SuperAbs privacy

Privacy Policy

This policy explains what stays on your device, what is sent to service providers when you use online features, and the choices available to you.

Effective date: 1 August 2026

1. Scope and age requirement

SuperAbs is operated by Dipanshu in India ("we," "us," or "our"). This policy applies to the SuperAbs iOS app (the "App"), its AI-powered features, and its optional public weekly leaderboard.

Photo-based body scans, meal-photo analysis, and the public leaderboard are available only to people aged 18 or older. Typed meal-description analysis does not require a photograph and remains available as implemented in the App. Do not submit another person's photograph, meal information, or other personal information without their permission.

2. Information we handle

Information stored on your device

The App stores information locally in its iOS app container so it can provide your plan and history. This may include:

  • Profile and plan information, including your name if supplied, age, gender, height, weight, goals, activity and training preferences, equipment, and obstacles.
  • Workout plans, completed workouts, progress, hydration, and weight entries.
  • Meal entries, nutrition estimates, meal descriptions, food photographs, and associated AI results.
  • Body-scan photographs, scan scores, recommendations, and progress comparisons.

We do not upload this local history to our own database as part of the App's ordinary operation.

If you do not join the public leaderboard, the App calculates the same weekly XP goal only on your device. Private XP and private activity history are not uploaded to the leaderboard and are never backfilled if you join later.

Information sent when you join the public leaderboard

Joining is optional and requires an adult self-attestation, acceptance of the current leaderboard consent, and linking the App's Firebase account to Sign in with Apple. We store the attestation and consent timestamps and versions, but not your age or birth date. Firebase Authentication stores the Apple-provider link and a Firebase user identifier so the leaderboard remains associated with the correct account.

Only activity occurring after enrollment can earn public XP. For accepted events, we store a minimal event type, time, replay-prevention key, locked weekly time zone, weekly XP totals, lifetime XP and level, division, result, and trophy summary. We do not upload meal contents, photos, calorie or macro values, water quantities, workout duration, weight, body fat, scan data, body measurements, streak length, or the rest of your private health history for leaderboard scoring.

Other participants see only a server-generated alias and fixed icon, weekly XP, level, division, rank, and league result. They do not see your name, Apple account details, photographs, biography, meals, measurements, or workout details.

Information sent when you use AI analysis

When you choose an AI body scan or meal analysis, we send the selected photograph or typed meal description, your declared age where required for photo analysis, and an anonymous Firebase account identifier to our Firebase Functions service in the United States. The service sends the photo or text to OpenAI to moderate the input and generate the requested analysis or estimate. The result is returned to your device and stored with your local history only after you choose to save it.

We do not use AI inputs to identify you by name. A hashed version of the anonymous Firebase identifier is sent to OpenAI as a safety identifier. OpenAI API requests are configured with store: false. OpenAI may retain API content and related metadata in abuse-monitoring logs for up to 30 days under its standard API data controls, and does not use API data to train or improve its models unless the API customer opts in.

Service, purchase, and attribution information

To run, secure, and improve the App, our service providers may process:

  • An anonymous Firebase Authentication identifier and the number of AI analyses used on a given UTC day.
  • Limited operational logs such as a hashed anonymous identifier, endpoint, outcome, model, timing, usage totals, and provider request ID.
  • Subscription entitlement and purchase-status information from RevenueCat and Apple. We do not receive or store your full payment-card number.
  • A randomly generated Firebase app-instance identifier and privacy-safe product-interaction information, including screens, feature entry points, actions, outcomes, permission outcomes, subscription-access state, aggregate workout counts, and feature timing.
  • Device, app, network, and attribution information collected by AppsFlyer, such as device identifiers, IP address, app interaction or campaign-attribution data, and—only if you allow tracking—the advertising identifier (IDFA).
  • Permission status for camera, photos, notifications, and tracking.

If you join the public leaderboard, we also process the Firebase user identifier linked to Apple, generated alias and icon, adult-attestation and consent records, minimal qualifying-activity events, weekly and lifetime XP, level, division, standings, and results. Leaderboard analytics record flow and outcome events but do not contain aliases, Apple account details, health values, or meal and workout contents.

Firebase product analytics does not receive your name, onboarding answers, photographs, meal descriptions, foods, body measurements, nutrition values, scan scores, free-text feedback, leaderboard alias, or identifiers for records stored on your device. Advertising-personalization signals are disabled and the Firebase Authentication identifier is not used as an Analytics User-ID.

