Privacy Policy
PostureFix AI · Last updated: 18 August 2026 · Applies to app version 1.0 (8) and later Controller: Kacper Lewandowski, an individual developer based in Poland, who publishes PostureFix AI on the App Store. Contact for any privacy matter: kacperloczek3@gmail.com (a postal address for privacy correspondence is provided on request to the same address).
The short version
PostureFix has no accounts, no sign-up and no login, so nothing in the app is tied to your identity. Everything you enter — your profile, your intake answers, your pain notes, your measurements, your photos, your chats — is stored in a local database on your phone.
The app also has AI features. Those features do not work on your phone alone: to build your plan, read your posture photos, interpret your camera measurements and answer you in the coach chat, the app sends the data described in section 3 to Google LLC, which processes it with the Google Gemini API on our behalf. That is a real transfer of health-related data to a third party, and it happens only after you have tapped Agree on the dedicated AI consent screen inside the app. Refusal is a real option: the app stays usable, the plan is then built on your device, and nothing you have paid for is withheld.
The consent check is enforced in the app's network layer, not in individual screens, so every AI request — including the coach messages the app prepares in the background — is blocked until you agree, and blocked again the moment you withdraw.
1. What data we collect
Profile basics. Sex, age, height, weight, your dominant side, and how much of your day you spend sitting.
Goals and intake answers. What you want to achieve, your training and sports history, and the remaining answers you give in the onboarding questionnaire and in in-app screens.
Injury, surgery and diagnosis history — HEALTH DATA. Past and current injuries, operations, and diagnoses you have been given, plus the symptom patterns you select (for example when the pain appears and what makes it worse).
Pain map and pain notes — HEALTH DATA. Every body region you mark as painful together with its intensity on a 0–10 scale, and anything you type in your own words about your pain in the intake, in the pain journal and in the coach chat.
Measurements, tests and session results. Range-of-motion angles and other values measured with the camera or entered manually, test scores, completed exercises and sessions, and the reports generated from them.
Photos and video frames — HEALTH DATA. The posture-scan photos you take or pick from your photo library, single frames captured during camera range-of-motion measurements, and the photos or video frames used by camera-read body tests. These are images of your body, so we treat them as health-related data.
Coach chat messages and coach memory. Your messages to the AI coach, the coach's replies, the conversation history, and the short summary of facts about you ("coach memory") that the app stores so the coach does not ask you the same thing twice. This content routinely contains health data.
Purchase data. The App Store purchase receipt and an anonymous, app-generated identifier used to unlock your subscription. It contains no name, e-mail address or payment card details — Apple handles the payment and we never see your card.
Technical request data. Standard network metadata (IP address, device and app version, timestamps) that our hosting, update and content-delivery providers necessarily see when your app makes a request. We do not build profiles from it and we do not use analytics or advertising SDKs.
We never ask for your e-mail address, phone number, contacts or location. We do ask for a first name — the coach greets you with it — but it is stored only on this device, substituted into messages locally, and never sent to Google or any other third party.
2. How we collect it
Typed by you. Profile basics, goals, intake answers, injury/surgery/diagnosis history, pain regions and 0–10 intensities, free-text pain notes and manually entered test values are collected as you type or tap them in onboarding and in the app's screens.
Captured by the camera or chosen from your photo library. Posture-scan photos, range-of-motion frames and camera-read test frames are captured with the camera, or selected by you through the system photo picker. The app uses the out-of-process picker: it does not request full access to your photo library, and it only ever receives the specific items you pick.
Typed into the coach chat. Chat messages are collected as you send them; coach memory is derived from those messages and from your profile.
Derived from your use of the app. Session logs, completed exercises, streaks, test scores and generated reports are derived from what you do in the app.
From Apple, via RevenueCat. Your subscription status is derived from the App Store purchase receipt, validated by RevenueCat, Inc. against an anonymous app-generated identifier.
