This Privacy Policy explains how Thaw ("Thaw", "the app", "we", "us", or "our") handles information in connection with your use of the Thaw iOS application (bundle identifier xyz.bogtsi.thaw). Thaw is a frozen-shoulder recovery companion developed and operated by an individual developer based in Israel (the "Developer").
We built Thaw to be private by design. Thaw has no user accounts, no login, and no backend server operated by us. The data you create in the app stays on your device. The only information leaving your device is handled by the third-party services described below, each under their own privacy policy.
Thaw is operated by a solo developer based in Israel. For any privacy question or request, contact us at support@bogtsi.xyz.
The following information is created and stored only on your device, in local storage inside the app's own sandbox. It is never transmitted to us — we operate no server to receive it — and we cannot access it:
Because this data lives only on your device, it is removed when you delete the app. We provide no cloud backup or sync of this information ourselves; if you use iCloud device backup, your device backup is governed by Apple's policies.
If you enable reminders, Thaw schedules local notifications on your device only — session reminders, a daily check-in reminder, and a weekly range-check reminder. They are generated and delivered entirely on-device. We use no push tokens and send no remote push notifications.
Thaw can export everything you have logged as a CSV or JSON file, free for every user. When you tap Export in Settings, the app writes the file to its own temporary storage on your device and hands it to the standard iOS share sheet. Where the file goes next is entirely your choice — Files, Mail, another app — and that destination's handling of the file is governed by whatever app or service you choose. The file is not sent anywhere by us.
Thaw can optionally write your completed recovery sessions to Apple Health. This is off by default; it does nothing until you turn on "Sync sessions to Apple Health" in Settings and grant permission when iOS asks. When enabled, each session you finish is recorded in the Health app as a flexibility workout lasting the length of that session — that is the only thing Thaw ever writes.
Thaw is write-only: it never reads any data from Apple Health. The app requests a write ("update") permission only and never asks for read access, so it cannot see your steps, heart rate, or any other health information. The workout entries Thaw writes are stored by iOS in your own on-device Health database, under your control in the Health app, and are governed by Apple's privacy protections for Health data — they are not sent to the Developer or to any third party. You can turn the sync off at any time in Settings, and you can review or delete the entries Thaw wrote directly in the Health app.
Thaw relies on a small number of third-party services. When you use the app, some of these services may collect or process data directly, under their own privacy policies. We map each one below.
| Service | When it applies | What it processes | Purpose |
|---|---|---|---|
| RevenueCat | When you start, restore, or manage a Thaw Premium subscription | Purchase and subscription data, keyed to a pseudonymous app-user identifier (we never set a user ID, because there are no accounts). No check-in, session, range-of-motion, or any other health-related data is ever sent to RevenueCat. | To process purchases, validate receipts, and unlock Premium features |
| Apple / App Store | Download, updates, and in-app purchases | Purchase transactions and standard App Store data handled by Apple. Payment is made to Apple with your Apple ID — the Developer never receives or sees your payment card details. | App distribution and payment processing |
| Expo / EAS | App build, distribution, and over-the-air updates | Used to build and ship the app and to deliver JavaScript updates; the app sends no personal data, and none of your logged data, to Expo at runtime as part of Thaw's features | To build and ship app updates |
We use no analytics or crash-reporting SDKs of our own (no Firebase, Sentry, Amplitude, or similar), and Thaw's own code makes no network requests to any server we operate.
Thaw contains no advertising and no advertising SDK. The app displays no ads, contains no third-party ad or tracking framework, and does not collect or use the advertising identifier (IDFA). Thaw's Apple privacy manifest declares NSPrivacyTracking: false — the app does not track you, and it never presents Apple's App Tracking Transparency prompt. If advertising were ever introduced in a future version, this Privacy Policy would be updated before it shipped.
The services above process data under their own privacy policies, which we encourage you to review:
We ourselves do not collect or receive your personal data on any server. Information is used only for the purposes described above: providing app features on-device (guided sessions, the check-in diary, range-of-motion charts, progress comparisons, streaks and badges, reminders) and processing subscriptions. We do not sell your personal data, and we do not use it for advertising or profiling. The phase suggestions Thaw shows are computed on your device from the entries you logged — they never leave it.
Data stored locally on your device is retained until you uninstall the app. Data processed by third parties (RevenueCat, Apple) is retained according to their respective policies.
Thaw is not directed to children and is not intended for use by anyone under the age of 13 (or the minimum age of digital consent in your jurisdiction, such as 16 under the GDPR). We do not knowingly collect personal information from children. In line with the U.S. Children's Online Privacy Protection Act (COPPA) and the GDPR's protections for children, if you believe a child has provided personal information through the app, please contact us at support@bogtsi.xyz and we will take appropriate steps.
The Developer is based in Israel. Thaw is available through the Apple App Store internationally. The third-party services we use (RevenueCat, Apple, Expo) may process data in various countries, including the United States, in accordance with their own policies and legal safeguards. Your check-ins, session history, and range-of-motion data are not part of any such transfer — they never leave your device. By using the app, you understand that the limited subscription information described above may be processed in countries other than your own.
Because your app data stays on your device, its security is tied to your device's own protections (passcode, encryption, biometric lock). Data handled by third-party services is protected under their respective security practices. No method of storage or transmission is 100% secure.
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and post the new version at this URL. Material changes will be reflected here; your continued use of the app after an update constitutes acceptance of the revised policy.
Questions about this Privacy Policy or your data? Email support@bogtsi.xyz.