Privacy Policy
Last updated 19 September 2026
This policy describes what GritCore collects, why, and what you can do about it. It is written to match what the app actually does. If you find a difference between this document and the app's behaviour, the difference is a bug — please report it.
Who is responsible
GritCore is an independent app, operated by its developer. For anything in this policy, including requests about your own data, write to gritcore.support@gmail.com. Messages are read by the person who builds it.
What is collected, and why
Information you give us
| Data | Why | Required? |
|---|---|---|
| Email address | To create and sign you into your account | Yes |
| Date of birth | To confirm you are 13 or older, and to group results by age band | Yes |
| Gender | To group results by category. "Prefer not to say" is an option | Optional |
| Country and region | To show where claims come from | Optional |
| Display name, username, bio | Shown on your public profile | Optional |
| Language preference | So notifications reach you in the language you chose | Set by the app |
Information about your activity in the app
- The ultras you claim, the evidence you submit for them, and whether each claim passed validation
- Ultras you create, endorsements you give, and who you follow
- Badges you unlock
- Notification preferences
Health and fitness data (Android)
If you connect Health Connect, the app reads:
- Exercise sessions — the type, start and end time of a workout
- Distance — metres recorded during that workout
- Elevation gained — metres climbed during that workout
Only when you ask it to. The app reads your health data at two moments, and only at those: when you choose "Verify from a recorded activity" for a specific ultra, and when you tap "Sync" during a duel to score your side of it. It does not read in the background, does not sync continuously, and does not read any other health data — not heart rate, weight, sleep, nutrition, or anything else. Permission is granted by you on your device and can be withdrawn there at any time.
Duel syncing stores only the single total for the duel's window — distance, elevation or duration, whichever the duel measures. It does not store the sessions behind it.
When you select an activity, the following is stored on our servers as evidence for that claim: distance, duration, elevation gain, whether a GPS trace was present, how the record was produced (measured or entered by hand), the activity date, and the source record's identifier. The route itself — where you went — is never read or stored.
Health and fitness data (iPhone)
If you connect Apple Health, the app reads:
- Workouts — the type, start and end time and duration of a workout, the height it climbed if that was recorded, and which app or device recorded it
- Distance — walking and running, cycling, swimming, and wheelchair distance
Only when you ask it to, exactly as on Android: when you verify a claim from a recorded workout, or when you sync a duel. It does not read in the background, never writes anything to Apple Health, and does not read any other health data — not heart rate, weight, sleep, nutrition, or anything else. Workout routes are never read. Whether a workout was tracked outdoors is worked out from how it was recorded, not from where you went.
You grant access on Apple's own permission screen, and can change it at any time in the Health app or under Settings → Privacy & Security → Health. The evidence stored for a claim or a duel is the same as on Android, described above.
Data read from Apple Health goes only to our own database, as evidence for your claims. It is never shared with Apple or anyone else, never used for advertising, and never stored in iCloud.
What you type into the rarity estimator
The app has a feature that estimates how rare a physical feat is from a sentence you write — for example "I ran 100 km" or "I held a dead hang for three minutes".
That sentence is sent to Google. It is processed by Google's Gemini model. It does not search the web: the answer comes from what the model already knows, and the app says so on every estimate. Google's handling of it is governed by Google's privacy policy and its API terms. We use Google's free tier, under which Google may use what is sent to improve its products.
Write it as a description of the feat, not as somewhere to put personal details. We do not send your name, email, or account identifier with it — Google receives the sentence and nothing that identifies you.
The app asks first. Before your first estimate, it tells you that the sentence goes to Google and sends nothing until you agree. You can decline and use everything else in the app.
The sentence and the answer are also stored on our servers so the same question does not have to be asked twice. Anyone writing the same sentence receives the cached answer.
Sign-in with Google
If you choose Continue with Google instead of an email address, Google tells us your email address and confirms you own it. Google is told that you signed in to this app. We receive nothing else, and you can use an email address and password instead if you would rather Google not be involved.
Sign in with Apple
On iPhone you can choose Sign in with Apple instead. Apple gives us an identifier for your account and an email address — either your own, or, if you choose Hide My Email, a private address at Apple that forwards to yours. We do not ask Apple for your name. Apple is told that you signed in to this app.
Device information
If you enable notifications, a push token identifying your device is stored so notifications can be delivered. It is not readable by other users and is deleted when you delete your account.
Delivering a notification to an Android phone is only possible through Firebase Cloud Messaging, which is operated by Google. Your push token and the text of each notification pass through it. The text is the notification you would see on your lock screen — for example "Someone started following you" — and nothing more.
