Apex Fitness by Zero Deficit LLC
Last Updated: April 28, 2026
This page describes what data Apex Fitness collects, how it's used, and whether it's shared with third parties. This information is provided to comply with Apple App Store and Google Play Store data safety requirements.
| Data Type | Collected | Shared | Purpose |
|---|---|---|---|
| Email Address | Collected | Not Shared | Account creation, login, password reset, transactional email |
| Name | Collected | Not Shared | Display in app profile |
| Password | Collected | Not Shared | Authentication (stored as bcrypt hash, never in plaintext) |
| Body Measurements | Collected | Not Shared | Calculate BMR, TDEE, body fat %, and nutrition targets |
| Mobility / Injury Flags | Optional | Not Shared | Personalize prehab protocols & injury-aware exercise swaps |
| Workout Logs | Collected | Not Shared | Track exercise progress, progressive overload, PRs |
| Cardio Sessions (incl. GPS points) | Optional | Not Shared | Compute distance, pace, elevation gain. GPS collected only while you're actively tracking a run/walk/hike/ride |
| Food Diary Entries | Collected | Not Shared | Track daily nutrition and macro intake |
| Scanned Barcode History | Optional | Not Shared | Store previously-scanned product name, brand, nutrients & scan count for one-tap re-logging |
| Recovery Metrics | Optional | Not Shared | Sleep hours & quality, soreness, energy, stress, mood, custom metrics → feed the daily Recovery Score |
| Apple HealthKit Data | On-Device Only | Not Shared | Steps, heart rate, active energy, sleep & workouts processed locally by Apple's framework. Never leaves your device unless you sync a derived metric into Apex. |
| Android Health Connect Data | On-Device Only | Not Shared | Steps, active calories, sleep, exercise sessions read on-device via the Android Jetpack Health Connect SDK. Never leaves your device unless you sync a derived metric into Apex. |
| Purchase History | Collected | Not Shared | Manage subscription status (Pro/Elite tiers) via Stripe (web), Apple IAP (iOS), or Google Play Billing (Android) |
| Push Notification Token | Optional | Not Shared | Deliver opt-in workout reminders, PR celebrations, weekly summaries, and recovery insights via APNs (iOS), Firebase Cloud Messaging (Android), or Web Push (browsers) |
| Cosmetic Preferences | Optional | Not Shared | Active app icon (alternate iOS home-screen icons: Default / Pro Gold / Streak Master / Launch Edition / Founder), theme, units, dietary filters, "Always show scroll bar" preference. Eligibility for alternate icons is computed from existing data — no new data is collected. |
| Workout History (read for prefill) | Collected | Not Shared | Most recent weight_lifted + reps_completed per exercise from your own past lifting_logs is read internally to pre-populate Quick Log / Logbook / Speed Run / Start Workout. Never shared with third parties. |
| Permission | When Requested | What Leaves Your Device |
|---|---|---|
| Camera (barcode scanner) | First time you tap "Scan Barcode" on the Food Diary | Only the decoded numeric barcode (e.g. 3017620422003). No images, video, or camera frames ever leave your device — decoding is performed locally by @zxing/browser / BarcodeDetector API. |
| Precise Location (While Using App) | First time you start a cardio session with "Track with GPS" | Timestamped lat/lon points, speed, altitude — stored only in your own private cardio_sessions record. Collected only during an active session and stopped the moment you pause or end the workout. We do NOT request background or always-on location. |
| Apple HealthKit (iOS) | When you enable HealthKit sync in Settings | Nothing leaves your device automatically. Raw Health samples are read on-device by Apple's framework. Only if you explicitly sync a derived metric (e.g. sleep hours) into your Apex recovery log is that value stored on our servers. |
| Health Connect (Android) | When you enable Health Connect sync in Settings | Nothing leaves your device automatically. Health Connect reads/writes happen on-device via the Android Jetpack SDK and require explicit per-data-type consent in the system Health Connect app. Only metrics you explicitly sync into your Apex recovery log are stored on our servers. |
| Vibration / Haptics (Android) | When the app starts (declared in AndroidManifest) | Nothing. Used by the WebView wrapper to fire short haptic taps on number-entry steppers, scroll wheels, and set-logging buttons. No data is collected or transmitted. |
| Push Notifications | When you opt into reminders in onboarding or Settings | Anonymous APNs device token (iOS), FCM registration token (Android), or Web Push subscription, plus each notification payload. |
| Data Type | Status |
|---|---|
| Camera images, video, or photos | Not Collected |
| Background or always-on location | Not Collected |
| Contacts | Not Collected |
| Microphone / Audio | Not Collected |
| Financial Information (card numbers, CVV, bank details) | Not Collected |
| Browsing History | Not Collected |
| SMS or Call Logs | Not Collected |
| Advertising Identifiers (IDFA/AAID) | Not Collected |
You can delete your data at any time:
Apex Fitness is not intended for users under the age of 16. We do not knowingly collect data from minors.
Data Protection Officer: privacy@apexfitness.ai
General Support: support@apexfitness.ai