Privacy Policy

Last updated: August 12, 2026

Effective date: August 12, 2026

Policy version: 2026.08.12

Overview

This Privacy Policy explains how False Summit Solutions LLC ("PostureMax," "we," "us," or "our") collects, uses, stores, and shares your information when you use the PostureMax mobile application (the "App") and related services. We've tried to write this in plain language. If anything is unclear, email us at support@posturemaxapp.com.

In short: we collect what we need to make the App work — your account, your posture data, and the photos you take during scans. Photos are used for AI analysis and discarded; only the results are kept. We also use limited pseudonymous product-funnel events to understand onboarding and subscription conversion; those events do not contain camera, motion, health, fitness, sensor, or posture-measurement data. Account deletion and requests concerning pseudonymous funnel data are described in Section 5.

1. Information We Collect

1.1 Account Information

You can sign in using Apple Sign-In or Google Sign-In. When you do, we receive:

  • Your email address (or, with Apple Sign-In, a private relay address if you choose)
  • Your name, if provided by the sign-in service
  • A unique account identifier from Firebase Authentication

1.2 Profile Information

During onboarding and in Settings, you may provide:

  • Gender
  • Height and weight
  • Age (must be 13 or older — see Section 8)
  • Activity level
  • Daily reminder preferences
  • Where you heard about the App (referral source)

1.3 Posture & Activity Data

  • Daily check-ins: dates, completion counts, and reminder responses
  • Streak data: current streak, best streak, last active date
  • Training drills: drill type, duration, completion timestamps
  • AirPods posture sessions: session date, duration, average / best / worst score, and head-orientation samples used to compute posture scores (see Section 1.5)
  • Posture scan reports: the numerical Shell Score, identified problem zones, summary text, and recommended drills generated from your scans (the source images are not retained — see Section 1.4)

1.4 Camera & Photo Data (Posture Scans)

When you run an AI Posture Scan, the App captures one or two photos (front and side) using your device camera. These photos are:

  • Resized and compressed on your device before transmission;
  • Sent over an encrypted (HTTPS / TLS) connection to our backend, which forwards them to OpenAI's GPT-4 family Vision API (in some configurations via the AIProxy proxy service) for analysis;
  • Held in memory only for as long as the analysis takes, and then discarded — neither we nor our backend store the photos persistently;
  • Never written to your device's Photo Library, never shared with anyone other than the AI provider described above.

Only the textual / numeric analysis results (your Shell Score, problem zones, and recommended drills) are saved on your device and synced to your account.

1.5 Motion Data (AirPods)

If you start an AirPods posture monitoring session, we use the Headphone Motion API (compatible with AirPods Pro, AirPods Max, AirPods 3rd generation, and other headphones supporting head tracking) to read head orientation while the session is active. This motion data:

  • Is processed entirely on your device to compute a real-time posture score;
  • Is summarized into a session record (averages, durations, score samples) that is saved locally and synced to your account;
  • Is not transmitted to OpenAI, Anthropic, or any other third party.

1.6 Gamification Data

The App includes a mascot-evolution gamification layer. We collect and store:

  • Your shrimp's display name (defaults to "Shrimpy"; you can rename it)
  • Your chosen shell color
  • Total XP, current evolution stage, and highest stage reached
  • XP events (source, amount, timestamp) and daily XP totals
  • Streak length and last-active date

1.7 Subscription & Purchase Data

If you purchase a subscription, Apple's App Store handles the transaction. We use RevenueCat to receive your subscription entitlement status (active / expired / trial) keyed to an anonymous user ID. We do not see, receive, or store your full payment card or Apple ID credentials.

