Document version token: 2026-07-29
Effective date: July 30, 2026
Last updated: July 30, 2026
Summary
Movenue is a social workout planning and coaching service for iPhone with an
Apple Watch companion. This Policy explains how Movenue
(“Movenue,” “we,” “us,” or “our”) collects, uses, discloses, retains, and
protects personal data when you use the Movenue app, website at
movenue.me, support, and related services (together, the “Service”).
In brief:
- we process account, profile, routine, social, workout, device, and support data to operate the Service;
- the Watch can provide heart rate and fitness readings only with applicable device permission and while an iPhone workout is active;
- we do not use HealthKit-derived data for advertising, sell it to data brokers, or publish private completed-workout HealthKit samples in profiles or feeds;
- live workout metric sharing is off by default and is not inferred from joining an event;
- you can manage visibility and other preferences, export supported data, and delete your Movenue account inside the app;
- the full details, limitations, and jurisdiction-specific rights follow.
1. Who is responsible
Controller/operator:
Movenue
Movenue digital service
Legal correspondence is accepted at support@movenue.me
Email: support@movenue.me
Privacy representative or Data Protection Officer, if applicable:
Privacy contact: support@movenue.me
2. Scope
This Policy applies to the Movenue iOS app, Apple Watch companion, Movenue website, support communications, and related Movenue-operated services.
It does not govern:
- Apple, Google, an app store, an identity provider, a device manufacturer, or another service that processes data under its own terms;
- a destination you choose when exporting or sharing a routine or workout CSV;
- content or services linked from Movenue but not operated by us.
Review those providers’ privacy information before using their services.
3. Personal data we process
The categories below describe the current Movenue product and supporting website.
A. Account and authentication
We may process:
- identity-provider subject or account reference;
- identity token and one-time authorization code transiently for secure sign-in verification;
- name and email address supplied by the identity provider, including an Apple private relay address where you choose that option;
- Movenue user ID;
- secure Movenue access/refresh session information;
- linked-provider status;
- account creation, sign-in, sign-out, refresh, and deletion timestamps;
- minimum-age confirmation;
- Terms acceptance and Privacy acknowledgment version and time.
We do not need your identity-provider password and you should never send it to us.
B. Profile
We may process:
- username and display name;
- avatar;
- bio;
- location text you choose to add to the profile;
- public/private profile preference;
- follower/following and public profile counts;
- profile edits and visibility state.
Profile location is user-entered profile content; do not enter a precise home address or another sensitive location.
C. Routines, media, and user content
We may process:
- routine name, description, visibility, status, schedule, and image;
- exercise steps, order, counter/timer type, sets, rep or duration targets, recovery, notes, and images;
- supported metric threshold conditions;
- imported routine JSON/ZIP content and exported packages;
- public posts and associated activity;
- comments and other content you submit;
- media ownership, purpose, safe renditions, and technical metadata needed to validate and serve an image.
The reviewed backend design normalizes uploaded images and strips embedded metadata such as GPS/EXIF from retained renditions. The production operator must verify that this remains true.
D. Social and event activity
We may process:
- follows, likes, comments, saves/favorites, views, and searches;
- scheduled workout and reminder choices;
- event creation, join/leave state, participant roster, and completion state;
- block relationships;
- reports, report reason, details, target content, review status, and safety actions;
- privacy-safe public activity counts and server-derived completion details permitted for the event.
Blocking and reporting information may be restricted from the reported or blocked member where disclosure would undermine safety, privacy, fraud prevention, legal rights, or another person’s rights.
E. Workout and fitness data
We may process:
- routine and step snapshots associated with a session;
- workout start/end time, duration, phase, sets, reps, timers, recovery, and completion;
- monitored metric definitions;
- current, average, and maximum workout aggregates where available;
- bounded raw samples with timestamps and workout context;
- heart rate obtained by the Watch through HealthKit during an active workout;
- pace and distance estimated by the Watch using location during an active workout;
- active time, total time, and derived distance-per-set;
- eligible live current values if you explicitly enable live metric sharing and an approved live-participant feature is available.
The iPhone app in the reviewed architecture receives available readings from the Watch; unavailable values are not inferred. Workout/fitness data can be sensitive personal data under applicable law.
F. Preferences and local data
We may process:
- appearance and unit system;
- default recovery and reminder;
- sound cue, narrator/counter sound, voice, and volume choices;
- workout/social notification preference;
- explicit live-metric-sharing preference;
- current timezone;
- account-scoped cache, drafts, retry state, and active-workout restoration state stored on the device;
- session credentials stored in the iOS Keychain.
Movenue Cloud is authoritative for supported synchronized data. Local files provide continuity, offline display, drafts, active-workout recovery, and bounded retries.
