PerformApp logo PerformApp
  • Home
  • Features
  • How it works
  • Changelog
  • Contact

Privacy Policy - PerformApp

Last updated: 27 September 2026

This policy describes how PerformApp processes data in the mobile app and, where indicated, on the performapp.net website.

Data controller

The controller is Lorenzo Mastriani, who develops and manages PerformApp, including under the MasterWare project name. MasterWare is not a separate company: the product and user-facing service are identified by the PerformApp brand.

For information, objections or data-related requests: contact@performapp.net.

1. Data stored on the device

PerformApp stores the following locally in SQLite:

  • workouts, workout plans, timers, exercises, sets and history;
  • weights, repetitions, RIR/RPE, intensity and notes entered by the user;
  • exercise catalogue, custom content, settings and recoverable snapshots;
  • local profile and preference for sharing usage data;
  • a local technical log used to prevent duplicate Analytics events, with no identifiers sent to GA4, deleted at launch or on the first relevant event after 60 days and deleted immediately when the user disables Analytics.

This data remains on the device until the user deletes it, uninstalls the app or voluntarily uses remote functionality such as account services, Auto Sync, backup or support. It may also be included in device backups managed by the operating system and the user’s Apple or Google account, according to the relevant settings.

On iOS, location may be processed temporarily in memory during a workout for background features and distance calculation; it is not stored in the database or included in Analytics events. The operating-system permission is a technical user control and does not replace the legal basis for processing.

2. Account and Firebase Authentication

Creating an account is optional and may use Google or Apple through Firebase Authentication. The Firebase UID and provider identifier, email, display name, any profile photo URL, tokens and technical data required for authentication and security may be processed.

The Google Sign-In SDK included in the app also declares technical and usage data that may be linked to the account or device, such as identifiers, approximate location and interactions with the SDK, for sign-in service functionality and analytics. PerformApp does not add this data to the custom Analytics events described below.

Purpose and legal basis: to create and protect the account and provide the requested cloud features; performance of the service requested by the user. Data is retained while the account remains active, subject to legal obligations or security requirements.

3. Auto Sync

When Auto Sync is available in the version being used and the user signs in to their account, PerformApp synchronises supported content to keep it consistent across devices and recover it after the user signs in again. The profile and photo, settings, tutorial progress, personal exercise catalogue, timers, workout plans, sessions, workouts and history may be synchronised, including sets, repetitions, weights, RIR/RPE or intensity, times, dates and notes. Identifiers for the account, personal data space and device, together with revisions and technical information needed to manage changes, the recycle bin and conflicts, are also processed.

The data space associated with the account is individual: PerformApp does not allow other people to access the entire personal space. Any future sharing features will concern individual workout plans or workouts transferred by the user, not access to the complete space.

Purpose and legal basis: to provide synchronisation, recovery and continuity between devices, prevent overwrites and manage conflicts; performance of the requested service. Active Auto Sync data is retained while the account is active or until the user deletes it.

Active Auto Sync data is stored in Cloud SQL in the Milan Google Cloud region. Technical backups and point-in-time recovery (PITR) are retained for 7 days: after account deletion, residual copies may therefore remain temporarily in isolated backups until they expire automatically, but they are no longer available in the active account.

Complete account deletion removes the sign-in identity and associated cloud data, including active Auto Sync data, profile photos and manual backups. A pseudonymous technical receipt, containing none of the account content and used only to track and ensure the reliability of deletion, remains for 30 days. The local database associated with that account is also deleted from the device. The app returns to any guest archive that already existed and remained separate; this archive may retain its own local settings. A separate, inactive imported guest archive may also exist. These archives are not data from the deleted account, which is not converted or copied into them. If no previous guest archive exists, the app restarts with an empty guest archive.

4. Backups and Firebase Storage

Only when the user voluntarily creates a backup may PerformApp upload a file associated with the Firebase UID to Firebase Storage containing:

  • timers, workout plans, sessions, workouts, exercises and sets;
  • weights, repetitions, RIR/RPE, intensity, notes and history;
  • settings, exercise catalogue and custom content;
  • local profile, including name, email, URL or profile image if present.

