Legal
Privacy Policy
How GrindUp collects, uses, and protects your data.
1. Who we are
GrindUp is a social mobile app for strength sports (powerlifting). It lets you create an account, publish videos of your lifts (squat, bench press, deadlift), have your performances validated by the community, appear in leaderboards internal to GrindUp, follow other athletes, comment, send private messages, report content, and — optionally — subscribe to the paid GrindUp+ plan.
This policy explains what personal data we process, why, for how long, with whom we share it, and what your rights are, in accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act (Informatique et Libertés).
2. Effective date and version
- Version: technical version identifier
2026-06-25(kept in step with the legal-consent version recorded in the app). - Effective date: 3 July 2026.
- This policy is available from within the app (sign-up, settings, subscription screen) and at https://grindup.app/privacy.
3. Data controller
The data controller is:
- Maxime Scigala, sole trader (entrepreneur individuel), trading as GrindUp
- Registered office: 21 rue du Tibet, 62300 Lens, France
- SIREN: 106 023 161
- Contact e-mail: support@grindup.app
Full publisher and hosting details are set out in our Legal Notice.
4. Data we collect
4.1 When you create your account
Depending on the sign-in method you choose:
- E-mail and password: your e-mail address and password. The password is handled exclusively by our authentication provider (Firebase Authentication, Google); GrindUp never has access to it and never stores it. E-mail verification by link is required before your profile is created. A reset e-mail can be sent to you if you forget your password.
- Google sign-in: we receive an identity token from Google containing your e-mail address and your Google display name.
- Apple sign-in (Sign in with Apple, iOS): we request your name and e-mail address (which may be a private relay address provided by Apple). When you delete your account, a single-use Apple authorization code may be used to revoke the link with Apple; it is never retained.
4.2 When you complete your profile (required)
- Username (a unique nickname);
- Date of birth — used to verify the minimum age (15 — see §17) and to compute your competitive age category;
- Declared sex or competitive category — determines your competitive categories and leaderboards (men's / women's categories); see §6.1 on its visibility;
- Country (used for national leaderboards);
- Preferred weight unit (kg / lb);
- Proof of acceptance of the legal documents: the accepted versions of the Terms, Privacy Policy and content rules, a server timestamp, the acceptance context (sign-up or re-acceptance) and the interface language at the time of acceptance. No IP address is recorded with this consent.
Your exact date of birth, declared sex, weight unit and proof of consent are stored in a private area of your account and are not necessarily shown as separate fields on your public profile. Note, however, that your declared sex or competitive category, as well as the attributes derived from your date of birth and bodyweight, are used for competitive categories, filters, leaderboards, performance and personal-record (PR) cards, and ranking surfaces — so they may be visible, accessible or inferable through those surfaces (see §6.1 and its summary table).
4.3 Content and data you provide afterwards
- Performance videos and their metadata: movement, weight lifted (and the unit entered), declared bodyweight, date of the lift, equipment used (belt, wraps, etc.), associated gym (optional), number of repetitions, title/description;
- For verified athletes submitting an official competition (the "PRO" lane) performance: the public link to the competition result (openpowerlifting.org), the competition name and the federation. The "verified athlete" status relies on a verification code that you send us through a channel designated in the app (for example GrindUp's official Instagram account);
- Profile picture (avatar) — subject to moderation before publication (see §8);
- Profile biography, if any;
- Comments, likes, follows, blocks;
- Private messages (see §6.3);
- Validation votes on other people's performances (see §5.2);
- Reports of content or users (a reason chosen from a list);
- Feedback sent through the dedicated form: category, free text, app version, platform, device make and model and, only if you tick the option, a means of contact (e-mail or phone);
- Gyms you create: name, city, country, geographic location of the gym.
4.4 Device data and permissions
Depending on how you use it, the app may request access to: the camera and microphone (to film a lift), the photo library (to pick/save a video or photo), notifications (see §9) and the device location (while using the app only).
Location: when you grant location permission, your position is used to show nearby gyms and to centre the gym map. GrindUp does not record it as profile data and does not keep it in its databases; only the coordinates of the gym you select or create are stored. Map providers and your operating system (Google Maps on Android, Apple Maps on iOS) may process technical information related to displaying the map under their own rules.
