In this policy, “we”, “us”, and “Gravus” mean the operator of the Gravus app. The public contact is support@getgravus.com.

This policy is for the Gravus iOS app (com.gravus.app) and the pages on getgravus.com. It is written for the v1.0 App Store binary: local-first logging, optional Apple Health (read-only), and subscriptions via Apple / RevenueCat. It is not a generic template.


1. Plain-language summary


2. Who is responsible

The operator of Gravus is the controller of personal data processed through Gravus, except:

If you are in the EEA, UK, or Switzerland, you may contact us at support@getgravus.com. We do not currently appoint an EU/UK representative; we will update this policy if that changes.


3. What we collect

3.1 Data you enter (stored on device)

Collected during onboarding and while you use the app. Stored in SQLite on the device (gravus.db). Not uploaded to Gravus servers in v1.0.

CategoryExamples
IdentityFirst name, last name
ContactEmail address
Profile for estimatesDate of birth / age, sex, height, activity level, timezone, preferred units, week-start, weekly session target, training types
GoalsCut / bulk / recomp, start and target weight, pace, notes, body-fat settings
Training logSessions, exercises, sets (reps, weight, optional RPE), duration, distance, notes
Body metrics you logBody weight, body-fat % and method (tape / calipers / DEXA), tape or skinfold measurements
App settingsUnits, Health permission flags, onboarding progress

3.2 Apple Health (optional, read-only, on-device cache)

Only if you tap Connect and grant categories in the system sheet. We request read access for:

We do not request write access. We do not use HealthKit as a marketing source.

Cached copies live in on-device tables so Calendar and Progress still work offline. Revoking access in the Health app stops new reads; existing cache remains until you delete the app or clear local data.

3.3 Email we send off-device

The email from onboarding may be sent to:

3.4 Purchases and identifiers (Apple + RevenueCat)

DataWho holds itWhy
Apple ID, payment method, billing addressAppleCharging and tax
Product ID, trial / subscription status, original transaction IDApple and RevenueCatEntitlement (premium), restore purchases
RevenueCat anonymous App User IDRevenueCat + on deviceTie the receipt to this installation

We do not store card numbers.

3.5 Data we do not collect in v1.0

If we add analytics, crash reporting, iCloud backup, or cloud sync, we will update this policy and the App Store privacy labels before that binary ships.

3.6 Website

getgravus.com legal pages are static. We do not set advertising cookies. The host may process standard server logs (IP address, user agent) as needed to serve the page and protect the site.


For users in the EEA/UK, GDPR requires a legal basis. Health, sex, and body-composition data can be special-category / health data (GDPR Art. 9). We only process that data to provide the fitness-tracking service you asked for.

PurposeDataBasis (GDPR)
Provide the app: calendar, goals, progress, estimatesOn-device profile and logsContract (Art. 6(1)(b)); health data: explicit consent (Art. 9(2)(a)) by entering it and using the feature
Read Apple Health to enrich calories / workoutsHealthKit samples + on-device cacheExplicit consent via the Health permission sheet (Art. 6(1)(a) + Art. 9(2)(a)); you can refuse and still log manually
Start trial, subscribe, restore, show statusEmail, App User ID, receiptsContract (Art. 6(1)(b)); Apple’s processing under Apple’s terms
Support and abuse / fraud on subscriptionsEmail, app version, purchase statusLegitimate interests (Art. 6(1)(f)) and/or contract
Legal obligations (tax, accounting on our side; consumer law)Limited billing metadata we may receiveLegal obligation (Art. 6(1)(c))

We do not use Health, fitness, or body data for third-party advertising, our own advertising, data mining unrelated to the app, or sale.

California (CCPA/CPRA): we do not sell or share (for cross-context behavioral advertising) personal information. Sensitive personal information (health, precise body metrics) is used only to provide Gravus on device.


5. Apple Health and App Store health rules

Gravus is a fitness tracking and education app, not a medical device and not a source of diagnosis or treatment. See the Health & Fitness Disclaimer.

