Privacy Policy

Version 4.1 | Published: 7 September 2026

Beta policy update. Published 7 September 2026. Updated contractual terms apply to new registrations on express acceptance and to existing accounts from 8 October 2026 after notice and any required fresh acceptance. Existing rights are preserved. Corrected operator information and new safety/privacy controls apply as they are released; notices describe those controls and do not create consent by themselves. Read the complete update.

1. Scope and responsible operator

SocialGryd is a product name for a service under development; it is not currently an incorporated company. Julian Nevin, trading as SocialGryd, with correspondence at 61 Bridge Street, Kington, HR5 3DJ, United Kingdom is the operator and, for personal data handled for its own purposes, the responsible organisation or data controller. Contact legal@socialgryd.com for privacy matters and support@socialgryd.com for support.

This Policy covers the marketing website, mobile app and related group, club and administrative services. The beta is not geographically restricted. EU/EEA GDPR, UK GDPR and other laws apply where their territorial and other requirements are met. Being a Singapore pilot or not yet incorporated does not itself remove those obligations.

Data-protection enquiries: legal@socialgryd.com. Julian Nevin is responsible for handling privacy enquiries through this address. We do not claim an Estonian establishment or an appointed EU/UK representative. A correspondence address is not a claim of establishment, company registration or appointment as a statutory representative.

2. Information collected

Sources include you, your permitted device features, sign-in providers, people who interact with or report you, and operational providers. Camera, photos, microphone, motion and location permissions serve the feature described when requested. Device permission is not blanket permission for unrelated processing. Current step tracking uses device motion/pedometer data; this notice does not claim a current Apple Health or Health Connect import.

3. Purposes and legal basis

For Singapore data, we collect, use and disclose information for notified purposes with consent where required, or a specifically applicable PDPA exception. You may withdraw consent on reasonable notice; we explain the consequence and stop the affected use unless a lawful exception applies. We do not require consent to unnecessary processing as a condition of using unrelated features.

PurposeDataEU/UK basis, where applicable
Provide accounts, private logs, posts, groups and requested featuresAccount, content, fitness and interactionsContract for necessary service delivery; an additional Article 9 condition for health data
Optional health/fitness personalisation and AI processingFood, workout, health-revealing inputs and selected historyConsent for optional processing, including explicit consent under Article 9(2)(a) where applicable
Optional location, motion and publishing featuresCoordinates, steps and selected shared informationConsent where required; contract for the specific requested service; additional health-data condition where applicable
Security, moderation, account recovery and essential reliabilityAuthentication, logs, reports and relevant contentLegitimate interests in protecting users and the service; legal obligation where a specific duty applies
Optional analytics or marketingUsage/device information and contact preferencesConsent where required; objection and withdrawal controls
Support, billing and legal claimsSupport, transactions and necessary evidenceContract, specific legal obligations or legitimate interests in resolving disputes, as relevant

Legitimate interests are balanced against individuals' rights and do not by themselves permit special-category health processing. A notice or acceptance of Terms does not constitute explicit health-data consent. Private fitness setup and diary saves have a separate explicit data choice; precise workout location and AI have their own choices. Manage these in Settings > Data and privacy. Withdrawing private fitness consent stops new cloud diary saves and edits; existing records remain available to read, export or delete. Stop an active GPS session in the tracker or switch off phone location permission; withdrawing location consent prevents new tracking and route saves. Challenge leaderboard participation uses its own opt-in and leave controls. General wellness features are not used to provide medical diagnosis, clinical treatment or insurance/employment eligibility decisions.

4. AI requests and providers

OpenAI processes food estimates and workout/coach requests. Meal requests include submitted images, descriptions, clarifications, locale/measurement preferences, barcode results and selected saved or corrected meal context (currently up to six meals). Workout planning uses your request, stated goals and experience, selected recent workouts (up to twelve), saved plan and programme/check-in context where relevant. Daily coaching can use up to twenty recent diary summaries. The automatic daily-coaching payload excludes GPS route geometry, media links and internal account identifiers; text you submit may itself contain identifying information. A hashed account safety identifier is sent; hashing does not make it anonymous. Text and images may themselves identify you. Do not include unnecessary medical records or other people's sensitive information.

