Privacy Policy
Privacy
BEARSCAR is a social challenge app. We use your data to run accounts, challenges,
leaderboards, notifications, integrations, safety tools, and support. In the current
launch_free mode no purchase is required. If a paid soft_pro or
pro_live mode is enabled after legal and release approval, purchase
processing uses Apple App Store or Google Play with RevenueCat. We do not sell your
personal information.
Information we collect
- Email address and authentication data used to sign in and secure your account.
- Profile data such as full name, username, avatar, bio, ambassador or badge status.
- Challenge and activity data such as goals, exercises, logs, progress, scores, wins, streaks, deadlines, teams, squads, leagues, invites, and leaderboard placement.
- Social content such as friends, participants, comments, reactions, reports, blocks, and media you upload or attach to activity.
- Device notification tokens and notification preferences if you enable push alerts.
- Apple Health or HealthKit data on iOS, and Google Health Connect data on Android, if you explicitly allow access on your device.
- Diagnostics, crash reports, device information, and security logs used to operate and protect the app.
- Support enquiry data such as your name, reply email, optional organization and BEARSCAR account email, topic, subject, message, and the page where you submitted the request. Do not send passwords, recovery codes, or health data through the form.
- For signed-in mobile users, minimized, account-linked product and usage telemetry: an allowlisted event name, timestamp, coarse app/build/platform/language/country context, and controlled product dimensions, counts, and booleans. The allowlist excludes free text, entity identifiers, URLs, tokens or secrets, and raw health/workout measurements.
- Vercel handles limited request and network metadata to deliver and protect the public website. Optional first-party site analytics stays off unless you consent and we enable consented mode; if enabled, it uses minimized page/device data and pseudonymous identifiers, not advertising profiles.
-
In
soft_proorpro_liveonly, store, product, subscription/entitlement status, provider timestamps, and transaction references needed to process or restore access. Apple or Google handles payment; BEARSCAR does not receive payment-card details.
How we use information
- Create, authenticate, sync, and protect your account.
- Run solo, duel, free-for-all, team, co-op, squad, and league challenge features.
- Show progress, leaderboards, activity feeds, comments, reactions, badges, and profile stats.
- Send notifications about invites, friend requests, challenge activity, wins, reminders, and account events.
- Keep features working reliably and prevent abuse.
- Investigate reports, enforce community rules, troubleshoot issues, and improve reliability.
- Answer and protect support, privacy, legal, press, and business enquiries.
- Process and reconcile an enabled store purchase or subscription.
- Measure use of mobile features and improve the product using minimized telemetry.
Legal bases for processing
Under the GDPR, we rely on the following legal bases: performing our contract with you to provide your account, challenges and social features (Art. 6(1)(b)); your consent for optional features such as push notifications and a public profile (Art. 6(1)(a)); and our legitimate interests in security, abuse prevention and debugging (Art. 6(1)(f)). We rely on contract/request steps or legitimate interests to answer enquiries, and consent for any optional public-site analytics. Minimized mobile product/usage telemetry is processed on our legitimate interests in understanding and improving BEARSCAR (Art. 6(1)(f)), subject to a balancing assessment and your Art. 21 right to object. When store purchase processing is enabled, subscription and entitlement handling is necessary to perform our contract with you (Art. 6(1)(b)). Health and fitness data imported from Apple Health and Google Health Connect is a special category of data and is processed only with your explicit consent (Art. 9(2)(a)), which we capture separately for each source and which you can withdraw at any time.
Visibility and sharing
BEARSCAR is social by design. Your profile, avatar, username, challenge participation, progress, comments, reactions, badges, and leaderboard results may be visible to friends, challenge participants, squads, leagues, or users who receive a share link, depending on the feature and privacy context. We do not sell your personal information.
Integrations and providers
We use trusted providers to run BEARSCAR, including Supabase for authentication and data storage (EU region), Vercel for public/admin hosting and serverless delivery, Resend for delivering support requests, Expo for app infrastructure and push notifications, Sentry for diagnostics (no health data is sent), the Apple App Store and Google Play for distribution, Apple HealthKit when you grant permission on iOS, and Google Health Connect when you grant permission on Android. RevenueCat is used only when purchase processing is enabled, or when historical provider evidence must be erased, for subscription/entitlement reconciliation and provider-customer erasure. Paid mode remains blocked until the applicable RevenueCat processor agreement and transfer safeguards are approved. An OpenAI-backed, admin-only read-only assistant is disabled by default. If approved and enabled, it receives only minimized/redacted operational context; we do not intentionally send health data, raw identifiers, tokens, or passwords, and it does not make automated decisions about users. Where a provider is involved only for cleanup, new Strava connections remain disabled; Strava receives a token solely to revoke any historical authorisation after withdrawal or deletion. Where a provider is outside the EEA, transfers are protected by EU Standard Contractual Clauses and applicable additional safeguards.
Health and workout data
Apple Health/HealthKit (iOS) and Google Health Connect (Android) access is optional. BEARSCAR only reads workout sessions and, when a challenge needs them, daily step and floor totals; it never writes data back to Apple Health or Health Connect. You can change Apple Health / Health Connect permissions from your device settings. Revoking an operating-system read permission stops the affected reads but is not, by itself, a deletion request. To withdraw BEARSCAR's consent record and delete data already imported from that source, use Settings → Integrations in the app. You can also contact us if you want imported activity data reviewed or deleted.
