Upp Privacy Policy

Last updated: 7 September 2026 · Version 2026-09-07-v1

This Privacy Policy explains how Upp ("Upp", "we", "us", "our") collects, uses, stores, shares and protects personal data when you use the Upp mobile application (the "App") or our website at glowupp.org (the "Website"). It is written in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the Slovenian Personal Data Protection Act (ZVOP-2) and the Google Play policies that apply to health and fitness apps. Please read it together with our Terms of Service.

1. Data controller

The controller of your personal data is:

Jakob Tominc

Butajnova 4a, 1354 Horjul, Slovenia

Data protection and privacy requests: jakob@glowupp.org

General support: info@glowupp.org

Website: glowupp.org

2. Data we collect

We only collect data that is necessary to provide the features you choose to use. Some data is required to use the App; other data is optional and collected only with your consent.

2.1 Account and profile data

2.2 Training, physical and nutrition data

2.3 Injury and medical condition data (special category data, Art. 9 GDPR)

You can voluntarily tell us that you have a medical condition or an injury (for example a knee injury or back pain) so we can adapt your workout plan and show "Active Recovery (Injury)" days. This information reveals your health and is therefore special category personal data under Article 9 of the GDPR. We process it only with your explicit consent, which we ask for separately in Settings → Adjust Plan every time you add this information. You can withdraw your consent at any time by turning the option off. Withdrawal does not affect processing that was already carried out lawfully.

This data is stored in your private account and is never shared publicly or with advertisers.

Body measurements and fitness metrics (height, weight, waist/neck/hips circumference, heart rate, step counts, workout performance) can in some cases be regarded as health-related data. Where such values are used to assess or infer fitness or health status, they are treated with the same protections described in this section and under the same explicit-consent regime where required; they are never used for advertising and never made public by your Community profile setting.

2.4 Health Connect data (special category data, Art. 9 GDPR)

If you connect Android Health Connect, we read only the data types you explicitly grant in the system permission dialogue. Depending on your permissions these can include: steps, active calories burned, distance, exercise sessions, heart rate, resting heart rate, weight, height, body fat and sleep.

Health Connect records are read on your device to show progress and to personalise your experience. Raw Health Connect records stay on your device, under the permissions you control. Only values you record in Upp itself (for example the average heart rate or distance of a run you save) are stored in your account.

The use of information received from Google Health API and/or Developer Tools will adhere to the Google Health API Developer and User Data Policy, including the Limited Use requirements: we never sell this data, never use it for advertising, never share it with third parties without your explicit consent, and never make it publicly visible — regardless of your Community profile visibility setting.

2.5 Running and location data

If you use the running feature we process GPS coordinates, your route, distance, duration, pace, speed and elevation. We request the location permission at runtime from the run screen, after you have seen an in-app explanation of how location is used. While a run is active we keep tracking in a visible foreground service notification; on Android you can also set location access to "Allow all the time" so that Upp can continue tracking the run in the background — even when the app is closed or not in use (for example while your phone is in your pocket or the screen is off). Background location is used only while a run is active, is never used for advertising, and you can change it at any time in Android system privacy settings. Routes and run summaries are stored in your private account (route points as a JSON file in private cloud storage). Mapbox receives your device location and map requests so that we can render your route on the map, and may receive anonymised telemetry (device type, operating system and approximate location) to improve its map products; Mapbox processes this data under its own privacy policy, and its attribution control in the app lets you manage telemetry preferences.

2.6 Community, social and gamification data

2.7 Technical and usage data

2.8 Camera and storage

The camera is used only to scan food product barcodes (CameraX + Google ML Kit). We do not capture, record or store any photos, videos or audio from the camera, and no camera image is ever uploaded. You can also enter a barcode manually without using the camera.

The avatar shown in the app is generated in the app (a stylised figure) and stored as a PNG file in your private Firebase Cloud Storage space together with its position and zoom settings. Route point files for runs are stored in the same private space. Access to these files is restricted to your account by storage security rules.

2.9 Website, waitlist and contact data

The Website does not use advertising cookies and we do not use Website data for behavioural advertising.

