Effective date: 2026-10-05 · Last updated: 2026-10-05
Summary
- What PopUpTime does: uses your iPhone camera and on-device pose detection to watch your surf pop-up, time it, and help you make it smoother through daily practice. It can optionally hold apps you choose behind your practice using Apple's Screen Time system.
- Your camera never leaves your iPhone. The camera feed and the body-pose data derived from it are processed live, on your device, in real time. They are never uploaded, never sent to me, and never seen by anyone else.
- Your practice history stays on your device unless you sign in. Your pop-up times, reps, daily goals, streak and session history are stored only on your device. If you sign in, a copy is backed up to your account so it survives a reinstall or a new phone.
- Saved replay clips stay on your device. If you choose to record a pop-up, the clip is stored locally and is never uploaded.
- An account is optional. You can use PopUpTime without one. If you sign in with Apple or Google, I hold your email address, your name if the provider shares it, and an account ID — never a password. You can delete your account in the app at any time.
- Subscriptions are pseudonymous unless you sign in. Buying a subscription creates a random identifier that is not linked to your name or your Apple ID. If you sign in, your subscription is linked to your account instead.
- No advertising, no analytics SDKs, no data brokers, no tracking. PopUpTime shows no ads and does not track you across apps or websites.
Who is responsible for your data
PopUpTime is built and operated by Franklin Velásquez, an individual developer, acting as the data controller for the limited processing described below.
Contact: popuptimeapp@gmail.com
What stays on your device and is never collected
The following never leaves your iPhone, whether or not you sign in. It is held on your device and is not transmitted to me or to anyone else:
- Your camera feed. PopUpTime uses the camera to watch your pop-up. Each frame is analysed on your device, in real time, to detect your body position, and is then discarded. No video is uploaded or sent to me.
- Your pose data. The body points the app detects to time and judge your pop-up are computed and used on your device only.
- Saved replay clips. If you record a pop-up, the video is written to your device's storage so you can review it. It stays there until you delete it, and is never uploaded.
- Your practice history — your pop-up times, each session's reps, your daily goal, your streak and your history — stays on your device unless you sign in, in which case it is backed up as described below.
- Motion sensor readings. PopUpTime reads your device's accelerometer to tell when the phone has been set down and is still, so a session starts only once it is in place. These readings are used live, on your device, and are not stored or transmitted.
- Your app selection, if you use app-locking. When you pick apps to hold behind your practice, Apple's Family Controls framework returns an opaque FamilyActivitySelection token. The token is meaningless outside Apple's own system — even PopUpTime cannot tell which apps you picked or read their names. This is Apple's design.
To remove any ambiguity, PopUpTime does not collect your location, contacts, photos library, calendar, or health data. The app does not use the microphone, and its practice clips are recorded without audio. It processes the camera only for the pop-up feature, on-device, and does not retain the video stream.
PopUpTime does not use cookies and does not track you across other apps or websites. No App Tracking Transparency prompt appears because there is nothing to track.
What is collected, and by whom
Your account (optional)
You can sign in with Apple or Google from the app's Settings. Signing in is never required to use PopUpTime or to subscribe. If you do, my Supabase backend creates an account holding:
- your email address, as your sign-in provider shares it. With Sign in with Apple you can choose Hide My Email, in which case I receive only an Apple relay address;
- your name, if the provider shares it. Apple shares it only the first time you sign in, and only if you allow it. Google shares your profile name and a link to your profile picture, which PopUpTime does not display;
- an account ID — a random identifier Supabase assigns, and which provider you used;
- sign-in records — when the account was created and last signed in to, and, in Supabase's security logs, the IP address and device details of sign-in requests.
Progress backup. While you are signed in, PopUpTime also saves a copy of your practice history (your sessions, pop-up times, goal and streak) to your account, and restores it when you sign in on a new install. It contains no video and no camera data — only the numbers and dates of your practice.
I use this only to sign you in, to back up and restore your practice history, to link your subscription to your account (below), and to answer you if you contact me. I never receive your Apple or Google password.
Deleting your account. In PopUpTime, go to Settings → Account → Delete account. This permanently deletes your account, the backup of your practice history, and the copy of your subscription record held in Supabase. The data on your phone stays there. For Sign in with Apple, it also revokes PopUpTime's access to your Apple ID; for Google, it disconnects PopUpTime from your Google account. Deleting your account does not cancel your subscription, which belongs to your Apple ID — cancel it in your Apple account settings.
