Privacy Policy
Privacy Policy for Locked: Workouts & Coach
Effective date: September 18, 2026
This Privacy Policy explains how Ponuz, LLC (“we”, “us”, “our”) collects, uses, stores, and shares personal information when you use the Locked: Workouts & Coach mobile app (“Locked”) and the associated marketing landing site (if you visit it).
Questions? Email contact@ponuz.com.
1. Who we are
Controller / business responsible for processing (or equivalent under applicable law):
- Entity: Ponuz, LLC
- Privacy email: contact@ponuz.com
- Legal / general email: contact@ponuz.com
- Address: 131 Continental Dr, Suite 305, Newark, Delaware 19713, United States
Locked is part of the Ponuz consumer-apps ecosystem. The contractual operator of the Service is Ponuz, LLC (United States).
2. Scope
This policy covers:
- The Locked app (iOS 15+ / Android API 26+, phone-only)
- Account, training plan, Rocco chat, photos, subscriptions, and cloud sync
- The static marketing landing site (Next.js), with minimal cookies
We do not control Apple’s, Google’s, or other platforms’ practices beyond what they process for us or send to us.
3. What data we collect
We collect what we need to operate the Service. Categories include:
3.1 Onboarding and profile
- Name
- Sex
- Age
- Height and weight
- Goal (muscle / strength / fitness)
- Experience and available equipment
- Days per week and minutes per session
- Units of measure
- Avatar (catalog id; custom photo possible)
- Goal weight and pace (premium preview, if applicable)
- First-rank / bodyrank inputs
- Appearance preference
- Notification permission state
3.2 Product usage
- Workout sessions and sets (weight, reps, timestamps, RIR, etc.)
- Coach plans
- Rocco chat messages (text)
- Chat photos (private storage; e.g.
profile-photosbucket under<user-id>/...) - Food photo for calorie preview (when the feature is available and you use it)
3.3 Account and authentication
- Email and credentials (or tokens) depending on method: email/password (Supabase Auth), Sign in with Apple, Sign in with Google
- Technical session identifiers needed for the
gymapp://login-callbackdeep link
3.4 Purchases and subscriptions
- Subscription / paywall events (Superwall + App Store / Google Play)
- Restore-purchases flows
- Server-side entitlement status (do not rely on client alone)
3.5 Analytics and crash reporting (gated)
- AppsFlyer: attribution only after explicit consent. We do not send your Supabase auth ID. Allowlisted tracking does not include user-content payloads (chats, photos, etc.).
- Sentry: error reporting. PII, screenshots, and view hierarchy are disabled by default; field filters apply.
3.6 What we do not do
We do not sell your personal information. We do not use your chat photos for third-party advertising.
4. How we use data (purposes)
- Create and maintain your account and profile
- Generate and adjust training plans and progress (ranks / bodyrank)
- Operate Locked and related features (including processing messages/photos you send)
- Provide food calorie preview from photo when enabled
- Sync data to the cloud when you are signed in
- Manage subscriptions and entitlements
- Send workout reminders only if you opt into notifications
- Improve stability (Sentry) and measure install/campaign attribution (AppsFlyer) when consented
- Meet legal obligations and respond to rights requests
- Contact you about the Service (e.g. security or material changes)
5. Legal bases / grounds for processing
Depending on where you live, we rely on one or more of the following (non-exhaustive):
- Mexico (LFPDPPP and related rules): consent, the legal relationship / provision of the service, and legal obligations, as applicable. You may exercise ARCO rights (access, rectification, cancellation, opposition) and related rights.
- United States (including CCPA/CPRA if you are a California resident): transparency; we do not “sell” or “share” personal information for cross-context behavioral advertising as described here; rights to know, delete, and non-discrimination, as applicable.
- EEA/UK (if applicable): contract performance, legitimate interests (security, limited improvement), consent (e.g. AppsFlyer / certain notifications), and legal obligation.
If a feature requires consent (AppsFlyer, push notifications), we do not enable it without that consent.
6. Local (guest) profile vs. cloud account
You may keep data only on-device (local profile) and, separately, use a cloud account. We do not silently merge a guest local profile with a signed-in account. Any future migration would require an explicit action from you.
