Last updated: October 10, 2026
This Privacy Policy describes how Power Leveling (“the App,” “we,” “us”), operated by Noland Software LLC (brendancribbs@nolandsoftwarellc.com), collects, uses, and shares information when you use the Power Leveling Android application (package com.powerleveling.app).
By using the App, you agree to this Policy. If you do not agree, do not use the App.
1. Summary
- Workout PRs, body metrics, tape-measure estimates, activity and nutrition you type, military fitness attempt inputs, and optional proof videos stay on your device unless you choose to share related content (for example, posting a feed item to friends).
- Friends, profile, and hype feed features use Firebase (Google) so you can connect with other users.
- We do not sell your personal information.
- The App shows Google AdMob ads: a banner above the bottom navigation, native ads in the Feed about every six posts by default, and an optional rewarded ad that unlocks the Activity 7-day history until midnight on your device. Ads load only after a consent check. The App does not show full-screen interstitial ads. Remote Config can change native-ad spacing or turn ads off. It cannot turn ads on for a Remove ads purchase or an active referral ad-free period.
- You can buy a one-time Remove ads purchase through Google Play (product id
remove_ads). That purchase removes the banner and native ads and unlocks the 7-day history without a rewarded ad. Google Play processes the payment. We do not receive your full payment card number. - Power Leveling Pro is an optional auto-renewing Google Play subscription (product id
pro, base plansmonthlyandyearly, with a 7-day free trial when Play offers it). Pro removes ads, backs up workouts, PRs, and body metrics to your private Firestore area, and lets you create personal API keys. You can cancel anytime in Google Play. Details are in Section 2.8. - Invite a friend uses your existing friend code. When someone redeems it, both accounts get 7 days ad-free. Days stack, up to 12 months ahead. Each account can redeem one code. While that period is active, the banner and native ads stay off and the 7-day history stays unlocked. Time already granted keeps its expiry if the bonus length changes.
- Optional Google and Facebook sign-in are used only to link accounts and help find friends who also use the App.
- Your email address is not saved to our cloud database and is not shown to other users.
- Crash reports and usage data use Firebase Crashlytics and Google Analytics for Firebase (Firebase Analytics). When they are on, Google may receive device and operating-system information, crash stack traces, an installation ID for this app install, an app-instance ID, the app version, the app language, which main screens you open, and a few actions (a workout finished, a PR logged, a tracker mode selected, Remove ads purchased, or a rewarded history unlock). Counts and built-in lift or mode names may be included. We do not send your email address, display name, friend code, or anything you type. This collection is on by default. You can turn it off under Friends → Settings → Share crash reports & usage data. Debug builds do not send it. Ad personalization signals for Analytics stay off unless the ad consent check says they are allowed.
- Firebase Remote Config downloads app settings such as how often a native ad may appear, whether ads and the rewarded unlock are offered, how many finished workouts are required before a review prompt, and the minimum supported version. It does not receive your name, email, or friend code. A remote setting cannot turn ads on if you bought Remove ads or a referral ad-free period is still active.
- Google Play In-App Review may show Google’s rating dialog after you dismiss the workout finish summary, and only after enough finished workouts (5 by default), at least 3 days since install, and at most once every 90 days. It does not run during a workout.
- Google Play In-App Updates checks for an update when the App opens. A flexible update can download in the background and then show Update ready - Restart. An immediate update is used only when the minimum supported version is newer than this install. An update already in progress is resumed.
- Bug reports are voluntary. Friends → Settings → Report a bug opens an email to brendancribbs@nolandsoftwarellc.com. The message can include the app version and version code, device model, Android version, app language, what you write, and a screenshot you choose to attach. Nothing is emailed unless you send it.
2. Information we collect
2.1 Information you provide on your device (local)
Stored primarily in a local database on your phone (and related app-private files):
- Personal records (PRs): lift type, performance value, timestamps, and optional proof video files you attach.