1.8 Diagnostics & Usage Data

We automatically collect:

  • Crash logs and performance diagnostics (Firebase Crashlytics)
  • Pseudonymous event-level feature-usage data (Firebase Analytics) — e.g. which screens are opened, which features are used, and how often the App is launched; reports produced from this data may be aggregate
  • Device model, operating system version, App version, language, and region

1.9 First-Party Product & Funnel Analytics

To understand where people leave onboarding and whether advertising acquisition leads to subscription conversion, the App is designed to collect a limited event-level product analytics stream. When enabled, each record may include:

  • A random, pseudonymous identifier for this App installation (rotated after the App is reinstalled), a per-process session identifier, and RevenueCat's anonymous App User ID so product milestones can be related to subscription outcomes;
  • For relay security, an Apple App Attest key identifier plus challenge, attestation, and assertion metadata used to verify that requests came from a supported genuine App instance;
  • App version, build, operating-system version, ATT authorization status, and event timestamps;
  • First-open and app-open milestones; onboarding steps viewed, completed, or skipped; permission prompts and their results; and the first qualifying activation milestone (starting monitoring, completing a scan report, or completing a guided drill);
  • Paywall presentation and interactions, checkout initiation and result (success, cancellation, pending, or failure), and restore outcomes, including whether no active entitlement was found; and
  • Low-cardinality paywall, offering, and product identifiers and, when shown, the displayed localized price and currency. These client events are not verified subscription revenue records.

This stream does not contain your name, email address, Firebase account ID, IDFA, photos or camera frames, motion or other sensor samples, HealthKit data, health or fitness content, body or posture measurements or scores, diagnoses, free-form health information, payment-card details, or verified subscription revenue amounts.

The relay is deployed through OpenAI ChatGPT Sites on Cloudflare infrastructure. Cloudflare Workers handles relay requests, Cloudflare D1 stores accepted event records, and Cloudflare R2 stores bounded dashboard report and review artifacts. OpenAI processes this hosted data to host, maintain, and support the Site, while PostureMax controls its retention and deletion through the service. The App does not include an IP address in the funnel event payload, but OpenAI and its subprocessors may necessarily process source IP addresses and standard HTTP request metadata while delivering, securing, or rate-limiting requests. Provider security and operational logs are governed by the applicable provider terms and are not used by PostureMax as product-funnel analytics.

Events are stored temporarily on the device if delivery is unavailable and, when all launch safeguards are enabled, are sent over HTTPS through the protected relay described in Section 3.2. Retention and deletion are described in Sections 5 and 6.

1.10 Push Notifications

If you grant notification permission, we send local and remote notifications for posture reminders, streaks, milestones, and evolution events. You can disable these in iOS Settings or in the App's settings at any time.

1.11 Advertising & Tracking Data

The App integrates the Meta (Facebook) iOS SDK for advertising attribution and campaign measurement. During onboarding, the App may request permission through Apple's App Tracking Transparency (ATT) prompt. Meta attribution, events, device-identifier collection, and RevenueCat-to-Meta linkage are enabled only while ATT authorization is explicitly granted. The data processing depends on your choice:

  • If you allow tracking: the App may provide Meta with your IDFA and generic paywall, checkout, and registration milestones for ad measurement. It may also attach Meta's anonymous attribution identifier and permitted device identifiers to your RevenueCat anonymous profile. RevenueCat, rather than the App, may then report verified trial, subscription, renewal, conversion, billing, refund, and other subscription-lifecycle or revenue outcomes to Meta through its server-to-server integration. The App does not directly send Meta purchase or revenue events.
  • If you do not allow tracking: the App does not send Meta custom product events, handle Meta deep-link attribution, collect advertising identifiers for RevenueCat, or link the RevenueCat anonymous profile to Meta. If permission is later withdrawn, the App stops further Meta attribution and linkage activity for the current profile. Apple may independently provide privacy-preserving aggregate attribution through SKAdNetwork.

Denying tracking does not change any core functionality of the App.

2. How We Use Your Information

We use your information to:

  • Operate the App's core posture-monitoring, scanning, and coaching features;
  • Compute Shell Scores, generate drills, and award XP;
  • Track streaks, evolve your mascot, and deliver gamification rewards;
  • Sync your data across devices when you are signed in;
  • Send notifications you've opted in to;
  • Process subscription purchases and manage entitlements;
  • Understand onboarding and paywall drop-off and measure pseudonymous subscription conversion;
  • Measure advertising effectiveness only when ATT authorization permits Meta attribution;
  • Diagnose crashes, fix bugs, and improve performance;
  • Prevent abuse and enforce our Terms;
  • Provide customer support;
  • Comply with legal obligations.

We do not sell your personal information. We do not use your posture data, scans, or motion data to train AI models.

