Privacy Policy — HyperMass
Effective date: 2026-08-02 Publisher: Red Spectrum LLC (“we”, “us”, “our”) Contact: adrian.adduci@gmail.com
The short version
HyperMass is built to be private by default. Your workouts, routines, custom exercises, bodyweight log and other activity are stored only on your device. We do not run accounts or a server that collects your data, and the app does not use analytics, crash reporting, advertising, or tracking of any kind. The only information that ever leaves your device is (1) completed workouts you choose to sync to your phone’s health app, and (2) requests your device makes to download exercise images. Details below.
Who this policy covers
This policy applies to the HyperMass mobile app for iOS and Android, and to the static web pages where this policy and our Terms are published (see “This website” below). It does not cover third-party services the app connects to (Apple Health, Google Health Connect, the app stores), which have their own policies.
What data the app handles, and where it lives
Everything you enter or generate in the app is stored in a local database on your device and is not transmitted to us:
- Workout activity: sessions, sets (weight, reps, warmup flags), completion times, personal records.
- Routines & custom exercises you create.
- Body metrics: bodyweight entries you log, and a gender setting used to pick the correct anatomy illustration and default body map. (Gender and bodyweight are health-related information; they stay on your device.)
- Schedule & preferences: recurring training days, one-off calendar overrides, reminder settings.
- Notes you write: per-exercise and per-session notes. These stay on your device and are not monitored or reviewed by anyone.
We have no ability to see, retrieve, or back up this data. If you uninstall the app or clear its data, it is gone (subject to any backup your own device/OS makes — see “Device backups”).
Health data (Apple Health / Google Health Connect)
If you enable workout syncing, the app writes each completed workout to your platform’s health store:
- iOS (Apple Health / HealthKit): a workout sample with estimated energy burned.
- Android (Google Health Connect): an Exercise Session record and an Active Calories Burned record.
This is opt-in and controlled by a toggle in the app. This health data is stored in your device’s health app, governed by Apple’s or Google’s privacy terms — it is not sent to us or any server we control. We never store health data in iCloud or any cloud service of ours.
On iOS the app also declares the ability to read workout data (to avoid creating duplicate entries). Any such access happens only on your device and is subject to the permission you grant in the iOS Health permission screen. You can revoke health permissions at any time in your device’s Health/Health Connect settings.
Notifications
If you enable reminders, the app schedules local notifications on your device — workout reminders for your chosen training days and time, and rest-timer alerts during a workout. These are generated on-device. We do not operate a push-notification server, and no device token or notification content is sent to us or any third party.
Network requests (exercise images)
To show anatomy illustrations for exercises, your device downloads image files from our static image host (GitHub Pages, operated by GitHub, Inc.). These are ordinary web requests for image files named after the exercise. They contain no account or personal information, but as with any web request the host can observe standard technical metadata such as your IP address, the time of the request, and which image was requested. The host is used solely to deliver images and not to profile or track you. If an image is unavailable, the app falls back to a built-in muscle diagram and makes no further request for it.
What we do NOT do
- We do not require an account, login, email, or phone number to use the app.
- We do not collect, receive, or store your workout or health data on our servers.
- We do not use analytics, crash-reporting, advertising, or tracking SDKs.
- We do not sell, rent, or share your personal information. We do not engage in “sharing” for cross-context behavioral advertising as defined under California law.
Third parties
- Apple Health / Google Health Connect — recipients of workout data you choose to sync; controlled by you.
- GitHub, Inc. (GitHub Pages) — hosts our exercise images and these legal pages; sees technical request metadata only (see above).
- Apple App Store / Google Play — handle app distribution and any purchases under their own policies; they may provide us aggregate, non-identifying statistics (e.g., download counts).
We do not have data-sharing arrangements beyond these.
Device backups and exports
- Android: the app opts out of Android’s device backup (
allowBackupis disabled), so its local database is not included in Google device backups. - iOS: your device’s iCloud Backup may currently include the app’s local database as part of a full-device backup, depending on your settings. Those backups are encrypted and governed by Apple’s policies and your device settings, not by us. (We plan to exclude the app’s database from iOS device backups in a future update.)
- Your export files: the in-app “Export data” feature creates a plain-text JSON file containing your data. You choose where that file goes; store it somewhere you trust. Importing a backup replaces the app’s local data.
Data retention & deletion
Because your data lives on your device, you control retention and deletion:
- Delete individual items in the app where the UI allows.
- Clear the app’s data or uninstall the app to remove its local database from your device.
- Remove synced workouts in your device’s Health / Health Connect app.
We hold no copy to delete on your behalf. If you believe we hold any information about you, contact us at adrian.adduci@gmail.com and we will respond.
This website
The pages where this policy and our Terms are published are plain static files served over HTTPS. There are no accounts, no logins, no forms, no cookies, no analytics, and no advertising or tracking of any kind on them. As with any website, the hosting provider (GitHub Pages) processes standard technical request data — your IP address, the time of the request, and which page you requested — in order to serve the page to you.
These pages never receive any data from the app. Opening them from the app’s “About & Legal” screen simply opens the page in your browser; nothing about you or your training is sent with the request beyond the ordinary technical metadata above.
Children’s privacy
HyperMass is not directed to children under 13 (or the minimum age of digital consent in your region, such as 16 in parts of the EU). We do not knowingly collect personal information from children. Because the app stores data only on the device and requires no account, it does not gather children’s data on our servers.
Your privacy rights (GDPR, UK GDPR, CCPA/CPRA, and similar)
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, and to object to or restrict certain processing. Because we do not collect or store your personal data on our systems, you can exercise the substance of these rights directly:
- Access / portability: your data is on your device in the app.
- Correction / deletion: edit or delete it in the app, or clear the app’s data.
- Objection / restriction / opt-out of sale or sharing: not applicable — we do not sell or share your personal information and do not process it for advertising.
To ask a question or make a request, email adrian.adduci@gmail.com. You also have the right to lodge a complaint with your local data-protection authority.
Legal basis (EEA/UK): where processing occurs, it is to provide the app’s core functionality at your request (contract) and, for optional features like health sync and reminders, your consent, which you can withdraw at any time via the in-app toggles and your device settings.
Security
Your data is protected primarily by your device’s own security (passcode, biometrics, OS sandboxing, and disk encryption). Because we do not transmit or store your data on servers, there is no server-side database of your information to breach. No method of electronic storage is perfectly secure; keep your device and OS up to date.
Changes to this policy
We may update this policy as the app evolves (for example, if we later add optional cloud features). We will revise the “Effective date” above and, for material changes, provide notice in the app or store listing. Continued use after an update means you accept the revised policy.
Contact
Questions or requests: adrian.adduci@gmail.com Red Spectrum LLC