Privacy Policy
Last updated: September 11, 2026
1. Introduction
Roster ("we," "our," or "us") is a fitness calculator app for iPhone: 31 calculators, a roster of profiles to run them against, saved histories, and PDF export. This Privacy Policy explains what data we collect, what we don't, and how your data flows between your device, Firebase, RevenueCat, and Apple.
Roster is built by one developer. We don't sell your data, we don't run ads, we don't include any analytics SDK, and we don't track you across other companies' apps or websites. There are also no sharing features of any kind: nothing you put into Roster is ever visible to another user.
2. How Your Data Flows
The cleanest way to understand Roster's privacy model is to follow the data:
- Device ↔ Firebase Auth (sign-in): You sign in with Apple or Google; there is no email-and-password option. Your chosen provider authenticates you and returns a token to Firebase Authentication over HTTPS. We never see your Apple or Google password. Apple may relay a private email address if you choose to hide yours.
- On your device (the calculations): Every formula in Roster is computed locally on your phone. Your inputs are not sent to any server to produce a result. The only thing that happens remotely when you calculate is a counter on your account incrementing by one, which is how the free allowance is enforced.
- Device ↔ Firestore (your account data): Your account record (display name, email, unit preference, pinned calculators, preferred formulas, calculation count, and subscription status), the profiles you create (name, sex, birthdate, height, weight, activity level, tape and skinfold measurements, resting heart rate, and any notes you write), and the results you choose to save (the metric, the formula, the exact inputs, the outputs, and the date) are stored in Google Firestore under your user ID (UID). Security rules scope every document to your own UID; no other user can read or write your data. Offline persistence keeps a local copy on your device so the app works without signal and syncs later.
- Device ↔ Firebase Storage (profile photos): If you set a photo on a profile, one image per profile is downsized to 512 pixels and stored in Firebase Storage under a path keyed to your UID, readable only by your signed-in account. Photos never appear in exported PDFs.
- Device ↔ RevenueCat ↔ Apple (Roster Pro): If you subscribe, Apple processes the purchase. RevenueCat sits between the app and Apple to report whether your subscription is active; it receives your UID and the subscription data Apple returns. A server function listens to RevenueCat to switch your account's entitlement on and off. We never see your Apple ID or payment method.
- PDF export stays local: Reports are rendered on your device and handed to the iOS print and save sheet: your printer, your Files. Nothing is uploaded, and no export contains a link, a QR code, or anything addressed to a third party. Notes and profile photos are deliberately excluded from every export.
3. Information We Collect
Account information
- Email address and display name as shared by your sign-in provider (Apple may relay a private address)
- A Firebase Authentication user ID (UID)
- The sign-in provider you used (Apple or Google)
Profiles and measurements
- For each profile you create: a name, and optionally sex, birthdate, height, weight, activity level, body measurements (neck, waist, hip, skinfolds, resting heart rate, current lifts), notes, and a photo
Saved results
- For each result you choose to save: which calculator and formula, the inputs used, the outputs, the date, and an optional note
App settings and subscription state
- Unit system, pinned calculators, preferred formula per calculator, how many of your free calculations you've used, and whether a subscription is active
4. What We Don't Collect
- No analytics or usage tracking of any kind; there is no analytics SDK in the app
- No precise (GPS) or approximate location
- No contacts, camera roll scanning, or microphone recording; photo access is only the picker for a photo you choose
- No Apple Health / HealthKit data
- No advertising identifiers, no data sold or shared for advertising
5. People on Your Roster
If you're a coach, the client profiles you create are records you typed into your own account. Roster has no relationship with the people those profiles describe: it never contacts them, never shows them anything, and by design has no field for their email or phone number. Their measurements and your notes about them are visible only to your signed-in account, and notes never appear in an exported PDF, so a report you hand a client contains their numbers and nothing you wrote privately. You are responsible for having a person's permission before recording their measurements.
6. Third-Party Services
Roster relies on these processors, each receiving only what's described above:
- Google Firebase (Authentication, Firestore, Cloud Functions, Storage): accounts, app data, and profile photos
- RevenueCat and Apple: subscription status and billing
7. Data Retention and Deletion
Your data is kept while your account exists. Profiles and saved results can be deleted individually inside the app at any time. To delete everything, open Settings inside the app and tap Delete account: a server function permanently removes your Firestore data, your profile photos from Storage, and your Firebase Auth record. This is irreversible. Deleting the app from your phone removes the local copy but not your account; use Delete account for that, or email us and we'll do it for you.
8. Children
Roster is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, contact us and we'll delete it.
9. Changes to This Policy
If this policy changes materially, we'll update this page and the "Last updated" date above.
10. Contact
Questions about privacy or your data: support@moetalaat.com
See also: Terms of Service · Support
