Privacy Policy
Version 1.0 | Date: 27/04/2026 | Effective Date: 27/04/2026
Fidelis Software Limited | 6 Berryfield Close, Broadwas, Worcester, WR65NJ | 17157758
IMPORTANT — PLEASE READ BEFORE USING GYMWARS
This Privacy Policy explains how Fidelis Software Limited ("we", "us", "our") collects, uses, stores, and protects your personal data when you use the Gym Wars mobile application ("the App").
Gym Wars processes health and fitness data, which is classified as special category data under UK GDPR and requires a higher standard of protection. By creating an account, you confirm you have read and understood this policy.
If you have questions, contact us at: [email protected]
1. Who We Are
Fidelis Software Limited is the data controller responsible for your personal data. We are registered with the Information Commissioner's Office (ICO) under registration number ZC132262.
For all privacy-related enquiries, you can contact our data controller at:
- Email: [email protected]
- Post: Fidelis Software Limited, 6 Berryfield Close, Worcester, WR6 5NJ
- Response time: We aim to respond to all privacy enquiries within 72 hours
2. The Data We Collect
2.1 Account and Identity Data
- Full name and display name
- Email address
- Username (publicly visible)
- Password (stored as a hashed value — we cannot read your password)
- Profile avatar or photo (optional)
- Home gym selection
- Gym Wars XP (GWXP) earned by taking part in the community in-app activities
- Account creation date and last login timestamp
2.2 Fitness and Health Data (Special Category)
The following data is classified as special category health data under UK GDPR Article 9 and receives the highest level of protection we apply:
- Workout logs: exercises performed, sets, repetitions, weights lifted, heart rate, duration
- Cardio data: exercise type, duration, and heart rate zone multipliers
- Gym Wars Points (GWP) earned per session and over the lifetime use of the account
- Personal records and performance history
- Injury reports: body location and date reported (if you use this feature)
- Heart Rate: Max, average and HR Zones for logged workouts (if you use this feature)
- Experience points (XP) and tier/level progression
2.3 Location Data
We collect your precise GPS coordinates for the following specific purposes only:
- Verifying you are within 200 metres of your registered home gym before awarding Gym Wars Points ("the geo-gate")
- Attributing your gym to the correct city for City vs City challenges, using official UK Government (ONS) geographic boundary data
We do not track your location continuously. Location data is only accessed when you actively tap "Claim Points" at the end of a workout.
2.4 Social and Engagement Data
- Posts you create, including captions and attached workout summaries
- Comments you write on other users' posts
- Likes you give to posts
- Users you follow and users who follow you
- Challenge participation and results
- Badges and achievements earned
2.5 Device and Technical Data
- Device type, operating system, and version (iOS or Android)
- Push notification token (used to deliver notifications to your device)
- App version
- Crash and error reports (via Sentry — see Section 7)
- Session timestamps and feature usage logs (anonymised)
2.6 Payment Data
If you purchase a Battle Pass or pay for challenge entry fees, payment processing is handled entirely by Stripe, our payment processor. We do not store, see, or have access to your card number, CVV, or full payment details. We receive only:
- Confirmation that a payment was successful or failed
- Your subscription status and expiry date
- A Stripe customer ID (a reference number, not payment data)
3. Why We Collect Your Data and Our Legal Basis
Under UK GDPR, we must have a valid legal basis for every type of data processing. The table below sets out our purposes and the legal basis for each.
Purpose
Data Used
Legal Basis
Creating and managing your account
Identity data, email
Contract performance
Processing workout sessions and awarding GWP
Fitness/health data, location
Explicit consent (Art. 9)
Displaying leaderboards and rankings
GWP scores, username
Legitimate interests
Enabling social features (posts, likes, comments)
Social data, profile
Contract performance
Sending push notifications
Device token, activity data
Consent
Processing payments for Battle Pass
Payment confirmation only
Contract performance
Verifying gym proximity for point claims
GPS location (on demand)
Explicit consent (Art. 9)
Improving app performance and fixing bugs
Anonymised crash data
Legitimate interests
Complying with legal obligations
Identity, transaction data
Legal obligation
Processing injury reports (if used)
Injury location, dates
Explicit consent (Art. 9)
Special Category Data — Your Explicit Consent
Fitness, health, and location data are special category data under UK GDPR Article 9. We only process this data with your explicit, granular consent, which you provide when you create your account. You may withdraw consent at any time — see Section 8 for your rights.
