undesk
FeaturesSupportPrivacy

Privacy Policy

Last updated: 25 September 2026

The short version. We collect what we need to build your stretching routines: your sign-in details, the answers you give during onboarding (including some health information such as pain areas and injuries), and how your sessions go. We use AI to generate routines, but we never send your name or email to the AI provider. We don't sell your data, don't show ads, and don't use analytics or tracking SDKs.

1. Who we are

The controller of your personal data is Jakub Nowacki, running a sole proprietorship under the name SwiftIT Nowacki Jakub, ul. Ks. Kazimierza Ciuby 14, 43-600 Jaworzno, Poland, tax ID (NIP) 6322036596, REGON 527957448, registered in CEIDG ("we", "us"). We operate the Undesk mobile app (the "App") and this website.

For anything related to privacy, write to privacy@getundesk.app. We have not appointed a Data Protection Officer, as we are not required to.

2. What data we collect

Account data

You sign in with Apple or Google. We receive and store your email address, your name and, for Google, your profile photo URL, plus the account identifier Apple or Google assigns to you. If you use Apple's "Hide My Email", we only receive a private relay address. We never receive your Apple or Google password.

Profile and health data

During onboarding and in your profile you give us:

  • your age and, optionally, your weight;
  • how many hours a day you spend at a desk;
  • areas where you feel pain and any injuries you choose to tell us about;
  • your fitness level, goal, available time and preferred workout days;
  • your time zone.

Pain areas and injuries are data concerning health, a special category of personal data under the GDPR. We process them only with your explicit consent (see section 4).

Activity data

  • the routines generated for you (Quick Fixes, daily stretches, weekly plans) and when you start, complete or skip them;
  • feedback after a session: difficulty, energy level and any pain you report;
  • daily body check-ins: your mood and where it hurts, if anywhere;
  • your streak, streak shields and related dates.

Subscription data

If you subscribe to Undesk Pro, we store your subscription status, plan, trial and expiry dates, and your customer ID at our subscription provider. Payment is handled entirely by Apple or Google; we never see your card details.

Technical data

  • a push notification token for your device, if you allow notifications;
  • sign-in session tokens, stored securely on your device and as identifiers on our servers;
  • your IP address, used briefly in memory to protect the service against abuse (rate limiting); we do not store it in our database.

The App also stores a few preferences locally on your device, such as whether sounds are on and a cached copy of your streak.

What we don't collect

We don't use analytics, advertising or crash-reporting SDKs, we don't track you across other apps or websites, and we don't access your location, contacts, camera, microphone or photos. This website does not use cookies.

3. Why we use your data

  • To provide the App: create and manage your account, generate personalised routines and plans, adapt them to your feedback, and show your progress and streaks.
  • To manage subscriptions: unlock Pro features, handle trials, renewals, cancellations and restores.
  • To send notifications: for example when your plan is ready, a morning reminder, streak updates and a weekly progress summary. The weekly summary may tell you how your activity compares with other users as an anonymous percentile; no other user ever sees your data.
  • To keep the service secure and working: prevent abuse, fix problems and answer your support requests.
  • To meet legal obligations: for example accounting and tax records.

We do not use your data for advertising, we do not sell it, and we do not make decisions about you that have legal or similarly significant effects based solely on automated processing. AI only chooses which exercises to put in your routine.

4. Legal bases (GDPR)

PurposeLegal basis
Account, routines, progress, subscriptions, service notificationsPerformance of our contract with you (Art. 6(1)(b) GDPR)
Pain areas, injuries, pain reported in feedback and body checksYour explicit consent (Art. 9(2)(a) and Art. 6(1)(a) GDPR), given when you enter this information
Reminders, streak and weekly summary push notificationsYour consent via your device's notification permission (Art. 6(1)(a))
Security, abuse prevention, service improvement, handling claimsOur legitimate interests (Art. 6(1)(f))
Accounting and tax recordsLegal obligation (Art. 6(1)(c))

You can withdraw consent at any time, for example by removing pain areas and injuries from your profile, turning off notifications in your device settings, or deleting your account. Withdrawal does not affect processing that happened before it. Without health information, routines will be less tailored to you.

