Legal

Privacy Policy

Effective date: March 15, 2026  ·  Last updated: July 4, 2026

Contents
  1. Who We Are
  2. Information We Collect
  3. How We Use Your Data
  4. Data Storage & Security
  5. Data Sharing & International Transfers
  6. Your Rights
  7. Data Retention & Deletion
  8. Children's Privacy
  9. Changes to This Policy
  10. Contact

01 Who We Are

ShaRPE ("we", "our", or "us") is an independent fitness tracking application developed and operated by an individual developer. ShaRPE is accessible at sharpeapp.com and related domains.

This Privacy Policy explains how we collect, use, and protect your personal information when you use the ShaRPE application.

02 Information We Collect

We collect only what is necessary to provide the service. We do not collect data beyond what is listed below.

Account Information (via Google Sign-In)

Workout Data (user-generated)

App Preferences

We do not collect location data, biometric data, payment information, device identifiers, or usage analytics beyond what Firebase provides for basic app functionality.

03 How We Use Your Data

Your data is used exclusively for the following purposes:

We do not use your data for advertising, profiling, or any purpose other than operating the core application features.

Legal Basis for Processing

We process your personal data under the following legal bases: (a) Contract performance — processing is necessary to provide you with the ShaRPE service you signed up for; (b) Legitimate interests — to maintain app reliability, prevent abuse, and ensure security; (c) Legal obligation — where required by applicable law. For users in Turkey, processing is carried out in accordance with the Law on Protection of Personal Data (KVKK No. 6698).

04 Data Storage & Security

Your data is stored in two places:

All cloud data is protected by Firebase Security Rules, ensuring only you can read or write your own data. Authentication is handled by Google Firebase Auth with App Check enabled to prevent unauthorized API access.

Data in transit is encrypted via HTTPS/TLS. We do not have access to your Google account password.

05 Data Sharing & International Transfers

We do not sell, rent, or share your personal data with third parties for commercial purposes.

We use the following third-party services to operate the application:

Google Firebase is governed by Google's Privacy Policy. Google reCAPTCHA / App Check is governed by the Google Cloud Data Processing Addendum, under which Google acts as a data processor for data collected on this site.

We may disclose data if required by law or to protect the rights, property, or safety of users.

International Data Transfers & Storage Outside Turkey

ShaRPE is built on Google Firebase, whose infrastructure stores and processes data on servers that may be located outside Turkey (including the United States and EU regions). This means your account and workout data are regularly transferred abroad on an ongoing basis, not as a one-off event.

As of the amendment to Article 9 of the KVKK made by Law No. 7499 (in force since June 1, 2024) and the related Regulation on the Procedures and Principles Regarding the Transfer of Personal Data Abroad, explicit consent can no longer serve as the legal basis for regular, continuing transfers such as ours — it is only available for occasional, non-recurring transfers. As of this writing, the Personal Data Protection Board ("Kurul") has not announced an adequacy decision covering the United States. We therefore rely on appropriate safeguards as our legal basis: our data processing arrangement with Google incorporates the standard contract form announced by the Board, together with Google's own contractual and technical safeguards (encryption in transit and at rest, access controls, and its Cloud Data Processing Addendum). Where a Board-approved standard contract is used, we notify the Board as required by the Regulation.

We are actively evaluating options to minimize cross-border transfer where feasible, including Firebase's regional data location settings. If you would like more detail on the safeguards in place for your data, contact us using the details in Section 10.

06 Your Rights

Regardless of your location, you have the following rights over your data:

For users in the European Economic Area (EEA), you additionally have rights under the GDPR including the right to lodge a complaint with your local supervisory authority.

For users in Turkey, you may exercise the rights listed in Article 11 of the KVKK (including requesting information about, and objecting to, the transfer of your data abroad) by contacting us at the address in Section 10, and you may file a complaint with the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) if your request is not resolved within the statutory period.

07 Data Retention & Deletion

Your data is retained for as long as your account is active. When you delete your account via Settings → Delete Account:

Deletion is processed immediately and cannot be undone. We do not retain backups of deleted accounts.

08 Children's Privacy

ShaRPE is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal data, please contact us and we will delete it promptly.

09 Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via a notice within the application. The "last updated" date at the top of this page will always reflect the most recent revision.

Continued use of ShaRPE after changes are posted constitutes your acceptance of the updated policy.

10 Contact

For any privacy-related questions, requests, or concerns, please contact us at:

ShaRPE
Email: support@sharpeapp.com
Website: www.sharpeapp.com

We aim to respond to all privacy inquiries within 30 days.