Privacy Policy
Last updated July 15, 2026
This Privacy Policy explains how Aristocoded LLC ("Aristocoded," "we," "us," or "our") handles information in connection with the Massiv mobile application (the "App") and the Massiv website at massiv.app (the "Website").
The short version Massiv is built to be private by default. Your workout history, body measurements, progress photos, and personal notes are stored on your device — not on our servers. We have no user accounts and no central database of your training data. The limited information that may leave your device (subscription status, optional anonymous usage analytics, crash reports, and data you choose to sync, export, or back up) is described in detail below.
The App does not require an account or email. If you separately choose to join the Website newsletter, we receive the email address you provide for that purpose. Newsletter identity is not linked to your workout history or the App's random analytics identifier.
1. Who we are
Massiv is operated by Aristocoded LLC. If you have any questions about this policy or your data, contact us at:
Email: [email protected]
2. Our privacy-first design
Massiv is a local-first application. This means:
- There is no Massiv account to create — you do not give us a name, email address, or password to use the App.
- We do not operate a server that stores your workouts, programs, body weight, photos, or notes.
- Your training data lives in a database on your device. If you delete the App, that data is removed with it (unless you have separately exported a backup).
Because of this design, most of the "data collection" people associate with apps simply does not happen here. The sections below describe the narrow set of cases where information is processed.
2.1 Website and newsletter information
You can browse the Website and use the App without joining the newsletter. If you choose to subscribe to Massiv Training Notes, we process:
- Email address — to send the confirmation message, newsletter issues, and occasional Massiv product updates described on the signup form.
- Consent record — subscription time, signup source, and the version of the signup promise shown when you subscribed.
- Delivery and engagement information — MailerLite may process delivery, bounce, unsubscribe, open, and link-click information to operate the mailing list and protect sender reputation.
Newsletter subscriptions use double opt-in: you are not an active newsletter subscriber until you confirm through the email MailerLite sends. You can unsubscribe at any time using the link in every issue. Unsubscribing does not affect your ability to use the App.
We use MailerLite to manage subscriptions and send newsletter email. MailerLite processes subscriber information on our behalf under its privacy and data-processing terms. We do not sell newsletter addresses and do not connect them to workout, health, body, or progress-photo data.
2.2 Website security and logs
Newsletter forms use Cloudflare Turnstile to prevent automated abuse. Cloudflare may process technical request information, including an IP address and browser signals, to determine whether a request is legitimate. Our hosting provider may also create ordinary security and access logs when the Website is requested. We use these records only to operate, secure, and troubleshoot the Website.
The Website does not currently use advertising pixels, cross-site tracking, or a website analytics product. If that changes, we will update this policy before enabling it.
3. Information stored on your device
The following information is created and stored locally on your device only, and is not transmitted to Aristocoded:
- Workout and training data — logged sets, reps, weights, programs, exercise selections, session targets, rest times, personal records, achievements, streaks, and your Level/XP progress.
- Body metrics — body weight and other measurements you choose to enter.
- Progress / body photos — any photos you capture or import. Photos are stored in a protected location on your device, location and other EXIF metadata are stripped on import, and you can optionally lock them behind Face ID, Touch ID, or your device passcode. Massiv does not upload photos to us. Photos leave the App only if you choose to export or share them, or if you turn on Cloud Backup with photos included — in which case they are encrypted on your device and stored in your own iCloud or Google Drive (see Sections 4.5 and 8). In every case, photos go to a destination you control, never to Aristocoded.
- Coach notes and personal notes — any free-text you add.
- App settings and preferences — equipment profiles, units, notification preferences, and similar.
You control this data. You can edit or delete it within the App, export it (see Section 8), or remove all of it by uninstalling the App.
4. Information processed by third-party services
To deliver certain features, Massiv relies on a small number of reputable third-party services. Each is described below, including what it receives and why.
4.1 Purchases and subscriptions (RevenueCat + Apple / Google)
Massiv offers optional paid access to Massiv Pro through monthly subscriptions, annual subscriptions, and a one-time lifetime purchase. Purchases are made through the Apple App Store or Google Play, and your payment information is handled entirely by Apple or Google — we never see or store your credit card or payment details.
We use RevenueCat to manage and verify paid entitlements. RevenueCat receives a randomly generated app user identifier, your purchase receipts, and basic device/platform information so it can tell the App whether your Pro access is active. RevenueCat does not receive your name or email.