5. Data created by using the app
5.1 Technical data derived from your profile
Each time you publish a performance video, the app freezes competitive attributes computed server-side from your profile at the time of the lift: age at the time of the lift, age category, sex/competitive category, bodyweight category, country, equipment. These "at the time of the lift" attributes are attached to the video. Your exact date of birth is never transmitted to other users — see §6.1 for the visibility of the derived attributes.
5.2 Community validation, Verified Leaderboards and trust score
- Other users vote to validate or reject your performance. A performance is validated once it reaches a vote threshold and a weighted approval rate (by default: at least 10 votes and 70% approval).
- A validated performance receives the "Verified" status and joins the Verified Leaderboards. These leaderboards are indicators internal to GrindUp, verified by the community: they are neither a federation ranking, nor a sporting certification or homologation, and have no official sporting value outside the app. The "Official" label is reserved for official competition performances submitted through the "PRO" lane (openpowerlifting.org result, approved by our team).
- Each voting account has an internal trust score (0–100), recalculated automatically several times a day based on how well its past votes matched the final decisions. The trust score is not shown publicly and does not reveal individual votes. It is used to weight votes and may be accessible to the user concerned (through their own validation statistics) or to administrators where necessary for operation, security or support.
- Individual votes are confidential: they are not shown publicly and are not disclosed to other users — neither a video's author nor other users see who voted what. If a performance is rejected, only the aggregated dominant reason is shown to you. Votes may nonetheless be processed by GrindUp to operate the validation system, for security, audit, fraud prevention or moderation (see §5.4).
- If the community rejects a performance, the author may request a single revalidation.
5.3 Internal usage measurement (product analytics)
We record internal usage events, linked to your account identifier: video impressions and watch time in feeds, votes/skips, screens viewed, sign-up funnel steps, subscription purchase events (result and technical error code only), usage sessions (iOS/Android platform, app version, start/end, duration, activity volume) and a last-activity timestamp. These events follow a strict "safe metadata" contract: never an e-mail, date of birth, message content, token or purchase receipt. They are used solely to measure and improve the product and are not shared with third parties for advertising. No advertising SDK or third-party tracking tool (Google Analytics, etc.) is integrated.
5.4 Technical logs and anti-abuse
- Per-account rate-limiting counters (uploads, votes, comments, messages, etc.) and a reinforced probation period during an account's first 24 hours;
- Device-integrity attestation tokens (Firebase App Check: Play Integrity on Android, App Attest/DeviceCheck on iOS) to block unofficial clients;
- Infrastructure logs (Google Cloud): as with any online service, the platform's technical logs may contain the IP address and request headers. We do not store your IP address in our application databases; it may be used transiently for rate-limiting and error diagnosis. Technical identifiers appearing in these logs are minimised or truncated where possible. Cloud Logging retention follows Google Cloud's default configuration (the
_Defaultbucket: 30 days; the_Requiredbucket: 400 days, locked). - Validation audit log: validation votes and decisions are recorded in an internal log for the integrity of the ranking system.
6. Public data and data visible to other users
GrindUp is a sports social network: visibility is at the heart of the product. There is currently no "private account" mode.
6.1 Visible to all signed-in users
- Your public profile: username, approved avatar, biography, country, follower/following counts, personal records (PRs), "verified athlete" badge, GrindUp+ badge and premium customisations (banner, PR-card themes, featured lifts);
- Your published videos and their frozen competitive metadata (weight lifted, bodyweight category derived from the bodyweight declared at the time of the lift, age at the time of the lift and age category, sex/competitive category, equipment, gym, date of the lift), including videos pending validation;
- Your comments and likes;
- Your presence in the leaderboards ("Open" and "Verified Leaderboards" surfaces — world, country, gym) and in gym records: username, avatar, country, performance, categories (sex/competitive category, age category, bodyweight category, equipment) and proof badges ("Verified" for a community validation, "Official" for an approved competition performance);
- For a "PRO" performance (official competition): the openpowerlifting.org public link you provided;
- The gyms you create (the creator's identifier is technically readable by signed-in users).
