LUDUZO

This is a draft. Do not rely on it.

It is missing the legal entity, the business address, the governing law, a contact address for data requests. Until those are filled in and a lawyer has read the whole thing, this page states no binding terms and should not be shown to a paying customer.

Privacy

This explains what LUDUZO stores about you, where it is kept, and who can reach it. It is written to be read, not to be survived.

Two different relationships, and which one is yours

This matters more than anything else here, because it decides who you ask when you want something changed.

  • If you are a member of a gym, your gym decides what to record about you and why. They are responsible for that information. LUDUZO holds it on their behalf and does nothing with it that the gym has not asked for. Ask your gym first — they can correct or delete your record themselves.
  • If you run a gym, the account you signed up with — your name, your email, your sign-in history — is ours to answer for, and you can ask us about it directly.

What is stored

A gym chooses how much of this to fill in. Most fill in very little. Nothing below is collected automatically — every field is one a person at the gym typed, or one you typed yourself.

  • Name, email address, phone number, date of birth, and a membership number.
  • A photograph, if you or your gym upload one.
  • Attendance — when you checked in and out, and which classes you booked.
  • Purchases and invoices raised at the gym, and any passes bought.
  • Anything the gym records about your training: goals, fitness level, body measurements, workout and meal plans, and free-text notes.
  • Documents your gym stores against your record, such as a signed waiver.

Some of that is health information

Body measurements, fitness level, training goals and meal plans say something about your health, and the law treats that more carefully than it treats your phone number. Your gym should only record it with your agreement and only because you are asking them to train you. If you would rather they did not hold it, tell them — the system lets them clear those fields without closing your membership.

Where it is kept

On a single dedicated server in Nuremberg, Germany, operated by Hetzner Online GmbH. Your information does not leave the European Union, and it is not copied to another company's service to be processed.

Who else can see it

Nobody. There are none third-party services in this product — no analytics, no advertising trackers, no tag managers, no external fonts or scripts loading in the background while you use it. This was verified against the source code on 28 August 2026 rather than assumed.

Two honest exceptions worth naming. If your gym has published its address, tapping it opens a map at Google — that request is yours, made when you tap it, and nothing about you is sent unless you do. And email we send you passes through the internet like any other email before it reaches your inbox.

One gym can never see another gym's members. That is enforced by the database itself rather than by application code remembering to check, and it is tested by attacking it — every table is driven from a rival gym's account on every deploy to confirm it returns nothing.

Cookies

a single sign-in cookie, and nothing else. It exists so that signing in lasts, it cannot be read by scripts in your browser, it is not sent to other sites, and it expires after 30 days. There are no advertising or analytics cookies, which is why this product has never shown you a cookie banner.

How long it is kept

  • Your record is kept while your membership exists, and for as long afterwards as your gym chooses.
  • Encrypted backups of the whole database are kept for 14 days and then deleted. A record erased today can therefore still exist in a backup for a short time before ageing out.
  • Sign-in sessions expire after 30 days.

What you can ask for

You can ask for a copy of what is held about you, ask for it to be corrected, or ask for it to be erased. Erasure is real here: it removes the record rather than hiding it, and the system keeps a note that an erasure happened without keeping what was erased.

Ask your gym first — they can do all of this themselves and they will be quicker. If they cannot help, write to us at «not yet set».

How it is protected

  • Everything travels over an encrypted connection; plain HTTP is refused.
  • Passwords are never stored — only a value that cannot be turned back into your password.
  • Separation between gyms is enforced in the database, and tested by attack on every deploy.
  • Backups are encrypted before they leave the machine.

No one can promise a system cannot be broken into. What we can say is what is actually done, which is written above, and that we would tell you if it happened.

Who we are

«not yet set», of «not yet set». Questions about any of this go to «not yet set».

See also the terms of service.