SportIn ← Back to home
Legal

Privacy Policy

How SportIn.io SRL collects, uses, and protects your personal data.

Last updated: 7 May 2026 · Version 1.0

Contents

  1. Who we are
  2. What this policy covers
  3. Data we collect
  4. How we use your data and legal basis
  5. Apple HealthKit data
  6. Location data
  7. Wearables and Spike
  8. AI voice commentary (ElevenLabs)
  9. Map tiles (Mapbox)
  10. Sharing your data
  11. International transfers
  12. Retention
  13. Your rights
  14. How to delete your account
  15. Children
  16. Security
  17. Right to complain
  18. Changes
  19. Contact

1. Who we are

SportIn.io SRL ("SportIn", "we", "us", "our") is a Romanian company. We are the data controller for the personal data described in this policy.

Email: hello@sportin.io
Privacy contact: privacy@sportin.io

2. What this policy covers

This Privacy Policy applies to the SportIn mobile application (iOS and Android), the website at sportin.io and try.sportin.io, and the SportIn web application at app.sportin.io (together, the "Service").

3. Data we collect

CategoryExamplesSource
Account dataEmail, display name, password hash, Apple ID identifier (when you Sign in with Apple), profile photo, countryYou
Movement dataStep count, walking and running distance, workout duration, pace, splits, calculated Movement IndexApple HealthKit, your phone's Core Motion sensor, our eMotion engine, connected wearables via Spike (Garmin, Fitbit)
Location dataPrecise GPS location and route polyline collected only during an active workout you startYour device's location services
Social dataFriend graph, posts, photos, comments, reactions, reports, blocksYou and other users
Competition dataTeam affiliation, House or Brand Team membership, leaderboard rank, race participation, lap timesGenerated by your use of the Service
Rewards dataVouchers earned, redemption events, sponsor offers viewedYour use of the Service
NotificationsAPNs push token, your notification preferencesYour device
AI commentary dataStats we send to a third-party speech provider to synthesize voice commentary about your performance — we do not include personally identifying information in those promptsGenerated by your use of the Service
Wearable connection metadataOAuth tokens for Garmin, Fitbit, and other providers (held by Spike on our behalf), connection statusSpike
Compliance dataTerms acceptance time and version, account deletion requests, ban statusYour use of the Service
Technical dataApp version, OS version, language, crash diagnostics provided by Apple, Mapbox map-tile request metadataApple, Mapbox, your device

4. How we use your data and the legal basis

PurposeLegal basis (GDPR Art. 6)
Create and manage your accountPerformance of contract — Art. 6(1)(b)
Track movement, calculate the Movement Index, show your activityPerformance of contract; explicit consent for HealthKit data
Show your route on the map and replay your runExplicit consent (location services)
Place you on leaderboards, run competitions, calculate winnersPerformance of contract
Generate AI voice commentaryLegitimate interest (entertainment), with transparency
Send transactional and competition emailsPerformance of contract
Send marketing emailsConsent (you can withdraw at any time)
Send push notifications about your runs, leaderboards, and racesPerformance of contract; marketing pushes only with consent
Detect cheating via SafeGuard AILegitimate interest in maintaining fair competition
Comply with legal obligations (accounting, anti-fraud, regulator requests)Legal obligation — Art. 6(1)(c)
Account deletion fulfillmentLegal obligation; performance of contract

5. Apple HealthKit data

SportIn reads step count and walking and running distance from Apple Health when you grant permission.

6. Location data

SportIn collects precise GPS location only while a workout is active — that is, from when you tap Start until you tap Stop. We use this to show your route on the map, calculate distance, and verify the integrity of activities for competitions.

7. Wearables and Spike

If you connect a wearable such as Garmin or Fitbit, we use Spike (TryTerra Inc.) as our integration provider. Connecting a wearable shares your activity data (steps, distance, sessions) with us via Spike. You can disconnect any wearable from the Connections screen in your profile, which revokes the Spike token.

Spike processes data on our behalf as a sub-processor under a data processing agreement.

8. AI voice commentary (ElevenLabs)

We use ElevenLabs Inc. to synthesize voice commentary about your performance. We send a short text prompt containing your stats (such as distance, pace, time, and a few descriptive words) to ElevenLabs, which returns audio. We do not include your name, email, or other identifying details in that prompt.

The output is generative AI: it can be inaccurate. It is provided for entertainment only and is not coaching, medical, or training advice.

9. Map tiles (Mapbox)

We use Mapbox to render the map. Mapbox receives the data necessary to deliver appropriate map tiles. We do not use Mapbox's product analytics for our own purposes.

10. Sharing your data

We share personal data only with:

We never sell your personal data.

11. International transfers

Some of our processors are based outside the European Economic Area, including in the United States. For these transfers we rely on the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914) and, where applicable, adequacy decisions, with supplementary measures where appropriate.

12. Retention

13. Your rights

Under the GDPR you have the right to:

To exercise any of these rights, email privacy@sportin.io. We respond within one month and may extend by two further months for complex requests, with notice.

14. How to delete your account

Account deletion removes your profile, posts, activities, route history, and rewards balance, except records we are legally required to retain.

15. Children

SportIn is intended for users 16 years of age and older. We do not knowingly collect personal data from anyone under 16. If you believe a minor has registered, contact privacy@sportin.io and we will delete the account.

16. Security

We use TLS in transit, encrypted storage at rest, role-based access, and Supabase Row-Level Security policies. No system is perfectly secure. In the event of a personal data breach affecting your rights and freedoms, we will notify you and the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) per GDPR Articles 33–34.

17. Right to complain

You may lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, Romania — www.dataprotection.ro — or with the supervisory authority of your country of residence.

18. Changes

We will notify material changes to this Privacy Policy by email or in-app. The "Last updated" date at the top of this page reflects the current version.

19. Contact

SportIn.io SRL · Romania
Email: hello@sportin.io
Privacy: privacy@sportin.io