Upp Privacy Policy
This Privacy Policy explains how Upp ("Upp", "we", "us", "our") collects, uses, stores, shares and protects personal data when you use the Upp mobile application (the "App") or our website at glowupp.org (the "Website"). It is written in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the Slovenian Personal Data Protection Act (ZVOP-2) and the Google Play policies that apply to health and fitness apps. Please read it together with our Terms of Service.
1. Data controller
The controller of your personal data is:
Jakob Tominc
Butajnova 4a, 1354 Horjul, Slovenia
Data protection and privacy requests: jakob@glowupp.org
General support: info@glowupp.org
Website: glowupp.org
2. Data we collect
We only collect data that is necessary to provide the features you choose to use. Some data is required to use the App; other data is optional and collected only with your consent.
2.1 Account and profile data
- Required: email address, password or Google Sign-In account (authentication is handled by Firebase Authentication; we never store your raw password), username (which is also your public display name), gender, date of birth / age, height, weight, and the training data listed below.
- Optional: waist, neck and hips circumference, training experience, personal records, preferred workout time, community bio (currently disabled), and the avatar image mentioned in section 2.8.
2.2 Training, physical and nutrition data
- Activity level, main goal, target training days per week, available equipment.
- Your workout plans, completed workouts, set-by-set performance, personal records, workout history and progress.
- Food logs, water intake, calories, macros and micronutrients, entered manually or scanned from a product barcode using your camera.
2.3 Injury and medical condition data (special category data, Art. 9 GDPR)
You can voluntarily tell us that you have a medical condition or an injury (for example a knee injury or back pain) so we can adapt your workout plan and show "Active Recovery (Injury)" days. This information reveals your health and is therefore special category personal data under Article 9 of the GDPR. We process it only with your explicit consent, which we ask for separately in Settings → Adjust Plan every time you add this information. You can withdraw your consent at any time by turning the option off. Withdrawal does not affect processing that was already carried out lawfully.
This data is stored in your private account and is never shared publicly or with advertisers.
Body measurements and fitness metrics (height, weight, waist/neck/hips circumference, heart rate, step counts, workout performance) can in some cases be regarded as health-related data. Where such values are used to assess or infer fitness or health status, they are treated with the same protections described in this section and under the same explicit-consent regime where required; they are never used for advertising and never made public by your Community profile setting.
2.4 Health Connect data (special category data, Art. 9 GDPR)
If you connect Android Health Connect, we read only the data types you explicitly grant in the system permission dialogue. Depending on your permissions these can include: steps, active calories burned, distance, exercise sessions, heart rate, resting heart rate, weight, height, body fat and sleep.
Health Connect records are read on your device to show progress and to personalise your experience. Raw Health Connect records stay on your device, under the permissions you control. Only values you record in Upp itself (for example the average heart rate or distance of a run you save) are stored in your account.
The use of information received from Google Health API and/or Developer Tools will adhere to the Google Health API Developer and User Data Policy, including the Limited Use requirements: we never sell this data, never use it for advertising, never share it with third parties without your explicit consent, and never make it publicly visible — regardless of your Community profile visibility setting.
2.5 Running and location data
If you use the running feature we process GPS coordinates, your route, distance, duration, pace, speed and elevation. We request the location permission at runtime from the run screen, after you have seen an in-app explanation of how location is used. While a run is active we keep tracking in a visible foreground service notification; on Android you can also set location access to "Allow all the time" so that Upp can continue tracking the run in the background — even when the app is closed or not in use (for example while your phone is in your pocket or the screen is off). Background location is used only while a run is active, is never used for advertising, and you can change it at any time in Android system privacy settings. Routes and run summaries are stored in your private account (route points as a JSON file in private cloud storage). Mapbox receives your device location and map requests so that we can render your route on the map, and may receive anonymised telemetry (device type, operating system and approximate location) to improve its map products; Mapbox processes this data under its own privacy policy, and its attribution control in the app lets you manage telemetry preferences.
2.6 Community, social and gamification data
- Your posts (currently text only; no photos or videos are supported), likes, followers, follows, blocked accounts, and interactions with other users.
- XP, level, streaks, badges, achievements, challenge results, leaderboard entries, gems and in-app credits.
- Your Community profile visibility choice: Private, Friends only or Public. New accounts are Private by default. When your profile is Private, neither your profile nor your activity is visible to other users.
2.7 Technical and usage data
- Crash reports (Firebase Crashlytics): app and device version, operating system, installation identifiers, technical error context and stack traces. We do not intentionally include your name, email, routes, food entries or health measurements in crash reports.
- Usage analytics (PostHog EU Cloud): started only if you explicitly opt in during onboarding or from Settings → Privacy. Events are pseudonymously linked to your internal Firebase user ID (never your name, email or username) and may include screen names, feature usage and high-level attributes (for example your main goal or preferred units). They never include GPS coordinates, routes, meal names, body measurements, health readings or photos. Session replay, advertising storage and personalisation are disabled and we do not use analytics for advertising.
