Home › Privacy Policy

Privacy Policy

⚠️ Draft — do not publish as-is. Every item marked ⚠️ … below still needs a real value before this page goes live. Once it is live, update URL_PRIVACY_POLICY in Constants.kt and the privacy fields in App Store Connect and Play Console to point here. Delete this box when the placeholders are filled in.

Flexi (“the app”) is published by ⚠️ [legal entity name] (“we”, “us”). This policy explains what the app collects, why, and what choices you have.

In short: Flexi has no accounts and no sign-in. Your stretching history, streaks and reminder settings are stored only on your device and are never uploaded to us. The only information that leaves your device is anonymous usage analytics, used to understand how the app is used and improve it.

1. Information stored only on your device

The following never leaves your phone. We cannot see it, and we have no copy of it:

  • Stretching history — which plan you completed and when (a local SQLite database on the device).
  • Streaks and progress totals — derived from that history.
  • Reminder settings — whether the daily reminder is on, and the time you chose.
  • App preferences and counters — for example your subscription status flag, install date, session count, and whether you have dismissed the research survey card.

This data is removed when you uninstall the app. It may also be included in your device’s own backup (for example iCloud Backup or Android Auto Backup) if you have that feature enabled; those backups are controlled by Apple or Google under their own privacy policies, not by us.

2. Information collected through analytics

The app uses Google Firebase Analytics (Google LLC) to record anonymous, aggregated usage data. There is no account, so this data is not linked to your name, email address, or any identifier you provide.

Events we record

  • App lifecycle — app opened, first open, screen views.
  • Plans and sessions — plan viewed, session started, session completed or abandoned, number of exercises, session length.
  • Content — exercise information sheet opened.
  • Subscription — paywall viewed or dismissed, purchase initiated, completed or failed, product ID, price and currency.
  • Reminders — reminder enabled or disabled (including the hour and minute you chose), reminder notification opened.
  • Research survey — survey card shown, tapped, or dismissed.

Profile attributes we record, stored as coarse ranges rather than exact numbers (for example “4–7 days”, “6–20 sessions”): days since install, sessions completed, current streak, whether you have an active subscription, and whether reminders are enabled.

Collected automatically by Firebase: a randomly generated app-instance identifier, device model, operating system version, app version, language, and an approximate region derived from your IP address. Firebase does not store your full IP address for analytics purposes.

We do not collect your name, email address, phone number, postal address, precise location, contacts, calendar, photos, files, health records, or any data from Apple Health or Health Connect. The app requests no permission other than notifications.

3. Why we process this data

  • To understand which stretching plans and features are used, so we can improve them and decide what to build next.
  • To measure whether the app is working correctly across devices and versions.
  • To understand how many people subscribe, and at what point in their use.

Where the GDPR applies, our legal basis is our legitimate interest (Article 6(1)(f)) in maintaining and improving the app, balanced against the limited, non-identifying nature of the data. Where consent is required in your jurisdiction, we rely on the consent you give when prompted by the operating system or the app.

4. Purchases and subscriptions

Flexi offers optional monthly and yearly subscriptions. Payments are handled entirely by Apple (App Store) or Google (Google Play). We never receive or store your payment card details, billing address, or store account credentials.

We do receive the fact that a purchase succeeded or failed, the product identifier, and the price and currency, which we record as an analytics event. Manage or cancel your subscription in the App Store or Google Play subscription settings.

5. Notifications

If you enable the daily reminder, the notification is scheduled and delivered locally on your device. We do not operate a push notification server and do not send you messages. You can turn reminders off inside the app, or revoke the notification permission in your device settings.

6. Third-party links and the research survey

The app may show a card inviting you to take an optional research survey, which opens in your browser at harness-survey.vercel.app. Taking it is entirely voluntary. Anything you enter there is handled by that survey service, not by the app; the app passes only a code indicating which screen you tapped from. Other links in the app (such as the app store listing) likewise take you to sites governed by their own privacy policies.

7. Data sharing and retention

We do not sell your data, and we do not share it with advertisers. The app contains no advertising and no advertising SDKs.

Analytics data is processed by Google as our service provider, under Google’s Privacy Policy, and may be processed on servers outside your country, including the United States. Google applies its standard contractual clauses and other safeguards to those transfers.

Firebase retains event-level analytics data according to the retention period configured in our Firebase project ⚠️ [state the configured period, e.g. 14 months], after which it is deleted or retained only in aggregated form.

8. Your rights and choices

  • Stop analytics collection: uninstalling the app ends all collection and causes the associated app-instance data to be deleted. You can also reset or limit the advertising/analytics identifiers in your device settings (iOS: Settings → Privacy & Security → Tracking / Analytics & Improvements; Android: Settings → Google → Ads).
  • Delete on-device data: uninstall the app, or clear its storage in Android settings. This permanently removes your stretching history and streaks; we hold no backup and cannot restore it.
  • Access, correction, deletion, objection, portability: depending on where you live (for example under the GDPR or the CCPA/CPRA), you may have these rights over personal data we hold. Because we hold no account and no directly identifying information, we may need you to supply the Firebase app-instance ID from your device to locate any record. Contact us at the address below and we will respond within the time your law requires.
  • California residents: we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not offer financial incentives for personal information.

9. Children

Flexi is not directed at children and is not intended for anyone under 13 (or the minimum age of digital consent in your country, where that is higher). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

10. Security

Data sent to Firebase is encrypted in transit using HTTPS. Data stored on your device is protected by your device’s own operating-system protections, including disk encryption and your passcode. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

11. Health and medical disclaimer

Flexi is a general fitness and wellbeing app. It is not a medical device, it does not provide medical advice, and it does not access or store health records. Stop any stretch that causes pain, and consult a doctor or physiotherapist before starting a new exercise routine — particularly if you are injured, pregnant, or recently postpartum.

12. Changes to this policy

If we change how the app handles data, we will update this page and revise the “last updated” date above. Material changes will also be noted in the app’s release notes. Continuing to use the app after a change means you accept the updated policy.

13. Contact

Questions, or a request about your data:

  • Email: ⚠️ [support@yourdomain.com]
  • Postal address: ⚠️ [required in some jurisdictions — add if you have one]
  • Data controller: ⚠️ [legal entity name]