← Back

Data Safety

Apex Fitness by Zero Deficit LLC

Last Updated: April 28, 2026

Overview

This page describes what data Apex Fitness collects, how it's used, and whether it's shared with third parties. This information is provided to comply with Apple App Store and Google Play Store data safety requirements.

Opt-in means opt-in. Camera, precise location, HealthKit, and push notifications are only accessed after you explicitly enable the corresponding feature (Barcode Scanner, GPS Cardio, HealthKit Sync, or Notifications). Declining any of these permissions disables only that feature — the rest of the app continues to work.

Data Collected

Data Type Collected Shared Purpose
Email Address Collected Not Shared Account creation, login, password reset, transactional email
Name Collected Not Shared Display in app profile
Password Collected Not Shared Authentication (stored as bcrypt hash, never in plaintext)
Body Measurements Collected Not Shared Calculate BMR, TDEE, body fat %, and nutrition targets
Mobility / Injury Flags Optional Not Shared Personalize prehab protocols & injury-aware exercise swaps
Workout Logs Collected Not Shared Track exercise progress, progressive overload, PRs
Cardio Sessions (incl. GPS points) Optional Not Shared Compute distance, pace, elevation gain. GPS collected only while you're actively tracking a run/walk/hike/ride
Food Diary Entries Collected Not Shared Track daily nutrition and macro intake
Scanned Barcode History Optional Not Shared Store previously-scanned product name, brand, nutrients & scan count for one-tap re-logging
Recovery Metrics Optional Not Shared Sleep hours & quality, soreness, energy, stress, mood, custom metrics → feed the daily Recovery Score
Apple HealthKit Data On-Device Only Not Shared Steps, heart rate, active energy, sleep & workouts processed locally by Apple's framework. Never leaves your device unless you sync a derived metric into Apex.
Android Health Connect Data On-Device Only Not Shared Steps, active calories, sleep, exercise sessions read on-device via the Android Jetpack Health Connect SDK. Never leaves your device unless you sync a derived metric into Apex.
Purchase History Collected Not Shared Manage subscription status (Pro/Elite tiers) via Stripe (web), Apple IAP (iOS), or Google Play Billing (Android)
Push Notification Token Optional Not Shared Deliver opt-in workout reminders, PR celebrations, weekly summaries, and recovery insights via APNs (iOS), Firebase Cloud Messaging (Android), or Web Push (browsers)
Cosmetic Preferences Optional Not Shared Active app icon (alternate iOS home-screen icons: Default / Pro Gold / Streak Master / Launch Edition / Founder), theme, units, dietary filters, "Always show scroll bar" preference. Eligibility for alternate icons is computed from existing data — no new data is collected.
Workout History (read for prefill) Collected Not Shared Most recent weight_lifted + reps_completed per exercise from your own past lifting_logs is read internally to pre-populate Quick Log / Logbook / Speed Run / Start Workout. Never shared with third parties.

Device Permissions & On-Device Processing

Permission When Requested What Leaves Your Device
Camera (barcode scanner) First time you tap "Scan Barcode" on the Food Diary Only the decoded numeric barcode (e.g. 3017620422003). No images, video, or camera frames ever leave your device — decoding is performed locally by @zxing/browser / BarcodeDetector API.
Precise Location (While Using App) First time you start a cardio session with "Track with GPS" Timestamped lat/lon points, speed, altitude — stored only in your own private cardio_sessions record. Collected only during an active session and stopped the moment you pause or end the workout. We do NOT request background or always-on location.
Apple HealthKit (iOS) When you enable HealthKit sync in Settings Nothing leaves your device automatically. Raw Health samples are read on-device by Apple's framework. Only if you explicitly sync a derived metric (e.g. sleep hours) into your Apex recovery log is that value stored on our servers.
Health Connect (Android) When you enable Health Connect sync in Settings Nothing leaves your device automatically. Health Connect reads/writes happen on-device via the Android Jetpack SDK and require explicit per-data-type consent in the system Health Connect app. Only metrics you explicitly sync into your Apex recovery log are stored on our servers.
Vibration / Haptics (Android) When the app starts (declared in AndroidManifest) Nothing. Used by the WebView wrapper to fire short haptic taps on number-entry steppers, scroll wheels, and set-logging buttons. No data is collected or transmitted.
Push Notifications When you opt into reminders in onboarding or Settings Anonymous APNs device token (iOS), FCM registration token (Android), or Web Push subscription, plus each notification payload.

Data NOT Collected

Data Type Status
Camera images, video, or photos Not Collected
Background or always-on location Not Collected
Contacts Not Collected
Microphone / Audio Not Collected
Financial Information (card numbers, CVV, bank details) Not Collected
Browsing History Not Collected
SMS or Call Logs Not Collected
Advertising Identifiers (IDFA/AAID) Not Collected

Third-Party Services

Data Security

Data Deletion & Soft-Delete

You can delete your data at any time:

Children's Privacy

Apex Fitness is not intended for users under the age of 16. We do not knowingly collect data from minors.

Contact

Data Protection Officer: privacy@apexfitness.ai

General Support: support@apexfitness.ai

Privacy Policy | Terms of Service | Back to App