What is not shown: your exact date of birth, your e-mail address and your settings are not fields of your public profile and are not transmitted to other users. Your exact bodyweight is not shown to other users (only the derived bodyweight category is — see below). Your trust score is not shown publicly (see §5.2).
What is visible, accessible or inferable through competitive categories: your declared sex or competitive category is not necessarily shown as a standalone profile field, but it is used for competitive categories, filters, leaderboards, performance and PR cards and ranking surfaces — so it may be visible, accessible or inferable through those surfaces. The same applies to your age category, your age at the time of the lift and your bodyweight category. The bodyweight declared at the time of the lift is used to determine the bodyweight category and to rank performances. Your exact bodyweight is not shown to other users: the Service's purpose is to display the derived bodyweight category, not the exact bodyweight, on surfaces visible to other users. Your exact bodyweight is not carried by surfaces readable by other users: it is removed from the public video document and kept in a private server area (inaccessible to clients under our security rules); API responses, client-readable documents and share surfaces expose the derived bodyweight category or minimised data.
Summary — competitive attributes and visibility:
| Data | Use | Visibility |
|---|---|---|
| Exact date of birth | Minimum-age verification, age-category calculation | Not shown publicly; never transmitted to other users |
| Age at the time of the lift / age category | Leaderboards, competitive categories | Visible or inferable through ranking surfaces and performance cards |
| Declared sex or competitive category | Competitive categories, filters, leaderboards, performance cards | Visible, accessible or inferable through those surfaces |
| Declared bodyweight (at the time of the lift) | Collected; used to derive the bodyweight category and rank the performance | Not shown to other users; kept in a private server area inaccessible to clients; only the derived bodyweight category is exposed |
| Bodyweight category (derived) | Leaderboards, competitive categories, filters, performance cards, PR cards | Visible or inferable through those surfaces |
| Country | National leaderboards, filters | Visible (profile and leaderboards) |
| Gym associated with a lift | Performance cards, gym records and leaderboards | Visible if provided |
| Trust score | Internal weighting of validation votes | Not public; does not reveal individual votes; accessible to the user concerned (their statistics) and to administrators where necessary |
6.2 Technical accessibility of published media
The files for approved videos (playback, thumbnails) and for approved avatars are delivered through a public CDN: anyone with the file's URL can technically access it, even without an account. Do not publish a video you do not want to be public. Read access to media is provided exclusively through the CDN according to the visibility rules; there is no "guest" signed-URL playback route. Signed URLs are reserved for upload flows.
6.3 Private data between users
- Private messages: visible only to the participants in the conversation; they are not end-to-end encrypted. They may be processed by GrindUp where strictly necessary for technical operation, security, moderation or compliance with a legal obligation. A message's content is never included in push notifications. Messages are immutable once sent.
- Blocks: visible only to the two accounts concerned.
- Reports: visible only to you (the reporter) and to our moderation team.
6.4 Data accessible only to our team (admin/moderation)
Our administrators and moderators access, through a secured internal console, the data needed for their tasks: user record (including e-mail, date of birth, declared sex, validation statistics), reports, video and avatar moderation queues (analysis scores, OCR-detected text, duplicate hints), feedback, audit logs. Each administrative access and action is logged (administrator's e-mail, action, timestamp, administrator's IP address).
