Privacy Policy

Last updated: January 31, 2026

1. Introduction

Streamline Swim LTD ("Streamline", "we", "our", "us") respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use, store, and safeguard your information when you use the Streamline iOS app, our website at streamlineswimapp.com, and any related services (collectively, the "Service").

This policy applies to all users of our Service and is designed to comply with the UK General Data Protection Regulation (UK GDPR), the UK Data Protection Act 2018, and Apple's App Store requirements including HealthKit guidelines.

By using our Service, you acknowledge that you have read and understood this privacy policy. If you do not agree with this policy, please do not use our Service.

2. Data Controller Information

Streamline Swim LTD is the data controller responsible for your personal data. We are registered in England and Wales.

Contact Information:

For any privacy-related inquiries or to exercise your data protection rights, please contact us at the email address above.

3. Apple App Store Compliance

This privacy policy applies to our iOS application available on the Apple App Store. This policy is publicly accessible at streamlineswim.app/privacy and is also accessible within the app. Our data collection and usage practices align with our App Privacy "nutrition label" as displayed on the App Store.

4. What Data We Collect

We collect different types of information depending on how you interact with our Service:

A. Account & Profile Information

  • Email address (for communication purposes only)
  • Account preferences and settings
  • Subscription status and history

B. Fitness & Workout Data

  • Swimming workouts completed through the app
  • Workout metrics (distance, duration, lap count)
  • Progress tracking and achievement data
  • Personal goals and targets
  • Historical workout data

C. HealthKit Data

With your explicit permission, we may read and write the following data types from Apple HealthKit:

  • Swimming distance
  • Swimming stroke count
  • Active energy burned (calories)
  • Workout sessions
  • Heart rate data (from Apple Watch during workouts)

Important: HealthKit data is sent directly from HealthKit to Streamline and is not routed through Apple. You control which data types Streamline can access through your device's Health app settings.

D. Apple Watch Data

If you use Streamline on Apple Watch, we collect:

  • Workout metrics recorded during swim sessions
  • Heart rate data during workouts
  • Motion and activity data related to swimming

E. Device Information

  • Device type and model
  • iOS/watchOS version
  • App version
  • IP address (anonymised for analytics)
  • Device identifiers (for app functionality, not advertising)

F. Usage Data

  • Features used within the app
  • Time spent in the app
  • Navigation patterns and user flows
  • Crash reports and error logs
  • Performance metrics

G. Payment Information

All payments are processed through Apple's App Store. We do not collect or store your credit card details, bank account numbers, or other payment credentials. We receive only:

  • Transaction confirmation from Apple
  • Subscription status and renewal dates
  • Purchase history related to Streamline

H. Location Data

Streamline does not collect or use your location data. We do not request location permissions.

I. Communications

  • Emails you send to our support team
  • Feedback and feature requests
  • Survey responses (if you choose to participate)

5. How We Collect Data

We collect data through the following methods:

  • Directly from you: When you update your preferences, submit feedback, or contact support
  • Automatically through app usage: When you use the app, we automatically collect usage data and device information
  • From HealthKit: Only with your explicit permission granted through iOS system prompts
  • From Apple Watch: During workout sessions when you use our watchOS app
  • From third-party services: Such as Beehiiv for email newsletter subscriptions (website waitlist)

6. Legal Basis for Processing

Under UK GDPR, we process your personal data based on the following legal grounds:

Contract Performance

Processing necessary to provide you with our Service, including:

  • Creating and managing your account
  • Providing the Deck to 1K swimming programme
  • Processing subscriptions and in-app purchases
  • Delivering workout tracking functionality

Consent

We obtain your explicit consent for:

  • Accessing and writing HealthKit data (health data requires explicit consent)
  • Sending marketing communications and newsletters
  • Any processing of special category data (health and fitness information)

You may withdraw consent at any time. For HealthKit, you can revoke access through your device's Settings > Health > Data Access & Devices > Streamline. For marketing, use the unsubscribe link in any email or contact us directly.

Legitimate Interests

We process data for our legitimate business interests, including:

  • App analytics and improvements (using Firebase Analytics)
  • Fraud prevention and security
  • Customer support and issue resolution
  • Business development and service optimisation

We balance these interests against your rights and freedoms.

