Squatoll Privacy Policy
Effective date: July 14, 2026
Squatoll ("Squatoll", "we", "us") is an iOS app that lets you earn screen time for selected apps by doing squats. This policy explains what information the app handles, what little of it ever leaves your iPhone, and the choices you have. The short version: Squatoll has no user accounts, your fitness and screen-time data stays on your device, your camera video never leaves your iPhone, and the only data we receive is anonymous usage analytics and crash reports.
1. Data that stays on your device
The following is stored only on your iPhone (in the app's private storage) and is never transmitted to us or anyone else:
- Camera video and body-pose data. Squat counting runs entirely on-device using Apple's on-device vision frameworks. Video is processed frame-by-frame in memory to detect your squat movement. It is never recorded, saved, or uploaded — by us or by Apple on our behalf.
- Your screen-time choices. The apps you choose to block are represented by opaque tokens provided by Apple's Screen Time (Family Controls) framework. By Apple's design, Squatoll cannot read which apps these are — we only receive anonymous tokens, and they never leave your device.
- Your activity history. Squat sessions, minutes earned and spent, your wallet balance, streaks, and awards.
- Your first name, if you optionally enter one in Settings. It is used only to personalize greetings and notifications on your device and is never sent anywhere.
Deleting the app deletes all of this data.
2. Data we receive
We receive two categories of data, both tied to a random app-generated identifier — not to your name, email, phone number, or Apple ID:
Usage analytics (PostHog)
To understand which features work and improve the app, we collect anonymous product events — for example: onboarding steps completed, a squat session finished (with rep count), a screen viewed, a pass started or paused, a subscription screen shown. Events include basic technical context: device model, iOS version, app version, and language. Analytics events never include your name, your camera data, or the identity of the apps you block.
Feedback you send
If you use "Send feedback" in Settings, the text you write is transmitted to us together with the anonymous identifier and app version. Please don't include personal information in feedback unless you want us to have it (for example, an email address if you'd like a reply).
Crash and error reports (Sentry)
If the app crashes or encounters an error, a technical report is sent to Sentry, our error-monitoring provider. It contains stack traces, device model, iOS version, and app state at the time of the crash — no fitness data, no camera data, no blocked-app identity.
3. Payments
Subscriptions are purchased through Apple. Apple processes the payment; we never see your payment details, billing address, or Apple ID. We receive only an anonymous confirmation of subscription status from Apple's StoreKit on your device.
4. What we don't do
- We do not sell your data, ever.
- We do not use your data for third-party advertising and we do not track you across other companies' apps or websites.
- We have no user accounts and no server-side profile of you.
- We do not knowingly collect data from children. Squatoll is intended for users aged 13 and over.
5. Legal bases (EU/EEA/UK users)
Where the GDPR applies, we process personal data on these bases:
- Legitimate interests (Art. 6(1)(f) GDPR): anonymous usage analytics and crash reporting, to maintain, secure, and improve the App. We chose the least intrusive setup we could: no accounts, a random identifier, EU-hosted processing, and no advertising or cross-app tracking.
- Performance of a contract (Art. 6(1)(b) GDPR): providing the App and your subscription.
- Consent (Art. 6(1)(a) GDPR): feedback you choose to send us. You provide it voluntarily and can request its deletion at any time.
We do not use automated decision-making or profiling that produces legal or similarly significant effects.
6. Service providers and international transfers
We use two processors, both bound by their own data-processing agreements:
| Provider | Purpose | Data |
|---|---|---|
| PostHog | Product analytics | Anonymous events, device/app context, feedback text |
| Sentry (Functional Software, Inc.) | Crash and error monitoring | Crash reports, device/app context |
Apple (App Store, StoreKit, Screen Time framework) processes purchases and enforces app blocking as part of iOS itself, under Apple's own privacy policy.
Where your data is stored. Our PostHog project is hosted on PostHog's EU cloud, and our Sentry project is hosted in Sentry's EU (Germany) data region — so analytics and crash data are stored within the EU. Where a provider's parent company is located outside the EEA (Sentry is a US company), transfers are safeguarded by the EU–US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses, as reflected in each provider's data-processing agreement.
7. Retention
Analytics and crash data are retained by our providers for a limited period (no longer than 24 months) and then deleted or aggregated. Data on your device stays until you delete the app.
8. Your rights
Your rights depend on where you live; rights granted by one region's law do not extend to residents of other regions.
If you live in the EU/EEA or UK (GDPR): you have the right to access your personal data, rectify it, erase it, restrict or object to its processing, withdraw consent (for consent-based processing, without affecting prior processing), and receive a copy in a portable format (data portability). You also have the right to lodge a complaint with your local data-protection authority.
If you live in California or another US state with a privacy law (CCPA/CPRA and similar): you have the right to know what personal information we collect, to request its deletion or correction, and not to be discriminated against for exercising these rights. We do not sell or share personal information as those terms are defined in the CCPA, so no opt-out is needed.
Everywhere: because the data we hold is keyed to an anonymous identifier, the most effective controls are in your hands — deleting the app removes all on-device data and stops all collection. For anything else, including deletion of analytics or feedback data, contact us and we will honor your request within 30 days.
9. Security
Data on your device is protected by iOS's sandboxing and encryption. Data in transit to our providers is encrypted with TLS.
10. Changes to this policy
If we change this policy, we will update this page and the effective date. If a change meaningfully expands what we collect, we will inform you in the app before it takes effect.
11. Controller and contact
The data controller responsible for the processing described in this policy is:
Rashem Pandit Vorbergstr. 10A 10823 Berlin, Germany hello@squatoll.com
This policy is provided in several languages for convenience; in case of discrepancies, the English version prevails.