7. Who we share data with (processors)
We share data with providers that help us run the Service, under appropriate contractual instructions:
| Provider | Role |
|---|---|
| Supabase | Auth, database, storage, edge functions |
| Superwall | Paywall / subscription events |
| OpenAI (via Edge Function) | Coach reply generation; API key stays server-side |
| Apple / Google | Store auth and billing |
| AppsFlyer | Attribution after consent |
| Sentry | Errors / stability |
| Vercel | Hosting of the marketing site; cookieless, aggregated web analytics and performance metrics |
We do not list processors we do not use. If we add material new processors, we will update this policy.
We may also disclose information if required by law, to protect rights or safety, or in a corporate transaction (merger, etc.), with reasonable safeguards.
8. International transfers
Your data may be processed on servers outside your country (for example, Supabase or other providers’ infrastructure). Where required by law, we use appropriate mechanisms (contractual clauses, security measures, etc.).
9. Retention
We keep data while your account is active and for as long as needed to:
- Provide the Service and sync
- Meet legal, accounting, or store-dispute obligations
- Resolve claims
When you request deletion (see section 11), we will delete or anonymize personal data linked to your account within a reasonable time, except where retention is legally required (e.g. transaction records required by a store or by law).
Exact periods may vary by category; we are refining operational retention details — privacy contact can provide the current detail.
10. Security (high level)
We apply reasonable technical and organizational measures: authentication, access control, private per-user photo storage, AI keys only on the server, and filters on error reports. No system is 100% secure; please protect your credentials.
11. Your rights and how to exercise them
Depending on your jurisdiction, you may have the right to:
- Access your personal data
- Correct inaccurate data
- Cancel / delete your account and data
- Object to certain processing
- Restrict or port data (where applicable)
- CCPA/CPRA rights (know, delete, correct, opt out of sale/sharing — we do not sell personal information)
- Withdraw consent (AppsFlyer, notifications) without affecting prior lawfulness
What the product already does
Today you can manage much of your profile and preferences in-app, and control system permissions (notifications, camera, etc.). AppsFlyer attribution requires explicit consent. Sentry is configured to minimize PII.
Deletion and export (clear commitment)
If the app does not yet offer a full in-app “delete account” or “export my data” button, you can still request it.
- Email contact@ponuz.com from the address associated with your account (or provide information that lets us verify you).
- Say whether you want deletion, export, or both, and describe your request (ARCO / CCPA / other).
- We will respond within a reasonable time (in Mexico, per LFPDPPP timelines; in California, per CCPA/CPRA; otherwise typically within 30 days or the applicable legal deadline).
- After verifying your identity, we will delete or provide an exportable copy of the personal data we hold, subject to legal exceptions.
We do not claim a button that does not exist yet: the official request channel is the privacy email (and when an in-app flow is ready, it will be announced in the app and/or in an update to this policy).
12. Children
Locked is not directed to children under 13 (or the higher digital age of consent in your country). We do not knowingly collect data from children below that threshold. If you believe a child has provided data, contact us to delete it.
(The final minimum age—e.g. 13 vs. 16—may be adjusted based on entity policy and store requirements.)
13. Notifications
Workout reminders are opt-in. You can turn them off in system settings or, when available, in the app.
14. AppsFlyer and Sentry
- AppsFlyer: only after explicit consent; no Supabase auth ID; no user-content payloads.
- Sentry: technical errors; PII/screenshots/view hierarchy off by default; field filters.
15. Cookies and landing site
The marketing site (joinlocked.com) is hosted on Vercel and may use essential cookies for basic site operation. We use Vercel Web Analytics and Vercel Speed Insights to understand aggregated visits and page performance. These tools do not use cookies and do not identify you personally; they process limited technical data (such as the page visited, referrer, country, device and browser type, and performance timings). If we later enable marketing analytics that require consent, we will provide an appropriate notice or banner and, where required by law, obtain consent.
16. Changes to this policy
We may update this Privacy Policy. The effective date reflects the current version. For material changes, we will try to notify you by reasonable means.
17. Contact
- Privacy: contact@ponuz.com
- Legal: contact@ponuz.com
- Entity: Ponuz, LLC
- Address: 131 Continental Dr, Suite 305, Newark, Delaware 19713, United States
To exercise ARCO or other privacy rights, prefer contact@ponuz.com.
Questions? contact@ponuz.com