ALMAREN LABS LLC · PixelFit · almarenlabs.net

PixelFit Global Privacy Policy

Last Updated: August 2026

1. Introduction

ALMAREN LABS LLC ("we", "us", "our") respects your privacy. This Privacy Policy explains how we collect, use, and protect your personal data when you use the PixelFit application and its companion smartwatch application. We have designed this policy to align with global privacy standards, including the GDPR and CCPA, as well as app store requirements.

PixelFit is a step-tracking application in which your physical activity advances a pixel-art character. We collect only what that purpose requires.

2. Information We Collect

Identity & Account Data: Email address, secure encrypted password, and an optional display name.

Health & Activity Data: Daily step counts, and records of activity sessions you start (the type of activity and how long it lasted). Step data is read, with your permission, from the platform on your device:

  • Android: Android Health Connect, or the device's own motion sensors.
  • iOS: the device's built-in motion and fitness sensors, through the operating system's motion activity service. PixelFit does not use Apple HealthKit and reads nothing from the Apple Health app.
  • On a paired Wear OS smartwatch (Android only), the watch's own step counter may also be used.

Optional Body Data: Height and weight. Both are optional, are entered by you, and are used only to make the estimated distance and calorie figures shown in the app more realistic. If you do not enter them, the app tells you the estimate is unavailable rather than inventing a value. They do not affect your character, your progress, or anything else in the app. Because this data is optional and serves a purpose separate from the core Service, we ask for it in a separate, optional consent — a distinct, unticked box on the sign-up screen that you can leave unticked and still create your account. You can also give or withdraw it later in the app's settings.

Heart Rate — displayed, not collected (Android only): If you use the companion Wear OS smartwatch application, it may read your heart rate from the watch's sensor during an activity session and show it to you on screen while that session is running. This reading is not stored on the watch, not sent to your phone, and never transmitted to our servers. It exists only in the watch's memory during the session and is discarded when the session ends. We hold no heart rate data of any kind. The iOS version of PixelFit does not read heart rate at all.

Game Progress Data: Experience points, level, tier, in-game coins, activity statistics, daily streak, completed quests, and which characters and items you own. We also keep a short in-app event history — for example that a character was unlocked or an evolution happened, and when — so that progress can be recalculated correctly and so that rewards are not paid twice.

Preferences: Daily step goal, notification settings and reminder time, theme, and your time zone offset (which we need so that a "day" and the rewards tied to it match your local day rather than ours). Your language choice is not sent to us; it is stored on your device.

Consent Records: When you accept our documents or give a consent, we record it as an event so that we can show what was agreed, and when. Each record holds the document type, the version of the text you were shown, whether it was granted or withdrawn, the language of that text, the app version, and the time. It also holds a one-way hash of the IP address the request came from — we deliberately do not store the address itself; the hash exists only to show the record came from a real request and cannot be turned back into an address. These records exist so that what you agreed to, and when, can be shown. They are kept for as long as the account exists, and they are deleted together with the account — we do not keep a consent record for an account that no longer exists.

Technical Data: Standard server connection logs, and security records such as hashed session refresh tokens and hashed password-reset tokens. Limited diagnostic or crash-related information may be collected by your device or app distribution platform (Google on Android, Apple on iOS) as part of normal store or operating-system services.

What we do not collect: PixelFit contains no advertising, no analytics SDK, no crash-reporting SDK, and no in-app purchases. We do not collect your gender, your age or date of birth, your precise location, your contacts, your photos, or any payment information. We do not use tracking or advertising identifiers.

3. How We Use Your Data

Service Provision: To create and secure your account, store your progress, and keep your character and statistics in sync between your phone and your watch.

Activity Tracking and Game Progression: To count your daily steps against the goal you set, to award experience, coins, streaks, and quest completions, and to evolve your character accordingly.

Estimated Figures: To calculate approximate distance and calories from your step count and, if you provided them, your height and weight. These are motivational estimates, not measurements.

Reminders: To show the notifications you enabled — for example a daily goal reminder. These are generated on your device; we do not operate a push notification service and hold no push token.

Communication: To send necessary transactional emails, such as a password reset.

Integrity: To detect and reverse progress obtained through falsified activity data, automation, or exploitation of a defect.

We do not sell or share your personal data, and we do not use it for advertising or profiling of any kind.

Legal Bases (EEA / UK)

Where the GDPR applies, we rely on the following legal bases:

  • Explicit consent (Art. 9(2)(a)) — health data. Your step count and your activity sessions are data concerning health. We process them only on the basis of the explicit consent you give when you create your account. This consent is required to use PixelFit, because counting your activity is the entire function of the Service; if you do not wish to give it, please do not create an account.
  • Separate explicit consent — optional body data. Your height and weight are processed only on the basis of a separate, optional consent, offered as its own unticked box at sign-up and available in settings afterwards. You can withdraw it at any time; the rest of the Service continues to work.
  • Performance of a contract (Art. 6(1)(b)). Creating and securing your account, storing your progress, and syncing it between your phone and your watch.
  • Legitimate interests (Art. 6(1)(f)). Sending necessary transactional email, keeping the platform secure, detecting and reversing progress obtained through falsified data or automation, and keeping consent records so that the consents you gave can be evidenced.

