Privacy Policy
Last updated: September 1, 2026
This Privacy Policy explains how MoveShare collects, uses, discloses, retains, and protects personal data when you use the MoveShare iOS or Android app, visit moveshare.app, join our waitlist, or contact us (together, the "Service"). It also explains your choices and privacy rights.
The data controller and contact details are identified in section 15 below.
1. Personal data we collect
A. Account and profile information
- Authentication information: A Firebase user identifier and information provided by Google or Apple when you sign in, such as your email address, display name, and profile picture. Apple may provide some fields only the first time you sign in.
- Profile information: Your display name, profile picture, account creation date, and profile changes.
- Public profile: Your user identifier, display name, profile picture, and account creation date can be shown to other authenticated users so they can find and connect with you. Your email address is not included in your public MoveShare profile.
B. Health and workout information
If you choose to connect Apple Health or Android Health Connect, MoveShare first shows a contextual health-data disclosure and asks for your explicit consent. Only after you select "Agree and connect" does MoveShare request the separate operating-system permission. Depending on the workout and source, we process:
- Workout type or category, start and end time, and duration;
- Calories burned, distance, and elevation where available;
- Source and source workout identifier, used to identify the origin and prevent duplicate imports; and
- Limited workout metadata that may be supplied by the health platform, such as original workout type or weather-related workout metadata.
MoveShare requests read access for workout syncing and does not write health data back to Apple Health or Health Connect. We do not receive health records for categories you have not authorized. On iOS, Apple limits what apps can learn about a denied read permission, so an authorization response does not always prove that a particular category is readable.
Candidate workout details are sent to MoveShare's server so it can apply your Smart Sync rules. Workouts that do not match those rules are not stored or shared automatically; matching workouts are stored and used for the features described below. You can still choose to publish an individual non-matching workout yourself, which stores it in the same way.
You can choose whether automatic workout publishing is enabled and can limit supported publishing behavior in Settings. Revoking MoveShare's permission in Apple Health or Health Connect stops future reads but does not by itself delete workouts already imported into MoveShare. Separately, you can withdraw your MoveShare health-data consent in the app under Settings. Withdrawal stops health syncing and permanently deletes imported health workouts and their feed and kudos records, personal activity and record inputs, and your past goal result, streak, recovery, and freeze state. That history is removed in full, including progress you earned from manually entered workouts rather than from health data. Active goal progress is then recalculated from any manual workouts that remain. Your account, friendships, goal memberships, and the manual workouts themselves remain. The original workouts remain in Apple Health or Health Connect; if you later consent and connect again, eligible source workouts may be imported again. You may also delete supported individual workouts or your account.
C. Social, goal, and activity information
- Friend requests, friendships, invitations, invitation redemptions, and related timestamps;
- Workouts published to friend feeds, including the workout details described above;
- Kudos, selected encouragement messages, nudges, and notification activity;
- Goals, including titles, modes, workout categories, targets, time zones, participants, progress, cycle results, streaks, points, and freezes;
- Blocks and reports, including the reason and any details you add, the profile, photo, goal, or workout reported, the surface you reported it from, report status, moderation outcome, report-delivery information, and limited safety, abuse-prevention, and security logs; and
- Settings and preferences, including workout publishing choices and notification state.
D. Purchases and entitlements
If you use MoveShare Pro, we process subscription status and entitlement information such as product, store, environment, billing period type, activation status, and expiry time. Apple App Store or Google Play processes your payment details; MoveShare does not receive your complete card or bank-account details. RevenueCat helps us verify purchases and subscription access and sends us purchase-event records.
Android Early Access is not a purchase or subscription. If you activate or use it, we process its activation status, access source, and whether the request was verified as coming from our official Android app. We use this information to determine promotional eligibility, apply eligibility limits, prevent misuse, and secure the Service.
E. Notifications, device, and local app data
- Push-notification tokens, device identifier, platform, notification type, delivery-related information, read state, and notification-open events;
- Device and app information such as operating system, app version, language, and technical configuration; and
- Android app attestation: For Android Early Access, we use Google's app- and device-integrity services to verify that a request comes from our official Android app. We receive the verification result rather than your complete underlying integrity assessment, and use it for security, abuse prevention, and Android promotional eligibility.
- Information stored locally on your device, such as authentication state, health authorization state, workout-sync checkpoints, preferences, invite attribution, and widget snapshots. Some local information may remain until you sign out, clear app data, or uninstall the app.