Food analysis can use barcode/product lookups and provider web search. Product names, search terms and information visible in packaging may therefore be processed to retrieve supporting information. See the AI Notice and Provider Register.

Our AI requests ask OpenAI not to store responses as retrievable application state. That does not remove provider safety retention. OpenAI's standard API rules do not use customer inputs/outputs for general model training by default; abuse monitoring may retain content for up to 30 days, with legal/safety exceptions and endpoint-specific handling. SocialGryd saves selected outputs in your account until deleted under our retention rules. We do not authorise general foundation-model training on private user content.

AI food estimates and AI coaching have separate data choices before use and require an account date of birth showing age 18 or over during beta. You can withdraw either choice in Settings > Data and privacy. A recorded withdrawal stops new requests for that purpose; requests already sent cannot be recalled. Saved results and provider records follow the retention rules below. You can continue manual logging without agreeing to AI processing. Request correction of account details or deletion at legal@socialgryd.com.

5. Private records, location and chosen audiences

Private meal and workout records, including saved GPS routes, are stored for your account in Firebase and may also be cached on your device. They are not automatically public posts. Cloud providers process those records to operate the service. Google Maps/Places may receive requests, network/device information and coordinates or search text when mapping features are used, including map initialisation permitted by the app.

Publishing a post or session, joining a shared leaderboard, participating in a group or sharing a workout card can disclose your profile, chosen content, participation and activity totals to that feature's audience. Organisers may see information supplied for membership or participation, but group membership alone does not grant access to a private diary. Check the actual sharing control: public pages, events and share links may be accessible outside the app, and private-group participants can still copy content.

We do not sell private GPS routes or disclose them to unrelated advertisers. This is not a promise that no provider ever processes location. You can stop recording and revoke device permission; separately delete saved records and remove published information where available. Copies already received by others may remain. Do not publish your home location or sensitive routines.

6. Recipients and roles

Recipients include Google/Firebase for infrastructure, storage and delivery; OpenAI for requested AI features; Mux for video; Resend for email; Sentry (disabled in the new beta app) for configured app diagnostics; Better Stack for uptime/incident monitoring; Google for maps, sign-in and optional administrative Calendar integration; and Open Food Facts for product lookups. Limited portal location lookup also uses BigDataCloud. The Provider Register explains scope, roles, locations and vendor documents, with service-specific information and links to provider documents.

Other recipients are your chosen audience, authorised staff or contractors handling support/safety, independent organisers processing information you provide to them, professional advisers, and authorities where a valid legal basis permits or requires disclosure. Any transfer to a future operator or buyer must respect applicable notice and protection requirements. We do not sell personal data or use private health information for cross-context behavioural advertising, insurer scoring or employer screening.

Providers acting on our instructions are processors/data intermediaries; services such as independent sign-in, mapping, app stores and external websites may also act for their own purposes under their terms. This distinction does not remove SocialGryd's responsibility for disclosures it makes.

7. International processing

Data is not represented as Singapore-only. Application requests are processed by Google Cloud Functions in the United States. Production Firestore uses the US multi-region nam5. Point-in-time recovery retains up to seven days of database versions and scheduled backups are enabled. Storage, diagnostics and content delivery have service-specific locations and deletion cycles. Providers may use the United States, Europe and global delivery networks depending on service and account configuration. Contact us for information about the providers and safeguards applicable to your records.

Singapore transfers require protections meeting the PDPA's transfer requirements, including comparable protection where required. EU/UK transfers require an applicable adequacy arrangement or appropriate safeguards such as the relevant Standard Contractual Clauses and UK transfer instrument, together with any needed transfer assessment and supplementary measures. These protections remain necessary during beta. Request information about the safeguards applicable to your data at legal@socialgryd.com.

