Ember Fitness
Back to Home
Effective date: January 1, 2025  ·  Last updated: February 26, 2026

Privacy Policy

Summary: Ember Fitness stores your workout and account data in Google Firebase to provide the app's features. We use Google AdMob to show ads to non-premium users (requires your ATT consent on iOS). We never sell your personal data. You can export or delete all your data at any time from the app's Settings.

1. Who We Are

Ember Fitness ("we", "us", "our") is the data controller for personal data collected through the Ember Fitness mobile application (the "App"). If you have questions about this policy or wish to exercise your rights, contact us at:

Email: tryemberfitness@gmail.com

2. What Data We Collect and Why

We only collect data that is necessary to provide and improve the App's features.

Category Data Purpose Legal Basis (GDPR)
Account Email address, display name, account creation date, last login date Create and manage your account; authenticate you Contract (Art. 6(1)(b))
Workout & Fitness Workout history, exercise reps/duration, streak count, scheduled workout days, slip-up history, fitness level, goals, voice coach preference Power the core workout tracking and streak features Contract (Art. 6(1)(b))
Groups & Social Group membership, display name, current streak, last active date (visible to group members) Enable group accountability features Consent (Art. 6(1)(a)) — disclosed at onboarding
Device & Notifications Firebase Cloud Messaging (FCM) token, platform identifier ("iOS") Send workout reminders you have requested Legitimate interest / Consent (Art. 6(1)(f) / (a))
Location GPS coordinates during run workouts only (not stored remotely; used on-device for distance/pace) Calculate route, distance, and pace during a run Consent (Art. 6(1)(a)) — iOS permission prompt
Camera Camera feed during pose-detection exercises (processed entirely on-device; no images stored or transmitted) Count repetitions and provide real-time form feedback Contract (Art. 6(1)(b))
Apple Health Walk/run workouts imported from Apple Health on your explicit request Avoid double-entry of workouts recorded on Apple Watch Consent (Art. 6(1)(a)) — HealthKit permission prompt
Advertising Ad identifiers (for non-premium users, subject to ATT consent) Display relevant ads through Google AdMob Consent (Art. 6(1)(a)) — iOS ATT prompt
Analytics Anonymous app usage events (optional) Understand how features are used; improve the App Consent (Art. 6(1)(a)) — opt-in at onboarding, changeable in Settings

3. Data Processors and Third-Party Services

We share data with the following processors who act on our behalf under data processing agreements:

Google Firebase (Google LLC) Data Processor
We use Firebase Authentication, Cloud Firestore, and Cloud Messaging to store and sync your account data, workouts, and push notification tokens. Google acts as a data processor under our Data Processing Addendum (DPA). Data may be transferred to Google's servers in the United States under Standard Contractual Clauses (SCCs) approved by the European Commission.
Google Privacy Policy: policies.google.com/privacy

Google AdMob (Google LLC) Data Processor
Non-premium users may see interstitial ads powered by Google AdMob. If you grant permission through the iOS App Tracking Transparency (ATT) prompt, AdMob may use advertising identifiers to show personalized ads. If you deny ATT permission, non-personalized ads are shown and no advertising identifier is shared.
AdMob Privacy Policy: support.google.com/admob/answer/6128543

Apple Inc. Service Provider
We use Sign in with Apple for authentication, Apple HealthKit for optional workout sync, and Apple's push notification infrastructure. Apple processes data under its own privacy policy.
Apple Privacy Policy: apple.com/legal/privacy

We do not sell personal data to third parties. We do not use any additional analytics, advertising, or tracking SDKs beyond those listed above.

4. Data Retention

We retain your personal data for as long as your account is active. When you delete your account:

  • All Firestore documents (profile, workouts, stats, calibrations, slip-up history) are deleted immediately.
  • Your Firebase Authentication account is deleted immediately.
  • FCM push notification tokens are deleted as part of your user document.
  • Local offline cache on your device is cleared at the time of deletion.
  • Firebase may retain server-side logs for up to 180 days in accordance with Google's standard data retention policies.

If your account is inactive (no sign-in) for 2 years, we reserve the right to delete it and all associated data after providing 30 days' notice to your registered email address.

5. Your Rights Under GDPR

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights:

  • Right of access (Art. 15) — Request a copy of your personal data.
  • Right to rectification (Art. 16) — Correct inaccurate data. Use Settings > Edit Profile, or contact us.
  • Right to erasure (Art. 17) — Delete your account and all data via Settings > Account > Delete Account, or contact us.
  • Right to data portability (Art. 20) — Export your data as a JSON file via Settings > Account > Export My Data.
  • Right to restrict processing (Art. 18) — Request that we limit processing of your data in certain circumstances.
  • Right to object (Art. 21) — Object to processing based on legitimate interests (e.g., analytics). Toggle off Analytics in Settings > About & Legal.
  • Right to withdraw consent (Art. 7(3)) — Withdraw any consent you have given at any time without affecting prior processing. Use the toggles in Settings or contact us.

To exercise any of these rights, contact us at tryemberfitness@gmail.com. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority.

6. International Data Transfers

Your data is stored on Google Firebase servers, which may be located outside of the EEA (including the United States). Google processes this data under Standard Contractual Clauses (SCCs) that provide an equivalent level of protection to EEA data protection law. A copy of the applicable SCCs is available from Google at cloud.google.com/terms/sccs.

7. Children's Privacy

The App is not directed at children under the age of 13 (or 16 in certain EU member states). We do not knowingly collect personal data from children. If you believe a child has provided us with their data, contact us and we will delete it promptly.

8. Security

All data in transit is encrypted using HTTPS/TLS. Data at rest in Google Cloud Firestore is encrypted by Google. Camera-based pose detection is performed entirely on-device using Apple's Vision framework — no images or video are ever transmitted.

9. Changes to This Policy

We may update this policy as the App evolves. Significant changes will be communicated via an in-app notice or email to your registered address. Continued use of the App after the effective date constitutes acceptance of the revised policy.

10. Contact

For privacy-related questions, data requests, or complaints:
Email: tryemberfitness@gmail.com

© 2026 Ember Fitness. All rights reserved.

Privacy Terms Contact