Skip to privacy policy
MOVAPOINT
Home Privacy Terms

Clear by design

Privacy Policy.

Movapoint is built around on-device workout records. This policy explains what stays local, what leaves your device, who processes it, how long it is kept, and how to delete it.

Effective July 12, 2026 Last updated July 12, 2026 Version 1.0

On this page

  1. Who we are and scope
  2. Privacy at a glance
  3. Data used by the app
  4. Apple Health and fitness data
  5. Website and waitlist data
  6. Purposes and legal bases
  7. Service providers and sharing
  8. No sale, ads, or tracking
  9. Retention
  10. Account and data deletion
  11. Your controls and choices
  12. International transfers
  13. Security
  14. Children
  15. Regional privacy rights
  16. Changes and contact
On-device first Workout history, body entries, routines, gyms, and most preferences currently stay on your device.
No ad tracking We do not sell personal data, run behavioral ads, or use Health data for marketing or data mining.
Real deletion paths Delete identity in-app, remove local records from the device, and request waitlist deletion by email.

1. Who we are and scope

This Privacy Policy describes how Yağız Can Aslan, an individual developer based in Türkiye, operating Movapoint (“Movapoint,” “we,” “us,” or “our”) handles personal information in the Movapoint mobile application, on movapoint.com, through the beta waitlist, and when you contact us (collectively, the “Service”). For applicable data-protection law, Yağız Can Aslan is the data controller for information Movapoint determines how and why to process.

This policy covers the current production behavior described below. Features marked “coming soon,” prototypes, and internal developer tools are not treated as live data practices. If cloud sync, server accounts, analytics, social features, or new integrations are introduced, we will update this policy and any required in-app disclosures before the new processing begins.

Apple, Google, your device manufacturer, app marketplaces, gyms, and services you independently choose may process information under their own policies. This policy does not govern processing they perform for their own purposes.

2. Privacy at a glance

  • Core training records are local. Current workout, routine, gym, machine, setup, program, body-measurement, and preference data is stored in the app’s private storage on your device, not on a Movapoint server.
  • Apple identity is local. If you use Sign in with Apple, the app stores Apple’s app-specific user identifier and any name or email Apple releases on your device. Movapoint currently has no backend account database.
  • Health access is narrow and permission-based. During a workout, the app can read recent heart-rate samples for live display. At completion it can write a strength workout and estimated active energy to Apple Health. This information is not sent to Movapoint.
  • The waitlist is separate. If you join on the website, your email and limited browser-locale metadata are sent to Firebase so we can operate the beta list.
  • No current analytics or advertising SDK. The current app and website code do not include behavioral analytics, advertising, cross-app tracking, or data-broker integrations.

“Collected by Movapoint” below means data transmitted off your device in a way that we or our providers can access. Data processed only on your device is described for transparency but is not collected by us in that sense.

3. Data used by the app

Category Examples and source Current handling
Training content Routines, exercises, sets, weights, repetitions, RIR, difficulty, form, range of motion, rest, notes, sessions, duration, programs, progress, and calculated scores or estimates that you enter or generate through the app. Stored in the app’s local database and processed on-device to log training and produce charts, history, summaries, and suggestions.
Gym and equipment content Gym, machine, attachment, grip, seat, height, angle, setup, and related notes that you enter. Stored and processed on-device so the app can remember setups and show relevant history.
Body and fitness entries Body weight and, where the interface makes them available, optional measurements such as height, body-fat estimate, waist, chest, arm, or hip measurements. Stored on-device for progress displays and calculations. Not sent to Movapoint.
Profile and account data Display name, profile creation date, guest/Apple sign-in state, Apple’s app-specific user identifier, and any name or email Apple provides after you choose Sign in with Apple. Stored in device preferences. Used to personalize the app and maintain local sign-in state. No current Movapoint server profile is created.
Preferences and device state Weight unit, rest duration, language, onboarding state, notification choices, locally selected plan state during development, and similar settings. Stored on-device to remember your choices and operate the app.
Local notifications and Live Activities Rest-timer alerts, training-program reminders, workout timing, and related display content. Scheduled and displayed through Apple’s on-device system after permission where required. Movapoint does not operate a push-notification server for these features.
Exports and imports Portable backup files you explicitly export or choose to import. Created or read only at your direction. Once exported to Files, email, cloud storage, or another destination, you and that destination control the copy.
Purchase status When paid subscriptions are enabled: product, entitlement, renewal, and transaction status supplied by the app marketplace. Used to unlock purchased features and restore purchases. Apple or the marketplace processes payment details; Movapoint does not receive full card numbers.

