Summit — Privacy Policy
Effective September 13, 2026 · Lightbox Studios
Who this policy covers
This policy applies to the Summit iOS app, published by Lightbox Studios (“we,” “us”). It explains what information the app can access, what we do with it, and how to control or delete it.
Data Summit can access
- Health & fitness (HealthKit). Step count, walking/running distance, flights climbed, and workouts, read from Apple Health. This is what turns your real movement into progress up a mountain. Read-only — Summit never writes anything back to Health.
- Photos. Only if you choose to attach one — to a Drop left for friends, or to a Summit Register entry. Nothing is uploaded unless you actively add a photo to one of those.
- Account & device identifiers. A device- or account-level ID (and, if you sign in with Apple, the resulting identity token) used to run friend codes, parties, and the public Summit Register. We do not collect your email address or phone number through this process.
- Content you type. A display name/handle, notes on Drops, and Summit Register entries — only what you type into those specific features.
Summit does not access your precise location, contacts, camera roll beyond a photo you explicitly pick, microphone, or any financial information. Your position on a trail in the app is a simulated game state, not GPS.
How this data is used
- Health data drives your progress up the mountain you're climbing. If you turn on Social, your daily step/climb totals are shared only with friends you've explicitly added, so they can see your progress — never with anyone else, and never with us for any purpose beyond running that feature.
- Photos you attach to a Drop or Register entry are shown to the friends or other signed-in users that feature is designed to show them to.
- Identifiers let your account, friends list, and Summit Register entries work across sessions and devices.
What we don't do
- No analytics or crash-reporting SDKs are integrated into Summit.
- No advertising, and no ad networks receive any data from the app.
- We do not sell or rent your data to anyone, under any circumstances.
- No cross-app or cross-site tracking — nothing about you is used to track you across other companies' apps or websites.
Where data is stored
Health data stays on your device unless you opt into Social, in which case the specific figures described above are stored using Firebase (Google Cloud infrastructure) under our account, solely to run the social features you've turned on. Photos you attach are stored the same way.
Your controls
- Social is off by default — Summit only starts any network activity once you turn it on.
- You can remove a friend, delete a Drop or Register entry you posted, and report content from others, all from within the app.
- You can delete your account and associated data at any time from Settings inside the app. This removes your presence, friend connections, and posted content from our systems.
Children
Summit is not directed at children under 13, and we do not knowingly collect data from children under 13.
Changes to this policy
If this policy changes, we'll update the effective date above. Material changes affecting how Health data is used will be called out clearly in-app.
Contact
Questions, privacy requests, or account-deletion help: hello@lightboxstudios.org.