- Body / physique metrics you enter (for example body weight, height, body-fat percentage, sex, age, waist, neck, hips, notes). These are used for scoring modes and the tape-measure body-fat estimate in the App.
- Tape-measure estimates you save (circumferences, body-fat percentage, fat mass, lean mass, and the date).
- Activity log you type: steps, calories consumed, protein, and an elevation number if you tap save. Imported Health Connect values are read for display and are not copied into our cloud database.
- Military / service-style attempt inputs you enter for unofficial fitness trackers (for example AFT, PFT, CFT, PRT, PFRA style events).
- Workout plans you build on the Workout tab (exercises, sets, reps, and weights). These stay in the local database. They are uploaded only when you choose Share workout or Post workout, which publishes that session’s date, exercises, sets, reps, weight, and top muscles as a feed post friends can see.
- Local profile: display name, friend code, optional bio.
- Friends list and feed posts cached on device.
- App preferences such as weight units, tracker mode, the local calendar day the Activity 7-day history was unlocked, a cached copy of your referral ad-free expiry, a cached copy of a Remove ads purchase (so ads can stay off offline until Google Play is checked again), whether Share crash reports & usage data is on (on by default), and the on-device review counters (install time, finished-workout count, and the time of the last review prompt).
- Linked social account flags (which networks are connected, display handle, and provider user id — not long-lived OAuth tokens in our database).
2.2 Information processed in the cloud (when social features are used)
When Firebase is configured and you use friends / feed features, we process:
- Firebase Authentication identifiers (including anonymous account uid; and, if you connect them, Google and/or Facebook linked identities).
- Profile data: display name, friend code, bio, and linked-provider metadata (if you connect Google or Facebook: the provider account ID and the display name returned by that provider). Profile documents can be read by other signed-in users of the App so friend codes can be resolved. Your email address is not saved in your profile or anywhere else in our cloud database, and it is not shown to other users.
- Friend relationships (who you added).
- Feed posts you publish (type, title, body, optional lift label / value text, timestamps, hype counts) and who hyped a post.
- Block list and reports: if you block a user, their friend code and display name are stored in your private block list so the block persists across devices (only you can read it). If you report a post or user, we store your account id, the reported account id, the post id, the reason you chose and the time; reports are not readable by other users and are reviewed by us for moderation.
- Social index entries mapping a provider user id to your App friend code so friends who also use Power Leveling can be suggested.
- Referral data: your friend code is also your referral code. When an account redeems a code we store a referral record (the redeemer’s account id, the referrer’s account id, the code, and the time) and an ad-free expiry plus a count of successful referrals on the profile. Profile documents, including that expiry and count, can be read by other signed-in users who already know the account id. The referral record itself can be read only by the person who redeemed. Each account can redeem one code.
We do not upload your full PR history, body metrics tables, tape-measure history, activity log, nutrition entries, military attempt logs, or proof videos to Firestore as part of the free social features. A workout plan stays on your phone unless you post that workout to your feed, or you turn on Pro cloud backup (Section 2.8). Proof videos are never uploaded.
2.3 Information from third-party sign-in (optional)
If you choose Connect for Google (also used for YouTube identity) or Facebook:
- Google / Meta provide authentication credentials and basic account identifiers according to their permissions screens. The App uses your account ID (and display name) from that provider to link the account and match you with friends who also use the App.
- The App does not ask Google or Facebook for your email address, and does not save your email address to our cloud database (Cloud Firestore) or show it to other users. If an email address was stored in your profile by an earlier version of the App, the App deletes it the next time it syncs your linked accounts.
- Firebase Authentication (Google’s sign-in service that the App uses to keep your account linked) may still hold the email address associated with your Google or Facebook account as part of your sign-in account record — for example, if you linked before this change or your provider shares it. That record is visible only to the developer (through the Firebase console), is not copied into our cloud database, and is not shown to other users. You can ask us to delete it by requesting account deletion (see Section 5).
- Facebook may allow friend-id lookups used only to suggest other Power Leveling users — not to post on your behalf without using the system share sheet.
