Privacy Policy for Surge

Effective date: 11 August 2026
Last updated: 11 August 2026
Applies to: the Surge mobile application, Android package and iOS bundle identifier com.shmooneydev.surge
Canonical address of this Policy: https://surge.shmooneydev.com/privacy

The short version. Surge has no account, no login, and no server of our own. Your workouts, presets, history, achievements, and settings stay on your device. Analytics and crash reporting are switched off until you turn them on, and you can turn them back off at any time in Settings → Privacy. The free version shows ads, which means some pseudonymous technical information — such as your IP address and an advertising identifier — is processed by advertising providers. Health data that Surge writes to Apple Health or Health Connect is never sent to us, to analytics providers, or to advertisers. We do not sell your data for money.

1. Who we are and what this Policy covers

This Privacy Policy explains how Mykhailo Moskalenko, an independent developer and sole proprietor based in Ukraine ("we", "us", "our"), handles information in connection with the Surge mobile application.

"Surge" or the "App" means the mobile application published by Mykhailo Moskalenko under the Android package name and iOS bundle identifier com.shmooneydev.surge, regardless of the name shown in the store listing. The App may be listed as "Surge: Boxing Tabata Timer" or under a similar name, and the listing title may change without changing the application covered by this Policy.

This Policy applies to the Android version distributed through Google Play, the iOS version distributed through the Apple App Store, and this website. It does not apply to the separate services of Apple, Google, or any advertiser whose ad you tap, each of which is governed by its own policy.

2. No account, no Surge server

Surge does not require or offer a user account. We do not ask for your name, email address, telephone number, password, or profile information in order to use the App. We do not operate an application backend, user database, or cloud synchronisation service for the version of Surge covered by this Policy.

This has a practical consequence for privacy requests, and we would rather state it plainly than surprise you later: because we hold no account record, we usually cannot connect an email you send us to a specific pseudonymous record held by an analytics, advertising, or subscription provider unless you give us a technical identifier that we can use to find it. Section 12 explains how this works.

3. What Surge never collects

Regardless of any setting or consent choice, the App does not collect:

4. Information kept on your device

Workouts, presets, and settings

Workout history, timer settings, presets, achievements, consent choices, and related preferences are stored in the App's own storage on your device. We do not receive this information. It remains until you delete it in the App — Settings → Reset all data, or the more limited Settings → Reset settings — or until you clear the App's storage or uninstall the App.

Device backups

Your operating system may include some of the App's local data in an iCloud or Android device backup, depending on your device and your backup settings. Those backups are created and controlled by Apple or Google under their own policies, not by us, and we cannot read them.

Photos

If you choose to save an achievement image, Surge requests only the access needed to add that image to your photo library — on iOS, add-only access. The App does not read your library, upload your photos, scan them for analytics or advertising, or send photo content to us or to any service provider. You can refuse photo access and continue using the App; only that one feature is affected.

Notifications

Surge can schedule local notifications on your device for workout reminders, achievement unlocks, and similar prompts. Local notifications are created and delivered by your device and do not involve a server of ours. You can turn them off inside the App or in your device settings.

Running in the background

An active workout can continue to run while Surge is in the background or your screen is locked, so a round is not lost when you switch apps. Background operation exists only to keep the timer and its sounds accurate. It is not used to collect location, health information, or any other personal information while you are not looking.

5. Apple Health and Health Connect

Paid features may allow you to send completed workout information to Apple Health through HealthKit on iOS, or to Health Connect on Android. With your explicit permission, Surge may write the workout type, start and end time, duration, and active energy burned to the health service you selected.

Surge writes only. It never reads. We do not request or receive read access to Apple Health or Health Connect, we do not receive the records that are written, and we do not transmit health or fitness information to Amplitude, Sentry, RevenueCat, Google, AppLovin, any advertising partner, or any server of ours. We do not use health or fitness information for advertising, marketing, profiling, credit, insurance, employment decisions, or resale, and we do not permit anyone else to do so with data obtained through Surge.

