InChained

PRIVACY POLICY

Last updated: August 2026

This policy applies to the InChained web application, iOS app, and Android app (collectively “the Service”).

1. WHO WE ARE

The data controller for the Service is Rami Ejleh, Aarhus, Denmark (“we”, “us”, “our”). We are established in the European Union, so no Art. 27 GDPR representative is required.

Privacy enquiries and data-rights requests: privacy@inchained.com

2. DATA WE COLLECT AND WHY

We collect the following categories of personal data:

CATEGORYDATA
AccountEmail address, password (hashed — we never see it), callsign (display name), avatar image or colour, date of birth (used only to verify the 16+ age requirement), account creation date, timezone, record of your acceptance of these terms, and whether you opted in to product emails.
ActivityCrew memberships, proof submissions (images and captions), peer votes, reactions and comments, objective commitments, compliance records, chain history, achievement unlocks, duels, join requests, and War Room chat messages.
Health and fitnessIf — and only if — you choose to submit a tracked workout as proof, we read the selected workout from Apple Health (iOS) or Health Connect (Android): activity type, duration, distance, calories, and start/end times. See section 4.
SubscriptionSubscription plan, billing currency and interval, trial status, subscription origin (Stripe / Apple / Google), and the customer and subscription identifiers issued by those providers. We never see or store your card details.
Safety and moderationContent reports you file or that concern you, users you block, kick-vote records, and account suspension status.
Push notificationsDevice push tokens (FCM / APNs) and your per-category notification preferences.
Aggregate analyticsAnonymous, cookieless product events (e.g. app opened, proof submitted) via PostHog EU. No cookies, no persistent identifiers, and no person profiles are ever created — events cannot be linked back to you.
Error and crash dataAnonymous application errors and stack traces via PostHog EU. No personal data is included in error payloads.
TechnicalIP address and HTTP request metadata, processed by our hosting and database providers for security, abuse prevention, and operating the Service.

4. HEALTH AND FITNESS DATA

Submitting a tracked workout as proof is entirely optional. Every other feature of the Service works without granting any health permission.

  • What we read: only completed workout summaries — activity type, duration, distance, calories, and start/end time. We request read-only access. We never write to Apple Health or Health Connect, and we do not read heart rate, sleep, steps, body measurements, medical records, or any other health category.
  • When we read it: only at the moment you open the tracked-workout picker and pick a specific workout. We do not read your health data in the background or on a schedule.
  • Who sees it: a workout you submit as proof is shown to the members of that Crew, exactly like an image proof. It is stored in our database (Supabase, EU) alongside the proof record.
  • What we never do: we never use health data for advertising, marketing, profiling, or data mining; we never sell it; and we never share it with any third party other than the infrastructure providers in section 5 who store it on our behalf.
  • Withdrawing consent: open Profile in the app and switch off Health data consent— we stop reading your workouts immediately and the tracked-workout option is disabled until you consent again. To cut access off at the source as well, revoke Crew in iOS Settings → Privacy & Security → Health, or in Android Health Connect settings. Workouts you already submitted stay attached to those proofs until the proof or your account is deleted; contact us to have them removed sooner.

We treat this data as a special category of personal data under GDPR Art. 9 and process it only on the basis of your explicit consent.

5. PROCESSORS AND SUB-PROCESSORS

We share data only with the service providers listed below, each under a Data Processing Agreement. They process data on our instructions only.

PROVIDERPURPOSELOCATION
SupabaseDatabase, authentication, file storage, serverless functionsEU (Frankfurt, AWS eu-central-1)
NetlifyWeb application hosting and deliveryGlobal CDN (SCCs apply)
StripePayment processing and subscription management (web)EU/US (SCCs apply)
AppleiOS subscription billing, push notifications (APNs), Sign in with AppleGlobal (SCCs apply)
Google / FirebaseAndroid subscription billing, push notifications (FCM), Google Sign-InGlobal (SCCs apply)
PostHog (EU Cloud)Anonymous aggregate analytics and error trackingEU (Frankfurt)
ResendTransactional and moderation email deliveryEU/US (SCCs apply)

We do not sell your personal data, and we do not share it for cross-context behavioural advertising. We use no advertising cookies, no ad SDKs, and no cross-site tracking technologies.

6. INTERNATIONAL TRANSFERS

Your account data, content, and health data are stored in the EU (Supabase, Frankfurt), and analytics are processed exclusively in the EU (PostHog EU Cloud, Frankfurt). Some providers (Netlify, Stripe, Apple, Google, Resend) may process data outside the EU/EEA. Where they do, we rely on the EU Standard Contractual Clauses (Commission Decision 2021/914) together with the providers' supplementary safeguards. You can request a copy of the relevant safeguards from the address in section 1.

7. DATA RETENTION

DATARETENTION
Account and activity dataUntil you delete your account.
Proof imagesKept while the Crew they belong to is running, so the group's history stays intact. Once a Crew is completed or cancelled, a daily job permanently deletes the image files; the proof record is kept without the image for the group's own history. Deleting your account removes your images immediately.
Tracked workout dataStored with the proof and subject to the same rule as proof images. The summary data is retained with the proof record after the image purge; delete the proof or your account to remove it.
War Room messagesUntil the Crew is deleted or you delete your account.
Subscription and transaction recordsDeleted from our database when you delete your account. Stripe, Apple, and Google independently retain the underlying transaction records for the period required by tax and accounting law (typically 5–7 years); we cannot shorten that.
Moderation recordsReports and suspension records are kept for up to 12 months after resolution so we can act on repeat abuse, then deleted.
Push tokensUntil replaced, revoked, or your account is deleted.
Analytics and error eventsUp to 12 months (PostHog EU). These events are anonymous and cannot be linked to you.

