Privacy Policy
Strongcy (“we”, “us”) is a fragmented-time movement decision and recording assistant for iOS. This Privacy Policy explains what stays on your device, what is sent to our servers when you choose optional account features, how we use that information, and the controls available to you.
By using Strongcy, you acknowledge this policy. If you do not agree, please use the app only in local mode without signing in, or stop using the service.
1. Who is responsible
The operator of Strongcy can be contacted at woshiwusa@gmail.com. For privacy requests, use the subject line “Strongcy Privacy”.
2. Data that stays on your device
By default, Strongcy is local-first. The following are stored and processed on your device unless you explicitly enable a cloud feature that requires them:
- Routines / scenes you create or install, personal movement blocks, order, notes, and targets.
- Daily progress, check-ins, streaks, and local analytics charts.
- App preferences, reminder settings, and membership presentation state cached from Apple.
- Apple Health / HealthKit samples (for example steps, active energy, resting heart rate) when you grant access. These samples are read on-device for insights you choose to view. Strongcy does not upload raw HealthKit samples to our servers and does not use health or fitness data for advertising, data brokerage, or cross-app tracking.
3. Data we receive on our servers
We receive server-side data only when you use account, purchase, sync, support, or optional analytics features.
3.1 Account (Sign in with Apple)
- Apple user identifier (subject).
- Display name and email address only when Apple provides them (including Apple’s private relay email).
- Session tokens we issue after a successful sign-in (access and refresh tokens).
We never receive your Apple ID password.
3.2 Cloud sync (Plus / Pro)
If your membership includes cloud sync and you are signed in, we store:
- Scene / routine structure and configuration.
- Personal block-library templates and their tracking configuration.
- Completed check-ins (counts, targets, durations, timestamps, idempotency keys).
- Deletion / tombstone markers needed to keep devices consistent.
Sync scope depends on tier (for example Plus may sync a limited history window; Pro may sync full history). Exact limits are shown in the app.
3.3 Purchases and subscriptions
- Apple-signed transaction and renewal information needed to unlock Plus or Pro (product identifier, transaction identifiers, status, expiration / renewal dates, and related App Store Server Notification payloads).
Strongcy never receives your payment card number, bank account, or full billing address. Payment is processed solely by Apple.
3.4 Optional product analytics
Product analytics is off by default. If you enable it in Settings, we may receive:
- Whitelisted interaction events (for example app open, scene installed, activity completed, paywall viewed, purchase funnel steps, sync success/failure).
- App version, iOS version, locale, and a random installation identifier.
The installation identifier is cryptographically pseudonymized on the server before storage. When signed in, product events may be linked to your account identifier. We also process the request IP address and infer an approximate country or region for product analysis. Analytics does not include HealthKit sample values, routine notes, custom titles, email addresses, precise location, or advertising identifiers (IDFA). You can turn this optional analysis off in Settings.
3.5 Support communications
If you use Settings → Send Feedback or email us, we receive the address and content you choose to send, plus any app/iOS version details included in the draft.
3.6 Technical and security logs
Our servers generate operational logs and metrics for reliability and abuse prevention (for example request identifiers, route, status code, latency, and whether a request was authenticated). We design application logs to avoid writing raw tokens, request bodies, or unnecessary personal identifiers.
4. How we use data
- Provide authentication, subscription entitlement checks, and cloud sync.
- Process account deletion and restore-purchase association.
- Respond to support requests and protect the service against fraud or abuse.
- When you opt in, improve product features using aggregated or pseudonymized analytics.
- Comply with legal obligations and App Store requirements.
We do not sell personal data. We do not serve third-party behavioral advertising in the app. We do not track you across other companies’ apps or websites for advertising.
5. Legal bases (where applicable)
If data-protection laws such as the GDPR apply to you, we generally rely on:
- Contract / requested service: account, sync, and subscription features you ask us to provide.
- Consent: HealthKit access on device; optional product analytics; certain notifications.
- Legitimate interests: security, fraud prevention, service reliability, and aggregated product improvement consistent with your expectations.
- Legal obligation: retaining limited records when required by law.
6. Sharing and processors
- Apple: Sign in with Apple, In-App Purchase, App Store Server Notifications, and HealthKit are operated by Apple under Apple’s terms and privacy policy.
- Infrastructure providers: we use hosting and related infrastructure only to run the Strongcy API and store account/sync data on our behalf.
- Approximate region lookup: for optional product analytics, when our infrastructure does not supply country information, the server sends the connection IP address to ipwho.is to obtain a country and region. This lookup does not send your account identifier, authentication tokens, or activity records.
We do not share your personal data with third parties for their own marketing. We may disclose information if required by law, legal process, or to protect users and the service from serious harm or abuse.
7. International processing
Your information may be processed on servers located outside your country or region. Where required, we use appropriate technical and contractual safeguards. Apple may also process authentication and purchase data according to Apple’s practices.
8. Retention
| Data | Retention |
|---|---|
| On-device local data | Until you clear it or remove the app |
| Account + cloud sync data | While the account exists; deleted when you delete the account (subject to brief backup/processing windows) |
| Product analytics events | No more than 24 months |
| Subscription / security records | As needed for entitlement integrity, dispute handling, abuse prevention, or legal requirements |
9. Security
We use HTTPS in production, short-lived access tokens, protected local credential storage on device, server-side authorization checks, analytics pseudonymization, and least-privilege operational access. No method of electronic storage or transmission is completely secure.
10. Your choices and rights
- Use core local features without creating an account.
- Decline or later revoke HealthKit access in iOS Settings.
- Keep product analytics disabled, or turn it off after enabling it.
- Export or clear local data from Settings (where provided).
- Sign out, restore purchases after signing in, or permanently delete your account and associated cloud data from My Profile.
Depending on your location, you may also have rights to access, correct, delete, restrict, port, or object to certain processing, and to withdraw consent. Contact woshiwusa@gmail.com. You may also have the right to lodge a complaint with a supervisory authority.
If California privacy laws apply, we do not “sell” or “share” personal information as those terms are commonly defined for cross-context behavioral advertising, and we do not use sensitive personal information to infer characteristics for advertising.
11. Children
Strongcy is not directed to children under 13 (or the higher minimum age required in your country). We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact us and we will take appropriate steps.
12. Third-party links and platforms
The app may link to Apple subscription management or other system sheets. Those experiences are governed by Apple’s policies, not this Privacy Policy.
13. Changes
We may update this policy as Strongcy evolves. We will revise the effective / updated date above. Material changes may also be highlighted in the app or on this page. Continued use after an update means you accept the revised policy to the extent permitted by law.
14. Contact
Privacy questions and requests: woshiwusa@gmail.com
Related pages: Terms of Use · Support