What we store about you, why we store it, and how you get rid of it again.
The long version follows. You need it if you want the detail.
The controller for data processing on this website and in the LEAN app within the meaning of the General Data Protection Regulation (GDPR) is:
HERO DREAMS LLCIf you have questions about privacy, write directly to that address. An external data protection officer is not legally required and therefore not appointed — your requests land with our team and are answered there.
You have the right, at any time, to:
An informal email to team (at) getlean (Punkt) info is enough. We respond within one month at the latest. Independently of this, you have a right to lodge a complaint with a supervisory authority (Art. 77 GDPR).
If you are in the United States: we apply the same standard to you. Requests for access, correction or deletion go to the same address and are handled the same way — we do not run a separate, weaker process for US residents.
This website runs on a server operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The server used is located in the Helsinki data center (Finland), i.e. within the EU. A data processing agreement under Art. 28 GDPR is in place with Hetzner.
On every request, the server automatically records access data transmitted by your browser:
We need this data to keep the site technically stable and to detect attacks. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure operation). This data is not merged with other data. We delete log files after 14 days at the latest, unless a specific security incident requires longer retention.
Technically necessary — these run without consent, because login and offline use do not work without them:
The legal basis for these technically necessary storage operations is § 25(2)(2) TDDDG in conjunction with Art. 6(1)(f) GDPR.
On top of that comes your choice itself: whether you consented to measurement is remembered in your browser’s localStorage (key lean-consent-v1). That is not a cookie, it never leaves your device, and it exists only so we don’t have to ask you again on every visit.
We run ads on Google. To see which of them actually reach anyone, we use the Google Ads conversion tag (provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland).
The tag only loads after you have clicked “Accept” in the banner. Before that, Google Consent Mode is set to denied — no advertising cookie is set and no click identifier is transmitted. The legal basis is § 25(1) TDDDG and Art. 6(1)(a) GDPR, i.e. your consent. The data processed includes device data, IP address, click identifiers and whether you registered or took out a subscription. Transfer to the United States cannot be ruled out; Google relies on standard contractual clauses and the EU-US Data Privacy Framework.
You can withdraw your consent at any time with effect for the future — here, with one click:
Dein aktueller Stand: wird geladen …
If you click “Essential only”, LEAN continues to work completely. There is no feature here that is tied to giving consent.
The LEAN Score quiz runs entirely in your browser. Your answers about weight, protein, training and medication are calculated locally and are not automatically transmitted to us. These details only leave your device once you actively request your result by email at the end, or create an account.
The answers contain health data within the meaning of Art. 9 GDPR. If you transmit them to us, the legal basis is your explicit consent under Art. 9(2)(a) GDPR, which you give when submitting and can withdraw at any time.
We use no Google Analytics and no Meta pixel. The only thing that goes beyond the server logs is the Google Ads conversion tag described under point 4 above — and only with your consent.
To understand which content is read, we otherwise evaluate only the server log files described above, statistically — aggregated, without profiling and without personal reference. If we introduce another analytics tool in future, we will update this policy beforehand and obtain your consent where required.
When you write to us through the contact form, we process the details you enter there:
We use this data solely to handle your request and for possible follow-up questions. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures) where your request relates to a contract, otherwise Art. 6(1)(f) GDPR (legitimate interest in answering enquiries).
AI-assisted replies: to answer faster, we have incoming requests classified and answered by our AI assistant Dr. Sarah Chen. For this, the content of your message is transmitted to the same language-model provider we use for the AI coach (processor under Art. 28 GDPR, no training on your data — see section 8). Every automatically generated reply is marked as an AI reply in the email. Sensitive cases — health complaints, cancellations, complaints and legal enquiries — are always answered by a human. You can object at any time and insist that a human answers: just say so in your message.
Important: please do not send us diagnoses, lab results or medication details through the contact form. For health-related topics, use the protected area inside your account.
We delete your request once it is resolved and no statutory retention periods apply — as a rule after 12 months at the latest. Just object if you want it sooner.
For a paid subscription (LEAN Pro or LEAN Premium) we create a user account. The following are processed:
The legal basis for master and usage data is Art. 6(1)(b) GDPR (performance of contract). For health-related details it is your explicit consent under Art. 9(2)(a) GDPR, which you give separately during sign-up.
To answer your questions in the AI coach we use language-model providers acting for us as processors under Art. 28 GDPR. Your inputs are processed there solely to generate the answer and are not used to train the models.
If you delete your account, we remove account and health data completely within 30 days. Billing data is excluded from this because we are required to retain it under commercial and tax law (see section 12).
We do not process payments ourselves. Depending on the payment method chosen, your payment data is transmitted directly to the respective provider. We never see credit card numbers or PayPal credentials.
Provider: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (for users in the EEA), together with Stripe, Inc., USA. Transmitted are name, email address, billing address, payment method data, amount and time of the transaction, plus technical data for fraud prevention (IP address, device information).
Provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. Transmitted are name, email address, amount, time and — depending on the payment route — further details for payment processing.
In both cases the legal basis is Art. 6(1)(b) GDPR (performance of contract) and Art. 6(1)(f) GDPR (legitimate interest in fraud prevention). Stripe and PayPal process some data as controllers in their own right, among other things for risk assessment and to meet their own legal obligations. You can find the detail in the privacy notices of Stripe and PayPal.
The typefaces Caprasimo and Figtree are served from our own server. They were downloaded once when the site was built and embedded locally. Visiting the site creates no connection to Google servers, so your IP address is not transmitted there.
There are no YouTube videos, no Google Maps and no social media plugins embedded.
HERO DREAMS LLC is based in Delaware, USA. When you use our services, your data may therefore also be processed in the United States. From an EU perspective the US is a third country without a general level of protection equivalent to the GDPR; authorities there can access data under certain conditions without you having the same legal remedies as in the EU.
We safeguard the transfer through:
For transfers of health data we additionally rely on your explicit consent under Art. 49(1)(a) GDPR.
Transmission between your browser and our server is encrypted end-to-end via TLS (recognizable by the padlock icon and “https://” in the address bar). We store passwords only as hashes. Access to production data is limited to the people who actually need it to operate the service.
When we introduce new features or change providers, we update this policy. The version published here is the one that applies. For material changes affecting your consent, we notify you by email beforehand.
This is a translation provided for convenience. In case of any discrepancy, the German version is the authoritative one.
Last updated: August 2, 2026