7. Purposes, legal bases and retention
| Purpose | Main data | Legal basis | Retention |
|---|---|---|---|
| Create and manage your account, verify e-mail, authenticate | e-mail, provider identifiers, password (via Firebase) | Performance of the contract (Art. 6(1)(b)) | Life of the account (§15) |
| Provide the service: profile, video publishing, feeds, community validation, Verified Leaderboards, gyms | profile, content, frozen competitive attributes, votes | Performance of the contract (Art. 6(1)(b)) | Life of the account / content (§14–§15) |
| Verify the minimum age and compute competitive categories (including the bodyweight category) | date of birth, declared sex/competitive category, bodyweight declared at the time of the lift | Performance of the contract (Art. 6(1)(b)); legitimate interest in protecting minors and Service security (Art. 6(1)(f)); legal obligation where applicable (Art. 6(1)(c)) | Life of the account / content |
| Private messaging, comments, follows; essential in-app notifications | content, social graph | Performance of the contract (Art. 6(1)(b)); legitimate interest (Art. 6(1)(f)) for certain service notifications | Messages: duration of the conversation (§15); notifications: 90 days |
| Content moderation (automated technical analysis + human review), handling of reports | videos, avatars, analysis scores, reports | Legitimate interest — service security, user protection (Art. 6(1)(f)); legal obligations applicable to hosting providers (Art. 6(1)(c)) | Artifacts: 7 to 30 days; reports and logs: §14 |
| Security, anti-fraud, anti-abuse (rate limiting, App Check, trust score, logs) | account identifiers, counters, attestation tokens | Legitimate interest (Art. 6(1)(f)) | §14 (logs, counters) |
| GrindUp+ subscription (purchase, access rights, restore) | account-linked identifier, subscription state, billing-event metadata | Performance of the contract (Art. 6(1)(b)); legal obligations where applicable (Art. 6(1)(c)) | Life of the account; technical log: §14 |
| Usage measurement and product improvement (internal analytics) | account-linked usage events (§5.3) | Legitimate interest (Art. 6(1)(f)) | ~90 days (sessions: ~30 days) |
| App stability (crash reporting, Sentry) | technical crash reports, limited sending of directly identifying data (§11) | Legitimate interest (Art. 6(1)(f)) | Per the provider's retention |
| Proof of consent to the legal documents | accepted versions, timestamp, language | Legal obligation / legitimate interest (Art. 6(1)(c) / 6(1)(f)) | Life of the account (§14) |
| Push notifications | device token, preferences | Device permission / consent (Art. 6(1)(a)), withdrawable at any time | Until withdrawal, invalidation or sign-out (§14) |
| Location (gym map) | device position (used for display) | Device permission / consent (Art. 6(1)(a)) | Not retained by GrindUp |
| Responding to your feedback when you ask to be contacted back | the means of contact you provide (opt-in) | Consent (Art. 6(1)(a)) | Life of the account (deleted at purge) |
The competitive attributes involved in these purposes (declared sex/competitive category, age category, bodyweight category) may be visible, accessible or inferable through ranking surfaces — see §6.1. Your exact bodyweight is processed internally to determine the bodyweight category and to rank performances (performance of the contract) and, where relevant, to handle sporting-integrity reports — for example a suspicious declared bodyweight (legitimate interest, §8.3); it is not shown to other users (see §6.1).
Bodyweight and performances: this sporting data is processed as athletic-performance data, not as health data.
8. Moderation, security and abuse prevention
8.1 Video moderation
Every uploaded video passes through a private storage area and undergoes an automated technical content analysis by the Google Video Intelligence API, limited to explicit-content detection (the only analysis requested from this service):
- no problematic signal → automatic publication;
- explicit content detected with high confidence → automatic rejection, with a notification;
- ambiguous signals → human review by our moderation team before any decision; in the event of a technical incident, the video is placed in review rather than published.
Rejected videos are never published; their files are kept briefly for audit purposes and then deleted automatically (see §14).
8.2 Avatar moderation
Each profile photo undergoes, before publication, a technical content analysis by the Google Cloud Vision API: detection of sensitive content (SafeSearch), text detection (OCR) compared against a list of forbidden terms, and computation of an image fingerprint (perceptual hash) used solely as a duplicate hint for moderators — a duplicate alone never triggers a decision. Depending on the result, the avatar is published automatically, rejected automatically (inappropriate content or offensive text), or sent to human review.
These analysis tools (video and image) are not used to identify a person, recognise their identity, or create a biometric template.
8.3 Reports and performance integrity
Reports (abusive content, suspicious performance, wrong gym, etc.) are reviewed by our team. An internal "anti-cheat" evaluation module aggregates report statistics (number of distinct reporters, reasons) in observation mode: it makes no automatic decision and does not change the visibility of your content.
