Privacy policy
Version 1.0 · in force from 28 September 2026
This privacy policy explains which personal data Apex Routine processes, why, for how long, with whom, and which rights you have over it. It applies to the Apex Routine app on iPhone and Apple Watch, to the server behind it, and to the website apexroutine.com. We wrote it to be read, not to put you off. If there is something you want to know that is not in here, email us.
In short
- Your data serves one purpose: your training. We sell nothing, we show no adverts and we do not track you across other apps or websites.
- Health data (injury zones, and heart rate and energy from your Apple Watch) is processed only with your explicit consent, which you can withdraw at any time without losing the app.
- Our own servers and backups are in the European Union.
- You can delete your account in the app. Everything is then removed from our database immediately and permanently; backups are overwritten within thirty days.
- You must be 16 or older.
This summary is a reading aid; the full text below is what applies.
1. Who is responsible
The controller within the meaning of the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) is Apex Development, Beukenlaan 27, 8810 Lichtervelde, Belgium.
Contact for anything to do with your data: support@apexroutine.com. We have no data protection officer: the health data we process is limited to what you enter in the app yourself or measure with your watch, and that does not happen on a large scale, so the GDPR does not require us to appoint one. Your question goes straight to the person responsible.
Where we write "art. 6.1.b" below, we mean Article 6, paragraph 1, point (b) of the GDPR, and likewise for the other references.
2. What this policy applies to
This policy covers three things:
- The app Apex Routine for iPhone, and the companion app for Apple Watch.
- The server the app talks to, where your account and your training history are stored.
- The website apexroutine.com, with the waiting list and the contact form.
It does not cover what Apple or Google themselves process when you use the App Store, buy a subscription, or sign in with your Apple or Google account. Their own privacy statements apply to that, and we refer to them in section 6.
3. Which data we process, what for, and on what basis
We collect nothing the app does not need. Below, per category, is what we keep, what for, and on which legal basis under Article 6 (and, for health data, Article 9) of the GDPR.
3.1 Your account
Your name, email address and password (or a link to your Apple or Google account) are needed to have an account; without them we cannot provide the service. The rest of your account is there to make the app work.
| Data | What for | Legal basis |
|---|---|---|
| First name, last name, email address | Creating your account, addressing you in the app and in emails, reaching you about your account | Performance of the contract (art. 6.1.b) |
| Password | Signing in. We never store it in readable form: only a cryptographic hash (bcrypt) | Performance of the contract (art. 6.1.b) |
| Language and time zone | Showing the app and our emails in your language, starting your weekly plan on the right day | Performance of the contract (art. 6.1.b) |
| Verification codes (hashed), time of creation and use, number of attempts | Confirming your email address and resetting your password; preventing misuse of codes | Performance of the contract (art. 6.1.b) and legitimate interest (art. 6.1.f): the security of your account |
| Access tokens for the iPhone app and a separate token for the Apple Watch | Staying signed in without entering your password every time; being able to unpair the watch separately | Performance of the contract (art. 6.1.b) |
| Time of registration and of email confirmation; the version of the terms you accepted at registration and when; the time you completed onboarding; the date and version of your most recent confirmation of the safety notice in the app | Knowing where you are in the app; being able to show what you accepted and when | Performance of the contract (art. 6.1.b) and legitimate interest (art. 6.1.f): proof of acceptance and our accountability obligation (art. 5.2) |
3.2 Signing in with Apple or Google
You can create an account and sign in with Sign in with Apple or with your Google account. We then store the fixed user ID that Apple or Google gives us, the provider (Apple or Google), and the email address they pass on to us. With Apple, that may be a private relay address from Apple if you hide your real address; we respect that. We receive your name from Apple only at the first sign-in and from Google at every sign-in, and we use it solely to give your account a name.
We get no access to your Apple or Google account, your contacts, your calendar or anything else. What Apple and Google themselves process when you sign in is set out in their own statements (section 6). Legal basis: performance of the contract (art. 6.1.b), because it is the way you have chosen to sign in.
