The Postava application (“App”) cares about your privacy. This Privacy Policy explains how we collect, use and share your personal data, what rights you have, and how we comply with applicable data protection laws (including the EU/UK GDPR, the California CCPA, and other applicable privacy legislation).
1. Who we are
The Postava App is operated by Appercut sp. z o.o. (“we”, “us”, or “Controller”), a Polish company with its registered office at ul. Twarda 18, 00-104 Warsaw, Poland (KRS: 0000775831, NIP: 5252783211).
For any questions or requests related to your personal data:
- Privacy inquiries: contact@postava.health
- General inquiries: contact@postava.health
- Mail: Appercut Sp. z o.o., ul. Twarda 18, 00-104 Warsaw, Poland
2. What we collect & why
Your data provided within the survey & while using the App
We process the data you provide in the survey to enable you to use the App and ensure you gain access to all of its features. As you use the App, we’ll record details of your workouts and progress, and ask you further questions to help improve your plan. This processing is necessary to provide the App’s core functionality and is performed on the basis of contract performance (GDPR Article 6(1)(b)).
The processing of the health-related data you provide is based on your explicit consent (GDPR Article 9(2)(a)). Until you provide this consent, the information you provide is stored only locally (on your device). Your responses are saved in our database only after you have given your consent.
Furthermore, the answers you provide will be linked to the email address you provide, after you have provided it.
We may pass on all the information you provide with the provider of the AI used within the App – Anthropic (USA), with the exception of your email address and user IDs. Subject to a separate consent, we may use the data to train AI and improve the selection of programmes.
Payment and subscription data
If you subscribe, we receive subscription status information and transaction documentation from our subscription management provider (Chargebee). We do not collect or store your payment card details, billing address, or other financial information – all payment processing is handled entirely by Stripe (through Chargebee) or PayPal. However, we do share your e-mail address with the payment providers.
This processing is performed on the basis of contract performance (GDPR Article 6(1)(b)).
Analytics and usage data
We use Mixpanel (product analytics), RedTrack (marketing attribution), Google Analytics (analytics and advertising), Meta Pixel and CAPI (marketing attribution and reporting conversion), TikTok Pixel and CAPI (marketing attribution and reporting conversion), Twitter Pixel and CAPI (marketing attribution and reporting conversion) and Snapchat Pixel and CAPI (marketing attribution and reporting conversion) to understand how users interact with the App and measure the effectiveness of our marketing. These services process pseudonymized data associated with your device identifier. Pseudonymized data is still personal data under the GDPR and is treated as such (the basis for processing is in our legitimate interests described above - GDPR Article 6(1)(f)). When you purchase a subscription, we also share a hashed email address and your estimated location (based on the IP address) with our marketing partners. The abovementioned tracking begins when you start using the App or our website.
In the EEA and UK, we activate analytics only after obtaining your consent, in compliance with the ePrivacy Directive and UK PECR. On iOS, we comply with Apple’s App Tracking Transparency (ATT) framework – if you deny tracking, no data is shared with the abovementioned providers for advertising attribution. You may withdraw your consent at any time through your device’s privacy settings. Providing consent for analytics is optional and does not affect your ability to use the App.
E-mail communication & Marketing
We use the services of Mandrill to send subscription and other App-related communications. Subject to your consent, we also use MailChimp services to send marketing e-mails. Your data is processed based on our legitimate interest in handling communications, including marketing (GDPR Article 6(1)(f)).
Customer support data
If you contact us, we process your message content and any contact details you provide, based on our legitimate interest in providing customer support (GDPR Article 6(1)(f)). We use Zendesk services to handle customer support.
Legal obligations & claims
We may process certain data to fulfill legal obligations in the field of accounting and taxation (GDPR Article 6(1)(c)), and to establish, investigate, or defend against legal claims (GDPR Article 6(1)(f)).
Is providing personal data required?
As described above, providing us with personal data for the purposes of analytics is optional. In other cases, providing your data is necessary to use the App or to respond to a customer support request.