Subscription data
PopUpTime is free to download; full practice requires a paid subscription. Payment is processed by Apple, and subscription status is managed by RevenueCat.
When you subscribe, RevenueCat assigns your installation a random anonymous identifier. PopUpTime never gives RevenueCat your name, email address, or Apple ID. If you sign in, PopUpTime tells RevenueCat your account ID instead, so that your subscription follows your account; because that ID belongs to your account, your subscription is then linked to the email address held with it. Against that identifier, the following is recorded:
- which product you bought, and from which store
- whether the subscription is currently active, and when it expires
- Apple's original transaction identifier
- whether the purchase was made in the sandbox or production environment
- the price paid, its currency, and your App Store country
To process purchases, RevenueCat also receives technical details that accompany any request from the app, such as your IP address and your app and iOS versions.
A copy of this subscription record is stored in my own Supabase database so that entitlements survive a reinstall.
When a purchase, renewal, cancellation or refund happens, I receive an automated message through a messaging service I use for internal alerts. It contains only the event type, product, price, currency, store, and App Store country — no subscriber identifier and no personal information.
I never see your credit card details, billing address, or Apple ID. Apple does not share them with me.
Update and configuration checks
When PopUpTime starts, it asks my Supabase backend for the minimum supported app version, so that a broken release can be corrected. This is a read-only request that sends no information about you. As with any internet request, the server necessarily sees the originating IP address and processes it transiently to serve the response.
PopUpTime also checks Expo's update service for bug fixes and content updates that can be delivered without a new App Store release. That request carries your IP address, your platform and app version, and a random identifier that Expo generates for this installation to roll updates out gradually. The identifier is not linked to your name, your Apple ID, or your subscription.
Diagnostics
PopUpTime integrates no crash-reporting or analytics SDK. If you choose to share crash diagnostics with developers in your iOS settings, Apple may provide me with aggregated crash reports — device model, iOS version, and where the crash occurred. These come from Apple, contain nothing about your camera, your pop-up activity or your gated apps, and are not linked to you.
If I add crash reporting or analytics in a future version, this policy will be updated and the provider named here before the feature ships.
Third parties I share data with
These are the third parties involved, and this is everything they receive. Each provides protections at least equivalent to those described in this policy, as required of me by Apple's App Store Review Guidelines.
| Provider | What it receives | Why | Their policy |
|---|---|---|---|
| Apple | Your purchase, processed under your Apple account. If you use Sign in with Apple: the sign-in itself, and the revocation request when you delete your account | Payment, subscription billing, App Store delivery; sign-in | apple.com/legal/privacy |
| If you use Sign in with Google: the sign-in itself, handled by Google's sign-in library inside the app | Sign-in | policies.google.com/privacy | |
| RevenueCat | Subscriber ID (anonymous, or your account ID if you signed in), purchase receipts, subscription status | Managing subscriptions and restoring purchases | revenuecat.com/privacy |
| Supabase | Your account and practice backup, if you signed in; the subscription record above; IP address of update checks, transiently | Sign-in, practice backup, backend database and configuration | supabase.com/privacy |
| Expo | IP address, platform, app version, random installation ID | Delivering app updates | expo.dev/privacy |
| Cloudflare | Purchase events from RevenueCat, in transit | Hosting the webhook that relays purchase notifications | cloudflare.com/privacypolicy |
| Messaging service | Event type, product, price, currency, store, App Store country — no identifiers | Delivering internal purchase notifications to me | — |
I do not sell your personal information, share it with advertisers or data brokers, or use it to build a profile of you. Per Apple's Family Controls framework agreement, PopUpTime does not use any device or usage data received through Family Controls for advertising or advertising measurement, or share it with data brokers.
Legal basis for processing
For users in the European Economic Area and the United Kingdom, I rely on the following lawful bases under Article 6 of the GDPR:
- Performance of a contract — processing your subscription record, so that you receive the paid features you bought and can restore them on a new device; and, if you create an account, holding it and your practice backup so that you can sign in, restore your history, and have your subscription follow you.
