Privacy policy
Your routine data should stay under your control.
SceneFit is designed for private routines, progress, optional session-adjustment details, and trusted-partner sharing you control. This policy summarizes what the app, server, public website, and support workflows collect and how that data is used.
Data SceneFit collects
- Account data such as user ID, Apple sign-in identifiers, display name, auth/session identifiers, and support contact details.
- Routine and progress data such as selected categories, protocols, schedules, completions, exercise logs, weekly reflections, milestones, and body check-ins.
- User content such as private notes, support submissions, and optional attachment metadata or objects if private attachments are enabled in the build you use.
- Trusted-partner data such as invite state, connection status, sharing settings, scoped previews, and revocation history.
- Subscription and entitlement data such as tier, trial, product ID, and App Store transaction identifiers when a user purchases or restores paid access.
- Device and security metadata such as request IDs, a stable app device ID, APNs device tokens for notifications, App Attest/device-trust records when enabled, audit events, and coarse diagnostics.
- First-party product analytics such as allowlisted screen/action events and coarse properties. SceneFit excludes private notes, body symptom text, attachment content, invite codes, partner names, and exact sensitive labels from analytics.
- Public website waitlist data such as email address, optional invite code, source metadata, and coarse site analytics.
Data SceneFit does not collect for the current app
- Device contacts or address book uploads.
- Precise or coarse location.
- Payment card details. Apple handles App Store payments.
- Public profiles, public feeds, random discovery, or public media browsing.
- Camera frames from QR invite scanning. Frames are processed locally and are not uploaded or stored.
- HealthKit reads. If Health export is enabled, SceneFit writes user-authorized workouts to the Health app and does not read or sync HealthKit data.
How SceneFit uses data
- Provide account access, sync, routines, schedules, session logging, progress, and content.
- Use reported session-adjustment details and keep age- or content-gated features behind required declarations and acknowledgments.
- Power trusted-partner sharing only when you enable specific scopes.
- Process export, deletion, subscription, notification, and support requests.
- Protect the service with authentication, authorization, audit logs, rate limits, and App Attest/device-trust checks when enabled.
- Improve the product using first-party, allowlisted analytics with opt-out support.
Trusted-partner sharing
- Sharing is off by default and invite-based.
- You choose each sharing scope and can preview what a partner can see.
- You can pause, revoke, remove, or block partner access.
- Partners cannot search for users, browse public profiles, change your routines, or see unshared notes, check-ins, attachments, or private categories.
Export, deletion, and subscriptions
- You can request data export and account deletion in the app.
- Export, deletion, and sharing revocation are not paid-only features.
- Deletion revokes sessions and partner access, removes or tombstones account data according to operational/legal needs, and removes private attachment objects where object storage is enabled.
- If you have an App Store-managed subscription, deleting your SceneFit account does not cancel Apple billing. The app links to Apple subscription management and asks you to acknowledge this before deletion proceeds.
- Minimal subscription, audit, deletion, and security records may be retained when needed for legal, accounting, abuse-prevention, or incident-response reasons.
Waitlist management and retention
- Waitlist submissions always receive the same public response. SceneFit does not reveal whether an email was already registered.
- Private links sent by email can update the address or platform preference, or unsubscribe. The management page does not display the current record and does not store the link token or entered email in browser storage.
- Active waitlist entries are retained for up to 365 days. Unsubscribe immediately removes contact and attribution fields; the redacted retry-safe tombstone is retained for up to 30 days before purge.
Site analytics
The public site and app use first-party, coarse analytics for product quality and launch planning. They do not send email addresses, private notes, invite codes, attachment contents, partner names, or private routine text to analytics.
Security and service providers
Production traffic should use HTTPS. SceneFit uses Cloudflare Workers, D1, R2, and Queue infrastructure for the server API, data storage, jobs, private attachment storage when enabled, and security controls. Apple services are used for Sign in with Apple, App Store purchases, notifications, HealthKit export, and App Attest when enabled. SceneFit does not use advertising or tracking SDKs in the iOS app.
Choices
- Control trusted-partner sharing in the app.
- Turn notifications on or off in the app and iOS Settings.
- Opt out of first-party analytics in app settings where available.
- Request export or deletion in settings.
- Contact privacy support for questions or rights requests.
Questions can be sent to privacy@scenefit.app.
Last updated: .