8.4 Automated processing and safeguards
Some publication or moderation decisions may be assisted or triggered by automated technical rules (automatic publication or rejection described in §8.1 and §8.2; automatic weighting of votes by the trust score, §5.2). These decisions concern the availability of content within GrindUp and are not intended to produce a legal effect on you. Ambiguous cases, technical incidents and appeals are subject to human review.
Safeguards: you are notified of decisions concerning your content (see also §8.6); you can request a human review, express your point of view and contest a decision by contacting us (support@grindup.app); a community rejection gives the right to a single revalidation in the app.
8.5 Anti-abuse measures
Per-account rate limiting, a 24-hour probation period for new accounts, device-integrity attestation (App Check), strict database security rules (sensitive writes reserved to the server), administrative disabling of infringing accounts (with logging), and hiding of the content of an account being deleted.
8.6 Information about moderation measures
In the event of removal, visibility restriction, suspension or another moderation measure, GrindUp may provide information about the measure taken and its reason, unless the law, Service security, the protection of a third party or abuse prevention prevents it. You can contest the decision at support@grindup.app.
9. Notifications
- In-app notifications: validation/rejection of your performances, moderation result, removal of content, new followers, messages, comments. They expire automatically after 90 days.
- Push notifications (Firebase Cloud Messaging): sent only if you grant the system permission. For this we store a device token (FCM token), the platform (iOS/Android) and the app version, limited to 10 devices per account. The token is deleted on sign-out, when it becomes invalid, and on account deletion.
- You control push notifications by notification type and via a global switch in the settings, as well as in your phone's system settings. Anti-spam caps (quiet windows, a daily maximum for non-critical notifications) are applied.
- The content of your private messages never appears in a push notification (only the sender is mentioned).
10. Subscriptions and payments (GrindUp+)
- The GrindUp+ subscription is purchased exclusively through the App Store (Apple) or Google Play. Payment, including your card details, is handled by Apple or Google: GrindUp never has access to your payment data and does not store it.
- We use RevenueCat to manage subscription entitlements. RevenueCat receives an account-linked identifier — personal data within the meaning of the GDPR — in order to associate your purchases with your access rights; we do not send it your e-mail or your name.
- We keep your subscription state: active/trial/grace period/expired/cancelled, access end date, purchased product identifier, purchase store and technical billing-event metadata (event identifiers and timestamps). No transaction amount or receipt is stored by GrindUp.
- The "GrindUp+ member" status (badge) is visible to other users; it is a product feature.
- Managing and cancelling the subscription is done in your store settings (a "Manage subscription" shortcut is provided in the app), as is restoring purchases.
11. Analytics, logs and crash reporting
- Internal analytics: see §5.3. Events linked to your account identifier, hosted in our own database, on the basis of our legitimate interest (§7), with an expiry marker of about 90 days (sessions: 30 days).
- Crash reporting (Sentry): in the event of a crash, a report is sent to Sentry. Crash reports are configured to limit the sending of directly identifying data (no IP-address enrichment, no user identifier attached to reports —
sendDefaultPii: false), but may contain technical information needed for diagnosis (device model, system and app versions, execution traces). A fraction of performance traces (10%) is also collected. - Server logs: backend services log technical events (Cloud Logging) with identifiers truncated where possible; the Google Cloud platform logs may contain IP addresses (see §5.4).
- No cookies are used in the mobile application. This public legal website is static and sets no tracking or advertising cookies. (Our internal administration console uses technical cookies tied to our team's Google IAP authentication.)
