Skip to content
CALLUS ← Back to site

Callus Privacy Policy

Version 1.3 - 2026-07-30

Callus is a minimalist weightlifting tracker for iPhone and Apple Watch. This policy explains how PRSPCTV AS (“we”, “us”, “our”) processes personal data when you use Callus, the optional cloud and social features, and the callusstrength.com website.

Controller and contact

The data controller is:

PRSPCTV AS Organisation number 938162581 (Norwegian Register of Business Enterprises) Nattlandsveien 67, 5093 Bergen, Norway

Privacy requests: privacy@prspctv.no

Support requests: support@prspctv.no

We aim to answer privacy requests within 5 business days. GDPR allows us up to 1 month for formal data subject requests.

What we process and why

PurposeDataLegal basis
Local workout loggingExercises, sessions, sets, weights, reps, personal records, programs, categories, notes, app settingsContract necessity, GDPR Art. 6(1)(b)
Optional cloud syncSupabase user UUID, Sign in with Apple account identifier, workout data, settings, sync metadataContract necessity
Optional social featuresUsername, display name, profile photo, friends, posts, reactions, comments, squad or group membershipsContract necessity
Premium subscription accessApple transaction identifiers, entitlement status, product identifiersContract necessity
Sign in with AppleApple identity token and stable Apple user identifierContract necessity
Push notificationsAPNs device token and notification preferencesConsent, GDPR Art. 6(1)(a)
HealthKitWorkout writes; and on-device reads of body weight and, when Recovery Intelligence is enabled, sleep, heart rate, resting heart rate, heart rate variability, steps, wrist temperature, respiratory rate, VO2 max, and menstrual/cycle data used to estimate recovery and cycle phaseConsent
Camera and photo libraryQR scans processed locally; selected profile photos uploaded only if you choose themConsent
Crash reportingApp version, build number, device and OS, screen context, breadcrumbs, stack traces, and signed-in Callus user ID tagConsent, with opt-out in Settings
Optional usage analyticsDetailed feature-use counts such as workout completion duration/counts and subscription restore — collected only when you enable Usage Analytics in SettingsConsent
Policy-accepted activation & conversion analyticsAfter you accept the current Privacy Policy, coarse milestones only: app open, onboarding completed/skipped, workout started, qualified workout completed, and purchase-funnel events — tied only to a random per-installation identifier and an immutable install/channel registry. activation_v1 marks a new eligible install. No exercises, weight, reps, duration, set count, workout source, HealthKit data, free text, or account ID. Collection pauses until local acceptance; Continue local-only keeps logging on-device and disables remote analytics for that launchLegitimate interest / product analytics after notice and acceptance; not linked to identity; not used to track you across apps or websites
Website waitlistEmail address if you join the waitlistConsent
Abuse prevention on public feedback ingressShort-lived keyed hash of the Cloudflare connecting IP (never the raw IP), used only to throttle anonymous submit-feedback submissionsLegitimate interest, GDPR Art. 6(1)(f)

Local-first storage

Workout data is stored on your device by default. It does not leave your device unless you sign in and use cloud or social features.

Friends-only workout visibility (v1)

When you use optional cloud sync and social features, synced workouts and related feed activity are visible to accepted friends. Callus v1 has no per-workout audience control — there is no public global feed and no way to hide individual workouts from friends while remaining connected. Server authorization is owner-or-accepted-friend only.

HealthKit and Health Data Cloud Sync

HealthKit data is processed on your device for recovery and relative-strength features. HealthKit-derived body-weight entries and body-weight snapshots sync to Callus servers only when you enable the separate Health Data Cloud Sync consent. Other recovery and HealthKit reads (sleep, heart rate, HRV, steps, and similar) remain on-device and are not uploaded.

