Skip to content
Maxtopia

Privacy

An accurate policy — not a template. Here's exactly what we store server-side, why we store it, and what we don't.

Maxtopia stores server-side, in Cloudflare's US region:

  • Your account: email, sign-in provider (Apple, Google, or magic link), display name, date of birth (required for age gating), country code.
  • Your training: every workout, exercise, and set you log, plus every program you build or adopt. Older months roll off to a compact per-user archive in Cloudflare R2 that only you can read.
  • Nutrition: custom foods, diary entries, macro targets. Denormalized at logging time so editing a food later doesn't rewrite history.
  • Media: check-in photos and progress photos live in Cloudflare R2. Auto-deleted after 30 days (90 days on Coach). A legal-hold flag can be opened on a specific item during moderation review — only Maxtopia admin can release it.
  • Coach relationships: any coach ↔ client link you accept, with a per-relationship permission set that YOU (as the client) toggle.
  • Subscription state: what Apple, Google, or Stripe told us via their webhooks. We never see your card number or address.
  • Sync watermarks: per-device cursors so you can log offline and reconnect. Zero polling.

What we don't store

  • Your address, phone number, or payment details.
  • Raw HealthKit data — unless you explicitly toggle it on for coach visibility.
  • Product analytics inside the app. There's no telemetry beacon from the logging screen. AI calls emit one telemetry event with model + neurons + latency; that event does not include the content of your prompt or response.
  • Advertising identifiers, fingerprints, or third-party tracking SDKs.

What we do with it

  • Show it back to you across your devices via sync.
  • Fulfill coach visibility per the toggles you set (enforced server-side, not just hidden in the UI).
  • Verify entitlements when you use paid features.
  • Answer support tickets you file.

We do not sell your data, share it with advertisers, or use it to train third-party AI models. Cache hits from prior AI runs on shared items (like a barcode-keyed label result) are reused globally to save costs — those items don't identify you.

Age gate

Accounts under 13 are refused at signup. Accounts under 18 can log workouts, use nutrition, and coach — but they can't send or receive progress photos. Enforced on the server, not just in the UI.

Your rights

  • Export: Settings → Export produces a complete JSON archive of every row we hold about you across every table.
  • Delete: Settings → Delete account soft-deletes your record instantly and revokes your session. A scheduled purge job hard-deletes 30 days later, unless a legal hold is open.
  • Portability: programs and history round-trip through the CC0 .maxtopia format. You can leave whenever.

iCloud + HealthKit (iOS)

Optional iCloud backup, off by default, adds a second copy of your local data into your own private iCloud database. HealthKit access is granted per-permission by you; we request the minimum needed for the features you use.

App Store, Play Store, and web payments

Plus is billed by Apple on iOS, Google on Android, and Stripe on web. Coach and Coach Pro are Stripe-only. We never see your card — the payment processors handle it and tell us only whether a subscription is active.

This website

maxtopia.app uses Cloudflare Web Analytics, which is cookie-free and doesn't retain raw IP addresses or build a profile of you. It gives us only aggregate counts. No Google Analytics, no Meta Pixel, no advertising tracker on this site.

Contact

Questions or requests: privacy@maxtopia.app.

Changes to this policy

If this policy changes, we'll update the date below and describe what changed on the changelog.


Last updated: August 28, 2026