Privacy Policy
Effective date: August 12, 2026
We collect only what is necessary to provide and protect this website and to handle your inquiries.
Who we are
This website is operated by Vsevolod Klementjev, Latvia, trading as KleMiX.com ("we", "us"), who is the controller of the personal data described here. You can reach us through the contact form or at the support address shown on our App Store listings. We have not appointed a Data Protection Officer and are not required to.
This policy explains how we process information when you use our site or contact us.
This policy also applies to our iOS apps available on the Apple App Store, as noted below.
What we collect
- Contact form content: the text of your message.
- Contact email (optional): if you choose to provide an email address, we use it only to reply to your message.
- Abuse protection: an hCaptcha token used solely to verify your submission.
- Operational logs: limited technical data (such as IP address and user agent) may be recorded by our servers or infrastructure providers for security and debugging.
- Admin notifications: we may send internal notifications (e.g., email or push) to alert us that a message was received. These notifications may include your message text.
- Purchase records: if you buy a subscription or an in-app purchase in one of our apps, Apple sends us a signed record of that transaction. See Purchases and subscriptions below.
- Ad attribution (some apps): if you installed one of our apps by tapping one of our App Store ads, we record which ad campaign brought you. If you did not, nothing is recorded. See If you arrived from an Apple ad below.
Our iOS apps
For apps listed on the Apple App Store:
- Support email: Our App Store listings display a support/contact email managed by us. Messages sent there are handled under this policy and used solely to address your inquiry.
- On-device processing: Your workouts, health data and app settings stay on your device and in your own iCloud account. We never receive them. Apart from server logs, our servers are involved only for the purchase records Apple sends us, ad attribution, and anything you send us through a support or contact form.
- Permissions: If an app requests access (e.g., HealthKit, Notifications, Location), it is only to provide the app’s features. You can change permissions in iOS Settings at any time.
- Analytics and crash reports: We may use Apple-provided aggregated analytics and crash reports (e.g., App Store Connect, Xcode/Crash logs). These reports are de-identified and used to improve stability and performance.
- Push notifications: If you opt in, your device token may be used to deliver notifications. You can opt out in iOS Settings at any time.
- In-app support: If an app includes a feedback form, it will follow the same minimization approach: only data needed to handle the request is collected, with clear notices.
Purchases and subscriptions
When you buy a subscription or an in-app purchase in one of our apps, the payment is made to Apple. We never see your name, email address, Apple Account, or payment details. Apple then sends our server a signed notification describing the transaction, and we keep it as our own sales record.
Each record contains:
- which app and which product was bought, and the type of event (a purchase, renewal, cancellation, refund, or billing issue), including the reason Apple gives for it;
- the dates of purchase, expiry, and any revocation, the date Apple signed the record, and the date we received it;
- the price, currency, and App Store country or region of the purchase;
- whether the purchase was made directly or received through Family Sharing, and whether an introductory or promotional offer was used;
- the transaction identifiers Apple assigns to the purchase, and the identifier Apple assigns to the notification itself;
- whether the record came from the live App Store or from a test environment such as TestFlight;
- where your install came from one of our ads, the random identifier described in If you arrived from an Apple ad, which links the purchase to the campaign. It is absent otherwise.
We use these records to understand our own sales: how many people buy each product, in which countries, how many subscriptions renew, and how many are refunded. They are not combined with anything you do inside the app, and we do not receive or store your workouts, health data, app usage, device identifiers, advertising identifiers, or location from these records; they are not used to build a profile of you or to target advertising at you.
These records contain no directly identifying information, but the transaction identifier Apple assigns is stable for a given customer and app. We therefore treat them as pseudonymous personal data under the GDPR, including for the retention and rights sections below.
If you arrived from an Apple ad
Some of our apps advertise on the App Store. In app versions that include this feature, the app asks Apple once, shortly after you install it, whether that install came from one of our ads. This uses Apple's AdServices framework. It does not use the advertising identifier (IDFA) and does not ask for App Tracking Transparency permission, because nothing here is ever combined with data from other companies. Apple's answer tells us which of our ads a device came from; it does not tell us who you are.
If the answer is no, no record is created and nothing about your install is stored on our servers.
If the answer is yes, we store the campaign, ad group, keyword and ad that brought you, where in the App Store the ad appeared, whether you tapped it or only saw it, the country or region of the App Store you used, whether it was a first download, a re-download or a pre-order, the date we recorded it, and a randomly generated identifier that exists only to connect that install to a later purchase of the same app. That identifier is created by us, is specific to one app, and is not derived from anything about you or your device. It is shared with Apple: the app attaches it to your purchase, and Apple returns it to us in the purchase record. We do not store the time you clicked the ad or the time you saw it.
