PlopFit Privacy Policy

1. Controller and contact

PE Matvienko Andrey Kirill, M. Khorenatsi str., bld. 26 a, 201 o, Yerevan, 0018, Armenia, is the controller for the processing described in this Policy. PlopFit is referred to as we or us.

For privacy or legal requests, email info@plopfit.com. For product support, email support@plopfit.com.

2. Scope and age

This Policy covers the PlopFit iOS app and the Marketing site at plopfit.com. The Service is offered worldwide without a geographic eligibility gate and is for people aged 18 or older. We do not request a date of birth solely to enforce this age rule and do not knowingly offer the Service to children.

3. Data we process

Account and identity data. PlopFit supports Sign in with Apple and Google sign-in. We receive the verified issuer and subject needed to map sign-in to an opaque internal user ID. We process account status, locale, timezone, authentication timestamps, required Terms and consent evidence, and privacy-workflow records. We do not use email to merge or link product accounts.

Workout and progress data. We process workout setup choices such as vibe position, space constraints, and disabled workout zones; generated sessions; workout and completion history; session-length feedback; retained XP; counted days; mini-game levels and awards; and badge progress. Some setup and history patterns may reveal health-related or body-limitation signals even though PlopFit does not ask for a diagnosis.

Subscription data. Apple processes purchases and payment details. RevenueCat processes the internal PlopFit user ID and subscription information needed to fulfill and reconcile access. PlopFit keeps a minimal subscription status and normalized provider references and events. We do not store payment-card details, Apple receipts, or raw RevenueCat payloads in product tables.

App analytics and diagnostics. After the app's authentication and required account-data gate open, eligible TestFlight or App Store builds may allow Firebase Analytics to process an approved allowlist of product interaction events tied to a pseudonymous analytics key. It does not receive raw PlopFit account IDs, submitted health-related setup choices, payment identifiers, or free text. Firebase Crashlytics processes crash and reliability diagnostics and ordinary app or device metadata needed to investigate failures.

Device-local data. The app keeps authentication credentials in protected device storage and may keep account-scoped preferences, workout-resume state, temporary export files, reminder settings, and deletion-confirmation state on the device. PlopFit clears applicable account-scoped local data on sign-out or account lock. Copies you export or share outside PlopFit are controlled by the destination you choose.

Marketing waitlist. If you join, we process your email, the waitlist-consent version, and server receipt time in a temporary waitlist record. SMTP2GO receives your email and generic message content to deliver confirmation and material waitlist or launch updates. PlopFit does not create a product account from a waitlist email.

Optional research. Only if you separately and explicitly consent, we may add an optional ISO country code and one allowlisted main-struggle answer to the same waitlist record and may send a generic research invitation. There is no free-text answer. In the ADHD-oriented context, the struggle choice may reveal a health-related inference. Declining or withdrawing research consent does not remove you from the waitlist.

Marketing analytics. Google Tag Manager and Google Analytics remain off unless you make a separate optional analytics choice. If accepted, Google receives page views, approved waitlist-journey events, the fixed prelaunch mode, and ordinary browser and network metadata. We do not send Google your waitlist submission, research answer, consent version, direct identifier, account data, or health-related data. Declining analytics does not affect waitlist use.

Support and operations. We process correspondence you send to our privacy, legal, or support addresses. We also process short-lived request information and minimized operational logs needed to secure and operate the Service. Marketing abuse controls use an IP address transiently without adding it to the waitlist record.

4. Why we process data

We process account, workout, subscription, and support data to provide the Service, perform our contract, respond to requests, and meet legal obligations. Required account-data consent records the user's direction to store the data needed to operate the account; withdrawing it starts account deletion because the account service cannot run without that data.

We rely on consent for waitlist email, separate explicit consent for optional research that may create a health-related inference, and separate consent for Marketing analytics. We use legitimate interests for minimal security, abuse prevention, reliability, service operations, crash diagnostics, and approved app product analytics where those interests are not overridden by your rights and consent is not required by applicable law. We do not sell personal data or use these data for third-party advertising.

5. Who processes data

Current external providers are Apple and Google for sign-in; Apple and RevenueCat for subscriptions; Google Firebase Analytics and Crashlytics for approved app analytics and reliability; SMTP2GO for approved email delivery; and Google Tag Manager and Google Analytics for consent-gated Marketing analytics.

These providers process data under their own infrastructure, terms, and security controls. Some processing may occur outside Armenia or the country where you live. Where required, we use applicable contractual or legal transfer safeguards and assess provider terms and access controls.

6. Retention and deletion

Account, workout, and progress data are kept while the account is active. An account-deletion request locks access during a 30-day grace period. When deletion processing runs, PlopFit deletes app-owned account, identity linkage, workout, progression, consent, and subscription-mirror data, asks current identity and subscription providers to delete the applicable user records, and keeps only narrowly required legal, dispute, security, or no-resurrection records. Non-statutory minimized subscription-event references may be kept for up to 24 months after account deletion or the last provider event, whichever is later.

Marketing waitlist records are kept until withdrawal or 12 months after receipt, whichever comes first. Minimized Marketing logs are kept for seven days unless an incident hold applies. Closed privacy and support correspondence is kept for 90 days unless a legal hold applies.

The Marketing analytics choice is kept in the browser for at most six months. Google Analytics event data uses a two-month retention period with reset disabled. Approved Firebase Analytics records are kept for no more than 24 months unless a later privacy review shortens that period. Crash diagnostics are kept only as long as needed to investigate and prevent recurring failures under the configured Firebase retention controls. Backups are protected and allowed to age deleted data out rather than restore it as active data.

7. Your choices and rights

Depending on applicable law, you may ask for access, a copy, correction, deletion, restriction, or objection, and you may withdraw consent. Withdrawing consent does not affect processing already performed lawfully.

Use the Account area in the app for account export, required-consent withdrawal, and account deletion. Deleting a PlopFit account does not cancel an Apple subscription or delete information Apple or Google keeps independently; manage Apple billing through Apple. Email info@plopfit.com for privacy requests concerning the app or Marketing site, including waitlist unsubscribe, waitlist deletion, correction, or research-only withdrawal. Use Analytics settings on the Marketing site to withdraw Marketing analytics consent and clear PlopFit-controlled analytics preferences and cookies.

We may need to verify that a request concerns you, but we do not request identity documents by default. You may complain to the data-protection authority that applies where you live or to the competent authority in Armenia.

8. Security

We use appropriate technical and organizational safeguards, including access restrictions, encrypted transport, data minimization, and secret-safe logging. We review and update these safeguards as the Service evolves.

9. Changes to this Policy

We may update this Policy. A material change to data, purpose, provider, retention, or rights receives a new version and, where required, notice and fresh consent. The effective date above identifies this version.

10. Contact details

Privacy and legal: info@plopfit.com
Support: support@plopfit.com
Postal address: PE Matvienko Andrey Kirill, M. Khorenatsi str., bld. 26 a, 201 o, Yerevan, 0018, Armenia.