Privacy Policy

Last updated: July 20, 2026

Oleg Chevdar, operating Vysota ("Vysota", "we", "us", or "our"), provides a fitness-based mountain progress app. Oleg Chevdar is the data controller for personal information processed by Vysota. This Privacy Policy explains what information the Vysota app and related services collect, how we use it, how it is shared, and the choices available to you.

You can use Vysota's core app features locally on your device without creating or signing in to a Vysota account. Account creation is optional and is used for account-based features such as cloud sync, account security, and support workflows.

The current iOS App Store version of Vysota is free and does not offer in-app purchases, subscriptions, external payment links, or paid feature access. The Android version may offer optional Premium subscriptions through Google Play. Android Premium purchase and restore are handled through the Google Play account used for purchase and do not require creating a Vysota account. Android Premium does not unlock anything in the current iOS App Store version because the current iOS version includes all available features at no charge.

For privacy questions or requests, contact us at support@vysota.net.

Health and fitness data is sensitive. We do not sell health or fitness data, do not use it for advertising or marketing, and do not use it to track you across apps or websites.

1. Information We Collect

CategoryExamplesPurpose
Account information Email address, display name, authentication provider, provider account identifier, profile image URL when supplied by an OAuth provider, email verification status, password hash for email/password accounts, access and refresh tokens. Account creation, sign-in, account security, password reset, email verification, and syncing your progress when you choose to use an account.
Health and fitness data Steps, flights/floors climbed, historical step/floor totals, and background step/floor updates where you grant permission. Calculating your mountain progress, importing historical progress, refreshing your daily activity, and showing health-based progress inside the app.
App progress and gameplay data Selected mountain, current elevation, meter balance, difficulty settings, floor/stair height settings, achievements, journal events, camps, manual entries, dates, notes you enter, and sync operation metadata. Providing the core Vysota experience, saving local progress on your device, syncing across sessions when you use an account, and restoring data after sign-in.
Technical and diagnostic data App version, build number, device model, operating system version, error messages, and limited stack traces when you manually export logs. Troubleshooting support requests and improving reliability.
Network and service metadata IP address, request headers, timestamps, and security logs processed by our hosting and infrastructure providers when the app communicates with our backend. Operating the service, security, abuse prevention, and backend reliability.
Purchase and subscription data For Android Premium only: store platform, product identifier, subscription plan, purchase-token verification result, hashed purchase token, subscription status, and expiration time. Verifying Google Play purchases where Android Premium is offered, restoring Android Premium access from the Google Play account used for purchase, preventing fraud, showing subscription status in the Android app, and supporting optional account linking when you choose to sign in.

2. HealthKit and Health Connect

On iOS, Vysota uses Apple HealthKit only after you grant permission and explicit in-app consent. The app requests read access to steps and flights climbed. Vysota does not write data to HealthKit.

On Android, Vysota uses Health Connect only after you grant permission and explicit in-app consent. The app requests read access to steps, floors climbed, historical health data, and background health data where supported by your device.

You can withdraw Vysota health sync consent in the app and revoke system health permissions at any time in the Apple Health app, iOS Settings, Android Health Connect, or your device settings. If you withdraw consent or revoke permission, Vysota will stop reading and syncing new health data. Previously calculated progress may remain locally on your device and, if you chose account sync, in your Vysota account unless you delete your health-derived app data, reset app data, or delete your account.

2A. Private Lobby Challenges

Private lobby challenges are invitation-only. An authenticated person with a valid, unexpired invite link can preview the lobby name and creator display name before joining. Invite previews do not show participant lists, avatars, or email addresses.

Under consent version private-lobbies-v1, active challenge participants can see aggregate competition scores, display names, and optional avatars on challenge boards. We do not share raw HealthKit or Health Connect data, exact activity time, source identity, notes, or email address with other participants.

Verified mode counts only server-confirmed aggregate activity. Honor mode can also include eligible manual activity in the aggregate score and may show aggregate automatic and manual totals; it never shows an entry's notes, exact time, or underlying source identity. Invite links expire after 72 hours, and Vysota stores their one-way hashes rather than the raw invite token.

Private-lobby membership, challenge rules, and aggregate competition records are retained while the lobby exists. If you leave a challenge, your row is hidden immediately and that challenge's contribution, Health watermark, and personal baseline records are deleted; this does not delete your private Health, manual-entry, mountain, camp, sync, or snapshot-transfer data. The lobby owner can delete a lobby, which deletes that lobby's social membership, invites, challenges, and aggregate competition records without deleting participants' private app data.

Vysota does not use private-lobby or health data for advertising and does not sell or provide it to data brokers.

3. How We Use Information

4. What We Do Not Do

5. Service Providers and Sharing

We share information only as needed to operate Vysota, provide account features, comply with law, or protect users and the service. Service providers are not permitted to use your data for their own advertising or marketing.

ProviderRoleInformation involved
AppleSign in with Apple and HealthKit permission system.Apple account identifier and email/name if you choose Apple sign-in; health data remains controlled by Apple's permission system and is read only with your consent.
GoogleGoogle Sign-In and app typography package support.Google account identifier, email, name, and profile image URL if you choose Google sign-in.
CloudflareBackend hosting, database, routing, and security.Account, progress, app data, and network/service metadata processed to operate the API.
ResendTransactional account email delivery.Email address and email content needed for verification, password reset, email change, and password change messages.
GoogleGoogle Play subscriptions and purchase verification.Google Play purchase tokens and subscription data needed to verify, restore, and manage subscriptions.

6. Legal Bases for Processing

Where GDPR or similar laws apply, our legal bases include:

7. Data Retention

8. Account Deletion and Privacy Choices

You can delete your account and associated active server data inside the app:

You can also request access, correction, deletion, export, consent withdrawal help, or other privacy help by emailing support@vysota.net. You may revoke Vysota health sync consent in app settings and revoke health permissions from your device settings at any time.

9. Your Rights

Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to processing of your personal information, and to withdraw consent where processing is based on consent.

California residents may have rights to know, delete, correct, opt out of sale or sharing, and limit the use and disclosure of sensitive personal information. Vysota does not sell personal information and does not share personal information for cross-context behavioral advertising.

European Economic Area, UK, and Swiss users may also have the right to lodge a complaint with their local data protection authority.

10. Children

Vysota is not directed to children under 13 and is not submitted as an App Store Kids Category app. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us at support@vysota.net so we can take appropriate action.

11. International Transfers

Vysota and its service providers may process information in countries other than where you live. We use service providers that maintain privacy and security safeguards appropriate for their services.

12. Security

We use HTTPS for data in transit, token-based authentication, hashed refresh tokens, password hashing for email/password accounts, access controls, and provider-managed infrastructure security. We avoid logging health payloads, tokens, email addresses, or other personal data in application logs. No method of transmission or storage is completely secure, but we work to protect information against unauthorized access, disclosure, alteration, and destruction.

13. Changes to This Policy

We may update this Privacy Policy as Vysota changes. The updated version will be posted on this page with a new "Last updated" date.