Privacy Policy
MuscleMap
Last updated: May 5, 2026
Anthony Colon Dominguez ("we," "our," or "us") built MuscleMap to help you
log workouts and visualize muscle recovery. This Privacy Policy explains
what information the app handles, who else receives it, and the choices
you have.
Quick Summary
-
You can use the core app without an account; data stays on your device.
-
If you create an account, we store your email with our auth provider so
you can sign in across devices.
-
If you tap Backup, we store your workout history in the cloud so you can
restore it later.
-
If you subscribe to Premium, billing is handled by Google Play;
subscription state is tracked by RevenueCat.
- We collect crash reports through Sentry to fix bugs.
-
We do not sell your data, do not show ads, and do not track you across
other apps.
-
You can delete your account and all cloud data from inside the app at
any time.
Information We Collect
Information You Provide
The following data is entered by you in the app:
-
Profile: name, birth date, height, weight, fitness
goals, experience level
-
Workouts: exercises performed, sets, reps, weights,
durations, notes
- Custom exercises and templates you create
-
Body measurements: weight, body fat, body part
measurements
-
Personal records (PRs): automatically tracked from your
workout performance
-
Account credentials (only if you choose to create an
account): email address and password
Information Collected Automatically
-
Device and app metadata: device model, operating system
version, app version, language
-
Crash reports: stack traces, error context, breadcrumb
logs of recent in-app actions (see "Sentry" below)
-
Subscription state: if you purchase Premium, the active
entitlement, plan type, and renewal status
How We Use Your Information
-
To provide the app's core features (workout logging, muscle map,
history, ranks)
-
To back up and restore your data across devices when you sign in and tap
Backup
-
To verify Premium entitlement so paid features unlock for paying
subscribers
-
To diagnose crashes and stability issues so we can fix them in future
versions
-
To send a local notification one day before your free trial ends, so you
can decide whether to continue
We do not use your data for advertising, profiling, sale to third parties,
or any purpose unrelated to running the app.
Third-Party Service Providers
MuscleMap relies on the following companies to operate. Each one receives
only the data described, and only when needed for that function. Each
company has its own privacy policy linked below.
Supabase (authentication and cloud backup)
If you create an account, your email and password are sent to Supabase for
authentication. Passwords are hashed by Supabase on their servers; we
never see, log, or store the plaintext password.
If you tap Backup, the contents of your local workout database (sessions,
sets, exercises, templates, measurements, achievements, PRs, and profile
fields) are stored in a single row associated with your account in a
Supabase Postgres database, protected by row-level security so other users
cannot read it.
Supabase privacy policy:
https://supabase.com/privacy
RevenueCat (subscription state)
If you subscribe to Premium, RevenueCat tracks your subscription status
(active, expired, in trial, will renew) so the app can unlock the right
features on each device. RevenueCat receives your account identifier (a
random ID issued by Supabase) and basic device characteristics (model, OS
version) needed to reconcile purchases with your account. We do not send
your email, name, or other profile fields to RevenueCat.
RevenueCat privacy policy:
https://www.revenuecat.com/privacy/
Google Play Billing (payment processing)
All payments for Premium are processed by Google Play Billing. We never
see, store, or have access to your payment instrument (card number,
billing address, etc.). Google Play sends us only a confirmation that a
purchase was made, which RevenueCat translates into your entitlement
status.
Google Play Billing privacy:
https://policies.google.com/privacy
Sentry (crash reporting and diagnostics)
Sentry receives crash reports and diagnostic events when the app
encounters an error. Each event includes:
- The exception or error stack trace
- Device model, OS version, and app version
-
Breadcrumb logs of recent in-app actions (for example: "auth deep link
received," "purchase reconciled," "trial reminder scheduled," "upgrade
screen viewed")
-
Your account identifier (the Supabase-issued user ID), used so we can
group multiple crashes from the same device together. We do not send
your email or name to Sentry.
-
A tag indicating whether you are a Premium subscriber, used to filter
crashes by tier
Sentry does not capture screenshots of your screen or
copies of the app's view hierarchy. We have explicitly disabled both
attachments.
