The short version

Your camera feed never leaves your Mac. Frames go to the Neural Engine, come back as body points, and are thrown away frame by frame. We have no server that could receive a video even if we wanted one. Your calendar stays on your Mac too, and recorded clips are files in your own Downloads folder.

The website sets no cookies and runs no tracking. The app sends anonymous usage counts — how many reps a break produced, whether a purchase went through — which you can switch off in one click. That is the whole story; the sections below are the same thing said carefully.

1. Controller (Art. 13(1)(a) GDPR)

Dr. Jan Philip Wahle
Siedlungsweg 24, 37124 Rosdorf, Germany
Email: [email protected]

A Data Protection Officer is not required under Art. 37 GDPR and Section 38 BDSG. Questions are routed to the contact email above.

2. Overview of data processing

Processing of personal data is limited to what is needed to run the website, provide the app, and respond to you when you write in. We do not sell data, we do not run advertising, and we do not build profiles. For each activity below we name the purpose, the legal basis, and how long data is kept.

3. The OfficeSquats Mac app

Camera and squat counting

When a break starts, the app opens the camera you selected and runs Apple's on-device pose estimation over the live frames. Each frame is reduced to a set of body points — roughly, where your head, shoulders, hips, knees and ankles are — and the app watches how far those points drop to decide that a squat happened. The frame is then released. Nothing is written to disk, nothing is queued, and nothing is transmitted. There is no server-side component: we could not look at your camera if we wanted to, because no endpoint exists that receives images.

macOS asks for camera permission the first time a break runs. You can withdraw it at any time in System Settings → Privacy & Security → Camera; the app then simply cannot count, and breaks fall back to a manual finish.

Recorded clips

If you press the record button — or switch on "record every break" yourself — the app writes a .mov file of that session, rep counter and skeleton overlay included, into your Downloads folder. The file is yours. It is not uploaded, indexed, or reported on; the only thing analytics ever learns is the boolean fact that a break was recorded, never the file, its name, or its contents. Delete it like any other file.

Calendar

Calendar access is optional. If you grant it, the app reads the calendars you tick through Apple's EventKit framework, on your Mac, to decide whether a break should be skipped because you are in a meeting. Event titles, participants, notes, and locations are never transmitted, never logged, and never included in analytics events. Withdraw access at any time in System Settings → Privacy & Security → Calendars.

Awareness of what is running

So that a break does not steal the keyboard from a coding agent mid-task, the app asks macOS for a list of running processes and their CPU time, and matches executable names against a list you can edit. This happens entirely on your Mac. No process list, window title, file name, or document content is transmitted or stored anywhere by us.

What the app stores on your Mac

Your schedule, work hours, rep target, camera choice, streak and rep history, and your analytics preference live in the app's own preferences on your Mac. We have no copy. Deleting the app removes them.

Anonymous usage statistics

The app sends a small set of product events to PostHog (PostHog, Inc., EU Cloud, with data stored in Frankfurt, Germany) so we can see whether the thing actually works: whether breaks get finished or skipped, at what hour of the day people squat, and whether the paywall converts. A data processing agreement under Art. 28 GDPR is in place.

The complete list of events we send is:

  • break_completed — reps done, rep target, whether the target was hit, and whether the break was being recorded
  • break_skipped — the rep target that was skipped
  • break_snoozed — the snooze length in minutes
  • onboarding_setup_skipped — that you took the "try it first" route
  • paywall_shown, purchase_completed, purchase_failed — with the price variant, product identifier, displayed price, and, on failure, a coarse reason such as "cancelled"

Every event additionally carries the local hour and weekday it happened in and the app version. The PostHog SDK adds its own lifecycle events (such as first install and app open), technical properties (operating system and version, device type, locale, library version), and an approximate location derived from the IP address of the connection.

No profile is built. The app never calls PostHog's identify function, so events stay attached to a random per-install identifier and are never linked to a name, an email address, an Apple ID, or an account — there is no account to link them to. Camera frames, pose data, calendar contents, process names, file names, and your quiz answers during setup are never part of an analytics event.

Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in understanding whether the product works and in fixing what does not, balanced against an interest that is minimal because the data is anonymous by construction. You can switch this off entirely in the app's settings under "Anonymous usage stats"; the SDK stops sending immediately, not at next launch. Retention in PostHog is 12 months for events, after which they are deleted.

Price experiment

On launch the app asks PostHog which of three price arms this install belongs to, and shows that price on the paywall. The assignment is made from the random install identifier and is pinned for the lifetime of the install so the price you were shown never changes underneath you. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in pricing our own product sensibly).

