1. Information We Collect or Generate
Depending on the features you use, the App collects or generates the following categories of information:
- Alarm, repeat-day, skip, volume, notification, speech, departure-timer, and display-language settings
- Squat counts, completion times, streaks, history, rewards, and selected display items
- Sign-in, profile, ranking, friend, friend-request, block, and safety-report information
- RiseRep Adventure progress, battles, level, inventory, currencies, shops, and crafting data
- Product type, purchase token, purchase state, and verification results for Pro and Gem purchases
- Identifiers such as advertising IDs, IP address, ad interactions, diagnostic information, and consent status
- App Check, Play Integrity, or App Attest data, request records, and fraud-prevention information
- Email address, subject, message, attachments, and correspondence you send when contacting support
We receive this information from your input, from use of the App, or from third-party services such as Google Play, the Apple App Store, Firebase, and advertising SDKs.
2. Information Processed and Stored on Your Device
Alarm schedules, repeat days, one-time skips, selected sounds, volume, vibration and notification settings, squat history, departure-timer settings, display settings, and temporary ad or Pro state may be stored in local databases, files, or preferences. The App uses this information to provide features, restore alarms after reboot, and retry operations after failures.
If Android or iOS backup or device transfer is enabled, eligible data may be encrypted, transferred, and stored by the operating system, Google, or Apple. Certain information that must be verified again, including the local Pro entitlement cache, may be excluded from backup.
The App lets you select one of 17 display languages: Japanese, English, Italian, Hindi, Bengali, Nepali, Urdu, Persian, Arabic, Korean, Simplified Chinese, Spanish, French, German, Brazilian Portuguese, Indonesian, and Vietnamese. The selected display language is processed as an on-device setting.
3. Accounts and Authentication
Google sign-in, Sign in with Apple, or email-and-password sign-in may be used for rankings, friends, cloud sync, and RiseRep Adventure. Through Firebase Authentication, we process a user ID (UID), display name, email address, authentication provider, and account status.
When using Sign in with Apple, you can share the email address on your Apple Account (including an icloud.com address) or choose Hide My Email and share an Apple private relay address. Firebase stores the address selected for that account. With your explicit action, another sign-in method may be linked to the same RiseRep account.
Passwords are managed by Firebase Authentication. We do not view or store passwords in plaintext. Your profile name, system-generated avatar initial, selected reward, and related settings may be stored in the cloud.
If you voluntarily choose a profile photo through the operating system’s photo picker, the App resizes and converts it on your device and stores it in the App’s private storage. Android versions that support photo sharing upload and store a thumbnail in your Firebase user profile during signed-in synchronization, and display it to other users in rankings, friends, and user profiles. Photos retained on the device while sharing was disabled may also be uploaded again when a supported version synchronizes. The current iOS app uses selected photos only on the device and does not upload them. Attachments you voluntarily send to support outside the App are handled as support correspondence.
4. Fitness Records, Rankings, and Friends
When signed in, total, daily, and weekly squat counts, personal bests, streaks, ranking position, reward unlocks, first-share completion, and related information may be stored in Firebase. We use this data for cross-device sync, ranking calculations, rewards, and prevention of duplicate submissions.
Friend features process friend lists, incoming and outgoing requests, public profiles, friend counts, and read or quota-management information. We may also store processing timestamps, event identifiers, and completion ledgers needed for reliable aggregation and duplicate prevention.
Safety features process the reporter and target UIDs, report reason, optional details, source screen, report time, deduplication and rate-limit information. We store the UID of a user you block to exclude both sides of the block relationship from each other's rankings, friends, requests, and Adventure support choices and to prevent new requests. Reports and block relationships are not visible to other ordinary users.
5. RiseRep Adventure Data
RiseRep Adventure processes the following cloud game data for each account:
- Stages, laps, bosses, remaining boss HP, attack counts, and clear status
- Shared level, EXP, Coins, Gems, materials, treasure chests, and rewards
- Characters, weapons, talismans, treasures, blueprints, equipment, and party loadouts
- Shop purchases, crafting, ad rewards, login rewards, and Pro benefits
- Friend support, support loadouts, requests, results, rate limits, and operational audit records
When you complete an alarm mission or free-squat session, the App may send a completion event ID, required and completed reps, completion time, and difficulty-related values to grant Adventure attacks or rewards and update rankings. Raw accelerometer streams are not uploaded to the cloud.
6. Pro, Gems, and Store Purchases
The one-time Pro purchase and the 100, 500, and 1,000 Gem products use Google Play Billing on Android and Apple StoreKit on iOS. We process the product ID, a hash of the purchase token or transaction ID, order or acknowledgment status, purchase time, verification result, and associated user ID. Google Play or the Apple App Store handles payment credentials such as card numbers; we do not receive them.