On-device pose detection. Live camera guidance uses a MediaPipe pose model that runs entirely on your device. The model file and its runtime library are downloaded once from Google's model CDN (storage.googleapis.com) and from the public jsDelivr CDN; those downloads reveal only ordinary request metadata such as your IP address. Your camera image is not sent to them.
3. What we send to Google, and exactly when
When you have agreed on the AI consent screen, the app sends data to the Google Gemini API, operated by Google LLC, over an encrypted (TLS) connection, relayed through our own server. These are all the triggers, and they are the only ones:
a) Plan generation, at the end of onboarding. Sent: sex, age, height, weight, how much you sit, your dominant side, your sports history, your injury/surgery/diagnosis history, your symptom patterns, every painful body region with its 0–10 intensity, and your own free-text notes about your pain. Purpose: to generate your personalised corrective training plan.
b) Posture scan. Sent: the posture photos you captured or picked, plus your health intake so the reading is interpreted in context. Purpose: to measure your alignment and produce your posture report.
c) Camera range-of-motion measurement. Sent: one frame from the measurement together with the measured values. Purpose: to produce the written insight that explains what the measurement means for you.
d) Camera-read body test. Sent: the photos or video frames of the test, plus your full health intake. Purpose: to score the test and explain the result.
e) Every coach chat message. Sent on each turn: your message, the conversation history, your profile, your pain journal and the stored coach memory. Purpose: to answer you in context.
f) Proactive coach messages — sent without you pressing anything. The app also prepares coach messages in the background, and each of those sends the same chat payload (profile, pain journal, coach memory and relevant history) to Google without a gesture from you. There are six of them: the comeback message when you have been away, the education drip, the weekly recap, coach check-ins, plan refreshes, and the follow-up after an analysis. This is stated here, and on the consent screen, so that your agreement covers it; if you would rather this did not happen, withdraw consent as described in section 8.
Photos are reduced before they are sent. Every image is downscaled to 560 pixels wide and re-compressed as JPEG at quality 0.55 before it leaves your device — small enough to yield body angles, not a detailed picture of how you look. The full-resolution original stays on your phone and is never transmitted.
Your name stays here; no e-mail, no location. The app asks only for a first name, stores it on this device and never includes it in anything it sends; e-mail address and location are never asked for at all. Up to and including version 1.0 (7), a first name entered in onboarding was included in the plan request; that field has been removed from the app and from the plan payload in version 1.0 (8), and no name is sent any more.
Nothing is sent before you agree. No personal data goes to Google before you tap Agree on the AI consent screen — not as a warm-up request, not to fill a loading state, not from a background sender. The check lives in the transport layer that every one of these requests passes through.
4. All uses of the data
We use the data described above only for the following purposes:
- to run the app's on-device features: your profile, body map, plan, exercise library, timers, pain journal, tests, measurements and progress history; - to generate your training plan — either by sending your intake to Google Gemini (section 3a) or, if you decline AI processing, by building the plan on your device; - to analyse your posture photos, camera measurements and camera-read tests and to return the resulting reports and scores to your phone (sections 3b–3d); - to answer your questions in the coach chat and to keep the coach's replies consistent with what you have already told it (section 3e); - to prepare the proactive coach messages listed in section 3f and to adapt your plan over time; - to schedule local reminders and desk-break alerts on your device (they are scheduled locally; no data leaves the phone for this); - to validate your App Store purchase and unlock premium features; - to deliver app updates and to keep the service secure and working (error handling, abuse prevention, operations).
We do not use your data for anything else. In particular: we do not sell personal data; we do not share it with advertising networks, data brokers or analytics vendors; we do not use it for marketing or profiling; we do not attempt to identify you or reconstruct a profile of an anonymous user; and no data derived from the camera or from depth/face APIs is used for marketing, advertising or use-based data mining, by us or by anyone else. Data you gave us for one purpose is not repurposed for another without asking you first.
5. Third parties who process data for us
We use a small number of processors. Each one acts on our instructions, for the purposes described above and for nothing else.
