Privacy Policy

Last updated: August 12, 2026

Frez ("we", "our", or "us") values your privacy and is committed to protecting your personal data. This Privacy Policy explains what data we collect, how we use it, and your rights regarding your information.

1. Information We Collect

1.1 Account Information

  • Email address (via OAuth providers such as Google or Apple)
  • OAuth authentication tokens

1.2 User-Provided Data

  • Name, gender and birth date information
  • Profile media and content you upload
  • Isometric training routines and session records
  • User-created notes, tags, and comments

1.3 Automatically Collected Information

  • Device Information: Device model, OS version, unique identifiers
  • App Usage Data: Session duration, screens visited, interaction logs
  • Crash Logs & Diagnostics: Anonymized crash reports for stability
  • Performance Metrics: Loading speed, API response time

1.4 Health Data Used Locally on Your Device

If you choose to connect health data sources, the related health data is processed locally on your device to support app features and does not leave your device unless explicitly disclosed otherwise.

2. Purpose of Collecting Information

  • To provide and improve our services
  • To manage and authenticate user accounts
  • To save and analyze your workout data
  • To offer customer support and respond to inquiries
  • To send service updates and important notifications

3. Data Retention and Deletion

We keep your personal information and workout data until you delete your account.

If you request account deletion, we will delete or irreversibly anonymize your personal data within 30 days, unless we are required to keep certain information for legal, security, fraud prevention, or dispute resolution purposes.

Payment or transaction records may be retained for up to 5 years to comply with legal, tax, accounting, and related obligations.

Crash logs, diagnostics, and analytics data are retained for up to 1 year and then deleted or anonymized.

For Developer Program accounts, we retain pseudonymous identity fingerprints, registered Personal API and allowlist device state, replacement counts, and suspension status for up to 365 days after account deletion. We use this limited record to prevent restriction evasion, restore legitimate re-enrollment, and review device ownership transfers. For API security and abuse prevention, we also derive a keyed, pseudonymous network fingerprint from the request IP address and retain only that fingerprint for up to 24 hours; we do not store the raw IP address in this limiter record. Coefficient request logs follow a separate maximum retention period of 90 days. When the 365-day period ends, the retained Developer Program record is deleted or irreversibly anonymized.

You can request deletion through the in-app settings or by contacting us at [email protected].

4. Your Rights

  • Access your personal information
  • Request correction of inaccurate data
  • Request deletion of your data
  • Request restriction of data processing

You can exercise these rights via the in-app settings or by contacting us.

5. Marketing measurement and Meta

On our marketing website, we use Meta measurement to understand whether advertising campaigns lead to page visits, downloads, and similar actions. In the EU/EEA, United Kingdom, Switzerland, locations we cannot reliably determine, and markets not yet approved for notice-and-opt-out operation, Meta measurement remains off unless you explicitly allow it. In markets approved for notice-and-opt-out operation, measurement starts by default unless you opt out. You can change this choice at any time using Cookie settings (or the localized equivalent) in the website footer. Where a legally recognized Global Privacy Control signal applies, we treat it as an opt-out.

When Meta measurement is active, the categories of data shared with Meta may include the page or event URL, browser and user-agent information, Meta browser identifiers such as _fbp and _fbc, and the IP address used for request delivery and matching. These identifiers and related event data may be pseudonymous, but we do not describe them as anonymous. We use this data to measure campaign performance, attribute visits and downloads, limit duplicate reporting, and improve our marketing.

The marketing website does not expose a browser-callable server relay for these events. Any future server-side commerce measurement must originate from a trusted commerce backend and is outside this website Pixel flow. Disabling website measurement stops future browser events, sends a Meta consent-revocation signal when the Pixel is present, and attempts to clear the _fbp and _fbc browser cookies.

We exclude sensitive website routes, including activation, redemption, and developer credential areas, from Meta measurement. Purchases or other activity on commerce platforms are also subject to those platforms' own privacy notices and controls.

6. Contact