Privacy Policy

Effective 1 January 2026 · Version 2.0

This Privacy Policy explains how Athivo (“we”, “us”, or “our”) collects, uses, shares, and protects your personal data when you use the Athivo mobile application and website at athivo.co.uk(together, “the Service”).

We are committed to protecting your personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. If you have questions or concerns, contact our Privacy Team at privacy@athivo.co.uk.

1. Who we are

Athivo is operated in the United Kingdom. For the purposes of UK data protection law, Athivo is the data controller of your personal information. You can contact us at privacy@athivo.co.uk.

2. Data we collect

We collect only what we need to operate the Service. Below is each category of personal data, what we collect, and why.

Account and profile data

  • Name, email address, and profile photo
  • Date of birth (to verify minimum age — 16+)
  • City, bio, pronouns, gender, and training experience level
  • Training goals, preferred activities, and availability schedule
  • Languages spoken and preferred training times
  • Fitness level and experience history
  • Sign-in method (Apple Sign-In or email)

Identity verification data

If you choose to complete identity verification, we collect:

  • A selfie or short video for liveness detection
  • A government-issued ID document (passport, driving licence) — processed by our third-party verification provider; we do not store raw document images
  • A verified badge status (true/false) recorded in your profile

Identity verification is voluntary. Raw biometric and document data is processed by our verification provider and is not stored on Athivo’s servers after verification is complete.

Activity and training data

  • Workout commitments you create, accept, or cancel
  • Sessions attended, missed, or cancelled
  • Accountability score and reliability statistics
  • Group memberships and roles
  • Events created, joined, or declined
  • Check-in confirmations for events and commitments
  • Training streak and consistency history

Location data

  • City (stored): The city you enter in your profile is stored and used for matching and discovery.
  • Approximate location (stored):If you set your location precision to “Neighbourhood”, only your general area is stored and shown to other users — not your exact address.
  • Address search (transient):If you use the GPS pin to suggest a meeting location when creating a group, your device’s GPS is used momentarily to reverse-geocode an address. Raw coordinates are converted to a street address and are not stored or transmitted to our servers.
  • Live location during events (when you opt in): If you enable live location sharing for a specific event, your real-time location is shared only with participants of that event for the duration of the event. Live location is not logged or stored after the event ends. You can disable live sharing at any time.

Messaging data

  • Messages you send and receive within Athivo
  • Message timestamps and read receipts
  • Conversation metadata (who you’ve messaged)

Messages are stored to enable the chat feature and are deleted when you delete your account. We do not read your messages except where required by law, safety necessity, or a valid report under our Community Guidelines.

Favourite locations

  • Gyms, parks, studios, and other training locations you save to your profile
  • These are stored as place names and optional addresses — no continuous location tracking is involved

Contacts (optional)

If you grant optional access to your device contacts, we use contact information solely to help you find people you already know on Athivo. Contact data is hashed and compared against Athivo accounts. We do not store your contacts’ data on our servers.

Payment data

  • Subscription status (Free or Plus)
  • Subscription renewal dates
  • Payment is processed by Apple or Google through their respective app stores. Card and payment details are handled entirely by Apple or Google — Athivo never sees or stores your payment card details.

Technical and device data

  • Device type, operating system, and app version
  • Crash reports and diagnostic data
  • Feature interaction analytics (e.g., screens viewed, features used)
  • Push notification tokens
  • IP address (logged temporarily for security purposes)
  • Session tokens and authentication data

3. Legal basis for processing

  • Contract (Article 6(1)(b)): To provide you with the Athivo Service, including matching, commitments, groups, events, messaging, and subscription features.
  • Legitimate interests (Article 6(1)(f)): To improve the app, detect and prevent fraud and abuse, maintain security, and send product updates. Our legitimate interests do not override your rights.
  • Consent (Article 6(1)(a)): For push notifications, location access, camera access, photo library access, and contact list access. You may withdraw consent at any time in your device Settings, though this may limit some features.
  • Legal obligation (Article 6(1)(c)): Where required by UK law, including tax record-keeping and responding to law enforcement requests.
  • Biometric data (Schedule 1 DPA 2018): Identity verification involving biometric processing is conducted with your explicit consent. You may use Athivo without completing verification.

