Alignment

Legal

Privacy Policy

Alignment: Posture & Back Pain — mobile application for iOS and Android.

Effective 3 August 2026 Last updated 3 August 2026

This Privacy Policy describes how personal information is collected, used, disclosed and retained in connection with the mobile application Alignment: Posture & Back Pain. It applies to the application on iOS and Android and to any related services operated by the Publisher. It does not apply to any third-party service that maintains its own privacy policy.

In this Policy, “Alignment” or the “App” means the mobile application identified above; “we”, “us” and “our” mean Daniel Namatinia, an individual developer trading as a sole trader (the “Publisher”); and “you” means the individual who uses the App. For the purposes of the UK General Data Protection Regulation, the EU General Data Protection Regulation and comparable legislation, the Publisher is the data controller in respect of the personal information described in this Policy.

Contents — 11 sections
  1. Information We Collect
  2. Posture and Flexibility Scan Data
  3. How We Use Information
  4. Third-Party Services and Disclosure
  5. Storage, Transfers and Retention
  6. Device Permissions
  7. Children’s Privacy
  8. Your Rights and Choices
  9. Data Security
  10. Changes to This Policy
  11. Contact

1Information We Collect

We collect only information that is provided by you within the App, generated by your use of the App, or derived on your device and subsequently synchronised. We do not purchase personal information from third parties, and we do not combine your information with data obtained from data brokers.

1.1 Account information

An anonymous account is created automatically when the App is first opened, in order that your progress may be stored and synchronised. That account contains no name and no email address; it is nevertheless an account held on our servers, and your activity within the App is recorded against it from the first session, whether or not you subsequently sign in. Where you elect to establish a named account, we receive:

  • Sign in with Apple. Your name, where you elect to share it, and either your email address or the private relay address issued by Apple. We do not receive your Apple Account password.
  • Sign in with Google. Your name, email address and Google profile image. We do not receive your Google password.
  • Email sign-in. Your email address, for the purpose of issuing a six-digit sign-in code.

1.2 Profile and preferences

The display name you enter, a profile image where you elect to select one from your device library, your theme and language preferences, and whether daily reminders are enabled.

1.3 Setup responses

Your stated goals, your reported level of physical activity, and the areas in which you report stiffness or tension. This information is provided voluntarily and is used to personalise routines and to establish baseline scores. Because it describes your physical condition, it is treated as health-related information; see clause 3.3. We additionally record which variant of an onboarding screen was presented to you where two variants are under test, so that your experience remains consistent between sessions.

1.4 Activity and progress

The routines you complete and the times at which you complete them, session duration, your current and longest streak, and any custom routines you create.

1.5 Subscription status

Payment is processed by Apple or Google. We do not receive or store payment card details. Our subscription management provider reports to us the product you hold, whether it is active, whether a trial period is running, and a purchase identifier. A copy of that status is replicated to our own database so that the App may determine your entitlements.

1.6 Correspondence

Feedback and support messages, including any content you elect to include within them, together with basic application context such as the application version, for the purpose of reproducing reported faults.

1.7 Usage analytics and diagnostics

  • Product analytics. The screens you open, the features you use, onboarding and subscription funnel events, and device model, operating system version, application version, language and the country from which your connection originates. Certain events carry additional properties: upon completion of a scan we transmit the resulting posture or flexibility score together with the reliability of the reading; each captured scan view reports the measured tilt of the device; and upon completion of onboarding we transmit the display name you entered. The App additionally records interactions automatically, and an interaction event carries the text of the control touched, which includes the label of a response selected during setup.
  • Session replay. In release builds the App records a replay of the screens presented and the interactions performed, for the purpose of identifying usability defects. Because the recording is of screens, a replay may include any screen presented to you, including screens displaying your setup responses or your scan results.
  • Diagnostic reports. Upon a fault, the technical particulars of the fault, device and operating system information, and the IP address from which the device connected, which is received by our error-reporting provider with the report.

1.8 Information we do not collect

We do not collect: photographs, video or camera frames captured during a scan; your geographic location, for which the App holds no permission and issues no request; your contacts, calendar entries, microphone input, or data held in Apple Health or Google Fit; payment card or bank details; or any information originating from other applications on your device. Our analytics and error-reporting providers receive the IP address from which your device connects, from which an approximate country may be inferred, as stated in clause 1.7.

