Effective date: 2 Sep 2026

Whisk Mobile Development Pty Ltd ("we", "our", "us") is the controller of the personal information described in this policy. It explains how Praxis handles information when you use the app, including beta versions and future updates.

1. Health and workout data

Praxis can connect to Apple Health and, only with the permissions you choose in Apple's Health settings, read and write health and workout data needed for its fitness features. This can include heart rate and completed cycling workouts. Praxis uses that data to show and record your rides. We do not send it to our servers, use it for advertising, or disclose it to third parties.

On a shared iPad setup, a rider's Apple Watch writes a completed workout to that rider's own Apple Health database. You can change or withdraw Health access at any time in Apple's Health settings.

2. Operational services

Praxis uses only the following services to operate the app, manage purchases, and diagnose faults. We do not use Firebase Analytics, Google Analytics, advertising SDKs, the advertising identifier (IDFA), or tracking across other companies' apps and websites.

Sentry

Sentry receives limited diagnostics when Praxis crashes or has a performance problem: crash reports, error logs, performance metrics, device type, operating-system version, and app version and build number. It is configured to avoid collecting names, email addresses, health data, workout content, or other directly identifying information. We use it only to keep Praxis stable and secure.

RevenueCat and purchases

If Praxis offers an in-app purchase or subscription, we use RevenueCat to validate purchases, restore entitlements, and prevent purchase fraud. RevenueCat processes a random anonymous app user ID, technical device information, and purchase information such as the Apple receipt and entitlement status. We do not send RevenueCat a name, email address, health data, or workout content.

Praxis has no accounts and does not provide RevenueCat with a custom user ID. That means we cannot ordinarily connect a RevenueCat customer record to a named person, but the random ID and technical information can still be personal data under applicable law. RevenueCat's own privacy practices are explained in its privacy policy.

Standard Apple Ads attribution through RevenueCat

RevenueCat may receive standard Apple Ads attribution information so that we can measure whether a purchase followed an Apple Ads campaign. This uses Apple's standard attribution mechanism, not the IDFA; it does not invoke Apple's App Tracking Transparency prompt, enable detailed attribution, or send purchase events to an advertising network. We use the information only in RevenueCat's own reporting for purchase measurement.

Google Firebase

Praxis uses Firebase only for an anonymous installation identifier, Remote Config, and App Check. The identifier lets app settings and purchase entitlements work across launches. Remote Config sends standard request metadata such as IP address and device type so we can safely deliver a configuration. App Check helps verify that a request comes from a genuine, unmodified copy of Praxis. We do not use Firebase Analytics.

3. Why we process this information

We process Health data only with the Health permissions you choose, and only to provide the fitness features you request. Where applicable, this is based on your explicit consent; you can withdraw it through Apple's Health settings.

We process purchase information to perform our agreement with you and to prevent fraud. We process limited diagnostics, app-integrity, configuration, and standard Apple Ads attribution information on the basis of our legitimate interests in running a reliable, secure app and measuring the effectiveness of our own Apple Ads. We balance those interests against your privacy and collect only the information needed for those purposes. You may object to processing based on legitimate interests by contacting us.

4. Beta testing and contact

If you contact us to ask about beta access, we use the contact details and message you provide to reply and, if you choose to join, to manage your beta access. TestFlight invitations are managed through Apple App Store Connect. You can ask us to remove you from the beta at any time.

5. Retention, security, and international processing

Health and workout data stays on your devices and in Apple Health unless you choose to delete it there. We retain beta-contact information only for as long as it is needed to reply or manage the beta. Operational service providers retain their limited records under the retention settings and legal obligations that apply to their services; we keep those settings no longer than needed for the purposes described above.

Sentry, RevenueCat, and Google Firebase may process limited technical or purchase information outside Australia and the country where you live, including in the United States. Where required, we use the providers' contractual and other appropriate safeguards for international transfers. Technical information is transmitted over encrypted connections using industry-standard transport security, such as HTTPS/TLS.

6. Your rights and complaints

Depending on where you live, you may ask us to access, correct, delete, or restrict the personal information we hold about you; object to processing based on legitimate interests; or request a portable copy where the law provides that right. You may withdraw Health permissions at any time in Apple's Health settings. You may also complain to your local privacy regulator.

To make a request or privacy complaint, email privacy@whiskmobile.com. We will investigate and respond to complaints. If you are unhappy with our response in Australia, you may contact the Office of the Australian Information Commissioner.

7. Changes to this policy

We may update this policy to reflect changes in legal requirements or Praxis. The effective date at the top of this page shows when it was last revised.