The app does not currently request contacts, precise location, photos, microphone, camera, or advertising identifiers for its core features.

4. Apple Health and fitness data

Apple Health integration is optional and uses Apple’s permission controls. Movapoint requests only the data types needed for the features below:

  • Heart rate (read): after you request the feature and grant permission, Movapoint reads recent heart-rate samples available in Apple Health during an active workout and displays the latest beats-per-minute value and source. The live value is held in memory for the workout and is not saved to Movapoint’s workout database or sent to us.
  • Workouts and active energy (write): after permission, Movapoint can save a completed traditional strength-training workout to Apple Health with start and end time, duration, workout title, and estimated active energy.
  • Body weight used for an estimate: the active-energy estimate uses body weight you stored in Movapoint, or a general fallback value if none is available, together with workout duration and a standard resistance-training estimate. Movapoint does not read body weight from Apple Health.

We do not send HealthKit data to Movapoint servers, use it for advertising or marketing, sell it, disclose it to data brokers, use it to determine insurance, credit, or employment eligibility, use it for generalized AI-model training, or perform health-related human-subject research. Personal HealthKit data is not stored in iCloud by Movapoint.

Movapoint is not a medical device and does not diagnose, treat, cure, or prevent a medical condition. Heart rate, calorie estimates, and other fitness outputs may be delayed or inaccurate and must not be used for diagnosis, treatment, emergency response, or another safety-critical decision. Consult a qualified healthcare professional for medical advice.

You can review or revoke Movapoint’s Health permissions in Apple Health or device Settings. Apple controls the Health database and its retention. Deleting Movapoint does not automatically delete workouts already written to Apple Health; those can be managed in Apple Health.

5. Website, waitlist, and support data

Beta waitlist

When you submit the website waitlist form, we send the following to Google Firebase/Cloud Firestore:

  • your email address, normalized to lowercase and also used as the waitlist record identifier;
  • the signup time generated by Firebase;
  • schema version;
  • your browser-reported language/locale and time zone; and
  • a country code inferred from the locale, when available. We do not use an IP-geolocation service for this field.

We use that information to maintain the waitlist, prevent duplicate entries, understand the broad language/time-zone mix of beta interest, and send the beta or launch communications you requested. The public website cannot read, edit, or delete waitlist entries under its database rules.

Website preferences and demo inputs

The website stores your EN/TR language preference in browser local storage. It does not currently set advertising or behavioral-tracking cookies. Values entered into the interactive workout demonstration—such as weight, repetitions, RIR, difficulty, form, or range of motion—are used only in the page demonstration and are not submitted to Firebase or retained after the page session.

Ordinary network information

When you visit the website, hosting and content-delivery providers may automatically process ordinary request information such as IP address, browser/device type, requested URL, date and time, and security logs to deliver content, prevent abuse, and maintain reliability. The website loads hosting/database components from Google Firebase, fonts from Google Fonts, and Three.js code from jsDelivr. We do not use those requests to build advertising profiles.

Support and privacy requests

If you email us, we receive your email address, message, attachments, and any information you choose to include. We use it to respond, verify a request, resolve problems, and keep appropriate records. Please do not send unnecessary health information, passwords, payment-card data, or government identifiers.

6. Purposes and legal bases

Depending on where you live, we process personal information under one or more of these legal bases:

Purpose Typical information Legal basis where required
Provide and personalize the Service Local training, profile, settings, entitlement, and app-state data. Performing our contract with you; your request before entering a contract; and processing you direct on your device.
Apple Health features Heart-rate access; completed workout and estimated active energy written to Health. Your affirmative Health permission and, where special-category rules apply, your explicit consent. You can revoke access at any time.
Waitlist and requested communications Email, signup time, locale, time zone, locale-country hint. Your consent and request to join. You can withdraw at any time.
Security, reliability, and abuse prevention Request logs, timestamps, technical and security information. Our legitimate interests in securing and operating the Service, balanced against your rights; and legal obligations.
Support and privacy requests Contact details, correspondence, and verification information. Performing our contract, complying with law, and our legitimate interests in responding and documenting resolutions.
Purchases and compliance Entitlement and transaction status, records required by law. Performing our contract and legal obligations, including tax, accounting, consumer, and fraud-prevention duties.

We do not use solely automated decision-making that produces legal or similarly significant effects about you.

