Ascent Mode privacy policy & data use
Current service notice · October 9, 2026 · Version 2026-10-09.4 · Standalone service
Ascent Mode stores your profile, training goals, workout sets and notes, and body measurements to provide your training plan, history and progress. Google Firebase handles sign-in. Ascent Mode receives your verified account identifier, sign-in email and available display name. Email/password sign-in and configured Google or Apple options are supported; Ascent Mode does not store your password.
Your records are protected by account access controls. Authorized Ascent Mode operators can review account names/emails, workout completion summaries, challenge participation and referral records to run and support the service. Optional Crew features share your nickname and challenge progress with participants. Phone-health imports need separate permission. Your workouts and body measurements are never used for marketing, sold, or shared for targeted advertising.
Setup entries, saved workouts and pending uploads can remain on this device. Anyone who can unlock it may be able to read them. Settings → Privacy lets you review your choices, export your data and delete your Ascent account.
Operator and privacy contact
Operated by Ascent Mode, LLC. For privacy questions or requests, email privacy@ascentmode.app. For account or app help, email support@ascentmode.app.
What we collect and why
Profile and account identifiers keep accounts separate. Goals, routines, sets, workout notes, recovery ratings and body measurements support training suggestions and progress. Optional Crew activity supports friendships, challenges and rewards. Device grants authorize the specific phone access you choose. Privacy records store your selected marketing channels, notice/wording versions, timestamps and changes.
Phone health data
Apple Health and Android Health Connect imports read supported body measurements only with your permission. Imports upload to your paired Ascent account when you tap Sync. Ascent doesn't write to your phone's health store. Workout access is a separate pairing choice; import-only grants are never upgraded automatically. You can disconnect a phone in Settings → Health connections or revoke health permissions in phone settings. Revoking access stops future access; existing imported records remain until you delete them.
Screenshots, offline storage and essential services
Screenshot text recognition runs on your device. Review extracted values before saving. Public workout code and exercise guides can be cached for offline use. Private snapshots, setup entries and queued sets stay in browser/app storage. Sign-out locks offline entry but doesn't erase every saved copy. Cloudflare Workers hosts this app and Cloudflare D1 stores its training records. Google Firebase Authentication processes sign-in identifiers, available provider names/emails, passwords when used, verification and recovery requests. Choosing a configured Google or Apple option also uses that provider to confirm your identity. Test environments use separate accounts unless you explicitly link an original profile through the transfer process. These services process information needed to operate, secure and troubleshoot the app. Requests may generate service logs, including request/network metadata.
Sharing and marketing
Service providers process data needed to run the app. Crew participants see your nickname and challenge progress when you enable Crew and join; they don't receive body measurements, loads, private workout notes or account contact details. The current app has no advertising or marketing analytics SDK, and does not sell personal data or share it for targeted advertising.
Email and promotional push preferences are separate and optional. They start off. Marketing delivery is currently disabled, and the saved choices are preferences only: fresh consent will be requested with the finalized publisher notice before marketing starts. Push also needs permission on each device. Health permissions, operating-system notification permission and agreeing to read this notice do not authorize marketing. In-app alerts appear while the app is open. Optional phone notifications use Firebase Cloud Messaging on Android and Apple APNs on iPhone, with generic alert text and a device registration token. Delivery requires provider configuration, separate category choices and phone permission. Those providers process the token and alert metadata. No background health uploads are enabled.
Restricted business records and referrals
Authorized operators can view and download names, sign-in emails, privacy choices, workout completion summaries, challenge participation and referral records for account support, service operations and promotion verification. Operator exports exclude workout loads, repetitions, private notes and body/health values. Feature-action reports include current usage-analytics opt-ins only. Access requires a server-authorized operator account and is logged by account, dataset, action, row count and time for up to 90 days. Downloaded files need separate protection and deletion handling. Promotional email lists stay unavailable until fresh campaign consent is collected; account records do not authorize promotional messages.
Referral verification uses an accepted friendship and the referred account’s first confirmed workout with a logged working set. When the offer is enabled, qualifying verified, distinct accounts receive 30 days of Pro access or a pending credit for their existing paid subscription. Pending billing credits do not stop renewals or change charges; the billing provider must confirm fulfillment. Earned credits for another account may retain an anonymous source reference after account deletion.
Optional product analytics
If you turn on usage analytics, Ascent stores a small set of feature-use and reliability events in its own Cloudflare D1 database with a 90-day rolling retention window. Cleanup runs when the service is used. A protected maintenance trigger supports scheduled cleanup; its operator schedule and infrastructure backup retention must be finalized before wider distribution. Setup steps are recorded only if you opt in at the end of setup. Events exclude lifted loads, repetitions, workout notes, body values, sleep/recovery ratings and phone health payloads. They are not sent to a marketing platform. Account identifiers keep analytics scoped to your account and support deletion. Settings → Privacy lets you turn analytics off and remove stored events. Training recommendations and saved review history remain separate service data, available in your export and account deletion.
Subscription records
Native checkout is limited to explicitly configured and authorized store sandbox testing. The current public build has no store products or authorized test accounts. Verified subscriptions are bound to your Ascent account. Subscriptions are purchased only through the App Store or Google Play; the website has no checkout. Payment details remain with the store. Ascent will retain subscription status and purchase references needed to deliver access and prevent duplicate claims. Production purchases remain unavailable. Store setup and sandbox device validation are required before checkout is enabled.
Retention, export and deletion
Your service records remain until you delete them or your account. Privacy preference history remains while the account exists and is included in your export. Settings → Privacy links to export and account deletion. Deletion removes the live profile, workout/body records, routines, privacy records and connections, phone notification registrations, delivery records and subscription references, and revokes paired phones. Anonymous completed challenge results may remain for other participants. A minimal account identifier and deletion time are retained to reject late writes that could recreate deleted data.
Deletion doesn't erase exported files, other devices' offline copies, or original Apple Health, Health Connect or scale-app records. Remove those copies separately. Infrastructure backup/log retention, processor terms and deletion propagation must be finalized with the operator before store release; a backup-purge deadline is not promised by this test notice.
Standalone account deletion also requests removal of your Firebase sign-in account after deleting live training records. Confirm your identity again using your current sign-in method: your password or the same Google or Apple account. Connecting another sign-in method requires your explicit choice and links that provider's sign-in identity to this Ascent profile; it does not merge separate profiles. If Firebase is unavailable, Ascent keeps the training account closed and shows a retry control until sign-in removal is confirmed.
Your controls and security
You can edit profile goals, review or remove body records, pause Crew, disconnect phones, withdraw either marketing preference, export your records and delete your account. Marketing withdrawal takes effect only after the server confirms it; offline changes are not silently queued as consent. Requests are tied to the signed-in/paired account and transported over HTTPS. Device grants are scoped and revocable. Protect devices and exported files; no service can promise absolute security.
Audience and changes
The intended launch market is the United States. Marketing signup and delivery are unavailable; creating a profile doesn't authorize promotions. The intended audience is adults. Launch states, audience eligibility and state-specific privacy requirements must be finalized before external beta enrollment. Material changes to data use require an updated notice and any new permissions or consent required for that use. Reading a notice isn't blanket consent to new purposes.
Consumer health data privacy · Manage or delete your account · Return to Ascent Mode