Maxxd

Workout & progress tracker · Privacy & Support

Support

Questions, feedback, or a data request? We're happy to help.

maxxdapp@gmail.com

We aim to respond within a few days.

Reporting a bug

To help us fix it faster, please include: what you were doing, what you expected to happen, what happened instead, your iOS version, and whether it's reproducible. A screenshot or screen recording helps a lot.

Import / export

You can import workout history from another app (CSV export from Strong, Hevy and similar) and export your own data as JSON/CSV from Settings ▸ Data. If an import doesn't look right, email us the file (with any personal data you're comfortable sharing removed) and describe what you expected.

Apple Health

If sync isn't working as expected, check iOS Settings ▸ Health ▸ Data Access & Devices ▸ Maxxd, and Maxxd's own Settings ▸ Health screen. Reconnecting there resolves most sync issues.

Notifications

Rest-timer and reminder notifications can be turned on or off per category in iOS Settings ▸ Notifications ▸ Maxxd, and rest-timer sound specifically in Maxxd's own Settings ▸ Rest timer screen.

Deleting your account

See Account deletion below — this can be done entirely from within the app, no email required.

See our full Privacy Policy below.

Privacy Policy

Last updated: 16 August 2026

Maxxd ("the app", "we") is a workout and progress tracker, developed and operated by Milan Akinci, an individual developer based in the Netherlands. This policy explains what data the app handles, where it is stored, your rights, and your choices.

The short version

Data controller

Milan Akinci, operating Maxxd as an individual developer (Netherlands). Contact for all privacy matters: maxxdapp@gmail.com. As an individual developer we do not maintain a separate public postal address; email is the fastest and most reliable way to reach us.

Training data and optional Cloud Backup

Cloud Backup is off by default. If you actively enable it in Settings ▸ Data & recovery, Maxxd links one private current snapshot to your authenticated account. It can include workouts and sets; routines and training plans; exercises and configurations; body weight and measurements; sleep, water, creatine, manual steps and goals; relevant profile details, training preferences and settings; and relational imported data.

Maxxd replaces the same snapshot when later changes are synchronized; it does not keep automatic daily or unlimited backup history. Turning Cloud Backup off stops new uploads but retains the current snapshot. The separate Delete cloud backup action removes that snapshot and leaves Cloud Backup off. Account deletion also removes the snapshot and backup preference.

Progress photos, your profile photo, exercise setup photos and technique videos remain device-only and are never included in Cloud Backup. Any JSON/CSV backup you export is created locally and only leaves your device if you share it.

Apple Health (optional)

If you connect Apple Health, the app asks for permission separately for reading and writing, and can, once granted, read your step count, body weight and sleep, and write your body weight, completed strength workouts, and sleep. Maxxd does not copy your complete Apple Health database to our servers, and this data is never used for advertising. If an imported body-weight or sleep value is saved as a normal Maxxd log, that resulting record can be included in your optional Cloud Backup just like a value you entered manually. You can revoke Apple Health access in the iOS Health app or Maxxd settings; turning Cloud Backup off is a separate choice.

Notifications

Rest-timer and daily-tracking reminders are scheduled locally on your device by the app itself — no server sends them. The optional community uses a push token only to notify you about reactions and comments on your own content. You can disable notifications per category in iOS Settings ▸ Notifications ▸ Maxxd. We do not use Critical Alerts, and we cannot guarantee a notification sound plays if your device's silent switch, volume, or Focus settings prevent it.

Community (optional, requires an account)

The community is entirely optional; your tracker works fully without an account. If you create one, the following is processed on our backend (Supabase):

Access is enforced by database Row Level Security: other users only see what the rules explicitly allow.

Why we process your data

Performance of the service you asked for (storing/restoring a snapshot after you enable Cloud Backup, syncing community content/chats/friends, scheduling reminders you enabled); consent (Cloud Backup, Apple Health, activity sharing, joining the community, notifications); and a narrow legitimate interest in security, abuse prevention and support. You can withdraw Cloud Backup consent by turning it off.

What we do not do

No advertising, no ad identifiers, no App Tracking Transparency prompt (because we don't track), no third-party analytics or crash-reporting SDKs, and no selling or sharing of personal data.

Third parties

Supabase provides the backend for authentication, the optional community and optional Cloud Backup, hosted in the West EU (Paris) region, over HTTPS/TLS. Apple provides Apple Health (if connected) and push notification delivery. Netlify hosts this page only — it never receives your Maxxd account or training data. We use no analytics, advertising, or crash-reporting sub-processor.

International data transfer

Our backend for authentication, the optional community and optional Cloud Backup is hosted in the West EU (Paris) region (eu-west-3) — your account, community data and enabled backup snapshot are stored on servers within the EU/EEA. This doesn't mean every piece of data touched by the app stays within the EU/EEA in every case: Apple (Apple Health, push delivery, App Store infrastructure) and our email provider (for support requests you send us) are separate services that may process data outside the EU/EEA under their own safeguards, regardless of where our own backend is hosted. We do not control or claim otherwise for those third parties.

Data retention

Local training data stays on your device until you delete it or uninstall the app. One current Cloud Backup snapshot is retained while enabled or until you use Delete cloud backup or delete your account. Community group-chat messages are automatically removed after 30 days, or sooner if you delete your account. Community feed posts are automatically removed after 90 days, or sooner if you delete the post, a moderator removes it, or you delete your account — comments, likes and reactions on a post (and its photo, if any) are removed together with it. Community membership, friend connections and your community profile are kept while your account exists, until you delete the specific connection or your account (not affected by the 30/90-day windows above). Moderation reports and resolved support emails are normally retained for at most 2 years, unless an ongoing dispute or legal obligation requires longer.

Account deletion

You can delete your account at any time from Maxxd's Settings. This removes, on our server: your authentication account, Cloud Backup snapshot and preference, profile, posts, comments, reactions, photos, chats, and any communities you own after required ownership resolution. Local data stays on your phone until you delete it or uninstall. Uninstalling does not delete your server account or an existing cloud backup.

Your rights (GDPR/AVG)

You can ask us to access, correct, or delete your data (most of this you can do yourself, instantly, in the app), restrict or object to processing, receive a portable copy of your data, or withdraw consent at any time — without affecting processing that already happened lawfully. To exercise any of these rights, email maxxdapp@gmail.com. If you're not satisfied with our response, you can lodge a complaint with your national data protection authority — in the Netherlands, the Autoriteit Persoonsgegevens.

Children

Maxxd is not directed at children under 13 and we do not knowingly collect data from them. The community feature contains user-generated content and the app is rated for users aged 12 and up on the App Store, consistent with this policy.

Security

Local training data is protected by iOS Data Protection. Session tokens are stored using the device's secure storage (Keychain). Server-side access to community data is governed by database Row Level Security, and data in transit uses HTTPS/TLS. No method of storage or transmission is 100% secure, but we don't take shortcuts with the above.

Changes

We may update this policy; the "last updated" date reflects the latest version. Material changes will be communicated in the app or on this page.

Contact

Questions or requests (including data access, correction, or deletion): maxxdapp@gmail.com.