We retain Google Play and App Store purchase-verification ledgers for Pro and Gems to restore entitlements and prevent duplicate grants or fraud. When an account is deleted, direct owner links (the owner UID and account hash) are removed, but hashed purchase-token or transaction data and an irreversible hash of a previous owner identifier may be retained where necessary for legal compliance, purchase restoration, fraud prevention, and dispute handling. Consumable Gem ledgers also remain to prevent a transaction from being granted twice after deletion.
On Android, Google Play real-time developer notifications and the Voided Purchases API are used to check completed, canceled, refunded, or charged-back purchases. If a Gem purchase is voided, the server-controlled refund ledger records the amount removed from the available balance, any amount already spent that could not be removed, and whether review is required.
On iOS, we verify Apple-signed transaction information on the server and reflect any cancellation, refund, or refund-reversal status we receive in the Pro entitlement and Gem ledgers.
Gems, Coins, equipment, blueprints, and other virtual items have no cash, cryptocurrency, or property redemption feature.
7. Advertising, Rewarded Ads, and Consent
Advertising and tracking on iOS 4.2.3 (build 201) and later: Until ATT permission is granted, the app does not start UMP advertising consent forms or advertising SDKs and does not request ads. Alarm and regular exercise features remain available when permission is denied, restricted, or undecided. If permission is revoked in Settings, the app stops ad requests and discards cached ads when it becomes active again. Where required, UMP consent is checked separately from ATT. The iOS advertising SDKs are Google AdMob, Liftoff Monetize, Unity Ads, Meta Audience Network, and Chartboost.
The terms, privacy policy, and support pages on this official website do not use advertising tags, analytics scripts, tracking cookies, or cookie consent banners.
The free version displays banner, interstitial, and rewarded ads through Google AdMob. The mediation SDKs are Liftoff Monetize, InMobi, and Unity Ads on Android 4.1.0, and Liftoff Monetize, Unity Ads, Meta Audience Network, and Chartboost on iOS 4.2.3. These ad networks may process information when AdMob selects them to serve an ad. Completion of a rewarded ad may be used to grant Gems or other in-app benefits.
Advertising SDKs may collect or share an IP address (which may estimate general location), Android advertising ID, App Set ID, Apple's Identifier for Advertisers (IDFA), Identifier for Vendor (IDFV), or other identifiers, app launches, taps, video views, device and app information, ad results, diagnostics, performance data, and fraud-prevention signals. We use Google User Messaging Platform (UMP) to request advertising consent and provide privacy choices where required. On iOS, we request App Tracking Transparency (ATT) permission before accessing the IDFA.
For rewarded ads in RiseRep Adventure, the App sends AdMob a random, single-use claim value that expires after a short period so that rewards are granted only for a valid completed view. Our server verifies the claim value, ad unit, reward settings, transaction identifier, and timestamp in AdMob's signed callback. We retain hashes of the claim and transaction identifiers and the verification result for as long as needed to prevent duplicate rewards and abuse. This process does not send your Firebase user ID, email address, or profile information to AdMob.
Ads are generally disabled for Pro users. Limited network activity may still occur before purchase status is confirmed, during restoration, or for SDK initialization and legally required consent management.
8. Sensors, Audio, Speech, and Sharing
- Motion sensors: The App uses accelerometer or similar sensor readings on the device to estimate squat movements. Raw sensor readings are not normally stored in the cloud.
- Sounds and speech: The App can use a sound selected on the device, included app sounds, and the device text-to-speech engine for alarms and timers. It does not record audio or use microphone input.
- Sharing: Progress images may be generated locally and sent through the operating system’s share feature to an app you select. The App does not post automatically on your behalf.
The App does not request permissions for the purpose of accessing your camera, microphone recordings, contacts, SMS, call history, or precise location.
9. App Check, Play Integrity, App Attest, and Security Data
The App integrates Firebase App Check and attempts to obtain and attach integrity tokens using Google Play Integrity on Android and Apple App Attest or equivalent attestation on iOS. Some security-sensitive operations may require a valid token. For other server operations, enforcement is introduced in stages after verification metrics show that legitimate store-distributed builds will not be disrupted. Firebase Authentication and server-side authorization, input validation, rate limits, and duplicate prevention apply independently of App Check enforcement. Google, Apple, and our systems may process integrity tokens, app identifiers, request time and result, IP address, and failure counts for these purposes.
10. Purposes of Processing
- Providing alarms, squat detection, departure timers, notifications, and speech
- Authenticating accounts and operating sync, rankings, friends, and Adventure
- Verifying, granting, and restoring Pro, Gem purchases, ad rewards, and game items
- Providing support and improving reliability, performance, and usability
- Detecting inappropriate display names, responding to reports, providing blocking, and protecting user safety
- Detecting and preventing abuse, duplicate submissions, cheating, attacks, and purchase fraud
- Complying with law, Google Play and Apple App Store policies, and valid requests from authorities
11. Information Visible to Other Users or Shared by You
Rankings, friends, and support features may display your display name, system-generated avatar, selected reward, squat totals, rank, Pro badge, and Adventure support information to other users. Android photo sharing also displays a thumbnail of your selected profile photo in rankings, friends, and user profiles. Your email address and authentication credentials are not made public.