Reminders are scheduled locally on your device. We therefore hold no push notification token and are unable to issue server-initiated notifications.

2Posture and Flexibility Scan Data

2.1 Processing of images

The posture and flexibility scan operates by means of a pose-estimation model executed entirely on your device. For each view captured, the camera writes a single still image to a temporary file on your device. That image is measured by the on-device model and is used by the results screen to display the tracked skeleton over the captured frame. The file remains on your device until you commence a further scan, at which point the previous set is cleared.

No photograph, video or camera frame is at any time transmitted to us, uploaded to our servers, copied to your device photo library, or otherwise disclosed to any third party. Only the derived measurements described in clause 2.2 are transmitted.

2.2 Derived measurements retained

Upon completion of a scan, the following are recorded and synchronised to your account:

  • your posture score and flexibility score;
  • the constituent measurements, being head-forward, head tilt, shoulder symmetry and hip level for posture, and forward fold, overhead reach and side bend for flexibility, retained both as the normalised sub-score and as the underlying angle or ratio, so that historical scans may be re-scored rather than reinterpreted upon a revision of the scoring model;
  • the observations presented in your results;
  • the reliability of the reading, whether it was designated low-confidence, the views captured, whether the capture-quality conditions were satisfied, the capture mode employed, and the provenance of the pose measurement;
  • the version of the scoring model and the time at which the scan was scored.

2.3 Device motion

During a scan the App samples the motion sensors of your device in order to confirm that the device is level, a tilted device being otherwise indistinguishable from an equivalent degree of postural asymmetry. The reading is applied at the time of capture, and the measured tilt angles are included in the analytics event transmitted upon capture of a view, so that an unreliable reading may be distinguished from an unusual posture.

3How We Use Information

3.1 Purposes and legal bases

PurposeInformation usedLegal basis (UK and EU)
Operation of the App, retention of progress, and synchronisation between your devicesAccount, profile, activity, custom routinesPerformance of a contract
Personalisation of routines and scores, and retention of scan historySetup responses, scan scores and measurementsExplicit consent — see clause 3.3
Administration of subscriptions and restoration of purchasesSubscription statusPerformance of a contract
Diagnosis and correction of faultsDiagnostic reports, including IP addressLegitimate interests in maintaining a functioning application
Analysis of usage and improvement of the AppUsage analytics, session replayLegitimate interests in improving the App; consent where required by local law
Attribution of installations to a marketing sourceDevice identifiers, IP addressConsent, given through the iOS tracking prompt
Response to correspondenceYour message and accountLegitimate interests in providing support
Compliance with legal, tax and accounting obligationsPurchase and subscription recordsLegal obligation

We do not use personal information for any purpose other than those stated above. In the event of a material change to those purposes, this Policy will be amended and, where required by law, your consent will be obtained in advance.

3.2 No sale and no advertising use

We do not sell personal information, and we do not share personal information for cross-context behavioural advertising, as those terms are defined under the California Consumer Privacy Act. Health-related responses and scan scores are not used for advertising of any kind. The App carries no advertising.

3.3 Health-related information

Certain information provided to the App, namely the areas in which you report stiffness or tension and the posture and flexibility scores derived from a scan, may constitute data concerning health under the UK and EU General Data Protection Regulation and sensitive personal information under certain United States state legislation. It is treated as such irrespective of your place of residence.

  • Such information is processed on the basis of your explicit consent, given by electing to respond to the setup questions concerning your physical condition and by electing to perform a scan, the camera permission for which constitutes a separate and deliberate step.
  • Consent may be withdrawn at any time. Selecting Delete account & reset data within the App erases your setup responses and your entire scan history from your device and from our servers. One category falls outside that operation: the scores and selected response labels previously received by our analytics provider, as described in clauses 1.7 and 4.1. Those may be erased upon request under clause 8.3. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.
  • Under California law, such information is used solely to provide and personalise the App. It is not used to infer characteristics concerning you and is not used for advertising. Because its use is limited to purposes permitted without a separate election, the right to limit the use of sensitive personal information does not arise. The right of erasure under clause 8.1 is unaffected.

