Privacy Policy
Last updated: July 8, 2026
Regulate is built to be private by default. There are no accounts, no sign-up, and no advertising. Your exercise history and progress stay on your device. This policy explains, in plain English, what little data exists and where it goes.
The short version
- Your data stays on your phone. Sessions, progress, streaks, goals, and settings are stored locally on your device.
- No account required. We never ask for your name, email, or any profile information.
- No advertising or tracking SDKs. The app contains no ad networks and no third-party behavioral analytics.
- Purchases go through Apple and RevenueCat. That's the only third party that routinely receives data, and only what's needed to process your subscription.
- You control export and deletion. You can export your data or wipe it at any time from within the app.
Data stored on your device (never sent to us)
The app stores the following locally, on your device only:
- Exercise session records (which exercise, when, how long, optional before/after ratings)
- Progress statistics, streaks, and goals derived from those sessions
- App settings and preferences
- A randomly generated installation identifier (a random ID created on first launch - it is not linked to you, your device serial, or any account)
We do not have servers that collect or store your session data. If you delete the app, this data is deleted with it (subject to your device backups, which you control).
Data shared with third parties
Apple (App Store)
Subscriptions and purchases are processed by Apple. Apple's handling of your payment information is governed by Apple's own privacy policy. We never see your payment details.
RevenueCat (purchase management)
We use RevenueCat to manage subscriptions and verify purchase entitlements. When you make or restore a purchase, RevenueCat receives purchase receipt information and an anonymous app user identifier so your subscription works reliably. RevenueCat does not receive your exercise or session data. See RevenueCat's privacy policy.
Diagnostic error reports (optional, anonymous)
If the app crashes or hits an error in a production build, it may send a minimal diagnostic report to our error-collection endpoint: the error type and message, a code location, the platform (iOS/Android), and a timestamp. These reports are scrubbed of sensitive values before sending and contain no session content, no health information, and no identifiers tied to your identity. If no error-collection endpoint is configured in a given release, nothing is sent at all.
Entitlement verification (if enabled)
Some releases may verify premium access against our server. If enabled, this check sends only the random installation identifier and a subscription/usage flag - no personal information and no exercise data.
That's the complete list. No analytics SDKs (no Google Analytics, no Facebook SDK, no PostHog, Amplitude, Mixpanel, or similar), no data brokers, no selling or sharing of personal information for advertising - ever.
Data export
You can export your session history (CSV, JSON, or PDF) from within the app. The export file is generated on your device and handed to the system share sheet. Where it goes from there - email, files, AirDrop - is entirely your choice; we never receive a copy.
Data categories (App Store disclosure)
- Purchases - purchase history, linked to an anonymous identifier (RevenueCat). Used for app functionality only.
- Identifiers - a random installation ID, not linked to your identity. Used for app functionality only.
- Diagnostics - anonymous crash/error data, not linked to your identity. Used for app functionality only.
- Health & fitness, usage data, contact info, location - not collected by us. Your session records exist only on your device.
Retention
- On-device data: kept until you delete it in the app or uninstall the app.
- RevenueCat purchase records: retained per RevenueCat's policy for as long as needed to service your subscription.
- Diagnostic error reports: retained only as long as needed to fix the underlying issue, then deleted.
Children
Regulate is not directed at children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from children. Because the app collects essentially no personal information from anyone, there is no child data to collect - but if you believe a child has provided personal information to us, contact us and we will delete it.
Your rights (GDPR, UK GDPR, California and similar laws)
Because your data lives on your device, you can exercise most rights directly: view your data in the app, export it, or delete it in settings (or by uninstalling). For the limited data held by third parties or in diagnostics:
- Access / deletion: email us and we will handle requests concerning any diagnostic data, and point you to Apple/RevenueCat processes for purchase records.
- No sale or sharing: we do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of (California CCPA/CPRA).
- Legal basis (GDPR): processing purchase data is necessary to perform our contract with you; minimal diagnostics rest on our legitimate interest in keeping the app working.
- Complaints: EU/UK users may lodge a complaint with their local supervisory authority.
Security
On-device data is protected by your device's own security (passcode, encryption at rest as provided by iOS/Android). Data sent to RevenueCat or our diagnostics endpoint travels over encrypted connections (HTTPS).
Changes to this policy
If we change what data the app handles, we will update this page and the "last updated" date. Material changes will be flagged in the app's release notes.
Contact
Questions or requests: support@getregulate.app