DisciplineX

Privacy Policy

Effective: 8 September 2026 · Last updated: 8 September 2026

In short: your journal, goals and workout logs stay on your phone. Your account, messages, scores and (if you turn it on) location live on our server. When you ask the AI coach for a comment, that day's text is sent to the coach server. We work with no ad network, run no analytics tracking, and sell no data.

1. Who is responsible

DisciplineX is published by Kağan Keskin, an individual developer, who is the data controller under the GDPR and under Türkiye's personal data protection law (KVKK).

Contact: disciplinex0011@gmail.com

This policy covers the DisciplineX iOS app and this website.

2. What never leaves your phone

The following is kept in the app's own local storage — on your device. There is no copy on our server:

This has two consequences, and both are deliberate: we cannot read any of it; in exchange, if you lose your phone or delete the app, these records are gone. There is no cloud backup.

The one exception is section 4 below: when you ask the coach for a comment, that day's goals, journal and workout text is sent to the coach server.

3. What we keep on our server

Accounts and social features are hosted on Supabase. Everything we keep is listed below — this list is complete.

WhatWhat's in itWhyLegal basis
Account Your email address and a cryptographic hash of your password (the password itself is never stored anywhere in readable form) So you can sign in Performance of a contract
Profile Your username, your name if you entered one, your profile photo, the sports you selected, your total score, your current and longest streak To show you on the leaderboard and in the social section Performance of a contract
Messages Sender and recipient, message text; for workout invites the sport, date, time and the invite's status For the messaging feature Performance of a contract
Scores The date and the score the coach gave that day For the leaderboard and your history Performance of a contract
Location Latitude, longitude and time of the reading — only when you turn on "Nearby" To list users near you Your consent
Notification record Your device's notification token and your app language To send message and invite notifications in the right language Your consent (iOS notification permission)
Blocks Who you have blocked So blocked people can't reach you Legitimate interest — user safety
Reports Who reported whom, the reason selected and your description if you wrote one To review abuse Legitimate interest — user safety
Membership status Whether your subscription is active and when it ends To unlock membership features Performance of a contract

We do not hold your age, gender, phone number, government ID, address, contacts list or payment card details — we never ask for any of it.

4. The AI coach — exactly what gets sent

Read this section carefully, because it is the only place where content stored on your phone leaves it.

When you seal a day and ask the coach for a comment, the app sends the following as a single block of text to our coach server running on Cloudflare, which passes it to Google's Gemini AI service to generate the comment:

This request is only sent when you ask the coach for a comment. Nothing goes out on its own in the background. The coach server does not store the text you send; it generates the comment and returns it. The only thing that remains is the coach's score — that is stored on our server, the text you wrote is not.

How Google processes this data on its side is governed by Google's own terms. If there's something you'd rather not send to the coach, you can seal the day without asking for a comment.

5. Location

Location is entirely optional. If you don't turn on "Nearby", location is never requested and never sent.

If you do turn it on:

6. Apple Health

With your permission, the app reads running, cycling, swimming and walking workouts from Apple Health, along with duration, distance, pace, heart rate and calories. This data is not saved to our server; it is displayed on your phone.

The only exception is section 4 above: when you ask the coach for a comment, that day's duration, heart rate, calories, distance and pace are included in the coach text. If you'd rather not send health data to the coach, you can revoke Health access in iOS Settings → Privacy & Security → Health.

We do not use health data for advertising, marketing or profiling, and we share it with no one.

7. Notifications

There are two kinds:

The notification token belongs to the device and carries no identity. We delete it when you sign out — so that if someone else uses the same phone, your notifications don't go to them.

8. Your profile photo is public

A profile photo you upload is stored at a publicly accessible address that anyone who knows it can open. Inside the app we only show that address to users who can already see you, but the link itself does not require signing in.

So: don't use a photo you would mind anyone seeing. When you change your photo the new one replaces it; the old file may stay reachable for a while.

9. Messages and deleting them

Messages are not end-to-end encrypted between devices. Technically they sit readable in the database. We do not read messages as a matter of routine; we would only access them for a report investigation or a lawful legal request.

What you should know about deleting:

"Delete for everyone" removes the message text (and for an invite, the date and time), leaving a "this message was deleted" marker. The row itself — who sent it to whom, and when — stays in the database.

"Delete for me" only removes the message from your screen. The other person still sees it.

The other person may also have taken a screenshot, which we cannot prevent.

10. Membership and payment

Membership purchases go entirely through Apple. Your card details, invoices and payment history are held by Apple and never reach us.

We use a service called RevenueCat to track subscription status. RevenueCat tells us only whether a given user's subscription is active and when it ends, and we store that against your account. The only identifier sent to that service is your account's random number.

11. Who we share with

We do not sell your data and pass it to no one for advertising. These are the service providers the app relies on, and what reaches each of them:

WhoWhat forWhat reaches them
Supabase Database, accounts, file storage Everything in section 3
Cloudflare Where the coach server runs The coach text in section 4
Google (Gemini) Generates the coach's comment The coach text in section 4
Expo Notification delivery Notification token and notification text
Apple App distribution and payment Payment details (which never reach us)
RevenueCat Subscription status tracking Your account's random number and subscription status

Beyond these, data is shared in only two situations: a lawful request from a competent authority, and a transfer of the app (in which case you'd be told beforehand).

12. Where your data is held

All of the providers above process data on servers outside Türkiye, mainly in the European Union and the United States. By using the app you accept this international transfer. The providers carry it out under mechanisms such as standard contractual clauses.

13. How long we keep it

14. Deleting your account

You can delete your account yourself in the app: Settings → Delete My Account. This cannot be undone and permanently deletes:

The journal, goal and workout records on your phone are removed separately, by deleting the app.

Copies may persist briefly in backups; these are removed automatically as the backup cycle turns over and are not accessible in normal use.

15. Your rights

Under the GDPR and Article 11 of Türkiye's KVKK you have the right to: learn whether your data is being processed, request a copy, have inaccurate data corrected, request erasure, object to processing, withdraw consent you have given, and receive your data in a portable form.

To exercise any of these, write to disciplinex0011@gmail.com. We respond within 30 days at the latest. You don't have to wait for a deletion request — you can do it yourself with "Delete My Account" in the app.

If you have a complaint about how your data is handled, you can contact the data protection authority in your country, or in Türkiye the Personal Data Protection Authority (KVKK).

16. Age limit

DisciplineX is not for anyone under 18. You confirm you are over 18 when you sign up. If we learn that an account belongs to someone under 18, we delete the account and its data. If you believe your child has created an account, write to the address above.

17. Things we don't do

18. Security

Connections are encrypted (HTTPS), passwords are stored as cryptographic hashes, and the database enforces row-level access rules — technically, a user can only read rows that belong to them or are shared with them. Even so, no system is completely secure, and we cannot guarantee absolute security of your data.

19. If this policy changes

If we update this policy we'll change the date on this page. For a significant change we'll also tell you inside the app. Continuing to use the app after a change means you accept the updated version.

20. Contact

For anything at all: disciplinex0011@gmail.com