Skip to content
2MINSPLANK
Download on the App Store
Back to 2minsplank

Privacy Policy

Effective date: September 13, 2026 · Last updated: October 4, 2026

On this page

  1. Who we are
  2. The short version
  3. What's stored on your device
  4. Camera and pose detection
  5. Apple Screen Time and app blocking
  6. Purchases and subscriptions
  7. Analytics and crash reporting
  8. Identity and returning-user offers
  9. Notifications
  10. Support emails and this website
  11. What we never do
  12. Your rights
  13. Retention and deletion
  14. International processing
  15. Children
  16. Security
  17. Changes to this policy
  18. Contact

Who we are

2minsplank is an iPhone app made and operated by Gokul, an independent developer based in India ("we", "us", "our"). This policy explains what happens to your information when you use the app, and when you visit gokulkrish.com/apps/2minsplank.

If anything here is unclear, or you want to exercise a privacy right, email support@gokulkrish.com.

The short version

2minsplank is built to know as little about you as possible. There is no sign-up form; the app creates a pseudonymous service identity. Your saved workout history, the apps you choose to lock, and your camera frames stay on your device. We use Firebase Analytics to understand app interactions and workout summaries, and Firebase Crashlytics to diagnose crashes. Apple and our subscriptions provider also process information needed to manage subscriptions.
  • No sign-up form. Saved workout history stays local; usage summaries, diagnostics, subscription and offer records are processed remotely.
  • Camera frames are processed on your device and are never recorded or uploaded.
  • No advertising or tracking across apps or websites for advertising.
  • You can erase locally stored app data from Settings, or by deleting the app.

What's stored on your device

The following information is created and kept locally on your iPhone. These saved records remain local. Selected onboarding answers and workout/progress summaries are also sent as analytics events, as explained below:

  • Your name, if you choose to type one during onboarding.
  • Workout records: the date, duration, pause count and form score of each plank session.
  • Progress: streaks, XP, levels, badges and daily goals.
  • Your app selection: which apps you asked to lock — stored as opaque tokens provided by Apple's Screen Time system (see below).
  • Preferences: focus time, reminders and notification settings.
  • Onboarding answers: things like how long you can hold a plank and your goal, used to personalise the app.

Some of this data is shared between the app and its widget/extensions through Apple's App Group container on your device. If you back up your device (iCloud or computer), app data is included in that backup under Apple's privacy policy.

Camera and pose detection

Plank detection needs the camera. With your permission, the app analyses camera frames in real time on your device using MediaPipe, an on-device machine-learning framework. The analysis produces body landmarks and a form score that exist only for the duration of the workout (the final score is saved with your session).

  • Video and camera frames are never recorded, saved, or uploaded.
  • We do not receive your camera feed, images, or pose data.
  • You can revoke camera access at any time in iOS Settings; plank detection stops working without it.

One technical note: if the pose model file isn't bundled with a given install, the app downloads it once from Google Cloud Storage. Like any HTTPS request, that fetch exposes your IP address to Google's infrastructure; no camera data is sent, and the file is a static machine-learning model.

Apple Screen Time and app blocking

2minsplank uses Apple's Screen Time frameworks (FamilyControls, ManagedSettings and DeviceActivity) to block the apps you choose. Apple is designed so that your selections are represented using privacy-preserving tokens:

  • The app-selection picker is provided by Apple; your selection is handed to us as opaque tokens.
  • We do not upload selected-app names, tokens or browsing history. Analytics records selection counts and blocking/unlocking actions.
  • Tokens are stored on your device (and in the App Group container) so the lock survives restarts.
  • You can withdraw Screen Time authorization at any time in iOS Settings.

Purchases and subscriptions

Subscriptions are sold through Apple. Apple processes your payment — we never see your card details, billing address or Apple ID.

We use RevenueCat, Inc. as our subscription management provider. When you view or buy a subscription, RevenueCat processes:

  • a pseudonymous app user ID, linked to the Firebase anonymous-authentication identity for offers (no name, email, phone number or Apple ID);
  • purchase history, receipt data and entitlement status for the app;
  • basic technical information (such as device platform and app version) needed to run the service.

We may also attach onboarding signals (for example, "goal: get stronger") to that pseudonymous profile so we can understand which features lead people to subscribe. RevenueCat acts as our service provider and processes this data under its own privacy policy. These identifiers can link subscription and offer activity without a sign-up form.

Analytics and crash reporting

We use Google Firebase Analytics and Firebase Crashlytics to understand onboarding, workouts, blocking, widgets, offers and subscription interactions and improve app reliability. Analytics includes interaction events, onboarding answers, permission outcomes, selected-app counts, workout outcomes and hold durations, streak milestones, badge unlocks, widget interactions, and basic app and device information. RevenueCat shares subscription lifecycle events with Google Analytics when that integration is enabled, using a pseudonymous app installation identifier. Crashlytics collects crash diagnostics, stack traces, app and device information, installation identifiers, and event names leading up to a crash. Production releases enable Analytics and Crashlytics automatically; the app currently has no dedicated Analytics or Crashlytics opt-out switch. Turning off marketing notifications does not turn off these services.