5. How we use AI

Your routines and plans are generated by Anthropic's Claude models. To do that we send Anthropic a de-identified request containing: your age, desk hours, pain areas, injuries, fitness level, goal, available time, workout frequency, the body area you selected, and a summary of your recent feedback (difficulty, energy, pain reported and which exercises helped). We do not send your name, email address, account ID or weight.

Anthropic processes these requests as our service provider under its commercial terms, does not use them to train its models, and keeps them only for a limited period in line with its data retention policy.

6. Who we share data with

We share personal data only with service providers that help us run the App, under contracts that require them to protect it and use it only on our instructions:

ProviderWhat forData involved
Anthropic, PBC (USA)Generating routines and plansDe-identified profile, health and feedback data (see section 5)
Render Services, Inc. (USA)Hosting our servers, database and job queuesAll data stored by the App
RevenueCat, Inc. (USA)Managing subscriptionsYour account ID, purchase and subscription status
Apple Inc. / Google LLCSign-in, in-app purchases, push notification deliverySign-in identifiers, purchase data, push token and notification content
650 Industries, Inc. (Expo) (USA)Delivering push notificationsPush token and notification content

We may also disclose data if required by law, to protect our rights or the safety of others, or to a successor if the App is transferred to another operator, in which case we will tell you in advance.

7. International transfers

Some of our providers are located in, or process data in, the United States. Where data leaves the European Economic Area, we rely on the EU–US Data Privacy Framework for certified providers or on the European Commission's Standard Contractual Clauses, together with additional safeguards where needed. You can ask us for a copy of the relevant safeguards at privacy@getundesk.app.

8. How long we keep data

  • Account, profile and activity data: for as long as your account exists. When you delete your account, we delete this data within 30 days. Backups are overwritten within a further 30 days.
  • Health data: until you remove it, withdraw consent or delete your account.
  • Push tokens and session tokens: until they expire, you sign out or you delete your account.
  • Records we must keep by law (for example invoices or tax records, if any relate to you): for the period required by law, typically 5 years.
  • Support emails: up to 2 years after your last message.

9. Your rights

Under the GDPR you have the right to:

  • access your data and get a copy of it;
  • correct inaccurate data (most of it you can edit in the App);
  • have your data deleted (see Delete Your Account);
  • restrict or object to processing based on our legitimate interests;
  • data portability, receiving your data in a machine-readable format;
  • withdraw consent at any time.

To exercise any of these, email privacy@getundesk.app from the address linked to your account. We will reply within one month. You also have the right to lodge a complaint with a supervisory authority, in Poland the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl), or the authority in your country of residence.

California and other US state residents: we do not sell or share your personal information for cross-context behavioural advertising. You can request access to or deletion of your information using the contact above, and we will not discriminate against you for doing so.

10. Security

Data is encrypted in transit (HTTPS). Sign-in tokens are stored in your device's secure storage (Keychain / Keystore). Access to our servers is restricted and protected. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data, and we will notify you and the authorities of a breach where the law requires it.

11. Children

The App is not intended for children under 13, and users in the European Economic Area or the UK must be at least 16 (or have a parent's or guardian's consent, where local law allows). We do not knowingly collect data from younger children. If you believe a child has given us personal data, contact us and we will delete it.

12. Changes to this policy

We may update this policy as the App changes. We will post the new version here and update the date at the top. If a change is significant, we will also tell you in the App or by notification before it takes effect.

13. Contact

SwiftIT Nowacki Jakub, ul. Ks. Kazimierza Ciuby 14, 43-600 Jaworzno, Poland
Email: privacy@getundesk.app
Phone: +48 507 664 977

© 2026 SwiftIT Nowacki Jakub
Privacy PolicyTerms of ServiceDelete Your AccountSupportInstagramTikToksupport@getundesk.app