When you delete your account, your profile, activity, messages, achievements, health data, avatar, proof images, and device tokens are permanently erased from our systems. Anonymous aggregate analytics are not attributable to any individual and are therefore not affected by deletion requests.

8. COOKIES AND TRACKING

We do not use advertising cookies or persistent tracking identifiers.

The web app sets strictly necessary cookies from Supabase Auth to keep you signed in. These are essential to deliver a service you requested and are exempt from consent under Art. 5(3) of the ePrivacy Directive.

Our analytics run in cookieless, memory-only mode: no cookie is written, no persistent cross-session identifier is created, and no person profile is ever generated. Because no information is stored on or read from your device for analytics, no consent banner is required. This is why you will not see a cookie pop-up.

9. HOW WE PROTECT YOUR DATA

  • All traffic is encrypted in transit (TLS) and data is encrypted at rest.
  • Every database table is protected by row-level security policies, so one user cannot read another user's data even if a client is tampered with.
  • Proof images and avatars live in private storage buckets and are served only through short-lived signed URLs.
  • Payment card data never reaches our servers — it is handled by Stripe or the app stores.
  • Passwords are hashed by Supabase Auth; we cannot read them. Sign in with Apple and Google are supported so you need not create one at all.

No system is perfectly secure. If a personal data breach is likely to result in a risk to your rights, we will notify the Danish Data Protection Agency within 72 hours and inform you without undue delay where the risk is high (GDPR Arts. 33–34).

10. YOUR RIGHTS (EU/EEA AND UK)

Under the GDPR and UK GDPR you have the right to:

  • Access (Art. 15):get a copy of your data. Use “Export my data” in your Profile on web, Android, or iOS for an immediate machine-readable download.
  • Rectification (Art. 16): correct inaccurate data. You can edit your callsign and avatar in the app.
  • Erasure (Art. 17): delete your account and its data via Profile → Delete Account, or the steps at /delete-account. If you are the owner of a Crew that still has other active members, the app will ask you to transfer ownership or wind the Crew down first, so the group is not destroyed underneath them. If that is not possible for you, email us and we will complete the erasure manually within 30 days.
  • Restriction (Art. 18): ask us to pause processing in certain circumstances.
  • Portability (Art. 20): receive your data in a structured, commonly used, machine-readable format (the JSON export above).
  • Objection (Art. 21): object to processing based on legitimate interests.
  • Withdraw consent (Art. 7(3)): for health data and marketing email, at any time, without affecting prior lawful processing.
  • Complain: lodge a complaint with your local supervisory authority — in Denmark, Datatilsynet (datatilsynet.dk); in the UK, the ICO (ico.org.uk).

Email privacy@inchained.com to exercise any right. We respond within one month and never charge a fee for a first request.

11. UNITED STATES PRIVACY RIGHTS

If you live in California, Colorado, Connecticut, Virginia, Texas, Oregon, Montana, or another US state with a comprehensive privacy law, you have the rights below. We extend them to all US residents regardless of whether the law technically applies to us.

  • Know / access: what personal information we collect, the purposes, and the categories of recipients — all set out in sections 2, 3, and 5 of this policy.
  • Delete: request deletion of your personal information.
  • Correct: request correction of inaccurate personal information.
  • Portability: obtain a copy in a portable format.
  • Opt out of sale, sharing, and targeted advertising: we do not sell or share personal information, and we do not conduct targeted advertising or profiling with legal or similarly significant effects — so there is nothing to opt out of. We honour Global Privacy Control signals as a matter of course.
  • Limit use of sensitive personal information: health and fitness data is sensitive personal information. We use it solely to display the proof you chose to submit, which is a purpose exempt from the right to limit — we never use it to infer characteristics.
  • Non-discrimination: we will never degrade your service or charge you more for exercising a privacy right.

Categories collected in the last 12 months (CCPA terminology): identifiers (email, user ID); customer records (callsign, date of birth); commercial information (subscription and transaction records); internet activity (in-app product events); health information (tracked workouts, only with your permission); and user-generated content (proof images, captions, messages). We disclose these for business purposes only, to the providers listed in section 5. We have not sold or shared personal information in the preceding 12 months.

To exercise a right, email privacy@inchained.com. We verify requests using the email address on your account. You may use an authorised agent; we will ask for written proof of authority. We respond within 45 days and may extend once where permitted.

12. CHILDREN

The Service is not directed at children. You must be at least 16 years old to create an account, and we ask for your date of birth at sign-up to enforce this. We do not knowingly collect personal data from anyone under 16.

If you believe a child under 16 has created an account, email privacy@inchained.com and we will delete the account and its data promptly.

13. CHANGES TO THIS POLICY

We may update this policy when our practices change or the law requires it. For material changes we will give notice in-app or by email at least 14 days before the change takes effect. The “Last updated” date above reflects the most recent revision.

Terms of Service