Privacy Policy — Kettlebell Power Session Sync
Last updated: 29 August 2026 · Covers the optional session-sync feature of the paid Kettlebell Power Pro Garmin app (v2.0.0 and later) and the builder at bikintulis.de/kb.
This policy covers one optional feature: building kettlebell sessions on this website and syncing them to your watch.
Everything the app does on the watch itself is covered by its own policy, which is the one linked from the Connect IQ store listing: Kettlebell Power. Other apps published by BIKINTULIS have their own — see the directory.
The free edition of Kettlebell Power cannot use this feature at all. It is built without the sync code — it contains no networking code whatsoever — it does not request internet permission, and it cannot reach this service. Simple & Sinister is free forever in that edition; syncing your own sessions is not part of it.
And in Kettlebell Power Pro, this is the only web request the app ever makes. There is no analytics, no crash reporting, no update check and no advertising anywhere in the binary. If you never open the sync screen, the Pro app never contacts any server either.
1. Who we are
BIKINTULIS is an independent developer of Garmin Connect IQ apps. For questions about this policy, use the contact form.
2. Summary in plain language
- Sync is optional and opt-in. If you never open the pairing screen on your watch, nothing about you is stored. Note that simply opening it is already the start of it: the watch asks our server for a pairing code as soon as that screen appears, and that alone creates a device record and a code on our server, even if you never type the code in here.
- There is no account. No email, no password, no username, no sign-up. Your watch is the identity.
- What we store is small and deliberate: a random device key generated on your watch, the sessions you build, and short-lived pairing codes.
- Sync only travels one way — website to watch. The watch downloads sessions. It never uploads a completed session, a rep count, a personal best, a tonnage figure, a heart rate, which bells you own, or your hand-care log.
- We store no name, no email, no location, no heart rate, and no training data of any kind — and specifically nothing about your bell inventory or your anchor bell. A session carries a percentage, and your watch works out which of your bells that is. We never learn which bells you have.
- The sessions you build do leave your watch's manufacturer environment — they are stored on our server at bikintulis.de so your watch can download them. That is the whole point of the feature, and we say it plainly.
- If you pair more than one watch, this browser remembers each separately, and each one's sessions are kept apart from the others.
- You can delete everything we hold for a watch yourself, at any time, with one button.
3. What the app sends, and when
The app contacts our server only when you ask it to — when you open the pairing screen, or choose Sync now under Settings → Sync. It never syncs automatically, never in the background, and never during a session. When it does, it sends:
- a device key — 32 random hexadecimal characters generated on your watch the first time you open the feature. It is not your Garmin ID, not a serial number, and is not linked to your Garmin account or to you personally;
- an app identifier, so the server knows the request came from the paid app.
That is all. It does not send your location, your heart rate, your session results, your rep counts, your personal bests, your best bell per movement, your total tonnage, your hand-care log, your bell inventory, your anchor bell, your training history, your Garmin account details, your watch model, or any other data.
4. What we store on our server
- The device key (the random string above), with the dates it was created, paired and last synced, and which edition of the app that watch is running — that last one is what lets the builder label your watches in the “Sessions for” dropdown.
- The sessions you build — their names, and for each segment: whether it is a set or a rest; which movement it is (chosen from the app's fixed list of 23); whether it is counted in reps or in seconds, and how many; the length of its interval window, if it has one; the left or right hand, for the movements that have one; and the load as a percentage.
- Pairing codes — a 6-digit code that works for 15 minutes and can be used once. After that it stops working; the used-up code row itself stays in our database for up to 24 hours and is then deleted.
- A cookie in your browser (see §6).
The load is a percentage and never a weight. A session says “85 % of the anchor bell”, not “20 kg”. Your watch turns that into an actual bell using the bells you told it you own, and it does that entirely on the watch — that information is never sent to us and we have no way to derive it. It is also why a session you build works for someone with a completely different set of bells.
Please bear in mind that the session name is free text. Whatever you type into it is stored as typed. Everything else in a session is a number or a movement chosen from the app's own fixed list, so the name is the only field that could hold personal information. Keep it to training details — don't put anything personal in there.
5. What we never collect
- No name, email address, phone number, postal address or password — there is no account to hold them.
- No location or GPS data.
- No heart rate, calories, activity data, session results, rep counts, personal bests, tonnage, streaks or training history — the watch never uploads any of it.
- No bell inventory and no anchor bell. We do not know which kettlebells you own, and the feature is designed so that we do not need to.
- No hand-care log. The weekly ballistic-rep allowance that protects your palms is computed and stored only on your watch.
