PilatesScroll
Privacy Policy
The short version
- Camera frames and pose results stay on your device. We do not record or upload workout video.
- You can use local workout features without a cloud account. Optional cloud backup requires an explicit 16+ confirmation and consent.
- Android disables operating-system cloud backup and device transfer for app-owned data. On iOS, PilatesScroll requests backup exclusion on a best-effort basis, but Apple-controlled full-device, Finder, or MDM backups may still include local state. Firebase workout backup is the app's explicit in-app cross-device option.
- Firebase Analytics and Crashlytics are separate optional choices, both off by default.
- Feedback and feature requests are sent only when you write a message and submit it. They carry no account, workout, camera, or advertising identifier.
- Buying a subscription and restoring a purchase never require a PilatesScroll cloud account.
- We do not sell personal information, show third-party ads, or use cross-app tracking. The apps do not request advertising identifiers or ad-attribution permissions.
- Settings > Privacy & Data lets you review choices, export data, and delete an optional cloud account while preserving local workout progress.
1. Scope and Controller
This policy explains how Kaironos LLC (“Kaironos,” “we,” “us,” or “our”) processes information in connection with the PilatesScroll iOS and Android apps. Kaironos LLC is the controller for the processing described here.
2. Information We Process
Local workout and preference data
Workout progress, rep totals, streaks, banked and used time, collectibles, selected apps, themes, workout and voice preferences, your weekly plan settings, your Pilates Alarm schedule, your privacy choices, and onboarding answers are stored on your device. Screen Time or Usage Access selections remain device-local.
Optional cloud account and workout backup
If you explicitly enable cloud backup, Firebase processes a user identifier, a consent receipt, linked Apple or Google account details, and the workout data needed to restore progress across devices. Provider details may include an email address and, for Google, a basic display name or profile-image URL retained by Firebase Authentication. We do not use the profile image in the app.
Optional usage analytics
If you opt in, Firebase Analytics receives limited product interactions, such as onboarding, workout start/finish, paywall, purchase, and feature events. It may also process an app-instance identifier, device and app information, language, and an approximate region derived from network information. We exclude exact reps, selected moves, camera data, streaks, and earned time. Firebase's automatic store-purchase measurement may include product identifier, price, and currency.
Optional crash reports
If you opt in, Firebase Crashlytics receives crash traces, diagnostics, installation identifiers, and device and app information needed to investigate reliability problems. We do not attach a Firebase account user ID to Analytics or Crashlytics.
Notifications and push token
Streak reminders, the optional daily plan reminder, Pilates Alarm, and any trial-end reminder are scheduled locally on your device. If cloud backup is enabled and notification permission is granted, Firebase Messaging may assign and store a device push token to support app notification delivery. The token is removed when cloud backup is withdrawn or the cloud account is deleted. You can revoke notification permission in device settings.
Subscriptions and necessary service data
Apple, Google Play, and RevenueCat process subscription status, app-scoped customer identifiers, product and transaction information, and limited device, app, and network-derived region information. We do not receive your full payment-card number. Purchasing a subscription and restoring an existing purchase do not require a PilatesScroll cloud account; if you never sign in, the subscription identifier stays unlinked to any Apple or Google profile we hold.
Firebase Remote Config, App Check, and Installations process limited installation, device, app, integrity, version, language, and approximate-region data needed for compatibility, security, and service delivery. On Android, Google ML Kit documents limited device and app information, per-installation identifiers, performance and API metadata, feature-event types, and error codes for SDK diagnostics. It does not receive camera images or pose results.
Optional in-app feedback and feature requests
If you write a message in the app's feedback form and submit it, the app sends only that message, the category you picked (for example bug report, feature request, or why you are leaving), where you opened the form, your platform, the app version and build, your app language, and a random code the app generated for itself to limit spam. Nothing is sent while you are typing, and nothing is sent if you close the form.
The submission goes to a Kaironos service protected by Firebase App Check, which turns the message into a ticket in a private issue repository hosted by GitHub that only Kaironos can read. The random anti-spam code is hashed on the server, used only to count how many submissions one installation has sent in the last 24 hours, and is never written into the ticket or returned to the app.
Feedback deliberately carries no Firebase account or user ID, no email address, no name, no workout, streak, or banked-time data, no camera or pose data, no advertising identifier, and no device model. If you type personal details into the message yourself, they become part of the ticket, so please leave them out unless you want us to have them. Google Cloud and GitHub may process ordinary network metadata such as an IP address as part of their own infrastructure security; the app does not copy that into the ticket.
Because a ticket carries no account identifier, we cannot connect it to you or find it from your account. To ask us to remove something you sent, email privacy@kaironosapps.com with the approximate date and enough of the wording to identify it.
Support and rights requests
If you contact us, we process your email address, message, and the limited verification information needed to answer the request or prevent deletion of another person's account.
3. Camera and On-Device Pose Detection
PilatesScroll uses Apple Vision on iOS and Google ML Kit on Android to estimate body pose and count repetitions. Camera frames are analyzed live on the device. They are not recorded, stored, uploaded, or shared with Kaironos, Apple, Google, Firebase, or RevenueCat.
You can revoke camera permission in device settings. Without it, automatic rep detection cannot operate.
4. Purposes and Legal Bases
- Local workouts, settings, and setup personalization: performance of the app service under GDPR Article 6(1)(b); app-owned state remains on your device.
