This policy explains the data used by the UpperMax iPhone app, the choices you have, and how to request deletion.
Nicolas Raillot operates UpperMax as an individual and is the data controller. Address: 290 rue Jean Moulin, 76770 Houppeville, France. Contact: dev@uppermaxapp.com.
UpperMax provides guided physique scans, physique analyses and four-week Focus Programs. Nutrition, food logging, dictation, Apple Health and step tracking are not available in the current product.
| Data | Purpose | Processing basis |
|---|---|---|
| Account identifier, sign-in provider, and the name and email supplied by Apple or Google | Secure your account and recover its data on another installation | Providing the service you request |
| Birth month and year, height, weight, training experience, goals, equipment and other profile answers | Check adult eligibility and prepare your physique analysis and Focus Program | Providing the service you request; explicit consent where the information reveals health data |
| Front, left-oblique and right-oblique body photographs; physique evidence, body-composition estimates, Frame grade and signal grades | Analyze your physique and preserve your own comparison history | Your consent to the analysis and, where these are health data, explicit consent under GDPR Article 9(2)(a) |
| Focus Program exercises, working sets, loads, repetitions, final-set effort, discomfort reports, session times and recorded progression | Record focus work, propose comparable exercise targets and show weekly and four-week summaries | Providing the service you request; explicit consent where the information reveals health data |
| App Store transactions and subscription status, including an account identifier used by RevenueCat | Unlock paid access, restore purchases and manage subscription access | Providing the subscription you request and meeting applicable legal obligations |
| Location while selecting a gym, and the gym name, address and coordinates saved on your device | Optional nearby gym search and gym arrival reminders | Your permission for these optional features |
| Installation and session identifiers, app and iOS versions, screens opened, onboarding interactions, scans and sessions completed, and subscription events | Understand use of the app and improve reliability and product flows | Legitimate interests where available under applicable law; see section 4 for timing, choices and limits |
| Crash reports, server error logs that may include an account identifier, installation identifiers used for integrity checks, and Firebase App Check tokens | Investigate defects, protect accounts and reduce abuse | Legitimate interests in operating a secure and reliable service, subject to applicable law |
| AI permission version, choice and timestamp; account deletion status and a minimal completion receipt | Honor your choices, enforce permission before analysis, and complete and confirm deletion | Honoring consent choices, providing requested deletion and documenting compliance |
Network metadata, including your IP address, reaches the services that receive requests from the app. UpperMax does not send precise gym coordinates or saved gym details to its analytics service. Apple processes map searches and optional arrival reminders. We do not request contacts, microphone, speech-recognition or Apple Health access.
Before a scan is uploaded or analyzed, UpperMax asks for your explicit permission to send the three body photographs to Google's Gemini AI service to analyze your physique. Photos are uploaded to private Google Cloud storage and submitted to Gemini for the requested analysis. UpperMax stores the resulting analysis with your account.
The scan preparation screen explains that tapping Continue allows UpperMax to share your three photographs and relevant profile and scan data with Google’s AI for physique analysis and personalized training explanations. You can leave using the back control without granting permission or starting an upload or analysis. The server records the permission version, your choice and the time. It checks this permission when an analysis starts or retries.
You grant permission on the scan preparation screen. You can withdraw it in Account and privacy, available during onboarding, from the purchase screen and in Profile. Withdrawal prevents new uploads and analysis requests. A request already sent to Google cannot be recalled. Withdrawal does not by itself erase an existing scan or its analysis; use scan or account deletion to request that removal.
Gemini output and the physique grades derived from it are estimates. They are not medical measurements or a diagnosis. UpperMax uses Google's paid Gemini service terms, under which prompts, files and responses are not used to improve Google's products. Google may retain inputs and outputs for security, abuse detection or legal obligations under its own applicable terms. UpperMax does not use your photographs to train its own models.
Usage analytics is enabled from app launch, including before sign-in. PostHog initially receives events associated with an installation identifier. When an account is created or signed in, the installation's analytics history may be linked to the UpperMax account identifier. Events include app lifecycle activity, screens, onboarding choices, completed scans, focus work and subscription changes. Context may include language, age and training-experience bands, training goals, scan count and derived physique grades.
We use PostHog's EU Cloud service. Session replay and screen recording are disabled. We do not send body photographs, raw body measurements, free-text entries or precise location to PostHog. This analytics use is for UpperMax, not advertising across other companies' apps or websites.
Turn off Usage analytics in Account and privacy to stop future optional analytics collection on that installation. The control is available during onboarding, from the purchase screen and in Profile. Turning it off does not erase previously received events. You can request their deletion by contacting us or deleting your account.
Our stated basis for limited service analytics is our legitimate interest in understanding use and improving UpperMax, where that basis is available. You may object to this processing. This basis does not override local requirements for consent, access to device storage, or processing health-related information. Availability of a settings switch alone is not a statement that collection without prior consent is permitted in every country.