4. How we use your data

  • To create and maintain your account and profile
  • To match you with compatible training partners
  • To facilitate commitments, groups, events, and messaging
  • To calculate and display your accountability score
  • To enable live location sharing when you choose to attend events
  • To process subscription status via Apple or Google
  • To send push notifications about matches, commitments, and events
  • To identify and prevent fake accounts and abusive behaviour
  • To improve the app and diagnose technical issues
  • To comply with legal obligations and respond to lawful requests
  • To conduct identity verification (when you choose to verify)

5. Third-party services

We share data with the following trusted third parties, each with whom we maintain appropriate Data Processing Agreements (DPAs) where required:

  • Supabase (EU) — Database, authentication, and storage infrastructure. Data is stored on servers in the European Union.
  • Stripe — Stripe is used only for internal analytics of subscription status passed from Apple/Google. We do not process card payments through Stripe directly.
  • PostHog (EU-hosted) — Product analytics. Data is anonymised where possible and processed on EU infrastructure.
  • Google Maps Platform — Address autocomplete and reverse geocoding. Google receives search queries and coordinates during address lookup only.
  • Apple / Google — Push notifications (via APNs / FCM), Sign-In with Apple, and in-app subscription billing.
  • Expo — Mobile app build infrastructure and over-the-air updates.
  • Identity verification provider (Persona / Veriff) — When you choose to complete identity verification. Your ID document and selfie are processed by the verification provider under their own privacy policy. Raw verification data is not transferred to Athivo after the result is determined.

We do not sell, rent, or share your personal data with advertisers or data brokers.

6. International data transfers

We store your data on servers operated by Supabase, located within the European Union. EU data protection law is recognised as providing an adequate level of protection under UK GDPR (Article 45). Where any transfer outside the UK/EU is necessary (e.g., for push notification delivery via Apple or Google), we rely on Standard Contractual Clauses or other appropriate safeguards.

7. Data retention

  • Active account data — retained for as long as your account is active.
  • Live location — not retained; cleared at the end of each event session.
  • Messages — retained until you delete your account. Deleted within 30 days of account deletion.
  • Identity verification — verification status (verified/not) is stored in your profile. Raw biometric and document data is retained only for the verification session and is not stored by Athivo.
  • Analytics — anonymised aggregate analytics may be retained indefinitely. Personal analytics are deleted with your account.
  • Financial records — transaction records required for UK tax purposes may be retained for up to 7 years.
  • Crash and security logs — retained for up to 90 days.
  • Deleted accounts — personal data is permanently removed within 30 days of account deletion.

8. Your rights under UK GDPR

You have the following rights:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Correct inaccurate or incomplete data.
  • Erasure: Request deletion of your data. See our account deletion page for details.
  • Restriction: Ask us to pause processing of your data.
  • Portability: Receive a structured, machine-readable export of your personal data (available via Profile → Download My Data in the app).
  • Objection: Object to processing based on legitimate interests.
  • Withdraw consent: Withdraw consent for location, notifications, camera, or contacts at any time in your device Settings.
  • Automated decision-making: Our matching uses automated scoring. You can request a review of any automated decision that significantly affects you.

To exercise any right, email privacy@athivo.co.uk. We will respond within 30 days. You have the right to lodge a complaint with the Information Commissioner’s Office (ICO).

9. Security

We protect your data with:

  • TLS encryption for all data in transit
  • Encrypted storage at rest for the database and file storage
  • Row-level security (RLS) — users can only access their own data
  • Multi-factor authentication for all administrative access to our infrastructure
  • Regular dependency and vulnerability audits
  • Access to personal data limited to authorised personnel only

If you discover a security vulnerability, please report it to privacy@athivo.co.uk. We aim to respond within 72 hours.

10. Children’s privacy

Athivo is not intended for users under the age of 16. We do not knowingly collect personal data from children. If you believe a child has created an account or submitted their data, please contact us immediately at privacy@athivo.co.uk and we will delete the data promptly.

11. Cookies and tracking

The Athivo mobile app does not use browser cookies. The Athivo website (athivo.co.uk) uses only functional, first-party cookies necessary to serve the site. No advertising, tracking, or third-party marketing cookies are used on our website.

Within the app, we use PostHog (EU-hosted) for anonymous product analytics. No cross-app tracking or advertising identifiers (IDFA/GAID) are used.

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified via in-app notice or email at least 14 days before they take effect. The current version is always available at athivo.co.uk/privacy.

13. Contact

Data controller: Athivo, United Kingdom
Privacy enquiries: privacy@athivo.co.uk
General support: support@athivo.co.uk
Response time: within 2 business days for general queries; within 30 days for formal rights requests.