EVO LVL - Privacy Policy

Last updated: 2026-07-30 · App: EVO LVL (com.bharath.evolvl) · Contact: evolvl.service@gmail.com

This policy explains what EVO LVL collects, why, where it is stored, and how you get rid of it. It is written to be read, not to be survived. If anything here is unclear, email us and we will answer.

1. Who we are

EVO LVL is a gamified fitness and habit tracker that turns workouts, sleep, nutrition and body-weight logs into game progression. The app is published by an independent developer based in India. For privacy questions, data requests, or complaints, contact evolvl.service@gmail.com (see Section 11).

2. What we collect

Information you give us:

DataWhy
Email address and display nameTo create and sign you into your account (Firebase Authentication, email/password or Google Sign-In)
Health & fitness data you type in: body weight, goal weight, workouts (exercises, sets, reps, load, duration), sleep logs, food and water logs, cardio and mindfulness sessionsThis is the product. It is what we track, score and show back to you
Profile and preferences: training path, goals, in-game customisationTo personalise your plan and the app's guidance

Information collected automatically:

DataWhy
Purchase and subscription status (via RevenueCat and the store you purchased through - the Apple App Store or Google Play)To verify your subscription or free trial and keep the App unlocked, including after a reinstall or device change
Pseudonymous app-usage events (Firebase Analytics) - e.g. sign-up, login, paywall viewedTo understand aggregate usage and improve the app. Your account ID is SHA-256 hashed before it reaches analytics - we never send the raw ID
Crash and error diagnostics (Firebase Crashlytics)To find and fix crashes. Reports are redacted and carry a hashed account ID, not your identity
App configuration and experiment assignment (Firebase Remote Config)To roll out changes safely and test which version of a screen works better
Device integrity and clock-sync signalsTo protect data integrity and prevent cheating. Results are not stored on our servers
Referral data (only if you use Invite & Earn): your invite code, which accounts were attributed to it, the status and timing of each referral, and a random app-generated install identifierTo run the referral programme and to detect self-referrals and other abuse. The install identifier is generated by the app, is hashed before it leaves your device, is not a hardware or advertising ID, cannot be linked to you across other apps, and is reset if you reinstall. We compare account identifiers such as email address between a referrer and a referred user solely to detect self-referral. People you invite are never shown to you by name, email or account ID - only an anonymous position and a status

What we do NOT collect: precise or background location; your contacts, SMS, or call logs; microphone audio; any data from Apple Health, Google Fit, Health Connect or any wearable. Every health figure in EVO LVL is one you typed in yourself.

Camera: the app can use your camera to scan a food barcode. The image is processed on your device to read the barcode and is never uploaded or stored. You can decline the permission and keep using the app - just search foods by name instead.

3. Where your data lives, and how it is protected

No system is perfectly secure, and we do not claim otherwise. We use the protections above because they are the strongest ones practically available to an app of this kind - not as a guarantee against every possible attack.

4. How we use your data

We do not sell your personal data. We do not share it with advertisers. We do not use your health data for advertising. We do not make automated decisions that have legal or similarly significant effects on you.

5. Notifications

Reminders are off by default. We ask for notification permission only after you have used the app enough for a reminder to be useful, and only when you tap to enable them - never at first launch. Reminders are scheduled on your device from your own streak and log data; we do not run a server that watches you. You can turn them off per-category, set quiet hours, or revoke the permission in your device Settings (iOS or Android) at any time. If you decline, everything else in the app keeps working.

6. Who else processes your data

ProcessorWhat they handle
Google Firebase (Authentication, Firestore, Cloud Functions, Analytics, Crashlytics, App Check, Remote Config)Account, cloud storage, diagnostics, configuration
RevenueCatSubscription and entitlement management
Apple App Store / Google Play BillingPayment processing on the store you purchased through. We never see or store your card details

Each processes data under its own privacy terms. Your data may be processed on servers outside your country; where required, transfers rely on the safeguards those providers publish.

