Privacy Policy
Effective date: 18 July 2026
This policy covers the Attendlr app (Android, iOS and the web version at app.attendlr.com) and the attendlr.com website.
Attendlr is a record-keeping app for trainers: attendance, passes, payments and client management. This policy explains in plain language what data we handle, why, and what rights you have.
1. Who is responsible for your data?
Service provider (data controller):
Attila Tóth, sole proprietor (registered in Hungary)
Registered address: Bartók Béla út 98/F, 1115 Budapest, Hungary
Registration number: 50144734
Email: support@attendlr.com
Two kinds of data appear in Attendlr, and different rules apply to each:
- Your data (your trainer account and subscription) — for this, we are the data controller.
- Your clients' data, which you enter into the app (students, leads, contact persons) — for this, you are the data controller and we act as your data processor. See section 6.
2. What data do we collect about you?
When you create an account and use the app, we process the following:
| Data | Required? | What we use it for |
|---|---|---|
| Name (display name) | Yes | Identifying your account, addressing you in the app |
| Email address | Yes | Sign-in, account management, password reset, support |
| Password | Yes (email sign-up) | Sign-in — stored only in encrypted form by Firebase Authentication; we never see it |
| Phone number | No | Contacting you, if you provide it |
| Timezone and language | Yes (automatic) | Showing times and the interface correctly |
| User ID (UID) | Yes (automatic) | Technically linking your data to your account |
| Subscription tier and status | Yes (paid plans) | Unlocking the features you purchased |
| Push notification token | No (only if you enable notifications) | Delivering push notifications to your phone |
| Crash reports (mobile app only) | Yes (automatic) | If the app crashes, we receive the technical error report — the stack trace, your device model, OS and app version, plus your user ID (UID) so we can connect the crash to a support request. It contains no name, email or client data. Used solely to fix the fault. |
| Usage statistics | Yes (automatic — you can switch it off) | Which screens you open and which core actions you take (e.g. an attendance was recorded), together with your user ID (UID) and your subscription tier. It contains no name, email, client data or amounts — only anonymous counts and labels. We use it solely to understand which features are used, so we can improve the app. You can switch it off at any time: Settings → Account → Privacy. |
| Support chat messages | No (Premium plan, only if you write to us) | If you use the in-app support chat, we store your messages and our replies so we can help you and keep the conversation history. Visible only to you and our support staff. |
If you sign in with Google or Apple, we receive your name and email address from them — nothing else.
We never handle card details. Subscriptions are billed through Google Play or the App Store; your payment details go to them, never to us.
3. What we deliberately do NOT do
- No advertising in the app, and no data handed to advertisers.
- We never sell your data, in any form.
- No advertising profiling, no cross-app tracking: we do not build a profile of you, do not follow you across other apps or websites, and do not measure what you click for marketing purposes. We do measure how the app itself is used — anonymously, without names, emails or amounts — so we can improve it; you can switch that off in Settings → Account → Privacy. (We also receive automatic crash reports — purely technical fault data. See section 2.)
- We never request access to your phone's contacts, photos or location.
- We do not process health data — the app records attendance and payments, not performance or body metrics.
4. Purposes and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the service: account, storage, sync | Performance of a contract — Art. 6(1)(b) |
| Subscription management, entitlements | Performance of a contract — Art. 6(1)(b) |
| Sending push notifications | Consent — Art. 6(1)(a) (withdrawable any time in your phone settings) |
| Support, troubleshooting | Legitimate interest — Art. 6(1)(f) |
| Legal obligations (e.g. invoicing) | Legal obligation — Art. 6(1)(c) |
5. Who has access to the data? (processors)
Attendlr is built on trusted, contracted data processors. They act on our instructions only and may not use the data for their own purposes:
| Processor | What it does | Where it stores data |
|---|---|---|
| Google Cloud / Firebase (Google Ireland Ltd.) | Database (Cloud Firestore), sign-in (Authentication), server-side functions, web hosting, push notifications (Cloud Messaging), crash reporting (Crashlytics — mobile app only), usage statistics (Google Analytics for Firebase) | The database is located in the European Union (eur3 multi-region). Crash reports and usage statistics are processed on Google's infrastructure. |
| RevenueCat, Inc. | Subscription tracking (which plan is active) | USA — under the EU–US Data Privacy Framework and Standard Contractual Clauses |
| Google Play / Apple App Store | Processing subscription payments | Under their own privacy policies |
| Cloudflare, Inc. | Visit statistics for the attendlr.com website (cookieless Cloudflare Web Analytics) and the domain's DNS | USA — under the EU–US Data Privacy Framework; measurement uses no cookies and no individual identification, and IP addresses are processed only transiently |
Beyond these, we share your data with no one, unless required by law (e.g. an official request from an authority).