Sentry privacy policy:
https://sentry.io/privacy/
Subscription Billing
MuscleMap Premium is sold as an auto-renewing subscription through Google
Play. You can subscribe inside the app from the upgrade screen.
-
Plans: $4.99/month or $29.99/year. The yearly plan
includes a 7-day free trial for first-time subscribers.
-
Renewal: Subscriptions renew automatically at the end
of each period unless cancelled.
-
Manage or cancel: Open Google Play Store → Account
→ Subscriptions. The app provides a "Manage subscription" link that
opens this page directly.
-
Refunds: Handled by Google Play under their standard
refund policy.
Data Storage and Security
If You Use the App Without an Account
All of your data is stored locally on your device using on-device storage.
Nothing is transmitted to our servers. If you uninstall the app or clear
its data, all stored information is permanently deleted.
If You Sign In
Your email and authentication tokens are stored on your device in
encrypted form (managed by the Supabase SDK). Your account credentials
live on Supabase's servers.
If You Tap Backup
The contents of your local workout database are uploaded to Supabase and
associated with your account, so you can restore them on a new device.
Your backup is protected by row-level security: only requests
authenticated as your account can read or write it.
Encryption
All data transmitted between the app and our service providers (Supabase,
RevenueCat, Sentry, Google Play) is encrypted in transit using HTTPS/TLS.
We do not implement certificate pinning.
Account Deletion
You can delete your account from inside the app at any time. The path is:
Profile → Account → Delete Account.
Deleting your account permanently:
- Removes your authentication record from Supabase
- Removes your cloud backup (if any) from Supabase
- Clears all locally stored data on your device
Important: deleting your account does not cancel an
active Premium subscription. Google Play continues to bill you separately.
To stop the charges, cancel your subscription in the Play Store before
deleting your account. The app warns you about this before allowing
deletion.
If you cannot access the in-app deletion flow for any reason, email
musclemapsupport@gmail.com
and we will manually process your request.
Data Retention
-
Local data on your device: retained until you uninstall
the app or clear its data.
-
Cloud backups (Supabase): retained until you delete
your account or overwrite the backup by tapping Backup again on a
different device.
-
Subscription records (RevenueCat and Google Play):
retained according to each provider's standard policy. Google Play
retains transaction records as required by tax and accounting
regulations even after account deletion.
-
Crash reports (Sentry): retained up to 90 days, as
configured by our error monitoring provider, then automatically purged.
Your Rights
Depending on where you live, you may have rights under privacy laws such
as the European Union's General Data Protection Regulation (GDPR) or the
California Consumer Privacy Act (CCPA). These typically include:
-
Right of access: request a copy of the personal
information we hold about you.
-
Right of correction: request that we update incorrect
or incomplete information.
-
Right of deletion: request that we delete your personal
information. The in-app account deletion flow described above is the
primary mechanism.
-
Right of portability: request a machine-readable copy
of your data. Premium users can use the Data Export feature in-app;
free-tier users can email the address below to request an export.
-
Right to object: request that we stop processing your
data for specific purposes.
To exercise any of these rights, email
musclemapsupport@gmail.com.
Information We Do Not Collect
- We do not collect your location.
- We do not access your camera or microphone.
- We do not show advertisements.
- We do not sell or rent your personal data to anyone.
- We do not track you across other apps or websites.
-
We do not use third-party advertising or analytics SDKs (Google
Analytics, Facebook SDK, etc.). The only data leaving your device goes
to the providers listed in "Third-Party Service Providers" above, for
the purposes described there.
Children's Privacy
MuscleMap is a general-audience fitness app and is not directed at
children under the age of 13. We do not knowingly collect personal
information from children under 13. If you are a parent or guardian and
believe your child has provided us with personal information, please
contact us at
musclemapsupport@gmail.com
and we will delete the information.
Changes to This Privacy Policy
We may update this Privacy Policy as the app evolves (for example, when we
add a new feature that handles data differently). Material changes will
update the "Last updated" date at the top of this page. We recommend
reviewing the policy periodically.
Contact Us
Questions, concerns, or rights requests:
Email:
musclemapsupport@gmail.com