Health synchronisation is optional. You can refuse permission, or withdraw it later, and continue to use every timing feature of the App. You can review, manage, or delete individual records and permissions in Apple Health, in Health Connect, or in your system privacy settings. Deleting Surge's local data — or uninstalling the App — does not automatically delete a record you previously chose to write to a health service; that record lives in the health service and must be removed there.

6. Information sent to service providers

The App includes software development kits (SDKs) supplied by third parties. When one of them is active, it may send pseudonymous technical information directly from your device to that provider. Pseudonymous means the information is tied to a device or installation identifier rather than to your real-world identity, which we do not know.

Analytics and crash reporting are off by default. Neither Amplitude nor Sentry starts until you switch it on, either on the consent screen shown at first launch or later in Settings → Privacy. If you decline both, neither SDK is initialised and neither sends anything. Declining does not restrict any App feature.

Category What may be sent Why, and who receives it
Usage analytics
only if you opt in
App launches and session counts, screens viewed, features used, whether a workout was started or completed, which workout format was chosen, settings toggled, upgrade-screen events, App version, device model, operating system version, language, a pseudonymous device or installation identifier, IP address, and the approximate location inferred from that IP address. Understanding which features are used and where people get stuck, so the App can be improved. Received by Amplitude. Surge does not enable Amplitude Session Replay, does not set a user ID, and does not send preset names, workout parameters, workout content, or health information.
Crash diagnostics
only if you opt in
Stack traces and error messages, the screen you were on and the last few actions taken in the App, App version, build number, operating system version, device model, and basic device state such as free memory. Finding and fixing crashes. Received by Sentry. Surge does not enable Sentry Session Replay, automatic screenshots, or user-content attachments.
Advertising
free version only
IP address and the approximate location inferred from it, device and App characteristics, an advertising identifier such as the IDFA or Google Advertising ID where permitted, App Set ID or vendor identifier, your consent and tracking status, which ads were requested and shown, interactions with them, and technical delivery diagnostics. Requesting, filling, displaying, capping, measuring, and securing ads, and preventing ad fraud. Received by AppLovin as the mediation layer and by the demand partners it calls, including Google AdMob. Section 7 explains your choices.
Purchases and subscriptions An anonymous App user identifier generated by the SDK, the product purchased, entitlement and subscription status, purchase and renewal history, the Apple receipt or Google purchase token, device type, and operating system. Validating purchases, unlocking and restoring paid features, and preventing purchase fraud. Received by RevenueCat, and by Apple or Google as the payment processor. We never receive your card number or bank details.

An IP address is sent as an unavoidable part of any internet request; it is how a response reaches your device. Providers may use it to derive an approximate location, typically at city or regional level, and for fraud prevention and security. Surge does not request GPS or precise location from your device.

7. Advertising, tracking, and your choices

The free version of Surge shows ads, delivered through AppLovin MAX with Google AdMob and other demand partners bidding for each impression. Depending on your region, your choices, and your platform settings, ads may be personalised, contextual, non-personalised, or limited. A Premium subscription removes ads.

In the EEA, the UK, and Switzerland, Surge shows a consent interface before any consent-based advertising processing begins, and passes your choices to advertising providers. You can reopen it at any time from Settings → Privacy.

On iOS, Surge shows a short explanation and then Apple's App Tracking Transparency prompt before accessing the IDFA or permitting tracking across apps and websites. If you decline, the App works exactly as before; only ad relevance changes. You can change this decision at any time in Settings → Privacy & Security → Tracking.

On Android, you can delete or reset your advertising ID in your device's privacy or ads settings. Deleting it stops apps from receiving that identifier.

Advertising providers may use the information listed in section 6 for measurement and attribution — for example, to determine whether an ad led to an install. Apple's SKAdNetwork and Google's install referrer perform this measurement in a form designed to limit what any single party learns about you.

Declining tracking, declining personalised ads, or declining analytics never restricts the timer, presets, history, achievements, or any other feature of the App.