- Network and security: IP addresses and other standard technical data processed by our infrastructure (Firebase/Google Cloud) to operate and secure the service.
- Notifications: we send reminders (workout, meals, water, streaks) as local notifications on your device. We do not send push messages through a third-party push provider and we do not collect push notification tokens.
2.8 Camera and storage
The camera is used only to scan food product barcodes (CameraX + Google ML Kit). We do not capture, record or store any photos, videos or audio from the camera, and no camera image is ever uploaded. You can also enter a barcode manually without using the camera.
The avatar shown in the app is generated in the app (a stylised figure) and stored as a PNG file in your private Firebase Cloud Storage space together with its position and zoom settings. Route point files for runs are stored in the same private space. Access to these files is restricted to your account by storage security rules.
2.9 Website, waitlist and contact data
- Waitlist: if you join the early-access waitlist, we collect your email address, submission time and source. We use a one-way hash of your email to prevent duplicate registrations. We also use a shortened one-way hash of your IP address to enforce a per-hour abuse limit; the rate-limit record expires after one hour. The public waitlist counter shows only an aggregate number and never exposes email addresses.
- Confirmation email: for a new waitlist registration, we send your email address to Resend so it can deliver the confirmation message.
- Contact form: if you contact us through the Website, we process your name, email address and message so we can respond. The form is delivered through Formspree.
- Website delivery and security: Netlify processes standard request information such as IP address, browser/device information, requested URL, timestamps and security logs when it hosts and protects the Website. Upstash stores the waitlist records. Your browser may also connect to Google Fonts to download the Website typeface, which exposes standard request information such as your IP address to Google.
The Website does not use advertising cookies and we do not use Website data for behavioural advertising.
3. Why we process your data and the legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Creating and operating your account, providing workouts, nutrition, running, Community and gamification features | Account, profile, training, nutrition, run, Community and gamification data | Performance of a contract — Art. 6(1)(b) GDPR (where body or fitness metrics qualify as health data, the safeguards in section 2.3 also apply) |
| Adapting your plan to an injury or medical condition | Injury / medical condition data | Your explicit consent — Art. 9(2)(a) GDPR (separate, unticked consent) |
| Reading Health Connect data for progress and personalisation | Health Connect data | Your explicit consent — Art. 9(2)(a) GDPR, given through the Health Connect permission dialogue |
| Recording a run | GPS location, route, pace | Your consent — Art. 6(1)(a) GDPR, granted through the location permission |
| Optional usage analytics | Pseudonymous usage events with no directly identifying fields | Your consent — Art. 6(1)(a) GDPR, granted during onboarding or in Settings → Privacy; you can withdraw it at any time |
| Fixing crashes, protecting the service, preventing abuse | Crash reports, technical data | Legitimate interest — Art. 6(1)(f) GDPR (balanced and limited to what is necessary) |
| Managing the early-access waitlist and sending confirmation | Email address, submission metadata | Your consent — Art. 6(1)(a) GDPR, given when you submit the waitlist form; you can withdraw it at any time |
| Preventing automated or abusive Website submissions | One-way IP hash and technical request data | Legitimate interest — Art. 6(1)(f) GDPR |
| Responding to Website enquiries | Name, email address and message | Steps at your request / performance of a contract — Art. 6(1)(b) GDPR, or legitimate interest — Art. 6(1)(f), depending on the enquiry |
4. Sharing with third parties
We do not sell your personal data, we do not show advertising and we never share health data with advertisers. We disclose data only to the service providers and other recipients below, each of which receives the minimum data needed to perform its task. Depending on the service and processing activity, a provider may act as our processor or as an independent controller under its own privacy terms.
| Provider / recipient | What it receives | Where |
|---|---|---|
| Google LLC — Firebase Authentication, Firestore, Cloud Storage, Cloud Functions, Google Sign-In, Crashlytics | Account credentials, profile and app data, uploaded images, run routes, crash diagnostics | Google Cloud infrastructure, partly in the US |
| Mapbox | Device location and map/tile requests to render maps and routes; anonymised Mapbox telemetry (device type, OS, approximate location) for map improvement | US |
| FatSecret | Food search terms and barcode queries, forwarded through our own authenticated Cloud Function proxy | US |
| Open Food Facts | Barcode queries sent directly from the App to the public Open Food Facts API | France (EU) |
| PostHog (EU Cloud) | Opt-in pseudonymous usage analytics events with no directly identifying fields | EU |
| Netlify | Website requests, deployment and security logs, and execution of the waitlist functions | Global infrastructure, including the US |
| Upstash | Waitlist email address, submission record, duplicate-protection hash and temporary abuse-prevention hash | Configured database region |
| Resend | Waitlist email address and confirmation-email delivery metadata | US |
| Formspree | Name, email address and the message submitted through the Website contact form | US |
| Google Fonts | Standard browser request data needed to deliver the Website font | Global infrastructure, including the US |
5. International data transfers
Some of our infrastructure and processors are located outside the European Economic Area, in particular the United States (including Google/Firebase, Mapbox, FatSecret, Netlify, Resend and Formspree). Where personal data is transferred outside the EEA we rely on appropriate safeguards under Chapter V GDPR, in particular an applicable adequacy decision such as the EU–US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses. Upstash processes data in the database region we configure. PostHog EU Cloud and Open Food Facts process data within the EU.
