Zap

PRIVACY

Privacy Policy

Zap is designed so your personal workout data stays on your device.

Effective August 9, 2026

Data collection

Zap does not ask for or send names, contact details, account data, workout records, exercise names or identifiers, weights, reps, dates, notes, or search terms.

If you explicitly enable the integration in Settings, Zap may read your height, weight, date of birth, and biological sex from HealthKit on iOS. Health data, permission state, and latest values are not stored in the app database or sent to external services.

Release builds send intentionally selected product events to PostHog in the European Union. These events contain fixed action or screen names, a random pseudonymous identifier, a pseudonymous session identifier, app version and build, and operating system. The app SDK disables PostHog person profiles, GeoIP enrichment, autocapture, session replay, surveys, and logs. The RevenueCat purchase integration described below may create a pseudonymous purchase profile. Development and test builds do not initialize the PostHog app SDK.

Sending product events, crash diagnostics, and performance measurements is off by default and requires your consent. You can turn "Share usage statistics" on during onboarding or anytime in Settings, and turn it back off the same way. While it is off, none of those three categories are sent. Stored events are deleted when the retention period of the PostHog plan expires.

Regardless of that setting, Zap fetches only the minimum supported native build numbers from PostHog remote configuration to decide whether a store update is required. This request sends no usage data. If the setting cannot be fetched, Zap uses a cached value or continues normal operation.

With your consent, release builds use PostHog error tracking to automatically collect crash traces and app version information, then send them to PostHog when a crash occurs or the app next starts. Without consent, crashes are not captured at all. Debug builds do not send crash diagnostics.

With your consent, release builds send performance measurements for app startup and screen transitions to EAS Observe, operated by Expo. These contain elapsed times and frame statistics, a random anonymous installation identifier, an anonymous session identifier, app version and build, operating system and version, device model, and country. Screens are identified only by their fixed route pattern, such as "/sets/[exerciseId]". The values behind dynamic route parameters and the resolved URL are never sent. Without consent, measurements are discarded on your device instead of being sent. Debug builds do not send performance measurements. Stored measurements are deleted after 90 days.

RevenueCat processes a random anonymous App User ID, purchase history, product and transaction identifiers, store receipts or purchase tokens, and basic app and device information to validate purchases, grant paid theme access, restore purchases, and provide purchase analytics. Zap also sends RevenueCat the reserved $posthogUserId attribute containing the random PostHog identifier.

RevenueCat sends purchase lifecycle events to PostHog. These events can include revenue, currency, products, offerings, entitlements, purchase and expiration times, transaction identifiers, RevenueCat anonymous App User IDs and aliases, store, platform, subscription status, and customer attributes. This allows purchase events and consented product events to use the same pseudonymous PostHog identifier. Zap does not send names, contact details, advertising identifiers, or workout data to RevenueCat or PostHog.

The app does not include accounts, advertising, cloud synchronization, or cross-app tracking. Zap does not combine these identifiers with third-party advertising data.

Data storage

Exercises, sets, workout history, preferences, and calculated statistics are stored only in the app database on your device.

Deleting the app or its local data may permanently remove these records. Zap does not keep a server-side copy and cannot restore them.

Notifications

Zap may request notification permission only to notify you when a local rest timer finishes. These notifications are scheduled and delivered on your device.

This website

This site uses PostHog in the European Union to measure page views, App Store link clicks, Core Web Vitals (FCP, LCP, INP and CLS), and unhandled browser exceptions. Events contain a fixed site marker, the page path without query strings or fragments, language, referring domain, browser, operating system, device type, CTA placement when applicable, performance values, and exception details. Full referrer URLs, form or email content, element text or attributes, screen dimensions, advertising identifiers, and location are not sent.

PostHog cookieless mode stores no cookies and uses no local or session storage. To count anonymous visitors per day, PostHog temporarily uses the IP address, user agent, and hostname to create a one-way hash with a salt that changes daily, then removes the IP address before GeoIP processing. The hash cannot link the same visitor across days. Person profiles, interaction autocapture, session replay, surveys, heatmaps, logs, and GeoIP enrichment are disabled.

If you contact support by email, only your message and your email address are processed, and only to answer you. Do not include personal workout data.

Changes and contact

You can use the Support page to request deletion of pseudonymous purchase analytics. Zap may need a purchase transaction or order identifier to locate the records because it has no account system. Purchase records that must be retained for entitlement, fraud prevention, accounting, or legal obligations may be kept for the required period.

If this policy changes, the updated policy and effective date will be published on this page. Questions can be sent through the Support page.