Skip to content

Legal

Privacy Policy

The formal document. For the plain-English explanation of how the encryption actually works, read the privacy explainer.

Last updated · 14 September 2026

1. The short version

Your session log is encrypted on your device before it is synced. We hold ciphertext and no key, so we cannot read it. Your assessment answers stay in your browser unless you ask us to save a result. We run no advertising technology, we sell nothing to anyone, and you can delete everything in one tap.

2. Who we are

iSexercise is the controller of the personal data described here. Write to hello@isexercise.com with any question about this policy. We answer every message within one business day.

3. What we collect

  • Account data. Your email address, and a password hash if you sign up with a password. If you sign in with Google we receive your email address and nothing else we ask for.
  • Subscription data. Plan, status and renewal date. Card details are handled by our payment processor and never reach our servers.
  • Encrypted session and score data. Stored as ciphertext we cannot decrypt.
  • Circle data. Your chosen handle, streak length, badges, program completions and PQ movement.
  • Marketing-page analytics. Only if you accept the consent banner, and only on public marketing pages.
  • Support correspondence. Whatever you choose to put in an email to us.

4. What we deliberately do not collect

  • Anything a microphone, camera or motion sensor could capture. Heart rate only.
  • Your partner's identity. We never ask, and there is no field for it.
  • Advertising identifiers, device fingerprints or cross-site tracking data.
  • Readable session content — occurrence, timing, duration, intensity or notes.
  • Assessment answers, unless you explicitly ask us to save a result. The assessment runs entirely in your browser.

5. Local-first storage and end-to-end encryption

Sessions and scores are written to your device first. When sync is enabled, they are encrypted on the device with a key derived from your passphrase and held only on your devices. Our servers store and return opaque ciphertext. This is an architectural property, not a policy promise: even under legal compulsion we could hand over only data we cannot read. The plain-English explainer walks through the mechanics.

6. Analytics, and the limits we put on it

We use Google Analytics 4 on public marketing pages only. It does not load at all until you accept the consent banner, and declining genuinely means no script and no cookies.

  • The script is blocked outright on the assessment, on every /app surface and on the thank-you page. This is enforced in code, not left to convention.
  • IP anonymisation is on. Google Signals and ad personalisation are off.
  • We record six events only: page view, assessment started, assessment completed, thank-you reached, pricing viewed and plan selected.
  • No PQ score, SQ score, assessment answer or session value is ever sent as an event parameter or a user property. There is a parameter allow-list in the code that makes this impossible rather than unlikely.

7. Legal bases for processing

We process account and subscription data to perform our contract with you; encrypted session data on the basis of your consent and your instruction to sync; analytics on the basis of your consent; and a minimal amount of security logging on the basis of our legitimate interest in keeping the service up and unabused.

8. Sharing

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We use a small number of processors — hosting, database, payment processing, transactional email and, with your consent, analytics — each bound by contract to process data only on our instructions. We will disclose data if legally compelled, and note again that encrypted session content is not readable by us and therefore not meaningfully disclosable.

9. Retention

  • Account and encrypted data: kept while your account is open.
  • After deletion: removed from live systems immediately and from backups within 30 days.
  • Billing records: kept as long as tax and accounting law requires.
  • Support email: kept for 24 months, then deleted.
  • Analytics data: retained for 14 months, the shortest GA4 setting.

10. Deleting your data

The one-tap purge lives in the app under Settings. It wipes the local log and instructs the server to destroy the stored ciphertext. It is available whether or not you are a subscriber, and it does not require you to talk to us first. If you would rather we did it, email hello@isexercise.com.

11. Your rights

If you are in the EU or UK, you have the right to access, rectify, erase, restrict, port and object to processing of your personal data, and to withdraw consent at any time and to complain to your supervisory authority.

If you are in California, you have the right to know, delete, correct and opt out of the sale or sharing of personal information, and not to be discriminated against for exercising those rights. We do not sell or share personal information, so there is nothing to opt out of — but the right stands.

Exercise any of these by emailing hello@isexercise.com. We respond within one business day and complete requests within 30 days.

12. Children

iSexercise is for adults. We do not knowingly collect data from anyone under 18, and we delete any such account on discovery.

13. International transfers

Our infrastructure runs in the United States and the European Union. Where data moves between them, it does so under Standard Contractual Clauses.

14. Changes

If we change this policy in a way that materially affects you, we will email you before it takes effect. The date at the top always reflects the current version.

This policy is published as a draft pending review by qualified counsel. It describes our actual practice honestly; it is not legal advice.

Free PQ assessment · 6 min

No account needed

Start