Privacy Policy
Effective: 29 August 2026
Poise is built so that the data that matters most, your raw motion and moment-to-moment posture, is read on your device and never transmitted. Poise is provided by Aaron Lalor-Fitzpatrick, an independent developer based in Paraguay, who is responsible for the limited data described below.
What we collect
Here's everything, broken down by where it happens. The short version: your raw motion never leaves your device, and the rest is a limited set of data linked to random identifiers rather than to you, used to run your stats and improve Poise, plus attribution data.
Your raw motion stays on your device. The motion stream Poise reads to detect slouching, the moment-to-moment head angles it produces, and your calibration baseline are all processed entirely on-device. We never collect, store, or transmit your raw motion or the angles derived from it.
What we send to PostHog. To power your progress stats and community comparisons, and to improve Poise, we collect a small amount of data linked to a random, app-generated identifier rather than to you personally:
- your daily good-posture total (how long you held good posture each day), which drives your goals, achievements, and comparisons such as "better posture than 26% of users this week";
- usage statistics such as how long you use Poise and how many nudges you receive;
- the settings you choose, such as nudge sensitivity and hold timers.
About those identifiers. Poise generates two random identifiers. Neither is your name, email address, Apple ID, or an identifier belonging to your device, and they behave differently on purpose.
The analytics identifier is what everything described above is linked to. It is kept in the app's own settings storage, so deleting Poise erases it. Once it is gone, the analytics data left behind cannot be connected back to you.
The referral identifier is kept in your device's keychain, and it deliberately survives deleting and reinstalling the app. That is so a referral count or a promotional entitlement you have already earned is not lost when you reinstall. It is also the account id Poise gives RevenueCat for your subscription, and it is the key your referral code and nickname are stored under. Deleting the app does not erase it.
When you send feedback from inside the app, we attach the analytics identifier, so that we can see how Poise was being used when you reported a problem. Where you also provide an email address with your feedback, that submission is no longer anonymous to us.
Awards you unlock. When you bring Poise to the foreground, the app sends your analytics identifier and the list of awards that install has unlocked to a table hosted by Supabase. We use it for one thing: working out the percentage shown on an award's detail sheet, such as "Earned by 12% of Poise users". Only that aggregate is readable. Nobody can look up another person's awards, and there is no name or email on the row.
Because this data is tied to those identifiers and not to you, we cannot look it up from your name or email address. If you want it removed, see Deleting your data below.
Analytics on this website
This website uses Google Analytics 4 to understand how visitors find and use the page. Google Analytics is loaded only after you accept the cookie banner. If you decline, no analytics cookies are set and only anonymous, aggregate signals are sent to Google. Within Google Analytics we never see your IP address in full (it's anonymised), and we don't use this data for advertising. This applies to Google Analytics on this website only; other services we use handle IP addresses differently, as described in their own sections below.
This website also uses Vercel Speed Insights to measure how fast the page loads for real visitors. Speed Insights does not use cookies, does not identify users, and is enabled regardless of cookie consent.
Analytics in the app
The Poise app uses RevenueCat to manage your subscription and PostHog to understand aggregate app usage patterns. Alongside the data described above, PostHog may collect further details such as session length and which screens you open, all linked to the same analytics identifier, but never your name, contacts, or your raw motion stream.
PostHog also attaches basic technical details to every event: your device model, iOS version, app version, locale, timezone, screen size, and network type. This is standard analytics context that helps us tell a bug on one iOS version from a bug everywhere. Like everything else in this section, it is linked to the analytics identifier rather than to you.
For a small sample of sessions we also record an anonymised replay of the app screens and taps, to help us find where the app is confusing. Anything you type is masked and never recorded.
Those recordings also carry timing for the network requests the app makes during the session: the address requested, the status it came back with, how many milliseconds it took, and how many bytes moved. We do not record request headers, and we do not record the contents of any request or response. That is why nothing you write in a feedback message, and no key the app uses to talk to a service, can end up in a recording.
If the app crashes, PostHog sends us a crash report: the stack trace, the type of error, and your device and iOS version. Crash reports carry no content you have entered.
PostHog works out where your device is connecting from, using the IP address the request arrives with. The IP address itself is not kept: PostHog is set to discard client IP data, and the location lookup happens before that discard.
What is kept is the location that lookup returns, and it is worth being clear that this is more than your country. It can include your city, your state or region, your continent, your timezone, and a latitude and longitude, plus a postal code in countries where the lookup returns one. It is approximate rather than exact: it describes roughly where your network connection appears to come from, usually to within about ten kilometres, not where you are. We use it to understand where Poise is being used. Poise never requests or uses GPS or location services, and never tracks your movements.
Advertising attribution
If you install Poise after tapping one of our ads (for example on TikTok), we use Apple's SKAdNetwork to understand which campaign led to the install, so we can measure whether our advertising is working. This tells us things at the campaign level only, such as how many installs a given ad produced.
We do not collect Apple's advertising identifier (IDFA), and Poise does not track you across other apps or websites, so iOS does not ask you for tracking permission. Attribution relies only on Apple's privacy-preserving SKAdNetwork. We never use this to build an advertising profile about you, and we never sell it.