- RevenueCat privacy policy: revenuecat.com/privacy
- Apple App Store privacy: apple.com/legal/privacy
- Google Play privacy: policies.google.com/privacy
4.2 Analytics (PostHog)
We use PostHog to understand how features are used in aggregate (for example, how many people complete onboarding or finish a workout) so we can improve the App. Analytics is on by default in current releases, but you can turn it off at any time — see the opt-out below.
- Analytics is associated with a random, anonymous identifier generated on your device. We do not attach your name, email, or any directly identifying information to analytics events, and we do not link this identifier to your real-world identity.
- Analytics events describe in-app actions and screens — they do not include your photos, body measurements, or the contents of your notes. If you voluntarily use the in-app feedback form, the message you enter is sent to PostHog as described in Section 4.4.
- PostHog may derive an approximate, general location (such as country or region) from your IP address to help us understand where Massiv is used. This is coarse location only — it does not identify you or pinpoint your precise whereabouts.
- Opt-out: You can turn analytics off at any time in Settings → Privacy & Data → Share usage analytics. Turning it off stops collection immediately on your device, and no further analytics events are sent.
PostHog privacy policy: posthog.com/privacy
4.3 Crash and error reporting (Sentry)
We use Sentry to capture crashes and technical errors so we can fix bugs. When the App crashes or hits an error, Sentry may receive a technical report including the error and stack trace, your device model, operating system version, the App version, and a short trail of recent in-app navigation events. Crash reports are not tagged with your identity — we have configured Sentry to omit personally identifying information (such as your IP address) from these reports. They are used solely for stability and debugging.
Sentry privacy policy: sentry.io/privacy
4.4 In-app feedback (optional)
If you choose to use the in-app feedback form, Massiv sends the category and message you enter to PostHog so our team can review it. We also include limited technical context: the App version, device platform, selected language, and the current App screen. If you categorize the message as a bug report, the message and technical context are also sent to Sentry and may be associated with recent navigation breadcrumbs to help us diagnose the issue.
Submitting feedback is optional. Please do not include sensitive health information, personal information, workout notes, or other content you do not want processed by PostHog or Sentry. Feedback is associated with a random App identifier rather than your name or email. To request deletion of submitted feedback, contact [email protected] with enough information for us to locate it.
4.5 Cloud Backup — your iCloud or Google Drive (optional)
If you turn on Cloud Backup, Massiv automatically saves an encrypted copy of your training data — and, if you opt in, your progress photos — to your own personal cloud storage so you can restore it on a new device. This feature is off until you set it up.
- The destination is your account, not ours. Backups are stored in your Apple iCloud (on iOS) or your Google Drive (on Android). Aristocoded operates no backup server and never receives a copy of your data.
- End-to-end encrypted. Each backup is encrypted on your device with a Backup Password that only you know (AES-256-GCM, with the key derived from your password using PBKDF2) before it is uploaded. We cannot read your backups and cannot recover your password — if you forget it, the backups encrypted with it cannot be restored.
- Google Drive access (Android). To store backups in your Google Drive, Massiv asks you to sign in with Google and requests access limited to the files Massiv itself creates. Massiv uses this access solely to create, list, and restore your Massiv backups; it does not read or access your other Drive files. Google's handling of your data is governed by the Google Privacy Policy.
- iCloud (iOS). Backups are written to your iCloud through Apple's iCloud services; Apple's handling is governed by Apple's privacy policy.
- You stay in control. You choose whether photos are included, and you can turn Cloud Backup off or delete your cloud backups at any time in Settings → Backup & Restore.
5. Apple Health and Health Connect (optional)
If you choose to enable it, Massiv can sync with Apple Health (iOS) or Health Connect (Android):
- Writing from the phone app — Massiv may write completed workouts and body weight to Apple Health or Health Connect.
- Apple Watch workout data — if you use the Apple Watch companion and authorize HealthKit access, Massiv may read live heart rate and active energy during an active workout and may write workout records to Apple Health.
This sync happens directly between Massiv on your device and the Apple or Google health platform. We do not receive a copy of your health data, and health data is never sent to our analytics or crash-reporting providers. You grant and revoke these permissions through the system Health/Fitness settings on your device, and you can turn the integration off at any time.