3. Who receives your data
We share your personal data with the following service providers:
- Amazon Web Services (AWS) – cloud hosting and storage;
- providers of services described in Section 2 ‘What we collect & why’ for the purposes described there;
- Other providers as necessary for ICT support, customer support, and legal compliance.
We have data processing agreements with all providers, guaranteeing the confidentiality and security of your data.
We do not sell your personal information as defined by the CCPA or any other applicable law. We do not sell, lease, or trade your information. We do not share your personal information for cross-context behavioral advertising without your consent.
Transfers outside the EEA/UK
Some of our service providers are located outside the EEA/UK. These transfers are safeguarded by the European Commission’s or UK Secretary of State’s adequacy decisions, standard contractual clauses (SCCs), or the UK International Data Transfer Agreement (IDTA). You can obtain a copy of the data transfer safeguards by contacting us using the contact details described above.
Our providers (such as AWS and Mixpanel) may transfer data to countries covered by adequacy decisions (e.g. the United States under the EU-U.S. Data Privacy Framework) or on the basis of SCCs.
4. How we protect your data
Pursuant to obligations under Article 32 of the GDPR, we have implemented appropriate technical and organizational measures to ensure a level of security appropriate to the risk to your data.
Data breach notification
In the event of a data breach likely to risk your rights, we will notify the competent supervisory authority within 72 hours (GDPR Article 33). If the breach is likely to result in a high risk, we will also notify you directly (GDPR Article 34). For U.S. users, we will comply with applicable state breach notification laws.
5. How long we keep your data
- As a general rule, we will process your data for as long as you use the App;
- Analytics data: up to 24 months, then deleted or fully anonymized;
- Data processed for the purpose of fulfilling accounting and tax obligations: for the duration of the subscription plus up to 5 years for accounting obligations;
Storage may be extended for the establishment or defense of legal claims (up to 6 years or until proceedings conclude).
6. Your rights & choices
All users
Regardless of where you live, you can:
- Request deletion of all your data by emailing contact@postava.health;
- Opt out of analytics tracking through your device’s privacy settings (iOS: Settings → Privacy → Tracking).
EEA and UK users (GDPR / UK GDPR)
You have the right to: access your data, rectify it, delete it, restrict its processing, port it to another service, withdraw consent for analytics, marketing or AI-training at any time, and object to processing based on our legitimate interest.
You will not be subject to decisions based solely on automated processing, including profiling, which produce legal effects concerning you or similarly significantly affect you.
You may lodge a complaint with:
- Poland: PUODO, ul. Stanisława Moniuszki 1A, 00-014 Warsaw (uodo.gov.pl);
- United Kingdom: ICO, Wycliffe House, Water Lane, Wilmslow SK9 5AF (ico.org.uk);
- Other EEA countries: your local supervisory authority.
California residents (CCPA)
You have the right to: know what personal information we collect and why, delete your personal information, correct inaccurate information, and not be discriminated against for exercising your rights. We do not sell your personal information and do not share it for cross-context behavioral advertising without your consent.
Under the CCPA, health data is sensitive personal information. We use it only for providing the functionalities of the App, a purpose for which limitation is not required under CCPA regulations.
You may designate an authorized agent to submit a request on your behalf. The agent must provide written proof of authorization signed by you or a power of attorney. We may verify your identity directly.
We will respond to verifiable consumer requests within 45 days.
Categories of personal information collected (CCPA disclosure)
In the preceding 12 months, we have collected:
- Identifiers (device identifiers);
- Internet or electronic network activity (usage data, analytics events);
- Inferences drawn from the above (analytics profiles);
- Health data (data related to various types of health conditions to provide the App).
We have not sold any personal information. We have not shared personal information for cross-context behavioral advertising without consent.
7. How to delete your data
You can request to delete your data via email: contact contact@postava.health. We will respond within one month (GDPR) or 45 days (CCPA).
8. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you within the App and/or through other reasonable means. The updated policy will include a new effective date at the top.
Your continued use of the App after the effective date constitutes your acceptance of the changes. If you do not agree, please stop using the App.
Last updated: September 2, 2026