Privacy Policy
Last updated: August 26, 2026
1. Who we are
Basalt is published by OTIA LTD. For any question: [email protected].
2. Data we collect
2.1 Data you provide
- Profile: first name, sex, age, height, weight, goal, level, frequency, equipment
- Account: email (Apple, Google, or direct sign-up)
- Sessions: exercises, sets (weight, reps, duration, distance, RPE), notes
- Photos (optional, only the ones you choose): profile picture, workout memory photo, photo illustrating a custom exercise. Taken with the camera or picked from your photo library, they are only used to display that content in the app — never to identify you, never analyzed, never shared
2.2 Data collected automatically
- Apple Health (only with your permission): sex, age, height, weight, heart rate during sessions
- Apple/Google identifier: for authentication (never your password)
- Crash diagnostics (Sentry): crash and error reports to fix bugs, with no personal data (PII disabled), attached to your pseudonymized Supabase ID
- Usage analytics (PostHog): app usage events (workout completed, subscription screen shown, etc.), hosted in Europe (EU). By default these measurements are anonymous: tied to a random identifier specific to the installation, never to your account, and can be turned off at any time in Profile → Privacy & legal. If you agree to link them to your account (offered at the end of the welcome questionnaire, changeable in the same place), they are tied to your pseudonymized Supabase ID, including those already recorded on this device. Never your loads or body measurements
- Welcome journey: each completed step of the welcome questionnaire is recorded on our servers (the step and its date, tied to your account), to see where the journey stalls and improve it
- Ad attribution (AppsFlyer): when you install the app after seeing one of our ads (Meta, TikTok, Google), attribution signals let us measure our campaigns — an app-scoped AppsFlyer identifier, the vendor-scoped device identifier (IDFV) and Apple's aggregated SKAdNetwork signals. Never the IDFA: we do not show iOS's tracking request (App Tracking Transparency), and without that consent iOS itself blocks any cross-app tracking
2.3 What we do NOT collect
- No cross-app tracking: the IDFA is never read (no App Tracking Transparency request) — our campaign attribution relies on the app-scoped AppsFlyer identifier, the IDFV and Apple's aggregated signals (see 2.2)
- No ad networks or social pixels (Google Analytics, Facebook Pixel, etc.) — usage analytics are anonymous by default, can be turned off at any time, and are only tied to your account with your explicit consent (see 2.2)
- No location
- No contacts, no microphone
- No access to your photo library beyond the photos you select yourself
3. Why we use this data
- To let you use the app (log your sessions, track your progress)
- Sync your profile and sessions across your devices
- Compute your stats (records, plateau detection, 1RM projections)
- Measure the effectiveness of our own ad campaigns (attribution, see 2.2)
No data is ever sold. Attribution is only used to measure our ads — never to profile you for third parties.
4. Where your data is stored
- Locally on your iPhone (SwiftData)
- On Supabase (servers in Europe, EU): cloud backup + cross-device sync
- Your photos on Supabase Storage (servers in Europe, EU): private storage areas, partitioned per account — only you can access them, through temporary signed links
- Apple Health stays on your device and iCloud under Apple's control
All communications with our servers are encrypted (TLS).
5. Your rights (GDPR)
You have the right to:
- Access your data: from the Profile screen
- Modify your data: from the Profile screen
- Delete your account and all your data: Profile → "Delete my account" (irreversible, full cascade on our servers)
- Export your data: send us an email at [email protected]
For any GDPR question: [email protected].
6. Retention
- As long as your account exists: your data stays stored
- A photo you remove yourself (profile picture, workout photo, exercise photo) is erased from our servers
- On account deletion: immediate erasure of all your data on our side, photos included
- Supabase backups: purged within 30 days after deletion
7. Minors
Basalt is not intended for children under 13. If you are under 13, do not use the app.
8. Changes
This policy may evolve. Any significant change will be notified to you in the app.
9. Subprocessors
- Supabase (Postgres, auth, storage) — Europe (EU)
- Apple (Sign in with Apple, Apple Health) — subject to Apple Privacy Policy
- Google (Sign in with Google) — subject to Google Privacy Policy
- RevenueCat (subscription management) — pseudonymized via your Supabase ID
- Sentry (crash reporting) — Germany (EU); PII disabled, pseudonymized via your Supabase ID
- PostHog (usage analytics — anonymous by default, can be turned off; tied to your account only with your consent; also receives subscription events forwarded by RevenueCat, pseudonymized) — Europe cloud (EU, Frankfurt); random installation identifier, or your pseudonymized Supabase ID if you accepted the link
- AppsFlyer (attribution of our ad campaigns — measures which ads drive installs; also receives subscription events forwarded by RevenueCat, pseudonymized) — app-scoped AppsFlyer identifier, IDFV and aggregated SKAdNetwork signals, never the IDFA without consent
- Have I Been Pwned (sign-up check that a password has not publicly leaked) — only receives an anonymous hash fragment (5 SHA-1 characters), never your password or email