Withdrawing your consent does not affect the lawfulness of processing carried out before the withdrawal. Because the health-data consent is what the Service runs on, withdrawing it means closing your account — see section 6.

4. The Companion Smartwatch Application (Android only)

The companion watch application exists only for Wear OS watches paired with the Android version of PixelFit. There is no PixelFit watch application on iOS, and nothing in this section applies to iOS users.

The watch application never communicates with our servers. It has no account credentials and no network session of its own.

Data flows between your phone and your watch over the operating system's own device-to-device channel, which links the two only when the same application, signed by the same developer, is installed on both. Your phone sends the watch your character, level, step count, and statistics so it can display them; the watch sends your phone the activity sessions you started from your wrist so they can be counted. The watch keeps the last state it received so that it still shows something useful when it is out of range of your phone.

Heart rate is the exception described in section 2: it is displayed on the watch and never leaves it.

5. Data Storage and Third-Party Subprocessors

Your account data and progress are hosted on cloud servers located in Sweden (European Union). We use trusted third-party providers for a small number of functions:

  • Cloud hosting and database management.
  • Transactional email infrastructure (used for password reset messages).
  • App store platforms — Google LLC (Google Play) and Apple Inc. (App Store) — for distribution and the basic services they provide.

There are no advertising, analytics, or profiling subprocessors, because the app contains no such components.

6. Your Privacy Rights

Depending on your location (for example the EU or California), you may have rights regarding your data:

Access & Portability: You may request a copy of your data by contacting us at the email below; we will respond within a reasonable time.

Erasure: You can permanently delete your account and all associated personal data using the in-app Settings → Account → Delete Account feature. Deletion is confirmed with your password and takes effect immediately. See also: https://www.almarenlabs.net/pixelfit/account-deletion

Note that Deactivate Account, offered on the same screen, is a different action: it closes the account but keeps your data (see section 8). Only deletion erases it.

Correction: You can update your display name, body data, goal, and preferences directly in the app at any time.

Withdrawing consent for optional body data: Clear your height and weight in the app. Nothing else in the Service depends on them.

Withdrawing consent for health data: Because the Service exists to count your activity, the way to stop this processing is to delete your account, which erases the data along with it.

Withdrawing device permissions: You can revoke the app's access to activity data at any time in your device settings — on Android, Settings → Health Connect → App permissions; on iOS, Settings → Privacy & Security → Motion & Fitness → PixelFit — or in the app's own permission screen. Revoking access stops new step data from being read; it does not delete data already recorded in your account. To remove that as well, delete your account.

EEA / UK (GDPR): You may have rights including access, rectification, erasure, restriction, objection, and data portability. Contact info@almarenlabs.net. You may also lodge a complaint with your local supervisory authority.

California (CCPA/CPRA): You may have additional rights, including the right to request information about our practices. We do not sell personal information and we do not share it for cross-context behavioral advertising, because PixelFit displays no advertising.

7. Children

The Service is intended for users aged 16 and over. We set the limit at 16 because PixelFit relies on your explicit consent to process health data, and in several jurisdictions a person under 16 cannot give that consent alone.

We do not collect a date of birth and therefore cannot verify anyone's age; we rely on the user's own statement. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has provided us with personal data, contact info@almarenlabs.net and we will delete the account and the data.

8. Data Retention and Security

We retain your data for as long as your account is active. When you delete your account, your personal data — including your character progress, coins, activity history, and body data — is purged from our active databases and cannot be restored.

Deactivation does not withdraw your consent. Deactivating closes the account but leaves your consent in place, and your data continues to be held on that basis so the account can be restored. If your intention is to withdraw consent and stop the processing, deactivation is not the action to use — delete your account instead, or write to info@almarenlabs.net.

Deactivated accounts. If you deactivate your account instead of deleting it, we keep your account and its data so that the account can be restored at your request. We do not automatically delete deactivated accounts, because deactivation is chosen precisely by people who intend to come back; the data stays until you ask us to delete it, or you delete the account yourself. If you want it gone, use Delete Account rather than deactivation, or write to info@almarenlabs.net from the registered address and we will delete it for you.

We use encryption for data in transit, store passwords using a strong one-way hashing algorithm, and never store session refresh tokens or password-reset tokens in a readable form.

9. Contact Us

If you have questions about your privacy or wish to exercise your rights, please contact us at:

Email: info@almarenlabs.net
Address: ALMAREN LABS LLC, 8 The Green, STE 23103, Dover, DE 19901, USA

Last updated: August 2026