3. Why we process your data and the legal bases

PurposeDataLegal basis
Creating and operating your account, providing workouts, nutrition, running, Community and gamification featuresAccount, profile, training, nutrition, run, Community and gamification dataPerformance of a contract — Art. 6(1)(b) GDPR (where body or fitness metrics qualify as health data, the safeguards in section 2.3 also apply)
Adapting your plan to an injury or medical conditionInjury / medical condition dataYour explicit consent — Art. 9(2)(a) GDPR (separate, unticked consent)
Reading Health Connect data for progress and personalisationHealth Connect dataYour explicit consent — Art. 9(2)(a) GDPR, given through the Health Connect permission dialogue
Recording a runGPS location, route, paceYour consent — Art. 6(1)(a) GDPR, granted through the location permission
Optional usage analyticsPseudonymous usage events with no directly identifying fieldsYour consent — Art. 6(1)(a) GDPR, granted during onboarding or in Settings → Privacy; you can withdraw it at any time
Fixing crashes, protecting the service, preventing abuseCrash reports, technical dataLegitimate interest — Art. 6(1)(f) GDPR (balanced and limited to what is necessary)
Managing the early-access waitlist and sending confirmationEmail address, submission metadataYour consent — Art. 6(1)(a) GDPR, given when you submit the waitlist form; you can withdraw it at any time
Preventing automated or abusive Website submissionsOne-way IP hash and technical request dataLegitimate interest — Art. 6(1)(f) GDPR
Responding to Website enquiriesName, email address and messageSteps at your request / performance of a contract — Art. 6(1)(b) GDPR, or legitimate interest — Art. 6(1)(f), depending on the enquiry

4. Sharing with third parties

We do not sell your personal data, we do not show advertising and we never share health data with advertisers. We disclose data only to the service providers and other recipients below, each of which receives the minimum data needed to perform its task. Depending on the service and processing activity, a provider may act as our processor or as an independent controller under its own privacy terms.

Provider / recipientWhat it receivesWhere
Google LLC — Firebase Authentication, Firestore, Cloud Storage, Cloud Functions, Google Sign-In, CrashlyticsAccount credentials, profile and app data, uploaded images, run routes, crash diagnosticsGoogle Cloud infrastructure, partly in the US
MapboxDevice location and map/tile requests to render maps and routes; anonymised Mapbox telemetry (device type, OS, approximate location) for map improvementUS
FatSecretFood search terms and barcode queries, forwarded through our own authenticated Cloud Function proxyUS
Open Food FactsBarcode queries sent directly from the App to the public Open Food Facts APIFrance (EU)
PostHog (EU Cloud)Opt-in pseudonymous usage analytics events with no directly identifying fieldsEU
NetlifyWebsite requests, deployment and security logs, and execution of the waitlist functionsGlobal infrastructure, including the US
UpstashWaitlist email address, submission record, duplicate-protection hash and temporary abuse-prevention hashConfigured database region
ResendWaitlist email address and confirmation-email delivery metadataUS
FormspreeName, email address and the message submitted through the Website contact formUS
Google FontsStandard browser request data needed to deliver the Website fontGlobal infrastructure, including the US

5. International data transfers

Some of our infrastructure and processors are located outside the European Economic Area, in particular the United States (including Google/Firebase, Mapbox, FatSecret, Netlify, Resend and Formspree). Where personal data is transferred outside the EEA we rely on appropriate safeguards under Chapter V GDPR, in particular an applicable adequacy decision such as the EU–US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses. Upstash processes data in the database region we configure. PostHog EU Cloud and Open Food Facts process data within the EU.

6. Retention

7. Security

We implement appropriate technical and organisational measures, including:

No method of transmission or storage is completely secure. If you believe your account has been compromised, contact us immediately at info@glowupp.org.

8. Your rights

Under the GDPR and ZVOP-2 you have the right to:

To exercise any right, contact jakob@glowupp.org. We will respond within one month as required by the GDPR.

9. Children

Upp is intended for people aged 15 or older, in line with the Slovenian digital age of consent (Art. 8 GDPR and ZVOP-2). We do not knowingly collect personal data from children under 15 and we do not offer parental consent — instead, children under 15 are not allowed to use the App. If we become aware that an account belongs to a child under 15, we will terminate the account and delete the associated data.

10. Automated recommendations and decisions

Your training plan and some nutrition and gamification suggestions are generated by rule-based algorithms from the settings and data you provide. These are recommendations that you can always change or override; they are not decisions with legal or similarly significant effects and we do not use automated decision-making as defined in Art. 22 GDPR. We do not create advertising profiles.

11. Changes to this policy

If we make material changes, we will notify you in the App (through an in-app notice or a prompt) or on the Website before they take effect and update the version and date at the top of this document. Where a change requires new consent, we will ask for it before carrying out the relevant processing. If you disagree, you may stop using the service, withdraw consent where applicable, or delete your account.

12. Contact

Jakob Tominc — Upp

Butajnova 4a, 1354 Horjul, Slovenia

Privacy requests: jakob@glowupp.org

Support: info@glowupp.org

The use of information received from Google Health API and/or Developer Tools will adhere to the Google Health API Developer and User Data Policy, including the Limited Use requirements.