Privacy Policy
This Privacy Policy explains how Apex Fitness (Apex, we, us) handles information when you use the Apex Fitness mobile application (the App).
Effective date: 6 October 2026
1. The short version
Apex is a fitness and habit-building app. Depending on the features you use, it can process account information, profile information, workout and challenge progress, optional Apple Health data, local notification settings, purchase information, app-usage analytics, and challenge reviews.
Camera-based workouts use the camera to recognise movement and count repetitions. Camera frames and face observations are processed temporarily on your device and in real time. Apex does not record or upload the camera feed, create a face template, perform facial recognition, or use camera data for advertising.
Apple Health is optional. Apex requests only the HealthKit permissions needed for the feature you choose. HealthKit data is not sold, used for advertising, or sent to Apex analytics or challenge-review systems.
2. Information we handle
The information we handle depends on your account and the features you choose:
Account and authentication information: a Firebase user identifier, account type, email address, display name, and authentication provider. A guest account may use an anonymous identifier until you create or link an account.
How we use it: To create and secure your account, sign you in, link accounts, provide account recovery, enforce account permissions, and provide support.
Profile information: name, date of birth, biological sex, activity level, weight, and optional avatar photo.
How we use it: To display your profile, personalise the App, and estimate exercise calories. In the current App, these records and the avatar are stored locally on your device.
Workout information: exercise type, repetitions, sets, start and end times, wall-clock and active duration, pause/rest intervals, calorie estimates, completion state, and challenge association.
How we use it: To save workouts, show history, calculate progress and streaks, apply free-plan limits, and improve the App. Workout history is stored locally on your device.
Challenge information: joined challenges, start dates, completed or skipped days, volume progress, optional goal records and check-ins, access source, and challenge-related identifiers.
How we use it: To provide challenge access, synchronise challenge progress across signed-in devices, show challenge status, and operate challenge features. This information is stored locally and, for signed-in users, selected progress is also stored in Firebase Cloud Firestore.
Challenge reviews and moderation information: rating, review text, optional public alias, publication consent, challenge identifier, moderation status, reports, and a user's block list.
How we use it: To receive feedback, moderate reviews, display approved reviews and aggregate ratings, and protect users from unwanted content. A review is displayed publicly only when you provide publication consent and it is approved.
Camera and movement information: temporary camera frames and on-device movement or face-position observations during a camera-tracked workout.
How we use it: To recognise exercise movement and count repetitions. These data are processed on your device and are not retained or transmitted by Apex.
Apple Health information, if you connect Apple Health: date of birth, biological sex, body mass, step count, workouts, and active energy burned, subject to the permissions you grant.
How we use it: To personalise estimates and read or write the HealthKit information needed for the feature you request. HealthKit remains controlled by Apple and your device permissions.
Purchase and subscription information: product identifiers, verified transaction or entitlement information, subscription status, plan, trial state, and purchase-related event metadata.
How we use it: Apple uses this information to process purchases, renewals, refunds, and restore purchases. Apex uses entitlement information to provide paid features. Apex does not receive your payment-card details.
Usage and product analytics: events such as sign-in, workout start/save, exercise type, repetition and duration totals, challenge identifiers and progress events, paywall interactions, subscription state, reminder interactions, ratings, app version, and a pseudonymous Firebase user identifier when you are signed in.
How we use it: To understand reliability and feature usage, measure product performance, improve the App, detect misuse, and make product decisions. We do not use camera or HealthKit data for analytics.
Notification information: your notification permission and preferences for workout, challenge, rest-timer, activity, and product reminders.
How we use it: To schedule the local notifications you request. The current App uses device-local notifications and does not require a remote push-notification backend for these reminders.
Support communications: your email address and the information you include when contacting us or using the Help Center.
How we use it: To answer questions, investigate problems, and manage support requests.
3. Sign-in providers
You may use Apple, Google, email/password, or an anonymous guest account where those options are offered. If you use Sign in with Apple or Google, the provider shares the account information and authentication credentials you authorise. Apple may provide a private relay email address. Firebase Authentication processes the authentication request and maintains the Firebase account needed to sign you in.
4. Camera and movement tracking
Apex requests camera access only for camera-based workouts. While a workout is active, on-device Vision processing may detect that a face or body is present and measure movement or position in the current frame. This is movement tracking for exercise feedback, not facial recognition or identification.