7. Service providers and sharing

We disclose information only as needed for the purposes described here:

  • Apple: Sign in with Apple, HealthKit, App Store/StoreKit purchases, operating-system permissions, local notifications, and device services. Apple handles information under its Privacy Policy and applicable service terms. We do not receive HealthKit data from Apple on a server.
  • Google Firebase and Google Cloud: website hosting, delivery of the Firebase web SDK, and storage/security of waitlist records. See Firebase Privacy and Security and the Google Privacy Policy.
  • Google Fonts: delivery of website font files. Ordinary request information may be processed under the Google Privacy Policy.
  • jsDelivr: delivery of Three.js files used by the website’s 3D experience. See jsDelivr’s Privacy Policy.
  • Your chosen recipients: when you export, share, or send data to a destination you select.
  • Legal and safety recipients: if reasonably necessary to comply with valid law or legal process, protect rights and safety, investigate fraud or abuse, or establish or defend legal claims.
  • Business transfer recipients: if the Service or business is reorganized, financed, sold, or transferred, subject to confidentiality, applicable law, and notice where required.

We select providers appropriate to the Service and require them, through their terms, contracts, and applicable platform rules, to protect data consistently with this policy and applicable law. They may not use information we provide for their own advertising purposes unless you separately direct or consent to that use.

8. No sale, behavioral ads, or cross-app tracking

Movapoint does not currently:

  • sell or rent personal information;
  • “share” personal information for cross-context behavioral advertising;
  • serve third-party or personalized advertisements;
  • use advertising identifiers or track your activity across other companies’ apps or websites;
  • use HealthKit, health, fitness, or workout data for advertising, marketing, data brokerage, credit, insurance, employment, or use-based data mining; or
  • use private workout or health information to train generalized artificial-intelligence models.

Because we do not engage in those practices, we do not offer a sale/share opt-out mechanism. If that changes, we will update this policy and provide legally required choices before the new practice begins. Browser “Do Not Track” and Global Privacy Control signals do not change current behavior because there is no behavioral tracking or sale/share to opt out of.

9. Data retention

Information Retention
Local workout, body, gym, program, and preference data Until you delete individual records, replace/import data, reset relevant settings, or delete the app and its data from the device. We cannot remotely retrieve or delete data that never leaves your device.
Local Apple sign-in identity Until you sign out, use Delete Account in the app, or delete the app and its data.
Health data Live heart-rate values are not retained by Movapoint after use. Workouts written to Apple Health remain under Apple Health’s controls until you delete them there.
Waitlist record Until the beta/invitation purpose ends, you withdraw, or the record is no longer needed. We review the list periodically and generally delete inactive waitlist records no later than 24 months after the last beta or invitation communication, unless a shorter period is required.
Support and privacy correspondence Generally up to 24 months after resolution, or longer when reasonably necessary for security, dispute, or legal-compliance records.
Technical/security logs held by providers For the provider’s documented operational and security period, subject to its service terms and our configuration. We retain only what is reasonably necessary.
Purchase and legal records For the period required by marketplace, tax, accounting, consumer-protection, fraud-prevention, or other applicable law.

Deletion from active systems may take up to 30 days after a verified request. Residual copies may remain temporarily in provider backups and are isolated until overwritten under normal retention cycles. We may retain the minimum information needed to document a request, prevent abuse, resolve a dispute, or comply with law.

10. Account and data deletion

Movapoint deletion request: email support@movapoint.com from the email connected to your account or waitlist. State whether you want us to delete your app account information, waitlist record, support history, or all data we control.

Delete your app identity

In the iOS app, go to Profile → Settings → Account → Delete Account. The current version removes the locally stored Apple app-specific identifier, Apple-provided email, account state, and profile display name. Because there is currently no Movapoint backend account database, there is no server profile to remove.

Delete local workout records

Delete records with the available in-app controls, or delete Movapoint and its data from your device to remove the app’s local database and preferences. Delete Account intentionally does not erase local workout history. This separation lets you unlink identity without losing training records. Exported backups are independent copies and must be deleted wherever you saved or shared them.

Delete Apple Health records

Revoke Health access in Apple Health or device Settings to stop future access. Workouts already written to Apple Health are controlled there and can be reviewed or deleted using Apple Health’s data controls. Deleting the Movapoint app or account does not remove Apple Health records.

Delete waitlist or support data

Use the email link above. We may ask you to verify control of the relevant email so we do not delete another person’s data. We aim to complete verified requests within 30 days, or within the period required by applicable law, and will confirm completion or explain any lawful retention.

Subscriptions are separate

Deleting an account or data does not cancel a marketplace subscription. Cancel separately through Apple Subscriptions or Google Play Subscriptions. Deletion can proceed without waiting for a subscription to end; canceling prevents future renewal charges.