G. Device, network, diagnostic, and security data
We may process:
- app version/build and API contract version;
- device/operating-system class and compatible capability state;
- request ID, response status, timing, and rate-limit state;
- network address and limited server/security log data;
- product interaction and synchronization state;
- crash, error, and other diagnostic data if production diagnostics are enabled;
- security signals used to protect accounts and the Service.
Movenue is designed to keep provider tokens, free text, image bytes, email addresses, usernames, HealthKit values, and private paths out of routine operational logs. Production logging is reviewed against this requirement.
The public website does not use a client-side crash-monitoring or session-replay SDK. Any production app diagnostic provider and its fields, IP handling, and retention will be listed here before use.
H. Website, cookies, and support
When you visit movenue.me or contact support, we may process:
- page requests, browser/device class, referring domain, and security log data;
- cookie/local-storage choices described in the Cookie Policy;
- optional aggregate analytics only if implemented and lawfully activated;
- support email, subject, message, category, device/app details you submit, attachment, ticket ID, correspondence, and resolution;
- privacy, deletion, security, and safety request records.
Do not include passwords, sign-in codes, access tokens, unnecessary health information, or another person’s personal data in a support request.
The current website uses Cloudflare Sites for delivery and security, does not run audience analytics, does not set cookies or local storage, and does not collect information through a web form. Support is handled through direct email.
I. Notification data
The current release does not promise production push-notification delivery. If Movenue later collects a device push token, this Policy will be updated with the provider, purpose, status data, retention, and deletion behavior before that processing begins.
4. How we obtain data
We obtain personal data:
- directly from you when you create a profile, routine, comment, report, preference, export/import, support request, or other content;
- from Apple or an enabled identity provider when you choose to sign in;
- from your iPhone and Apple Watch, with applicable permission, during use;
- from your interactions with other members and Movenue features;
- automatically from systems needed for network delivery, security, reliability, and approved analytics;
- from another member when their content or report relates to you;
- from service providers operating on our behalf.
5. Why we process data
We use personal data to:
- create, authenticate, secure, and administer accounts;
- provide profile, routine, workout, Watch, history, export, social, event, moderation, support, and deletion functionality;
- synchronize supported data and restore eligible app state;
- apply visibility, blocking, sharing, and notification preferences;
- show public content you intentionally publish;
- provide explicitly enabled, eligible live event functionality;
- prevent abuse, fraud, unauthorized access, and technical failures;
- investigate reports, enforce rules, and protect members and rights;
- respond to support, privacy, safety, and legal requests;
- maintain, debug, measure, and improve the Service using minimized data;
- comply with law, lawful process, and enforceable obligations;
- establish, exercise, or defend legal claims;
- communicate material service, safety, security, privacy, or legal updates.
We do not use HealthKit-derived data for advertising or similar data mining, sell it to advertising platforms, data brokers, or information resellers, or disclose it to a third party for an unrelated purpose.
6. Legal bases where applicable
Different laws use different concepts. Where the GDPR, UK GDPR, or a similar law applies, Movenue relies on the following bases as appropriate to the purpose and circumstances:
| Processing | Legal basis |
|---|---|
| Account, routines, workouts, requested social features, exports, support | Performance of the contract / steps requested by you |
| Optional HealthKit access and processing of health data | Explicit consent or another valid Article 9 condition, implemented and documented as required |
| Optional live metric sharing | Explicit, specific, revocable choice; joining an event is not consent |
| Security, fraud prevention, limited service measurement, rule enforcement | Legitimate interests after balancing and minimization |
| Legal requests, tax/accounting if later applicable, mandatory retention | Legal obligation |
| Emergency protection in a truly applicable case | Vital interests or another lawful basis |
| Optional marketing/newsletter/cookies | Consent where required; not approved for launch without an implemented flow |
You may withdraw consent for future processing at any time through the
applicable setting, system permission, cookie control, unsubscribe action, or
support@movenue.me. Withdrawal does not affect processing already lawful
before withdrawal and may make an optional feature unavailable.
7. When data is public or shared
Other members and the public
Depending on visibility and your actions, other members may see:
- public profile information;
- public routines and associated images/notes;
- posts, comments, likes, follows, saves/counts, and public interactions;
- eligible schedule/event information;
- permitted participant and completion information.
Private routines and private workout history are not intended to be public profile/feed content.
Live event participants
The current product preference for live metric sharing is off by default. When an approved live-sharing feature exists and you enable it, authorized event participants may receive only eligible current values during that live event. Any eligible future live-sharing implementation is intended to keep those values ephemeral and out of history, posts, feeds, profiles, routine logs, diagnostics, and backups. Movenue does not represent live participant metric streaming as available in the current release.
