Privacy Policy
Last updated: 12 August 2026 · Applies to the WakeStrong mobile app and this website.
Contents
- Who is responsible
- What we collect
- Camera and photos
- Why we use it, and our legal basis
- What other users can see
- Who we share it with
- International transfers
- How long we keep it
- Your rights
- Deleting your account
- Tracking, ads and selling data
- Children
- Security
- This website
- Changes to this policy
- Contact
1. Who is responsible
WakeStrong (“WakeStrong”, “we”, “us”) is an independently developed and operated iOS app. The data controller for the personal data described here is Oscar Márquez, an independent developer established in Spain.
Contact for anything privacy-related: bagre.armario0n@icloud.com. We are established in Spain, so the EU General Data Protection Regulation (GDPR) and Spanish data protection law apply. We have not appointed a Data Protection Officer, as we are not required to.
2. What we collect
The app works almost entirely on your device. Personal data only reaches a server once you subscribe and sign in with Apple, and even then only for the account and the leaderboard.
| Data | Where it lives | Notes |
|---|---|---|
| Your first name or nickname, and the answers you give during onboarding (wake-up habits, age range, sex, energy levels, push-up goal) | Your device only | Used to personalise the plan. Your name is also used as your leaderboard display name once you create an account. |
| Alarms, alarm days, chosen alarm sound, app settings | Your device only | Never uploaded. |
| Progress photos | Your device only | Stored in the app's private storage. Never uploaded to us or to anyone else. |
| Camera images while counting push-ups | Processed live on your device | Not recorded, not stored, not transmitted. See section 3. |
| Account identifier and email from Sign in with Apple, and your display name | Our server (Supabase) | Only after you subscribe and sign in. If you choose “Hide My Email”, we only ever see Apple's private relay address. |
| Points (RP), current streak, best streak, and one record per completed day (date, whether it was on time, late or failed, and how many push-ups) | Our server (Supabase) | Powers the leaderboard, ranks and syncing between reinstalls. |
| Usage events: app opened, onboarding screens viewed, onboarding completed, paywall shown, trial started, features used | Analytics provider (PostHog, EU servers) | Tied to a random identifier created on your device, not to your name or email. |
| Crash and error reports: error message, stack trace, app version, device model, OS version | Sentry and PostHog | Used to fix bugs. May incidentally include technical details of what you were doing when it crashed. |
| Subscription status: which product you bought, whether the trial or subscription is active, purchase and renewal dates, store country | RevenueCat and Apple | We never receive your card number or billing address — Apple handles payment. |
| Technical data sent with any network request: IP address, approximate country, device and OS type, app version, language | Our providers | Standard for any connected app; used for delivery, security and abuse prevention. |
We do not collect contacts, precise location, health records, HealthKit data, microphone audio, browsing history, or advertising identifiers.
3. Camera and photos
Push-up counting. When an alarm is running, the app opens the front camera and analyses the video stream in real time on your iPhone to count repetitions. Those frames are held in memory for the fraction of a second needed to analyse them and are then discarded. They are never saved to disk, never sent to us and never sent to a third party. No cloud service sees your camera.
Progress photos. If you take a weekly progress photo, the image is copied into the app's private folder on your device. It stays there. It is not backed up to our servers, not shared, and not visible to anyone else. You can delete any photo from inside the app, and deleting the app deletes all of them permanently — export anything you want to keep to your Photos library first.
You control camera access in Settings → WakeStrong → Camera. Without it, the app cannot verify push-ups and the alarm can't be completed the intended way.
4. Why we use it, and our legal basis
- To run the app you asked for — alarms, push-up verification, streaks, points, ranks, the leaderboard, syncing and restoring your progress, and managing your subscription. Legal basis: performance of a contract (GDPR Art. 6(1)(b)).
- To keep it working and improve it — analytics on how features and onboarding are used, and crash reports. Legal basis: our legitimate interest (Art. 6(1)(f)) in a stable, understandable product. You can object at any time (section 9) and we will delete your analytics profile.
- To answer you — when you email support, we use your message and address to reply. Legal basis: legitimate interest, or contract if it concerns your subscription.
- To prevent abuse — detecting fake accounts, manipulated scores or attacks on our servers. Legal basis: legitimate interest in a fair leaderboard and a secure service.
- To comply with the law — tax, accounting and responding to lawful requests. Legal basis: legal obligation (Art. 6(1)(c)).
Where we ask for a permission (camera, notifications, alarms), you can withdraw it at any time in iOS Settings.
