Privacy Policy
GymTag is a United States pilot operated personally by Kahlil Padgham for adults age 18 or older. This policy covers the GymTag mobile app, API, and these public pages. Questions and requests go to safety@playgymtag.fit.
1. The private pilot
GymTag runs one-to-one fitness challenges between adults who already know each other. There is no participant directory for strangers. A participant shares a private handle directly, and only the two members of a rivalry can access its ordinary gameplay and authorized media.
2. Information GymTag handles
- Account and profile: email address, provider account identifier, private handle, display name, adult eligibility statement, and versions of rules and safety notices accepted.
- Fitness, gameplay, and content: challenge type, activity, target, measure, response window, safety selections, terms, decisions, deadlines, proof claims, disputes, scores, Letters, Completion points, belt state, written summaries, and uploaded video with embedded sound.
- Safety and moderation: reports, selected reason, optional private detail, blocks, keyed one-way email digests used to keep blocks effective after account recreation, safety exits, media state, moderation decisions, and action audit records.
- Support and operation: correspondence sent to the support address, session credentials, and network or operational records necessarily processed while delivering and protecting the service.
A selected video may contain metadata already in the file. GymTag does not intentionally extract location metadata. The app does not intentionally request Contacts, Location Services, HealthKit, Motion and Fitness, advertising identifiers, or tracking permission.
3. How information is collected and used
Information comes directly from participants when they sign in, build a profile, play, upload, report, block, request deletion, or contact support. The service also records the state transitions needed to authorize private access, enforce agreed deadlines, prevent unfair scoring, respond to reports, preserve blocks, and complete deletion.
GymTag uses this information only to authenticate participants; operate the private game; provide accessible written meaning for video; enforce safety, moderation, and fair-play controls; answer support; protect the service; and carry out deletion. The pilot runs no advertising, analytics, telemetry, or cross-app tracking. Participant content is not used for model training.
4. Who can access information
- The participant and rival can access the identity, terms, state, and authorized content needed for their shared rivalry. Blocking, quarantine, removal, or account deletion can stop that access.
- The operator can access bounded report and moderation records and content attached to a case. GymTag does not proactively inspect every video. Ordinary private video is not sent to an outside artificial-intelligence moderation service.
- Service providers process information only to provide their named function: Supabase for authentication, database, and private media storage; Render for API, worker, and operator-console hosting; Resend for sign-in email; and Forward Email plus Gmail/Google for support correspondence.
Kahlil remains responsible for limiting each provider's access and instructions to the stated service purpose. Each provider also publishes its own privacy and security terms. Information may be preserved or disclosed when required by a valid legal obligation. An evidence hold removes participant playback access; it does not make the content public.
5. Video, text, and moderation
Participants must follow the community rules for video, summaries, terms, and reports. Before each new video selection, the participant must confirm ownership or permission, recording consent for recognizable people, and that the video contains no prohibited content. Before participant-written terms, summaries, counters, proof alternatives, dispute clarifications, or retry adjustments become visible to a rival, GymTag runs the same deterministic safety filter; rejected output carries only a bounded category and never the submitted text.
Videos remain private to the rivalry unless access is needed for a report or legal obligation. GymTag does not proactively inspect every video or send ordinary private video to an outside artificial-intelligence moderation service. Each in-app report enters a durable operator case. Only content bound to that reported case can be opened or acted on there; the operator can quarantine it, place it under an evidence hold, release it, and resolve the report. These controls do not guarantee Apple approval; App Review decisions remain Apple's.
6. Retention
- Participant video remains while its owner's account is active unless the owner removes it. Removal immediately stops rival access.
- Confirmed account deletion immediately blocks product access and rival media playback. Active media is scheduled to clear within 30 days and backups within 90 days.
- Report evidence and closed report or support correspondence may remain for up to 180 days after closure.
- Operational logs target deletion after 30 days.
- Minimal gameplay results, policy and action audit records, and block-suppression records remain through the pilot and are scheduled for deletion within 180 days after the pilot ends.
A valid legal or evidence hold can delay deletion of the affected record. Held video is not playable to the rival. Account deletion, report evidence expiry, and pilot-end game, audit, and block-suppression cleanup are worker-driven through durable claimed jobs. Provider-managed backup, hosting-log, and support-mail jobs remain visibly open and are never recorded complete merely because time passed; completion requires restricted operator evidence from the provider.
7. Account and content deletion
A participant can remove owned media where the app offers that control and can start permanent account deletion at Account → Delete account. Confirmation raises an immediate API barrier, ends unresolved play without a Letter, winner, Completion point, or belt transfer, vacates a belt held by the deleting participant, and stops the rival from playing that participant's media.
The active-store process removes media and clears the participant's display name and handle. A rival may retain a minimal completed result identified only as involving a former player. Keyed block-suppression digests remain for the retention period above so deletion and recreation cannot defeat a block.
Provider authentication cleanup is a distinct deletion stage. The server revokes Supabase sessions and replaces the Auth email with a non-contactable deletion address before the request can report active-store completion. The app reports deletion stages rather than claiming that every backup or held copy is gone early.
8. Choices and requests
Participants can decline before acceptance, use Safety Exit after acceptance, report, block, remove eligible owned media, sign out, and initiate account deletion. For access, correction, appeal, takedown, privacy, or deletion questions, email safety@playgymtag.fit. Include an in-app identifier when useful, but do not email passwords, one-time codes, or video files.
9. Security
GymTag uses HTTPS outside local development, provider authentication, server-side authorization, private media storage, restricted operator access, and lifecycle states that deny playback when media is quarantined, held, revoked, deletion-pending, or deleted. Mobile clients do not receive database or private-storage administrative credentials. No storage or transmission method can be guaranteed completely secure.
10. Policy changes
This policy may change as the pilot changes. When an updated rule or acknowledgement is required for gameplay, GymTag's versioned policy controls require the current version before further scoring actions.
11. Contact
Operator and controller: Kahlil Padgham, operating personally in the United States.
Privacy, safety, and support: safety@playgymtag.fit.