Legal
Privacy Policy
What Postural collects, at a glance
The short version: your posture photos are analysed on your phone and stay there. Your scores sync to your account so your history survives a reinstall. Nothing is sold, and nothing is used for advertising.
| Data | Where it goes | Tied to you |
|---|---|---|
| Posture photos | Your device only, never uploaded | On device |
| Scan scores & history | Firebase Firestore | Your account |
| Email address | Firebase Authentication | Your account |
| Product analytics events | PostHog | Account ID only |
| Crash reports | Firebase Crashlytics | Not identified |
| Push notification token | Firebase Firestore | Your account |
| Birth year & height | Firebase Firestore | Your account |
| Subscription status | Firebase Firestore | Your account |
About this policy
This policy describes how Rahul Kumar Gupta, trading as SRS Tech ("we", "our", "us"), of Bengaluru, Karnataka, India, handles information when you use Postural, an iOS application we develop and publish.
By downloading or using Postural, you agree to the collection and use of information described here. If you don't agree, please don't use the app.
Your posture photos
Postural photographs you from the front and the side to measure five biomechanical markers, four of which feed your Postural Age. Those photos are the most personal thing the app touches, and they are handled accordingly:
- Every photo is stored only on your device, in the app's Application Support directory.
- Each file is flagged at the filesystem level to exclude it from iCloud backup, so it isn't copied off your phone by an unrelated process. Exporting a timelapse or sharing a comparison card is different: that writes the image into your Photos library, where your iCloud Photos settings apply.
- An automated test verifies that flag on every build, so no future release can drop the exclusion without failing the build.
- Photos are never uploaded to our servers or to any third party. Only the resulting scores leave your device.
- Deleting the app permanently removes every locally stored photo.
Accounts and sign-in
Postural requires an account. You sign in with Sign in with Apple or Google Sign-In. We never ask you to create a password with us, and we never see one.
- Your email address is stored in Firebase Authentication to identify your account. Sign in with Apple may relay a private proxy address instead of your real one; that works fine here.
- Your scan scores and progress history are stored in Firebase Firestore against your account, so your history survives reinstalling the app or changing phones.
- Your birth year and height are typed into the app during setup, and both are stored in Firestore against your account. Birth year is what the Postural Age comparison is measured against; height scales the landmark distances. Neither is sent to analytics.
- A device notification token (APNs/FCM) is stored in Firestore so push notifications can be delivered. It identifies a device, not a person, and is never shared with advertisers.
- Your subscription status is mirrored into Firestore so the app knows what you have access to on any device: the product identifier, whether it is active, the trial end date, the current period end date, and when the record was last updated. Apple handles the payment; we never see a card number.
In full, your user document in Firestore holds: email address, birth year, height, an onboarding-completed flag, your notification time, your timezone, your weekly scan day, your scan direction, your push token, the subscription fields above, and created and updated timestamps.
Analytics and crash reporting
Postural records product analytics covering which screens are opened, which actions are taken, and whether a scan completed, so we can find where the app is confusing or broken. These events go to one service: PostHog (US region).
- Events carry no photos, no scores, and no email address. The only identity attached is your account ID and which provider you signed in with (Apple or Google).
- Session replay is switched off, so we never capture a recording of your screen, including the camera and scan screens.
- Automatic event capture is switched off, so no screen view or app-lifecycle event is collected on its own. Only events we deliberately added are sent.
- Postural uses no Advertising Identifier (IDFA), so it shows no App Tracking Transparency prompt and does no cross-app tracking. PostHog derives a coarse, city-level location from your IP address for aggregate reporting only.
- Crash and error reports go to Firebase Crashlytics and contain a device model, an iOS version and a stack trace, with no user identity.
Exercise videos
Daily routines include video demonstrations embedded from YouTube in an in-app web view. When a video plays, your device connects directly to YouTube's servers and Google's privacy policy applies to that connection.
We do not send your posture data, scan results or identity to YouTube.
Notifications
Daily reminders are scheduled as iOS local notifications (UNUserNotificationCenter) on your device, and nothing is sent to a server to trigger them.
The app also registers a push token with Apple and Firebase and stores it against your account. No server-side push campaigns are currently sent; the token is stored in anticipation of future use.
You can turn all notifications off at any time in iOS Settings → Postural → Notifications.
How we use this information
- Analytics: to understand in aggregate how the app is used, and to improve it.
- Crash reporting: to find and fix stability problems.
- Your account: to keep your progress history and to delete it when you ask.
We do not use your information for advertising or behavioural profiling, we do not sell it, and we do not use it for anything not listed above.
Third-party services
Postural relies on the following services, each governed by its own privacy policy:
- Firebase: Authentication, Firestore, Crashlytics, Cloud Messaging (Google). firebase.google.com/support/privacy
- PostHog: product analytics, US region. posthog.com/privacy
- Google Sign-In: policies.google.com/privacy
- Sign in with Apple: apple.com/legal/privacy
- YouTube: exercise video playback. policies.google.com/privacy
Retention and deletion
On-device data: posture photos, local history and preferences, is deleted when you uninstall the app.
Account data is kept in Firebase until you delete your account, which you can do at any time from Settings → Delete Account inside the app. That permanently removes your account and all associated scan history.
Analytics and crash data is retained by PostHog and Firebase Crashlytics under their own retention policies, which run to 90 days for Crashlytics.
Children's privacy
Postural is intended for adults and is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we'll delete it.
Your rights
Depending on where you live, you may have the right to access, correct or delete the personal data we hold about you, or to withdraw consent at any time.
The fastest route is Settings → Delete Account in the app, which removes your account and history right away. For anything else, email support@srstech.in.
Medical disclaimer
Postural is a consumer wellness app, not a medical device. Postural Age is a trend indicator derived from geometric measurements taken by your phone camera. It does not diagnose, treat or prevent any condition, and it cannot replace a professional physiotherapy assessment. For clinical concerns, consult a qualified healthcare provider.
Changes to this policy
We may update this policy. Each update changes the "last updated" date at the top of this page. Continuing to use Postural after an update means you accept the revised policy.
Contact
Questions about this policy or your data:
Rahul Kumar Gupta, trading as SRS Tech
Bengaluru, Karnataka, India
support@srstech.in
srstech.in