The identifier is random, but it exists so that an install can be connected to a purchase. We therefore treat ad-attribution records as pseudonymous personal data under the GDPR, including for the retention and rights sections below.
Purposes and legal bases
- Handle inquiries: process your message to review and address your request. If you provide an email address, we use it only to reply. Legal basis: legitimate interests (Art. 6(1)(f) GDPR).
- Protect the service: prevent spam and abuse (hCaptcha), ensure availability, and maintain security. Legal basis: legitimate interests (Art. 6(1)(f) GDPR).
- Notifications: send push notifications if you opt in. Legal basis: consent (Art. 6(1)(a) GDPR). You can withdraw consent anytime in iOS Settings.
- Understand our own sales: keep a record of purchases, renewals and refunds in our apps so we can see how the products are selling and whether subscriptions renew. Legal basis: legitimate interests (Art. 6(1)(f) GDPR).
- Measure our own advertising: for installs that came from one of our App Store ads, record which campaign brought them so we can tell whether the advertising pays for itself. Legal basis: legitimate interests (Art. 6(1)(f) GDPR). The limits on this processing are set out in If you arrived from an Apple ad. You can object at any time; see Your rights.
- Compliance: comply with legal obligations, as required. Legal basis: legal obligation (Art. 6(1)(c) GDPR).
Cookies and similar technologies
We do not use analytics cookies on this site. hCaptcha may set cookies strictly for bot prevention. See hCaptcha’s Privacy Policy and Terms.
Data retention
We retain contact messages only for the period necessary to review and address your inquiry. If you provide an email address, we use it only to reply to your message and then delete it along with the message when it is no longer needed. Deletion is permanent. The hCaptcha token that accompanied your submission is used to check it and is then discarded. Server access logs, which include IP address and user agent, are retained for a limited period for security and operational purposes.
Ad attribution records are deleted once they are older than 455 days (about 15 months).
Purchase records are deleted once they are older than 760 days (about 25 months).
Apple is the merchant of record and keeps the accounting record of the sale. Our copy exists only for our own sales analysis, so no accounting obligation prevents us from deleting it earlier at your request.
Sharing and processors
- hCaptcha: to protect forms from abuse. See their Privacy Policy and Terms.
- Notification and email delivery: we may use push notification services (e.g., Apple Push Notification service) and email delivery infrastructure to deliver internal alerts and to send replies when you provide an email address.
- Hosting and infrastructure: our hosting, networking, and CDN providers may process limited technical data as part of operating the service.
- Apple: for purchases and App Store advertising, Apple is an independent controller, not our processor. Apple is the merchant of record for your purchase and holds your Apple Account and payment details under its own privacy policy. We receive only the pseudonymous records described above, and we have no access to Apple's own data about you.
- Details: A list of our current processors is available upon request.
We do not sell your personal data. We do not share your email address with third parties for their own marketing or independent purposes.
Source of purchase records
We receive purchase records from Apple, not from you. Because those records contain no name, email address or account, we cannot contact you individually, and we provide this notice instead (Art. 14(5)(b) GDPR).
International transfers
Some processing may occur outside your country. Where applicable, we rely on appropriate safeguards (such as Standard Contractual Clauses) for transfers.
Your rights
Subject to conditions and applicable law, you may have rights to access, rectify, erase, restrict or object to processing, and data portability. Where we rely on your consent, you can withdraw it at any time, without affecting processing already carried out. We do not use your data for automated decision-making or profiling. You can lodge a complaint with the Data State Inspectorate of Latvia (Datu valsts inspekcija) or with the supervisory authority where you live.
If you submit a request, please provide enough information (e.g., the message text and approximate date/time) to help us locate your message.
Purchase and ad-attribution records contain no name, email address or account, so we cannot identify you from them or match them to a request on our own (Art. 11(2) GDPR). The identifier that does work is the transaction identifier Apple assigned to the purchase; Apple Support can look it up for you. Send it to us and we will locate, export or delete the corresponding records, including any ad-attribution record linked to them. We may ask you to confirm the purchase is yours before we act. We answer requests within one month.
Children’s privacy
This site and our apps are not directed to children under 13, and in certain jurisdictions under 16. If you believe we have information about a child, please contact us so we can take appropriate action.
Changes to this policy
We may update this policy from time to time. We will post the updated version on this page with an updated effective date.
Contact
For privacy requests or questions (including GDPR data subject rights), contact us via the website contact form or by emailing the support address shown on our App Store listings. Include details that help us locate your message.
If you email us, we may process emails via our email service provider acting as our processor.