8. Purchases and subscriptions

Purchases on Android are processed by Google Play and purchases on iOS are processed by the Apple App Store, each under its own privacy policy and payment terms. RevenueCat assists us with receipt validation, entitlement management, restoring purchases across reinstalls, and aggregate subscription reporting. We receive subscription and entitlement information — for example, whether a device currently holds Premium — but never your full card, bank, or billing details.

Manage, change, or cancel a subscription in your Google Play or Apple App Store account settings. Refunds are handled by Apple and Google under their published policies.

9. Service providers and other recipients

These are the parties that may receive information in connection with the App:

Amplitude, Sentry, and RevenueCat act as processors on our behalf. Advertising providers and store operators act as independent controllers for part of their processing, meaning they determine some purposes themselves and answer for that processing under their own policies.

We may also disclose information where reasonably necessary to comply with law, respond to a lawful request from a public authority, protect users or the public, investigate fraud, abuse, or a security incident, establish or defend legal claims, or in connection with a sale or transfer of the App, in which case this Policy continues to apply until the recipient publishes its own and gives notice.

We do not sell personal information for money, and we never will. Disclosures to advertising partners for personalised advertising or advertising measurement may nonetheless meet the broad definition of a "sale", "sharing", or "targeted advertising" used by some privacy laws. Sections 7 and 13 explain how to opt out.

10. Legal bases (EEA, UK, Switzerland)

Where the GDPR, UK GDPR, or Swiss FADP applies, we rely on the following legal bases:

Processing Legal basis
Usage analytics (Amplitude) Consent — Article 6(1)(a). Given on the consent screen or in Settings → Privacy, withdrawable at any time.
Crash reporting (Sentry) Consent — Article 6(1)(a), collected separately from analytics.
Advertising, including personalisation and measurement Consent — Article 6(1)(a), collected through the in-App consent interface and, on iOS, through App Tracking Transparency.
Storing or reading information on your device for the purposes above Consent, as required by national laws implementing Article 5(3) of the ePrivacy Directive.
Writing workouts to Apple Health or Health Connect Explicit consent — Articles 6(1)(a) and 9(2)(a), given through the system permission prompt and revocable in your health settings.
Providing and restoring subscriptions and paid features Performance of a contract — Article 6(1)(b).
Detecting fraud, abuse, and security incidents; keeping the App working Legitimate interests — Article 6(1)(f), in operating a secure and functioning App, balanced against your rights.
Responding to privacy requests and keeping records of them Legal obligation — Article 6(1)(c).

Withdrawing consent is as easy as giving it and does not affect the lawfulness of processing carried out before withdrawal. We do not use your data for automated decision-making that produces legal or similarly significant effects.

11. How long information is kept

12. Your rights and how to use them

Depending on where you live, you may have the right to access the information held about you, correct it, delete it, restrict or object to its processing, receive it in a portable form, withdraw consent, and opt out of targeted advertising. To exercise a right, email surge.app.mail@gmail.com with a short description of what you want. We do not charge for this, and using a privacy right will never degrade the App for you.

We acknowledge requests as soon as we reasonably can and respond within one month, or within 45 days where United States state law applies. Where a request is complex or you have made several, we may extend that period as the applicable law permits and will tell you why.

The identification problem, stated honestly. Surge has no account, so an email address alone tells us nothing about which pseudonymous record is yours. To locate data at a provider we generally need a technical identifier — for example the identifier shown in Settings → Privacy, an advertising identifier, or a purchase receipt. We will ask for the minimum needed and will never ask you to prove your identity with a document when a technical identifier will do. If no identifier can be produced, we will say so rather than pretend a deletion has occurred.

You can also act directly, without contacting us:

If you are in the EEA, the UK, or Switzerland and you believe we have handled your data improperly, we would like the chance to fix it first — but you are entitled to complain to your local supervisory authority regardless, and you do not need our agreement to do so.

13. United States state privacy rights

If you live in California, Colorado, Connecticut, Virginia, Texas, Oregon, Montana, or another state with a comprehensive privacy law, this section applies to you in addition to the rest of this Policy. The table sets out the categories used by those laws.

