Contents
- Introduction
- Who We Are
- Scope
- Information We Collect
- Apple Health Integration
- How We Use Your Information
- Face ID / Biometric Authentication
- AI-Powered Insights
- Push Notifications
- Data Sharing and Disclosure
- Children and Minors
- Service Providers
- International Data Transfers
- Data Retention
- Your Rights (GDPR)
- Security Measures
- Changes to This Policy
- Contact Us
1. Introduction
This Privacy Policy explains how we collect, use, store, and protect your personal information when you use the Qruza mobile application (the "App"). Qruza is designed for athletes and coaches in Luxembourg sports federations to track performance, manage training, and train smarter.
We are committed to protecting your privacy and handling your data responsibly. Please read this policy carefully. By creating a Qruza account or using the App, you acknowledge that you have read and understood this policy.
2. Who We Are
Contact email: qruza.app@gmail.com
Data protection contact: matteodacruz@icloud.com
For the purposes of the EU General Data Protection Regulation (GDPR), Qruza is the data controller responsible for your personal data.
3. Scope
This policy applies to all personal data processed through the Qruza iOS application, including data stored in our backend systems.
Qruza is currently invite-only. This policy covers all users who access the App through a valid invite code, whether in an athlete or coach role.
Qruza is not intended to provide medical diagnosis, treatment advice, or emergency medical services. Training insights and performance analysis are for informational purposes only.
4. Information We Collect
4.1 Account and Profile Information
- Full name
- Email address and password
- Role selection (Athlete or Coach)
- Weight class and federation affiliation
- Push notification token
4.2 Training and Performance Data
- Training sessions: session type, date, duration, RPE (1–10), free-text notes
- Gym sessions: focus type, duration, RPE, notes
- Wellness logs: sleep quality, nutrition, energy levels, mood, and soreness ratings
- Competition records: name, location, date, weight class, result
- Goals: title, description, and status
- Weight logs
- Performance statistics derived from session data
4.3 Health and Injury Data
- Injury reports: body part, injury type, severity, estimated return date, recovery status, injury history
- Apple HealthKit data (if permission granted; iOS only, read-only — never written): sleep hours (last night), step count (today), active calories (today), heart rate (latest)
4.4 Coach Notes and Feedback
- Notes from coach to athlete: note text, note type, coach name, date, contextual reference
4.5 AI-Generated Insights
- Weekly AI-generated performance summaries analysing the prior 14 days
- Generated automatically each Sunday and cached in our database
- Post-session coach insights generated from athlete RPE scores and session notes
4.6 Technical and Access Data
- Invite code, authentication session data
Not collected
Device location, contacts, camera/photos, payment information, advertising identifiers, analytics/crash-reporting data.
5. Apple Health / HealthKit Integration
Qruza reads the following data from Apple HealthKit on iOS devices, subject to your explicit permission:
- Sleep hours (last night)
- Step count (today)
- Active calories (today)
- Heart rate (latest)
HealthKit data is read only. Qruza does not write any data to HealthKit.
This data is used solely to enrich your training insights and wellness tracking within the App. HealthKit data is transmitted to our backend for storage and may be included in AI-generated insights (see Section 8). It is never sold to third parties or used for advertising.
You may revoke HealthKit access at any time through your iOS device Settings > Privacy & Security > Health > Qruza. Revoking access will stop new data from being read but will not delete previously imported data from your Qruza account.
6. How We Use Your Information
We process your personal data for the following purposes:
- Providing core App functionality (training logging, performance tracking, coaching)
- Generating AI-powered weekly performance insights
- Generating post-session coaching insights for coaches
- Enabling coach-athlete communication
- Displaying wellness and recovery trends
- Delivering push notifications (session reminders, coach notes, weekly insights)
- Maintaining account security and authentication
Legal bases for processing (GDPR Article 6)
- Contract performance: processing necessary to provide the App services you requested
- Legitimate interest: improving App functionality, generating performance insights
- Consent: HealthKit data access, push notifications, AI processing of health-related data
7. Face ID / Biometric Authentication
7.1 What We Use
Qruza supports Face ID (iOS) as an optional convenience feature for unlocking the App.
