Legal

Privacy Policy

PointMeOut AB ("PointMeOut", "we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what personal data we collect, how we use it, when we share it, how long we keep it, and what rights and choices you have when you use the PointMeOut app and related services (the "Service").

1. Data Controller

PointMeOut AB is the data controller responsible for the processing of your personal data under this Privacy Policy.

PointMeOut AB
Magnoliagatan 25
256 68 Helsingborg
Sweden
Email: privacy@pointmeout.com

2. Scope

This Privacy Policy applies to personal data processed in connection with the PointMeOut mobile application, related services, customer support, community features, diagnostics, and communications with you.

It does not apply to third-party services, websites, or platforms that we do not control, even if they are linked to or integrated with our Service. Those services process personal data under their own privacy policies.

3. Personal Data We Collect

3.1 Account and Profile Information

We may collect account and profile information such as your email address, display name, profile photo, date of birth, and account credentials or authentication-related information.

3.2 Workout and Performance Data

We may collect workout and performance data such as workout type, duration, repetitions, workout history, progress, achievements, leaderboard participation, and AI-generated workout feedback.

3.3 Videos and Images

We may collect workout videos, images, and thumbnails that you choose to record or upload in connection with the Service.

3.4 Pose and Movement Analysis Data

We may process pose or movement analysis data to provide workout analysis and feedback. This processing takes place locally on your device.

PointMeOut does not use pose or movement analysis data for biometric identification or to uniquely identify you.

3.5 Apple Health / HealthKit Data

If you choose to connect Apple Health / HealthKit and grant permission, we may access health and fitness data that you specifically authorize, such as workouts, heart rate, exercise minutes, and active energy burned.

We use Apple Health / HealthKit data only to provide and improve the health and fitness features you choose to use, such as workout syncing, workout insights, and related in-app functionality. We do not use Apple Health / HealthKit data for advertising, marketing, or personalised advertising purposes.

Where Apple Health / HealthKit data constitutes health-related data or other special category data under applicable law, we process that data only as permitted by applicable law and, where required, based on your explicit consent.

3.6 Community and Social Data

If you use community features, we may process posts, comments, reactions, follows, blocks, reports, leaderboard participation, and your public or private profile setting.

3.7 Device, Usage, and Diagnostic Data

We may collect device, usage, and diagnostic data such as device type, operating system, app version, crash reports, diagnostics, and information about how the Service is used.

3.8 Subscription Data

If you purchase a subscription, we may process information necessary to manage your subscription status and provide premium access.

3.9 Sources of Personal Data

We collect personal data directly from you, automatically through your use of the Service, and in some cases from third parties that you choose to connect or use through the Service.

For example, subscription status and transaction-related information may be received from Apple in connection with App Store purchases, and health and fitness data may be received from Apple Health / HealthKit if you choose to connect it and grant permission.

3.10 Support Communications

If you contact us, we may process the information you provide in support requests and other communications with us.

4. How We Use Personal Data

We use personal data to:

  • provide, operate, and maintain the Service;
  • create and manage user accounts;
  • deliver workout tracking, workout history, and AI-based feedback;
  • sync data across devices;
  • enable community and social features;
  • process Apple Health integrations you choose to enable;
  • manage subscriptions and premium access;
  • communicate with you about your account, support matters, updates, and service messages;
  • detect, prevent, and investigate abuse, fraud, security incidents, and violations of our terms;
  • improve the functionality, reliability, and user experience of the Service; and
  • comply with legal obligations.

We do not use your personal data to train general-purpose AI models.

We process personal data only for the purposes described in this Privacy Policy and only where we have a valid legal basis to do so.

5. Legal Bases for Processing

Where GDPR, UK GDPR, or Swiss data protection law applies, we process personal data on one or more of the following legal bases, depending on the type of data and the purpose of processing:

Performance of a Contract

We process personal data where necessary to provide the Service you request, including:

  • creating and managing your account;
  • authenticating you and enabling login;
  • providing workout tracking, workout history, and core app functionality;
  • syncing your data across devices;
  • enabling subscriptions and premium access; and
  • providing community features you choose to use.

Consent

We rely on consent where required, including:

  • when you choose to connect Apple Health / HealthKit and authorise access;
  • where applicable law requires consent for personalised advertising, tracking technologies, or advertising-related identifiers;
  • where applicable law requires consent for certain optional processing activities; and
  • for certain marketing communications where consent is required.

Where Apple Health / HealthKit data constitutes health-related data or other special category data under applicable law, we process that data only as permitted by applicable law and, where required, based on your explicit consent.

You may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Legitimate Interests

We may process personal data where necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms. This includes:

  • maintaining the security, integrity, and reliability of the Service;
  • detecting, preventing, and investigating abuse, fraud, and violations of our terms;
  • moderating community content and handling reports;
  • debugging, troubleshooting, and improving app performance and user experience; and
  • operating and improving the Service efficiently.

Legal Obligation

We may process personal data where necessary to comply with applicable law, lawful requests, court orders, regulatory obligations, or legal reporting requirements.

6. Advertising and Consent Choices

If advertising is displayed in the Service, it may be provided through Google AdMob.

Where required by applicable law, we ask for consent before using advertising-related identifiers, tracking technologies, or showing personalised advertising.

On iOS, where applicable, we request permission through Apple's App Tracking Transparency framework before accessing the Identifier for Advertisers (IDFA) for tracking purposes.

We do not share HealthKit data, workout videos, or pose or movement analysis data with advertisers.