Category Collected? Purpose Disclosed to
Identifiers — device identifier, advertising identifier, IP address Yes, from your device Analytics, advertising, subscription management, security Analytics, advertising, and subscription providers
Internet or network activity — App interactions, screens viewed, ad interactions, diagnostics Yes, from your device Analytics, advertising, crash fixing Analytics, crash reporting, and advertising providers
Commercial information — purchase and subscription history Yes, from Apple, Google, and the App Providing and restoring paid features, fraud prevention RevenueCat, Apple, Google
Geolocation — approximate, inferred from IP address Yes, inferred Analytics, ad delivery, fraud prevention Analytics and advertising providers
Precise geolocation, biometric information, health information transmitted to us, contacts, communications, government identifiers, financial account details, sensitive personal information No

Sale, sharing, and targeted advertising. We do not sell personal information for money. We do disclose identifiers and App activity to advertising partners for personalised advertising and its measurement, which several state laws treat as "sharing", a "sale", or "targeted advertising". To opt out, turn off personalised advertising in Settings → Privacy, decline the App Tracking Transparency prompt on iOS, or delete your advertising ID on Android. We honour a Global Privacy Control signal where it reaches us in a form we can technically recognise. We do not use or disclose sensitive personal information for purposes requiring a right to limit.

Minors. We do not knowingly sell or share the personal information of anyone under 16.

Rights. You may request to know what we hold, obtain a copy, correct it, or delete it, and you may opt out of targeted advertising, using the contact details in section 19. An authorised agent may act for you with written permission that we may verify. We will not discriminate against you for exercising a right; the App does not offer a paid tier in exchange for data, and Premium simply removes ads.

Appeals. If we refuse a request, you may appeal by replying to our decision with the word "Appeal". We will review it and respond in writing within 45 days with our reasons. If we deny the appeal, you may complain to your state's Attorney General.

14. Children and teenagers

Surge is intended for people aged 13 and over. It is not directed to children, is not offered in a kids category, and includes no child-oriented content. We do not knowingly collect personal information from a child under 13.

In countries where the minimum age for consenting to information-society services is higher than 13 — it ranges up to 16 in parts of the EEA — a parent or guardian should make or authorise the consent choices described in this Policy on behalf of anyone below that age.

If you believe a child has provided personal information through the App, contact us at surge.app.mail@gmail.com and we will take reasonable steps to delete it and to instruct our providers to do the same.

15. International transfers

We are based in Ukraine, and our service providers process information in the United States, the European Economic Area, and other countries. Where information originating in the EEA, the UK, or Switzerland is transferred to a country that has not received an adequacy decision — including Ukraine, from where we access provider dashboards — the transfer relies on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another safeguard recognised under applicable law, together with the additional measures the recipient applies.

You may ask us for information about the safeguards used for a specific provider by writing to the address in section 19.

16. Security

Information sent by the App to a service provider travels over encrypted connections using HTTPS and TLS. Information on your device is protected by your operating system's own storage protections and by your device lock. We keep collection to what is described here, which is itself a security measure: data that is never collected cannot leak.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a breach affecting your information occurs and the law requires notification, we will notify the competent authority and, where required, affected users.

17. This website

This page is served as a static document. It sets no cookies, runs no analytics, embeds no third-party fonts, scripts, or trackers, and asks for nothing from you. Our hosting provider processes standard server request information, including IP addresses, for delivery, caching, and protection against attacks.

18. Changes to this Policy

We will update this Policy when the App, our providers, or the law changes. The current version always lives at https://surge.shmooneydev.com/privacy. When a change materially affects how your information is handled, we will update the effective date, show a notice in the App, and — where the change concerns processing based on consent — ask for your consent again rather than treating silence as agreement.

VersionDateSummary of changes
1.011 August 2026First published version.

19. How to contact us

Controller: Mykhailo Moskalenko, independent developer and sole proprietor, Ukraine
Email for all privacy matters: surge.app.mail@gmail.com
Website: https://shmooneydev.com
Postal address: available on request to the email address above.

We aim to answer every privacy email from a real person, not a template.