Cloud processors and recipients

We use these processors to provide optional online features:

  • Supabase Inc. for authentication, cloud sync, social data, anonymous product analytics, and database hosting in the EU region.
  • Apple for Sign in with Apple, StoreKit subscriptions, HealthKit permissions, and Apple Push Notification service.
  • Sentry for optional crash reporting in its EU region.
  • Website waitlist emails are stored in our own Supabase (EU-region) database; no third-party email-list processor is used.
  • Plausible Analytics for cookieless website analytics.
  • Giphy, a Shutterstock service, for optional GIF search in chat. When you search for a GIF, your search text is sent to Giphy to return results. Giphy is not used unless you open GIF search.

Processor use is governed by data processing terms or data processing addenda. APNs carries notification delivery data in transit. Notification bodies may include limited previews of social content you receive, such as a commenter’s username, a short excerpt of their comment or message, and the name/date of the workout they interacted with. You can disable lock-screen previews in iOS Settings if you prefer.

Sentry crash reporting

If you enable crash reporting, we collect crash reports that may include app version, build number, screen context, stack traces, breadcrumbs, view hierarchy snapshots, and a tag containing your Callus user ID after sign-in. We do not intentionally include passwords, emails, message contents, HealthKit data, or workout set contents in crash reports. You can opt out in Settings.

Sentry events are retained according to the active Sentry plan at publication time. We verify the active plan before publishing material updates to this policy.

Retention

  • Local data: kept on your device until you delete it or uninstall Callus.
  • Account and cloud sync data: kept while your account is active.
  • Account deletion: active cloud records are deleted or anonymized within 30 days, with backups aging out within 90 days.
  • Push tokens: invalidated or removed within 24 hours of account deletion where technically available.
  • Sentry events: retained according to the active Sentry plan. Sentry retry diagnostics for analytics uploads use a local-only queue identifier and do not join to analytics event IDs.
  • Anonymous activation analytics events and the install registry: each retained for 13 months from receipt / first seen, then purged.
  • Waitlist email: kept until you unsubscribe or request deletion.
  • Feedback abuse-throttle counters: keyed hashes only. Minute windows are purged after ~10 minutes and day windows after 2 days via purge_submit_feedback_rate_buckets (best-effort from the edge function and/or a scheduled job). Without traffic or a scheduled purge, rows may linger until the next purge run.

Public analytics ingress is rate-limited and bounded but not cryptographically attested (no App Attest). Metrics are directional product signals only.

Callus uses soft deletes internally before purge so sync can remain consistent across devices.

Your rights

Where GDPR or similar law applies, you may request:

  • Access to your personal data.
  • Correction of inaccurate data.
  • Deletion of your account and cloud data.
  • Restriction of processing.
  • Data portability.
  • Objection to processing where applicable.
  • Withdrawal of consent for optional features.

You can export app data in Settings, delete your account in Settings, turn off HealthKit in iOS Settings, disable notifications in iOS Settings, and disable optional Usage Analytics or crash reporting in Callus Settings. Remote activation analytics require acceptance of the current Privacy Policy; you may continue local-only workout logging without accepting, in which case remote analytics remain off.

Callus does not use automated decision-making that produces legal or similarly significant effects.

Children

Callus is not directed to children under 13. Users under 16 in the EEA must have parental consent where required by local law.

Cookies and tracking

Callus is an iOS-native app and does not use web cookies in the app. The callusstrength.com website may use cookieless, privacy-focused analytics.

Security

Cloud communication uses HTTPS. Authentication is handled through Sign in with Apple. Database access is protected with row-level security. We do not store passwords.

Changes to this policy

We will notify you in-app of material policy changes. Material changes require explicit acceptance before continued use of features that rely on changed processing, such as cloud sync, social features, or analytics. You can continue using local-only workout logging while reviewing changes.

Supervisory authority

If you believe your data protection rights have been violated, you may complain to your local supervisory authority. In Norway, this is:

Datatilsynet

Postboks 458 Sentrum, 0105 Oslo, Norway

postkasse@datatilsynet.no

https://www.datatilsynet.no

© 2026 Callus. All rights reserved.