Contact form and in-app feedback
If you send us a message via the contact form, we receive the name, email address, topic, and message you submit. Submissions are delivered to us by a third-party form provider, Web3Forms, which also captures the sender's IP address so we can identify and block abuse. We use this information solely to reply to your message and to keep the form free of spam. We never share it with advertisers or use it for marketing.
You can ask us to delete the message thread at any time by replying to our response and requesting deletion. See Web3Forms' own privacy policy for details on how they process form submissions on our behalf.
In-app feedback. You can also send feedback from inside the Poise app. When you do, we receive the message you write, along with basic technical details such as your app version and device model (for example, "iPhone16,2"). The email field is optional: if you provide one, we use it solely to reply to you; if you leave it blank, your feedback reaches us with no contact details attached. Unlike the website contact form above, no name or topic is collected, and we do not store your IP address alongside your feedback. As with any internet service, Supabase records the IP address your request comes from in its own server logs, which it retains for a limited period for security and operational purposes.
Feedback you send, your referral code and its nickname, the rewards you've earned, and the awards you've unlocked are stored by Supabase, Inc. on servers in the United States.
Your referral code and nickname
If you share a referral code, you can set a nickname to go with it. The nickname is optional, you choose the text yourself, and it is stored with your referral code under your referral identifier. Anyone you share the code with sees it, so pick something you are comfortable showing them rather than your full name. You can change it or clear it at any time.
When someone tries to redeem a referral or promotional code, we record the attempt so that the same code cannot be used twice, and we record the IP address the request came from. The address is used for one thing: refusing more than thirty attempts from the same address in a minute, so that nobody can work through codes automatically. It is not linked to a name or an account, and we never use it for analytics or advertising.
These attempt records get pruned as the referral system is used, and we do not keep them beyond what stopping that abuse needs. You can ask us to delete them at any time.
Subscriptions
Subscription purchases are processed through Apple's App Store. Payment information is handled entirely by Apple and is never accessed by Poise.
No account required
Poise does not require account creation, and we never collect your Apple ID. The only information the app collects on its own is the limited data described above, linked to random identifiers rather than to you. We receive contact details only if you choose to give them to us, either by messaging us through the website contact form or by adding an email address to feedback you send from inside the app.
How long we keep data
- Your raw motion and the angles derived from it: stays on your device; deleted when you delete the app.
- Analytics data: stored by our analytics provider, PostHog, under their retention policy, currently up to 7 years. It is never linked to your name or Apple ID. You can ask us to delete it at any time (see Deleting your data), and deleting the app erases the analytics identifier on your device, so what remains cannot be connected back to you.
- Contact messages: kept only as long as needed to handle your enquiry, and deleted on request.
- In-app feedback: kept for as long as it's useful for improving the app, and deleted whenever you ask.
- Award unlocks, your referral code and its nickname: kept until you ask us to delete them.
- Referral redemption attempts, and the IP address recorded with them: pruned as the referral system is used, and deleted whenever you ask.
- Attribution data: SKAdNetwork reports are aggregated by Apple and are not tied to you.
Deleting your data
Your usage data isn't linked to your name, email, or Apple ID, so we can't find it from an email address alone. To request deletion, open Settings → Contact / Feedback in the app and ask us to delete your data. The message carries the analytics identifier for your install, which is what lets us find and remove the right records.
Deleting Poise from your device erases the analytics identifier, and once that is gone the analytics data left behind cannot be connected back to you. It does not delete anything by itself, and it does not erase the referral identifier, which stays in your keychain so that a referral count or promotional entitlement survives a reinstall. Your referral code, its nickname, and your award unlocks stay with it. To have those removed, ask us.
Children's privacy
Poise is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has provided us information through the contact form or in-app feedback, get in touch and we'll delete it.
Your rights
- You can stop using the app at any time and delete all local data by removing the app.
- You can cancel your subscription anytime through your Apple subscription settings.
- You can ask us to delete your app-usage data, as described in Deleting your data.
- If you have questions about your data, get in touch.
Your rights in your region
Depending on where you live, you may have additional rights over your personal data:
- EU / UK (GDPR): you can request access to, correction of, or deletion of your data, object to or restrict its processing, and request a copy of it. The legal basis for our limited processing is our legitimate interest in understanding and improving how Poise works, which covers the app-usage data, the awards you unlock, and the feedback described above. Your referral code and its nickname rest on a different basis: processing them is necessary to provide the referral feature you chose to use. The IP address recorded when a code is redeemed rests on our legitimate interest in preventing abuse of that feature. Website analytics rely on your consent. To object to app analytics, or to have app-usage data or feedback you have sent us deleted, message us from Settings → Contact / Feedback in the app, which is what lets us identify the right record. You can also complain to your local data-protection authority.
- California (CCPA/CPRA): you can request to know what personal information we hold, request its deletion, and opt out of any sale or sharing of personal information. We do not sell your personal information.
To exercise any of these rights, get in touch. We won't charge you or treat you differently for asking.
Changes to this policy
If we update this policy, we'll change the effective date at the top of the page. Material changes will be highlighted within the app.
Contact
For privacy questions, send us a message or email support@poise-app.com. To request deletion of your app-usage data, use Settings → Contact / Feedback in the app instead, for the reason explained in Deleting your data.