BEARSCAR Get the app

Privacy Policy

Privacy

Last updated · July 10, 2026

BEARSCAR is a social challenge app. We use your data to run accounts, challenges, leaderboards, notifications, integrations, safety tools, and support. In the current launch_free mode no purchase is required. If a paid soft_pro or pro_live mode is enabled after legal and release approval, purchase processing uses Apple App Store or Google Play with RevenueCat. We do not sell your personal information.

Information we collect

How we use information

Legal bases for processing

Under the GDPR, we rely on the following legal bases: performing our contract with you to provide your account, challenges and social features (Art. 6(1)(b)); your consent for optional features such as push notifications and a public profile (Art. 6(1)(a)); and our legitimate interests in security, abuse prevention and debugging (Art. 6(1)(f)). We rely on contract/request steps or legitimate interests to answer enquiries, and consent for any optional public-site analytics. Minimized mobile product/usage telemetry is processed on our legitimate interests in understanding and improving BEARSCAR (Art. 6(1)(f)), subject to a balancing assessment and your Art. 21 right to object. When store purchase processing is enabled, subscription and entitlement handling is necessary to perform our contract with you (Art. 6(1)(b)). Health and fitness data imported from Apple Health and Google Health Connect is a special category of data and is processed only with your explicit consent (Art. 9(2)(a)), which we capture separately for each source and which you can withdraw at any time.

Visibility and sharing

BEARSCAR is social by design. Your profile, avatar, username, challenge participation, progress, comments, reactions, badges, and leaderboard results may be visible to friends, challenge participants, squads, leagues, or users who receive a share link, depending on the feature and privacy context. We do not sell your personal information.

Integrations and providers

We use trusted providers to run BEARSCAR, including Supabase for authentication and data storage (EU region), Vercel for public/admin hosting and serverless delivery, Resend for delivering support requests, Expo for app infrastructure and push notifications, Sentry for diagnostics (no health data is sent), the Apple App Store and Google Play for distribution, Apple HealthKit when you grant permission on iOS, and Google Health Connect when you grant permission on Android. RevenueCat is used only when purchase processing is enabled, or when historical provider evidence must be erased, for subscription/entitlement reconciliation and provider-customer erasure. Paid mode remains blocked until the applicable RevenueCat processor agreement and transfer safeguards are approved. An OpenAI-backed, admin-only read-only assistant is disabled by default. If approved and enabled, it receives only minimized/redacted operational context; we do not intentionally send health data, raw identifiers, tokens, or passwords, and it does not make automated decisions about users. Where a provider is involved only for cleanup, new Strava connections remain disabled; Strava receives a token solely to revoke any historical authorisation after withdrawal or deletion. Where a provider is outside the EEA, transfers are protected by EU Standard Contractual Clauses and applicable additional safeguards.

Health and workout data

Apple Health/HealthKit (iOS) and Google Health Connect (Android) access is optional. BEARSCAR only reads workout sessions and, when a challenge needs them, daily step and floor totals; it never writes data back to Apple Health or Health Connect. You can change Apple Health / Health Connect permissions from your device settings. Revoking an operating-system read permission stops the affected reads but is not, by itself, a deletion request. To withdraw BEARSCAR's consent record and delete data already imported from that source, use Settings → Integrations in the app. You can also contact us if you want imported activity data reviewed or deleted.

Data retention and deletion

Data security

We use authentication, access controls, infrastructure security, and operational monitoring to protect user data. No storage or transmission method is perfect, but we work to keep BEARSCAR protected and to limit access to what is needed to operate the service.

Your rights and choices

Under the GDPR you have the right to access, rectify, erase, restrict or object to processing, data portability, and to withdraw consent. You can exercise the main rights directly in the app:

You also have the right to lodge a complaint with your supervisory authority. In Norway this is Datatilsynet (datatilsynet.no).

Children

BEARSCAR is intended for users aged 16 and older. If you believe someone under 16 has provided personal information, contact us so we can review and remove it when appropriate.

Contact

The data controller is baert AS (org. no. 936 033 245), registered in Norway (Foretaksregisteret), Oslo. We have not appointed a Data Protection Officer, as we are not required to under GDPR Art. 37; privacy enquiries go to the address below. As the controller is established in the EEA, no Article 27 representative is required. For privacy questions, access, correction, or deletion requests, email privacy@bearscar.org or use the privacy contact form.