5. What other users can see
The leaderboard is the point of the app, so some of your data is visible to other signed-in users: your display name, your points, your streak and your position. Nothing else — not your email, not your alarms, not your photos, not which days you missed. If you'd rather not be identifiable, use a nickname: you can ask us to change your display name at any time.
6. Who we share it with
We don't sell or rent personal data. We share it only with the service providers that make the app work, each acting on our instructions as a processor (or, where indicated, as an independent controller for its own purposes):
- Apple — Sign in with Apple, App Store purchases, alarms and notifications delivery. Apple acts as an independent controller for payments. Apple Privacy Policy.
- Supabase — hosts our database and authentication (profile, points, streak, completed days). Supabase Privacy Policy.
- RevenueCat — manages subscription status and entitlements. RevenueCat Privacy Policy.
- PostHog — product analytics and error tracking, on its European servers. PostHog Privacy Policy.
- Sentry — crash and error diagnostics. Sentry Privacy Policy.
We may also disclose data if the law requires it, to establish or defend legal claims, or if the app is ever transferred to another owner — in which case you'll be told before your data moves.
7. International transfers
Some of the providers above are based in, or use infrastructure in, the United States. Where personal data leaves the European Economic Area, the transfer is covered by the European Commission's Standard Contractual Clauses and/or the EU–US Data Privacy Framework, together with the additional safeguards those providers commit to in their data processing agreements. You can ask us for details.
8. How long we keep it
- Account, profile, points and completed days: for as long as your account exists. When you delete it, we remove them and they are gone from backups within 30 days.
- Analytics and crash events: up to 24 months, then deleted or aggregated so they no longer identify a device.
- Subscription records: for as long as required by tax and accounting law (generally up to 6 years, and 4 years for tax purposes in Spain), through Apple and RevenueCat.
- Support emails: up to 24 months after the conversation ends.
- Everything stored only on your device: until you delete it in the app or uninstall the app.
9. Your rights
Under the GDPR you can ask us to:
- Access the personal data we hold about you, and get a copy.
- Correct anything inaccurate — including your display name.
- Delete your data (section 10).
- Restrict or object to processing based on legitimate interest, including analytics.
- Receive your data in a portable, machine-readable format.
- Withdraw consent where processing is based on it, without affecting what came before.
Write to bagre.armario0n@icloud.com from the address linked to your account. We answer within one month, free of charge. If we need to verify it's really you, we'll ask — we won't hand your data to someone else.
If you think we've handled your data badly, please tell us first; you also have the right to complain to your data protection authority. In Spain that is the Agencia Española de Protección de Datos (aepd.es).
10. Deleting your account
You delete your account from inside the app, at any time: Profile → Delete account. That erases your profile, display name, points, streak and completed-day history from our servers straight away, and the same action wipes the alarms, settings and progress photos held on your iPhone. It cannot be undone.
If you have uninstalled the app, reinstall it and sign in to delete the account. Your right to have us erase your data on request is unaffected and is covered in section 9.
Data held only on your iPhone is deleted by deleting the app. Deleting your account does not cancel your subscription: cancel that in Settings → your name → Subscriptions, or at apps.apple.com/account/subscriptions.
11. Tracking, ads and selling data
WakeStrong shows no advertising. We do not use advertising identifiers (IDFA), we do not build advertising profiles, and we do not track you across apps and websites owned by other companies — which is why the app never asks for App Tracking Transparency permission.
We do not sell personal data, and we do not “sell” or “share” it as those terms are defined by California privacy law. Analytics are used only to understand how WakeStrong itself is used.
12. Children
WakeStrong is not intended for children under 13, and we do not knowingly collect their personal data. In parts of the EEA the minimum age for consent to online services is up to 16 — where that applies, use of the app needs a parent or guardian's authorisation. If you believe a child has given us data, write to us and we'll delete it.
13. Security
Traffic between the app and our servers travels over TLS. Our database enforces row-level security, so an account can only read and write its own records — the leaderboard exposes only the fields listed in section 5. Access to production systems is limited to the developer and protected by two-factor authentication. No system is perfectly secure, but if a breach ever affects your personal data and poses a risk to you, we will notify you and the relevant authority as the law requires.
14. This website
These pages are static, set no cookies of their own and load nothing from a third party: the fonts are served from this same site, so no outside company sees your IP address when you read them. We use no web analytics here. Our host keeps standard server logs for security and reliability.
15. Changes to this policy
If we change how we handle data, we'll update this page and the date at the top. For changes that matter to you, we'll flag it in the app or by email before they take effect. Previous versions are available on request.
16. Contact
Privacy questions, requests and complaints: bagre.armario0n@icloud.com. General help lives on the support page.