Service providers
We disclose personal data to vendors that process it under instruction to provide hosting, database, media storage, delivery/CDN, identity verification, email/helpdesk, security, monitoring, analytics, backup, and other approved operations.
The public website is delivered through Cloudflare Sites. Identity and device services are provided by Apple where you choose or permit them. Additional production app subprocessors will be identified in this Policy before they receive personal data.
Identity and platform providers
Apple and any enabled identity provider process sign-in and device/platform information under their terms. Apple also operates HealthKit, system permissions, App Store distribution, and related device services.
Your direction
We disclose data when you intentionally publish content, join an eligible social activity, export/share data, or direct us to connect with another service. The recipient’s privacy terms then apply.
Legal, safety, and corporate events
We may disclose data where reasonably necessary to:
- comply with valid law or binding legal process;
- protect rights, safety, and security;
- investigate abuse, fraud, or a credible threat;
- establish, exercise, or defend legal claims;
- complete a merger, financing, reorganization, acquisition, or asset transfer subject to appropriate confidentiality and notice required by law.
We assess requests and disclose only data legally required or otherwise lawfully permitted.
8. Sale, sharing, and advertising
Movenue’s current policy is:
- no sale of personal data;
- no “sharing” for cross-context behavioral advertising;
- no targeted advertising based on health, fitness, precise location, or other sensitive data;
- no advertising use or sale of HealthKit-derived data;
- no disclosure of HealthKit-derived data to data brokers or information resellers.
9. International data transfers
Movenue may operate and use providers in countries other than yours. Those countries may have different data-protection laws.
The public website is delivered through Cloudflare’s global network. App and support providers may process information in countries other than yours. Where a restricted international transfer occurs, Movenue will use a legally recognized safeguard or another lawful basis and will provide information about that safeguard on request where required.
10. Retention
We retain personal data only as long as necessary for the stated purposes, account/service operation, safety and security, dispute/legal obligations, and approved backups. Criteria include account status, content visibility, sync/retry needs, legal limitation periods, safety risks, and deletion requests.
Our current retention approach is:
| Data | Retention |
|---|---|
| Active account/profile | For the life of the account; normally removed from active systems within 30 days after a verified deletion request, subject to lawful exceptions |
| Private/public routines, media, posts, comments | While active; removed or de-identified after deletion, with moderated or safety records retained only as reasonably necessary |
| Workout history and HealthKit-derived samples | Until the user deletes the record or account; active-system deletion normally completes within 30 days |
| Live ephemeral metrics | Not stored as a participant stream in the current release; any future live-sharing release requires a separate policy update |
| Authentication/session records | Until expiration or revocation; limited security records may be retained for up to 90 days |
| Reports, blocks, safety actions | For the time needed to protect users, handle an appeal, and meet legal obligations; generally no longer than 24 months unless a continuing risk or claim requires more |
| Security/rate-limit/operational logs | Up to 90 days in ordinary operation, unless needed longer for an active security investigation |
| Diagnostics | Up to 90 days after collection, unless retained longer in de-identified form |
| Support tickets/attachments | Up to 24 months after closure; unnecessary sensitive attachments are deleted sooner where practical |
| Privacy/deletion request records | Up to 36 months after closure, or longer where law requires |
| Website analytics | None — the current website does not run audience analytics |
| Backups | Encrypted rotating backups may preserve residual copies for up to 90 days; they are isolated from ordinary use |
When retention ends, we delete or de-identify data using methods appropriate to the system. Deletion from backups may occur on the documented rotation cycle; restricted backup data must not be restored to active use except for recovery and must be deleted again according to the request/process.
We may preserve limited data where law requires or permits it, including to protect security, prevent fraud/re-registration abuse, resolve disputes, enforce rights, or maintain a record of a privacy request. We must document the reason and restrict further use.
11. Security
Movenue uses administrative, technical, and organizational safeguards appropriate to the data and risks. The reviewed app design includes secure transport, iOS Keychain storage for Movenue session credentials, rotating sessions, account-scoped caches, backend authorization, privacy-safe logging requirements, upload validation, and deletion controls.
Movenue reviews production safeguards and vendor controls as the Service changes. No internet
service is perfectly secure. Contact support@movenue.me with subject
Movenue security report if you believe data or an account is at risk. Do not
include exploit data belonging to another person in ordinary email.
12. Your choices
Depending on the release and device, you can:
- edit eligible profile fields;
- choose public/private profile visibility;
- choose public/private routine visibility;
- follow/unfollow, save/unsave, join/leave;
- report and block;
- manage sound, units, appearance, reminders, and notification preferences;
- keep live metric sharing off or turn it off;
- change HealthKit and location access in Apple system settings;
- export compatible routines and raw workout samples;
- delete an individual workout history record;
- clear downloaded device cache without deleting the Cloud account;
- sign out;
- permanently delete the account inside Movenue.
