Privacy Policy
1. Scope and Controller
This Policy explains how SocialGryd Limited handles personal data when you visit socialgryd.com or use the SocialGryd mobile applications, fitness tracking, AI coaching, challenges, Train Together and community features, together called the "Service".
The controller is:
SocialGryd Limited
Narva mnt 5, Kesklinna linnaosa, Tallinn, Harju maakond 10117, Estonia
Email: privacy@socialgryd.com
Data Protection Officer: dpo@socialgryd.com
2. Information We Collect
Account and profile information
Name, username, email address, date of birth or age confirmation, profile image, biography, interests, sign-in provider, account identifiers, blocked users, privacy settings and notification choices.
Fitness and activity information
Workouts, exercises, sets, repetitions, load, duration, distance, pace, activity type, notes, perceived effort, goals, streaks, challenge progress and related trends. If you connect a device or health platform in the future, we will show a separate permission notice before importing its data.
Food and nutrition information
Meal photographs, food descriptions, portion information, ingredients, calories, macronutrients, corrections, saved meals and related estimates.
Location and route information
Approximate or precise location, GPS coordinates, routes, timestamps, place searches and Train Together meeting locations when you enable a location feature. We do not collect precise location merely because the app is installed.
AI coaching and insight information
Prompts, responses, selected fitness records, recent activity, goals and feedback used to provide meal estimates, explain patterns or generate coaching suggestions. We aim to send only the information needed for the specific request.
Community and communications information
Posts, photographs, videos, comments, reactions, selected progress updates, Train Together sessions, challenge participation, friend or connection information, messages, reports and the audience you select.
Subscription, device and support information
App-store purchase token or transaction identifier, subscription status, country, device type, operating system, app version, language, IP address, push token, crash and performance information, security logs, cookie choices and communications with support.
3. Health and Other Sensitive Information
Fitness records, nutrition records, body measurements, GPS activity and inferences drawn from them may constitute health data or other sensitive personal data under some laws. Where EU or UK law treats processing as special-category data, SocialGryd relies on your explicit consent for optional health-related features unless another legal condition clearly applies.
You can withdraw consent in the relevant setting or by contacting us. Withdrawal does not make earlier lawful processing unlawful, but it may prevent us from providing features that require the data. Do not upload clinical records or information about another person's health.
4. Where Information Comes From
- directly from you when you create an account, log activity, upload a meal, post content or contact us;
- from your device when you grant camera, photo, notification, sensor or location permission;
- from Apple, Google or another sign-in or app-store provider you choose;
- from other users when they interact with you, invite you or report content; and
- from service providers that help us detect errors, fraud, abuse or security incidents.
5. Why We Use Information and Our Legal Bases
| Purpose | Main data | EU and UK legal basis |
|---|---|---|
| Create and secure your account | Account, authentication, device and security data | Contract and legitimate interests in account security |
| Record meals, workouts, progress and challenges | Fitness, nutrition and goal data | Contract; explicit consent where the data is treated as health data |
| Provide AI estimates and coaching | Meal images, prompts and selected fitness context | Contract; explicit consent where health data is processed |
| Track routes and enable location features | Precise or approximate location and routes | Consent through device and in-app controls |
| Provide community, sharing and Train Together | Profile, posts, selected progress, sessions and interactions | Contract and your publishing choices |
| Moderate content and keep people safe | Content, reports, account, device and security data | Legitimate interests, legal obligation and protection of vital interests where applicable |
| Manage subscriptions | Purchase token, subscription status and support records | Contract, consumer law and accounting obligations |
| Improve reliability and understand use | Crash, performance and consented analytics data | Legitimate interests for essential diagnostics; consent for non-essential analytics where required |
| Send service messages and optional marketing | Email, push token and preferences | Contract or legitimate interests for service messages; consent where required for marketing |
Where we rely on legitimate interests, those interests are operating a secure, understandable and useful Service, preventing abuse and improving reliability. We balance them against your rights and reasonable expectations.
6. AI Processing and Automated Decisions
AI may analyse a meal image, text or selected fitness context and return an estimate, summary or coaching suggestion. Outputs contain uncertainty and can be corrected or ignored. We do not use these features to diagnose a condition or make a solely automated decision that produces legal or similarly significant effects.
Current AI service providers process API inputs on our instructions. Under the current provider terms, private API content is not used to train their general foundation models. Safety or diagnostic copies may be retained for a limited period, currently up to 30 days under the existing configuration. We will update this Policy before materially changing that arrangement.
7. What Is Private and What You Choose to Share
Food logs, private workouts, GPS routes, coaching conversations and progress records are private by default unless the feature clearly asks you to publish or share them. You choose the audience for posts, challenges and Train Together information from the controls available.
People who can view shared information may copy, screenshot or reshare it. Do not publish precise home locations, private routes or sensitive health information unless you understand the audience and risk.
