Privacy Policy
-
• We only collect what we need to run XPulse — your workouts, plans and profile. • We never sell your data and never share it with advertisers. • You can permanently delete your account from Profile → Delete account. • AI features use Google Gemini via the Emergent LLM proxy. • Payments are handled by Apple App Store or Google Play — we never see your card.
-
• Account info: name, email, picture (only if you sign in with Google). • Fitness data: workouts, plans, PRs, streaks, notes. • Optional body metrics: age, sex, height, weight, self-reported injuries — only if you enter them. • Social: friend links, feed likes, PRs you explicitly share. • Habit tracker: creatine log if enabled. • Device: stable device id (guest usage), language, OS, push token if you opt in. • Subscription receipts: transaction and product IDs used to verify purchases. We do NOT collect precise location, camera/microphone content, contacts, SMS/call logs, or biometrics.
-
• Deliver core features (save workouts, generate plans, calculate PRs). • Sync data across your devices when you sign in. • Send transactional emails (deletion codes, subscription notices). • Send push notifications you have enabled (workout reminders, friend PRs, creatine). • Prevent fraud and secure the service. • Comply with legal obligations (tax, subscription receipts).
-
• Google (Sign in with Google) — authentication. • Google Gemini via Emergent LLM proxy — AI plans and coach chat. • Emergent Resend — transactional emails. • Emergent Push — notification delivery. • MongoDB Atlas — encrypted database. • Apple App Store / Google Play — payments & receipt validation. • Expo — app delivery and aggregate performance metrics.
Each processor is contractually bound to process data only on our instructions.
-
Your workouts appear in the community feed with your first name and picture. When you set a Personal Record you get an explicit choice — Friends, Global, Both, or Not now — before the 'SHARED PR' highlight is broadcast. Nothing else is auto-shared. You can delete any log at any time.
-
• Account data is kept while your account is active. • When you delete your account, we permanently wipe your data — usually within seconds, always within 30 days. • Subscription receipts may be retained up to 7 years for tax/accounting law (personal identifiers stripped where possible). • Server logs are kept up to 90 days for security & debugging.
-
You can: • Access — request a copy of your data. • Rectify — correct inaccurate data. • Erase — delete your account in-app or by email. • Port — request an export of your logs, plans and PRs. • Object — turn off any notification category from Profile → Notifications. • Withdraw consent at any time. • Complain to your local data-protection authority. Email support@xpulsefit.com — we respond within 30 days.
-
• All data transmitted over TLS 1.2+. • Databases encrypted at rest (AES-256). • Authentication via Google OAuth + short-lived server-side session tokens. • Purchases validated server-side against Apple/Google APIs — no client-side 'I paid' signal is trusted. • Least-privilege access for all internal systems.
-
XPulse is not directed to children under 13. Users between 13 and 16 may only use XPulse with parental consent where required. We do not knowingly collect data from minors below the applicable age.
-
XPulse does not serve third-party advertising and does not sell your personal information. We use no behavioural analytics SDKs.
-
Material changes will be notified in-app or by email at least 14 days before they take effect. The 'Last updated' date at the top reflects the current version.
-
Data controller: XPulse Contact: support@xpulsefit.com — response within 30 days.