8. Retention and deletion

RecordsRetention approach
Account, private meals/workouts/routes, goals and saved AI plansKept to provide your account and history until deleted, subject to necessary legal/safety retention and provider deletion cycles
Posts, messages, clubs, sessions and participationKept for the relevant feature; deletion, expiry and group ownership may affect what remains. Other participants' independent copies are outside our control
Device step historyThe local tracker keeps a rolling history of up to 60 days; shared challenge totals are separate account records
Provider AI recordsProvider retention differs from saved account outputs; see Section 4
Diagnostics, monitoring and delivery logsLimited according to the provider's service settings and the need to investigate reliability, delivery or security
Reports, legal acceptances, transactions and claimsOnly as long as necessary for the relevant duty, dispute, safety purpose or lawful ban enforcement, with review
Backups and provider deletionDeletion from active systems is distinct from backup expiry. We do not promise a universal 90-day erasure period. Firebase documents up to 180 days for some authentication/installation data after a deletion request

Uninstalling the app does not delete the account. Use Account Deletion. We minimise retained exceptions and explain them where legally permitted. De-identified statistics may be retained only where they cannot reasonably identify someone.

9. Security and incidents

We use access rules, authenticated requests, transport protection and other safeguards appropriate to the service. Authorised operational access may be needed; private records and messages are not represented as end-to-end encrypted. No system guarantees security. Report vulnerabilities to security@socialgryd.com. We assess incidents and notify regulators and affected people when legally required.

10. Cookies, diagnostics and marketing

Optional website and app analytics are off until an affirmative choice in the beta app. Cookie preferences and the app's data/privacy controls allow changes. Essential authentication, security and service delivery are separate. Sentry (disabled in the new beta app) error diagnostics are separate from the analytics toggle. Automatic session tracking and performance sampling are disabled in this beta release; necessary error reports may still be sent. See the Cookie Policy.

You can opt out of marketing without losing core service access. Service/security messages are distinct from promotions. Device settings control notifications and whether sensitive notification previews appear on your lock screen. The contents of messages submitted to support may be handled by our email and support providers.

11. Young users

Account ages are set out in the Terms, including 16 for Singapore. A self-declared date of birth is not independent age verification. We do not knowingly permit accounts below the applicable minimum. Report suspected underage use to legal@socialgryd.com. Health, location and community features involving 16–17-year-olds require particular safeguards; an age gate alone is not a complete child-safety programme.

12. Rights and complaints

Contact legal@socialgryd.com for access, correction, consent withdrawal, export or deletion requests. We verify identity proportionately and do not request unnecessary identity documents. For Singapore requests, we respond as soon as reasonably possible; if access or correction cannot be completed within 30 days, we provide the required written timing update. Singapore access may include information about use/disclosure in the preceding year, subject to statutory exceptions. The PDPA does not create an unrestricted general erasure right; we also offer account deletion as a service.

Where EU/UK law applies, rights include access, correction, erasure, restriction, portability where eligible, objection to legitimate-interest processing and direct marketing, consent withdrawal and protection against qualifying solely automated decisions. Requests normally receive a response within one month; a permitted extension and its reasons are communicated within that first month. Exceptions and other applicable local deadlines may apply.

You may complain to Singapore's Personal Data Protection Commission, the competent authority in the EEA where you live/work or an infringement occurred, or the UK ICO where applicable. No Estonian lead authority is claimed. Exercise of a right does not result in retaliation, although withdrawing information necessary for a particular feature may prevent that feature working.

13. Automation and policy changes

Automated estimates, rankings, anti-abuse checks and moderation can make mistakes. See the AI Notice and Terms for review and appeal routes. Ask for human review where automation significantly affects you. We publish policy versions and notify material changes with reasonable advance notice, normally 30 days unless law or urgent safety requires otherwise. A new use requiring consent requires a new informed choice; publishing a policy does not retrospectively legitimise earlier processing.