Codesplash Gym

Codesplash Gym Privacy Policy

Effective date: September 26, 2026

This policy describes privacy practices for Codesplash Gym, a CodeSplash app. For privacy questions, contact support@codesplash.ai.

Records on your device

Codesplash Gym stores workout history, routines, exercise records, food and water logs, body measurements, habits, imported records and preferences locally. You do not need a Codesplash account to use the core app. The current app does not include a developer-operated server for uploading these records or app-level iCloud synchronization.

Your device's backup settings, Apple Health settings and destinations you choose for exports may separately affect where copies exist. Local storage does not mean that no app feature ever communicates outside the device.

Apple Health

When you enable supported features and grant permission, the app can read relevant workout, activity, sleep, heart-rate, body-measurement and nutrition data. It uses these records to show history, progress, habits and fitness estimates. Depending on your settings and permissions, it can write completed workouts and enabled body, food and water entries to Apple Health.

You choose the permissions granted through Apple's Health controls and can revoke them. Revoking future access does not automatically delete records already stored locally or in Apple Health. Manage those copies separately using the applicable controls.

Codesplash Gym does not use Health data for advertising or tracking.

Apple Watch

The companion Watch app exchanges workout state and controls with the paired iPhone. If you start workout recording and grant Health permissions, it uses heart rate and active energy data to show live workout metrics and save the recorded workout to Apple Health.

File imports and exports

Imports read files you select, such as supported workout CSVs, Fitbit archives and Garmin files. Imported records, including retained source records where supported, are stored locally. Importing does not automatically upload your archive to the app developer.

Exports are shared through the system interface to destinations you choose. Those services and recipients control their own copies and handling of the exported information.

Barcode lookup and camera

The camera is used to recognize food barcodes. Camera frames are processed on the device by Apple's scanning framework; the app's product-lookup request sends the recognized barcode, not a camera image.

For an uncached barcode, the app contacts Open Food Facts with the product code and an app-identifying User-Agent. The provider also receives ordinary network request information, such as your IP address. Product results are cached locally.

See the Open Food Facts Privacy Policy.

Open Food Facts describes processing network logs for security, technical analysis and usage measurement, with retention periods that vary by processing activity. Its policy describes restricted administrator access and network security controls. Codesplash Gym does not use the Open Food Facts mobile scanner or Google ML Kit; its scanner uses Apple's framework. The provider controls its own logs and their deletion.

Optional Google Health connection

If you configure and authorize the optional Google Health connection, the app sends authentication and API requests to Google to retrieve authorized data. Access and refresh tokens are stored in the device Keychain. The current implementation requests read-only scopes for supported activity, health metrics, sleep and nutrition data.

You can sign out in the connection screen and manage authorization through your Google account. Signing out does not by itself remove previously imported local records.

See the Google Privacy Policy and Google's retention explanation.

Google processes authentication and request information under its service terms and privacy policy. Its retention depends on the data, your account settings, service operation and legal requirements; we do not control deletion from Google's systems. Google describes encryption in transit, security reviews and access restrictions among its protections. Use your Google account controls to review connected apps, revoke access and manage information retained by Google.

Notifications and rest alerts

With permission, the app schedules local reminders and rest alerts. You can control notification and alarm access in system settings. Live Activities may show workout or rest information on system surfaces such as the Lock Screen.

Advertising and analytics

Codesplash Gym contains no advertising SDK or third-party analytics SDK and does not perform advertising tracking. Apple may provide diagnostic or beta-testing services under its own settings and terms.

During beta testing, Apple may share crash reports, installation and usage information, device details and feedback with us. Feedback can include comments, screenshots and contact information. We use these records to test the app and investigate problems, not for advertising. We delete downloaded or separately retained copies containing personal information within 90 days after the related issue is resolved or testing ends, unless a specific ongoing issue or legal obligation requires longer retention.

Apple controls information kept in TestFlight. Apple states that beta feedback is retained for one year and crash and usage information may remain until bugs are resolved. Our 90-day rule applies to copies we control, not to Apple's systems. See TestFlight & Privacy.

Support requests

If you contact support, we receive the contact information and message content you send, including any attachments you choose to provide. We use it to respond and investigate the issue.

Support email is provided through GoDaddy, with mail routed through Microsoft infrastructure. Messages and attachments pass through those services. Access to our support records is limited to people who need it to respond, investigate problems or administer the service. See GoDaddy's Privacy Notice, its Data Processing Addendum, and the Microsoft Privacy Statement.

We retain support correspondence while a request is active and delete messages, attachments and separately saved copies from active records within 90 days after resolution. Longer retention is limited to a specific continuing problem, security investigation or legal obligation. Provider backups, recovery copies and service logs follow the applicable provider's retention rules and may persist after deletion from active records. To request deletion earlier, email support@codesplash.ai. Please do not include health records or other sensitive information unless necessary to explain the issue.

Support and privacy website

Our public support and privacy website uses GitHub Pages. GitHub states that it logs and stores visitors' IP addresses for security purposes. These pages contain no advertising, analytics scripts, contact forms or embedded third-party resources. Email links open your email application; sending a message shares its contents with our support mailbox.

See GitHub's Pages data-collection explanation and GitHub's Privacy Statement.

Retention and deletion

Local records remain until removed through available app controls or the app's local data is removed. Settings → Delete all workouts deletes workouts, sets and records; it does not delete every data category. The Fitbit and Garmin import screens provide their respective source-data deletion controls. Use the available controls for other entries.

Removing the installation removes its local app container. Copies in Apple Health, exports, third-party accounts, paired-device storage or device backups may remain separately. Authentication credentials stored in Keychain should be cleared by signing out; do not assume uninstalling clears them.

We cannot remotely erase records held only on your device. To request deletion of information you sent to support, contact support@codesplash.ai. We may retain information where necessary to comply with law, address a security incident or establish, exercise or defend legal claims. We limit any exception to the information and period needed for that purpose.

Third-party protection and your choices

We limit outgoing information to what the features you choose require. App requests to external APIs use HTTPS. Google credentials are stored in the device Keychain, and Apple Health access requires your permission. Support access is restricted as described above. Service providers handle information under their applicable service terms, data-processing terms and privacy policies linked here. These providers may process information in countries other than yours; applicable provider terms describe international-transfer protections. No security measure can guarantee absolute security.

You can use core workout logging without connecting Health, enabling camera access or signing into Google. You can revoke permissions in system or provider settings and stop using optional network features.

Depending on your location, you may have rights to access, correct, delete or receive a copy of personal information, or object to or restrict its processing. Send requests to support@codesplash.ai. We may need to verify your request and will respond within the period required by applicable law. You may also contact your local data-protection authority. Requests about records held only on your device require the applicable device or app controls.

Changes and contact

We will update this policy when our practices change and revise its effective date. We publish changes on this page and, where required, provide an additional notice or obtain consent before applying a material change.

Privacy contact: support@codesplash.ai

Public support contact: CodeSplash — support@codesplash.ai