3.4 Automated processing

Posture and flexibility scores are generated automatically by a model executed on your device from the measurements it obtains. Such processing does not produce legal effects concerning you and does not similarly significantly affect you. It operates solely to personalise a wellness application, and no decision of consequence is taken on its basis.

4Third-Party Services and Disclosure

4.1 Service providers

We engage the following service providers in the operation of the App. Each receives only the information required for the performance of its function.

ProviderFunctionInformation receivedLocation
SupabaseAccounts, database and profile-image storageAccount, profile, setup responses, activity, custom routines, scan scores and measurements, correspondence, replicated subscription statusEuropean Union (EU Central, Frankfurt)
RevenueCatSubscription management and installation attributionSubscription status, purchase identifier, user identifier, device identifiers (advertising identifier where tracking is permitted, and vendor identifier) and IP addressUnited States
PostHogProduct analytics, session replay and A/B testingUsage events, device and application metadata, user identifier, display name, posture and flexibility scores, the text of controls touched (including setup response labels), and session replays of application screensUnited States
SentryDiagnostic and error reportingFault particulars, device and operating system metadata, IP addressEuropean Union (Germany)
AppleSign in with Apple, App Store distribution and billingOnly such information as it holds in its capacity as your platform providerGlobal
GoogleGoogle sign-in, Google Play distribution and billingOnly such information as it holds in its capacity as your platform providerGlobal

4.2 Processor obligations

Supabase, RevenueCat, PostHog and Sentry act as our processors. Each is bound by a written data processing agreement requiring it to protect your information to a standard at least equivalent to that set out in this Policy and required by the Apple App Store Review Guidelines, to process it only upon our documented instructions, to maintain its confidentiality, and to delete or return it upon termination of the engagement. No such provider is permitted to use your information for its own purposes.

4.3 Independent controllers

Apple and Google act as independent controllers in respect of data processed when you sign in by their means or purchase a subscription through their stores. Such processing is governed by their respective privacy policies and is not carried out upon our instructions.

4.4 Other disclosure

Beyond the providers identified above, personal information is disclosed only where required by law, including in response to a valid legal request, or where necessary to establish, exercise or defend a legal claim. In the event that the App is sold or otherwise transferred, personal information may transfer with it, and this Policy will continue to apply until you are notified otherwise.

5Storage, Transfers and Retention

5.1 Location of storage

Your account and all information synchronised to it are held in our database in the European Union (EU Central, Frankfurt). Diagnostic reports are processed in Germany. Analytics and subscription management are performed in the United States.

5.2 International transfers

Where personal information is transferred outside the United Kingdom or the European Economic Area, principally to our analytics and subscription providers in the United States, such transfer is effected under an appropriate safeguard, being the United Kingdom International Data Transfer Addendum, the Standard Contractual Clauses adopted by the European Commission, or the EU–US and UK–US Data Privacy Framework where the provider is certified thereunder. Details of the safeguard applicable to a given provider are available on request.

5.3 Retention periods

CategoryRetention
Camera stills captured during a scanRetained on your device to enable display of results and cleared upon commencement of a further scan. Never transmitted
Account, profile, setup responses, activity, custom routines, scan scoresFor so long as your account subsists
Accounts exhibiting no activityDeleted following 24 months without the App being opened
Correspondence24 months following conclusion of the matter
Product analytics and session replaysUp to 12 months
Diagnostic reportsUp to 90 days
Purchase and taxation recordsFor the period required by taxation and accounting legislation, ordinarily 6 to 7 years

6Device Permissions

Each permission requested by the App is optional, is explained at the point of request, and may be withdrawn at any time through your device settings. The App remains functional in the absence of any of them.

  • Camera. Used solely for the posture and flexibility scan. Refusal renders the scan unavailable and has no other effect.
  • Photo library. Used solely to set a profile image.
  • Motion and fitness. Used solely for the device level check performed during a scan.
  • Notifications. Used solely for the daily reminder you schedule. Reminders are generated locally on your device.
  • Tracking (iOS). The App presents the App Tracking Transparency prompt for the purpose of attributing installations to a marketing source. Where tracking is permitted, your device advertising identifier is transmitted to our subscription provider for that purpose; your vendor identifier and IP address are transmitted irrespective of your election. Such identifiers are not used to construct advertising profiles, and you are not tracked across the applications or websites of other undertakings.