On an iPhone the same happens through the Apple Push Notification service, operated by Apple: your push token and the text of each notification pass through it, and nothing more.
What is NOT collected
- No advertising identifiers. There is no advertising in this app.
- No analytics or tracking SDKs.
- No location tracking. The app never requests location permission.
- No contacts, photos, microphone, or camera access.
- No payment information. There are no purchases.
- No health data beyond the types listed above for each platform.
How your information is used
Only to operate the app: to run your account, validate your claims, calculate rarity, show leaderboards and public profiles, deliver notifications you asked for, and prevent cheating (for example detecting the same activity claimed by two people).
Aggregate statistics. Counts of how many people have verified each ultra may be published or used for research. These are counts, never individuals — your name is not attached, and only claims backed by sensor data are counted.
Your information is never sold, and never shared with advertisers or data brokers.
What other people can see
- Public by default: your display name, username, bio, country, avatar, the ultras you have verified, your badges, and your position on leaderboards.
- Private: your email address, date of birth (only the derived age band is used), your exact evidence values, your push token, your notification preferences, and any rejected claims.
- You can set your profile to private, which hides your claims and profile details from other users.
Blocking and reporting
If you block someone, we store that you blocked them and when. They are not told.
If you report a duel message or a profile, we store what you reported, the reason you chose, anything you added, and a copy of the reported content as it appeared at that moment — because a message or a bio can be changed afterwards. Reports are read by us to decide what to do about them, and are kept while your account exists.
Who your data is shared with
| Who | What they receive | Why |
|---|---|---|
| Supabase | All account and claim data | Hosts our database and authentication |
| Expo (Expo Application Services) | Push token, notification text | Sends push notifications |
| Google (Firebase Cloud Messaging) | Push token, notification text | The only way to deliver a notification to an Android phone |
| Google (Gemini API) | The sentence you type into the rarity estimator | Estimates how rare a feat is |
| Google (Sign-In) | Your email address, if you sign in with Google | Confirms you own the address |
| Apple (Push Notification service) | Push token, notification text | The only way to deliver a notification to an iPhone |
| Apple (Sign in with Apple) | That you signed in to this app, and a request to withdraw that access when you delete your account | Signs you in; ends GritCore's access to your Apple ID when you delete your account |
Supabase and Expo are processors acting on our instructions. Google's role differs by feature: for messaging and sign-in it carries data on our instructions, and for the estimator it processes the sentence under its own API terms. Apple carries notifications and sign-in on our instructions, and receives nothing from Apple Health through us.
Nothing here is advertising. None of these parties receives your data for their own marketing, and none of them is paid by us to profile you. Your data is not sold, and is not shared with advertisers or data brokers.
How long it is kept
Your data is kept while your account exists. When you delete your account it is removed immediately and permanently (see below). Backups are retained by our hosting provider for a limited period and then overwritten.
Deleting your account
In the app: Me tab → Account → Delete my account. You will be asked to type a confirmation word, because this cannot be undone.
Deletion is immediate and permanent. It removes your account, profile, claims, evidence, endorsements, badges, follows, push tokens, and notification preferences.
If you signed in with Apple, deleting your account also withdraws GritCore's access to your Apple ID, so it no longer appears among the apps using Sign in with Apple. Apple asks you to confirm once more; if you dismiss that, nothing is deleted.
Two exceptions, stated plainly.
Ultras you created are not deleted. They remain in the app without your name attached. This is because other people have claimed those ultras, and deleting the ultra would destroy their verified achievements. If you need such an ultra removed entirely, contact us at the address above.
Sentences typed into the rarity estimator are stored without any link to the account that typed them, so there is no record connecting them to you and nothing to find when your account is deleted. They remain as cached answers. Contact us if you typed something you want removed and we will delete that entry.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your data, to object to processing, or to complain to a data protection authority. You can exercise access, correction and deletion directly in the app; for anything else, contact us at the address above.
Our legal basis for processing (where the GDPR applies) is performance of a contract for operating your account, and your consent for health data and notifications — both withdrawable at any time without affecting the rest of the app. The rarity estimator sends your sentence to Google only after you have agreed to it once, and then only when you press the button that asks for an estimate.
Children
GritCore is not for children under 13. Age is checked at sign-up and enforced by the database. If you believe a child under 13 has an account, contact us and it will be removed.
Security
Data is transmitted over HTTPS and stored with access controls that prevent one user reading another's private data. Push tokens and provider credentials are held in tables no client can read. No system is perfectly secure, and we do not claim otherwise.
Changes to this policy
If this policy changes materially, the app will tell you before the change takes effect. The date at the top always reflects the current version.
Contact
gritcore.support@gmail.com