Privacy Policy

Version 4.0 | Last Updated: 27 August 2026 | Effective Date: 27 August 2026

Plain-language summary. SocialGryd uses the information you provide to run a fitness, AI coaching and community app. Fitness records, meal images, GPS routes and related insights can reveal health information, so they receive additional protection. Private records stay private unless you choose to share them. We do not sell personal data, use it for cross-context behavioural advertising or let a third-party foundation-model provider train its general models on your private content. You can request access, correction, export or deletion.

1. Scope and Controller

This Policy explains how SocialGryd Limited handles personal data when you visit socialgryd.com or use the SocialGryd mobile applications, fitness tracking, AI coaching, challenges, Train Together and community features, together called the "Service".

The controller is:

SocialGryd Limited
Narva mnt 5, Kesklinna linnaosa, Tallinn, Harju maakond 10117, Estonia
Email: privacy@socialgryd.com
Data Protection Officer: dpo@socialgryd.com

2. Information We Collect

Account and profile information

Name, username, email address, date of birth or age confirmation, profile image, biography, interests, sign-in provider, account identifiers, blocked users, privacy settings and notification choices.

Fitness and activity information

Workouts, exercises, sets, repetitions, load, duration, distance, pace, activity type, notes, perceived effort, goals, streaks, challenge progress and related trends. If you connect a device or health platform in the future, we will show a separate permission notice before importing its data.

Food and nutrition information

Meal photographs, food descriptions, portion information, ingredients, calories, macronutrients, corrections, saved meals and related estimates.

Location and route information

Approximate or precise location, GPS coordinates, routes, timestamps, place searches and Train Together meeting locations when you enable a location feature. We do not collect precise location merely because the app is installed.

AI coaching and insight information

Prompts, responses, selected fitness records, recent activity, goals and feedback used to provide meal estimates, explain patterns or generate coaching suggestions. We aim to send only the information needed for the specific request.

Community and communications information

Posts, photographs, videos, comments, reactions, selected progress updates, Train Together sessions, challenge participation, friend or connection information, messages, reports and the audience you select.

Subscription, device and support information

App-store purchase token or transaction identifier, subscription status, country, device type, operating system, app version, language, IP address, push token, crash and performance information, security logs, cookie choices and communications with support.

3. Health and Other Sensitive Information

Fitness records, nutrition records, body measurements, GPS activity and inferences drawn from them may constitute health data or other sensitive personal data under some laws. Where EU or UK law treats processing as special-category data, SocialGryd relies on your explicit consent for optional health-related features unless another legal condition clearly applies.

You can withdraw consent in the relevant setting or by contacting us. Withdrawal does not make earlier lawful processing unlawful, but it may prevent us from providing features that require the data. Do not upload clinical records or information about another person's health.

4. Where Information Comes From

5. Why We Use Information and Our Legal Bases

PurposeMain dataEU and UK legal basis
Create and secure your accountAccount, authentication, device and security dataContract and legitimate interests in account security
Record meals, workouts, progress and challengesFitness, nutrition and goal dataContract; explicit consent where the data is treated as health data
Provide AI estimates and coachingMeal images, prompts and selected fitness contextContract; explicit consent where health data is processed
Track routes and enable location featuresPrecise or approximate location and routesConsent through device and in-app controls
Provide community, sharing and Train TogetherProfile, posts, selected progress, sessions and interactionsContract and your publishing choices
Moderate content and keep people safeContent, reports, account, device and security dataLegitimate interests, legal obligation and protection of vital interests where applicable
Manage subscriptionsPurchase token, subscription status and support recordsContract, consumer law and accounting obligations
Improve reliability and understand useCrash, performance and consented analytics dataLegitimate interests for essential diagnostics; consent for non-essential analytics where required
Send service messages and optional marketingEmail, push token and preferencesContract or legitimate interests for service messages; consent where required for marketing

Where we rely on legitimate interests, those interests are operating a secure, understandable and useful Service, preventing abuse and improving reliability. We balance them against your rights and reasonable expectations.

6. AI Processing and Automated Decisions

AI may analyse a meal image, text or selected fitness context and return an estimate, summary or coaching suggestion. Outputs contain uncertainty and can be corrected or ignored. We do not use these features to diagnose a condition or make a solely automated decision that produces legal or similarly significant effects.

