GRITCORE

Privacy Policy

Last updated 19 September 2026

This policy describes what GritCore collects, why, and what you can do about it. It is written to match what the app actually does. If you find a difference between this document and the app's behaviour, the difference is a bug — please report it.

Who is responsible

GritCore is an independent app, operated by its developer. For anything in this policy, including requests about your own data, write to gritcore.support@gmail.com. Messages are read by the person who builds it.

What is collected, and why

Information you give us

DataWhyRequired?
Email addressTo create and sign you into your accountYes
Date of birthTo confirm you are 13 or older, and to group results by age bandYes
GenderTo group results by category. "Prefer not to say" is an optionOptional
Country and regionTo show where claims come fromOptional
Display name, username, bioShown on your public profileOptional
Language preferenceSo notifications reach you in the language you choseSet by the app

Information about your activity in the app

  • The ultras you claim, the evidence you submit for them, and whether each claim passed validation
  • Ultras you create, endorsements you give, and who you follow
  • Badges you unlock
  • Notification preferences

Health and fitness data (Android)

If you connect Health Connect, the app reads:

  • Exercise sessions — the type, start and end time of a workout
  • Distance — metres recorded during that workout
  • Elevation gained — metres climbed during that workout

Only when you ask it to. The app reads your health data at two moments, and only at those: when you choose "Verify from a recorded activity" for a specific ultra, and when you tap "Sync" during a duel to score your side of it. It does not read in the background, does not sync continuously, and does not read any other health data — not heart rate, weight, sleep, nutrition, or anything else. Permission is granted by you on your device and can be withdrawn there at any time.

Duel syncing stores only the single total for the duel's window — distance, elevation or duration, whichever the duel measures. It does not store the sessions behind it.

When you select an activity, the following is stored on our servers as evidence for that claim: distance, duration, elevation gain, whether a GPS trace was present, how the record was produced (measured or entered by hand), the activity date, and the source record's identifier. The route itself — where you went — is never read or stored.

Health and fitness data (iPhone)

If you connect Apple Health, the app reads:

  • Workouts — the type, start and end time and duration of a workout, the height it climbed if that was recorded, and which app or device recorded it
  • Distance — walking and running, cycling, swimming, and wheelchair distance

Only when you ask it to, exactly as on Android: when you verify a claim from a recorded workout, or when you sync a duel. It does not read in the background, never writes anything to Apple Health, and does not read any other health data — not heart rate, weight, sleep, nutrition, or anything else. Workout routes are never read. Whether a workout was tracked outdoors is worked out from how it was recorded, not from where you went.

You grant access on Apple's own permission screen, and can change it at any time in the Health app or under Settings → Privacy & Security → Health. The evidence stored for a claim or a duel is the same as on Android, described above.

Data read from Apple Health goes only to our own database, as evidence for your claims. It is never shared with Apple or anyone else, never used for advertising, and never stored in iCloud.

What you type into the rarity estimator

The app has a feature that estimates how rare a physical feat is from a sentence you write — for example "I ran 100 km" or "I held a dead hang for three minutes".

That sentence is sent to Google. It is processed by Google's Gemini model. It does not search the web: the answer comes from what the model already knows, and the app says so on every estimate. Google's handling of it is governed by Google's privacy policy and its API terms. We use Google's free tier, under which Google may use what is sent to improve its products.

Write it as a description of the feat, not as somewhere to put personal details. We do not send your name, email, or account identifier with it — Google receives the sentence and nothing that identifies you.

The app asks first. Before your first estimate, it tells you that the sentence goes to Google and sends nothing until you agree. You can decline and use everything else in the app.

The sentence and the answer are also stored on our servers so the same question does not have to be asked twice. Anyone writing the same sentence receives the cached answer.

Sign-in with Google

If you choose Continue with Google instead of an email address, Google tells us your email address and confirms you own it. Google is told that you signed in to this app. We receive nothing else, and you can use an email address and password instead if you would rather Google not be involved.

Sign in with Apple

On iPhone you can choose Sign in with Apple instead. Apple gives us an identifier for your account and an email address — either your own, or, if you choose Hide My Email, a private address at Apple that forwards to yours. We do not ask Apple for your name. Apple is told that you signed in to this app.

Device information

If you enable notifications, a push token identifying your device is stored so notifications can be delivered. It is not readable by other users and is deleted when you delete your account.

Delivering a notification to an Android phone is only possible through Firebase Cloud Messaging, which is operated by Google. Your push token and the text of each notification pass through it. The text is the notification you would see on your lock screen — for example "Someone started following you" — and nothing more.

