Activiki

Privacy Policy

Last updated: 23 August 2026
Operator: Activiki
Contact: support@activiki.com

This policy describes how Activiki collects, uses, stores and shares information when you use the Activiki mobile app, this website, and related services (together, the “Service”).

1. What Activiki is

Activiki is a training app. It builds and adapts workout plans, logs sets, estimates strength per muscle group, and lets you import a plan from a photo. It does not track food or calories.

2. Information we collect

Account and profile

  • Email address, name or display name, and authentication identifiers if you create an account

  • Language and locale (including right-to-left layouts)

  • Subscription and purchase status from Apple or Google (we receive entitlement signals, not your full payment card number)

Training data you enter

  • Goals, experience, schedule, available equipment, session length, and plan settings

  • Exercises, sets, reps, load, rest, RPE / reps in reserve, supersets and rounds

  • Estimated one-rep max and per-muscle strength scores derived from your logs

  • Challenge participation and progress

This is fitness performance data. We treat it as sensitive and use it only to run the Service.

Photos (plan import)

If you use Photo Import, you choose an image from the camera or gallery. We process that image to read exercise names and structure so the plan can be matched to Activiki’s library. You review matches before saving.

We do not use import photos for advertising, facial recognition, or training unrelated models. Images are processed to complete the import and are not kept longer than needed for that purpose and for support if you report a failed import.

Website and support

  • Contact form submissions (message content and the fields you fill in)

  • Newsletter signup if you opt in

  • Basic technical logs: IP address, device/OS, app version, crash and diagnostics, approximate region

We do not collect dietary logs. We do not require government ID.

Information we do not sell

We do not sell your personal information.

3. How we use information

  • Create and adapt your plan, log sessions, and show strength and recovery

  • Authenticate you and restore purchases

  • Localise the app (English, Spanish, German, Persian)

  • Diagnose bugs and keep the Service secure

  • Reply to support mail and contact-form messages

  • Send product email only if you subscribed, with an unsubscribe on every message

  • Meet legal, tax, and store-review obligations

We do not use your workout history or import photos to build advertising profiles.

4. Legal bases (EEA / UK / Switzerland)

Where GDPR or UK GDPR applies, we process data on these bases:

  • Contract — account, plans, logging, photo import, subscriptions

  • Legitimate interests — security, abuse prevention, aggregated product metrics that do not identify you

  • Consent — newsletter, optional analytics/crash reporting where required, and photo access on device

  • Legal obligation — bookkeeping, responding to lawful requests

You can withdraw consent without affecting processing that already happened.

5. Sharing

We share information only with:

  • Infrastructure and hosting needed to run the app and website

  • Apple App Store and Google Play for distribution and in-app purchases

  • Email / support tools when you write to us

  • Authorities if required by law

Processors are bound to use data only on our instructions. We do not share training logs with advertisers or data brokers.

If we ever transfer data out of the EEA/UK, we use an approved mechanism (e.g. Standard Contractual Clauses) plus whatever extra steps the transfer needs.

6. Retention

  • Account and training history: while the account is open, then deleted or irreversibly anonymised within 90 days of a confirmed deletion request, unless a longer period is required by law

  • Import photos: only as long as needed to finish import and handle a related support ticket

  • Contact and support threads: up to 24 months after the last message, then deleted unless needed for a dispute

  • Newsletter: until you unsubscribe

  • Security and server logs: typically 90 days

7. Security

Access to production data is limited to people who need it to run or support the Service. Data in transit uses TLS. We still cannot promise that any internet service is invulnerable; if we learn of a breach that affects you, we will notify you and regulators as the law requires.

8. Children

The Service is not directed at children under 16 (or the higher age in your country). We do not knowingly collect their data. If you believe we have, email support@activiki.com and we will delete it.

9. Your rights

Depending on where you live, you may have the right to access, correct, delete, export, restrict or object to processing, and to withdraw consent. California residents have additional rights under the CCPA/CPRA, including to know, delete, and opt out of “sale” or “sharing” as those laws define them. We do not sell or share personal information for cross-context behavioural advertising.

To exercise rights, email support@activiki.com. We will verify the request and respond within the time the law allows. You may also complain to your local data-protection authority.

A shorter, user-facing summary of controls and requests is in user-privacy.md.

10. Device permissions

The app may ask for:

  • Camera / photo library — only for Photo Import, when you start that flow

  • Notifications — rest timer and training reminders, if you enable them

You can refuse or later revoke these in system settings. Core logging still works without camera access.

11. Third-party links

Store listings, social links, and other sites have their own policies. This document covers Activiki only.

12. Changes

We will update the date at the top when this policy changes. Material changes will be flagged in the app or by email if we have an address for you.

13. Contact

Activiki
Email: support@activiki.com