Last updated: July 19, 2026
Privacy Policy
Strikt is an iOS fitness app and website operated by Francesco Morrone. This policy explains what information Strikt collects, how it is used, and the choices available to you.
Information We Collect
If you joined Strikt's website launch waitlist before the public App Store release, we collected the email address you submitted, submission time, browser locale, landing-page path, referring website domain, form placement, and any campaign labels included in the link you followed: utm_source, utm_medium, utm_campaign, utm_content, and utm_term. The public website no longer offers a waitlist form. Legacy records may retain both first and most recent source attribution.
In the app, Strikt may collect account identifiers, profile information, fitness and workout results, product interaction events, crash data, diagnostic logs, user-submitted feedback, community product ideas, votes and moderation reports, and media you choose to upload, such as avatars or share images.
Website Analytics And Your Choice
Optional website analytics are off unless you choose to allow them. If you do, Strikt uses a PostHog Cloud EU project to record a limited set of manually defined events, such as viewing a landing page, clicking an App Store download link, or opening a contextual app link. Event properties are limited to information such as the page type, button placement, destination, referring domain, and the campaign labels listed above. An App Store click does not tell us whether you installed the app or created an account.
Strikt does not send your email address, private feedback text, or community idea text to PostHog, does not identify you in PostHog by email, and does not intentionally send full URLs, arbitrary query parameters, race codes, or inviter handles. Website analytics use manual events only: autocapture, heatmaps, and session replay are disabled, person profiles are not created, and IP address capture is disabled for the PostHog project. Events can include coarse browser, operating-system and device category details, event time, SDK version, and random pseudonymous device and session identifiers. If you allow analytics, PostHog is configured to keep its identifier and analytics session state in first-party session storage, which normally clears when the browser tab closes. This state is not connected to a former waitlist email address or an app account.
Your analytics choice is stored as a first-party browser preference for up to six months so that the website can remember it. Refusing analytics does not limit the website or your access to the App Store.
Camera And Motion Data
Strikt uses the device camera to count reps and score form. For training, raw camera video and pose processing are designed to run on device. Strikt stores workout results and limited rep evidence needed for app functionality, leaderboards, integrity checks, and progress history. During a live race with video enabled, your camera is additionally streamed to your opponent as described in the next section.
Live Race Video
During head-to-head races you can choose to share live video with your opponent. Video streams directly between the two devices (peer-to-peer), is shown only to your opponent for the duration of the race, and is never recorded, stored, or viewed by Strikt. Video flows only when both athletes have it enabled, and you can pause or turn it off at any time, including mid-race, from Settings or the race screen. Live race video is available only to athletes aged 18 or over.
To establish the direct connection, connection setup data (including device network addresses) is exchanged through our infrastructure, readable only by the two race participants, and deleted after the race.
For safety, both athletes complete a short check-in after every race with video. Reports of inappropriate behavior result in the reported athlete being blocked from matching with the reporter and can suspend the reported athlete's access to video features. Reports are stored for moderation and abuse-prevention purposes and are not visible to the reported athlete.
How We Use Information
We use information to provide the app, manage accounts, maintain any necessary legacy waitlist records, show training history and social features, process subscriptions, prevent abuse, diagnose issues, improve product quality, measure the aggregate effectiveness of acquisition campaigns, and communicate about service updates.
Ideas And Community Feedback
Strikt Lab lets signed-in athletes submit product ideas and vote on published requests. Ideas are reviewed before publication. Published cards do not display an author name, handle, avatar, or account identifier, but Strikt keeps the submitting account identifier privately so it can enforce one vote per account, rate limits, blocking, moderation, and account deletion.
Reports and blocks are private. Other athletes do not see who reported or blocked a post. Do not include names, contact details, links, health information, or other personal information in an idea. Private bug reports, screenshots, and diagnostic logs use a separate support system and are never turned into community posts.
Service Providers
Strikt uses Firebase for authentication, database, storage, functions, and legacy waitlist records; RevenueCat for subscription entitlement management; Apple services for App Store purchases and Sign in with Apple; Resend for transactional and prior waitlist emails; and PostHog for app product analytics and, where enabled, crash reporting. In the app, Usage Sharing is enabled by default on new installations and can be disabled persistently in Settings. Consent-gated website analytics are processed separately through PostHog Cloud EU; the website does not automatically send browser exceptions or diagnostic logs to PostHog.
Advertising Attribution
If we run app-install advertising campaigns, install attribution uses Apple's privacy-preserving SKAdNetwork and the Meta (Facebook) SDK, which may log app install and app launch events to Meta. Advertiser-ID collection is disabled, and Strikt does not track you across other companies' apps or websites without your permission.
Legal Bases
Where GDPR applies, legacy waitlist information was processed to take the steps you requested and send the launch notice you asked for. We rely on our legitimate interests to measure aggregate campaign effectiveness using bounded campaign labels and reduced source information, without unique recipient tags. Optional website analytics and non-essential access to browser information are based on your consent. We also process information where necessary to perform our contract with you, comply with legal obligations, and pursue legitimate interests such as security, fraud prevention, service diagnostics, and product improvement, after considering your rights and interests.
Retention
Legacy waitlist records are kept only as long as needed to handle delivery, support, security, and legal needs related to the requested launch notice. We periodically review and delete records that are no longer needed, and you may ask us to delete yours sooner. Consent-gated website analytics event data is retained for no more than 12 months and is then deleted or converted into aggregate statistics. The first-party preference that remembers your analytics choice is kept for up to six months.
Account data is kept while your account is active or as needed for legal, security, and operational purposes. Diagnostic data is kept for a limited period and pruned when no longer needed. Deleting your account removes product ideas you authored and your account-level votes, reports, blocks, and rate-limit records from Strikt systems, subject to limited legal or security retention where required.
Your Choices
You can accept or refuse optional website analytics when asked. You can later change or withdraw that choice at any time through the Cookie settings control on the website. Withdrawal stops future website analytics events and clears the website's local analytics state; it does not affect processing that was lawful before withdrawal. You can use the website and follow App Store links even if you refuse analytics.
You can request access, correction, deletion, restriction, or export of personal information, and you can object to processing based on legitimate interests, by contacting us. In the app, you can delete your account from settings, which starts deletion of account data handled by Strikt systems. You can turn Usage Sharing off persistently in Settings at any time; doing so stops future app product-analytics and consent-aware diagnostic events and clears the active analytics runtime on that device. You can turn it back on later.
If you are in the EU or EEA, you also have the right to lodge a complaint with your data protection authority — in Italy, the Garante per la Protezione dei Dati Personali.
Children
Strikt is not intended for children under 13, or under the minimum age required in your jurisdiction. Do not use Strikt if you are not old enough to consent to this policy. Live race video is limited to athletes aged 18 or over; profiles under 18 have it locked off and race on the skeleton view.
International Transfers
Website analytics data is hosted through PostHog Cloud EU. Other providers may process data in countries other than your own. When required, we rely on appropriate safeguards for international transfers.
Contact
For privacy questions or requests, contact privacy@strikt.fit.