On an iPhone the same happens through the Apple Push Notification service, operated by Apple: your push token and the text of each notification pass through it, and nothing more.

What is NOT collected

  • No advertising identifiers. There is no advertising in this app.
  • No analytics or tracking SDKs.
  • No location tracking. The app never requests location permission.
  • No contacts, photos, microphone, or camera access.
  • No payment information. There are no purchases.
  • No health data beyond the types listed above for each platform.

How your information is used

Only to operate the app: to run your account, validate your claims, calculate rarity, show leaderboards and public profiles, deliver notifications you asked for, and prevent cheating (for example detecting the same activity claimed by two people).

Aggregate statistics. Counts of how many people have verified each ultra may be published or used for research. These are counts, never individuals — your name is not attached, and only claims backed by sensor data are counted.

Your information is never sold, and never shared with advertisers or data brokers.

What other people can see

  • Public by default: your display name, username, bio, country, avatar, the ultras you have verified, your badges, and your position on leaderboards.
  • Private: your email address, date of birth (only the derived age band is used), your exact evidence values, your push token, your notification preferences, and any rejected claims.
  • You can set your profile to private, which hides your claims and profile details from other users.

Blocking and reporting

If you block someone, we store that you blocked them and when. They are not told.

If you report a duel message or a profile, we store what you reported, the reason you chose, anything you added, and a copy of the reported content as it appeared at that moment — because a message or a bio can be changed afterwards. Reports are read by us to decide what to do about them, and are kept while your account exists.

Who your data is shared with

WhoWhat they receiveWhy
SupabaseAll account and claim dataHosts our database and authentication
Expo (Expo Application Services)Push token, notification textSends push notifications
Google (Firebase Cloud Messaging)Push token, notification textThe only way to deliver a notification to an Android phone
Google (Gemini API)The sentence you type into the rarity estimatorEstimates how rare a feat is
Google (Sign-In)Your email address, if you sign in with GoogleConfirms you own the address
Apple (Push Notification service)Push token, notification textThe only way to deliver a notification to an iPhone
Apple (Sign in with Apple)That you signed in to this app, and a request to withdraw that access when you delete your accountSigns you in; ends GritCore's access to your Apple ID when you delete your account

Supabase and Expo are processors acting on our instructions. Google's role differs by feature: for messaging and sign-in it carries data on our instructions, and for the estimator it processes the sentence under its own API terms. Apple carries notifications and sign-in on our instructions, and receives nothing from Apple Health through us.

Nothing here is advertising. None of these parties receives your data for their own marketing, and none of them is paid by us to profile you. Your data is not sold, and is not shared with advertisers or data brokers.

How long it is kept

Your data is kept while your account exists. When you delete your account it is removed immediately and permanently (see below). Backups are retained by our hosting provider for a limited period and then overwritten.

Deleting your account

In the app: Me tab → Account → Delete my account. You will be asked to type a confirmation word, because this cannot be undone.

Deletion is immediate and permanent. It removes your account, profile, claims, evidence, endorsements, badges, follows, push tokens, and notification preferences.

If you signed in with Apple, deleting your account also withdraws GritCore's access to your Apple ID, so it no longer appears among the apps using Sign in with Apple. Apple asks you to confirm once more; if you dismiss that, nothing is deleted.

Two exceptions, stated plainly.

Ultras you created are not deleted. They remain in the app without your name attached. This is because other people have claimed those ultras, and deleting the ultra would destroy their verified achievements. If you need such an ultra removed entirely, contact us at the address above.

Sentences typed into the rarity estimator are stored without any link to the account that typed them, so there is no record connecting them to you and nothing to find when your account is deleted. They remain as cached answers. Contact us if you typed something you want removed and we will delete that entry.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your data, to object to processing, or to complain to a data protection authority. You can exercise access, correction and deletion directly in the app; for anything else, contact us at the address above.

Our legal basis for processing (where the GDPR applies) is performance of a contract for operating your account, and your consent for health data and notifications — both withdrawable at any time without affecting the rest of the app. The rarity estimator sends your sentence to Google only after you have agreed to it once, and then only when you press the button that asks for an estimate.

Children

GritCore is not for children under 13. Age is checked at sign-up and enforced by the database. If you believe a child under 13 has an account, contact us and it will be removed.

Security

Data is transmitted over HTTPS and stored with access controls that prevent one user reading another's private data. Push tokens and provider credentials are held in tables no client can read. No system is perfectly secure, and we do not claim otherwise.

Changes to this policy

If this policy changes materially, the app will tell you before the change takes effect. The date at the top always reflects the current version.

Contact

gritcore.support@gmail.com