3.3 Your profile and your preferences
| Data | What for | Required? | Legal basis |
|---|---|---|---|
| Year of birth | Checking that you are 16 or older; adjusting your training volume to your age | Yes | Performance of the contract (art. 6.1.b) and legitimate interest (art. 6.1.f): enforcing the age limit |
| Sex, height and weight | Adjusting starting weights, target weights and progression. You can leave them empty; the app then uses general defaults | No | Performance of the contract (art. 6.1.b) |
| Experience level, goal, where you train, available equipment, maximum session length, planned training days, chosen technique per day | Building your weekly plan | During onboarding | Performance of the contract (art. 6.1.b) |
| Injury zones you mark, and the exercises excluded as a result | Avoiding exercises that load the marked zone. This is a filter based on general movement patterns, not a medical assessment | No | Explicit consent (art. 6.1.a and art. 9.2.a): this is health data |
| Favourite exercises, excluded exercises and the reason for exclusion | Suggesting only exercises you can and want to do | No | Performance of the contract (art. 6.1.b) |
| Settings: reminders, rest timer, light or dark mode, sync with Health | Making the app work the way you want | No | Performance of the contract (art. 6.1.b) |
We process injury zones only with your explicit consent. You give it with a separate confirmation on the screen where you mark a zone, in onboarding or in your profile; the screen says there what it is for, and without that confirmation we store no zones. You withdraw consent by removing the zones again: the generator then stops using them and we delete them immediately. You can do that without losing anything else in the app.
3.4 Your training
| Data | What for | Legal basis |
|---|---|---|
| Generated weekly plans: days, exercises, sets, suggested weights and reps, techniques, and the generator's notes | The core of the app: your plan | Performance of the contract (art. 6.1.b) |
| Logged workouts: start and end time, each set with weight, reps and perceived exertion, swapped or skipped exercises, max attempts | Calculating your progression, building your next plan, keeping track of your records | Performance of the contract (art. 6.1.b) |
| Personal records and estimated maxes per exercise | Showing your progress and suggesting your weights | Performance of the contract (art. 6.1.b) |
| Average and maximum heart rate and active energy per workout, only if you train with the Apple Watch and allow it | Showing and keeping your workout as you did it | Explicit consent (art. 6.1.a and art. 9.2.a): this is health data |
You give consent for heart rate and energy twice: in Apple's HealthKit dialog on your watch, and with the Keep heart rate switch in the app's settings. If you turn that switch off, the watch stops writing anything to us. The values we already hold, we delete as soon as you ask (section 10) and in any case when you delete your account. Your workouts themselves, with sets and weights, remain.
3.5 Apple HealthKit
During a workout, the Apple Watch app reads your heart rate and your active energy from HealthKit, and afterwards writes the workout to HealthKit so that it counts towards your Activity rings. That happens only after your consent in the HealthKit dialog, which you can withdraw at any time in the Health app.
What we do and do not do with HealthKit data, under Apple's rules and under the law:
- Per workout we store only your average and maximum heart rate and your active energy, linked to that workout, for you.
- We never use HealthKit data for advertising, marketing, profiling, or any purpose other than showing and keeping your workout.
- We never sell it, never share it with anyone, and do not pass it on to data brokers or advertisers.
- It leaves your device only to our own server in the European Union, over an encrypted connection, and only as part of your workout. We do not store HealthKit data in iCloud.
- We do not request any HealthKit data other than heart rate, active energy and the workout itself.
3.6 Apex Premium
| Data | What for | Legal basis |
|---|---|---|
| Status of your subscription, the product bought (monthly or yearly), start and end date, whether it renews automatically, and the environment (production or test) | Knowing whether you have Apex Premium and until when | Performance of the contract (art. 6.1.b) |
| Apple's transaction ID, the original transaction ID, a random account token that we attach to the purchase, and the ID of the most recent notification from Apple | Linking your purchase to your account, processing renewals and cancellations from Apple, restoring a purchase on a new device | Performance of the contract (art. 6.1.b) |
We never see your payment details. Payment takes place with Apple, through your Apple ID, under Apple's own terms and privacy policy. From Apple we receive only the information needed to know that there is a valid subscription.