Consistent with Apple’s HealthKit and Guideline 5.1.3 / 5.1.7:

You control sharing in iPhone Settings → Health → Data Access & Devices → Gravus (or Account → Data sources → Manage).


6. Who we share with

We do not sell your information. Sharing in v1.0 is limited to:

RecipientRoleWhat they get
ApplePayment platform / OSPurchases, Apple ID; Health store if you use Health
RevenueCat, Inc.Processor for subscriptionsAnonymous user ID, receipt validation, optional email attribute. Not workouts, weight, or Health samples
Email provider / hostInbox for support@getgravus.comMessages you send
Hosting for getgravus.comWebsiteServer logs as above

No analytics vendor in the v1.0 app binary.

If we are required by law to disclose data, we will do so only to the extent required.

International transfers: RevenueCat and Apple may process data in the United States. Where GDPR applies, transfers rely on the recipient’s stated mechanisms (e.g. Standard Contractual Clauses / Data Privacy Framework as they publish). Using Gravus means this processing is necessary to provide IAP.


7. Retention

DataRetention
On-device SQLite (profile, logs, Health cache)Until you delete the app or wipe the device. v1.0 has no cloud copy, so uninstall is deletion of the log.
RevenueCat subscriber recordFor the life of the subscription relationship plus a short period needed for restore, refunds, tax, and dispute handling (typically aligned with Apple’s receipt lifetime). Email attribute is removed on request.
Support emailsAs long as needed to resolve the ticket, then deleted or minimized; we may keep a brief record if required for legal claims.
Website logsPer the host’s default (typically days to weeks).

We do not keep a Gravus-side copy of your workout history in v1.0.


8. Your rights and how to delete data

On-device data

Delete Gravus from the iPhone (or offload and delete app data). That removes gravus.db. Reinstalling starts empty.

There is no Gravus account in v1.0, so there is no in-app “delete account” control. Guideline 5.1.1(v) account deletion will apply when sign-in ships (planned v2).

Email and subscription records

Email support@getgravus.com from the address you used in the app and ask us to:

  1. Remove your email from RevenueCat subscriber attributes, and
  2. Delete support threads we hold.

We will confirm. Apple still holds the purchase record on your Apple ID; cancel or request refunds through Apple. Uninstalling does not cancel a subscription.

Access / correction / portability (GDPR and similar laws)

Most data lives only on your device - you already have it. For email or subscriber attributes we hold, email support@getgravus.com. We may need to verify that you control that address. v1.0 has no in-app export; a local export is planned after launch.

You may lodge a complaint with your local data protection authority.

California

You may request to know, delete, or correct personal information we hold off-device (email / support / RevenueCat attributes) via support@getgravus.com. We will not discriminate against you for exercising these rights. We do not sell or share PI as defined by CPRA.


9. Children

Gravus is not directed at children under 13 (COPPA) and is intended for users 16 or older.

We do not knowingly collect personal information from children under 13. If you believe we have, contact support@getgravus.com and we will delete off-device data we hold.

Calorie targets and body-composition estimates are inappropriate as a product for younger children. Parents should not set up Gravus for a child.


10. Security

Treat the phone as the source of truth. Back up the device with Apple’s tools if you want a copy; v1.0 does not offer Gravus iCloud backup.


11. Automated decisions

Gravus calculates calorie and protein estimates from the profile and goal you enter. These are planning aids, not decisions that produce legal or similarly significant effects. They are not medical advice.


12. Changes

We will update this page and the “Last updated” date when practices change. Material changes (new vendors, Health write access, cloud sync, tracking) will also be reflected in App Store privacy labels before that version is released. Continued use after an update means you accept the revised policy, except where the law requires a new consent (for example a new HealthKit type).


13. Contact

Privacy and data requests: support@getgravus.com

App Store listing and in-app About must use this same URL: https://getgravus.com/privacy