Effective and Last Updated: September 5, 2026
UltasDev ("we," "our," or "us") provides the HeightMax mobile application (the "App"). This Privacy Policy explains what the App stores locally, what it transmits when you use connected features, why that processing occurs, and the choices available to you.
This material update clarifies HeightMax's paid-only service, AI processing, safety reports, local backup feature, platform backups, and age requirement.
Depending on what you enter or use, HeightMax may store the following locally:
Most of this information is held in ordinary local App storage protected by your device and operating-system security. AI chat history is kept only in memory while HeightMax is open and is not written to local storage. The current daily AI anti-abuse token uses platform secure storage. HeightMax does not operate account-based cloud sync.
HeightMax requests camera access only when you open AR height measurement. The AR session is processed on the device; HeightMax does not upload camera images or video through this feature.
You may create a HeightMax backup through the system share sheet. This is a user-initiated, unencrypted JSON file that can contain local onboarding answers, measurements and notes, sleep logs, meals and nutrition estimates, workout and streak history, weekly-update state, language, and unit preferences. It excludes subscriptions and payments, analytics, device notification state, paywall state, AI chat history, and AI quota state.
HeightMax does not upload this export. A destination you choose in the system share sheet may be a third-party or cloud service. Import reads a file you select locally and replaces the supported local HeightMax data sections.
Apple or Android backup and device-transfer services may copy ordinary App data according to your device and platform settings. Those copies are controlled by the platform, not HeightMax, and are not HeightMax cloud sync.
HeightMax uses Firebase Cloud Functions and Google Cloud Vertex AI, using a Gemini model, for AI coaching and optional meal analysis.
HeightMax does not automatically attach your locally stored height measurements, birth date, sex, estimate, sleep history, workout history, or nutrition history to AI Coach requests. If you type such information into a message or meal name, it is included in the request you choose to submit.
Normal prompts and responses are not stored in HeightMax's application database, and shared cross-user AI response caching is disabled. HeightMax holds up to 100 chat messages only in memory for the current App session; they are discarded when the App process ends or when you reset HeightMax. Google may process or retain request data under its applicable terms, security controls, and data-governance documentation.
If you explicitly report an AI response and confirm the action, HeightMax stores the reported response, language, model name, report time, and expiry time for safety review. We do not attach your original question, conversation history, HeightMax account information, or anti-abuse identifier. A reported response may itself repeat information from the conversation. Reports become eligible for deletion after 30 days and are removed by a daily cleanup job.
The server hashes a caller key and stores request counts, a quota category, the App ID, and timestamps. The caller key normally uses the random day-scoped token; if unavailable, the service may fall back to an IP-derived key before hashing. Records become eligible for deletion after eight days and are removed by a daily cleanup job.
Firebase Analytics uses a pseudonymous App-instance identifier. This identifier is a random value generated for the install; it is not linked to your name, email address, or any account, and it is reset when the App is deleted. First-party product analytics is enabled by default on every install and cannot be turned off inside the App; installs that disabled it through a product-improvement choice offered in earlier versions keep that setting. HeightMax records events such as screen and tab opens, onboarding steps, sessions and days since install, paywall and purchase lifecycle actions, product/package/paywall identifiers, transaction identifiers, price, currency, subscription period type, purchase failure codes or messages, workout plan/completion metrics, streak milestones, occurrence and timing of measurements, AI-feature use and report outcomes, notification interactions, and feature completion. HeightMax disables Firebase advertising-storage, advertising-user-data, and advertising-personalization signals and uses the iOS Firebase Analytics configuration without advertising-identifier support.
HeightMax's custom analytics events do not include chat or reported-response text, meal contents, height values, birth date, age, sex, sleep values, exercise names or identifiers, repetitions, or sets. Firebase Crashlytics may process crash reports, stack traces, diagnostic logs, and device, operating-system, and App technical data. Firebase Remote Config and App Check may process App-instance, configuration, integrity, network, and IP metadata.
Apple and Google process payment details, product IDs, receipts, transactions, and subscription status under your App-store account. RevenueCat processes product IDs, receipts, transactions, entitlement and subscription status, a RevenueCat-generated pseudonymous accountless purchaser/App-user identifier, and a Firebase App-instance ID used for subscription analytics. HeightMax disables RevenueCat's automatic attribution-device-identifier collection and does not attach Meta or advertising identifiers. HeightMax does not intentionally attach your height, birth date, measurements, sleep, meals, or chat values, and does not receive your full payment-card details.
If you contact us, we receive your email address, message, and any other information you choose to provide so we can respond and maintain appropriate support records.
Providers may process information in countries other than your own. Applicable provider terms and legally required transfer safeguards govern that processing.
Reset HeightMax does not erase records already held by Apple, Google, Firebase, or RevenueCat under their policies, or files and backups outside the App.
Because HeightMax has no account system and some server records are deliberately pseudonymous, we may not be able to identify a particular record as yours without information from the relevant provider. We may need to verify a request before acting on it.
HeightMax is not intended for children under 13. Do not use the App or submit information if you are under 13. If you believe a child under 13 has provided information through HeightMax, contact us so we can evaluate and respond appropriately. Users under the age of legal majority should use HeightMax only with permission from a parent or legal guardian.
We use reasonable technical and organizational safeguards, including encrypted transport, App integrity checks, restricted database fields, limited retention for AI safety and abuse records, and platform secure storage for the daily AI anti-abuse token. Chat history remains in memory for the current App session. No storage or transmission system can be guaranteed completely secure.
We may update this Privacy Policy as HeightMax, service providers, or legal requirements change. We will update the date above and provide additional notice where required for a material change.
For privacy questions or requests, contact ultasdevelopment@gmail.com or visit www.ultasdev.com.