2.4 Device, diagnostics, and crash reports
- Standard network connectivity is required for cloud social features and to deliver crash reports.
- Camera permission is requested only to scan friend QR codes (optional; you can add friends by code instead). Scanning a referral QR uses Google Play services’ on-device code scanner and does not add a camera permission. The image is not uploaded to Power Leveling.
- Firebase Crashlytics (Google) collects crash reports so we can fix crashes. Collection is on by default and uses the same switch as usage data. You can turn it off at any time under Friends → Settings → Share crash reports & usage data. That choice is stored only on your device. When collection is on, Crashlytics may process:
- Device and operating-system information (for example device model and Android version)
- Crash stack traces
- An installation ID (a random identifier for this app installation, not your account)
- App version and app language (locale), which the App sets as the only custom keys
- We do not send your email address, display name, friend code, workouts, or other profile fields to Crashlytics. We do not use Crashlytics as an advertising product. Usage data is collected separately by Firebase Analytics, described in Section 2.7, and uses the same switch.
- Purpose: diagnose crashes and improve the stability of the App.
- Opt-out: turn Share crash reports & usage data off. New crash reports and usage events stop. Reports already received stay with Google under its retention until they expire. Debug builds of the App do not send crash reports or usage data.
- Bug reports by email are separate and voluntary. If you tap Report a bug, the App opens your email app with a message addressed to brendancribbs@nolandsoftwarellc.com, subject Power Leveling bug report (vX) (X is the app version), and a body that lists the app version and version code, device model, Android version, app language, and a blank What happened? section for you to fill in. You can attach a screenshot from the photo picker before you send. The App does not send that email itself. If no email app is installed, the App copies those details to the clipboard and shows a short message so you can paste them somewhere else.
- If you enable device backup (for example Google backup), Android may include App data in your backup according to your device settings.
2.5 Advertising and purchases
The App uses Google AdMob and the User Messaging Platform.
- A banner can sit above the bottom navigation. It is one ad view for the whole session. Switching tabs does not load a new banner.
- The Feed may include a native ad, labeled Ad and Sponsored. The default spacing is about every six posts. Firebase Remote Config can change that spacing. A short feed has none. The ad includes Google’s ad attribution and AdChoices icon.
- The Activity screen’s 7-day history can be locked. The button says “Watch a short ad to unlock today.” The ad plays only after you tap it. If the reward is granted, the history stays open until midnight in your device’s local time zone. Closing the ad early does not unlock it. Today’s activity entry stays available.
- The App does not show interstitial (full-screen) ads between screens.
- Ads are requested only after the User Messaging Platform says ads may be requested. Where that platform requires a choice, you can change it under Friends → Settings → Ad privacy options.
- If you buy Remove ads (a one-time, non-consumable product) or a referral ad-free period is still in the future, the banner and native ads are not requested and the 7-day history is unlocked. Remote Config cannot turn those ads back on. The price shown in the App is the localized price from Google Play. The listed price in the United States is 2.99 USD; other regions may differ. Google Play handles the purchase, including a payment that is still pending. We acknowledge a completed purchase and check Google Play for existing purchases when the App starts. A pending purchase does not remove ads.
- Google may receive the advertising ID (
AD_ID), IP address, and device information described in Google’s Privacy Policy to request, show, measure, and, if you consent, personalize ads. - We do not sell your workout data, and we do not use it to build advertising profiles that we sell.
- The unlock day and the Remove ads cache stay on your device. The referral expiry is stored on your profile in Firebase so it can sync, and a copy is cached on the device.
2.6 Activity, Health Connect, and elevation (optional)
The Activity screen can read the following from Android Health Connect, and only if you allow each one:
- Step count
- Elevation gained
- Floors climbed
- Nutrition stored there by you or by another app: energy (calories) and protein
Power Leveling does not write workouts, steps, elevation, or nutrition to Health Connect. These reads stay on your phone. They are not uploaded, sold, or shared.