12. Recipients and processors
Your data is processed by our authorised teams (support, moderation, administration — logged access, restricted to the company domain) and by the following processors:
| Processor | Service | Purpose | Data concerned |
|---|---|---|---|
| Google Cloud / Firebase (Google Ireland Ltd / Google LLC) | Firestore, Cloud Storage + CDN, Cloud Functions/Run, Firebase Auth, App Check, Cloud Logging | Hosting, authentication, media delivery, security | All service data |
| Google Cloud | Video Intelligence API | Technical content analysis of videos (explicit-content detection) | Submitted video files |
| Google Cloud | Vision API | Technical content analysis of avatars (SafeSearch, OCR) | Submitted profile photos |
| Google (Firebase Cloud Messaging) / Apple (APNs) | Push notifications | Deliver notifications | Device token, notification content |
| RevenueCat, Inc. | Subscription management | GrindUp+ entitlements | Account-linked identifier, store purchase events |
| Apple (App Store) / Google (Play) | In-app purchase | Subscription payment | Payment data (processed by the stores as separate controllers) |
| Functional Software, Inc. (Sentry) | Crash reporting | App stability | Technical crash reports (directly identifying data limited) |
| Google (Sign-In) / Apple (Sign in with Apple) | Federated sign-in | Authentication | Identity tokens (e-mail, name) |
| Google Maps (Android only) | Gym map basemap | Map display | Tile requests issued by the device (iOS uses Apple Maps) |
No data is sold or shared for advertising purposes. Your data may also be disclosed to the competent authorities where required by law (for example judicial requests, obligations applicable to content-hosting providers).
13. Transfers outside the EU / EEA
For the components whose configuration we control (server functions, processing services, media file storage), the infrastructure is deployed in the Google Cloud europe-west1 (Belgium) region. We cannot, however, state at this stage that all processing takes place within the EU/EEA: the exact region of the Firestore database is not attested by the code; calls to the Video Intelligence and Vision APIs are not pinned to an EU region and may be processed by Google on infrastructure outside the EU (typically the US); Sentry and RevenueCat are US companies; notifications transit through Google's (FCM) and Apple's (APNs) global infrastructures.
Where such transfers occur, they are governed by the mechanisms provided for by the GDPR: an adequacy decision (in particular the EU–US "Data Privacy Framework" for certified providers) and/or the European Commission's Standard Contractual Clauses, together with supplementary measures where appropriate.
14. Retention periods
The periods below correspond to the mechanisms actually implemented. Where no automatic period exists, data is kept for as long as the account or the content exists, or for as long as necessary for the operation of the service, its security, fraud prevention, audit, compliance with our legal obligations and the defence of our rights.
| Data | Period |
|---|---|
| Account, profile, published content | For as long as the account exists, then deletion per §15 |
| Account-deletion request | 7-day grace period (account suspended, content hidden), then permanent purge |
| Video you delete | Hidden immediately; files and data purged after 7 days |
| Incomplete upload files / moderation artifacts / rejected files (private internal storage) | Pending upload: 7 days; moderation artifacts: 30 days; rejected videos: 7 days; abandoned uploads marked expired after 48 h |
| Copies of rejected avatars (private audit storage) | Kept for as long as necessary for moderation audit; deleted on account deletion |
| Avatar image fingerprints (duplicate detection) | 90 days (and immediate deletion on account deletion) |
| In-app notifications | 90 days |
| Internal usage events (analytics) | Expiry marker ~90 days; sessions ~30 days |
| Push tokens | Until sign-out, invalidation or account deletion (max. 10 devices) |
| GrindUp+ subscription state | Life of the account; deleted at account purge |
| Technical log of subscription events (RevenueCat webhook) | Kept after account deletion, for as long as necessary for anti-replay and audit (pseudonymized) |
| Reports | Kept for as long as necessary for moderation integrity, security, fraud prevention and the defence of our rights, including after the reporter's account is deleted; after the reporter's account is deleted, their identity is pseudonymized (the raw account ID is no longer retained) |
| Validation votes cast | Kept (pseudonymized, necessary for the integrity of decisions already made) |
| Validation audit log | Kept for as long as necessary for the integrity of the validation system |
| Administrator audit logs | Kept for as long as necessary for the security and traceability of administrative actions |
| Proof of legal consent | Life of the account (deleted with the account) |
| Anti-abuse counters (rate limiting) | Kept for as long as necessary for the security of the service |
15. Account deletion
You can delete your account directly in the app (Settings → Delete account), after a recent re-authentication:
- 7-day grace period: your account moves to a "deletion pending" state; your content is hidden immediately (feeds, leaderboards, records, validation queue); you can no longer interact. You can cancel the deletion at any time during those 7 days by signing in again and confirming the cancellation (cancelling leaves no trace visible to other users).