Public content may have been seen, copied, or shared by others before deletion. We will remove it from Movenue-controlled active systems according to the published retention and deletion process, subject to lawful exceptions.
13. Account deletion
In the app:
- Open Profile.
- Open the profile menu.
- Choose Settings.
- Scroll to Data.
- Choose Delete Movenue account.
- Confirm Delete Account.
The reviewed backend deletion design revokes Movenue sessions/provider grants and removes the profile, public content, eligible comments, relationships, saves, history, media, active state, and private HealthKit-derived data through an idempotent durable process.
If you cannot access the app, visit https://movenue.me/account-deletion or
email support@movenue.me. We may verify control of the account using a
proportionate method. We will not ask for your password or identity-provider
token.
Movenue’s current policy target is to complete verified deletion from active systems within 30 days. Encrypted rotating backups may preserve a restricted residual copy for up to 90 days. Provider revocation, lawful exceptions, and available confirmation are handled through the deletion process.
14. Privacy rights
Depending on where you live and subject to legal conditions/exceptions, you may have rights to:
- receive information about processing;
- access personal data;
- correct inaccurate/incomplete data;
- delete data;
- restrict processing;
- object to processing, including direct marketing;
- receive portable data;
- withdraw consent;
- opt out of sale, sharing, or targeted advertising where applicable;
- limit certain uses/disclosures of sensitive data where applicable;
- appeal a denied request where applicable;
- avoid unlawful discrimination for exercising a right;
- complain to a competent data-protection authority.
Movenue does not make decisions producing legal or similarly significant effects about you solely through automated processing in the reviewed product.
To exercise a right, use available app controls or email
support@movenue.me with subject Movenue privacy request. Describe the
request and country/state. Do not send a password, token, or unnecessary ID.
We may need to verify the request, account, jurisdiction, and authorized-agent authority. We use information provided for verification only for verification, security, compliance, and request records. We respond within the applicable period and explain a lawful denial or appeal path.
California notice, if applicable
If the California Consumer Privacy Act applies to Movenue and you, the categories processed during the preceding 12 months may include identifiers, customer-record/contact information, protected classification information limited to minimum-age confirmation, commercial/activity records, internet or electronic activity, geolocation-related information, audio/visual content, health/fitness and other sensitive personal information, and inferences limited to providing requested service features.
Sources, purposes, and recipient categories are described above. Movenue’s intended policy is not to sell personal information or share it for cross-context behavioral advertising and not to use/disclose sensitive personal information beyond providing and protecting requested services or other legally permitted purposes. Under this current policy, there is no sale/share opt-out transaction to perform; applicable opt-out preference signals will be honored if practices ever trigger that requirement.
EU/EEA and UK, if applicable
You may complain to the data-protection authority where you live, work, or believe an infringement occurred. Contact us first if you would like us to try to resolve the concern. You may also request information about the applicable Movenue privacy contact and international safeguards.
UAE, if applicable
Where the UAE Personal Data Protection Law or an applicable free-zone law applies, requests will be handled according to the rights, conditions, and exceptions of that regime. Movenue will provide the controller, transfer, and regulator information required by the regime that applies to a verified request.
15. Children and minimum age
Movenue is not directed to children under 13. Account setup requires confirmation that the user is at least 13. A higher minimum age or parental authorization may apply under local law, including where consent is used to process a child’s personal data.
Do not create an account if you are below the applicable minimum age. If you
believe an ineligible child supplied personal data, email
support@movenue.me. We will investigate, apply appropriate verification, and
delete or restrict data as required.
16. Health and location permissions
Apple controls HealthKit and location permissions. You can change them in system settings. Denying or withdrawing permission makes the related reading unavailable but should not prevent use of core manual iPhone workout coaching.
Changing a system permission stops future access through that permission; it does not automatically delete data already lawfully stored by Movenue. Use history deletion, account deletion, or a privacy request for stored data.
17. Changes to this Policy
We may update this Policy when the Service, vendors, laws, or practices change. We will post the updated version and date. If a change is material, we will provide additional notice and obtain renewed consent/acceptance where required.
The app records the legal version accepted or acknowledged. A material change will be coordinated with the app’s acceptance version so renewed notice or agreement can be requested where required.
18. Contact and complaints
Questions, privacy requests, or complaints:
Movenue
Legal correspondence: support@movenue.me
Email: support@movenue.me
Privacy representative/DPO, if applicable:
support@movenue.me
Competent regulator(s), if required:
The data-protection authority applicable to your place of residence