Privacy Policy
Last updated: July 20, 2026
1. Who we are
Basalt is published by OTIA LTD. For any question: contact@basaltlab.app.
2. Data we collect
2.1 Data you provide
- Profile: first name, sex, age, height, weight, goal, level, frequency, equipment
- Account: email (Apple, Google, or direct sign-up)
- Sessions: exercises, sets (weight, reps, duration, distance, RPE), notes
- Photos (optional, only the ones you choose): profile picture, workout memory photo, photo illustrating a custom exercise. Taken with the camera or picked from your photo library, they are only used to display that content in the app — never to identify you, never analyzed, never shared
2.2 Data collected automatically
- Apple Health (only with your permission): sex, age, height, weight, heart rate during sessions
- Apple/Google identifier: for authentication (never your password)
- Crash diagnostics (Sentry): crash and error reports to fix bugs, with no personal data (PII disabled), attached to your pseudonymized Supabase ID
2.3 What we do NOT collect
- No advertising tracking (IDFA)
- No third-party analytics (Google Analytics, Facebook Pixel, etc.)
- No location
- No contacts, no microphone
- No access to your photo library beyond the photos you select yourself
3. Why we use this data
- To let you use the app (log your sessions, track your progress)
- Sync your profile and sessions across your devices
- Compute your stats (records, plateau detection, 1RM projections)
No data is ever sold or shared for marketing purposes.
4. Where your data is stored
- Locally on your iPhone (SwiftData)
- On Supabase (servers in Europe, EU): cloud backup + cross-device sync
- Your photos on Supabase Storage (servers in Europe, EU): private storage areas, partitioned per account — only you can access them, through temporary signed links
- Apple Health stays on your device and iCloud under Apple's control
All communications with our servers are encrypted (TLS).
5. Your rights (GDPR)
You have the right to:
- Access your data: from the Profile screen
- Modify your data: from the Profile screen
- Delete your account and all your data: Profile → "Delete my account" (irreversible, full cascade on our servers)
- Export your data: send us an email at contact@basaltlab.app
For any GDPR question: contact@basaltlab.app.
6. Retention
- As long as your account exists: your data stays stored
- A photo you remove yourself (profile picture, workout photo, exercise photo) is erased from our servers
- On account deletion: immediate erasure of all your data on our side, photos included
- Supabase backups: purged within 30 days after deletion
7. Minors
Basalt is not intended for children under 13. If you are under 13, do not use the app.
8. Changes
This policy may evolve. Any significant change will be notified to you in the app.
9. Subprocessors
- Supabase (Postgres, auth, storage) — Europe (EU)
- Apple (Sign in with Apple, Apple Health) — subject to Apple Privacy Policy
- Google (Sign in with Google) — subject to Google Privacy Policy
- RevenueCat (subscription management) — pseudonymized via your Supabase ID
- Sentry (crash reporting) — Germany (EU); PII disabled, pseudonymized via your Supabase ID