Privacy Policy for Aria Pilates
Last Updated: 2026-09-22
This Privacy Policy describes how Frostskull AB ("we", "our", or "us") handles information in connection with Aria Pilates (the "App"), a guided mat-pilates app for iOS and Android, and this website. It does not cover any other product.
The short version. Your plan, your session history and the measurements you enter in the quiz stay on your phone. The height, weight and target weight you give are not even stored — they are used to build your plan and then discarded. The App does send a limited stream of usage events to Google Analytics for Firebase, and crash reports to Firebase Crashlytics, both tied to a random per-install identifier rather than to your name, and purchase records to RevenueCat and the app stores. There is no advertising, no advertising identifier, and no tracking across other apps. Everything is set out in full below.
1. Who we are
Frostskull AB is the controller of the personal data described here.
Frostskull AB
Martingalgatan 8
18374 TÄBY
Sweden
info@frostskull.com
2. Scope
This policy covers the Aria Pilates mobile app on iOS and Android, and the pages on this website. The App is not a web service; there is no Aria Pilates account, no web app and no desktop version.
3. What stays on your device
The following is held in the App's private storage on your phone and is never transmitted to us:
- Your first name, used only to address you in the App.
- Your plan and settings — the program you are on and which day you are at, your weekly goal, minutes per day, units, reminder time and whether reminders are on, and your sound, haptics and coach-voice preferences.
- Your session history — one record per finished session: which session it was, when you completed it, how many minutes, and where it sat in your program. Your streak, totals and heatmap are calculated from this log each time you look at them; they are not stored separately.
If you upgraded from an earlier version of the App, a copy of your previous settings record may remain on the device alongside the current one. It is not deleted automatically, it is never transmitted, and it is removed along with everything else when you delete the App.
4. The quiz, and what happens to your measurements
The first-launch quiz asks for your goal, the areas you want to focus on, your experience level, age range, height, weight, target weight, activity level, how many minutes a day and which days a week suit you, what has got in the way before, what motivates you, what equipment you have, your first name, and your reminder preference.
Your body measurements are not stored
Height, weight and target weight are held in memory only for as long as it takes to build your plan and draw the chart on the plan screen, and are then discarded. They are not written to your device's storage, and they are not transmitted to us or to any third party. The same is true of your age range, focus areas, obstacles and motivation. If you want them again, the App has to ask again.
Five coarse answers are sent to Google Analytics for Firebase when you finish the quiz, as described in Section 5: your goal, your experience level, your days per week, your minutes per day, and whether you turned reminders on. Your height, weight and target weight are not among them.
5. What the App sends, and to whom
Three services receive data from the App. There are no others: no advertising network, no attribution SDK, no social login, no analytics provider besides the one named here, and no server operated by us — the App has no facility to contact one.
Google Analytics for Firebase
Receives usage events so we can see which sessions get finished and where people drop out. These are: screens viewed; quiz started, each quiz step reached, and quiz completed (with the five answers named in Section 4); session started, completed and abandoned (with the session's name, its length, how long you spent and, if you stopped, which move you reached); program started; streak milestones reached; and paywall, trial and purchase events. Alongside them we set three properties — whether you subscribe, your weekly goal, and which program you are on — and a user identifier, which is the random identifier described in Section 6.
It never receives your name, your height, your weight or your target weight.
Separately, Google's own SDK collects a standard set that we do not choose or control: a random app-instance identifier, your device model, operating system version, app version, language, an approximate location derived from your IP address (typically country- or region-level), and session and engagement metrics. Google documents this at support.google.com/analytics.
Analytics is active in the released App on iOS and Android.
Firebase Crashlytics
When the App crashes, Crashlytics receives a crash report so we can fix it: the stack trace, the error details, your device model, operating system version and app version, and the random identifier from Section 6. Crash reporting runs in released builds only.
RevenueCat
Manages your subscription entitlement — that is, it works out from your store receipt whether your subscription is active, and tells the App. It receives purchase and receipt data from the store, plus standard device and SDK information. It identifies your purchase under its own anonymous identifier, which is not the identifier described in Section 6 and is not connected to it. RevenueCat receives none of your name, your measurements, your plan or your session history.
Purchases themselves are processed by the Apple App Store and Google Play under their own privacy policies. We never receive or store your payment card details; all the App learns back is whether your subscription is active.
One further transfer is worth naming because it is easy to miss: the App's typefaces are bundled with it, but if a style is needed that is not in the bundle, the App may request it from Google's font service. Such a request discloses your IP address to Google, as any web request does to the server it reaches. No other data is sent with it.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We may disclose information where required by law or valid legal process, and records could transfer as part of a merger, acquisition or asset sale.
6. Identifiers
The App creates a random identifier on first launch, through Firebase's anonymous authentication. It is not an account: there is no email address, no password and no sign-in, and it carries no personal detail. It is stored on your device, sent with analytics events and attached to crash reports so that a sequence of events can be recognised as coming from one installation. Reinstalling the App generally produces a new one.
