Privacy Policy
Last updated: September 24, 2026
Regulate is built to be private by default. There are no accounts, no sign-up, and no advertising. Your exercise history and progress stay on your device. This policy explains, in plain English, what little data exists and where it goes.
The short version
- Your data stays on your phone. Sessions, progress, streaks, goals, and settings are stored locally on your device.
- No account required. We never ask for your name, email, or any profile information.
- No advertising or tracking SDKs. The app contains no ad networks and does no tracking. From version 1.2 we use one privacy-first analytics service, TelemetryDeck, to count anonymous app events (details below).
- Purchases go through Apple and RevenueCat. RevenueCat receives only what's needed to process your subscription.
- You control export and deletion. You can export your data or wipe it at any time from within the app.
Data stored on your device (never sent to us)
The app stores the following locally, on your device only:
- Exercise session records (which exercise, when, how long, optional before/after ratings)
- Progress statistics, streaks, and goals derived from those sessions
- App settings and preferences
- A randomly generated installation identifier (a random ID created on first launch - it is not linked to you, your device serial, or any account)
We do not have servers that collect or store your session data. If you delete the app, this data is deleted with it (subject to your device backups, which you control). The only exception is the small set of anonymous usage events described under "Anonymous usage analytics" below.
Data shared with third parties
Apple (App Store)
Subscriptions and purchases are processed by Apple. Apple's handling of your payment information is governed by Apple's own privacy policy. We never see your payment details.
RevenueCat (purchase management)
We use RevenueCat to manage subscriptions and verify purchase entitlements. When you make or restore a purchase, RevenueCat receives purchase receipt information and an anonymous app user identifier so your subscription works reliably. RevenueCat does not receive your exercise or session data. See RevenueCat's privacy policy.
Diagnostic crash reports (anonymous)
If the app crashes or hits an error in a production build, it sends a minimal diagnostic report to our error-monitoring provider, Sentry (Functional Software, Inc.), who processes it on our behalf in Sentry's EU (Germany) region: the error type and message, a code location, the platform (iOS/Android), device model and OS version, and a timestamp. These reports are scrubbed of sensitive values before sending and contain no session content, no health information, and no identifiers tied to your identity. See Sentry's privacy policy.
Entitlement verification (if enabled)
Some releases may verify premium access against our server. If enabled, this check sends only the random installation identifier and a subscription/usage flag - no personal information and no exercise data.
Anonymous usage analytics
From version 1.2, the app sends anonymous usage events to TelemetryDeck (TelemetryDeck GmbH, Germany) so we can see which parts of Regulate actually help: the app was opened, onboarding was completed, an exercise was started or completed (and which one), the 1-5 rating you give an exercise and the state you picked (anxious, freeze, anger or balanced), the paywall was viewed, and a purchase was completed. Each event carries a random ID created on your device, which is hashed before it is sent; it is not linked to your name, email, advertising identifier or any account. Nothing you type in the app (for example, your grounding answers) is ever sent. We do not use this data for advertising or tracking. See TelemetryDeck's privacy policy.
That's the complete list. No other analytics SDKs (no Google Analytics, no Facebook SDK, no PostHog, Amplitude, Mixpanel, or similar), no data brokers, no selling or sharing of personal information for advertising - ever.
Data export
You can export your session history (CSV, JSON, or PDF) from within the app. The export file is generated on your device and handed to the system share sheet. Where it goes from there - email, files, AirDrop - is entirely your choice; we never receive a copy.
Data categories (App Store disclosure)
- Purchases - purchase history, linked to an anonymous identifier (RevenueCat). Used for app functionality only.
- Identifiers - a random installation ID, not linked to your identity. Used for app functionality and anonymous analytics.
- Usage data - product interaction (anonymous app events and exercise ratings, via TelemetryDeck), not linked to your identity. Used for analytics only.
- Diagnostics - anonymous crash/error data, not linked to your identity. Used for app functionality only.
- Health & fitness, contact info, location - not collected by us. Your full session records exist only on your device.
Retention
- On-device data: kept until you delete it in the app or uninstall the app.
- RevenueCat purchase records: retained per RevenueCat's policy for as long as needed to service your subscription.
- Diagnostic error reports: retained only as long as needed to fix the underlying issue, then deleted.
Children
Regulate is not directed at children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from children. Because the app collects essentially no personal information from anyone, there is no child data to collect - but if you believe a child has provided personal information to us, contact us and we will delete it.
Your rights (GDPR, UK GDPR, California and similar laws)
Because your data lives on your device, you can exercise most rights directly: view your data in the app, export it, or delete it in settings (or by uninstalling). For the limited data held by third parties or in diagnostics:
- Access / deletion: email us and we will handle requests concerning any diagnostic data, and point you to Apple/RevenueCat processes for purchase records.
- No sale or sharing: we do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of (California CCPA/CPRA).
- Legal basis (GDPR): processing purchase data is necessary to perform our contract with you; minimal diagnostics and anonymous usage analytics rest on our legitimate interest in keeping the app working and improving it.
- Complaints: EU/UK users may lodge a complaint with their local supervisory authority.
Security
On-device data is protected by your device's own security (passcode, encryption at rest as provided by iOS/Android). Data sent to RevenueCat or our diagnostics endpoint travels over encrypted connections (HTTPS).
Changes to this policy
If we change what data the app handles, we will update this page and the "last updated" date. Material changes will be flagged in the app's release notes.
Contact
Questions or requests: support@getregulate.app