle.com/legal/privacy. The UK is covered by a European Commission adequacy decision.
6. The Nowhere app
- Local-first: your treadmill, step and session data is stored locally on your device and is not sent to us.
- Optional cloud backup/sync (a Plus feature): if you turn it on, your data is encrypted on your device before upload (end-to-end). We store only encrypted blobs and cannot read their contents.
- Licence activation: to bind a Plus licence to your installations and enforce seat limits, we use a randomly generated, anonymous device identifier — not a hardware fingerprint.
7. We do not sell your data
We do not sell your personal data and do not share it with third parties for advertising. The only processors involved are those named above (hosting, mail, and the payment provider), each engaged to run the service.
8. Your rights
Under the GDPR you have the right to access, rectification, erasure, restriction of processing, data portability, and to object to processing, as well as to withdraw any consent at any time. To exercise any of these, email support@nowhere.fitness.
You also have the right to lodge a complaint with a supervisory authority. Ours is the Saxon Data Protection and Transparency Commissioner (Sächsische Datenschutz- und Transparenzbeauftragte, Devrientstraße 5, 01067 Dresden).
9. Changes to this policy
We may update this policy as the product evolves (for example, when the app and its cloud features launch). The current version always lives at this URL, with the date shown above.