Privacy Policy
Last updated: 9 July 2026. This is a plain-English draft — have it reviewed by counsel before public launch.
What we collect
Every item below matches exactly what we declare in the Google Play Data Safety form for this app — nothing is collected that isn't listed here.
| Data | Why | Required? |
|---|---|---|
| Email address | Account creation & sign-in | Required |
| App activity (quests, habits, streaks, level/rank) | Runs the core app functionality | Required |
| Sleep hours (self-reported) | Energy system feature | Optional |
| Workouts / food & macros (self-reported) | Fuel-tracking feature | Optional |
| Body profile (age, height, weight, goal weight, biological sex, self-reported) | Personalizing the macro/nutrition calculator | Optional |
| Purchase history | Unlocking the subscription tier you paid for | Only if you subscribe |
| Push-notification device token | Sending the reminders you opt into | Only if you enable notifications |
| Crash/diagnostic report (error message, stack trace, page, app version) | Fixing bugs | Only if you click "Send report" — see below |
Sleep and fitness/food entries are self-reported by you — we do not read data from device health sensors, Health Connect, Apple Health, or any third-party fitness API.
How we use it
Only to run Ascend for you: compute your levels and stats, send the reminders you opt into, process your subscription, and keep the service working. We do not use your data for advertising and do not sell it. We do not use any third-party analytics or crash-reporting SDK — see the next section for the one first-party mechanism we do have.
Crash & diagnostic reports
If the app hits an error, the details (error message, stack trace, the page it happened on, and app version) are held on your device only. The next time you open the app, a popup asks whether to send that report — nothing is transmitted unless you click "Send report." Dismissing discards it. Reports go to our own server, never a third-party crash-reporting vendor, and are used only to find and fix bugs. We use this to measure how often crashes happen so we can prioritize fixes.
Who we share it with
Nobody, except the processors that have to touch it to do their job — and only the minimum needed:
- Apple, Google Play Billing, and Stripe — process your subscription payment. We receive a purchase confirmation and your subscription status; we never see or store your full card number.
- RevenueCat — validates and manages mobile subscription purchases on our behalf (a middleware layer between the app and Apple/Google's billing systems). It receives your app account ID, product/plan ID, and transaction ID — never payment details.
- Fly.io — hosts the application and database that store your account data.
- Push notification delivery (device platform) — delivers the reminder notifications you opt into.
These are service providers acting on our instructions (data processing), not third parties we share data with for their own purposes. None of them may use your data for advertising or resell it.
How long we keep it
We keep your account data for as long as your account is active. Deleting your account (in-app or via the account deletion page) immediately schedules it for removal and logs you out — your data is then permanently deleted within 30 days. During that 30-day grace period your data is left untouched, solely so that logging back in reinstates your account exactly as it was; after 30 days, deletion is final and cannot be reversed. We also keep routine backups for disaster recovery only — they are not used operationally and are overwritten on our normal backup rotation; they are never restored except to recover from data loss.
Your rights
- Delete everything: Settings → Danger Zone schedules your account and all data for permanent deletion within 30 days, in-app. Log back in during that window to reinstate. See how to delete your account.
- Access / export: email us and we'll provide a copy of the data tied to your account.
- Correct: most fields are editable directly in the app; email us for anything that isn't.
- You can turn off notifications any time in your device settings.
If you're in the EU/EEA/UK, these are your rights under GDPR (access, rectification, erasure, portability, and objection to processing based on our legitimate interest in running the app). If you're a California resident, you have the same practical rights under the CCPA — and since we don't sell personal information, there's nothing to opt out of. We don't discriminate against anyone for exercising these rights.
Where your data is processed
Our hosting and payment processors operate in the United States and other countries where they maintain infrastructure. If you're outside the US, your data may be processed there under the safeguards those providers maintain for international transfers.
Security
All traffic between your device and our servers is encrypted in transit (HTTPS/TLS). Passwords are stored as salted hashes, never in plain text. No online service can guarantee perfect security, but we don't cut corners on the basics.
Children's privacy
Ascend is intended for users 18 and older and is not directed at children. We do not knowingly collect personal information from anyone under 13 (or the relevant age of digital consent in your region). If you believe a child has provided us data, contact us and we'll delete it.
Not medical advice
Ascend is a motivation and organization tool, not a medical or dietary service. You set your own goals; we don't diagnose, treat, or prescribe. Consult a professional for health decisions.
Changes to this policy
If we make a material change to how we handle your data, we'll post the update here and change the "Last updated" date above; significant changes will also be announced in-app.
Contact
Questions or data requests: privacy@joinascendapp.com