3. Where Your Data Lives

3.1 On Your Device

  • Core Data stores your check-ins, sessions, profile, and gamification data locally;
  • iOS Keychain stores authentication tokens, the pseudonymous installation identifier, and App Attest registration state securely;
  • Protected App storage temporarily stores pending or quarantined funnel events when they cannot be delivered;
  • UserDefaults stores small preference values.

3.2 In the Cloud

When you are signed in, your data is synchronized to Firebase Firestore, hosted by Google Cloud in the United States. Stored items include your profile, check-ins, streaks, training drill history, AirPods session summaries, posture report results (no images), gamification data, and XP events. Firestore is governed by security rules that prevent any user from reading or writing another user's data.

When first-party funnel analytics is enabled, event records are sent over HTTPS to a private PostureMax product-analytics relay and dashboard deployed through OpenAI ChatGPT Sites on Cloudflare Workers. Accepted event records are stored in Cloudflare D1, and bounded dashboard report and review artifacts are stored in Cloudflare R2. The relay uses Apple App Attest challenges and cryptographic assertions to reject unsupported or unauthenticated clients; there is no shared relay secret stored in the App. The relay accepts only the limited event fields described in Section 1.9 and does not accept posture, camera, motion, health, fitness, or sensor payloads. OpenAI ChatGPT Sites does not provide a data-residency setting at launch, and no Cloudflare D1 jurisdiction setting is evidenced for this relay, so this service has no fixed processing or storage residency.

3.3 Security

  • All network traffic uses HTTPS / TLS encryption;
  • Authentication tokens are stored in the iOS Keychain;
  • Server-side requests to our backend are authenticated using Firebase ID tokens;
  • First-party funnel requests use replay-protected Apple App Attest challenges and assertions and fail closed when attestation or required launch configuration is unavailable;
  • Firestore security rules restrict every user to their own documents.

No system is perfectly secure. We work to protect your data, but we cannot guarantee absolute security.

4. Third-Party Services

We use the following service providers ("processors") to run the App. Each operates under their own privacy policy.

4.1 Firebase (Google LLC)

  • Firebase Authentication — Apple / Google sign-in and account identity
  • Cloud Firestore — encrypted storage of your account data
  • Firebase Analytics — pseudonymous event-level usage data and aggregate reporting
  • Firebase Crashlytics — crash reports and stack traces

Privacy: firebase.google.com/support/privacy

4.2 OpenAI (OpenAI, L.L.C.)

  • Posture-scan photos and the analysis prompt are sent to OpenAI's GPT-4 family Vision API for analysis.
  • Only the data needed to perform the analysis is sent. We do not include your name, email, or any other identifying profile data.
  • Per OpenAI's API data-usage policy, prompts and outputs are not used to train OpenAI's models.

Privacy: openai.com/privacy

4.3 AIProxy

In some configurations, posture-scan requests are routed through AIProxy, a proxy that authenticates and forwards requests to OpenAI on our behalf without exposing our API keys. AIProxy does not retain image content beyond what is required to deliver the request.

Privacy: aiproxy.com/privacy

4.4 Anthropic

Our backend supports the Anthropic Claude API as an alternative coaching provider. If a feature you use is configured to call Claude, the relevant text prompt will be sent to Anthropic. Photos are never sent to Anthropic.

Privacy: anthropic.com/legal/privacy

4.5 RevenueCat

Manages App Store subscriptions and entitlements using an anonymous App User ID and receives transaction metadata (product ID, period, status). That anonymous ID is also used by the first-party funnel stream to relate product milestones to subscription outcomes. Only while ATT is authorized may the App attach Meta attribution identifiers to the RevenueCat profile so RevenueCat can send verified subscription-lifecycle and revenue outcomes to Meta. RevenueCat does not receive your name, email, posture data, or scan photos from this integration.

Privacy: revenuecat.com/privacy

4.6 Meta Platforms (Facebook)

Used solely for advertising attribution and campaign measurement, subject to your ATT choice (see Section 1.11). Meta event and RevenueCat-linkage activity is disabled unless ATT is authorized. Tracking domains are facebook.com, facebook.net, fb.com, and fb.gg.

Privacy: facebook.com/privacy/policy

4.7 Apple & Google

Apple provides Sign in with Apple, the App Store, in-app purchase processing, push notifications (APNs), SKAdNetwork, and App Attest verification for the protected funnel relay. Google provides Google Sign-In and the Firebase services listed above.