Purchases

Billing is handled by the store you buy from, which acts as the seller of record. For App Store purchases that is Apple, through your Apple Account; for purchases made directly from this website it is our payment provider. Either way, we never receive your card details, your Apple Account, or your billing address. We see aggregate sales reports and, in the case of a direct purchase, the email address you gave the payment provider so we can send you the download and your receipt. Legal basis: Art. 6(1)(b) GDPR (performance of the purchase contract) and Art. 6(1)(c) GDPR (statutory retention of accounting records, generally ten years under German law).

Crash reports

If you have opted in to sharing diagnostics with developers in your macOS privacy settings, Apple may forward anonymised crash reports to us through App Store Connect. We use them only to fix bugs. Opt out at any time in System Settings → Privacy & Security → Analytics & Improvements. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in fixing crashes).

4. Hosting and server log files

The origin server for officesquats.app is operated for us by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, in a German data centre. Traffic is delivered through Cloudflare (Cloudflare Germany GmbH, Rosental 7, 80331 Munich, and Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA), which acts as a content delivery network and reverse proxy and terminates the encrypted connection. Both act as our processors under Art. 28 GDPR.

Every request produces a temporary log entry containing:

  • IP address
  • Request date and time
  • URL requested and HTTP method
  • HTTP status code and response size
  • Browser type, version, and operating system
  • Referrer URL, if your browser sends one

Purpose: keeping the site online, defending it against attack and abuse, and investigating faults. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operating a secure service). Retention: log entries are deleted after 14 days unless we need them to investigate a security incident. Transfers to Cloudflare, Inc. in the United States are covered by the EU–US Data Privacy Framework adequacy decision (C(2023) 4745) and by standard contractual clauses.

5. Cookies and local storage

This website sets no cookies, runs no analytics, embeds no advertising or social media trackers, and stores nothing in your browser. That is why you have not been asked to click a consent banner — there is nothing to consent to. Nothing on this site reads or writes information on your device within the meaning of Section 25 TDDDG.

6. Web fonts and third-party content

The typeface used on this site is served from our own server. We do not use Google Fonts or any other external font service, and your browser therefore sends no request, and no IP address, to Google or anyone else in order to render this page.

The same holds for everything else here: no scripts, stylesheets, images, embedded videos, maps, social media widgets, or advertising pixels are loaded from a third-party domain. Apart from the request to our own server, visiting this website causes no automatic connection to any outside party. Ordinary links to other websites are of course still links — following one takes you to that site, where that site's own privacy policy applies.

7. Contact by email

When you email [email protected], we process your email address, your name if you give one, and the content of your message in order to answer you. Legal basis: Art. 6(1)(b) GDPR for pre-contractual and support matters, otherwise Art. 6(1)(f) GDPR (legitimate interest in responding to correspondence). Retention: we keep the thread until the matter is resolved and then delete it, unless we are required by law to retain it, for example for accounting purposes.

8. Recipients and third countries

Personal data is disclosed only to the processors named above — Hetzner, Cloudflare, PostHog, our email provider, and the store or payment provider handling your purchase — and only to the extent needed for the purpose described. Beyond that, data is passed on only where we are legally required to do so. We do not sell or rent personal data, and we do not use it to train machine-learning models.

9. Your rights under the GDPR

You can reach us about any of these at [email protected]:

  • Right of access (Art. 15)
  • Right to rectification (Art. 16)
  • Right to erasure (Art. 17)
  • Right to restriction of processing (Art. 18)
  • Right to data portability (Art. 20)
  • Right to object, in particular to processing based on legitimate interests (Art. 21)
  • Right to withdraw consent with effect for the future (Art. 7(3))

One honest caveat: because the app has no accounts and analytics carries no identifier we can tie to you, we are generally unable to single out "your" data in our analytics under Art. 11 GDPR. If you send us additional information that makes identification possible we will act on it; otherwise the fastest route to erasure is the opt-out switch in the app.

10. Right to lodge a complaint

You may file a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement. Our competent authority is:

Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5, 30159 Hannover, Germany
Phone: +49 511 120-4500
Email: [email protected]
Web: lfd.niedersachsen.de

11. Data security

Connections to this site and to our processors are TLS-encrypted. Access to our infrastructure is restricted and kept patched. No system is perfectly secure, which is exactly why the app is built so that the sensitive part — the video of you — never travels in the first place.

12. Automated decision-making

The app uses on-device machine learning to recognise a squat, and a randomised assignment to pick which price it shows you. Neither produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR. Every break can be skipped or snoozed by you, and no purchase happens without your action.

13. Children

OfficeSquats is aimed at adults with desk jobs and is not directed at children. We do not knowingly process data from anyone under 16.

14. Changes to this policy

We update this policy when the law, our tools, or our practices change. The current version is always at this URL, and the date at the top says when it last moved.