F. Mobile product analytics
We use Amplitude in the mobile app to understand onboarding, feature use, invitations, goal adoption, and retention. Amplitude may receive a pseudonymous device identifier before sign-in and your Firebase user identifier after sign-in, together with event names, timestamps, session information, platform, app version, and tightly limited event properties.
We configure Amplitude not to collect advertising IDs, carrier, App Set ID, IDFV, IP-derived properties, device manufacturer, or device model. We may record whether the health-setup screen was viewed, connection was initiated, setup was skipped, setup completed, or setup did not complete. On Android, completion means the required access was available after the request. On iOS, completion of the authorization call does not prove read access. We do not send a per-permission grant or denial breakdown, requested health-data types, names, email addresses, profile pictures, messages, goal titles, invite codes, friend identifiers, workout-sync results, workout attributes, health-source names, exact workout quantities, or raw health values to Amplitude. Session Replay is disabled.
We also create a privacy-minimized server analytics dataset in Google BigQuery from our operational database. User-level rows and service-level measures are limited to non-health product activity such as account setup, friendships, invitations, goal actions, encouragement, retention, and subscription-entitlement changes. Individual workouts, workout attributes, health-connection state, and user-level goal-cycle results are not used for this analytics dataset. It is rebuilt daily rather than being a copy of Amplitude's raw events.
G. Diagnostics and security
We use Sentry to detect crashes, errors, app hangs, and operational problems. Diagnostic reports may include stack traces, error messages, warning or error logs, app and operating-system details, IP address, screen or operation context, and relevant account, workout, or goal identifiers. We do not intentionally include raw health records or user-written content in diagnostic context, but an unexpected error can sometimes contain information submitted to or returned by the Service.
H. Website, waitlist, and communications
- Waitlist and email: Your email address, optional name, subscription preference, and delivery information such as whether a message bounced.
- Support: Your contact details, the content of your message, attachments you send, and the information needed to respond.
- Website analytics: If you accept analytics cookies, Google Analytics 4 receives cookie or online identifiers, pages viewed, interactions, referral source, approximate location, browser/device information, and timestamps. We enable IP anonymization and disable advertising storage and personalization signals.
- Cookie preference: Your analytics-cookie choice is stored locally so the website can remember it.
2. How we collect data
We collect personal data:
- Directly from you when you create or edit a profile, configure sharing, create or join a goal, contact us, or join the waitlist;
- From your device and Apple Health or Health Connect when you choose to connect a health source and grant permission;
- From Google or Apple when you authenticate;
- From Apple App Store, Google Play, and RevenueCat in connection with purchases and entitlements;
- From Firebase App Check and Google Play Integrity when the Android app requests attestation for Android Early Access;
- From other users when they invite you, connect with you, add you to a goal, or interact with your shared activity; and
- Automatically from the app, backend, and website when you use the Service.
3. Why we use personal data and our legal bases
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Provide the Service and perform our contract: Creating and authenticating your account; importing workouts at your request; operating profiles, feeds, friends, goals, invitations, notifications, support, and subscription access; and enforcing the Terms of Service.
Legal basis: Article 6(1)(b), performance of a contract or steps you request before entering one. - Process health-related workout information: Reading and processing workout data after you deliberately accept MoveShare's health-data consent and separately grant the requested Apple Health or Health Connect permission, in order to import workouts and provide progress, feed, goal, sharing, and related features.
Legal basis: Article 6(1)(a) and, where workout information is special-category health data, explicit consent under Article 9(2)(a). You may withdraw this consent at any time in MoveShare Settings, without affecting earlier lawful processing. - Keep MoveShare secure and reliable: Preventing abuse and fraud, applying blocks and pairwise visibility rules, reviewing reports and evidence, verifying official Android app requests, determining Android Early Access eligibility, protecting accounts, maintaining logs, diagnosing failures, enforcing the Terms, and defending legal claims.
Legal basis: Article 6(1)(f), our legitimate interests in operating a safe and reliable service, and Article 6(1)(c) where processing is legally required. - Understand and improve the mobile product: Using privacy-minimized non-health product events and non-health service-level measures to understand onboarding, feature performance, retention, and technical quality.
Legal basis: Article 6(1)(f), our legitimate interests in improving the Service, subject to your right to object; and consent where applicable device-access law requires it. - Website analytics: Loading Google Analytics and setting analytics cookies after you accept them.
Legal basis: Article 6(1)(a), consent. Google Analytics is not loaded before you accept through our banner. - Waitlist and optional product updates: Managing your subscription and sending communications you requested.
Legal basis: Article 6(1)(a), consent. You can unsubscribe at any time. - Purchases, accounting, and compliance: Confirming entitlements, keeping transaction records, complying with tax, accounting, consumer-protection, and lawful authority requirements.