You can also withdraw or change advertising-related consent choices at any time through the app settings, where available, or through applicable device-level permissions.

7. Payments and Subscriptions

If you purchase a subscription through Apple's App Store, the purchase and payment transaction is processed by Apple.

We may receive limited subscription status information from Apple that is necessary to provide premium access, manage your subscription within the app, and handle support matters.

8. Sharing of Personal Data

We do not sell your personal data.

We may share personal data with the following categories of recipients where necessary to operate the Service:

Service Providers

We use service providers that process personal data on our behalf, including providers for infrastructure, database hosting, authentication, storage, diagnostics, crash reporting, email delivery, advertising, consent management, subscriptions, and platform distribution.

These providers may include, for example:

  • Supabase, for backend infrastructure, database services, authentication, and storage;
  • Amazon Web Services (AWS), as underlying infrastructure used by service providers;
  • Sentry, for crash reporting and diagnostics;
  • Resend, for transactional email delivery;
  • Google AdMob, for in-app advertising where enabled; and
  • Apple, for app distribution, subscriptions, platform services, and App Store-related transactions.

Other Users

If your profile or content is set to public, other users may be able to view information you choose to share through the community features.

Legal and Compliance Disclosures

We may disclose personal data where required to comply with law, lawful requests, court orders, or to protect our rights, users, or the public.

Corporate Transactions

We may disclose personal data in connection with a merger, acquisition, financing, reorganization, sale of assets, or similar corporate event, subject to appropriate safeguards.

9. International Transfers

Some of our service providers may process personal data outside your country of residence, including outside the EEA, the UK, or Switzerland.

Where personal data is transferred internationally, we take steps intended to ensure that appropriate safeguards are in place in accordance with applicable data protection law. Depending on the circumstances, these safeguards may include adequacy decisions, Standard Contractual Clauses, or other lawful transfer mechanisms recognised under applicable law, together with supplementary measures where required.

You may contact us at privacy@pointmeout.com if you would like more information about the safeguards applicable to your personal data.

10. Data Retention

We retain personal data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. In determining retention periods, we consider the nature of the data, the purpose for which it is processed, operational and security needs, legal obligations, and the need to establish, exercise, or defend legal claims.

In general:

  • account data, workout history, uploaded videos, and related user content are kept until you delete them or delete your account;
  • if you delete individual videos or other content, they are deleted from the active service environment without undue delay, subject to limited retention in backups, logs, and where necessary for legal, security, or fraud-prevention purposes;
  • if you delete your account, we will delete or anonymize your personal data without undue delay, except where retention is necessary for legal, security, fraud-prevention, or compliance purposes;
  • diagnostic and crash data is retained for a limited period in accordance with our service provider configuration and operational needs; and
  • backup copies may be retained for a limited period before being overwritten or deleted.

11. Data Security

We use appropriate technical and organizational measures designed to protect personal data, including measures such as encryption in transit, access controls, authentication safeguards, database security controls, and monitoring and security review procedures.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

12. Children's Privacy

PointMeOut is not intended for children under the age of 16.

We do not knowingly collect personal data from children under 16. If we learn that we have collected personal data from a child under 16 in violation of applicable law, we will take steps to delete that data.

If you believe that a child under 16 has provided personal data to us, please contact us at privacy@pointmeout.com

13. Your Rights

Depending on your location and applicable law, you may have the right to:

  • request access to your personal data;
  • request correction of inaccurate data;
  • request deletion of your personal data;
  • request restriction of processing;
  • object to certain processing;
  • withdraw consent where processing is based on consent;
  • request data portability, where applicable; and
  • lodge a complaint with a supervisory authority.

To exercise your rights, contact us at privacy@pointmeout.com or use available in-app controls where applicable.

We may need to verify your identity before fulfilling a request, particularly for requests involving access, deletion, correction, or portability of personal data.

We will respond to privacy rights requests within the time required by applicable law. Where permitted by law, we may extend that period, for example where a request is complex or where we receive multiple requests from the same individual.

These rights are not absolute. In certain circumstances, we may refuse, limit, or defer a request where permitted by law, including where necessary to comply with legal obligations, protect security, prevent fraud, or establish, exercise, or defend legal claims.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in the Service, our processing activities, or legal requirements.

If we make material changes, we will provide notice through the app, by email, or by other appropriate means where required by law.

15. Additional Information for Users in the EEA, UK, and Switzerland

If you are located in the EEA, the UK, or Switzerland, the following additional information applies:

  • Where applicable law requires a legal basis for processing, we rely on the legal bases described in Section 5.
  • Where Apple Health / HealthKit data constitutes health-related data or other special category data under applicable law, we process that data only as permitted by applicable law and, where required, based on your explicit consent.
  • If you have concerns about how we process your personal data, we encourage you to contact us first at privacy@pointmeout.com so we can try to resolve the issue.
  • You also have the right to lodge a complaint with a competent supervisory authority. For example:
  • if you are in Sweden, you may lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY);
  • if you are in the UK, you may lodge a complaint with the Information Commissioner's Office (ICO); and
  • if you are in Switzerland, you may contact the Federal Data Protection and Information Commissioner (FDPIC).

16. Contact

If you have questions about this Privacy Policy or want to exercise your privacy rights, please contact:

PointMeOut AB
Magnoliagatan 25
256 68 Helsingborg
Sweden
Email: privacy@pointmeout.com

If you are not satisfied with our response, you may lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) or your local supervisory authority.