If Health Connect is missing, you decline access, or a day has no nutrition records, you can type steps, calories, and protein yourself. Those entries are saved in the local database on your phone.
Calorie-burn figures are estimates from your steps, elevation gained, height, body weight, and the duration of workouts saved in the App. The tape-measure body-fat figure is an estimate from circumferences. Neither is medical advice or a medical measurement.
Current elevation. When you tap refresh, the App asks for location permission and takes one foreground location reading to estimate height above sea level. The App does not request background location and does not keep a location history. If the phone cannot provide an altitude, the App may send that latitude and longitude to the Open-Meteo elevation service (https://api.open-meteo.com/v1/elevation) to look up ground elevation, then discard the coordinates. If you tap save, only the elevation number is stored on the device.
2.7 Usage data, Remote Config, in-app review, and updates
- Google Analytics for Firebase records anonymous usage: which main screens you open, and whether you finish a workout, log a PR, select a tracker mode, buy Remove ads, or unlock history with a rewarded ad. Parameters are counts or built-in names of lifts and tracker modes. We do not log your name, email, friend code, bio, notes, or anything you type, and we do not set an analytics user id.
- The same Friends → Settings switch, Share crash reports & usage data, controls this collection and crash reports. It is on by default. The choice stays on this device. Debug builds do not send usage data.
- Firebase may process an app-instance ID and device information with these events. Ad personalization signals stay off unless the User Messaging Platform says consent is not required, or you agree to personalized ads there (storage, an ads profile, and personalized ads). You can change that under Ad privacy options where the control is shown.
- Firebase Remote Config fetches: native ad spacing (default every 6 posts), whether ads are offered, whether the rewarded unlock is offered, the finished-workout count required before a review prompt (default 5), and the minimum supported version code (default 0). It does not include your name, email, or friend code. Those values cannot enable ads while Remove ads is owned or a referral ad-free period is active.
- Google Play In-App Review may request Google’s rating sheet after you dismiss the finish summary. The App asks only when the finished-workout count is at least the configured minimum, at least 3 days have passed since install, and the last request was at least 90 days ago. It does not run while a workout is open. Install time, the finished-workout count, and the last request time stay on the device.
- Google Play In-App Updates looks for an update on launch. A flexible update downloads in the background. When it is ready the App shows Update ready - Restart. An immediate update, which must be finished before you continue, is used only when the configured minimum version is newer than this install. An update that was already running is resumed when you return.
2.8 Pro subscription, cloud backup, and the personal API
Pro is optional. The price you see in the App is the localized price from Google Play for the monthly or yearly base plan. A 7-day free trial, when Play offers it, is configured in Play Console. After the trial, the subscription renews automatically until you cancel. Cancel anytime in Google Play subscriptions. After you cancel, Pro stays on until the end of the period you already paid for. If a payment fails, Google Play may put the subscription in a grace period (Pro stays on) or on hold (Pro turns off until you fix payment). We acknowledge completed purchases. We do not receive your full payment card number.
If Pro is active, the App can copy these Room records to Cloud Firestore under users/{your account id}/, readable and writable only by that account:
- Workout sessions, exercises, and sets (exercise, sets, reps, weight in kilograms, and whether a set was bodyweight)
- Personal-record values and dates (not proof videos)
- Body metrics you saved (weight, height, body-fat percentage, sex, age, circumferences, notes)
- Your display name, so the personal API can name the export
The App syncs when those records change and when you tap Back up now. A new device signed into the same account can restore them. If the same record changed on two devices, the later updatedAt time wins. Account deletion deletes this tree.
Personal API keys. From Settings you can ask a Cloud Function to create a key that starts with pl_. The plaintext key is shown once on your phone. We store only a SHA-256 hash in the apiKeys collection, which the App cannot read. You can keep up to 3 active keys and revoke them. A key lets a read-only HTTPS API return your synced profile, PRs, workouts, and body metrics. The server checks that your stored Play purchase token is still an active Pro subscription (including grace, and a canceled plan that has not expired) using the Google Play Developer API. Keys are rate limited. This API is not medical advice.