11. Your controls and choices

  • Guest use: use the current core app as a guest where offered instead of Sign in with Apple.
  • Health: grant only the Apple Health permissions you want and revoke them at any time in Apple Health or device Settings.
  • Notifications: change notification permissions in device Settings and adjust available reminder settings in the app.
  • Waitlist: do not submit the form, or withdraw later by emailing us. Any marketing email we send will include an appropriate unsubscribe method where required.
  • Language storage: change the website language or clear the site’s local storage in your browser.
  • Access and portability: view and edit local records in the app and use the app’s export feature to create a portable backup.
  • Account unlinking: sign out to remove local Apple identity while keeping your display name and workout data, or use Delete Account for the broader local identity removal described above.

Withdrawing consent does not affect processing that was lawful before withdrawal. Some features cannot work without the data or permission they specifically require.

12. International data transfers

Movapoint is operated from Türkiye. Apple, Google, Firebase, content-delivery providers, and other recipients may process information in the European Economic Area, United States, Türkiye, and other countries where they or their subprocessors operate. Those countries may have different privacy laws.

Where law requires, we use an available lawful transfer mechanism—such as an adequacy decision, contractual safeguards, provider data-protection terms, or your explicit consent—and apply supplementary measures appropriate to the risk. You may contact us for information about safeguards relevant to information we control.

13. Security

We use administrative and technical measures appropriate to the current Service, including data minimization, Apple’s app sandbox and permission systems, local-first storage, HTTPS/TLS for website transmissions, provider access controls, and restrictive Firestore rules that prevent public reading, updating, or deletion of waitlist records.

We limit service-provider use to defined functions and expect protections at least consistent with this policy and applicable app-store requirements. However, no device, transmission, or storage system is perfectly secure. Keep your device, Apple ID, and exported backups protected; install security updates; and contact us if you suspect a privacy or security issue.

If a breach affecting information we control creates a legally reportable risk, we will notify affected people and authorities as required.

14. Children’s privacy

Movapoint is a general strength-training tool and is not directed to children under 13. We do not knowingly collect personal information from a child below the minimum age permitted by applicable law without valid parental authorization. Minors should use exercise features only with appropriate guardian and qualified supervision.

If you believe a child submitted personal information to the waitlist or support channel without appropriate authorization, contact us. After reasonable verification, we will delete it as required. The app should not be used to record another child’s health or fitness data without lawful authority and consent.

15. Regional privacy rights

Privacy rights vary. Subject to applicable conditions and exceptions, you may request access, confirmation, correction, deletion, restriction, portability, or a copy of personal information we control; object to certain processing; withdraw consent; or appeal a denied request. You may also complain to your local data-protection authority.

European Economic Area, United Kingdom, and Switzerland

You may have rights under the GDPR or similar laws to access, rectify, erase, restrict, or port personal data; object to legitimate-interest processing and direct marketing; withdraw consent; and lodge a complaint with a supervisory authority. Where we rely on legitimate interests, you can ask about the balancing assessment.

Türkiye

Under Article 11 of Türkiye’s Law No. 6698 on the Protection of Personal Data (KVKK), you may have the right to learn whether personal data is processed; request information; learn the purpose and whether data is used accordingly; learn recipients in or outside Türkiye; request correction, deletion, or destruction where conditions are met; request notice of those actions to recipients; object to a result arising exclusively from automated analysis; and claim compensation for unlawful processing. Apply using the contact method below and include enough information to verify and fulfill the request.

California and other U.S. states

Where applicable, you may have rights to know, access, correct, delete, or obtain a portable copy of personal information and to opt out of sale, targeted advertising, or certain profiling; you may also have a right to limit certain sensitive-data uses and appeal a denial. Movapoint does not currently sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising, and will not discriminate against you for exercising a privacy right.

Making a request

Email support@movapoint.com with the subject “Privacy rights request,” your country or state, the email associated with the relevant record, and the right you want to exercise. We will request only the verification reasonably needed, respond within the applicable period, and explain any denial and appeal option. An authorized agent may submit a request where law permits, subject to proof of authority and identity verification.

Most app data is only on your device and is not accessible to us. For that data, the in-app viewing, editing, export, and deletion tools are the direct way to exercise access, correction, portability, and deletion.

16. Changes and contact

We may update this policy when the Service, law, or our providers change. We will post the revised policy here and update the date above. If a change materially affects how we use information already collected, we will provide additional notice and request consent where required before the new use begins.

Questions, complaints, deletion requests, and privacy-rights requests can be sent to the contact below. We have not appointed a separate data protection officer; this address is the privacy contact and request mechanism for Movapoint.

Data controller and developer
Yağız Can Aslan, operating Movapoint
İstanbul, Türkiye

support@movapoint.com

Movapoint © 2026 · All rights reserved.

Home Terms of Service Contact