- Exercise sessions: BEARSCAR reads workout type, start/end time and source for running, walking and cycling sessions so eligible workouts can count in challenges.
- Distance: BEARSCAR reads distance for those running, walking and cycling sessions to score distance-based challenges.
- Steps: BEARSCAR reads daily step totals only for active step challenges or when you enable step auto-log.
- Floors climbed: BEARSCAR reads daily floors-climbed totals only for active floors challenges or when you enable floors auto-log.
- Not collected: BEARSCAR does not read heart rate, sleep, calories, routes or cadence values, and never writes data back to Health Connect.
Data retention and deletion
- Account, profile, challenge, activity, social, purchase entitlement, and support data is kept until you delete your account, or an authorized administrator deletes it at your request or where legally permitted. We do not currently delete accounts automatically because of inactivity. If we introduce an inactivity-deletion routine, we will update this policy and notify affected users before it is activated.
- When you delete your account, access is revoked and account-linked rows in the live database are deleted transactionally, including profile data, activity logs, comments, reactions, friendships, notification tokens, imported health or workout data, and authentication data. Associated storage objects are then removed by an automated, monitored retry queue and cannot be accessed through the deleted account while cleanup is pending. If a historical Strava authorisation exists, the same local transaction replaces the live credential with a restricted AES-256-GCM-encrypted revocation job before deleting the connection. A monitored worker retries temporary Strava failures without storing or logging the credential in plaintext, and redacts the ciphertext when Strava confirms revocation. A Strava outage therefore does not delay local account deletion or lose the ability to retry. If RevenueCat evidence exists, a restricted worker deletes the provider customer and verifies completion; the customer UUID is kept only while unresolved, nulled on completion, and completed job metadata is removed after 30 days. Limited cleanup metadata is retained temporarily to operate and verify retries. Encrypted backups remain only for the hosting provider's limited backup window and are then overwritten, unless a legal hold applies.
- Deleting your BEARSCAR account or RevenueCat customer record does not cancel an Apple App Store or Google Play subscription or stop renewal. Cancel it separately in the store's subscription settings.
- Imported Apple Health/HealthKit or Google Health Connect workout data is kept while your BEARSCAR consent for that source remains active. Database records are deleted and associated media is queued for monitored deletion when you withdraw that consent in Settings → Integrations or delete your account. Revoking only an operating-system read permission stops affected future reads but does not automatically delete data already imported into BEARSCAR.
- Mobile product/usage telemetry is stored in Supabase for 90 days and remains account-linked during that period unless erased earlier where required. Other operational records are limited: notifications for 60 days, sent or failed notification queue records for 14 days, public share events for 60 days, and audit or security logs for 365 days.
- Optional consented public-site analytics, if enabled after consent/legal approval, is kept for 90 days.
- Crash and error reports are generally kept for up to 90 days unless we need them longer to investigate security, fraud, abuse, legal, or service-integrity issues.
- Support correspondence is kept only as long as needed to answer the request and meet applicable security, dispute, or legal obligations.
- Limited records may be retained when required for security, fraud prevention, legal compliance, dispute handling, purchase or accounting obligations, or abuse investigation. Retained records are not used to operate a public BEARSCAR profile.
- Anonymous, aggregated metrics that no longer identify a user may be retained indefinitely.
Data security
We use authentication, access controls, infrastructure security, and operational monitoring to protect user data. No storage or transmission method is perfect, but we work to keep BEARSCAR protected and to limit access to what is needed to operate the service.
Your rights and choices
Under the GDPR you have the right to access, rectify, erase, restrict or object to processing, data portability, and to withdraw consent. You can exercise the main rights directly in the app:
- Export your data: Settings → export your data (machine-readable JSON).
- Delete your account and all associated data: app settings, or request deletion at bearscar.org/account-deletion.
- Withdraw health-data consent: Settings → Integrations (or revoke in device settings).
- Update your profile, and disable notifications in app or device settings.
- Contact us for any privacy, access, correction, or deletion request.
- Object to mobile product/usage telemetry processed on legitimate interests (GDPR Art. 21) by contacting us at privacy@bearscar.org. We will stop that processing where the law requires after assessing the objection. Optional public-site analytics, if introduced, requires consent that can be withheld or withdrawn.
You also have the right to lodge a complaint with your supervisory authority. In Norway this is Datatilsynet (datatilsynet.no).
Children
BEARSCAR is intended for users aged 16 and older. If you believe someone under 16 has provided personal information, contact us so we can review and remove it when appropriate.
Contact
The data controller is baert AS (org. no. 936 033 245), registered in Norway (Foretaksregisteret), Oslo. We have not appointed a Data Protection Officer, as we are not required to under GDPR Art. 37; privacy enquiries go to the address below. As the controller is established in the EEA, no Article 27 representative is required. For privacy questions, access, correction, or deletion requests, email privacy@bearscar.org or use the privacy contact form.