ARISE — WORKOUT RPG
Privacy Policy
Effective 15 September 2026
Your training history is personal. Here is what Arise processes, what stays on your device, and how you can manage or delete your information.
1. Who we are and what this covers
Paul Smith operates Arise — Workout RPG (Arise), its website at arise.paulsmith.codes and its support service. In this policy, “we” means Paul Smith and “you” means a person using those services. For privacy questions or requests, email paulrsmithjnr@gmail.com.
This policy explains information processed by the iOS and Android app, our backend, our website and support. Availability of individual features may vary by device, app version, permissions and subscription. It does not replace the privacy policies of Apple, Google or another service you use independently.
2. Account, training and purchase information
- Account and profile: email address, name, account identifier and sign-in provider information. Google sign-in may supply a profile-picture URL. Authentication is handled through Firebase Authentication; social sign-in does not give us your Apple or Google password.
- Planning information: age, gender, height, current and target weight, goals, experience, activity, equipment, availability, exercise preferences and limitations you enter. We use this to create and personalize your training experience.
- Workout and progression records: plans and edits, exercises, sets, repetitions, weights, duration, distance, notes, dates, completion records, XP, ranks, challenges and related history. These support logging, recommendations, analytics shown to you, objectives and account recovery. Workout data is saved locally for offline use and synchronized to your account in Cloud Firestore.
- Purchases: products, transactions, purchase history, subscription status and entitlement identifiers are processed by Apple or Google, RevenueCat and our backend to provide paid access, restore purchases, validate eligibility and prevent duplicate or fraudulent use. We do not receive your full payment-card details.
- Support and community: information you send us, privacy/deletion requests, invite-only Guild membership, preset messages, reports and sharing choices. Avoid including unnecessary sensitive information in support messages, workout notes or shared content.
Core account and training information is linked to your account and needed for the corresponding features. Optional health permissions, measurement choices and notification permission are described below. Declining an optional permission does not itself remove subscription access.
3. Apple Health, Health Connect and daily goals
Health connections are optional and controlled separately by metric. Arise can read Steps and Sleep from Apple Health (HealthKit) or Android Health Connect, after your permission. It does not write steps or sleep. Optional hydration export can write water entries you record in Arise to your health service; Arise does not read hydration from that service. Arise does not request location tracking for these features.
Raw step and sleep samples are processed on your device. Exact daily step counts, sleep duration, hydration totals, health-source details and permission state stay on that device rather than being uploaded to Arise’s cloud. The optional adaptive step-goal feature uses local daily aggregates from up to 14 completed days to suggest a future target; it does not upload those readings.
Some health-related progress does sync: your authored daily-goal targets and categorical completion or excusal records, with account, date, timezone and timestamps, can be stored in Firestore so your objectives and earned progress survive recovery. These records can reveal that a health-related goal was completed, but do not contain the exact readings, partial totals or health provider. Profile/body measurements and workout measurements you enter are separate from this local-only health-service boundary and can sync as described in section 2.
We do not sell health data or use health-service readings for advertising, advertising measurement, data brokerage, insurance decisions or AI-model training. Exact health-service readings are not sent to our AI provider, product analytics, crash reports or push-notification payloads.
Use Profile → Health Data and your device’s Apple Health or Health Connect settings to manage access. You can use manual tracking where available. Turning off export or deleting Arise does not automatically erase entries already in Apple Health or Health Connect; manage those records in the relevant health service.
4. AI-assisted plans and challenges
When you request AI-assisted planning or a supported challenge, our backend sends selected training information to OpenAI’s API. This can include goals, training preferences, equipment, schedule, relevant limitations and summarized training evidence needed for the request, plus a pseudonymous safety identifier. Account email addresses and raw Apple Health/Health Connect samples are not included in the generation payload.
Generated results are checked by our backend and relevant plans or challenge records are saved to your account. They may still be unsuitable or incorrect; they are general fitness guidance, not professional medical advice.