3.7 Technical data and logs
| Data | What for | Legal basis |
|---|---|---|
| Server logs of the app server: time, requested address, response code, error messages, and the IP address the request came from | Finding faults, recognising misuse and attacks | Legitimate interest (art. 6.1.f): keeping the service secure and working |
| The queue of background jobs and the list of failed jobs, with the data of the job that failed | Running a failed job (for example an email) again | Legitimate interest (art. 6.1.f) |
The app contains no analytics SDK, no third-party crash reporting, no advertising identifier, no location tracking and no access to your contacts or photos. Training reminders are local notifications on your device: nothing is sent to us for them and we use no push service. We do not measure which screens you view. The Analytics switch in the settings exists today only to store that choice; there is nothing it turns on, and as long as that is the case, we collect nothing.
3.8 Emails we send you
We send only emails that belong to your account: the confirmation of your email address, containing the version of the terms you accepted, so that you always have it to hand; a code to reset your password; a final confirmation if you delete your account, for which we use your address one last time and then no longer keep it; and a message if this policy or the terms change materially. We send no newsletters or advertising from the app, and if we ever want to, we will ask you separately first. Legal basis: performance of the contract (art. 6.1.b) and, for the notification of changes, our transparency obligation under the GDPR and our legitimate interest (art. 6.1.c and 6.1.f).
3.9 Support
If you email us, we keep your message, your email address and what we reply, so that we can help you and understand a follow-up question. Legal basis: legitimate interest (art. 6.1.f), namely answering your question, and where it concerns a request under the GDPR, legal obligation (art. 6.1.c).
4. The website
The website apexroutine.com is hosted by OVHcloud in a data centre in the European Union. What happens on the website:
- Session cookie. A technical cookie without name or identification, which protects forms against misuse and disappears as soon as you close your browser. It is strictly necessary and requires no consent (art. 6.1.f GDPR and Article 129 of the Belgian Electronic Communications Act).
- Cookie preference. We keep your choice about Google Analytics for one year in your browser's storage (localStorage). That item contains only your choice and the time you made it, and serves solely to respect your choice. Strictly necessary, no consent required.
- Server logs. As hosting provider, OVHcloud keeps the usual access logs (IP address, time, requested page, browser). We use them only in case of faults or misuse. Legal basis: legitimate interest (art. 6.1.f).
- Google Analytics. Only with your consent in the cookie notice does Google Analytics 4 measure which pages you view, which link or search engine brought you here, your type of device and browser, and your country or region. Google Ireland Limited processes that data for us as a processor. It may be transferred to Google LLC in the United States; that happens under the EU-US Data Privacy Framework, for which Google is certified, and should that framework fall away, under the European Commission's standard contractual clauses included in Google's data processing terms. Google Analytics 4 stores no full IP addresses, we have disabled advertising features and sharing with other Google products, and we link nothing to your app account. The cookies (
_gaand_ga_…) remain for at most two years, the data in Google Analytics for at most fourteen months. You can refuse or withdraw your consent at any time via Cookie settings at the bottom of every page; if you say no after an earlier yes, we delete the Google cookies immediately. Refusing has no effect whatsoever on what you can do on the website. Legal basis: consent (art. 6.1.a). - Waiting list. If you leave your email address, we send one confirmation email. Only after you click the link in that email is your address on the list. We use it solely to send you one message when the app is released. We keep your address, your language, the time of sign-up and confirmation, and a hash with a secret addition (salted hash) of your IP address as proof of your consent. You can unsubscribe with one click in every email. Legal basis: consent (art. 6.1.a).
- Contact form. We keep your name, email address, the subject, your message and any screenshot in order to reply to you. The screenshot is not stored on the website itself and disappears together with your message. Legal basis: legitimate interest (art. 6.1.f), namely answering your question.