Google Analytics for Firebase is disabled. Essential authentication, subscription and security requests continue when usage analytics is turned off.
| Service | Data and purpose | Processing locations |
|---|---|---|
| Google Firebase and Google Cloud | Authentication, profile and scan storage, Focus Program records, server processing, integrity checks, diagnostics and deletion jobs | EU, United States and other locations described by Google |
| Google Gemini | Body photographs and generated measurement evidence for the analysis you authorize | Locations where Google and its processors operate |
| PostHog EU Cloud | Usage events, installation and account identifiers and the limited context described above | European Union |
| RevenueCat | App Store transaction and subscription information associated with your UpperMax account | United States and other locations described by RevenueCat |
| Apple | Sign-in, App Store payments, push and local notifications, maps, optional location reminders, App Attest and Live Activities | As described by Apple's applicable privacy information |
| Google Sign-In | Authentication information when you choose Google sign-in | As described by Google's applicable privacy information |
Service providers may process data outside your country. Where applicable, transfers from the EEA require a valid transfer mechanism, such as an adequacy decision or Standard Contractual Clauses. Contact us for information about the safeguards relevant to your data.
| Data | Retention |
|---|---|
| Account, profile, physique analyses and Focus Program history | Kept to provide your account history until account deletion, subject to necessary legal retention |
| Scan photographs | Until you delete the scan or request account deletion |
| AI permission record | While needed to honor the account's current permission; removed with account data during deletion |
| Saved gym and local app or widget data | Until removed or replaced by you, or cleared as part of account deletion |
| Usage and diagnostic events | While needed for the purposes above, subject to processor retention settings and applicable legal limits. Account deletion includes deletion of associated PostHog events. |
| Active deletion job | Until the app can verify the required server and processor deletion steps. Failed steps are retained for retry. |
| Completed deletion receipt and server tombstone | 30 days after completion, then removed. These contain deletion status and minimal identifiers, not body photographs, profile answers or event history. |
| Records that must be retained by law | Only for the required period and purpose, such as an applicable accounting, fraud-prevention or legal obligation |
Historical nutrition records: nutrition and food logging are no longer available, but records created by an earlier version may remain in an account. Saved entries are removed with account deletion. Historical unfinished drafts have a 30-day retention threshold. Failed or abandoned meal photos have a 2-day threshold, with removal by the next daily cleanup. Successful photo analyses remove the temporary photo; failed immediate cleanup is retried by the scheduled cleanup. You can also contact us to request removal of historical records. We do not collect new nutrition entries, dictation or step counts through the current app.
Some providers may independently retain limited data to satisfy their own legal or security obligations. An UpperMax deletion receipt confirms completion of the deletion steps described below; it does not certify erasure of records a provider must lawfully retain independently.
Open Account and privacy from Profile, onboarding or the purchase screen and choose Delete account. Where required, confirm ownership with your existing sign-in provider. Apple sign-in authorization is revoked as part of the supported deletion flow.
Deletion is a background process. After a request is accepted, your access is closed and a local receipt lets you check its status after sign-out. The request stays pending until the service verifies the required removal of Firebase account data and stored files, PostHog person data and associated events, and the RevenueCat customer record. Failed processor steps are retried even when the app is closed. There is no guarantee that every external service completes removal immediately.
The receipt contains no scan photos or profile history. Keep its identifier if you need support. Completed receipts are available for 30 days. Requesting deletion is permanent once processing starts.
Deleting your UpperMax account does not cancel an App Store subscription. Manage or cancel it separately in iOS Settings › your name › Subscriptions. Apple processes payments and any applicable refund requests.
Depending on the law that applies, you may have rights to access, correct, export or delete your data, restrict or object to processing, and withdraw consent. Withdrawing consent does not affect processing already lawfully carried out. Email dev@uppermaxapp.com to exercise these rights. We respond within the applicable statutory period, normally one month for GDPR requests.
You can complain to the French supervisory authority, the CNIL, or the competent authority where you live. California residents may exercise applicable access, correction, deletion and opt-out rights without discrimination. UpperMax does not sell personal information or use it for cross-context behavioral advertising.
Network requests use TLS. Our infrastructure providers protect stored data, and server rules restrict account access. Firebase App Check helps validate requests from the app. No security measure can eliminate every risk.
Your scans are private. UpperMax does not publish them, use them in marketing or make them available to other users. If you choose Share, the exported image goes to the app or recipient you select through the iOS share sheet. Their handling of that copy is outside UpperMax's control.
UpperMax is for adults age 18 or older. Onboarding asks for birth month and year and blocks an under-18 selection. If you believe a child has provided data, contact us so we can investigate and remove it. A self-declared birth date is not a verified identity document.
We will explain material changes in the app. Changes that require renewed permission will be presented before the affected processing starts. Contact Nicolas Raillot at dev@uppermaxapp.com, or 290 rue Jean Moulin, 76770 Houppeville, France.