- No Garmin account information — we have no access to it.
- No advertising, no analytics, no tracking of any kind.
6. The cookie
When you type your watch's pairing code on this site, we set one cookie
(kb_dk). It is strictly necessary: it is the only thing that tells the site
which watch this browser is allowed to build sessions for. It holds the device key (or, if
you have paired more than one watch in this browser, up to five of them —
one per watch, the one you are currently editing first) plus a signature that stops it being
tampered with. It is HttpOnly, Secure and
SameSite=Lax, lasts about 400 days unless you remove it, and
is not used for tracking or advertising. "Disconnect this browser" deletes
it.
The builder also remembers one setting in your own browser only: the anchor bell the worked examples are drawn against, so the page does not ask you again on your next visit. It is stored in your browser's local storage, it is never sent to us, and clearing your browser data removes it.
This cookie is specific to Kettlebell Power. If you also use the Hyrox, GYM, PLANK or CrossFit workout builders on this site, those pages set their own separate cookies; none of them sees the others.
7. Legal basis (GDPR)
We process this data on the basis of your consent, given by the deliberate act of pairing your watch and building sessions. You can withdraw it at any time by deleting your data (§8) — no request or explanation needed.
8. Deleting your data — you can do it yourself
On the Session Builder page, "Delete this watch's data" permanently removes the sessions, the device key and any pairing codes for the watch currently selected in the "Sessions for" dropdown. It is immediate and cannot be undone.
It deletes that one watch, not all of them. If you have paired more than one watch in this browser, the others are untouched and one of them becomes the selected watch. To erase everything, repeat the deletion for each watch in the dropdown. We cannot do it for you from an email: we hold nothing that links a watch to a person, so there is no way for us to find your records — which is the same reason there is no account to recover.
Two things that do not delete anything on our server: removing the app from your watch, and "Disconnect this browser" — which forgets every watch paired in this browser at once (see §6), while leaving all of it on our server. Use the delete button for actual erasure.
9. Data retention
- Sessions and the device key: kept until you delete them, or until the watch has been inactive for 24 months. After 24 months with no sync and no pairing, the device record and its sessions are deleted automatically. Any sync or re-pair from the watch starts that clock again, so an app you are still using is never purged.
- Pairing codes: usable for 15 minutes and once only. Spent and expired codes are deleted within 24 hours.
- Standard web-server access logs: up to 30 days.
10. Security
- All traffic — watch and browser alike — is over HTTPS with a valid public certificate.
- The database is not exposed to the public internet.
- Pairing codes are single-use, expire in 15 minutes, and both issuing and redeeming them are rate-limited to make guessing impractical.
- The browser cookie is signed, so it cannot be edited to reach another watch's sessions.
- Everything the browser sends is re-checked on the server before it is stored, and rebuilt from scratch rather than passed through — and it is checked again by the watch before it is used.
- No payment data is ever handled by BIKINTULIS — purchases go through the Garmin Connect IQ store.
11. Garmin Connect & your Garmin account
The app runs inside Garmin's Connect IQ platform, and a sync travels over your phone's connection. Garmin's own collection and use of data is governed by Garmin's policy at garmin.com/privacy. BIKINTULIS has no access to your Garmin account or anything synced to Garmin Connect. The activity your watch records for a synced session is saved to Garmin Connect exactly as any other session is — through Garmin's own sync, which this feature does not touch.
12. The bikintulis.de website
Separate from this feature, when you use the rest of the bikintulis.de website:
- If you leave a comment or review, your name, email, rating and comment text are stored. Your name, rating and comment are published publicly after moderation; your email is never published.
- If you use the contact form, your name, email, subject and message are stored privately and used to reply to you.
- Your IP address is stored in our database only as a salted SHA-256 hash (rate-limiting / spam prevention), never in raw form there. Raw IP addresses do appear in the standard web-server access log, as they do on any website; those logs are kept for up to 30 days and are used only for security and troubleshooting.
- No third-party analytics, no advertising, no tracking pixels.
13. Your rights
Under the GDPR you can access, correct or delete your data, withdraw consent, object to processing, or complain to your data-protection authority. Deletion is available to you directly (§8); for anything else use the contact form — requests are answered within 30 days.
14. Children
Kettlebell Power is a general-purpose fitness app and is not directed at children under 13.
15. Changes to this policy
This policy may be updated to reflect new features or legal requirements. The "Last updated" date above reflects the latest change.
16. Contact
Questions, requests or complaints: please use the contact form.