6. Your clients' data — your responsibility
You enter data about your students, leads and their contact persons into the app: names, contact details, birthdays, gender, notes, attendance, payments.
For this data, you are the data controller under the GDPR, and Attendlr stores and processes it as your data processor. In practice this means:
- You must ensure you record your clients' data lawfully (informing them and having a legal basis — typically your training-service agreement with them).
- Recording a minor's data requires the knowledge of a parent or guardian.
- If a client asks you to delete or hand over their data, you must fulfil that request — every record in the app can be edited and deleted.
We store and display this data solely to provide the service to you; we never use it for any other purpose, analyse it, or pass it on.
7. How long do we keep data?
- Your data is kept as long as your account exists, or until you delete a given record.
- Account deletion: you can permanently delete your account and everything belonging to it — including your clients' records — at any time from inside the app: Settings → Account → Delete account. For your protection we ask you to sign in again first. The deletion is immediate and irreversible: it removes your profile, every record you created, any uploaded files, and your login itself. If you no longer have the app installed, email support@attendlr.com and we will delete the account for you. Note that a paid subscription is managed by Google Play or the App Store, so please cancel it there separately.
- Backups: the database is backed up regularly for operational safety. Deleted data disappears from backups permanently after at most 98 days.
- Billing records are retained for the legally required period (typically 8 years in Hungary).
8. Data security
- All traffic travels over encrypted connections (TLS).
- Data is stored on Google Cloud infrastructure in the EU, with industry-standard protection.
- Every trainer's data is technically isolated: access rules guarantee that you can only ever reach your own account's data.
- Passwords are handled by Firebase Authentication with one-way encryption — neither we nor anyone else can recover them.
9. Your rights
Under the GDPR you have the right at any time to:
- access the data we hold about you (request a copy);
- rectify inaccurate data;
- erase your data (the "right to be forgotten");
- restrict processing;
- port your data (receive it in a machine-readable format);
- object to processing based on legitimate interest;
- withdraw any consent (e.g. push notifications) at any time.
To exercise any of these, email support@attendlr.com — we respond within 30 days.
If you believe we process your data unlawfully, you may lodge a complaint with the supervisory authority:
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Falk Miksa utca 9–11, 1055 Budapest, Hungary · www.naih.hu · ugyfelszolgalat@naih.hu
You may also bring the matter before the competent court of your place of residence.
10. Children
Attendlr accounts are intended for professionals (trainers) aged 18 or over. We do not knowingly collect data from children. (Minors recorded as students are covered by section 6 — there, you are the data controller.)
11. Cookies and local storage
- The web app (app.attendlr.com) uses the local storage required for it to function (sign-in session, offline cache), plus a first-party analytics cookie (
_ga) for the usage statistics described in section 2 — which you can switch off in Settings → Account → Privacy. It uses no advertising cookies: all advertising consent signals are permanently denied. - The attendlr.com website measures visits with a cookieless method (Cloudflare Web Analytics): it sets no analytics cookies, builds no visitor profiles, and needs no consent for this. Measurement processes IP addresses only transiently, while serving the request.
12. Changes to this policy
If the app's data handling changes (e.g. a new feature needs new data), we will update this policy and notify you of the change in the app or by email. The current version is always available on this page.
13. Contact
For any privacy question, write to us:
Email: support@attendlr.com