4. How We Store and Protect Your Data
4.1 Where Your Data Is Stored
- Your account and workout data is stored in a PostgreSQL database hosted by Railway (cloud infrastructure provider) in EU West (Amsterdam, Netherlands)
- Profile photos and workout media are stored in Supabase Storage (currently) and will migrate to Cloudflare R2 storage (planned)
- All data is processed and stored within the European Economic Area (EEA)
4.2 Security Measures
We implement a layered security architecture including:
- All passwords are hashed using Argon2id — the current industry-standard algorithm — meaning we cannot read your password
- All data in transit is encrypted using TLS 1.2 or higher (HTTPS)
- Authentication uses short-lived tokens (15-minute expiry) with rotation and replay detection
- Account lockout after 5 failed login attempts, with escalating lockout periods
- Rate limiting on all API endpoints to prevent abuse
- Access controls ensuring staff can only access data necessary for their role
- Real-time error monitoring and alerting via Sentry
All data at rest is encrypted using AES-256 disk-level encryption
4.3 Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach, and will notify you directly without undue delay.
5. How Long We Keep Your Data
Data Type
Retention Period
Account and profile data
Duration of account + 30 days after deletion request
Workout and fitness data
Duration of account + 30 days after deletion request
Location data (GPS coordinates)
Used in real time to verify proximity — not stored beyond the request
Social posts and comments
Until deleted by you, or account deletion + 30 days
Push notification tokens
Until you log out, uninstall, or revoke permission
Payment records
7 years (UK financial record-keeping legal obligation)
Crash and error logs
90 days (automatically purged by Sentry)
Audit logs (sensitive actions)
2 years
Injury reports
Duration of account + 30 days, or until you delete them
6. Who We Share Your Data With
We do not sell your personal data. We do not share your data with advertisers. We share data only with the following categories of third-party service providers, under contractual data processing agreements:
6.1 Infrastructure and Hosting
- Railway (cloud infrastructure) — hosts our API server and database
- Supabase (storage) — stores profile photos and media uploads
- Cloudflare (CDN and security) — media delivery and DDoS protection [planned]
- Upstash (Redis) — caching for leaderboards and session management
6.2 Authentication and Notifications
- Google Firebase / FCM — delivery of push notifications to your device
- Apple APNs — delivery of push notifications to iOS devices
6.3 Payments
- Stripe — payment processing for Battle Pass and challenge fees. Stripe is independently PCI-DSS compliant. We do not pass card data through our servers.
6.4 Communications
- Resend — sending transactional emails (verification, password reset, account notifications)
6.5 Monitoring and Error Tracking
- Sentry — anonymised crash reports and error monitoring. Sentry is configured to strip personally identifiable information from all error reports.
6.6 Gym Data
- Google Places API — used to search for and verify gym locations. We query this API server-side only; your personal data is not passed to Google.
- Office for National Statistics (ONS) — open geographic boundary data used to attribute gyms to UK cities for City vs City challenges.
6.7 Legal Disclosure
We may disclose your personal data if required by law, court order, or regulatory authority (including the ICO). We will inform you of any such request unless legally prohibited from doing so.
7. Leaderboards, Social Features, and Public Visibility
Gym Wars is a competitive social fitness platform. The following data is visible to other users of the app by default:
- Your display name and username
- Your profile photo (if you upload one)
- Your Gym Wars Points (GWP) total and leaderboard rank
- Your home gym name and city
- Workout posts you create (unless you delete them)
- Comments you post publicly
- Badges and achievements you have earned
The following data is never publicly visible:
- Your email address
- Your precise GPS location or location history
- Your injury reports
- Your payment information
- Your full workout history beyond what you choose to post
Controlling Your Visibility
You can delete any post, comment, or profile content at any time from within the App. Deleted content is removed from public view immediately and permanently deleted from our systems within 30 days.
You can unfollow users and prevent users from following you through your privacy settings.
8. Your Rights Under UK GDPR
You have the following rights regarding your personal data. You can exercise most of these directly within the App, or by contacting us at [email protected].
- Right of Access: Request a copy of all personal data we hold about you. Available via Settings > Export My Data (GET /users/me/export).
- Right to Rectification: Correct inaccurate personal data. You can update most data directly in your profile settings.
- Right to Erasure ("Right to be Forgotten"): Request deletion of all your personal data. Available via Settings > Delete Account. Note: payment records are retained for 7 years under financial law even after account deletion.