We request generation without storing a retrievable response at the provider. This does not mean zero provider retention: OpenAI may retain API content for security, abuse prevention and legal obligations under its applicable terms. OpenAI states that API inputs and outputs are not used to train its models by default. See OpenAI’s business-data information. This policy is a disclosure, not a substitute for any separate permission required for a feature.
5. Technical data, analytics and advertising measurement
Firebase, Google Cloud and RevenueCat process technical information needed to operate and secure the service, such as account/app/installation identifiers, network information including IP addresses, approximate country, device and operating-system details, app version, access checks and service logs. Firebase App Check and platform integrity services help protect backend requests. This necessary operation is distinct from optional product analytics.
Optional measurement: Arise supports Firebase Analytics and advertising measurement on iOS and Android. Starting with version 1.0.0 build 23, both settings are enabled by default when there is no previously saved decision. Existing opt-outs remain off. Earlier builds start these settings off until you opt in. You can change either setting in Profile → Privacy & Data. Advertising measurement also requires App analytics to be enabled. Turning either setting off does not prevent training or purchases, subject to the usual subscription requirements.
With App analytics enabled, Google Analytics for Firebase receives an app-instance identifier, device/app information, interactions such as screens viewed and sessions, and supported in-app purchase and subscription events, including product identifiers, product names, prices and currency. It can derive approximate location from masked IP addresses; this is not GPS tracking. These records help us understand usage and improve the app. They are associated with an app installation; Arise does not set your account email or Firebase account ID as the Analytics user ID.
With Advertising measurement active, Google can also process permitted advertising identifiers and campaign-attribution information, alongside the relevant usage and purchase events, to measure whether advertising leads to app use or purchases. This can connect activity in Arise with advertising interactions on other apps or websites. In build 23 and later, iOS advertising-data sharing and advertising identifiers remain blocked until Apple’s tracking permission (ATT) is authorized, even if the in-app setting is on. Earlier builds also require ATT for access to the advertising identifier. Android does not display an equivalent native permission popup for these settings; in build 23 and later they take effect by default unless you have opted out. Advertising personalization remains off. Arise does not use session replay or display third-party advertisements.
The current builds do not send a separate server-verified first-payment advertising event. This does not prevent the store SDK’s purchase and subscription events from being collected while App analytics is enabled. Exact health values, questionnaire answers, workout contents and account email addresses are excluded from Arise’s measurement events.
Crash reporting: Firebase Crashlytics is enabled in the current store builds independently of your optional App analytics and Advertising measurement choices. It processes crash traces, diagnostic information, installation identifiers, and device, operating-system and app-version details to diagnose failures and improve reliability, not to measure advertising. Turning off optional measurement does not turn off Crashlytics, purchase verification, security checks or provider operational logs.
Turning off App analytics stops future optional Analytics collection on that device and also disables advertising measurement; turning off Advertising measurement alone leaves App analytics at its existing setting. You can also manage Apple’s tracking permission in iOS Settings. Choices are device-local and account-scoped, so review them on each device you use. Arise does not save its attempted measurement events while collection is off for later replay. Enabled defaults are not a record of an explicit consent decision, and this policy does not replace any separate consent required by applicable law. Opting out is not a request to delete records already sent; see section 9 for retention and deletion.
6. Notifications
If you enable notifications, Firebase Cloud Messaging and Apple’s push service process an installation token and delivery information. Our backend may store your timezone, reminder preferences, permission/consent records and notification delivery or interaction status to schedule training reminders, results, community updates and, where available and permitted, occasional subscription offers. An offer notification does not contain your health readings or a purchase commitment.
Use Arise’s notification settings for available categories, or your device’s notification settings to disable all Arise notifications. You may also contact us to withdraw permission for subscription-offer notifications. Notification permission and this policy do not replace any additional consent required by law or platform rules. Essential account or support responses may still be sent by email.
7. Website and support
Our site is hosted by Vercel. Hosting and security services process requests, including IP address, requested URL, device/browser information and operational logs. The marketing pages use Vercel Web Analytics and Speed Insights for aggregate traffic and performance statistics, such as page/referrer, approximate region, browser/device and page-load metrics. These tools do not use third-party tracking cookies or create cross-site advertising profiles.