Google LLC — Gemini API (AI analysis, plan generation, coach chat). Google LLC processes this data solely as our data processor under the Gemini API terms and its Data Processing Addendum, and provides the same or equal protection of user data as stated in this policy and as required by the App Store Review Guidelines. Google does not use this content to train its models.
RevenueCat, Inc. — purchase validation and subscription status. RevenueCat receives your App Store receipt and an anonymous app-generated identifier — never your name, e-mail or payment details. RevenueCat, Inc. processes this data solely as our data processor under its data processing addendum, and provides the same or equal protection of user data as stated in this policy and as required by the App Store Review Guidelines. RevenueCat does not use this data for its own purposes.
Vercel Inc. — hosting of our relay server. Our server is a stateless relay: it forwards your request to Google and returns the answer, and stores no copy of your photos, messages, intake or reports. Vercel may keep short-lived operational logs containing request metadata (such as IP address and timestamps) for security and reliability. Vercel Inc. processes this data solely as our data processor under its data processing addendum, and provides the same or equal protection of user data as stated in this policy and as required by the App Store Review Guidelines. Vercel does not use it for its own purposes.
Expo, Inc. — EAS Update (app updates). When your app checks for a JavaScript update, Expo's servers see request metadata such as your IP address, device platform and app version. No profile, health data, photos or chat content is involved. Expo, Inc. processes this data solely as our data processor under its terms, and provides the same or equal protection of user data as stated in this policy and as required by the App Store Review Guidelines.
Google's model CDN (storage.googleapis.com) and jsDelivr — delivery of the on-device pose model. Downloading the MediaPipe pose model and its runtime reveals only ordinary request metadata (IP address, user agent). No image, measurement or profile data is sent; the pose detection itself runs on your device. These providers provide the same or equal protection of user data as stated in this policy and as required by the App Store Review Guidelines.
Apple Inc. — payments and distribution. Apple processes your purchase as an independent controller under Apple's own privacy policy. We never receive your payment details.
International transfers. Google, RevenueCat, Vercel and Expo are established in the United States. Transfers of personal data outside the European Economic Area take place under the European Commission's Standard Contractual Clauses and/or the EU–US Data Privacy Framework, as provided for in each processor's data processing terms.
6. Retention and deletion
On your device. Everything listed in section 1 — profile, intake, health history, pain map and notes, measurements, tests, reports, photos, chat history and coach memory — is stored in a local SQLite database on your phone and stays there until you delete it or delete the app. We set no expiry and we hold no copy.
On our relay. Nothing. The relay is stateless: it does not write your photos, messages, intake or reports to any storage. Only Vercel's short-lived operational request logs (metadata, not content) exist, and they are retained by Vercel under its own terms.
At Google. Under the Gemini API terms, content sent through the API is processed to produce your result and may be retained briefly for abuse monitoring before being deleted. It is not used to train Google's models and it is not linked to any identity, because we send no identifier.
At RevenueCat and Apple. Purchase records are kept for as long as your subscription is active and afterwards as required for accounting, tax and dispute handling, tied to the anonymous app-generated identifier.
How to delete everything. In the app: Profile → System → Delete all my data. This wipes your profile, intake, health history, pain map and notes, measurements, tests, reports, photos, chat history, coach memory and your consent flags from the device. Deleting the app removes the same data. Because there is no account and no server-side copy, that deletion is final — there is nothing left on our side for us to delete. If you also want the anonymous purchase record removed, write to kacperloczek3@gmail.com.
7. How to withdraw your consent
Open Profile → System and turn off the AI permission ("Withdraw AI analysis permission"). It takes three taps from the main tab bar and takes effect immediately.
What stops. Posture scans, camera range-of-motion insights, camera-read tests, AI plan generation and refreshes, the coach chat, and all six proactive coach messages. The app's network layer refuses these requests outright; the block is not merely a hidden button.