Purpose and legal basis: to create and restore the requested backup; performance of the service. Backups remain available until the user deletes them or requests account deletion. If automatic removal fails, the user may contact the controller.

5. Feedback and support

When the user voluntarily submits feedback, Firebase Storage may receive the message, any attached images, device model, platform, app version and a minimised selection of technical logs. Before sending, the app excludes authentication, backup and database content from shared logs. Because upload requires an authenticated account, Firebase may technically associate the request with the relevant UID even if the UID is not included in the feedback file. This data is used to handle the request and resolve technical problems and is retained for as long as necessary, in any case no longer than 6 months unless documented needs related to the report or a dispute require otherwise.

6. Firebase Analytics / Google Analytics 4 in the app

User control

Analytics is active from the first launch to measure essential flows and improve PerformApp.

The user may object at any time under Settings → Privacy → Usage data sharing, without losing functionality.

Purpose and legal basis

The controller uses measurements to understand usage, usability, reliability and development priorities. The stated basis is the legitimate interest in improving the service under Article 6(1)(f) GDPR, with a right to object.

Data collected automatically

Firebase generates a pseudonymous installation identifier and may collect app-open, first-launch, update, session, screen and interaction events, as well as app version, operating system, device model, language and approximate location derived from the IP address. According to Google, GA4 uses the IP address to derive geographical data but does not log or retain the individual IP address.

Events sent by PerformApp

  • workout_created, workout_started, workout_completed and workout_abandoned;
  • plan_created;
  • mode, source, creation method and flow entry point;
  • ranges for the number of exercises, sets and completed sets, duration ranges and completion or abandonment type.

This data is pseudonymous, not anonymous. PerformApp does not set an Analytics User ID, does not intentionally link the App Instance ID to the Firebase account and does not include email, Firebase UID, username, exercise or workout-plan names, notes, weights, repetitions, RIR/RPE, workout dates, Spotify data or database content identifiers in custom events.

Advertising and identifiers

PerformApp does not use Analytics for advertising, remarketing or advertising profiling. On Android, the app does not request or collect the Advertising ID. On iOS, it uses Firebase Analytics Without Ad ID Support and does not integrate AdSupport, AppTrackingTransparency or IDFA. The ad_storage, ad_user_data and ad_personalization signals remain set to denied even when Analytics is active.

Disabling and retention

Disabling immediately blocks new custom PerformApp events and asks the SDK to suspend automatic collection, set analytics_storage to denied and reset the local Analytics identifier. If a technical check is not confirmed, the app asks the user to restart and check the option again. Disabling does not retroactively delete data already received by Google and does not disable or reset Crashlytics. The GA4 property retains event-level data for 2 months and user-level data for 14 months; the user-data window is renewed by new activity. Aggregated reports may be retained longer according to the service configuration. PerformApp does not set the Firebase UID as the Analytics User ID, so this data is not deleted as part of account deletion and remains subject to the stated GA4 retention periods.

7. Firebase Crashlytics

Crashlytics is active on mobile platforms independently of the Analytics preference. It may receive crashes, errors, stack traces, technical app state, version, operating system, device model, pseudonymous installation identifiers and diagnostic logs.

Crashlytics, like Google Analytics 4, is a global service: data may be processed in the data centres and facilities used by Google worldwide and is not restricted to the Milan region or to a single region of the European Union.

Purpose and legal basis: to identify malfunctions and keep the service reliable and secure; the controller’s legitimate interest. Firebase normally retains Crashlytics reports for 90 days before beginning the removal process.

8. Spotify

If the user connects Spotify, PerformApp uses the Spotify SDK to control playback. Connecting is optional and data is also processed by Spotify according to its policy. Spotify data is not added to PerformApp custom Analytics events.

9. Website

The performapp.net website uses Google Analytics 4 to measure visits, traffic sources and clicks on download or social links. Before the user makes a choice, Analytics operates with consent denied: it does not read or write Analytics cookies and may send Google only cookieless technical signals used for aggregated statistics and modelling. If the user accepts, cookies and full measurement are enabled. Advertising and personalisation remain disabled.