Server-side inappropriate-content and spam controls apply to public display names. You can report or block another user from that user's profile. Once either user blocks the other, the pair is excluded from each other's rankings, friends, requests, and Adventure support choices.
If you use sharing, information is sent to the service you select under that service’s terms and privacy policy. Do not place confidential information or a name that infringes another person’s rights in your public display name.
12. Third-Party Services and Disclosures
We do not sell personal information. The following providers process information under their own terms and policies as needed to provide the App:
- Google Play, Google Play Billing, and Google Play services: distribution, updates, purchases, reviews, authentication, and device services.
Google Privacy Policy - Firebase (Authentication, Cloud Firestore, Cloud Functions, and App Check): authentication, storage, synchronization, server processing, and abuse prevention.
Privacy and Security in Firebase - Apple App Store, StoreKit, and Sign in with Apple: app distribution, updates, purchases and restoration, Apple Account authentication, and provision of a shared email or private relay address.
Apple Privacy Policy - Google AdMob and User Messaging Platform: ad delivery, measurement, consent management, and fraud prevention.
Google Advertising Policies - InMobi (Android): ad mediation, delivery, measurement, and fraud prevention.
InMobi Privacy Policy - Unity Ads (Android and iOS): ad mediation, delivery, measurement, and fraud prevention.
Unity Privacy Policy - Liftoff Monetize (Vungle; Android and iOS): ad mediation, delivery, measurement, optimization, and fraud prevention.
Liftoff Privacy Policy - Meta Audience Network (iOS): Ad mediation, serving, measurement, and fraud prevention.
Meta Privacy Policy - Chartboost (iOS): Ad mediation, serving, measurement, and fraud prevention.
Chartboost Privacy Policy
We may disclose information where required by law, to protect life, safety, or property, or where reasonably necessary to establish rights, investigate abuse, or respond to lawful requests from courts or authorities.
13. International Processing
Apple, Google, Firebase, AdMob, InMobi, Unity, Liftoff, and their affiliates may process information on servers in various countries. Such processing is subject to the safeguards and applicable laws described by those providers.
14. Retention
On-device data may remain until you delete it, clear the App’s storage, or uninstall the App. Cloud data is retained while needed to provide your account or features and for periods reasonably necessary to handle failures, abuse, disputes, or legal obligations. Expired requests, duplicate-prevention ledgers, and rate-limit records may be deleted or refreshed on operational schedules.
Purchase-verification history, security records, and legally required records may remain after account deletion for as long as needed for their stated purpose, with direct identifiability reduced where appropriate.
Safety reports are retained only as long as reasonably necessary to review and act on the report, prevent abuse, and handle disputes, after which they are deleted or de-identified. Account deletion targets reports and block relationships directly linked to that UID.
Support correspondence is retained only as long as reasonably necessary to answer the request, resolve the issue, protect safety, or handle a dispute, after which it is deleted or de-identified.
15. Account and Data Deletion; Backups
While signed in, you can delete your account from the App’s account settings. The process targets the Firebase Authentication account, profile, friend relationships and requests, ranking-related data, and Adventure progress, inventory, and support data. Related friend or request links held under other users are also removed where practicable.
If you cannot use the App, see the data deletion page. To delete only local data, use Android’s App info screen or iOS storage settings to remove the App’s data.
Account deletion also targets the on-device profile photo and the thumbnail stored in that account’s Firebase user profile. Clearing the App's data or uninstalling it also removes the local photo. After deletion, limited records may remain temporarily in rotating backups or continue where required for law, security, purchase restoration, fraud prevention, or dispute handling, as described above.
16. Your Choices and Rights
- You can change notifications and other permissions available on your operating system in device settings.
- Where advertising choices are required, the App’s privacy settings can open the UMP choices screen. Advertising-identifier choices are available in device settings.
- You can change profile and public information in the App and request account deletion in the App or through the deletion page.
- You can report or block another user from that user's profile, unblock them from the same screen, and contact support about an urgent safety issue.
- To exercise access, correction, deletion, restriction, or other rights available under applicable law, contact us below. We may need to verify your identity.
17. Minors
Minors should use the App with parental consent and supervision where appropriate. The App is not intended to knowingly obtain personal information from a child without legally required consent. A parent or guardian who believes information was collected improperly should contact us.
18. Security
We use reasonable safeguards such as encryption in transit, Firebase access controls and authentication, App Check token verification and staged enforcement, Play Integrity, App Attest, rate limits, and purchase verification. No internet transmission or storage system can be guaranteed completely secure.
19. Changes to This Policy
We may revise this Policy to reflect changes in features, SDKs, law, or operations. Material changes will be announced on this page, in the App, or by another reasonable method. The effective date is shown at the top of this page.
20. Contact
Operator: Yotsuya (Developer: Yosuke Fujita)
Email: riserepalarm@gmail.com
Support: RiseRep Alarm Support