We do not send your name, camera frames, pose landmarks, your full saved workout history, or identities of selected apps to Firebase. Advertising ID collection and advertising personalization signals are disabled. Google processes this information through Firebase; see Firebase privacy information. Deleting the app or resetting local data does not automatically erase diagnostics or analytics already sent to these services. Contact us with questions about this information or requests concerning your privacy rights.

Identity and returning-user offers

Firebase Authentication creates an anonymous-authentication user ID without asking for an email or password. The app links this pseudonymous identity to RevenueCat and authenticates requests to our offer backend, hosted using Google Cloud Functions and Firestore.

The backend stores customer and campaign identifiers, offer start and expiry times, presentation counts, reminder delivery status, purchase suppression status, recent activity times, marketing notification preference, device time zone and a push destination when notifications are enabled. It checks subscription status through RevenueCat to determine offer eligibility and avoid sending offers to subscribers. Requests also expose standard network information such as IP addresses to the infrastructure providers. These records let us enforce offer deadlines and limit repeated presentations. They do not include your camera feed, selected-app identities or full workout history.

Notifications

Workout reminders and streak alerts are scheduled locally. Marketing and offer notifications use Firebase Cloud Messaging and Apple Push Notification service. These services process installation and delivery identifiers; our offer backend stores a delivery destination, time zone and notification preference when synced.

The app's marketing notification preference defaults to enabled, while notification delivery requires iOS permission. You can disable marketing notifications in app Settings and disable all notifications in iOS Settings. Disabling marketing triggers deregistration and updates the backend; failed network updates may be retried on a later app open. Offer notification opens and changes to the marketing preference are logged as analytics events.

Support emails and this website

If you contact support@gokulkrish.com, we receive your email address and the contents of your message. We use them only to reply and fix problems, and keep the thread only as long as needed for support and record-keeping. Our email provider processes the message on our behalf.

This website is a static site. It does not use cookies, analytics, fonts from third parties, or any third-party scripts — all assets are served from the same origin. Our hosting provider (Cloudflare, Inc.) processes standard technical request data (such as IP address and user agent) to deliver the site and protect it from abuse, under Cloudflare's privacy policy.

What we never do

  • We don't sell or rent your personal information.
  • We don't share it for cross-context behavioural advertising.
  • We don't include advertising SDKs in the app.
  • We don't collect location, contacts, photos, health records or your phone usage.
  • We don't ask for an email address, phone number or social account to use the app.

Your rights

Privacy laws in different regions give you rights over your personal data. Because 2minsplank keeps almost everything on your device, local data controls are available in the app; remote data requests can be made by email:

  • Access and portability: your data is visible in the app's Stats and Settings screens, and lives on your own device.
  • Erasure: use Settings → Reset All Data, or delete the app. Subscription records held by Apple and RevenueCat are kept as required for accounting and legal purposes; email us if you want help with those.
  • Correction and objection: you can change your settings at any time, and email us for anything else.

Under the EU/UK GDPR we rely on: performance of a contract (processing purchases), legitimate interests (support and keeping the service working), and consent where required. Camera, notifications and Screen Time have iOS permission controls; those permissions are separate from Analytics and Crashlytics collection. Under India's Digital Personal Data Protection Act, 2023, we process personal data only for the purposes described here and with your consent where required. California residents have the right to know, delete and opt out of sale/sharing — we do not sell or share personal information as defined by the CCPA/CPRA.

Retention and deletion

Reset All Data clears local workout and progress records. Removing the app removes its local container, but device backups and some system-managed identifiers may remain. Neither action cancels a subscription or automatically deletes remote records held by Firebase, RevenueCat or our offer backend.

Expired offer records are retained to prevent restarting an offer; the current backend does not implement automatic expiry-based deletion. Subscription records are retained for service operation and applicable accounting obligations. Analytics retention depends on the Firebase/Google Analytics property settings. Firebase documents a 90-day retention period for Crashlytics crash data and associated identifiers before removal begins. Support correspondence is retained as needed to resolve your request and meet record-keeping obligations.

Email support@gokulkrish.com to request access, correction or deletion of remote information. We may need information to locate your pseudonymous installation or purchase records and verify the request. We will explain any legal retention requirements or technical limits; deleting local data alone does not identify remote records for us.

International processing

We operate from India. Google/Firebase, Apple and RevenueCat may process service data in the United States and other countries where they operate, subject to their safeguards. Camera frames and selected-app tokens stay on your device. The remote data described above may be processed outside your country under the providers’ applicable safeguards.

Children

2minsplank is not directed to children under 13 (or the minimum age required in your country). We do not knowingly collect personal information from children. If you believe a child has provided information to us — including through app services or support — contact us and we will delete it.

Security

On-device data is protected by iOS's built-in app sandbox and device encryption. Remote service data is handled by Google/Firebase, Apple and RevenueCat using their security measures. No method of storage or transmission is completely secure, but the architecture here means there is deliberately very little for anyone to breach.

Changes to this policy

If we change this policy, we'll update the date at the top of this page. For changes that meaningfully affect what happens to your data, we'll surface a notice in the app before the change takes effect. Continued use after a change means you accept the updated policy.

Contact

Questions, requests, or anything that looks wrong: support@gokulkrish.com.

© 2026 Gokul. All rights reserved. Privacy · Terms · Support