The website uses no other cookies, no social media buttons that track you, and no embedded third-party services other than Google Analytics after consent.
5. How long we keep data
The principle is simple: your training history is the product, so it lives as long as your account lives, and no longer. For everything around it, short, fixed periods apply.
| Data | Retention period |
|---|---|
| Account, profile, preferences, plans, workouts, sets, records, heart rate and energy, subscription data | As long as your account exists. When you delete your account: removed from our database immediately and permanently |
| Injury zones | Until you remove them or delete your account |
| Heart rate and active energy | Until you ask for deletion or delete your account; after you turn off sync, nothing more is added |
| Verification codes | Expire after 15 minutes and are cleaned up afterwards |
| Access tokens (iPhone and Apple Watch) | Until you sign out on that device, unpair the watch or delete your account |
| Server logs of the app server | 14 days, then deleted automatically |
| Failed jobs in the queue | At most 30 days |
| Database backups | Overwritten within 30 days. A deleted account may therefore remain in a backup for at most 30 days; backups are used only to restore the service after a failure, never to put data back into the app |
| Proof of an account deletion: a hashed version of your email address and the time | 3 years (legitimate interest, art. 6.1.f: our accountability obligation, art. 5.2) |
| Support emails and contact form | At most 12 months after the last message in the conversation |
| Requests under the GDPR (access, deletion, etc.) and our reply | 3 years (legitimate interest, art. 6.1.f: our accountability obligation, art. 5.2) |
| Waiting list | Until you unsubscribe, and otherwise until 90 days after the launch message |
| Google Analytics (website, after consent) | 14 months |
| Access logs of the website (OVHcloud) | According to OVHcloud's own policy as hosting provider |
When we delete data, we do so by erasing it from the database, not by anonymising and keeping it. We build no anonymised datasets from your workouts.
6. Who sees your data
We sell no data, to anyone, ever. We share it only with the parties below, each for one clear reason.
6.1 Processors working on our behalf
A processor processes data only according to our instructions, under a data processing agreement, and may do nothing else with it.
| Party | What | Where |
|---|---|---|
| OVHcloud (OVH SAS, Roubaix, France) | Runs the app server and the database holding your account, your profile and your workouts, keeps the backups, and sends the app's emails | Data centre in the European Union |
| OVHcloud (the same company) | Hosts the website, the waiting list and the contact form, and provides the mailbox support@apexroutine.com at which you reach us and from which the website's emails are sent | European Union |
| Google Ireland Limited | Google Analytics on the website, only after your consent | European Union, with possible transfer to the United States under the EU-US Data Privacy Framework |
6.2 Parties responsible in their own right
These parties do not process your data on our behalf but under their own responsibility and their own privacy statement. We do not determine what they do.
| Party | What | More |
|---|---|---|
| Apple Inc. and Apple Distribution International Ltd. | The App Store, downloading and updating the app, buying and renewing Apex Premium, Sign in with Apple, and HealthKit on your device | apple.com/legal/privacy |
| Google LLC and Google Ireland Limited | Signing in with your Google account | policies.google.com/privacy |
6.3 When we have to go further
We hand data to a public authority or court only if a law obliges us to or a valid order requires it, and then no more than what is asked. Should the business ever be transferred, your data goes with it only under this policy, and we notify you in advance.
7. Where your data is stored
Our server, the database, the backups and the website are all hosted by OVHcloud in the European Union. We ourselves transfer no data to countries outside the European Economic Area.
Two exceptions are outside our control: Apple and Google, as independent controllers, may process the data they handle at sign-in or at a purchase outside the EU under their own statements; and Google Analytics on the website may, after your consent, transfer data to the United States under the EU-US Data Privacy Framework, which the European Commission has recognised as adequate, with the standard contractual clauses as a fallback.
8. How we protect your data
- All traffic between the app, the watch, the website and the server runs over an encrypted connection (TLS).
- We store passwords only as a bcrypt hash; we cannot read them and never send them by email.
