Wrist Trainer Privacy Policy

Effective date: August 18, 2026 · Version: 1.6 (current public version)

This is the current public v1.6 privacy policy, effective August 18, 2026. It describes the current account, membership, and on-device training data flows.

This policy applies to Wrist Trainer (the “App”). The App is an offline training aid that uses phone sensors to estimate phone posture relative to a calibrated position and help record repetitions.

1. Information processed on the device

During training, the App reads accelerometer and gyroscope motion samples to estimate movement angle and count repetitions in real time. Raw motion samples are processed only in device memory; they are not written to persistent storage or uploaded.

The App stores training summaries and preferences only on your device, including start and end times, target angle and repetition settings, completed counts in both directions, maximum estimated angle, theme, language, and orientation settings. The current version keeps up to 100 training summaries.

2. App accounts and sign-in information

Core training and local records do not require sign-in. If you voluntarily use Google Sign-In, the App sends the Google-issued ID token to the independent Wrist account service for verification and processes the Google account’s stable identifier, email address, display name, avatar URL, sign-in provider, and the Wrist-generated app account ID.

The Wrist account service runs on an independent Cloudflare Worker/D1. It stores the account, sign-in identity, HMAC-hashed session tokens, session expiry times, and membership verification snapshots. The original session token is stored only in the device’s secure system storage; server sessions expire after 30 days by default.

3. Android membership and purchase information

Signing in does not automatically start a membership. If you choose to purchase or restore after signing in, the App uses Google Play Billing and RevenueCat to process products, billing, and subscription status. The membership flow uses a stable appUserId generated by the Wrist service and does not create a new anonymous membership identity; the Wrist Worker verifies entitlements with RevenueCat, and only a verification result can grant Premium. Google Play handles payment methods and billing; the App does not read or store bank-card or other payment-instrument information.

Raw training sensor samples, training summaries, angles, counts, target settings, theme, and language are not sent to Google Play or RevenueCat and are not used as purchase-service Customer Attributes. Builds without membership configuration do not initialize the membership SDK; training, basic records, and local deletion remain available in that state, and the App does not pretend that a purchase exists.

4. Collection and permissions not included

Other than the account and Android purchase flows described above, the App does not include advertising, analytics, cloud sync for training data, social features, or tracking SDKs. We do not receive, sell, rent, or share your training data with third parties.

The App does not request camera, microphone, location, contacts, photos, Health Connect, or HealthKit permissions. Accelerometer and gyroscope access are not Android dangerous runtime permissions; iOS devices may manage motion-data access under system rules.

5. Retention and deletion

Training summaries and settings remain in the local app sandbox. You can delete all local training summaries from the Records page, or remove local data through the system’s clear-app-data function or by uninstalling the App; device backup settings may affect data retention after uninstall. Deleting local records does not delete Google Play or RevenueCat purchase history.

You can permanently delete your Wrist account in the App by opening Account, tapping Settings in the top-right corner, and choosing Delete account. This deletes the account, sign-in identities, sessions, membership cache, and associated webhook events in Wrist D1, and clears the secure session on the device. Local training records are not deleted. Transaction and security records retained by Google Play, Google, or RevenueCat under their rules or legal obligations are not affected. If you cannot enter the App, use the account deletion page to start a request.

6. Web access and support email

This privacy page is static and does not use advertising, analytics scripts, or cookies. For security and content delivery, the static hosting service may process necessary technical logs such as IP address, browser identifier, request time, and request path, and retain them under its applicable privacy policy.

If you voluntarily contact support, we process the email address, message content, and necessary reply records you provide only to respond to privacy questions, product feedback, or support requests.

7. Security and children

Local data is protected by the device operating system’s app sandbox, but no local storage can be guaranteed absolutely secure. The App is intended for adults, is not directed to children, and does not knowingly collect children’s personal information.

8. Medical and measurement disclaimer

The App is not a medical device. It is not intended to diagnose, treat, cure, or prevent any disease or medical condition and cannot replace advice from a doctor, rehabilitation professional, or other qualified healthcare professional. The displayed angle is an estimate of phone posture relative to calibration, not a clinical joint measurement. Stop training and seek professional advice if you experience pain, numbness, swelling, or other discomfort.

9. Policy updates and contact

If the App’s features, SDKs, or data processing change, we will update this policy before releasing the relevant version and keep the in-app explanation, store declarations, and actual behavior aligned.

For privacy questions, product feedback, or support requests, email mhgd3250905@gmail.com. For account deletion, please use the account deletion page.