8. Who We Share Information With
We disclose only the information reasonably needed to:
- cloud hosting, authentication, database, storage and push-notification providers, including Google Cloud and Firebase;
- AI processing providers, currently including Anthropic for supported AI operations;
- media delivery providers where you upload video or images;
- email, support, security, diagnostics and consent-management providers;
- Apple, Google and app-store billing services you choose to use;
- mapping and place-search services when you use a location feature;
- other users according to the audience and sharing choices you make;
- professional advisers, regulators, courts or law enforcement where legally required or necessary to protect rights and safety; and
- a buyer or successor in a genuine corporate transaction, subject to confidentiality and applicable notice requirements.
We do not sell personal data, share it for cross-context behavioural advertising or disclose private fitness data to employers, insurers or data brokers.
9. International Transfers
SocialGryd is established in Estonia and uses providers that may process data outside the EEA or UK. Where required, we use an adequacy decision, the European Commission Standard Contractual Clauses, the UK Addendum or another lawful transfer mechanism, together with appropriate technical and organisational safeguards.
10. Retention
| Information | Typical retention |
|---|---|
| Account and profile | While the account is active, then deleted or de-identified after an account-deletion request, subject to the exceptions below |
| Meals, workouts, progress, challenges and saved AI outputs | Until you delete the entry or account, unless a feature states a shorter period |
| GPS routes and precise location records | Until you delete the activity or account; transient live-location data is kept only as long as needed for the feature and safety |
| Posts, comments and shared media | Until you delete them or your account, subject to reports, legal holds and copies retained by other users |
| AI provider safety and diagnostic records | Up to 30 days under the current configuration, unless law requires a longer period |
| Security, moderation and abuse records | For as long as reasonably necessary to investigate, prevent repeat abuse, resolve disputes and meet legal duties |
| Subscription and transaction records | For the period required by tax, accounting, consumer and fraud-prevention law |
| Backups | Normally overwritten within 90 days |
We may retain a limited record after deletion when necessary for a legal claim, statutory obligation, fraud prevention, safeguarding or enforcement of a valid ban. De-identified information that cannot reasonably be linked back to a person may be kept for product analysis.
11. Security
We use access controls, encryption, secure authentication, logging, backups, provider contracts and other technical and organisational measures appropriate to the nature of the data. No service can guarantee absolute security. Keep your device and credentials secure and report concerns to security@socialgryd.com.
12. Cookies, Analytics and Notifications
Our Cookie Policy explains cookies, SDKs, local storage and analytics choices. Where law requires consent for non-essential analytics or marketing, we ask before enabling them. Essential security and service communications may still be sent when needed to operate your account.
You can control push notifications in the app or device settings and unsubscribe from marketing emails. You cannot opt out of strictly necessary security, transaction or legal notices while keeping an active account.
13. Children
The Service is not intended for children below the minimum account age described in our Terms. We do not knowingly collect account data from a child who cannot lawfully consent. Contact privacy@socialgryd.com if you believe a child has created an account contrary to these rules.
14. Your Rights
Depending on where you live and the legal basis used, you may have the right to:
- be informed and receive a copy of your personal data;
- correct inaccurate or incomplete data;
- request deletion or restriction;
- receive data you provided in a portable format;
- object to processing based on legitimate interests or to direct marketing;
- withdraw consent at any time;
- ask for human involvement where a solely automated decision significantly affects you; and
- complain to a data-protection authority.
To exercise a right, email privacy@socialgryd.com. We may need to verify your identity. EU users may complain to the Estonian Data Protection Inspectorate at aki.ee or the authority where they live or work. UK users may complain to the Information Commissioner's Office at ico.org.uk.
15. Account Deletion
You can request deletion through available in-app settings or at privacy@socialgryd.com. We will remove or de-identify account, fitness, nutrition, location and community information from active systems, subject to legal, safety and technical exceptions described above. Backup copies are normally overwritten within 90 days.
Deleting SocialGryd does not automatically cancel an Apple App Store or Google Play subscription. Cancel that subscription through the store used for purchase.
16. UK Representative
For UK GDPR Article 27 matters, UK users and the Information Commissioner's Office may contact:
Julian Nevin, UK Representative for SocialGryd Limited
61 Bridge Street
Kington HR5 3DJ
United Kingdom
Telephone: +44 1544 599385
Email: dpr@socialgryd.com
You may instead contact SocialGryd's Data Protection Officer directly. SocialGryd Limited remains responsible for the processing.
17. Changes to This Policy
We may update this Policy for product, legal, security or operational reasons. We will identify the new date and give reasonable advance notice of a material change, normally at least 30 days unless an earlier change is required for law or security. We will seek fresh consent where a new use requires it.
18. Contact
- Privacy and rights requests: privacy@socialgryd.com
- Data Protection Officer: dpo@socialgryd.com
- UK Representative: dpr@socialgryd.com
- Security: security@socialgryd.com
- Safety reports: report@socialgryd.com
- General support: support@socialgryd.com
SocialGryd Limited, Narva mnt 5, Kesklinna linnaosa, Tallinn, Harju maakond 10117, Estonia.