The Share with AI button does not use this API and does not upload the summary. It builds text on your phone and opens the Android share sheet, or saves a .txt file you pick.
3. How we use information
We use information to:
- Calculate power level / scoring and show your progress.
- Provide friends, QR / friend-code linking, and the hype feed.
- Authenticate you and keep optional Google / Facebook links attached to the same account.
- Maintain security, prevent abuse, and operate the App.
- Diagnose crashes and improve stability when crash reports are enabled.
- Understand which screens and actions are used when usage data is enabled.
- Apply Remote Config settings, offer an in-app review when the rules above are met, and deliver Play updates.
- Respond to support requests and voluntary bug reports you send to our contact email.
We do not sell personal information. Google may personalize ads according to your consent choices. We do not use your workout data to build advertising profiles that we sell.
4. How we share information
We share information only as needed to run the App:
- Open-Meteo, only when you refresh current elevation and the phone has no usable altitude. That request contains the latitude and longitude of the single fix. We do not send your account, name, workouts, or nutrition.
| Recipient | Purpose |
|---|---|
| Google Firebase (Auth, Cloud Firestore) | Accounts, profiles, friends, posts/hypes (Firebase Auth may hold your sign-in email; Firestore does not store it) |
| Google Firebase Crashlytics | Crash reports: device and OS information, crash stack traces, an installation ID, app version, and app language, so we can fix crashes. Not your email, display name, or friend code. Not shared with other users or advertisers. You can turn this off. |
| Google Analytics for Firebase | Anonymous usage: screen views and the events listed in Section 2.7, plus an app-instance ID and device information. Not your name, email, friend code, or free text. Not sold. Optional, and off in debug builds. Ad personalization signals stay off unless ad consent allows them. |
| Google Firebase Remote Config | App settings (ad spacing, whether ads and the rewarded unlock are offered, review threshold, minimum version). Not your name, email, or friend code. |
| Google AdMob and the User Messaging Platform | Banner, native, and optional rewarded ads, plus the advertising ID and consent choices needed to request them. No interstitial ads. |
| Google Play | The Remove ads purchase and the optional Pro subscription, including purchase state, purchase token (stored for verification), and the localized price. Also in-app review and in-app updates (version and update state). |
| Google Cloud Functions | Creating and revoking personal API keys, verifying the Pro purchase token, and serving the read-only personal API. |
| Google Sign-In / Play services | Optional Google account linking |
| Meta (Facebook Login) | Optional Facebook account linking / discovery |
| Other Power Leveling users you connect with | Your display name, friend code, and posts/hypes you share with friends |
| Service providers / legal | If required by law, or to protect rights, safety, and the App |
Feed content you publish is visible to you and to friends according to the App’s friendship model — treat posts as shared with your crew.
5. Data retention
- On-device data remains until you delete it in the App (where available), clear App storage, or uninstall.
- Crash reports and usage data collected while Share crash reports & usage data is on are stored by Google Firebase for Google’s retention period for Crashlytics and Google Analytics. Turning the setting off stops new reports and events. It does not by itself delete data already received. They are not tied to your name, email, or friend code. You can ask us about a report by emailing brendancribbs@nolandsoftwarellc.com with the approximate time and app version.
- Bug-report emails you choose to send are kept as long as needed to investigate them and for our records.
- Reports you file are kept for as long as needed to review them, act on them and keep a record of moderation decisions. Your block list is deleted when you delete your account.
- Cloud profile, friends, posts, and social index data are retained while needed to provide social features or until deleted upon a verified request, account cleanup, or product shutdown.
- Referral claim: if you redeemed a code,
referrals/{your account id}is kept even after you delete the account in the App, so that account cannot redeem a second code. It stores the two account ids, the code, and the time. Email brendancribbs@nolandsoftwarellc.com to have that record removed. The ad-free time already granted to the other person is not taken back. - You may disconnect Google / Facebook links from within the App (Friends → Linked accounts).