6. Retention
- Active accounts: your profile, training, nutrition and run data are kept as long as your account is active.
- Account deletion: when you delete your account (see section 8), your profile, credentials and personal data are removed from the active production systems within a short processing period. Temporary backup copies on Google infrastructure may remain for up to 30 days before they are overwritten or deleted.
- Public Community content after deletion: to preserve the integrity of conversations, your public posts are kept but anonymised (author, username and avatar replaced with "[deleted]" and an anonymised identity) rather than removed. You can permanently delete your own posts at any time before deleting your account.
- Deletion audit log: technical deletion records (user ID, status, time, anonymised error text) are kept for 180 days, after which they are deleted automatically.
- Crash reports: Firebase Crashlytics deletes crash reports after 90 days.
- Analytics: PostHog events are kept for the retention period configured in our PostHog project (currently 12 months from collection), after which they are deleted. You can opt out or request deletion earlier via the contact details below.
- Local caches: the food catalogue cache is stored on your device for at most 24 hours, in line with the FatSecret developer terms.
- Waitlist: we retain your waitlist record until early-access invitations have been completed, you withdraw your consent, or you ask us to delete it. Temporary abuse-prevention records expire after one hour. Resend and infrastructure delivery logs follow the applicable provider retention settings.
- Contact enquiries: we retain messages only as long as reasonably necessary to respond, maintain an appropriate record of the enquiry and establish or defend legal claims.
7. Security
We implement appropriate technical and organisational measures, including:
- Encryption of data in transit (TLS/HTTPS) and encryption at rest by our cloud providers (Firestore, Cloud Storage).
- Firebase Authentication with password hashing; we never see or store your raw password.
- Firestore security rules that restrict access to your data to your own account (and to legitimate public Community data you publish), app attestation with Firebase App Check / Play Integrity, and least-privilege access in Cloud Functions.
- Android file-based encryption for data stored on your device.
No method of transmission or storage is completely secure. If you believe your account has been compromised, contact us immediately at info@glowupp.org.
8. Your rights
Under the GDPR and ZVOP-2 you have the right to:
- Access — receive a copy of the personal data we hold about you;
- Rectification — correct inaccurate data (you can also do this in Profile settings);
- Erasure — delete your account and associated data in the App through Settings → Delete Account, or request deletion by emailing jakob@glowupp.org;
- Restriction of processing and objection to processing based on legitimate interests;
- Data portability — receive your data in a structured, machine-readable format;
- Withdraw consent at any time: location (device settings), analytics (Settings → Privacy), Health Connect (Settings → Health Connect), injury data (Settings → Adjust Plan);
- Lodge a complaint with the Slovenian Information Commissioner (ip-rs.si) or your local supervisory authority.
To exercise any right, contact jakob@glowupp.org. We will respond within one month as required by the GDPR.
9. Children
Upp is intended for people aged 15 or older, in line with the Slovenian digital age of consent (Art. 8 GDPR and ZVOP-2). We do not knowingly collect personal data from children under 15 and we do not offer parental consent — instead, children under 15 are not allowed to use the App. If we become aware that an account belongs to a child under 15, we will terminate the account and delete the associated data.
10. Automated recommendations and decisions
Your training plan and some nutrition and gamification suggestions are generated by rule-based algorithms from the settings and data you provide. These are recommendations that you can always change or override; they are not decisions with legal or similarly significant effects and we do not use automated decision-making as defined in Art. 22 GDPR. We do not create advertising profiles.
11. Changes to this policy
If we make material changes, we will notify you in the App (through an in-app notice or a prompt) or on the Website before they take effect and update the version and date at the top of this document. Where a change requires new consent, we will ask for it before carrying out the relevant processing. If you disagree, you may stop using the service, withdraw consent where applicable, or delete your account.
12. Contact
Jakob Tominc — Upp
Butajnova 4a, 1354 Horjul, Slovenia
Privacy requests: jakob@glowupp.org
Support: info@glowupp.org
The use of information received from Google Health API and/or Developer Tools will adhere to the Google Health API Developer and User Data Policy, including the Limited Use requirements.