GRIND is a fitness accountability app. We take your privacy seriously, especially because we handle photos and health data. This policy explains what we collect, what we never collect, how we use it, and your rights.
1. Who we are
GRIND is operated from India. For questions about this policy or your data, email hello@grindapp.in.
2. What we collect
- Account — your email, name, and age range.
- Squad data — squad memberships, squad name, your role.
- Check-in submissions — the live photo you capture, GPS coordinates used solely for verification, and derived health signals (for example: whether a workout was detected, total active energy in a 90-minute window).
- Device info — model, OS version, app version, and your push notification token.
- Usage analytics — anonymized event stream (button taps, screen views) to understand how the app is used.
3. What we explicitly do NOT collect
- Raw HealthKit (iOS) or Health Connect (Android) data — this never leaves your device.
- Raw heart-rate streams or workout objects.
- Photos from your gallery — only photos you capture live within the app.
4. How we use it
- To verify daily check-ins and produce a verdict (PASS, SOFT-PASS, or FAIL).
- To match you to and manage your squad.
- To display streaks and BOOM history within your squad.
- To send notifications you've opted into.
5. Sub-processors
We share specific data with the following third parties strictly to operate the service:
- Cloudflare R2 — encrypted photo storage with signed URLs that expire in 1 hour.
- Supabase — managed PostgreSQL database.
- Upstash — managed Redis queue.
- Sentry — error monitoring.
- PostHog (self-hosted) — product analytics.
- Google (Gemini) — vision API for verifying check-in photos. Sent only the derived signals plus the captured photo, never your raw Health data.
- Fly.io — application hosting.
6. Photo retention
- Check-in photos are kept for 90 days, then deleted.
- BOOM evidence photos are kept for 30 days after the related vote resolves, then deleted.
7. Account deletion
You can delete your account from inside the app at any time. We use a 30-day grace window: your account is hidden immediately, and after 30 days all your photos and personal data are hard-deleted. If you want immediate deletion, email hello@grindapp.in.
8. Your rights
Under India's Digital Personal Data Protection Act, 2023 (DPDP Act), you have the right to access, correct, delete, and port your data. Email us to exercise any of these rights and we'll respond within a reasonable time.
9. Children
The minimum age to use GRIND is 13. Users under 18 must have verifiable consent from a parent or legal guardian. If you believe a child has used GRIND without proper consent, contact us and we will take appropriate action.
10. Security
We encrypt your data in transit (HTTPS) and at rest. Internal access is least-privileged. No system is perfectly secure, but we work to minimize risk and respond quickly if anything goes wrong.
11. Changes to this policy
If we make material changes to this policy, we will notify you by email and inside the app. The “Last updated” date at the top will reflect any change.
Questions? hello@grindapp.in