Current AI service providers process API inputs on our instructions. Under the current provider terms, private API content is not used to train their general foundation models. Safety or diagnostic copies may be retained for a limited period, currently up to 30 days under the existing configuration. We will update this Policy before materially changing that arrangement.

7. What Is Private and What You Choose to Share

Food logs, private workouts, GPS routes, coaching conversations and progress records are private by default unless the feature clearly asks you to publish or share them. You choose the audience for posts, challenges and Train Together information from the controls available.

People who can view shared information may copy, screenshot or reshare it. Do not publish precise home locations, private routes or sensitive health information unless you understand the audience and risk.

8. Who We Share Information With

We disclose only the information reasonably needed to:

We do not sell personal data, share it for cross-context behavioural advertising or disclose private fitness data to employers, insurers or data brokers.

9. International Transfers

SocialGryd is established in Estonia and uses providers that may process data outside the EEA or UK. Where required, we use an adequacy decision, the European Commission Standard Contractual Clauses, the UK Addendum or another lawful transfer mechanism, together with appropriate technical and organisational safeguards.

10. Retention

InformationTypical retention
Account and profileWhile the account is active, then deleted or de-identified after an account-deletion request, subject to the exceptions below
Meals, workouts, progress, challenges and saved AI outputsUntil you delete the entry or account, unless a feature states a shorter period
GPS routes and precise location recordsUntil you delete the activity or account; transient live-location data is kept only as long as needed for the feature and safety
Posts, comments and shared mediaUntil you delete them or your account, subject to reports, legal holds and copies retained by other users
AI provider safety and diagnostic recordsUp to 30 days under the current configuration, unless law requires a longer period
Security, moderation and abuse recordsFor as long as reasonably necessary to investigate, prevent repeat abuse, resolve disputes and meet legal duties
Subscription and transaction recordsFor the period required by tax, accounting, consumer and fraud-prevention law
BackupsNormally overwritten within 90 days

We may retain a limited record after deletion when necessary for a legal claim, statutory obligation, fraud prevention, safeguarding or enforcement of a valid ban. De-identified information that cannot reasonably be linked back to a person may be kept for product analysis.

11. Security

We use access controls, encryption, secure authentication, logging, backups, provider contracts and other technical and organisational measures appropriate to the nature of the data. No service can guarantee absolute security. Keep your device and credentials secure and report concerns to security@socialgryd.com.

12. Cookies, Analytics and Notifications

Our Cookie Policy explains cookies, SDKs, local storage and analytics choices. Where law requires consent for non-essential analytics or marketing, we ask before enabling them. Essential security and service communications may still be sent when needed to operate your account.

You can control push notifications in the app or device settings and unsubscribe from marketing emails. You cannot opt out of strictly necessary security, transaction or legal notices while keeping an active account.

13. Children

The Service is not intended for children below the minimum account age described in our Terms. We do not knowingly collect account data from a child who cannot lawfully consent. Contact privacy@socialgryd.com if you believe a child has created an account contrary to these rules.

14. Your Rights

Depending on where you live and the legal basis used, you may have the right to:

To exercise a right, email privacy@socialgryd.com. We may need to verify your identity. EU users may complain to the Estonian Data Protection Inspectorate at aki.ee or the authority where they live or work. UK users may complain to the Information Commissioner's Office at ico.org.uk.

15. Account Deletion

You can request deletion through available in-app settings or at privacy@socialgryd.com. We will remove or de-identify account, fitness, nutrition, location and community information from active systems, subject to legal, safety and technical exceptions described above. Backup copies are normally overwritten within 90 days.

Deleting SocialGryd does not automatically cancel an Apple App Store or Google Play subscription. Cancel that subscription through the store used for purchase.

16. UK Representative

For UK GDPR Article 27 matters, UK users and the Information Commissioner's Office may contact:

Julian Nevin, UK Representative for SocialGryd Limited
61 Bridge Street
Kington HR5 3DJ
United Kingdom
Telephone: +44 1544 599385
Email: dpr@socialgryd.com

You may instead contact SocialGryd's Data Protection Officer directly. SocialGryd Limited remains responsible for the processing.

17. Changes to This Policy

We may update this Policy for product, legal, security or operational reasons. We will identify the new date and give reasonable advance notice of a material change, normally at least 30 days unless an earlier change is required for law or security. We will seek fresh consent where a new use requires it.

18. Contact

SocialGryd Limited, Narva mnt 5, Kesklinna linnaosa, Tallinn, Harju maakond 10117, Estonia.