Privacy Policy
- Health data stays localWeight, meals, sleep, heart rate, and workouts are read from Apple Health, processed on device, and never transmitted to our servers.
- No accounts, no loginsCrestoFit uses anonymous authentication. We never see your email, Apple ID, name, or any contact identifier.
- Anonymous diagnosticsCrash reports and basic app-session metrics. No personal data, no health data, and no advertising identifiers.
Overview
CrestoFitis a fitness journal that runs on your iPhone. Apple Health data — weight, meals, sleep, heart rate, workouts — is read on device and is never sent to our servers. The only information that leaves your phone is (a) a small set of squad scoreboard fields, transmitted only if you choose to join a squad, and (b) anonymous crash reports and app diagnostics that help us identify and fix bugs.
How accounts work
CrestoFit does not ask you to sign in. There is no email address, no password, no Sign in with Apple, no third-party login. On first launch the app creates an anonymous Firebase Authentication identity— a random per-install token stored in the iOS Keychain. We use that token only to authorize squad reads and writes against our backend. It is not tied to any contact information you can be reached at.
Because the identity is anonymous and tied to the device’s Keychain, reinstalling the app, erasing the device, or migrating to a new iPhone may rotate it. There is no cross-device recovery, by design— we don’t collect any contact identifier that would let us re-link a previous progression to a new install. iCloud-based account sync was considered and explicitly dropped in favor of zero-PII as a load-bearing claim.
Data we read from Apple Health
With your permission, CrestoFit reads the following from Apple Health to compute character stats and quests: steps, weight, sleep, heart rate, active energy, dietary water, and workouts. Your biological sex, date of birth, and height (if set in iOS Health) are read once during onboarding so the app can pre-fill those fields without requiring you to retype them.
CrestoFit writes weight logs, water logs, height edits, and completed workouts back to Apple Health so they are available to other applications you trust. No other data is written.
HealthKit data is never transmitted off your device by CrestoFit.It is not used for advertising, not sold, not used for data brokerage, and not shared with any third party. This is also a strict requirement of Apple's HealthKit developer terms.
Data we collect when you join a squad
Joining a squad is optional. When you create or join one, the following fields are stored in our cloud database (Firebase Firestore) so other authenticated members of your squad can see the in-app leaderboard:
- Display name (your in-app handle, for example “FrostWolf42”)
- Total XP, current level, current rank tier, and tier label (for example “Silver II”)
- Current streak length, in days
- The squad you belong to, if any
- The timestamp when you last opened the app, so squads can show a “last seen” signal
- The timestamp when your record was first created
These fields are visible only to other authenticated members of your squad. There is no public website leaderboard, and squad data is not readable by anyone outside the squad.
That is the entire list — nine fields, no exceptions. Your weight, meals, sleep, heart rate, photos, plan contents, quest definitions, and every other health field are never transmitted. The allowlist is enforced both in the iOS application (a single write path that rejects unknown keys) and on our server (Firestore Security Rules that reject any other field). If a future build tried to send a tenth field, the server would refuse the write.
Anonymous diagnostics
CrestoFituses Firebase Crashlytics and Firebase Analytics to identify crashes and understand basic application health. The information transmitted is anonymous and tied only to a per-install random identifier. It is never tied to your name or email address — we don’t collect those. Specifically:
- Crash reports— stack trace at the moment of the crash, device model, operating system version, application version, and free memory and disk space at the time of the crash.
- App diagnostics— application open events, session duration, and country (derived from the IP address at request time and not stored by us).
CrestoFitdoes not use Apple's Identifier for Advertisers (IDFA) and does not call setUserIDin Firebase Analytics. Either would shift this data into Apple's “Tracking” category and require an App Tracking Transparency permission prompt, which is not appropriate for diagnostics of this scope.
Apple Watch companion
The watch app is a paired companion (it requires your iPhone) and follows the same privacy contract. During a wrist-led workout it reads heart rate and active energyfrom Apple Health on the watch, then writes a HKWorkoutsample to Apple Health when you finish. Your iPhone imports that workout via Apple Health and credits XP, quests, streaks, and rank-ups through the same path as an in-app log. None of the watch data is sent to our servers. The watch app does not include Firebase, Crashlytics, or Analytics — only the iPhone target does.
What we never collect
- Your email address, name, phone number, or any contact identifier
- Your weight, body composition, or any HealthKit value (transmitted off device)
- Meal contents, meal photos, or estimated calorie intake
- Heart rate, sleep stages, heart-rate variability, or any clinical data
- GPS coordinates or precise location
- Contacts, calendar entries, or any data from outside CrestoFit
- Apple's Identifier for Advertisers (IDFA)
- Custom workout plans, custom quests, or any user-generated content
Sub-processors
CrestoFituses Google's Firebase platform for the squad backend, abuse prevention, anonymous diagnostics, and the website:
- Firebase Authentication — anonymous identities only
- Firebase Firestore — squad scoreboard storage (the fields listed above)
- Firebase App Check — server-side abuse prevention; uses Apple's App Attest to confirm requests come from a genuine, unmodified copy of the app. No personal data is sent.
- Firebase Remote Config — lets us publish a minimum supported app version so we can prompt users to update if a release contains a critical fix. No user data is sent.
- Firebase Crashlytics — anonymous crash reports
- Firebase Analytics — anonymous application sessions and country
- Firebase Hosting — this website (static export, no server-side functions)
Data in transit is protected by TLS. Firestore is not end-to-end encrypted, which means Google can technically access squad scoreboard data server-side. For that reason, we limit the data stored in Firestore to information that is appropriate to entrust to a sub-processor: handle, XP, level, tier, and streak. No health data is sent.
Data retention and deletion
On-device data persists until you delete the application or open Settings → Data → Delete my data within CrestoFit. That action does all of the following, in order:
- Removes you from any squad you belong to (or disbands the squad if you own it)
- Deletes your record from our cloud database
- Deletes your anonymous Firebase Authentication identity from the server
- Wipes all local logs, profile, custom quests, preferences, and any cached widget snapshot
- Re-creates a fresh anonymous identity and returns you to onboarding
Crashlytics and Analytics data is retained per Google's defaults (typically 90 days for crash reports and up to 14 months for events). Because this data is anonymous and is not linked to any contact identifier we hold, there is no per-user deletion handle. The data ages out automatically.
Your rights
You may at any time:
- Delete all of your local and cloud data (Settings → Data → Delete my data)
- Leave or disband your squad without deleting your local data (Squad tab)
- Revoke individual HealthKit permissions in iOS Settings → Health → Data Access & Devices → CrestoFit
If you reside in the European Economic Area, the United Kingdom (under GDPR), or California (under CCPA), you also have the right to access, correct, or delete personal data we hold about you, and to lodge a complaint with your local supervisory authority. To exercise these rights, email developer.crestofit@gmail.com. We will respond within 30 days. In most cases the in-app Delete-my-data action is faster and more thorough than a manual request, and we will recommend it first. We may not be able to fulfil an access or correction request for an anonymous identity unless you can demonstrate ownership of it — for example, by performing the request from inside the app on the device that holds the identity.
Children
CrestoFit is intended for users 13 years of age and older. We do not knowingly collect data from children under the age of 13. If you believe we have collected such data, please email developer.crestofit@gmail.com and we will delete it.
Changes to this policy
If we change what data leaves your device, we will update this page and the “Last updated” date at the top. Material changes will also be surfaced in the application's Privacy Report screen on the next launch.
Contact
For privacy questions or requests, email developer.crestofit@gmail.com. We respond within 5 business days.