- We store verification codes hashed, they expire after 15 minutes, and after a limited number of wrong attempts they become invalid.
- Each device has its own access token. If you sign out, that device's token becomes invalid; the watch has a token of its own, so unpairing the watch does not sign out your phone. If you delete your account, all tokens become invalid.
- Access to the server and the database is limited to the person responsible and works with keys, not passwords.
- Logs are erased automatically after 14 days.
No system is perfect. Should a breach nonetheless occur that poses a risk to your rights, we report it without undue delay and, where possible, within 72 hours of becoming aware of it to the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit), and if the risk is high also directly to you, as the GDPR requires.
9. Automated decisions
The Apex Routine generator builds your weekly plan, your sets and your suggested weights automatically, based on what you have entered and logged yourself. That is automated processing. It is not a decision with legal effects or a similarly significant effect within the meaning of Article 22 GDPR: the plan is a suggestion that you can adjust, ignore or regenerate every time, and no access, price or right depends on it. We use no profiling for marketing and we do not compare you with other users.
10. Your rights
Under the GDPR you have the following rights. For each, here is how to exercise it.
| Right | What it means | How |
|---|---|---|
| Access (art. 15) | Knowing which data we hold about you and receiving a copy, and knowing who our processors are | Email support@apexroutine.com; you receive a copy in a readable and machine-readable format (JSON) |
| Rectification (art. 16) | Having inaccurate data corrected | Directly in your profile in the app, or by email |
| Erasure (art. 17) | Having your data erased, in full or in part (for example only your heart rate values) | Your whole account: in the app via Profile → Delete account, or by email; see Delete account. Part of your data: by email |
| Restriction (art. 18) | Having processing paused temporarily, for example while we look into a dispute | By email |
| Portability (art. 20) | Taking your data with you in a common, machine-readable format | By email; you receive a JSON file with your profile, your settings, your plans, your workouts, your sets and your records |
| Objection (art. 21) | Objecting to processing based on legitimate interest | By email, stating the reason; we stop unless we can demonstrate compelling grounds |
| Withdrawing consent (art. 7.3) | Undoing a consent you gave, without affecting what happened before | Injury zones: remove them in the app. Heart rate and energy: turn off the Keep heart rate switch, and email us if you also want the existing values removed. Google Analytics: Cookie settings at the bottom of the website. Waiting list: the unsubscribe link in every email |
How a request works. Email from your account's email address to support@apexroutine.com. That is how we know it is you; if you email from another address, we first ask you to show in another way that the account is yours. We reply as soon as possible and at the latest within one month. If a request is exceptionally complex, we may extend that period by two months, but we tell you so within the first month. It is free, unless a request is manifestly unfounded or excessive.
Complaints. If you are not satisfied with our reply, you can lodge a complaint with the Belgian supervisory authority: the Data Protection Authority (Gegevensbeschermingsautoriteit), Drukpersstraat 35, 1000 Brussels, gegevensbeschermingsautoriteit.be. If you live in another country of the European Union, you may also go to the supervisory authority of your own country. And you can always go to court.
11. Age
Apex Routine is intended for people aged 16 or older. We ask for your year of birth during onboarding. If it shows that you are younger than 16, you cannot continue and we delete the account you just created. We do not knowingly collect data from children. If we nonetheless discover an account belonging to someone under 16, we delete it with everything in it. If you are a parent or guardian and suspect that your child has an account, email us.
12. Changes to this policy
This is version 1.0, in force from 28 September 2026. If this policy changes, it gets a new version number and a new date, and it is published here. In the event of a material change, for example a new category of data or a new processor, we notify you in advance in the app or by email, and we ask for your consent again where the law requires it. We provide previous versions on request.
13. Language
This policy exists in Dutch, English, French and German. We do our best to keep the four versions identical. Should they nonetheless differ, the Dutch text applies, but never to your detriment for what you have read in your own language.
14. Contact
Apex Development
Beukenlaan 27, 8810 Lichtervelde, Belgium
support@apexroutine.com