7. How long we keep it

DataRetention
Your account and health/fitness dataUntil you delete your account. Then erased as described in Section 8
Local on-device dataUntil you delete your account or uninstall the app
Crash and analytics recordsRetained by Google under Firebase defaults (typically up to 14 months for analytics, up to 90 days for crash reports)
Internal rate-limit and webhook recordsAutomatically expire within 24 hours to 30 days
Referral records and their audit logAnti-fraud signals expire after 12 months. Referral and reward records are kept for 24 months as a record of rewards issued. When you delete your account your referral code is deactivated and your identifier is stripped from any referral you were part of - the anonymised record of a reward another user already earned is retained, because it is a financial record
Billing recordsApple or Google retains transaction records under its own policy and tax law. We do not control this

8. Deleting your account and data

In the app: Settings → Delete Account (also reachable from the subscription screen if you are not subscribed). You will be asked to re-authenticate, because this is irreversible.

Without the app (web request): email evolvl.service@gmail.com with the subject "Account Deletion Request", from the email address on your account. We will verify ownership and complete the erasure within 30 days.

Deletion removes:

  1. Your local encrypted data on the device.
  2. Your cloud profile, weight history, routines, and subscription/access records (a recursive server-side delete of everything under your account).
  3. Any files you uploaded.
  4. Your authentication account itself.

What deletion does not do: it does not cancel your subscription. Apple or Google owns your billing relationship - cancel in the App Store or Play Store first, or you may continue to be charged for an account that no longer exists. It also does not remove records Apple or Google must keep for tax and accounting.

Deletion is permanent and cannot be undone.

9. Your rights

Wherever you live, you can:

We will not discriminate against you for exercising any of these rights - using them will never get you worse service, higher prices, or a degraded app experience.

If you are in the EEA or UK, our legal bases are: performing our contract with you (running the app and your subscription), your consent (notifications, camera), and our legitimate interests (security, anti-abuse, aggregate product improvement). Where we rely on legitimate interests you have the right to object; where we rely on consent you can withdraw it at any time. You may lodge a complaint with your local supervisory authority. If you are in India, you may raise a grievance under the Digital Personal Data Protection Act, 2023 with the contact in Section 11, and you have the right to nominate another person to exercise your rights on your behalf in the event of your death or incapacity (see Section 11). If you are in California, we do not sell or share your personal information as those terms are defined under the CCPA/CPRA, and we do not discriminate against you for exercising your privacy rights.

Sensitive data. The health and fitness figures you enter may be treated as "sensitive personal information" under some laws (for example the CPRA in California, or "sensitive personal data" under the DPDP Act and GDPR). We use this data only to provide the app and its features to you - to track, score and show back your own logs. We do not use it for advertising, and we do not sell or share it.

10. Children

EVO LVL is not intended for children under 13, or under the minimum digital-consent age in your country (16 in parts of the EEA), whichever is higher. We do not knowingly collect data from children. If you believe a child has created an account, email us and we will delete it.

11. Contact and grievances

Privacy questions, data requests, and complaints: evolvl.service@gmail.com

Grievance Officer (India, DPDP Act 2023): Bharath Adithya - evolvl.service@gmail.com

Nominating someone (India, DPDP Act 2023): you may nominate another individual to exercise your rights over your data in the event of your death or incapacity. To do this, email us from the address on your account with the nominee's details and we will record the nomination.

We aim to acknowledge any request within 72 hours and resolve it within 30 days.

12. If something goes wrong (data breach)

If we become aware of a security breach that affects your personal data, we will act to contain it and, where the law requires it, notify you and the relevant authority (such as the Data Protection Board of India under the DPDP Act, or your supervisory authority under the GDPR) within the timeframes that law sets. We will tell you what happened and what you can do, to the extent we are able. We cannot promise that a breach will never happen - no service can - but we can promise to take it seriously and to be honest with you if it does.

13. Changes to this policy

We may update this policy. Material changes will be reflected in the "Last updated" date at the top and, where the change is significant, shown to you inside the app. Continuing to use EVO LVL after a change means you accept the updated policy.

See also: Terms of Use