4.8 WishKit

If you submit a feature request or feedback through the in-App feedback view, that submission is processed by WishKit so we can collect and triage feedback.

Privacy: wishkit.io/privacy

4.9 Backend Hosting

Our backend API (which proxies AI requests, performs authentication, and applies rate limits) is hosted on Render in the United States.

4.10 Product-Analytics Relay Hosting

The separate first-party product-analytics relay and private dashboard are deployed through OpenAI ChatGPT Sites and use Cloudflare Workers, Cloudflare D1, and Cloudflare R2 as described in Sections 1.9 and 3.2. OpenAI processes hosted data to host, maintain, and support the Site, and identifies Cloudflare as a subprocessor for content-delivery-network and web-hosting services that may process data closest to end users for certain products. This service receives only the product-funnel and request-security data described above. Provider security and operational logs are governed by the applicable provider terms and are not used by PostureMax as product-funnel analytics.

5. Your Rights & Choices

5.1 Inside the App

  • View your data: Your check-ins, sessions, drills, scan reports, XP history, and profile are all accessible inside the App.
  • Delete individual items: Delete any saved posture report from the report list.
  • Delete product analytics: Settings → Privacy & Data → Delete analytics data removes queued and quarantined product analytics from the device and makes an App-Attest-protected request to delete the matching relay product events and analytics identity links. If the relay result cannot be confirmed, event delivery remains paused and the App retries rather than treating the request as complete. This does not delete your posture data, account, or subscription.
  • Delete your account: Settings → Delete Account permanently removes your Firebase account, all your Firestore data, and local Core Data on the device. Account deletion does not itself send the separate relay deletion request, so use Delete analytics data for the first-party funnel stream. This action cannot be undone. If you have an active App Store subscription, you must cancel it separately in iOS Settings → [your name] → Subscriptions — Apple does not allow developers to cancel subscriptions on your behalf.

Raw funnel records are keyed to pseudonymous installation and RevenueCat anonymous identifiers rather than your name or email. The in-App control authenticates the matching relay partition without disclosing those identifiers. If you cannot use the in-App control, email support@posturemaxapp.com. Because an email address alone may not identify a pseudonymous relay partition, support may be unable to locate those records without a matching identifier. Whether or not a support request can be matched, the relay automatically deletes event-level and aggregate funnel analytics no later than 90 days after relay receipt as described in Section 6.

5.2 In iOS Settings

  • Camera, Motion & Notifications: manage permissions in Settings → PostureMax. Revoking the camera disables AI scans; revoking motion disables AirPods sessions; revoking notifications disables reminders. The rest of the App continues to work.
  • Tracking: change your ATT choice in Settings → Privacy & Security → Tracking.
  • Apple Advertising Personalization: manage in Settings → Privacy & Security → Apple Advertising.

5.3 GDPR (EEA / UK Residents)

If you are in the European Economic Area, the United Kingdom, or Switzerland, the General Data Protection Regulation gives you the right to:

  • Access the personal data we hold about you;
  • Have inaccurate data corrected;
  • Have your data erased;
  • Restrict or object to certain processing;
  • Receive a copy of your data in a portable format;
  • Withdraw consent (where processing is based on consent) at any time;
  • Lodge a complaint with your local supervisory authority.

Our legal bases for processing are: (i) performance of contract for delivering the App's features, (ii) legitimate interests for diagnostics and abuse prevention, (iii) consent for advertising tracking and notifications, and (iv) legal obligation where required. Requirements for first-party funnel analytics may vary by jurisdiction. This Policy does not state that regional consent is unnecessary or replace a jurisdiction-specific review.

To exercise any of these rights, email support@posturemaxapp.com. For first-party funnel analytics, use Settings → Privacy & Data → Delete analytics data as described in Section 5.1. Users who cannot use that control may contact support; because the stream is pseudonymous, support may be unable to locate a relay partition without a matching identifier, and all such analytics is automatically deleted under Section 6.