- Right to Restrict Processing: Request that we limit how we use your data while a dispute is resolved.
- Right to Data Portability: Receive your personal data in a machine-readable format (JSON) to transfer to another service. Available via Settings > Export My Data.
- Right to Object: Object to processing based on legitimate interests. We will stop unless we have compelling legitimate grounds to continue.
- Right to Withdraw Consent: Withdraw consent for special category data processing at any time. Note: withdrawal may limit your ability to use core App features that rely on health or location data.
- Right Not to Be Subject to Automated Decisions: Gym Wars does not make automated decisions with legal or similarly significant effects. Leaderboard rankings are calculated automatically but have no legal significance.
We will respond to all rights requests within one calendar month. If your request is complex, we may extend this by a further two months — we will inform you if this is the case.
You also have the right to lodge a complaint with the ICO at any time: ico.org.uk | 0303 123 1113
9. Children's Privacy and the Age Appropriate Design Code
Gym Wars is intended for users aged 16 and over. We do not knowingly collect personal data from users under the age of 16.
If you are between 13 and 16, you must obtain parental or guardian consent before using Gym Wars. We reserve the right to verify age and to close accounts where we have reason to believe a user is under 13.
If you believe a child under 16 has created an account, please contact us at [email protected] and we will promptly investigate and delete the account and all associated data.
We comply with the ICO's Age Appropriate Design Code (Children's Code). High privacy protection settings are the default. We do not use nudge techniques designed to encourage children to provide more data than necessary.
10. Cookies and Tracking Technologies
Gym Wars is a mobile application and does not use browser cookies. We use the following device-level technologies:
- Secure local storage (iOS Keychain / Android Keystore) to store your authentication tokens on your device
- AsyncStorage for non-sensitive app preferences (e.g. notification settings)
- Push notification tokens registered with Google FCM and Apple APNs
We do not use advertising tracking, cross-app tracking, or advertising identifiers (IDFA/GAID). Gym Wars does not display advertising and we do not share data with advertising networks.
11. International Data Transfers
Some of our third-party service providers are based outside the UK. Where we transfer personal data internationally, we ensure appropriate safeguards are in place:
- Stripe (USA) — UK Standard Contractual Clauses (SCCs) in place; Stripe is also certified under the UK-US Data Bridge
- Google Firebase/FCM (USA) — UK SCCs in place
- Sentry (USA) — UK SCCs in place; EU data residency option configured
- Railway — EU West (Amsterdam, Netherlands)
- Resend — Ireland (EU-West-1)
You can obtain copies of the relevant Standard Contractual Clauses by contacting us at [email protected].
12. Automated Decision Making and Profiling
Gym Wars uses automated processing to:
- Calculate your Gym Wars Points (GWP) based on your workout data and gym proximity
- Determine your leaderboard ranking and competitive tier
- Verify that your GPS coordinates meet the 100-metre gym proximity requirement before awarding points
- Attribute your gym to the correct city using ONS boundary data
None of these automated processes produce decisions with legal or similarly significant effects on you. The leaderboard ranking is for competitive entertainment purposes and does not affect employment, credit, or legal status. You may request a human review of any automated decision by [email protected].
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, new features, or changes in applicable law.
Where we make material changes — particularly changes that affect how we process special category health data — we will:
- Notify you via a push notification and in-app message at least 14 days before the change takes effect
- Request fresh consent where required by UK GDPR
- Update the version number and effective date at the top of this document
Continued use of Gym Wars after the effective date constitutes acceptance of the updated policy for changes that do not require fresh consent. For changes that do require consent, you may decline — but this may limit your ability to use certain features.
14. Contact Us and How to Complain
14.1 Contact Us
For any privacy-related queries, data subject requests, or concerns:
- Email: [email protected]
- Post: Fidelis Software, 6 Berryfield Close, WR6 5NJ
- Response time: within 72 hours for general queries; within 30 days for formal rights requests
14.2 How to Complain
If you are unhappy with how we have handled your personal data, please contact us in the first instance and we will do our best to resolve the matter.
If you remain unsatisfied, you have the right to complain to the Information Commissioner's Office (ICO):
- Website: ico.org.uk/make-a-complaint
- Telephone: 0303 123 1113
- Post: ICO, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Fidelis Software Limited
Registered in England and Wales | Company No: 17157758 | ICO Registration No: ZC132262.
Document Revision History
Version
Date
Author
Summary of Changes
1.0
27/24/2026
[Matthew Davies]
Updated first copy