- Cloud workout backup: consent under GDPR Article 6(1)(a) and, where workout data is treated as health data, explicit consent under Article 9(2)(a).
- Optional Analytics and Crashlytics: consent under Article 6(1)(a), and explicit consent where an event is treated as health data.
- Subscriptions, restores, and support: performance of a contract under Article 6(1)(b).
- Feedback and feature requests you send us: handling the support request you asked for under Article 6(1)(b), and our legitimate interest in improving the app under Article 6(1)(f). You choose whether to send anything at all.
- Security, integrity, compatibility, and abuse prevention: our legitimate interests under Article 6(1)(f).
- Required transaction and dispute records: legal obligations under Article 6(1)(c), where applicable.
5. Your Privacy Choices
PilatesScroll asks separately about cloud workout backup, optional Analytics, and optional Crashlytics. Analytics and Crashlytics are off by default. You can change these choices in Settings > Privacy & Data.
We use one consistent threshold: users must confirm they are at least 16 before cloud workout processing or optional Firebase telemetry is enabled. We do not collect a birth date. Users who do not confirm 16+ can continue with local-only workout features.
Withdrawing consent stops future optional processing. Withdrawal does not affect processing that was lawful before withdrawal. Turning off cloud backup deletes the cloud account and synced copy while preserving workout progress on the current device.
Sending feedback is a one-off action rather than a standing setting, so there is no switch to turn off: if you never submit the form, nothing is ever sent.
6. Service Providers and Sharing
We do not sell personal information. We disclose information only to processors and platform providers needed for the purposes above, including:
- Google Firebase: Authentication, Firestore, Analytics, Crashlytics, Messaging, Remote Config, App Check, and Installations — Firebase privacy information.
- RevenueCat: subscription and entitlement management — RevenueCat Privacy Policy.
- Apple: App Store, Sign in with Apple, Vision, and Screen Time services — Apple Privacy Policy.
- Google: Google Play, Google Sign-In, and ML Kit — Google Privacy Policy.
- GitHub, Inc.: hosting of the private issue repository that receives in-app feedback and feature requests, if you send one — GitHub Privacy Statement.
We may also disclose information when required by law, to protect users and the service, or as part of a business transaction subject to appropriate safeguards.
7. International Transfers
Kaironos is based in the United States. Our providers may process information in the United States and other countries. Where required, transfers rely on contractual safeguards, adequacy decisions, or another lawful transfer mechanism provided by the relevant service provider.
8. Retention
- Local app data remains until you clear app data, uninstall the app, or the operating system removes it.
- Cloud workout data and the consent receipt remain while cloud backup is active and are deleted on withdrawal or account deletion.
- Recent per-day workout history is limited to approximately 60 days; aggregate totals remain while the cloud account is active.
- Optional Firebase Analytics is configured for two-month retention. Crashlytics reports are generally retained for 90 days.
- After Firebase Installation deletion, Firebase states that installation-linked information may take up to 180 days to leave live and backup systems.
- A feedback or feature-request ticket is kept while we work on it and then for no longer than 24 months, unless you ask us to remove it sooner or a documented legal or support need requires longer. When feedback intake is enabled, its hashed anti-spam rate-limit record expires after the 24-hour window and is scheduled for automatic deletion by Firestore's TTL service. TTL deletion may occur later.
- Stores, RevenueCat, and Kaironos may retain transaction, tax, fraud-prevention, security, support, or dispute records when required by law or needed to complete a transaction.
9. Your Rights and Controls
Settings > Privacy & Data provides a machine-readable JSON export, consent controls, and cloud-account deletion. Cloud deletion does not cancel a store subscription, and local workout progress remains on the device.
Depending on where you live, you may request access, correction, deletion, restriction, portability, or object to eligible processing. You may also withdraw consent and complain to your local data-protection authority.
For a specific optional Analytics erasure, use the Privacy & Data export. When available, it lists current and prior app-instance identifiers needed to cover data collected before a consent change. Send only those identifiers, not the full export or any sign-in token. See Data & Account Deletion for in-app and web-request instructions.
Feedback tickets are stored without any account identifier, so deleting an account cannot find or remove them. Ask us directly if you want a message you sent removed.
10. Children
PilatesScroll is not directed to children. We do not enable cloud workout processing, optional Analytics, or optional Crashlytics for users who do not confirm they are at least 16. They may use local-only features subject to app-store rules and appropriate parent or guardian involvement.
11. Ads, Tracking, and Automated Decisions
PilatesScroll does not display third-party ads, sell personal information, use the advertising identifier, or track you across other companies' apps or websites. We do not make legal or similarly significant decisions about you using automated processing.
12. Security
We use per-account access controls on the optional cloud service, encryption in transit, App Check on the app's server requests, on-device camera processing, and data minimization designed to protect information. No transmission or storage system can be guaranteed completely secure.
13. Health Disclaimer
PilatesScroll is a fitness and wellness app, not a medical device. It does not read from or write to Apple Health or Google Fit and does not collect clinical medical records.
14. Changes to This Policy
We may update this policy when the product or law changes. We will revise the date above and, for a material change affecting consent, require an in-app review before optional processing resumes.
15. Contact
- Controller: Kaironos LLC, United States
- Privacy: privacy@kaironosapps.com
- Support: support@kaironosapps.com