3. How we use information

We use information to provide personalized workouts and local progress tracking; operate the optional weekly leaderboard and prevent duplicate or abusive scoring; process requested AI analyses; apply daily AI-feature limits; verify and restore subscriptions; understand onboarding and feature use; measure subscription, retention, attribution, and App performance; protect the App from misuse; respond to support requests; and comply with legal obligations.

We do not sell personal information. We do not use body or meal images for advertising, and we do not use them to train AI models.

4. How information is shared

We share information only as needed to provide the App:

  • Apple processes App Store purchases, subscription management, iOS permissions, and Sign in with Apple authentication for adults who choose to join the public leaderboard.
  • Firebase / Google Cloud provides anonymous and Apple-linked authentication, App Check, product analytics, callable functions, Firestore leaderboard and quota storage, and associated cloud infrastructure. The online functions and Firestore database run in us-central1 in the United States.
  • OpenAI moderates and analyzes the photos and meal descriptions you choose to submit for AI features.
  • RevenueCat processes subscription entitlement and purchase-status information.
  • AppsFlyer provides mobile attribution and measurement services.

These providers may process information in countries other than yours. Their own privacy policies may also apply to their processing.

5. Permissions and tracking choices

  • Camera and photo library: Camera access is optional and requested only when an eligible adult chooses to capture a body-scan or meal photo. Selecting an existing image uses Apple's system photo picker. You can deny or revoke camera access in iOS Settings, skip the onboarding scan, and continue using non-photo parts of the App.
  • Notifications: Onboarding does not request notification permission. You can enable reminders later from the App and disable them in iOS Settings.
  • Tracking: Onboarding does not request tracking permission. At a later relevant moment, the App may ask through Apple's App Tracking Transparency prompt. If allowed, AppsFlyer may use IDFA for attribution and advertising measurement. Denying permission does not prevent use of the App.
  • Product analytics: Privacy-safe Firebase product analytics is independent of tracking permission and does not use IDFA. You can stop future collection in SuperAbs → Profile → App settings → Share Product Analytics. Disabling it also removes the Firebase app-instance identifier shared with RevenueCat for subscription-event measurement.
  • Public leaderboard: Joining is optional. Adults can decline and continue with private, device-only weekly XP. An enrolled participant can use Leave Leaderboard to stop public participation or Delete Account to remove leaderboard and quota data and delete the linked Firebase account. Account deletion requires Apple reauthentication and asks Apple to revoke the authorization before the App starts a fresh anonymous session.

6. Retention and deletion

Local App data remains on your device until you delete it through available App controls or delete the App. Deleting the App removes data in its local app container, including local photos, scan results, meal history, workout history, and profile data.

Server-side Firebase daily quota records are retained for 30 days. Minimal leaderboard event ledgers are retained for 35 days, and finalized league entries for 90 days. Leaderboard membership and the latest 12 trophy summaries remain until you leave or delete your account. Leaving removes your public identity, progress, events, trophies, and public participation; a minimal leave time and next-eligible-week record remains temporarily to enforce the weekly re-entry rule. Account deletion purges leaderboard and quota data, revokes the Apple authorization where applicable, and deletes the Firebase user. Deletion cannot remove aggregate, de-identified analytics or records that must be retained for security or legal reasons.

Limited operational logs are retained for 90 days. Firebase Analytics event-level data is configured for 14-month retention; aggregate reporting may remain available longer. OpenAI's API abuse-monitoring retention may be up to 30 days. Apple, RevenueCat, Firebase, and AppsFlyer may retain information for the periods described in their policies or as required by law.

Because the AI service uses a Firebase identifier rather than your name, we may not be able to locate a server-side record from an email address alone. Those records expire automatically on the schedules above. If you linked Apple for the leaderboard, use the in-App account controls while signed in whenever possible.

7. Your rights and choices

Depending on where you live, you may have rights to request access to, correction of, deletion of, or information about the processing of personal information, or to withdraw consent where processing is based on consent.

To make a request, email abmaxxing.contact@gmail.com with enough detail for us to understand the request. We may need to verify the request before responding. You may withdraw from the public leaderboard without deleting local health history, delete the linked online account from the App, stop future local collection by deleting the App, and manage subscriptions separately through your Apple account.

8. Security

We use reasonable technical and organizational safeguards designed to protect information, including platform security controls, Firebase App Check, authenticated callable services, and restricted database access. No method of electronic storage or transmission is completely secure, so we cannot guarantee absolute security.

9. Changes to this policy

We may update this policy when the App or applicable requirements change. We will post the updated version on this page and change the effective date. Material changes may also be communicated in the App where appropriate.

10. Contact

Dipanshu
India
abmaxxing.contact@gmail.com