Privacy Policy

Thaw · Effective date: July 22, 2026 · Last updated: July 22, 2026

This Privacy Policy explains how Thaw ("Thaw", "the app", "we", "us", or "our") handles information in connection with your use of the Thaw iOS application (bundle identifier xyz.bogtsi.thaw). Thaw is a frozen-shoulder recovery companion developed and operated by an individual developer based in Israel (the "Developer").

We built Thaw to be private by design. Thaw has no user accounts, no login, and no backend server operated by us. The data you create in the app stays on your device. The only information leaving your device is handled by the third-party services described below, each under their own privacy policy.

Short version: Your phase setting, daily check-ins (pain and night-pain entries), exercise-session history, range-of-motion test results, streaks, badges, and settings live only on your iPhone, in local on-device storage. We don't run a server and we can't see your data. The app contains no analytics, no ads, and no tracking — its Apple privacy manifest declares that it does not track you. Subscriptions are handled by Apple and RevenueCat, and that is the only data that ever involves a third party. If you choose to turn it on, Thaw can also write your completed sessions to Apple Health as flexibility workouts — write-only, off by default, and it never reads your health data.

1. Who we are & how to contact us

Thaw is operated by a solo developer based in Israel. For any privacy question or request, contact us at support@bogtsi.xyz.

2. Data stored locally on your device

The following information is created and stored only on your device, in local storage inside the app's own sandbox. It is never transmitted to us — we operate no server to receive it — and we cannot access it:

Because this data lives only on your device, it is removed when you delete the app. We provide no cloud backup or sync of this information ourselves; if you use iCloud device backup, your device backup is governed by Apple's policies.

3. Local notifications

If you enable reminders, Thaw schedules local notifications on your device only — session reminders, a daily check-in reminder, and a weekly range-check reminder. They are generated and delivered entirely on-device. We use no push tokens and send no remote push notifications.

4. Exporting your data (CSV & JSON)

Thaw can export everything you have logged as a CSV or JSON file, free for every user. When you tap Export in Settings, the app writes the file to its own temporary storage on your device and hands it to the standard iOS share sheet. Where the file goes next is entirely your choice — Files, Mail, another app — and that destination's handling of the file is governed by whatever app or service you choose. The file is not sent anywhere by us.

5. Apple Health (optional, off by default)

Thaw can optionally write your completed recovery sessions to Apple Health. This is off by default; it does nothing until you turn on "Sync sessions to Apple Health" in Settings and grant permission when iOS asks. When enabled, each session you finish is recorded in the Health app as a flexibility workout lasting the length of that session — that is the only thing Thaw ever writes.

Thaw is write-only: it never reads any data from Apple Health. The app requests a write ("update") permission only and never asks for read access, so it cannot see your steps, heart rate, or any other health information. The workout entries Thaw writes are stored by iOS in your own on-device Health database, under your control in the Health app, and are governed by Apple's privacy protections for Health data — they are not sent to the Developer or to any third party. You can turn the sync off at any time in Settings, and you can review or delete the entries Thaw wrote directly in the Health app.

6. Third-party services that process data

Thaw relies on a small number of third-party services. When you use the app, some of these services may collect or process data directly, under their own privacy policies. We map each one below.

ServiceWhen it appliesWhat it processesPurpose
RevenueCat When you start, restore, or manage a Thaw Premium subscription Purchase and subscription data, keyed to a pseudonymous app-user identifier (we never set a user ID, because there are no accounts). No check-in, session, range-of-motion, or any other health-related data is ever sent to RevenueCat. To process purchases, validate receipts, and unlock Premium features
Apple / App Store Download, updates, and in-app purchases Purchase transactions and standard App Store data handled by Apple. Payment is made to Apple with your Apple ID — the Developer never receives or sees your payment card details. App distribution and payment processing
Expo / EAS App build, distribution, and over-the-air updates Used to build and ship the app and to deliver JavaScript updates; the app sends no personal data, and none of your logged data, to Expo at runtime as part of Thaw's features To build and ship app updates

We use no analytics or crash-reporting SDKs of our own (no Firebase, Sentry, Amplitude, or similar), and Thaw's own code makes no network requests to any server we operate.

Advertising & App Tracking Transparency (ATT)

Thaw contains no advertising and no advertising SDK. The app displays no ads, contains no third-party ad or tracking framework, and does not collect or use the advertising identifier (IDFA). Thaw's Apple privacy manifest declares NSPrivacyTracking: false — the app does not track you, and it never presents Apple's App Tracking Transparency prompt. If advertising were ever introduced in a future version, this Privacy Policy would be updated before it shipped.

7. Third-party privacy policies

The services above process data under their own privacy policies, which we encourage you to review:

8. How we use information

We ourselves do not collect or receive your personal data on any server. Information is used only for the purposes described above: providing app features on-device (guided sessions, the check-in diary, range-of-motion charts, progress comparisons, streaks and badges, reminders) and processing subscriptions. We do not sell your personal data, and we do not use it for advertising or profiling. The phase suggestions Thaw shows are computed on your device from the entries you logged — they never leave it.

9. Data retention

Data stored locally on your device is retained until you uninstall the app. Data processed by third parties (RevenueCat, Apple) is retained according to their respective policies.

10. Your choices & controls

11. Children's privacy

Thaw is not directed to children and is not intended for use by anyone under the age of 13 (or the minimum age of digital consent in your jurisdiction, such as 16 under the GDPR). We do not knowingly collect personal information from children. In line with the U.S. Children's Online Privacy Protection Act (COPPA) and the GDPR's protections for children, if you believe a child has provided personal information through the app, please contact us at support@bogtsi.xyz and we will take appropriate steps.

12. International users

The Developer is based in Israel. Thaw is available through the Apple App Store internationally. The third-party services we use (RevenueCat, Apple, Expo) may process data in various countries, including the United States, in accordance with their own policies and legal safeguards. Your check-ins, session history, and range-of-motion data are not part of any such transfer — they never leave your device. By using the app, you understand that the limited subscription information described above may be processed in countries other than your own.

13. Security

Because your app data stays on your device, its security is tied to your device's own protections (passcode, encryption, biometric lock). Data handled by third-party services is protected under their respective security practices. No method of storage or transmission is 100% secure.

14. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and post the new version at this URL. Material changes will be reflected here; your continued use of the app after an update constitutes acceptance of the revised policy.

15. Contact

Questions about this Privacy Policy or your data? Email support@bogtsi.xyz.