Privacy Policy
Effective date: August 13, 2026
Alps App, Inc. ("we", "us") operates Alps (the "App"), a workout and fitness training application, and the website alpsapp.co (together, the "Services"). This policy explains what information we collect, how we use and share it, and the choices and rights you have.
Summary of the important bits (the full policy controls):
- We collect your account info, the workouts and fitness data you log, content you upload (photos, videos, PDFs, voice recordings), and chat messages you send to the in-app AI assistant.
- AI features send your content to third-party AI providers (OpenAI, Anthropic, Google) to generate responses and build workout programs. We do not allow these providers to use your content to train their models.
- Apple Health (HealthKit) syncing is off by default and opt-in. Health data is never used for advertising and never sold.
- We do not sell your personal information and we do not show ads.
- You can opt out of analytics and crash reporting in Settings, export your data, and delete your account from the App (permanently deleted after a 14-day grace period).
1. Information we collect
Information you provide
- Account information. Email address, name, and profile photo. If you sign in with Apple or Google, we receive your email and basic profile from them. If you sign in by email, we send a one-time code to your address.
- Fitness and workout data. Workout templates and programs you create or follow, logged sessions and sets (weights, reps, distance, duration, and similar metrics), personal records, fitness goals, schedules, and notes.
- Content you upload. Photos, videos, PDF documents (for example, a workout program you import), and voice recordings you make in the App. We automatically strip embedded metadata (such as EXIF location data) from images and documents before storing them.
- AI assistant conversations. Text, voice, and image messages you send to the in-app assistant, and the assistant's responses.
- Communications. Messages you send to support.
Information collected automatically
- Device and session data. When you sign in we record your IP address and device/browser user agent as part of your session, for security and abuse prevention. We store a push notification token for your device if you enable notifications, and your device platform (iOS/Android).
- Usage analytics (optional). With analytics enabled, we collect events about how you use the App (screens viewed, features used) via PostHog. We do not record your screen or capture keystrokes. You can turn this off in Settings → Privacy.
- Crash and error data (optional). With error tracking enabled, crash reports and diagnostic data (device model, OS version, error traces) are collected via Sentry. You can turn this off in Settings → Privacy.
- Server logs. Our servers keep operational logs (request metadata, errors) for security and debugging.
Information from Apple Health (opt-in)
If you enable Apple Health syncing (off by default), the App can read workouts and activity data from HealthKit to build your training history, and write your completed workouts back to Apple Health. Imported workouts are stored with your account so they appear across your devices.
We use Health data only to provide App features. We never use HealthKit data for advertising or marketing, never disclose it to data brokers, and never sell it. You can disable syncing at any time in Settings, and manage the App's Health permissions in iOS Settings → Health.
Information we do NOT collect
We do not collect precise location, contacts, or advertising identifiers, and the App contains no advertising SDKs. Calendar and reminders access, if you grant it, is used on-device to show and schedule your sessions.
2. How we use information
- Provide, sync, and maintain the Services (your data syncs across your devices).
- Power AI features: generate workout programs, parse imported documents, transcribe voice input, and respond in chat (see Section 3).
- Send transactional messages: sign-in codes, and push notifications you've enabled (e.g., scheduled workout reminders).
- Enable sharing and social features you choose to use (see Section 4).
- Secure the Services: authentication, abuse prevention, audit logging, debugging.
- Understand feature usage to improve the App (if analytics is enabled).
- Enforce our Terms of Service and comply with law.
- Track your AI usage against your plan's credit limits.
We do not use your information for third-party advertising, and we do not sell or share it for cross-context behavioral advertising.
3. AI features and your data
When you use AI features — the assistant chat, voice transcription, or importing a workout program from a photo or PDF — the relevant content (messages, images, document pages, audio) is sent to one or more third-party AI providers to generate the result: OpenAI, Anthropic, and Google. Which provider is used depends on the feature.
- These providers process your content on our behalf under API terms that prohibit using it to train their models.
- We use LangSmith for AI quality monitoring. Traces contain conversation text but uploaded media and binary content are redacted before export.
- AI outputs (for example, a generated workout program) are stored with your account like any other content you create.
- AI-generated content can be inaccurate. It is not medical, health, or professional coaching advice — see our Fitness & Medical Disclaimer.