We do not load those marketing analytics tools on our legal, support, account-deletion, authentication-action or share-link pages. Hosting/security processing still applies. Do not put sensitive information in website URLs.
Support and deletion email links open your email application. They do not submit a request until you send the email. Your email provider and our mailbox provider process the message, sender address, attachments and correspondence. We use these to respond, verify ownership where necessary and maintain an appropriate support record.
9. Retention, deletion and security
Account, workout and progression records are generally retained while your account exists so the service can preserve your history. Local health-observation history normally covers the current day and the previous 89 days. Water-entry revisions awaiting export reconciliation may remain longer. Device caches, provider operational records and backups have different lifecycles; not all information is erased at the same instant.
Previously sent Analytics and advertising-measurement records follow the applicable Google service settings and retention/deletion processes; switching off collection does not erase them. Firebase states that Crashlytics retains crash traces and associated installation identifiers for 90 days before starting removal from live and backup systems. This is a provider retention period, not a promise that an account-deletion request immediately removes every diagnostic record.
Deleting your Arise account does not automatically erase previously sent SDK Analytics or Crashlytics records. Some are identified by an app installation rather than your account email. Contact us to request access or deletion of retained measurement or diagnostic information; locating it may require additional information about the relevant installation. We will explain what can be located and deleted, any separate provider processing and any applicable retention exception. We do not promise that aggregated reports or independently retained store records can be traced back to and removed with an individual account.
Delete your account in Profile → Delete Account, or use our public account-deletion request page without reinstalling or signing into the app. We verify ownership before deleting an account. We aim to acknowledge email requests within two business days and complete verified requests within 30 days of receipt, or sooner where law requires; we will explain any permitted extension or information needed from you.
Deletion removes the account and associated Arise cloud plans, workouts, progression, preferences and owned sharing records, and removes or anonymizes related community records as described on the deletion page. Third-party deletion may require separate processing, including RevenueCat. Limited records may remain where needed for security, fraud prevention, deletion enforcement, disputes or legal obligations; backups may persist until their retention cycle ends. We restrict use of retained records to those purposes. Store transaction records and other people’s independently saved copies are not under our sole control.
Deleting your account does not cancel a store subscription. Cancel it separately in Apple or Google subscription settings. Deletion does not automatically erase your health-service history or an offline copy on another device.
We use encrypted network connections, account access controls and other reasonable safeguards. No storage or transmission method is completely secure. Protect your device and sign-in credentials; contact us if you suspect unauthorized access.
10. Your rights and international processing
Depending on where you live, you may have rights to access, correct, delete or receive a copy of your information; restrict or object to certain processing; withdraw consent; or complain to a data-protection authority. Email us to exercise these rights. We may need proportionate identity verification and will explain applicable exceptions. You can also edit supported profile fields and change optional permissions in the app or device settings.
Where a legal basis is required, we process necessary account and service data to provide the service you request; use consent for optional processing where required; and rely on legitimate interests for proportionate security, reliability and support, or legal obligations where applicable. Health data receives the additional protections and permissions required by applicable law.
Our providers may process data outside your country, including in the United States, where privacy laws may differ. Where required, we use applicable provider contractual safeguards for international transfers. Contact us for information about safeguards or assistance with your rights. We will not deny statutory privacy rights simply because you make a request.
11. Young users
Arise is intended for people aged 13 and older, not children under 13. If you are below the age at which you can independently agree to the service or relevant data processing where you live, involve a parent or guardian and obtain their permission before using it. Fitness suggestions are not a substitute for age-appropriate professional guidance.
We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided information, contact us so we can investigate and remove it where appropriate. Minimum-age wording does not replace additional protections required for teenagers in your location.
12. Policy changes and contact
We may update this policy when the service or legal requirements change. The effective date above identifies this version. We will provide additional notice and request a new choice when a material change or new use requires it; posting a policy is not permission for unrelated new processing.
Contact Paul Smith at paulrsmithjnr@gmail.com, visit Arise Support, or read our Terms of Service.