HeightMax

Privacy Policy

Effective and Last Updated: September 5, 2026

1. Scope and Overview

UltasDev ("we," "our," or "us") provides the HeightMax mobile application (the "App"). This Privacy Policy explains what the App stores locally, what it transmits when you use connected features, why that processing occurs, and the choices available to you.

Important summary: HeightMax does not require or provide a user account. Most height, wellness, and activity information is stored in App storage on your device. Limited data is transmitted when you invoke AI features and to service providers for first-party analytics, crash diagnostics, subscription management, and App security, as explained below. HeightMax does not include an advertising SDK or use data for cross-company advertising tracking.

This material update clarifies HeightMax's paid-only service, AI processing, safety reports, local backup feature, platform backups, and age requirement.

2. Information Stored on Your Device

Depending on what you enter or use, HeightMax may store the following locally:

  • first name, birth date, country, sex or gender, ethnicity, current and target height, weight, parental heights, shoe size, family answers, sports, puberty and lifestyle answers, and last-year growth;
  • height measurements, dates, and notes;
  • sleep duration and quality, meal names and quantities, nutrition estimates and goals, workouts, completed plan days, streaks, and weekly reports; and
  • language, units, notification choices, and other App preferences.

Most of this information is held in ordinary local App storage protected by your device and operating-system security. AI chat history is kept only in memory while HeightMax is open and is not written to local storage. The current daily AI anti-abuse token uses platform secure storage. HeightMax does not operate account-based cloud sync.

2.1 Camera and AR Measurement

HeightMax requests camera access only when you open AR height measurement. The AR session is processed on the device; HeightMax does not upload camera images or video through this feature.

2.2 Backup and Import

You may create a HeightMax backup through the system share sheet. This is a user-initiated, unencrypted JSON file that can contain local onboarding answers, measurements and notes, sleep logs, meals and nutrition estimates, workout and streak history, weekly-update state, language, and unit preferences. It excludes subscriptions and payments, analytics, device notification state, paywall state, AI chat history, and AI quota state.

HeightMax does not upload this export. A destination you choose in the system share sheet may be a third-party or cloud service. Import reads a file you select locally and replaces the supported local HeightMax data sections.

Apple or Android backup and device-transfer services may copy ordinary App data according to your device and platform settings. Those copies are controlled by the platform, not HeightMax, and are not HeightMax cloud sync.

3. Information Transmitted from the App

3.1 AI Coach and Meal Analysis

HeightMax uses Firebase Cloud Functions and Google Cloud Vertex AI, using a Gemini model, for AI coaching and optional meal analysis.

  • AI Coach: the message you submit, your preferred language, and up to four recent messages from the conversation.
  • Meal Analysis: the meal name, amount, unit, and preferred language you submit.
  • Security and abuse prevention: Firebase App Check integrity and network metadata plus a random day-scoped token that is not derived from an advertising or hardware identifier.

HeightMax does not automatically attach your locally stored height measurements, birth date, sex, estimate, sleep history, workout history, or nutrition history to AI Coach requests. If you type such information into a message or meal name, it is included in the request you choose to submit.

Normal prompts and responses are not stored in HeightMax's application database, and shared cross-user AI response caching is disabled. HeightMax holds up to 100 chat messages only in memory for the current App session; they are discarded when the App process ends or when you reset HeightMax. Google may process or retain request data under its applicable terms, security controls, and data-governance documentation.

3.2 Reporting an AI Response

If you explicitly report an AI response and confirm the action, HeightMax stores the reported response, language, model name, report time, and expiry time for safety review. We do not attach your original question, conversation history, HeightMax account information, or anti-abuse identifier. A reported response may itself repeat information from the conversation. Reports become eligible for deletion after 30 days and are removed by a daily cleanup job.

3.3 AI Abuse-Prevention Records

The server hashes a caller key and stores request counts, a quota category, the App ID, and timestamps. The caller key normally uses the random day-scoped token; if unavailable, the service may fall back to an IP-derived key before hashing. Records become eligible for deletion after eight days and are removed by a daily cleanup job.

3.4 Analytics and Diagnostics

Firebase Analytics uses a pseudonymous App-instance identifier. This identifier is a random value generated for the install; it is not linked to your name, email address, or any account, and it is reset when the App is deleted. First-party product analytics is enabled by default on every install and cannot be turned off inside the App; installs that disabled it through a product-improvement choice offered in earlier versions keep that setting. HeightMax records events such as screen and tab opens, onboarding steps, sessions and days since install, paywall and purchase lifecycle actions, product/package/paywall identifiers, transaction identifiers, price, currency, subscription period type, purchase failure codes or messages, workout plan/completion metrics, streak milestones, occurrence and timing of measurements, AI-feature use and report outcomes, notification interactions, and feature completion. HeightMax disables Firebase advertising-storage, advertising-user-data, and advertising-personalization signals and uses the iOS Firebase Analytics configuration without advertising-identifier support.