Apple's handling of Health data is governed by Apple's privacy policy; Google's handling is governed by Google's privacy policy.
6. Device permissions
Massiv may ask for the following device permissions. You can grant or deny each one, and most features that don't depend on a permission will continue to work without it.
- Camera — to take guided progress photos. Photos stay on your device.
- Microphone — required by the underlying camera capture component; Massiv does not record or use audio.
- Face ID / Touch ID / biometrics — used only on-device to unlock your private progress photos. Biometric data never leaves your device and is never accessible to us.
- Notifications — to deliver local reminders such as the rest timer and workout reminders. These are generated on your device; we do not run a push-notification server and do not send you marketing pushes.
- Health / Fitness — see Section 5.
7. How we use information
We use the limited information described above to:
- Verify and manage your Pro access.
- Diagnose crashes and fix bugs.
- Understand aggregate, anonymous feature usage to improve Massiv.
- Review feedback that you voluntarily submit.
- Provide the features you enable (such as Health sync and photo capture).
We do not sell your personal information, and we do not use your data for third-party advertising or to build advertising profiles.
8. Backups and export
Massiv gives you two ways to keep a copy of your data, and in both cases the data goes to a destination you control — Aristocoded does not operate a backup server and does not receive a copy:
- Manual export. You can create a backup file and export or share it through your device's standard share options (Files, iCloud Drive, Google Drive, email, and so on). Once you save or share it, that copy is governed by the privacy practices of the destination you choose.
- Cloud Backup (optional). An automatic, end-to-end encrypted backup to your own iCloud or Google Drive, described in Section 4.5.
Backups you create are your responsibility to manage and protect.
9. Data retention and deletion
Because your training data is stored locally:
- You can delete individual records within the App.
- You can delete all App data in Massiv by opening Settings, scrolling to the bottom, tapping Delete all data, and confirming the prompt.
- You can also remove local App data by uninstalling Massiv from your device.
- Subscription records held by Apple, Google, and RevenueCat are retained according to those providers' policies and as required for billing and tax purposes.
- Anonymous analytics, submitted feedback, and crash data are retained by PostHog and Sentry according to our configured retention settings and their policies.
- Newsletter information is retained while you remain subscribed. When you unsubscribe, MailerLite retains a suppression record so we do not accidentally resubscribe or email you. You may ask us to delete other newsletter information by emailing [email protected].
- Minimized newsletter consent backups and Website security logs are retained only as long as reasonably necessary for consent records, abuse prevention, troubleshooting, and legal obligations.
To request deletion of any information held by our third-party processors, contact us at [email protected] and we will assist where we are able.
10. Children's privacy
Massiv is not directed to children. The App is intended for users 13 years of age or older (or the minimum age of digital consent in your jurisdiction, such as 16 in parts of the European Economic Area). We do not knowingly collect personal information from children below the applicable age. If you believe a child has provided us information, contact us at [email protected].
11. Your privacy rights
Depending on where you live, you may have rights under laws such as the EU/UK GDPR or the California Consumer Privacy Act (CCPA/CPRA), including the right to access, correct, delete, or port your information, and to opt out of certain processing.
Because Massiv stores your core data only on your device, you can exercise most of these rights directly — your data is in your hands. For information processed by our third-party providers, you may contact us at [email protected] and we will respond consistent with applicable law. We do not sell or "share" personal information as those terms are defined under California law.
12. International users
Our third-party providers (such as RevenueCat, PostHog, and Sentry) may process limited information in the United States or other countries. Where required, these providers maintain appropriate safeguards for international data transfers. By using Massiv, you understand that this limited processing may occur outside your country of residence.
13. Security
We take reasonable measures to protect information, including storing on-device data in protected locations, stripping location metadata from imported photos, offering optional biometric locking for photos, and using encrypted connections (HTTPS) for the limited data exchanged with third-party services. When you use Cloud Backup, your data is additionally encrypted on your device with a Backup Password that only you know (AES-256-GCM) before it is stored in your personal cloud, so neither we nor your cloud provider can read its contents. No method of storage or transmission is completely secure, but the local-first design means there is no central store of your training data for an attacker to target.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide notice within the App or on our website. Your continued use of Massiv after an update means you accept the revised policy.
15. Contact us
Questions, requests, or concerns about privacy?
Aristocoded LLC
Email: [email protected]