5.4 CCPA / CPRA (California Residents)

California residents have the right to know what personal information we collect, to request deletion of that information, to correct inaccuracies, and to opt out of "sale" or "sharing" of personal information. We do not sell personal information. We do "share" certain identifiers with Meta for cross-context behavioral advertising only when you have granted ATT permission; you can opt out at any time by denying ATT or by emailing support@posturemaxapp.com. We will not discriminate against you for exercising any of these rights.

5.5 Other Jurisdictions

If your jurisdiction grants you additional privacy rights, you may exercise them by contacting us. We will respond within the timeframes required by applicable law.

6. Data Retention

  • Account data: retained while your account is active. Deleted permanently within 30 days after you delete your account.
  • Local account and posture data on your device: retained until you delete the App, sign out, or use the in-App account-deletion option. The separate funnel queue and pseudonymous security/installation state follow the funnel-specific rules below and are not currently cleared by in-App account deletion.
  • Posture-scan photos: not retained — held only in memory during analysis and then discarded.
  • Crash and analytics data: retained according to Google's default Firebase retention periods (typically up to 14 months for analytics; longer for crash reports until cleared).
  • First-party funnel analytics: the client expires pending and quarantined event-level records within 90 days of the event timestamp and never delivers them after that limit. If the protected relay accepts an event, no event-level record or aggregate derived from that event is retained beyond 90 days from the time the relay receives it. This same deadline applies to D1 records and to any R2 dashboard evidence, Markdown report, review artifact, or associated report or decision metadata that contains that funnel analytics.
  • Backups and logs: we do not intentionally copy funnel event payloads into application logs, and PostureMax-controlled backups, reports, and artifacts do not retain event-level or aggregate funnel analytics after the applicable relay-receipt deadline. Provider security and operational logs may process source IP addresses and standard HTTP metadata under the applicable provider terms; PostureMax does not use those logs as product-funnel analytics.

At the applicable 90-day deadline, the raw event-level funnel records and their installation, RevenueCat user, session, event, and idempotency identifiers are deleted. Any identifier-free daily aggregates, report or evidence contents, review artifacts, and associated report or decision metadata containing that event's funnel analytics are also deleted by that deadline. We retain no event-level or aggregate first-party funnel analytics beyond 90 days from relay receipt. App Attest registration and request-security records are security records rather than funnel analytics and follow their separate expiry process.

7. International Data Transfers

PostureMax is operated from the United States. Your data may be transferred to and processed in the United States and in countries where our service providers and their subprocessors operate.

The first-party funnel relay/dashboard is deployed through OpenAI ChatGPT Sites on Cloudflare Workers and uses Cloudflare D1 and R2. OpenAI ChatGPT Sites does not provide a data-residency setting at launch. Cloudflare D1 uses automatic placement unless a jurisdiction was selected when the database was created, and no jurisdiction setting is evidenced for this relay. OpenAI identifies Cloudflare as a content-delivery-network and web-hosting subprocessor that may process data closest to end users for certain products. Accordingly, no fixed processing or storage residency is promised for this service. OpenAI's Data Processing Addendum states that transfers of Hosted Data from the EEA or Switzerland use the EU Standard Contractual Clauses or an adequacy decision, while transfers from the United Kingdom use those clauses with the UK Addendum. Other provider transfers are governed by their applicable contractual terms.

8. Children's Privacy

PostureMax is intended for users 13 years of age or older. We do not knowingly collect personal information from children under 13. The App enforces a minimum age of 13 during onboarding. If you are a parent or guardian and believe a child under 13 has provided us with personal information, please contact support@posturemaxapp.com and we will delete it promptly. Users under 18 should obtain a parent or guardian's permission before using the App.

9. Health Information

PostureMax is a general wellness product and is not a medical device. The posture data, scores, and recommendations the App generates are for informational and motivational purposes only. They are not medical records, are not protected health information ("PHI") under HIPAA, and should not be used to make medical decisions. See our Terms & Conditions for the full health disclaimer.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we'll change the "Last updated" date above. For material changes, we will provide additional notice — for example, an in-App alert or email. Your continued use of the App after a change becomes effective indicates acceptance of the updated policy.

11. Contact Us

If you have any questions about this Privacy Policy, your data, or our practices, please contact us:

False Summit Solutions LLC
Developer of PostureMax

By creating an account or using PostureMax, you acknowledge that you have read and understood this Privacy Policy.