The choice can be changed at any time through Cookie preferences, available on pages that use Analytics, or by deleting site data in the browser.

The website’s origin server is hosted by Hostinger in France, and its technical backups are stored in Lithuania. Hostinger’s CDN distributes content through a global network: when a request is served by an edge node, the IP address, request headers and technical logs may be processed in the country where that node is located, including outside the European Economic Area. Fonts and libraries loaded from Google Fonts or external CDNs may receive ordinary technical connection data.

10. Recipients and transfers

The main infrastructure processing activities are mapped as follows:

  • Google Cloud, Milan (europe-west8): Cloud Run processes Auto Sync and account-management requests; Cloud SQL stores active Auto Sync data and the technical recovery copies described above. Artifact Registry stores in the same region the software artefacts used to deploy the service, not ordinary account content.
  • Firebase Storage, United States (US-CENTRAL1): stores files voluntarily uploaded for backups, profile images and feedback.
  • Firebase Authentication, United States: processes exclusively in the United States the data required to create and manage the sign-in identity.
  • Google Analytics 4 and Firebase Crashlytics, global infrastructure: respectively process usage data and diagnostic data in Google facilities worldwide; no exclusive European region is selected.
  • Hostinger: hosts the website’s origin server in France, stores backups in Lithuania and uses a global CDN whose nodes may process technical connection data, including outside the EEA.

Milan, France and Lithuania are in the EEA, and the movement of data between these locations does not, in itself, constitute a transfer to a third country. Choosing a European region does not, however, prevent necessary access or further processing by the provider and its sub-processors as described in the relevant agreements.

For transfers to Google LLC and US companies covered by its certification, Google states that it adheres to the EU-U.S. Data Privacy Framework (DPF), recognised by the European Commission through an adequacy decision. Where the recipient, service or onward transfer is not covered by the DPF or another adequacy decision, the Google Cloud terms incorporate the European Commission’s standard contractual clauses (SCCs), in the module applicable to the controller-to-processor or processor-to-processor relationship.

For the global CDN and any Hostinger sub-processors established outside the EEA in countries without an adequacy decision, Hostinger’s data processing addendum incorporates the 2021/914 SCCs, Module 2 (controller-to-processor) or Module 3 (processor-to-sub-processor), according to the actual roles. The DPF applies only to any US recipients that are certified and to processing covered by their certification; it is not used as a blanket safeguard for the entire Hostinger network.

Information on safeguards is available on the official pages covering Google’s transfer mechanisms, the Google Cloud SCCs and Hostinger’s data processing addendum. Google or Apple may also process data when selected as authentication providers, and Spotify when voluntarily connected; the policies and safeguards published by the respective providers also apply to those relationships.

PerformApp does not sell personal data.

11. Legal bases

  • Performance of the service: requested app features, account, Auto Sync and backups.
  • Legitimate interest: product analytics, security, Crashlytics and technical logs.
  • Consent or voluntary action: optional connections and processing for which the law requires it. Operating-system permissions remain separate technical controls.
  • Legal obligation: compliance requirements and valid requests from authorities.

12. User rights

Where applicable, the user may request access, rectification, erasure, restriction and portability, or object to processing based on legitimate interest. The user may also lodge a complaint with the Italian Data Protection Authority.

Workouts and workout plans can be managed in the app. The account, Auto Sync data and backups can be deleted through the available features or by contacting the controller. Account deletion also removes the related local database without changing any separate, pre-existing guest archive. Permissions and the Analytics preference can be changed in the app or device settings.

13. Security

PerformApp uses Firebase access controls, encrypted transmission over HTTPS/TLS and technical measures consistent with the services used. No system can guarantee absolute security; any issues can be reported using the contact details above.

14. Changes

This policy may be updated when features, providers or applicable obligations change. The date above identifies the current version.

Privacy contact

Email: contact@performapp.net

To request account deletion, you can also use the Delete Account page.

Back to Home
PerformApp logo PerformApp
Delete Account Privacy Terms of Service Changelog

© 2026 PerformApp. All rights reserved.

Change language
🇮🇹Italiano 🇫🇷Français 🇪🇸Español 🇬🇧English 🇩🇪Deutsch