Plain-language policy
Privacy, without the fog.
Last updated 29 July 2026 · Applies to Two Waters Fitness 1.0.1, build 2.
Who this policy covers
Two Waters Fitness is developed by Twowaters. This policy covers the pre-release iPhone, Apple Watch, WidgetKit and Watch complication app.
Account information
The current build requires Sign in with Apple. Apple supplies a stable app-specific user identifier and may supply a name and email address on first authorisation. The app stores the identifier and returned profile details in the iOS Keychain. Apple may provide a private relay address when Hide My Email is used.
Sign in with Apple does not grant Apple Health access. Health permissions are requested separately, and the user chooses whether to grant each category.
Information the app uses
With explicit permission, Two Waters Fitness reads selected Apple Health activity, workout, nutrition, sleep, heart-rate, weight and recovery categories. The requested categories are listed in the app’s Health Access screen.
Only after an explicit log action, the app can write dietary energy, protein, carbohydrate, fat, water and alcoholic beverage count where the corresponding Apple Health permission has been granted.
Users may enter preferences, workout completions, difficulty feedback, injuries, climbing sessions and routes, meals, notes, private photos, medication events and optional quit or reduction records. These support the calendar, streak, guidance, history and repeat features.
Shared climbing directory
The pre-release shared directory is designed around Apple’s public CloudKit database. It can store climbing sites, sections, routes, contributor labels, optional climbing-location coordinates, licensed images, moderation reports and explicitly opted-in leaderboard ascents.
Personal Apple Health data, private attempts, private sends, private notes, comments, meal photos and non-leaderboard logs are not stored in the public CloudKit directory.
Browsing public records does not require iCloud sign-in. Adding or editing a record requires an iCloud account so CloudKit can identify its owner. CloudKit Production activation remains a release gate and is not described here as a live service.
Shared photos and moderation
A contributor can publish climbing-site, section, route-reference and topo images after confirming they have permission. The app decodes, resizes and re-encodes selected images to remove source metadata, then creates thumbnail and full-screen copies for the public CloudKit database.
Other users can report a shared image as Wrong route, Misleading angle or Inappropriate picture. A report hides the image pending administrator review. An inappropriate-image report also hides the uploader’s other shared images and pauses further uploads in the unmodified app until the flag is cleared.
Location permission is requested only for precise climbing-location features. StoreKit processes membership transactions through Apple; the app does not receive payment-card details.
Final user blocking and the operational moderation service are still being completed before public release.
Storage and Keychain
Personal preferences and records are primarily stored in the app’s private local container. Private photos are copied into private app storage. Apple account details and the optional InfluxDB API token are stored in Keychain. Two Waters Fitness does not store personal health information in CloudKit.
Local pet or family coaching photos may be attached to on-device reminders only when the user enables that feature. They are not uploaded to Twowaters.
Optional InfluxDB export
If enabled, supported Apple Health and app records are sent directly to the URL, organisation and database configured by the user. Twowaters does not provide or operate that server and does not receive its contents. The server owner controls security, access, retention and deletion.
Export can include shopping-list state, workout and meal events, climbing metadata, quit or reduction entries, medication events, water and alcohol entries and progression awards. Medication names and user-entered dose labels may be sensitive.
Apple Maps, Wikimedia and external links
Indoor climbing-centre searches can send an entered venue name to Apple Maps. The app may also query Wikimedia Commons for an exact-match image with a reusable licence. Returned Wikimedia images retain their source and attribution. Apple and Wikimedia process those requests under their own policies.
Exercise, safety and company links open external websites in Safari, which process requests under their own privacy policies.
Advertising and tracking
The app contains no advertising, cross-app tracking or third-party analytics SDK. Health and fitness information is not sold and is not used for advertising, marketing or data brokerage.
Retention, choices and account deletion
Local records remain until the user removes them with an available in-app control or deletes the app. Apple Health records and permissions can be managed in Apple’s Health and Settings apps. Records exported to a user-controlled InfluxDB must be deleted from that server by its owner.
The current build can remove the local Apple sign-in association. Complete in-app account deletion, Apple token revocation and contribution anonymisation or deletion remain public-release gates and are not represented as complete.
For a public directory deletion or privacy request, email jaybirkett@two-waters.co.uk. Include only enough information to identify the contribution; do not email Health data, API tokens or private server details.
Health and safety
Two Waters Fitness is not a medical device. Health, nutrition, recovery and injury information is general fitness support, not diagnosis, treatment or rehabilitation advice.
Contact
Privacy and deletion questions: jaybirkett@two-waters.co.uk.