Legal Obligations

Processing required to comply with legal obligations, such as:

  • Tax and accounting requirements
  • Responding to lawful requests from authorities
  • Fraud prevention obligations

7. How We Use Your Data

We use your personal data for the following purposes:

  • Core Functionality: To provide swimming workout tracking, progress monitoring, and the Deck to 1k programme
  • Personalisation: To customise your experience and workout recommendations based on your progress
  • Account Management: To create, maintain, and secure your account
  • Payment Processing: To manage subscriptions and verify purchase status through Apple
  • Communications: To send transactional emails (account updates, programme milestones) and, with consent, marketing communications
  • Customer Support: To respond to your inquiries and resolve issues
  • App Improvement: To analyse usage patterns and improve features
  • Analytics: To understand how users interact with our Service using Firebase Analytics
  • Marketing: With your consent, to send newsletters and promotional content
  • Security: To detect and prevent fraud, abuse, and security threats
  • Legal Compliance: To comply with applicable laws and regulations

8. Health Data Restrictions

Important: Your health and fitness data is protected by strict limitations.

We collect health and fitness data only with your explicit consent. This data is used solely for providing you with swimming workout tracking and fitness improvement features.

We do NOT:

  • Use your health data for advertising or marketing purposes
  • Use your health data for data mining or data brokerage
  • Sell your health data to third parties under any circumstances
  • Share your health data with advertisers or marketing companies
  • Use your health data for any purpose beyond your health and fitness improvement

This restriction applies to all data collected from HealthKit, Apple Watch, and any health-related information you provide to us.

9. Data Sharing & Third Parties

We may share your data with the following categories of recipients:

Service Providers

  • Vercel (US): Cloud hosting and deployment for our website and backend services. Vercel Privacy Policy
  • Firebase Analytics (Google, US): App analytics to understand usage patterns. Firebase Privacy
  • Beehiiv (US): Email newsletter and waitlist management for website subscribers. Beehiiv Privacy Policy

Apple Services

  • App Store: Payment processing for subscriptions and purchases
  • HealthKit: Health data synchronisation (with your permission)
  • Apple Push Notification service (APNs): Delivering push notifications

Legal Requirements

We may disclose your data if required by law, court order, or governmental authority, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity. We will notify you of any such change and the choices you may have.

With Your Consent

We may share your data with other third parties when you have given us explicit consent to do so.

We do not sell your personal data to third parties.

10. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected:

  • Active Account Data: Retained while your account remains active
  • Workout History: Retained while your account is active, plus 24 months after account deletion (to allow for account recovery)
  • Payment Records: Retained for 7 years to comply with UK tax and accounting requirements
  • Marketing Consent Records: Retained until consent is withdrawn, plus 12 months for compliance records
  • Support Communications: Retained for 24 months from the last communication
  • Analytics Data: Aggregated and anonymised after 26 months (Firebase Analytics default)

When you delete your account, we will delete or anonymise your personal data within 30 days, except where retention is required for legal or legitimate business purposes as described above.

11. Data Security

We implement appropriate technical and organisational measures to protect your personal data:

  • Encryption in Transit: All data transmitted between your device and our servers is encrypted using TLS/SSL
  • Encryption at Rest: Sensitive data is encrypted when stored
  • Secure Authentication: Industry-standard authentication mechanisms protect your account
  • Access Controls: Access to personal data is limited to authorised personnel only
  • Regular Security Updates: We regularly update our systems and review security practices

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours and will inform you without undue delay if the breach is likely to result in a high risk to you.

12. Your Rights Under UK Data Protection Law

Under UK GDPR and the Data Protection Act 2018, you have the following rights:

  • Right of Access: Request a copy of the personal data we hold about you
  • Right to Rectification: Request correction of inaccurate or incomplete data
  • Right to Erasure: Request deletion of your personal data ("right to be forgotten")
  • Right to Restrict Processing: Request that we limit how we use your data
  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Object to processing based on legitimate interests or for direct marketing
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
  • Right to Lodge a Complaint: Complain to the Information Commissioner's Office (ICO)

How to Exercise Your Rights

You can exercise your rights by:

  • Using in-app settings to manage your data and preferences
  • Emailing us at support@streamlineswimapp.com
  • Deleting your account through the app settings

We will respond to your request within 30 days. In complex cases, we may extend this by a further 60 days, but we will inform you if this is necessary.

We will not charge a fee for most requests. However, we may charge a reasonable fee if your request is clearly unfounded or excessive, or refuse to comply with it in those circumstances.