What keeps working. Your plan (rebuilt on your device), the exercise library, Mobility Snacks, timers, manually entered tests and measurements, your body map, your pain journal, your history and your reminders. Withdrawing consent never cancels or reduces your subscription. Features that inherently run on the AI — the coach chat and the photo and measurement analyses — pause while AI is off; everything else Pro unlocks (the full exercise library, the adaptive weekly plan, your history and progress) keeps working.
You can grant consent again at any time in the same place. Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it.
8. No accounts
PostureFix has no sign-up, no login, no password and no server-side user record. We do not know who you are, we cannot link two devices to the same person, and we cannot look up "your" data — because it exists only on your phone. This is also why there is no account deletion feature: there is no account to delete.
9. Your rights under the GDPR (EU/EEA, including Poland)
Controller. Kacper Lewandowski, individual developer, Poland — kacperloczek3@gmail.com. There is no obligation to appoint a Data Protection Officer for processing of this scale; privacy requests go to the same address.
Special-category data. Your pain scores, injury, surgery and diagnosis history, symptom patterns and body photos are data concerning health within the meaning of Article 9(1) GDPR.
Legal bases. - Sending health-related data to Google Gemini: your explicit consent under Article 9(2)(a) GDPR, together with Article 6(1)(a) GDPR — given on the dedicated in-app consent screen and withdrawable at any time in Profile → System. - Providing the app itself and your purchased subscription: performance of a contract, Article 6(1)(b) GDPR. - Security, abuse prevention and keeping the service running: our legitimate interest, Article 6(1)(f) GDPR, limited to technical request metadata.
Consent is genuinely optional: refusing it keeps the whole app usable — your plan is then generated on the device — and only the features that cannot exist without sending data (the coach chat and the analyses) wait until you agree.
Your rights. You have the right of access, rectification, erasure, restriction of processing, objection, and data portability, the right to withdraw consent at any time without affecting the lawfulness of prior processing, and the right to lodge a complaint with a supervisory authority — in Poland the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa).
How to exercise them in practice. Because there is no account, we hold no data that would let us identify you (Article 11 GDPR), so we cannot answer an access or erasure request from our side — there is nothing there. Your rights are exercised directly in the app: view and edit everything in your profile and journal, and erase everything with Profile → System → Delete all my data. For anything else, including questions about the anonymous purchase record, write to kacperloczek3@gmail.com.
10. Children
PostureFix is not directed at children. It is intended for users aged 16 and over in the European Economic Area and 13 and over elsewhere, and we do not knowingly collect data from children below those ages. If you believe a child has used the app, delete the app's data (Profile → System → Delete all my data) and contact us.
11. Security
Everything sent to our relay and on to Google travels over an encrypted TLS connection. On-device data is protected by iOS app sandboxing and device encryption. Requests carrying personal data are additionally tagged with a consent marker, so the enforcement does not depend on any single screen; server-side verification of that marker is being rolled out as a further backstop.
What changed in this version (18 August 2026)
For transparency, this update corrected three statements in the previous version that no longer matched — or never fully matched — how the app worked:
- the previous claim that "nothing leaves your device until you agree" now holds for every AI feature, because consent is enforced in the network layer; previously the end-of-onboarding plan request, coach chat and the proactive coach messages were not covered by that gate; - the previous claim that your name is never included is now precise: in version 1.0 (8) the first name is no longer included in any request — it stays on the device and the coach's greetings substitute it locally; e-mail address and location were never collected and are never sent; - profile, intake, pain journal and chat history were previously described as staying on the device. They are stored on the device, but their content is also sent to Google Gemini for plan generation, the coach chat and the proactive coach messages. Section 3 now says exactly what is sent and when.
Contact
Privacy questions and requests: kacperloczek3@gmail.com. Support page: https://runposture-api.vercel.app/legal/support · Terms of Use: https://runposture-api.vercel.app/legal/terms. If this policy changes, the date at the top is updated and material changes are announced in the app.