4. Sharing features you control
The App has social features. What you share is visible to others according to settings you choose:
- Template visibility. Workout templates can be private (default), shared with your team, or public. Public templates are visible to other users along with your display name.
- Direct shares and collaborators. You can share templates or sessions with specific users, or add collaborators who can view or edit depending on the role you give them.
- Connections. If you connect with another user (friend, accountability partner, or follower), your connection settings control whether they can view your templates and/or sessions.
- Shared media. Media attached to shared content is accessible to recipients via time-limited links.
Content you make public or share may be viewed, copied, or re-shared by recipients. Deleting your account removes your content, but copies others made while it was shared may persist.
5. When we disclose information
We disclose personal information only to:
- Service providers (subprocessors) who process it on our behalf under contract — hosting, storage, email delivery, push notifications, AI processing, analytics, and error tracking. The current list is in our Subprocessor List.
- Other users, as you direct through the sharing features above.
- Legal and safety: to comply with law or valid legal process, or to protect the rights, safety, and security of users, the public, or the Services.
- Business transfers: if we are involved in a merger, acquisition, or sale of assets, your information may be transferred; this policy would continue to apply, and we would notify you of material changes.
We do not sell personal information. Health data from Apple Health is additionally never shared except as needed to provide App features you've enabled.
6. Data retention
- Account and fitness data: retained while your account is active. When you delete your account, it is deactivated and permanently deleted after a 14-day grace period (Section 7).
- Sessions and sign-in codes: sign-in codes expire after minutes; expired sessions are purged on a rolling basis.
- Server logs and diagnostics: retained for up to 90 days, then deleted.
- AI provider processing: content sent to AI providers is not used to train their models and is retained by those providers only for the limited periods allowed by our API terms with them.
- Backups: deleted data may persist in encrypted backups for up to 30 days before being purged.
7. Your choices and rights
- Privacy toggles. Turn analytics and crash reporting on/off in Settings → Privacy.
- Apple Health. Enable/disable syncing in Settings; revoke permissions in iOS Health settings.
- Notifications. Manage push notifications in Settings or at the OS level.
- Export. Request a machine-readable export of your data in Settings → Export My Data.
- Delete your account. Request deletion in Settings → Delete Account. We deactivate your account and, after a 14-day grace period, permanently delete your account, content, and uploaded media — this is irreversible. To cancel a pending deletion, contact support@alpsapp.co within the 14 days. Deleting your account does not automatically cancel an active subscription purchased through the App Store or Google Play — cancel it in your store account settings.
- Access & correction. Edit your profile in the App, or contact us for anything else.
Depending on where you live (including the EEA/UK under GDPR, California under CCPA/CPRA, Washington under the My Health My Data Act, and other US states), you may have legal rights to access, correct, delete, port, or restrict processing of your personal information, to opt out of sale/sharing (we don't sell or share for advertising), and to non-discrimination for exercising these rights. To exercise any right, use the in-app tools above or email support@alpsapp.co. We will verify your request and respond within the legally required time. You may also appeal a refusal by replying to our response, and you have the right to lodge a complaint with your local supervisory authority.
Legal bases (GDPR). We process your data to perform our contract with you (providing the Services), for our legitimate interests (security, debugging, improving the Services), with your consent where required (optional analytics, Apple Health), and to comply with legal obligations. Where we rely on consent, you can withdraw it at any time.
8. Security
We use industry-standard measures: encryption in transit, hashed credentials, secure token storage on device, scoped row-level authorization on every data access, metadata stripping on uploads, and audit logging. No system is perfectly secure; if a breach affecting your data occurs, we will notify you as required by law.
9. Children
The Services are not intended for anyone under 16. We do not knowingly collect personal information from children under that age; if we learn we have, we will delete it. Contact us at support@alpsapp.co if you believe a child has provided us information.
10. International transfers
We are a Delaware (USA) company and process data in the United States. If you use the Services from elsewhere, your information is transferred to and processed in countries that may have different data-protection laws. Where required, we use appropriate safeguards such as Standard Contractual Clauses.
11. Changes to this policy
We may update this policy. Material changes will be announced in the App or by email before they take effect, and the Effective Date above will change. Continued use after the effective date means the updated policy applies.
12. Contact
Alps App, Inc. 1220 Rosecrans St. #251, San Diego, CA 92106, USA Privacy requests: support@alpsapp.co General support: support@alpsapp.co