HeightMax's custom analytics events do not include chat or reported-response text, meal contents, height values, birth date, age, sex, sleep values, exercise names or identifiers, repetitions, or sets. Firebase Crashlytics may process crash reports, stack traces, diagnostic logs, and device, operating-system, and App technical data. Firebase Remote Config and App Check may process App-instance, configuration, integrity, network, and IP metadata.

3.5 Purchases and Subscriptions

Apple and Google process payment details, product IDs, receipts, transactions, and subscription status under your App-store account. RevenueCat processes product IDs, receipts, transactions, entitlement and subscription status, a RevenueCat-generated pseudonymous accountless purchaser/App-user identifier, and a Firebase App-instance ID used for subscription analytics. HeightMax disables RevenueCat's automatic attribution-device-identifier collection and does not attach Meta or advertising identifiers. HeightMax does not intentionally attach your height, birth date, measurements, sleep, meals, or chat values, and does not receive your full payment-card details.

3.6 Support Communications

If you contact us, we receive your email address, message, and any other information you choose to provide so we can respond and maintain appropriate support records.

4. How We Use Information

  • provide, personalize on-device, maintain, and secure HeightMax;
  • process AI requests and user-confirmed safety reports;
  • manage paid access, purchases, restorations, and subscription status;
  • measure use, diagnose crashes, prevent abuse, and improve reliability;
  • respond to support, safety, and legal requests.

5. Service Providers and Transfers

  • Google Firebase and Google Cloud Vertex AI: cloud functions, Firestore, AI processing, App Check, Remote Config, analytics, crash reporting, abuse records, and confirmed AI-response reports. See Firebase privacy information and the Google Cloud Privacy Notice.
  • RevenueCat: subscription and entitlement management. See the RevenueCat Privacy Policy.
  • Apple and Google: App distribution, purchases, platform backups, device transfer, and permissions under your platform account and settings.

Providers may process information in countries other than your own. Applicable provider terms and legally required transfer safeguards govern that processing.

6. Retention and Deletion

  • Local content: remains until you delete records or use Reset HeightMax. Reset deletes HeightMax-managed local content, the current in-memory AI conversation, and the daily AI token. It does not cancel your subscription and preserves RevenueCat's pseudonymous accountless purchaser identifier so paid access can be restored.
  • Uninstall and platform copies: uninstalling alone may not remove operating-system backups, user-created exports, or platform secure-storage remnants.
  • AI abuse records and reports: become eligible for deletion after eight and 30 days respectively and are removed by daily cleanup.
  • Provider and support records: analytics, diagnostics, purchases, and support data follow operational, legal, and provider retention requirements.

Reset HeightMax does not erase records already held by Apple, Google, Firebase, or RevenueCat under their policies, or files and backups outside the App.

7. Your Choices and Rights

  • view, correct, or delete local records in the App;
  • export or replace supported local data through Backup & Restore;
  • reset HeightMax data, which also clears the current in-memory chat conversation;
  • control camera and notification permissions through operating-system permission prompts and device settings; and
  • contact us to exercise privacy rights available under your local law.

Because HeightMax has no account system and some server records are deliberately pseudonymous, we may not be able to identify a particular record as yours without information from the relevant provider. We may need to verify a request before acting on it.

8. Children

HeightMax is not intended for children under 13. Do not use the App or submit information if you are under 13. If you believe a child under 13 has provided information through HeightMax, contact us so we can evaluate and respond appropriately. Users under the age of legal majority should use HeightMax only with permission from a parent or legal guardian.

9. Security

We use reasonable technical and organizational safeguards, including encrypted transport, App integrity checks, restricted database fields, limited retention for AI safety and abuse records, and platform secure storage for the daily AI anti-abuse token. Chat history remains in memory for the current App session. No storage or transmission system can be guaranteed completely secure.

10. Changes to This Policy

We may update this Privacy Policy as HeightMax, service providers, or legal requirements change. We will update the date above and provide additional notice where required for a material change.

11. Contact Us

For privacy questions or requests, contact ultasdevelopment@gmail.com or visit www.ultasdev.com.

Summary: No HeightMax account is required. Core height and wellness records are stored locally, subject to operating-system backups and user-directed exports. AI input is transmitted only when you invoke an AI feature. HeightMax also uses pseudonymous first-party analytics, diagnostics, subscription, and security services, without an advertising SDK or cross-company advertising tracking. HeightMax does not sell your locally stored height or wellness records.
Back to Home