- Switching to an existing account: if you connect a Google or Facebook account that already belongs to another Power Leveling profile, the App can sign you in to that existing profile instead (only if you confirm). Your cloud profile, friends and posts then come from that account; workout data stored on your phone is not changed. If the profile you were using was a temporary (anonymous) one with no friends, the App deletes its cloud data (profile, friend code entry, posts, social index entries) and its anonymous sign-in account. If any of that can't be deleted at the time (for example, a network error), you can ask us to remove it (see below).
Deleting your account
- In the App: Friends tab → About & legal → Account → Delete my account. After you confirm (type DELETE), the App deletes your cloud profile, friend code reservation, your friends list and your entry in other users' friend lists, your posts (and hypes on them), hypes you gave, social index entries, your Pro cloud backup (workouts, PRs, body metrics, display-name summary, and stored purchase token), your personal API keys, and then your Firebase sign-in account (including Google / Facebook links). You can also choose to erase PRs, body metrics, proof videos and settings stored on your phone. A referral claim, if you redeemed a code, is kept so the account cannot redeem again; email us to remove it. If your account is linked to Google or Facebook, you may be asked to sign in once more to confirm. If a step fails, nothing further is deleted and you can try again.
- On the web / without the App: see https://power-leveling-bud.web.app/delete-account for step-by-step instructions, or email brendancribbs@nolandsoftwarellc.com with your friend code (or enough detail for us to locate the account). We complete email requests within 30 days.
- What may remain: we don't keep copies of deleted cloud data except where the law requires. Google may keep deleted data in its internal backups for a limited period under Google Cloud's data-deletion policy. Copies already on your friends' devices (their cached friends list and feed) can't be removed by us. Email correspondence about a deletion request is kept as long as needed to handle it and for our records.
6. Children’s privacy
The App is not directed to children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided information, contact us and we will take appropriate steps.
7. Security
We use industry-standard providers (Firebase / Google) and keep OAuth tokens in the platform’s auth storage rather than in our Room database. No method of transmission or storage is 100% secure. You are responsible for protecting your device and any accounts you link.
8. International processing
Firebase / Google (including AdMob, Play Billing, Play In-App Review, Play In-App Updates, Crashlytics, Analytics, and Remote Config) and Meta may process data in the United States and other countries where they operate. By using cloud features, ads, crash reports, usage data, or a Google Play purchase or update, you understand that information may be transferred to those locations.
9. Your choices
- Use the App without linking Google or Facebook (anonymous Firebase Auth may still be used for social sync when enabled).
- Decline camera permission and add friends by code instead.
- Decline Health Connect or location access. Steps, calories, and protein can be typed by hand. Location is requested only when you refresh current elevation, and only in the foreground.
- Avoid publishing feed posts if you do not want workout highlights shared with friends.
- On Friends → Settings, open Ad privacy options where that control is offered, and review how many ad-free days you have left.
- Turn Share crash reports & usage data off under Friends → Settings. It is on unless you turn it off. The choice stays on this device and covers both crash reports and anonymous usage events.
- Send a bug report only if you want to. The email, including any screenshot, is voluntary and is sent by your email app.
- Buy Remove ads, or redeem a referral code, to turn the banner and native ads off and to unlock the 7-day history.
- Skip the rewarded ad. The 7-day history stays locked until you watch it, buy Remove ads, or have an active referral period. Today’s activity entry stays available.
- Uninstall the App or clear storage to remove local data.
- Delete your account in the App or request deletion on the web as described in Section 5.
10. Changes
We may update this Policy from time to time. The “Effective date” at the top will change when we do. Continued use of the App after an update means you accept the revised Policy. The current version is also available at:
https://power-leveling-bud.web.app/privacy
11. Contact
Noland Software LLC / Power Leveling
Email: brendancribbs@nolandsoftwarellc.com