Legal basis: Article 6(1)(b), Article 6(1)(c), and our legitimate interests under Article 6(1)(f).
4. How information is visible to other users
- Authenticated users may find your public profile using your display name.
- Your friends may see workouts you publish, including workout type, timing, duration, calories, distance, source, available metadata, and the kudos attached to that workout.
- Goal participants may see the goal details, participants, relevant workouts, progress, results, streaks, and encouragement activity.
- Blocking filters future access between the two people involved: each person's name, avatar, activity, progress, and contribution to shared totals are hidden from the other, while other participants in a shared goal are unaffected. A block can also cancel a group goal you share.
- The creator of a group goal keeps a limited member-management view so a blocked membership can still be removed. A member the creator blocked may remain visible there by name and avatar; a creator who has been blocked sees only an unavailable member, and is not told who initiated the block. That view does not expose the blocked person's progress, workouts, or activity.
- People who receive an invitation link can see the invitation preview needed to decide whether to join. Links can be forwarded by recipients, so share them carefully.
- Removing a friendship, blocking, or leaving or ending a goal changes future access but cannot erase information someone already saw, saved, or shared outside MoveShare.
5. Service providers and data recipients
We do not sell personal data and do not use health information for advertising. We disclose personal data only as needed to operate the Service, as described below:
- Google Firebase: Authentication, push messaging, and Android app-integrity verification.
- Google Cloud: Backend hosting, object storage for profile pictures, task processing, scheduling, and privacy-minimized BigQuery analytics in the EU.
- Managed database hosting: Stores account, workout, social, goal, subscription-entitlement, and service records in a European region.
- Amplitude: Mobile product analytics in its EU data zone.
- Sentry: Mobile crash, error, log, and performance diagnostics.
- RevenueCat: Purchase verification, subscription status, paywalls, and entitlement management.
- Apple and Google: Sign-in, health-platform access, app distribution, in-app purchases, subscription management, operating-system services, and—on Android—Play Integrity app-integrity checks.
- Resend: Waitlist, welcome, report-notification, and other email delivery. Reports may be accessed by authorized MoveShare support or moderation personnel and service providers acting under our instructions.
- Google Analytics: Website analytics only after cookie consent.
These providers process data under their own privacy terms and, where they act on our behalf, under contractual data-protection obligations. You can review the privacy information published by Google, Apple, Amplitude, Sentry, RevenueCat, and Resend.
We may also disclose information when reasonably necessary to comply with law or a valid legal request, protect a person or the Service, investigate abuse, establish or defend legal claims, or complete a merger, financing, reorganization, or sale. If ownership changes, we will require the recipient to handle personal data consistently with applicable law and this Policy.
6. International data transfers
We select European regions for our core backend, Amplitude, PostgreSQL, and BigQuery services where available. Some providers and support operations may nevertheless process data in the United Kingdom, United States, or other countries. Where personal data is transferred outside the EEA, we rely on an adequacy decision, the EU-U.S. Data Privacy Framework where applicable, the European Commission's Standard Contractual Clauses, or another lawful transfer mechanism, together with supplementary safeguards where required.
7. Cookies and website analytics choices
Google Analytics is not loaded when you first visit the website. If you select "Accept" in the cookie banner, we load Google Analytics 4, set analytics storage to granted, and allow analytics cookies such as _ga. Advertising storage, ad personalization, and ad-user-data signals remain denied.
If you decline, the website does not load Google Analytics. You can withdraw or change your choice at any time using Cookie Settings. Withdrawing consent stops future website analytics collection on that browser but does not retroactively delete data already collected.
8. Mobile analytics choices
You may object to mobile product analytics by contacting us at hello@moveshare.app. Where applicable law requires consent for mobile analytics, we will provide the required choice before collecting non-essential analytics.
When account deletion begins in the app, MoveShare stops Amplitude collection on that device on a best-effort basis, detaches the account identity, and submits a durable deletion request from our backend. Deletions initiated outside the app are also submitted through the backend process.
9. Data retention and deletion
We retain personal data only for as long as needed for the purposes described above, including providing the Service, meeting legal obligations, resolving disputes, preventing abuse, and maintaining security. The period depends on the data:
- Account, workout, and social data: Generally retained while your account is active. You may delete supported individual workouts. Withdrawing health-data consent removes imported health workouts and the goal, streak, recovery, and freeze records described in Section 1.B from the operational database while keeping the account, friendships, goal memberships, and manual workouts. Limited residual copies may remain temporarily in protected backups until overwritten under normal retention cycles. Account deletion removes the operational PostgreSQL account and associated records through database deletion rules.