Apex does not retain images, video, camera frames, facial landmarks, face embeddings, or a biometric identifier. Camera frames and observations are not sent to Firebase, Apple, Google, PostHog, advertisers, or other third parties. You can refuse or revoke camera permission in iOS Settings; camera-tracked workouts will then be unavailable.
5. Apple Health
Connecting Apple Health is optional. You choose whether to grant read or write permission in Apple’s Health permission screen. Apex may read the permitted profile and activity values listed above and may write an Apex workout and active-energy value when you request Health export.
Apex does not sell HealthKit data, use it for advertising or marketing, use it for data mining, or disclose it to data brokers. Apple Health records are not deleted when you delete an Apex account; manage them in the Apple Health app.
6. Analytics and service providers
We use service providers to operate Apex:
- Firebase Authentication processes account and authentication information.
- Firebase Cloud Firestore and Cloud Functions store and process signed-in challenge progress, challenge reviews, moderation data, and related account identifiers needed for those features.
- PostHog processes pseudonymous product-usage events. Apex sends event data described in Section 2 to PostHog’s European-hosted endpoint. PostHog may also receive ordinary technical information needed to deliver its service, such as device, app, network, and diagnostic metadata.
- Apple provides iOS, Sign in with Apple, Apple Health, App Store billing, subscription management, and restore-purchase services.
- Google processes Google sign-in according to the information and permissions you authorise.
- Featurebase may process information you submit through our Help Center or support forms under its own privacy terms.
The App also downloads exercise and challenge media from our content-hosting infrastructure. These requests deliver static content; they are not used to upload your camera feed, HealthKit data, workout history, or profile photo.
We may disclose information when required by law or when reasonably necessary to protect the security, rights, property, or safety of Apex, users, or others. We do not sell personal data, run third-party advertising in the App, or share camera or HealthKit data for advertising, marketing, or data mining.
7. Purposes and legal bases
For people in the EEA, UK, or Switzerland, we process personal data as necessary to perform our contract with you (including providing the App, account features, challenge progress, and purchases), for our legitimate interests (including security, fraud prevention, support, analytics, and improving the App), to comply with legal obligations, or with your consent where consent is required. You may withdraw consent by changing the relevant App or device permission; this does not affect processing already carried out lawfully.
8. Storage, retention, and deletion
Local profile, avatar, workout history, challenge cache, water logs, preferences, and local notification settings remain on your device until you delete them, remove the App’s data, or uninstall the App. Signing out does not necessarily erase local records.
Signed-in challenge progress, challenge reviews, moderation records, and account records are retained for as long as reasonably necessary to provide the feature, maintain security, resolve disputes, comply with law, and keep reliable purchase or moderation records. Approved reviews may remain visible under the public alias you choose where they were published with your consent; the underlying account identifier is used for moderation and is not shown as the public author name. You can ask us to withdraw or remove a review.
You can request account deletion or deletion of personal data in Settings → Account settings → Delete account, or by contacting support@ap3x-fit.com. The current in-App deletion flow deletes the Firebase Authentication account and clears the local profile, avatar, subscription cache, and workout records. Cloud challenge progress, reviews, reports, or block-list records may require a separate deletion request; contact us so we can review and remove them subject to legal, security, fraud-prevention, dispute, and financial-recordkeeping requirements. Deleting an Apex account does not cancel an Apple subscription or remove Apple Health records.
9. Your rights
Subject to applicable law, you may request access to, correction of, deletion of, restriction of, or a portable copy of your personal data, or object to certain processing. Contact support@ap3x-fit.com. We may need to verify your identity before acting on a request.
If the GDPR applies to you, you may complain to the data-protection authority in your country of residence, workplace, or the place of the alleged infringement. Our lead supervisory authority is the Czech Office for Personal Data Protection (ÚOOÚ).
10. Children
Apex is not directed to children under 16, and we do not knowingly provide account-based services to children under 16. If you believe a child has provided personal information, contact us so we can investigate and take appropriate steps.
11. Security
We use reasonable technical and organisational measures to protect information, including authenticated access controls and scoped access to cloud records. No storage or transmission method is completely secure, so we cannot guarantee absolute security.
12. Changes to this Policy
We may update this Policy when the App, our processing, or applicable law changes. We will post the updated version and revise the effective date. If a change is material, we will provide additional notice where required by law.
13. Contact and controller
Apex Fitness is developed and operated by Mykhailo Pashynskyi, a solo developer and self-employed entrepreneur registered in the Czech Republic, who is the controller of personal data under this Policy. For privacy questions or requests, contact support@ap3x-fit.com.