1. Who we are
Aaron Rockett, trading as PunchMate, is the controller responsible for personal information handled through PunchMate. You can contact us at aaron.rockettapps@gmail.com.
This policy covers the PunchMate iPhone app and PunchMate's public support and privacy pages. PunchMate is a general fitness app. It does not use HealthKit, the camera, the microphone, motion sensors or location permissions, and it does not detect your strikes or correct your form.
The public support and privacy pages are static. PunchMate does not place advertising or analytics cookies on those pages.
2. Information we handle
| Information | When and why it is handled |
|---|---|
| Profile and preferences | Your fitness goal, experience, stance, callout style, safety acknowledgement, haptic setting and audio levels personalise the app. They remain on your iPhone unless you choose cloud sync. Safety acknowledgement and analytics consent are never synced. |
| Workout history | PunchMate stores workout identifiers, discipline, dates, elapsed and planned time, completed rounds, completion feedback, effort and prescribed strike counts so it can show progress. This stays on your iPhone unless you choose cloud sync. |
| Account information | If you choose Sign in with Apple, Apple may provide your name, email or private relay email. Firebase Authentication creates a user ID so your cloud history can be secured and synced. |
| Subscription information | Apple processes payment. RevenueCat receives an App Store receipt, purchase and subscription status, a customer identifier, and limited technical information so PunchMate can unlock and restore Pro, prevent fraud, and understand subscription performance. We do not receive your card or bank details. |
| Product and Apple Ads analytics | Only if you opt in, Firebase Analytics receives pseudonymous events about onboarding, workout and paywall interactions, purchase results, experiments and audio errors. Apple may also tell PunchMate whether an install came from one of our Apple Ads campaigns and provide campaign, ad-group, keyword, claim, conversion and placement information. We use this to measure our own advertising and exclude names, email, authentication IDs, free text, body measurements and full workout records. The raw Apple attribution token is never stored or sent to Firebase. |
| Crash diagnostics | Only if you opt in, Firebase Crashlytics receives crash stack traces, relevant app state and technical device, operating-system and app information so we can diagnose faults. |
| Essential configuration data | Firebase Remote Config receives country code, language, time zone, operating-system version, app identifiers and an installation identifier. This provides safe presentation settings. It never changes workout technique or safety content. |
| Support messages | If you contact us, we receive the contact details and information you choose to include so we can reply and resolve your request. Please do not send medical information. |
3. Why we use information
Where UK or European data-protection law applies, we rely on the following legal bases:
- Contract: to provide workouts, local and optional cloud history, authentication, subscriptions, restore and customer support you request.
- Consent: to run product analytics, Crashlytics and measurement of PunchMate's own Apple Ads campaigns. You can withdraw this at any time in PunchMate Settings.
- Legitimate interests: to secure, maintain and troubleshoot the app, provide conservative Remote Config presentation defaults, prevent fraud and answer support requests. We balance these interests against your rights.
- Legal obligation: where records must be retained to comply with tax, accounting, consumer-protection or lawful-request requirements.
Providing profile information, creating an account, enabling analytics, and contacting support are optional. An App Store receipt and related subscription information are required only if you buy, restore, or use PunchMate Pro. If you do not provide optional information, the relevant optional feature will not be available, but you can still use PunchMate's free local features.
We do not make decisions based solely on automated processing that produce legal or similarly significant effects. Home recommendations, Remote Config assignments, and merchandising experiments only change presentation inside PunchMate.
We do not sell personal information. We do not share personal information for cross-context behavioural advertising, and we do not use or share workout, fitness, account, purchase or analytics information for third-party advertising, advertising audiences or cross-app tracking.
4. Service providers
We use providers that process information for us to deliver PunchMate:
- Apple: Sign in with Apple, App Store purchases, subscription management, distribution and, only with analytics consent, first-party Apple Ads attribution. See Apple's privacy policy.
- Google Firebase: optional authentication and Firestore sync; essential Remote Config; and, only with consent, Analytics and Crashlytics. See Firebase privacy and security.
- RevenueCat: subscription receipt validation, customer entitlement, purchase and restore handling, fraud prevention, and subscription reporting. See RevenueCat's privacy policy.
We require service providers that handle personal information for PunchMate to provide the same or an equivalent level of protection described in this policy and required by applicable law. They may process information in the United States and other countries. Where required, transfers are covered by adequacy regulations, contractual protections such as standard contractual clauses or the UK addendum, and the providers' data-processing terms. Contact us if you would like more information about applicable safeguards.
5. How long information is kept
- Local profile and workout history remain on your iPhone until you remove them by deleting the app.
- Synced profile, workout history and Firebase account information remain until you delete your cloud account, subject to provider backup-removal periods and records we must retain by law.
- Consented Firebase Analytics event data is retained for no longer than 14 months.
- Firebase states that Crashlytics stack traces and associated installation identifiers are retained for 90 days before removal begins.
- RevenueCat subscription records are kept while needed to provide and restore entitlements, analyse subscription performance, resolve billing issues, prevent fraud and comply with legal obligations. RevenueCat may retain records for longer where required by its contractual or legal obligations.
- Support correspondence is normally deleted within 24 months after the request is closed unless it must be kept longer for a dispute or legal requirement.
6. Your choices and rights
Use PunchMate without an account
You can complete onboarding, use free content, subscribe and keep local history without signing in.
Analytics consent
Turn “Share pseudonymous analytics” off in PunchMate Settings at any time. This stops future Analytics and Crashlytics collection. It does not automatically delete information already processed; contact us to make a deletion request.
Cloud history and account deletion
Sign out to stop cloud use while retaining the local copy. Choose Settings › Cloud history › Delete cloud account to remove your Firebase account and synced history. Local history remains on your iPhone. Deleting a PunchMate account does not cancel an App Store subscription; manage billing in Apple subscription settings.
Data-protection rights
Depending on where you live, you may have rights to access, correct, erase, restrict or object to processing, withdraw consent, and receive a portable copy of your information. You may also have the right to appeal our response. Email aaron.rockettapps@gmail.com. We may need to verify your identity before completing a request.
Your right to object: where we rely on legitimate interests, you may object to that processing by contacting us. We will stop unless we demonstrate compelling legitimate grounds or the information is needed for legal claims.
If you are in the UK, you may complain to the Information Commissioner's Office. If you are in the EEA, you may contact your local data-protection authority.
7. Security
We use platform authentication, access-controlled Firestore rules and encrypted network connections. Firestore documents are restricted to the authenticated user's document tree. No system can be guaranteed completely secure, so please contact us if you believe your information or account has been compromised.
8. Children
PunchMate is a general-audience fitness app and is not directed to children under 13. A parent or guardian should decide whether the workouts are suitable for a younger person and supervise exercise where appropriate. A person who is below the age at which they can consent to data processing in their country should not enable analytics or create a cloud account without valid permission from a parent or guardian. Contact us if you believe a child supplied personal information without valid permission.
9. Changes to this policy
We may update this policy as PunchMate changes. We will publish the revised date here and provide an in-app notice when a change materially affects how personal information is used.
10. Contact
For privacy questions or rights requests, email aaron.rockettapps@gmail.com.
Aaron Rockett
Trading as PunchMate
United Kingdom