POSTUREMAXX
HOMEPRIVACYTERMSGET THE APP ↗
LEGAL · 01

Privacy Policy

Your data in PostureMaxx.

This policy explains what PostureMaxx collects, how it is used, and how to delete your account and synced data.

POSTUREMAXX01
DOCUMENTPRIVACY POLICY
EFFECTIVEJULY 30, 2026
VERIFIED ✓
IN THIS DOCUMENT
01What we collect02Scan photos and on-device processing03Automated analysis and AI04Where other data lives05How we use data06Analytics, diagnostics, and attribution07Other service providers08Security09Deleting your account and photos10Accessing or exporting your data11Children12Changes and contact13Contact
01

What we collect

PostureMaxx creates a device account on first launch and uses its account identifier as your RevenueCat App User ID. This ties App Store entitlement status to the same account used for synced progress. We collect that identifier, a device-account credential, subscription state, onboarding answers, posture scores and landmark measurements, session activity, reminder preferences, and basic app diagnostics. We do not offer Apple or Google provider login, and we do not receive or store payment card details.

02

Scan photos and on-device processing

Your posture scan photos are processed on your device with Apple's Vision framework. PostureMaxx does not upload scan photos to our servers or analytics providers. If you keep them, the photo files remain in the app's private local storage so the app can show your scan history. You can delete all stored scan photos from Settings without deleting the scores derived from them.

03

Automated analysis and AI

PostureMaxx does not use a third-party or cloud AI service at runtime. Apple's Vision framework detects body landmarks on your device. PostureMaxx then calculates scores and chooses sessions with deterministic app code. Scan photos and raw pose points are not sent to an AI provider.

04

Where other data lives

Scores, settings, and session data are stored locally in an encrypted SQLite database. Account, subscription, and synced progress data may also be stored in our PostgreSQL database in the United States so we can secure the account, restore access, and sync supported data. Authentication tokens are stored in secure device storage.

05

How we use data

We use account and app data to calculate your posture score, choose a starting focus area, provide sessions, maintain history, verify premium access, deliver reminders you enable, prevent abuse, diagnose crashes, understand feature usage, and measure which marketing campaigns lead to installs and subscriptions.

06

Analytics, diagnostics, and attribution

We use PostHog for product analytics. PostHog may receive a device-account identifier, app event names, device and platform information, onboarding answer categories, posture score and lowest area, and session activity. We use RevenueCat for subscription management and verified advertising conversion delivery. RevenueCat may receive the device-account identifier, app and device information, App Store receipt and product information, subscription lifecycle events, Apple attribution data, experiment identifiers, a Meta anonymous app identifier, and your App Tracking Transparency consent status. We use the Meta SDK to measure app activations and Meta ad performance. Meta may receive an anonymous app identifier, app and device information, and an activation event. If you allow tracking in Apple's prompt, Meta may also receive the advertising identifier, a standard completed-session conversion event with no posture or exercise details, and verified subscription lifecycle and gross-revenue events sent by RevenueCat. We do not send Meta your email, name, posture score, scan results, scan photos, raw pose points, exercise responses, or health information. We do not sell personal data. Cross-app advertising measurement on iOS is enabled only if you choose Allow in Apple's App Tracking Transparency prompt.

07

Other service providers

We use Apple for App Store purchases and privacy-preserving ad attribution, RevenueCat for subscription management, entitlement identity, and verified conversion delivery, Meta for advertising attribution when enabled, Vercel for application hosting, and a PostgreSQL hosting provider for synced account data. Hosting providers may process the device-account identifier and credential, subscription state, onboarding answers, posture scores and derived landmark measurements, session activity, and settings needed to operate account recovery and sync. Each provider processes information under its own terms and privacy commitments.

08

Security

Local structured data is stored in an encrypted database, authentication credentials use secure device storage, and network traffic to our services uses HTTPS. No service can guarantee perfect security, but we use access controls and data minimization to reduce risk.

09

Deleting your account and photos

You can delete scan photos separately in Settings. You can also delete your device account in the app; this removes server-owned account and synced progress data and clears local account data. Account deletion does not cancel an App Store subscription, which must be managed through Apple. Contact us if you also want associated vendor analytics records located and deleted where supported.

10

Accessing or exporting your data

To request a copy of the personal data we hold, email support@posturemaxx.io. If you use only a device account, include the account identifier shown by support tooling so we can locate the correct record. We aim to respond within 30 days.

11

Children

PostureMaxx is not directed at children under 13 and we do not knowingly collect personal data from children under 13. If you believe a child has used the app, contact support@posturemaxx.io.

12

Changes and contact

We will update the effective date when this policy changes. For privacy questions, deletion requests, or access requests, email support@posturemaxx.io.

NEED SOMETHING CLARIFIED?

Talk to a person.

For privacy questions or deletion requests, email support@posturemaxx.io and include the support ID shown in the app when available.

You can also use the public account deletion request page.

EMAIL SUPPORT ↗
POSTUREMAXX© 2026 · PRIVACY POLICYBACK TO HOME ↑