FLUX WORKOUTS Download Free

Legal

Privacy Policy

Last updated: August 23, 2026

DIGITAL FLUX LTD ("we", "us", or "our") operates the Flux Workouts mobile application and the fluxworkouts.com website (together, the "Services").

This Privacy Policy explains how we collect, use, store, and protect personal data when you use the Services, and outlines your rights under applicable data protection laws, including the UK GDPR and EU GDPR.

1. Information We Collect

1.1 Information You Provide

When you use Flux Workouts, you may provide:

1.2 Automatically Collected Information

The App and its service providers may process:

1.3 Health & Fitness Data

Workout data and physical metrics you log are considered health-related data under certain laws. This data is collected only to provide and improve the Service and is never used to provide medical advice.

With your permission, the App may access Apple HealthKit data such as sleep duration, heart rate variability, resting heart rate, VO2 Max, date of birth, and biological sex to personalise training recommendations. HealthKit access is optional and controlled through Apple’s permissions. Processing for recommendations occurs on your device; supported health-derived values may also be included in your encrypted transport to Firebase when you choose signed-in cloud sync. We do not use HealthKit data for advertising.

1.4 Website Data

The website stores your analytics choice in local storage. If you accept website analytics, Google Analytics 4 (GA4) may process page views, link and button interactions, approximate location derived from IP address, referrer, browser, and device information. Website analytics is off until you consent. Advertising storage, ad-user-data, ad-personalisation signals, and Google Signals remain disabled.

2. How We Use Your Information

We use your information to:

Where required by law, you may opt out of certain data uses within the App.

3. Analytics, Machine Learning & Attribution

Flux’s personalised exercise-selection, progression, and readiness models run on your device. Flux is not a chatbot, and your workouts are not sent to an open-ended generative-AI service.

The App’s Share Analytics setting controls product-usage analytics sent through Tealium. It starts off for a newly created profile and onboarding presents it as a separate, optional choice; 8.4 also resets the former default-on preference to off until you choose to enable it again. It can be changed later in Profile. The App does not start Tealium or send product events until it has resolved a saved enabled preference under the current consent contract. When enabled, Tealium EventStream receives a pseudonymous visitor identifier, session and transport timestamps, and only the explicit screen, feature-interaction, configuration, commerce, and bounded training-event summaries that Flux records. Those summaries exclude free-text exercise names, workout notes, stress, and soreness. Flux disables Tealium’s optional Device, Connectivity, and Lifecycle collectors, suppresses the Core-generated app_uuid, and does not send automatic launch, wake, or sleep events. Tealium may forward selected pseudonymous events to GA4 for product measurement. Flux does not attach your email address or Firebase user ID as the Tealium analytics identity, although App privacy disclosures conservatively treat the events as linked because routine, workout, or gym identifiers may connect them to signed-in cloud data.

Turning Share Analytics off stops new Tealium product-analytics dispatches; it does not retroactively delete events already processed. Signing out, deleting an account, or changing to a different account clears pending Tealium context and events and replaces the visitor identifier before analytics can start for the next account.

Firebase Crashlytics separately processes crash and non-fatal error information, performance data, and other diagnostics needed to keep the App reliable and secure. Google/Firebase services may also process device identifiers and operational product-interaction or other usage data to provide authentication, App Check, cloud sync, Remote Config, notifications, and backend functions. When you are signed in, this functionality and diagnostic data may be associated with a Firebase account identifier. It is not controlled by the Share Analytics toggle. Deleting your account clears the current Crashlytics user identifier and custom diagnostic context for later reports, but it does not remove crash or non-fatal reports that were already created.

For Apple Ads attribution, the App obtains Apple’s short-lived attribution token and sends it to a protected Flux backend for immediate exchange with Apple. The raw attribution token is not stored locally or server-side. We retain only supported campaign fields and a one-way hash of the pseudonymous commerce identifier, and use them to measure Flux’s own acquisition campaigns and connect purchases, refunds, or revocations to aggregate campaign performance. Attribution records become unusable no later than 180 days after receipt and are then removed by Firestore’s asynchronous time-to-live process; current-version account deletion requests exact deletion of the matching hashed record earlier. After deletion, Flux retains only a minimal one-way-hash suppression marker, without campaign data, so an in-flight request, reinstall, or another device cannot recreate the deleted attribution record.

Flux does not use collected data to track you across apps or websites owned by other companies, does not access the advertising identifier (IDFA), and does not declare tracking domains. Apple Ads attribution measures only campaigns that promote Flux; it is not used to serve third-party advertising.

4. Legal Bases for Processing (GDPR)

We process personal data under the following legal bases:

You may withdraw consent where applicable. You can also change the App’s Share Analytics preference or the website analytics choice at any time.

5. Sharing Your Information

We do not sell your personal data.

We may share information with the following categories of service providers:

We do not sell personal data, and we do not use health or workout content to serve third-party advertising. Apple Ads attribution is used only to measure campaigns promoting Flux and to understand related trial, purchase, refund, or revocation outcomes.

The App stores its randomly generated commerce identifier and protected trial/access anchors in Apple’s synchronizable Keychain. This helps keep trial and purchase state consistent after reinstall and across eligible devices. The identifier is not your Apple Account identifier, email address, or Firebase user ID. Apple’s signed transaction remains the purchase authority.

6. International Data Transfers

Your data may be processed outside your country of residence, including in jurisdictions that may not offer the same level of data protection. Where required, we use appropriate safeguards such as:

7. Data Retention

We retain each category only for the purpose that requires it:

Deleting the App does not necessarily remove synchronizable Keychain items, optional cloud data, or App Store transaction records held by Apple. You may request account deletion in the App or contact us. Account deletion does not require Apple to erase its purchase records and may not remove the limited commerce evidence or limited Crashlytics diagnostic retention described above where continued retention is necessary and lawful.

8. Your Rights

Depending on your location, you may have the right to:

You can exercise these rights via the App or by contacting us.

9. Children's Privacy

Flux Workouts is intended for adults. Minors may use the App only under the supervision of a parent or legal guardian.

We do not knowingly collect personal data from children without appropriate parental consent. If you believe a child has provided personal data without consent, please contact us and we will take appropriate action.

10. Security

We implement reasonable technical and organisational measures to protect personal data, including encryption, access controls, and secure infrastructure. However, no system is completely secure, and we cannot guarantee absolute security.

11. Third-Party Services & Links

The App may contain links to third-party services or integrate with third-party platforms. We are not responsible for the privacy practices of those services. We recommend reviewing their privacy policies before providing personal data.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be communicated via the App or email and take effect upon posting. Continued use of the Service constitutes acceptance of the updated policy.

13. Contact Us

If you have questions or requests regarding this Privacy Policy or your personal data, contact us at:

[email protected]