- Legitimate interests — the update check that keeps the app working, and the security and integrity of the service. These are minimal and pseudonymous, and do not override your rights.
There is no processing based on consent today, because PopUpTime collects nothing that requires it. PopUpTime does not carry out automated decision-making or profiling that produces legal or similarly significant effects.
How long data is kept
- On-device data — including your camera-derived pose data (held only momentarily), your practice history and any saved clips — kept until you delete it in the app or uninstall PopUpTime. Deleting the app removes all of it permanently, and I have no copy.
- Your account and practice backup — kept until you delete your account. Deletion is immediate and permanent.
- Subscription records — kept for the life of the subscription and for up to 7 years after it ends, because tax and accounting rules require records of sales to be retained. If you delete your account, the copy in my Supabase database is deleted at once; Apple and RevenueCat keep their own transaction records under their policies.
- Crash diagnostics from Apple, where provided — kept no longer than 12 months.
- Purchase notifications — kept for the same period as subscription records, as part of my sales records.
- Server logs — rotated by Supabase, Expo and Cloudflare under their own retention schedules, typically measured in days.
International transfers
PopUpTime is available worldwide, and the providers above operate infrastructure in several countries, including the United States. Where data is transferred out of the European Economic Area or the United Kingdom, that transfer is covered by the providers' Standard Contractual Clauses and equivalent safeguards, as set out in the privacy policies linked in the table above.
Your rights
Wherever you live, you may ask me to:
- Access the data held about you, and receive a copy of it
- Correct anything inaccurate
- Delete it
- Export it in a portable format
- Restrict or object to how it is processed
- Withdraw consent, where processing rests on consent
How to exercise them: email popuptimeapp@gmail.com. I will respond within 30 days. If you have an account, write from its email address. If you don't, your subscription record is pseudonymous, so please include your Apple receipt or original transaction ID so that I can locate the right record — without it I may be unable to identify your data, which is itself a consequence of how little I collect.
To delete your account, use Settings → Account → Delete account in the app — no email needed.
To delete everything held on your device, uninstall PopUpTime. If you never created an account, nothing further is required and nothing is retained elsewhere, apart from the pseudonymous subscription record described above.
If you are in the EEA or the UK, you also have the right to lodge a complaint with your national data protection authority.
California residents
If you are a California resident, the CCPA as amended by the CPRA gives you the rights to know, delete, correct, and opt out of the sale or sharing of personal information, and not to be discriminated against for exercising them. I do not sell or share personal information, and never have. Exercise these rights at the same address above. PopUpTime is a small independent app that likely falls below the CCPA's applicability thresholds, but these rights are honoured regardless.
Security
Data that never leaves your iPhone — including your camera feed and the pose data derived from it — is protected by your iPhone: its encryption, its passcode, and iOS's app sandbox. This is deliberate: the most sensitive information PopUpTime touches is the information it never transmits.
The little that is transmitted travels over encrypted HTTPS connections. The database holding accounts and subscription records is reachable only with credentials I hold, and a signed-in app can read nothing but its own account. No method of transmission or storage is completely secure, and I cannot guarantee absolute security, but the amount of your data exposed to that risk is intentionally close to zero.
Children's privacy
PopUpTime is intended for teens and adults. It is not directed at children under 13, or under the minimum age required in your country, and I do not knowingly collect personal information from them. If you are a parent or guardian and believe your child has provided me with personal information, contact me and I will delete it.
Links to other sites
PopUpTime and this website may link to sites I do not operate, such as Apple's. I am not responsible for their content or privacy practices, and I encourage you to read their policies.
Changes to this policy
I may update this policy as PopUpTime changes — for example, if more of what stays on your device today were ever sent to my backend. The Last updated date at the top always reflects the current version, and material changes will be announced in the app before they take effect.
Changelog
| Date | Change |
|---|---|
| 2026-10-05 | First version, published for the PopUpTime release: on-device camera and pose processing; optional accounts (Sign in with Apple or Google) and practice backup; subscriptions via Apple and RevenueCat; Supabase, Expo and Cloudflare named as processors; legal bases, retention, international transfers, rights procedures, and the California section. |
Contact
Questions, requests, or corrections about this policy:
Email: popuptimeapp@gmail.com