Privacy notice
Last updated February 2026
Draft — pending legal review. This document is a working draft written for the Grapplov private beta. It has not been reviewed by a qualified lawyer and should be professionally reviewed before public launch.
Who is responsible
[LEGAL BUSINESS NAME], trading as Grapplov, is the data controller for the personal data described here. Contact us through the app for any privacy request.
What we collect and why
Account data — your email address and authentication details, to create and secure your account (performance of our contract with you).
Training profile — name, age band, bodyweight, sport, experience, goal, equipment, grappling schedule, lifting availability and competition dates, to generate your programme (contract).
Training records — logged sets, loads, reps, RPE, pain flags and weekly recovery check-in answers, to adapt your programme deterministically (contract). This is health-related information you choose to enter; you can skip any field.
Product analytics — non-personal counts of app milestones such as pages viewed, signup, onboarding and checkout steps, to understand and improve conversion (legitimate interests). Analytics never include health details, pain reports, recovery answers, payment information or email addresses.
Payment records — subscription status, plan, period dates and the identifiers Paddle gives us. We never see or store your card details.
Who we share it with
Hosting and database infrastructure providers that run the app on our behalf; Paddle, our Merchant of Record, for the sale, subscription management, payment, tax compliance and invoicing of your purchase; professional advisers where necessary; and authorities where required by law. We do not sell your data or share it with advertisers.
Retention
We keep your account and training data while your account exists so your history stays intact between subscriptions. When you delete your account, your profile, programmes, workouts, logs and check-ins are deleted with it. Billing records are retained by Paddle for the period their legal and tax obligations require.
Your rights
You can access, correct, export, restrict, object to or delete your data. Export and deletion are self-service in Account. Where the GDPR applies you may also withdraw consent, request portability and complain to your supervisory authority; we respond to requests within one month.
International transfers and security
Some providers process data outside the UK/EEA; where they do, transfers rely on adequacy decisions or standard contractual clauses. We protect your data with encryption in transit, per-account database access rules and server-side authorisation on every protected request.
Cookies
We use only essential storage: the session that keeps you signed in and the storage the checkout needs. We do not use advertising or third-party tracking cookies.