Permissions may be amended at iOS Settings → Alignment, or at Android Settings → Apps → Alignment → Permissions. The tracking election is located at iOS Settings → Privacy & Security → Tracking.

7Children’s Privacy

The App is not directed at children and is not intended for any person under the age of 16, consistent with the age requirement stated in our Terms of Service. We do not knowingly collect information from any person below that age, and within the United States we do not knowingly collect information from any person under the age of 13. Where you believe that a child has provided information to us, please contact us and it will be deleted.

8Your Rights and Choices

8.1 Erasure of your information

Two routes to erasure are available.

Within the App. Profile → Delete account & reset data. This operation is not confined to your device. It erases from our servers, and from your device, your setup responses and goals, your profile record including your display name, your streak and completed-session history, every posture and flexibility scan together with the measurements constituting it, and the contents of your custom routines. Because the server copy is erased, the operation takes effect across every device on which you use the App, and it operates whether or not you have signed in. It does not erase your sign-in identity, your profile image where one has been uploaded, correspondence, your subscription record, or the analytics copy described in clause 1.7.

By written request. To procure erasure of the remaining categories, use the account deletion page or contact us under clause 11. We will erase your account and all records associated with it, instruct our processors to do likewise, complete the operation within 30 days, and confirm completion in writing.

The only information surviving erasure is that which we are required by law to retain, including evidence of purchase for taxation purposes, and aggregate statistics from which you cannot be identified. Erasure of your account does not cancel a subscription; cancellation must be effected with Apple or Google.

8.2 Rights available to you

Subject to your place of residence, you hold some or all of the following rights: to obtain access to a copy of the information held concerning you; to obtain rectification of inaccurate information; to obtain erasure; to receive your information in a portable format; to object to or obtain restriction of processing conducted on the basis of legitimate interests; and to withdraw consent at any time without affecting the lawfulness of prior processing.

Residents of California, Colorado, Connecticut, Virginia and other states having comprehensive privacy legislation additionally hold the right to know the categories of information collected and the purposes of collection, to access, delete and correct such information, and to appeal a refusal. No adverse treatment will result from the exercise of any right.

Requests should be directed to the address in clause 11. No charge is levied, and we respond within one month. We may first require verification of your identity, ordinarily by reply from the email address associated with your account.

8.3 Withdrawal of permissions and analytics

Permissions may be withdrawn through your device settings as described in clause 6. To procure the disabling of product analytics and session replay, and the erasure of the analytics profile and replays held in respect of you, contact us under clause 11.

8.4 Complaints

Where you are situated in the United Kingdom or the European Economic Area and consider that your information has been handled improperly, you may lodge a complaint with your supervisory authority, being the Information Commissioner’s Office in the United Kingdom (ico.org.uk) or the corresponding national authority within the European Union. We invite you to raise the matter with us in the first instance.

9Data Security

Information is encrypted in transit and at rest with our providers. Records are protected by row-level security, such that an account is capable of reading and writing only its own records. Access to production systems is restricted to those persons requiring it. Scan imagery, being the most sensitive category of information processed by the App, does not leave your device and is accordingly excluded from that risk surface entirely.

No system of security is absolute. In the event of a breach affecting your personal information, we will notify you and the relevant supervisory authority without undue delay and within the periods prescribed by law.

10Changes to This Policy

This Policy may be amended from time to time. The revised Policy will be published on this page and the effective date amended accordingly. Where an amendment is material, notice will be given within the App prior to the amendment taking effect, and where required by law your consent will be obtained afresh.

11Contact

Enquiries concerning this Privacy Policy, requests to exercise data subject rights, and requests for erasure of personal information should be directed to:

danielnamatinia02@gmail.com

Daniel Namatinia, sole trader, publisher of Alignment. Enquiries are ordinarily answered within five working days. Requests under clause 8.2 are answered within one month.