Your moves, streaks and settings live on your device, not on our servers. There is no account, so there is nothing to log into and nothing to leak. As of version 6.0 there is no advertising SDK in SuperMoo on any platform, and no tracking prompt, because there is nothing left to ask permission for. What leaves your device is a purchase receipt and a random identifier so a purchase you already made keeps working. We never sell your data, we never use data brokers, and there are no ads inside SuperMoo.
This policy is written per app, because the apps genuinely differ. One ad measurement tool remains, on iPhone and iPad only: Apple's own attribution token. Android, the Mac menu bar app and the Chrome extension have no ad measurement at all. Where a section applies to only some of them, it says so.
Who we are
SuperMoo is made by Reweave, Inc., a 501(c)(3) nonprofit building tools for movement and learning. Find out more at reweave.org.
What data SuperMoo collects
There is no account, no login, no name, and no email address. We never learn who you are.
As of version 6.0 there is no advertising SDK in SuperMoo on any platform. The Meta SDK is gone from both the iPhone and Android apps. So is the Apple tracking prompt, so is the advertising identifier, and so is the Google Play Install Referrer. Android now has no ad attribution at all.
One measurement tool remains, and only on iPhone and iPad: Apple's own attribution token, described in the advertising section below. There is nothing equivalent on Android, Mac or Chrome.
What leaves your device, complete list. There are five things and this is all of them.
- A purchase receipt and a random identifier, to RevenueCat, so a purchase you already made survives a reinstall. RevenueCat is a payments provider, not an ad network and not a data broker.
- Apple’s attribution token, on iPhone and iPad only, described in the advertising section below.
- A weather lookup, for weather-aware nudges. The location comes from the city you typed, never from your device’s GPS.
- A city search, for the same feature, when you are choosing that city.
- A version check against Apple’s own listing, to see whether a newer SuperMoo exists. It carries nothing about you.
The only companies that receive anything at all are the ones named above. There is no separate analytics product in SuperMoo, no advertising network, no crash reporter, no social login and no data broker.
Want any of it gone? How to delete your data.
Apple and Google each ask developers to declare this on the store listing. Those declarations are kept current, and this policy will never claim less than they do. We describe behaviour here rather than repeating a label, because a label can be edited in a console and a policy should not quietly fall out of step with it.
Health and Fitness is not collected at all: SuperMoo writes completed moves into your own Apple Health store and can never read anything back, and writing to your own device is not collection by us.
The following information is stored only on your device using local storage on your phone (and your Apple Watch, if paired). It never leaves your device and is never sent to any server:
- Your daily move counts and move history
- Your current streak and all-time totals
- Your reminder preferences (days, times, frequency)
- Your move goal
- Whether you've completed onboarding
- Sound and notification settings
- Watch app sound preference (on the watch only)
This data is deleted if you delete the app. We have no copy of it.
Purchases and payments
On iPhone and iPad, purchases are processed by Apple through the App Store. On Android, by Google through Google Play. On the Mac menu bar app, by Apple through the Mac App Store. The Chrome extension is different. Its one-time purchase runs through RevenueCat’s own hosted checkout page, with Stripe as the payment account behind it, so your card details go to Stripe and never to us. Nothing is sold through the Chrome Web Store, which stopped processing payments years ago.
RevenueCat verifies purchase status on iPhone, iPad, Android and Chrome. The Mac menu bar app does not use RevenueCat; it talks to Apple directly.
RevenueCat receives a randomly generated anonymous identifier to track your purchase status. No name, email, or personal information is shared. You can review RevenueCat's privacy policy at revenuecat.com/privacy.
We do not store or process your payment details. All payment handling is done by Apple, Google, or Stripe.
Notifications
If you grant permission, SuperMoo schedules local notifications on your device as movement reminders. These are generated and stored entirely on your device. No notification content is sent to or processed by any external server.
Audio assets
The app's dance song streams from a Cloudflare R2 bucket controlled by Reweave. Cloudflare receives standard request data (your IP address) needed to serve the file. No personal information is sent. We do not log or correlate these requests with any user.
Analytics
There is no general analytics service. Firebase Analytics was removed and nothing replaced it, so SuperMoo does not report how you use the app to anyone. No session replay, no heatmaps, no data brokers.
SuperMoo collects no product interaction data at all. Not anonymously, not in aggregate, not for our own curiosity. The logging function inside the app is an empty stub: about 225 places in the code call it, and every one of them goes nowhere. That is why Product Interaction was removed from the App Store privacy label outright rather than declared and marked non-tracking. We do not know which buttons you press, which mooves you pick, or how often you open the app.
One advertising measurement tool remains, on iPhone and iPad only.
- Apple's attribution token. SuperMoo asks Apple whether an App Store search ad led to the install. Apple handles it end to end, it needs no tracking prompt because it is Apple's own mechanism rather than a third party's, and it carries no name, email or contact details. It exists for one reason: a nonprofit running a small ad budget has to know which ads are worth paying for.
There is no equivalent on Android, Mac or Chrome. Those three have no ad measurement of any kind.
It does not receive your moves, streaks, goals, history or settings. We verified that by reading the source rather than trusting our memory of it.