The App does not use an advertising identifier, does not ask permission to track you across other companies' apps and websites, and contains no advertising SDK.
7. Health-related information
Some of what the App handles is health-related: your height, weight and target weight, your age range, your activity level, a goal of postpartum recovery if you choose it, and your record of completed exercise sessions.
We treat it accordingly. The measurements are neither stored nor transmitted (Section 4). Your session history stays on your device (Section 3). Your goal — including postpartum recovery — is sent to analytics as one of the five coarse quiz answers, against the random identifier rather than your name; if you would rather it were not, you can decline to complete the quiz, or see Section 12 for how to object. None of this information is used for advertising, because the App carries no advertising.
8. Why we process this information
- To run the App — build your plan, remember where you are in it, and show your progress. Processed on your device. In the EU and UK, this is necessary to provide the service you asked for.
- To improve it — understand which sessions get finished and where people stop, so we can fix what is not working. This is the analytics described in Section 5, and in the EU and UK it rests on our legitimate interest in improving the App; see Section 12 on objecting.
- To diagnose crashes — Crashlytics, on the same basis.
- To bill and restore subscriptions — handled by RevenueCat and the app stores under their own terms, as necessary to perform our contract with you.
9. Reminders
Your daily reminder is scheduled and delivered by your own phone. There is no push service, no device push token collected by us, and nothing about the reminder is sent anywhere — its text is generated on the device from your local settings. It reads your device's time zone so it fires at the right local hour, and on Android the App asks for the permissions needed to reschedule it after a restart. Reminders are optional and the App works without them.
10. Permissions the App does not request
The App does not ask for access to your camera, microphone, photo library, contacts, calendar, precise location, Bluetooth, biometrics, Apple Health or Google Fit. It records no audio: the coach's voice is a set of pre-rendered files bundled inside the App and played from there.
Every session, photograph, cue and voice line ships inside the App. It does not stream content, and it needs no connection to run a session.
11. Retention
- On your device: your plan, settings, name and session history stay until you delete the App or clear its data. Nothing expires on its own, and the App does not delete session records.
- Your measurements: not retained at all — discarded as soon as your plan is built (Section 4).
- With Google: analytics and crash records are retained according to the settings on our Firebase project and Google's own retention policies. They are not linked to your name.
- With RevenueCat and the app stores: purchase and subscription records are kept under their policies, typically for accounting, tax and fraud-prevention purposes.
If you have device backups switched on, your operating system may include the App's data in its own backup. That behaviour belongs to Apple or Google and is governed by their policies and your device settings, not by us.
12. Your rights
Depending on where you live, you may have rights to access, correct, export, restrict, object to the processing of, or erase your personal data, to withdraw consent where processing rests on it, and to lodge a complaint with your data protection authority. If you are in California, you may have rights to know, delete and correct your personal information, to opt out of its sale or sharing — we do neither — and not to be discriminated against for exercising them.
For everything on your device you can act directly and immediately: it is all visible in the App, and deleting the App erases it. For the analytics, crash and purchase records described in Section 5, write to info@frostskull.com; see Delete Your Data for what we can and cannot reach. Please understand that those records carry no name, email address or account, so we may be unable to identify which are yours — where that is so we will tell you, rather than act on someone else's data.
If you are in the EU or UK and are not satisfied with our response, you may complain to your national supervisory authority; in Sweden this is Integritetsskyddsmyndigheten (IMY).
13. International transfers
Google, Apple and the app stores may process the data described above outside your country of residence, including in the United States, under their own terms and safeguards. Data held on your device is not transferred anywhere.
14. Children
The App is intended for adults aged 18 and over and is not directed at children. We do not knowingly collect personal information from anyone under that age. If we learn that we have, we will delete it.
15. Security
An honest account rather than a reassuring one:
- Your data is held in the App's private storage area, isolated from other apps by your operating system and protected by your device passcode or biometric lock.
- The App does not apply its own separate encryption to that storage on top of the protection the operating system provides.
- Traffic to Google and to the app stores is encrypted in transit by those services.
- Because there is no account and no copy of your practice on a server of ours, there is no online store of it to be breached — but equally, an unlocked or lost phone is the whole risk, and we have no way to wipe the App remotely. Keep a device passcode or biometric lock enabled.
16. This website
These pages are static and are served without setting cookies for advertising or analytics. Web fonts are loaded from Google Fonts, which discloses your IP address to Google in the same way as any request to a third-party server. Our hosting provider may keep standard server logs.
17. Changes to this policy
We may update this Privacy Policy. Material changes will be communicated through an in-app notice or an updated "Last Updated" date at the top of this page. Continued use of the App after changes are posted constitutes acceptance of the updated policy.
18. Contact
For privacy questions, data requests or concerns, contact us at: info@frostskull.com
Frostskull AB
Martingalgatan 8
18374 TÄBY
Sweden