Privacy policy

Last updated 7 October 2026

Xtrimly is a movement and sport app. This page explains exactly what we collect, why we collect it, who else sees it, and how to get rid of it. It is written to be read, not to be skimmed past.

Who we are

Xtrimly is the data controller for the information described here. You can reach us at support@xtrim.app about anything on this page, including a request to see or delete your data.

What we collect

  • Account details. Your email address, password (stored only as a one-way hash, never in readable form), display name and username.
  • Profile details you choose to add. Photo, bio, location text such as “Lekki, Lagos”, phone number, date of birth, body weight and resting heart rate. Every one of these is optional and can be cleared at any time.
  • Location during a GPS-tracked activity. While you are recording, the app reads your GPS position to work out distance, pace, elevation and the shape of your route. It records location only while a recording is running, and stops the moment you finish or discard it.
  • Activity data. Distance, duration, pace, splits, elevation, the route line when available, and anything you add to an activity such as a title or notes.
  • Activity in the app. Who you follow, kudos and comments, clubs you join, events you say you are attending, routes you save, and direct messages you send.
  • Device information for notifications. A push token per signed-in device, so we can send you an alert. It is deleted when you sign out on that device.

Health and fitness data

Activity data, body weight and resting heart rate are health-related, and we treat them that way. They are used only to show you your own numbers and anything you deliberately share. We never sell them, never use them for advertising, and never hand them to a data broker or an insurer. We do not connect to Apple Health or Google Fit unless you turn that on yourself, and turning it off stops the exchange straight away.

Location, specifically

Location is the most sensitive thing the app touches, so the rules are strict. It is collected only while a recording is active. Background location, if you allow it, exists solely so a GPS-tracked activity keeps recording with your phone in your pocket and the screen off. If you turn live sharing on during a run, a rough position updates roughly once a minute while you are out and is removed when the run ends. Denying location permission does not lock you out of the app; it only means GPS-tracked activities cannot be tracked by GPS.

Why we hold it

  • To provide the service you signed up for: recording activities, showing your history, clubs, messages and notifications.
  • To keep the service safe: handling reports of abuse, enforcing bans, and preventing fraud.
  • To meet legal obligations, such as keeping payment records where the law requires it.

In UK and EU terms, the legal bases are performance of a contract (the service itself), consent (location and health data, which you grant through your device’s permission prompts and can withdraw), and our legitimate interests (safety and abuse prevention).

Who else sees it

Other people in the app see only what your visibility settings allow. Each activity is set to everyone, followers, or only you, and you can change that at any time.

A run you share by link gets an unguessable web address. Anyone holding that link can open the run page, whatever the run’s feed visibility, because sharing the link is the act of granting access. For runs that are not set to everyone, the page shows only a simplified shape of the route, not the full track.

We use these processors, and no others:

  • Supabase — database, authentication and file storage.
  • Mapbox — maps and route images.
  • Google Firebase Cloud Messaging — push notifications.
  • Apple and Google — subscription billing. We never see your card details; the stores handle payment.
  • Sentry — crash reports, so we can fix what breaks.
  • Vercel — hosting for this website.

We do not sell personal data, and we do not share it for advertising or cross-context behavioural advertising.

Where it is stored

Data is held on servers in the European Union and the United States, depending on the provider. Transfers out of the UK and EEA rely on the standard contractual clauses our providers have in place.

How long we keep it

Your account data stays while your account exists. Delete your account and your profile, activities, kudos, comments, messages, saved routes, safety contacts and push tokens are removed within 30 days. Crash reports are kept for 90 days. Anything the law requires us to retain, such as billing records, is kept for as long as that obligation lasts and for no other purpose.

One thing to be aware of: a club you created outlives your account. The club and its history stay, with your name removed from it, so the people who joined do not lose their club when you leave.

Your rights

You can ask for a copy of your data, correct anything wrong, delete your account, object to a particular use, or complain to your data protection regulator (in the UK, the ICO). Most of it you can do yourself in the app, under Settings. For anything else, email support@xtrim.app and we will reply within 30 days.

Deleting your account

Settings → Account → Delete account inside the app, or use the deletion page on this site if you no longer have the app installed. Deletion is permanent and cannot be undone. If you pay for Xtrimly Pro through the App Store or Google Play, cancel the subscription in the store first: deleting your account does not stop store billing, because only the store can end that.

Children

Xtrimly is not for under-13s, and in the EU/UK not for anyone under the digital age of consent in their country. We do not knowingly collect data from children. If you believe a child has an account, email us and we will remove it.

Changes

If we change this policy in a way that matters, we will tell you in the app before it takes effect. The date at the top always reflects the current version.