- Permanent, irreversible purge (run daily after the deadline): deletion of your authentication account, your profile (including date of birth, declared sex, consents, trust score), your videos and media files (public and private), avatars and associated fingerprints, comments (yours, everywhere), follows/followers, blocks, notifications, push tokens, sessions and usage events, gym records, validation statistics, ranking snapshots, subscription entitlements, feedback you sent, and moderation queues concerning you.
- Data retained, pseudonymized or anonymized after the purge (see also §14): your conversations are kept for the other participant with your identity removed (username and avatar erased; the content of messages already sent remains visible to the recipient); your votes on other people's videos, your reports (where your reporter identity is pseudonymized) and the technical subscription log are kept to preserve the integrity of the service.
Deletion is therefore neither instantaneous nor total across all systems: depending on the case, data is deleted, anonymized, pseudonymized or retained for reasons of security, service integrity, fraud prevention, compliance or the defence of our rights (detail in §14). Where data is pseudonymized, it is no longer linked to your account, but pseudonymization is not the same as irreversible anonymization.
Deleting the account does not automatically cancel an ongoing GrindUp+ subscription: cancel it in your store settings (App Store / Google Play).
For Apple accounts, the "Sign in with Apple" link is revoked on a best-effort basis when the deletion is requested.
16. Your rights
Under Articles 15 to 22 of the GDPR, you have the following rights:
- Access: obtain a copy of the data we hold about you;
- Rectification: in the app, you can change your username (at most once every 30 days), correct your date of birth (at most once every 30 days), change your avatar, biography and weight unit. For the other fields (in particular the declared sex/competitive category and country, not self-editable because they condition the ranking categories where they are visible or inferable — see §6.1), contact us;
- Erasure: account deletion in the app (§15) or on request; individual deletion of your videos and comments in the app;
- Objection and restriction of processing, under the conditions set out in the GDPR (in particular for processing based on our legitimate interest);
- Portability: receive the data you provided to us in a structured format (requests are handled manually);
- Withdrawal of consent at any time (push notifications, location, feedback contact), without affecting the lawfulness of prior processing;
- Post-mortem instructions: set instructions on the fate of your data after your death (French law).
To exercise your rights: support@grindup.app. We may ask you to prove your identity (for example by writing from the account's e-mail address). We respond within one month, extendable by two months for complex requests.
You can lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés): www.cnil.fr — 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07.
17. Minors
- GrindUp is reserved for people aged at least 15. People under 15 cannot create an account. The date of birth is checked at sign-up (server-side verification) and age checks also apply to published performances. No sign-up below the minimum age is accepted.
- Some competitive categories may cover theoretical age ranges broader than the minimum age of access to the Service; GrindUp remains reserved for users aged 15 and over.
- If you believe a user does not meet the minimum age, contact us at support@grindup.app: the account concerned will be deleted.
18. Security
Main measures implemented:
- Encryption of data in transit (TLS) and at rest (Google Cloud default encryption);
- Authentication delegated to Firebase Auth; no password stored by GrindUp; session revocation on sensitive operations;
- Strict database security rules: sensitive data (votes, push tokens, moderation queues, private profile data) is inaccessible to clients; critical writes go exclusively through our servers;
- Storage separation: published media on a dedicated public bucket; pending uploads, moderation artifacts and images under review on private buckets;
- Device-integrity attestation (App Check), rate limiting, new-account probation;
- Administration console accessible only to our team via Google Identity-Aware Proxy (dual network + application verification, restricted domain), with logging of every action and reinforced confirmation for destructive actions in production;
- Secrets managed through a secret manager; strict separation of the development, pre-production and production environments.
No system is infallible: in the event of a data breach likely to create a high risk to your rights, we will inform you in accordance with Articles 33 and 34 of the GDPR.
19. Changes to this policy
We may amend this policy to reflect changes in the service or the law. In the event of a material change, the new version will be presented to you in the app for acceptance before you continue (the versioned re-consent mechanism is built into the app). The date and version in force appear at the top of this document.
20. Contact
- Questions about this policy or exercising your rights: support@grindup.app
- Postal address: 21 rue du Tibet, 62300 Lens, France
- Supervisory authority: CNIL (www.cnil.fr)