13. HealthKit-Specific Provisions

Streamline integrates with Apple HealthKit to enhance your swimming workout experience. This section explains how we handle HealthKit data:

Why We Request HealthKit Access

We use HealthKit to:

  • Record your swimming workouts to Apple Health
  • Read your workout history for progress tracking
  • Sync swimming metrics (distance, strokes, calories) with your health data
  • Contribute to your Apple Fitness activity rings

HealthKit Data Types

We may request permission to read and/or write the following HealthKit data types:

  • Swimming Distance
  • Swimming Stroke Count
  • Active Energy Burned
  • Workout Sessions
  • Heart Rate (read only, from Apple Watch)

Your Control Over HealthKit Data

  • You choose which data types Streamline can access when prompted by iOS
  • You can change permissions at any time in Settings > Health > Data Access & Devices > Streamline
  • Denying HealthKit access does not prevent you from using the app's core features
  • HealthKit data is transmitted directly from your device to Streamline—it does not pass through Apple's servers

HealthKit Data Storage

HealthKit data accessed by Streamline is processed locally on your device and synchronised with your Streamline account for progress tracking. In compliance with Apple's requirements, we do not store HealthKit data in iCloud or any unencrypted storage.

14. Children's Privacy

Streamline is not intended for children under 13 years of age (or under 16 in the European Economic Area and UK for certain data processing, including health data).

We do not knowingly collect personal data from children under these ages. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at support@streamlineswimapp.com. If we become aware that we have collected personal data from a child without verification of parental consent, we will take steps to delete that information.

15. International Data Transfers

Your personal data may be transferred to and processed in countries outside the United Kingdom, including the United States:

  • Vercel: Our hosting provider operates infrastructure in the United States
  • Firebase Analytics (Google): Analytics data is processed in the United States
  • Beehiiv: Email services are provided from the United States

When we transfer your data internationally, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs): We use EU/UK-approved contractual clauses with our service providers
  • UK-US Data Bridge: Where applicable, transfers may be made under the UK Extension to the EU-US Data Privacy Framework

Note: HealthKit data is processed locally on your device and is not transferred internationally by Streamline.

16. Cookies & Tracking Technologies

Website

Our website (streamlineswimapp.com) uses:

  • Essential cookies: Required for website functionality
  • Analytics cookies: Vercel Analytics to understand website usage (anonymous)

Mobile App

Our iOS app uses:

  • Firebase Analytics: To understand app usage patterns and improve our Service
  • Apple App Analytics: Standard App Store analytics provided by Apple

We do not use advertising tracking or cross-app tracking technologies. We do not participate in ad networks.

Opting Out

You can limit analytics collection by:

  • Enabling "Limit Ad Tracking" in your iOS settings
  • Disabling analytics sharing in iOS Settings > Privacy & Security > Analytics & Improvements

17. Marketing Communications

We only send marketing communications with your explicit consent (opt-in). We will never pre-tick consent boxes.

Types of Communications

  • Transactional: Essential emails about your account, subscription, or programme progress (these do not require consent)
  • Marketing: Newsletters, tips, promotions, and new feature announcements (requires your consent)

Unsubscribing

You can unsubscribe from marketing communications at any time by:

Unsubscribing from marketing will not affect transactional communications necessary for your account.

18. Apple-Specific Privacy Compliance

Our data practices align with Apple's App Store requirements:

  • App Privacy Details: Our App Store listing includes accurate privacy "nutrition labels" describing our data practices
  • App Tracking Transparency: We do not track users across apps or websites owned by other companies for advertising purposes
  • HealthKit Guidelines: We comply with all Apple HealthKit requirements, including not using health data for advertising
  • Privacy Choices: Users can control data sharing through iOS settings and in-app preferences

19. Changes to This Privacy Policy

We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

When we make changes:

  • We will update the "Last updated" date at the top of this policy
  • For significant changes, we will notify you via email and/or an in-app notification
  • We encourage you to review this policy periodically

Your continued use of the Service after any changes indicates your acceptance of the updated policy.

20. Contact Us

If you have any questions about this privacy policy, our data practices, or wish to exercise your data protection rights, please contact us:

Complaints to the Supervisory Authority

If you are not satisfied with our response to your privacy concerns, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection:

  • Information Commissioner's Office
  • Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
  • Phone: 0303 123 1113
  • Website: ico.org.uk

We encourage you to contact us first so we can try to resolve your concerns directly.

21. Governing Law

This privacy policy is governed by the laws of England and Wales. Any disputes relating to this policy shall be subject to the exclusive jurisdiction of the courts of England and Wales.

This policy is subject to the UK General Data Protection Regulation (UK GDPR) and the UK Data Protection Act 2018.

View our Terms of Service