- Profile pictures and authentication: We request deletion of stored profile pictures and the Firebase authentication account when your MoveShare account is deleted.
- Amplitude: Account deletion submits an asynchronous user-deletion request. Amplitude states that completion can take up to 30 days.
- BigQuery: The analytics table is rebuilt from current operational data each day. A deleted account is omitted from the next successful rebuild, so its prior exported non-health rows disappear and non-health service-level measures are recalculated without its contribution.
- Purchase and webhook records: Some RevenueCat purchase-event and audit records may be retained after account deletion where needed for transaction integrity, fraud prevention, accounting, tax, legal obligations, or dispute handling. They are excluded from rebuilt analytics after the user account is gone.
- Android Early Access: The promotional entitlement is generally retained while your account is active and the promotion remains available. Verification outcomes and related security logs may be retained for a limited period needed to enforce eligibility, investigate abuse, and protect the Service.
- Website analytics: Google Analytics event-level data is configured to be retained for up to 14 months, after which it is deleted or aggregated by Google.
- Waitlist and marketing: Retained until you unsubscribe, withdraw consent, or request deletion, except for a minimal suppression record where needed to honor an opt-out.
- Blocks: Retained while needed to enforce the block and prevent unwanted contact. The active block row is removed when the relevant account is deleted; a minimal reference may remain in a report or security record when needed for safety, abuse prevention, or legal purposes.
- Reports, evidence, moderation outcomes, and delivery metadata: Retained while needed for review, safety and abuse prevention, appeals, disputes, legal obligations, security incidents, or support reconciliation; a report has no fixed retention period. Delivery status, attempt counts, and the latest delivery error remain with the report for that purpose. Closed records are reviewed for deletion or minimization as part of the manual moderation process. If the reporter deletes their account, the report may remain with the reporter reference removed or anonymized; deleting the reported account does not automatically delete a report, its evidence, delivery history, or moderation history.
- Support, diagnostics, and security records: Retained for a limited period based on operational, security, and legal need and the settings of the relevant provider. Limited safety and legal records may remain after account deletion where required for these purposes.
Account deletion does not remove the original workout records from Apple Health or Health Connect, cancel an App Store or Google Play subscription, or erase copies another user saved outside MoveShare. Limited residual copies may remain temporarily in protected backups until overwritten under normal retention cycles, or longer where law requires preservation.
You can request account deletion in the app under Settings. You can also contact us if you cannot access the app. External deletion steps can be asynchronous; in particular, account-associated Amplitude deletion may take up to 30 days. The limited transaction, security, support, and backup records described above can remain for their applicable retention periods.
10. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or receive a portable copy of your personal data; restrict or object to processing; and withdraw consent. You may also have the right to appeal our response or complain to a data-protection authority.
Withdrawing consent does not affect processing that was lawful before withdrawal. Some information is necessary to provide an account or particular feature; if you do not provide it or ask us to delete it, that feature may no longer work.
To exercise a right, email hello@moveshare.app. We may need to verify your identity before completing the request. We will respond within the time required by applicable law.
If you are in the Netherlands, you can complain to the Autoriteit Persoonsgegevens. If you live elsewhere in the EEA or UK, you may contact your local supervisory authority.
11. Security
We use reasonable technical and organizational measures designed to protect personal data, including authenticated access, encrypted transport, managed cloud infrastructure, access controls, and restricted service permissions. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur. Please protect your device and sign-in account and contact us if you suspect unauthorized access.
12. Automated decisions and advertising
MoveShare does not sell personal data, use health information for targeted advertising, or make decisions producing legal or similarly significant effects about you solely through automated processing. Product analytics may be used to create aggregate cohorts and understand likely disengagement, but not to make medical, employment, insurance, credit, or other high-impact decisions about individuals.
13. Children
MoveShare is not directed to children under 16, and we do not knowingly allow them to create accounts or provide health data. If you believe a child under 16 has provided personal data, contact us so we can investigate and delete it where appropriate.
14. Changes to this Policy
We may update this Policy to reflect changes to the Service, providers, or law. We will publish the revised Policy and update the date above. If a change materially affects your rights or how we use personal data, we will provide additional notice through the app, website, or email where required.
15. Contact us
Questions, requests, objections, or complaints about privacy:
- Data Controller: Ulaş Akdeniz (MoveShare)
- Email: hello@moveshare.app
- Postal address:
Box D7986
Keurenplein 41
1069 CD Amsterdam
Netherlands