The advertising SDK we removed
Until version 6.0, SuperMoo carried Meta's SDK on iPhone and Android so we could tell whether the ads we paid for actually worked. It is gone. Removed from both apps in the same release, in August 2026.
Gone with it, on iPhone: the Apple tracking prompt, the Facebook configuration keys, and both Meta SKAdNetwork entries. On Android: the Meta SDK, the Google Play Install Referrer, and the AD_ID permission that made the advertising identifier readable at all. Google Play now records that SuperMoo does not use an advertising ID.
What this means in practice. There is no tracking prompt on first launch any more, because there is nothing left to ask permission for. Nothing about your install or your usage reaches Meta or any other advertising company. On Android there is now no ad attribution whatsoever, which we accepted as the cost.
We are not going to dress this up as a moral awakening. The immediate trigger was a Google Play policy requirement for apps that reach children. But we had been uncomfortable with it for a while, the app is used by kids and in classrooms, and once we looked properly the SDK was doing far less for us than it was costing anyone who installed.
The only ad measurement left anywhere in SuperMoo is Apple's own attribution token on iPhone and iPad, described in the section above.
Apple Health
If you grant permission, SuperMoo logs each completed move as 4 active calories and 1 exercise minute to Apple's Health app, from your iPhone, iPad, or Apple Watch. SuperMoo only writes these completed moves to Health; it never reads your health data.
This data is written directly to Apple's Health database on your device. It does not leave your device. Reweave does not see it, store it, or have any access to it.
You can revoke this permission at any time in iOS Settings → Health → Data Access & Devices → SuperMoo. The app continues to work normally if you decline or revoke.
The Mac menu bar app
The Mac menu bar app is built differently from the phone apps. It has never contained an advertising SDK or a tracking prompt, and unlike the phone apps it does not use RevenueCat either; it handles purchases through Apple directly using StoreKit.
One thing worth being straight about: Apple sets the App Privacy label per app record rather than per platform, so the Mac product page displays whatever the iPhone record declares. The paragraph above describes what the Mac build itself contains.
The Chrome extension
The extension is the easiest one to verify for yourself, because a browser extension has to declare everything it can touch and anyone can read that declaration. Ours asks for three permissions: alarms to schedule the hourly reminder, notifications to deliver it, and storage to keep your settings, move history and streak on your own machine. It asks for one outside address, RevenueCat's API, purely to check whether premium has been purchased.
One thing to be upfront about, because it is the only identifier involved. The first time the extension checks your premium status it generates a random identifier, stores it on your machine, and sends it to RevenueCat each time it checks again. It is a random string, it is tied to nothing else about you, and it exists so a purchase you already made keeps unlocking premium. It is not shared with anyone and it is not used for advertising.
It has no permission to read any page you visit. There is no tabs permission, no activeTab, and no content scripts, so the extension cannot see the pages you have open, their addresses, or anything you type into them. That is not a promise, it is the manifest, and checking it takes about thirty seconds.
One line in that manifest looks alarming and is not, so here it is before anyone screenshots it out of context. The extension marks its own five sound files as loadable by any page. That points the opposite way from a permission: it lets a page load our mp3 files, and gives the extension no access to anything at all.
You do not have to take our word for the storage part either. This is the justification filed with Google, public on the extension's own store page: "Used to save the user's reminder settings, move history, streak, and premium status locally on their device. No data is sent to external servers except RevenueCat for purchase verification." That is what we told Google, and it matches what this page tells you.
The extension has never contained an advertising SDK of any kind. As of version 1.2 the fonts are bundled with it rather than fetched from Google, so once installed it contacts nothing on the internet except RevenueCat. Its Chrome Web Store listing declares zero data collected across all nine of Google’s categories, and the justification filed there for the storage permission reads: no data is sent to external servers except RevenueCat for purchase verification. That is a different answer from the App Store label, and both are correct, because these are genuinely different builds with different code in them.
Apple Watch sync
If you have an Apple Watch paired with your iPhone, SuperMoo uses Apple's WatchConnectivity framework to sync your move count, daily goal, and streak between the two devices. This sync happens locally over Bluetooth between your devices. The data does not pass through any Reweave server.
The watch app stores its own copy of move data on the watch using on-device storage. Same rule: never leaves the device.
Third-party services
The third-party services SuperMoo uses are: RevenueCat (subscription management), Cloudflare R2 (to host the dance song asset), Givebutter (only on the donate page of this website, to process donations), and Apple Health (SuperMoo writes your completed moves to the Health app, on your device only, and never reads anything from it). No behavioural trackers or data brokers are used.
Children's privacy
SuperMoo has no account system, so we never knowingly collect a name, email address or contact detail from anyone, including children. There is no advertising SDK in the app on any platform, no advertising identifier is read, and no profile of any user is built anywhere. The one remaining measurement tool, Apple's attribution token on iPhone and iPad, reports whether an App Store ad led to an install and nothing about the person who installed it.
Changes to this policy
When we update this policy, the new version goes live at this URL with a fresh date at the top. If we ever start collecting more data, we'll say what and why in plain English.
Questions?
If you have any questions about this privacy policy or how SuperMoo handles data, reach us at:
supermoo@reweave.orgOne person builds SuperMoo, and reads every one of these.