7.2 How It Works
Face ID authentication is handled entirely by the iOS operating system. Qruza never receives, processes, stores, or transmits your biometric data (facial geometry). We only receive a success/failure response from the operating system.
7.3 What We Do NOT Collect
- Facial geometry or biometric templates
- Device location
- Contacts
- Camera images or photos
- Payment information
- Any biometric data whatsoever
Face ID can be enabled or disabled at any time in your device settings.
8. AI-Powered Insights
8.1 Weekly Performance Insights
Qruza generates AI-powered weekly performance summaries using the Anthropic Claude API.
Data sent to Anthropic for processing:
- Training sessions from the prior 14 days (type, duration, RPE, notes)
- Gym sessions (focus type, duration, RPE, notes)
- Wellness logs (sleep, nutrition, energy, mood, soreness)
- Active injuries and recovery status
- Competition records and results
- Goals (title, description, status)
- Profile data (role, weight class, federation)
Processing details:
- Insights are generated automatically each Sunday
- Data is sent via encrypted API call to Anthropic's servers (United States)
- Data is NOT stored by Anthropic after processing — it is used solely to generate the response and is not retained
- The resulting insight text is cached in the Qruza database while your account is active
- You may view past insights within the App
8.2 Post-Session Coach Insights
When an athlete completes a training session, Qruza may send the athlete's RPE scores and session notes to the Anthropic Claude API to generate contextual coaching insights for the coach.
Data sent: Athlete RPE (rate of perceived exertion) scores, session notes provided by the athlete.
Processing details:
- Data is sent via encrypted API call to Anthropic's servers
- Data is NOT stored by Anthropic after processing
- The resulting coaching insight is displayed to the coach within the App
- These insights are intended to help coaches provide better-informed feedback
8.3 AI Processing Safeguards
- No automated decision-making with legal or significant effects
- Insights are informational only — not medical or professional advice
- You can request deletion of all AI-generated content by contacting us. Anthropic does not retain your data after generating the insight response
9. Push Notifications
Qruza uses Expo Push Notification Service (hosted at exp.host) to deliver notifications.
Types of notifications: training session reminders, coach note notifications, weekly insight availability, competition reminders.
Data involved: Expo push token (device identifier for notifications), notification content (generated server-side).
You may disable push notifications at any time through your device settings. Your push token is stored securely and used solely for delivering Qruza notifications.
10. Data Sharing and Disclosure
10.1 Coach-Athlete Relationship
If you join a team using a team code, coaches can view athlete training sessions, competition records, injuries, wellness data, and AI insights, and can send notes to athletes. Athletes can view coach notes sent to them. Athletes cannot view other athletes' data.
10.2 No Sale of Data
We do not sell, rent, or trade your personal information to any third party.
10.3 No Advertising Use
Your data is never used for advertising, marketing profiling, or shared with ad networks.
11. Children and Minors
Qruza is designed for use by athletes aged 16 and over. We do not knowingly collect personal information from children under 16.
For users between 16 and 18, we recommend parental awareness of the App's data collection practices as described in this policy.
If we become aware that we have collected data from a child under 16, we will take steps to delete that information promptly. If you believe a child under 16 has provided us with personal data, please contact us at qruza.app@gmail.com.
12. Service Providers
We use the following third-party service providers to operate the App:
| Provider | Purpose | Data Shared | Location |
|---|---|---|---|
| Supabase | Database hosting, authentication | All user data | EU West (Paris, eu-west-3) |
| Anthropic | AI insight generation (Claude API) | Training, wellness, injury, competition, goals, and profile data | United States (data not retained after processing) |
| Expo (exp.host) | Push notification delivery | Push token, notification content | United States |
| Apple HealthKit | Health data read (on-device) | Sleep, steps, calories, heart rate (read only) | On-device (iOS) |
Each provider is bound by their respective privacy policies and data processing agreements. We select providers that maintain appropriate security certifications and GDPR compliance measures.
13. International Data Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA):
- Supabase: data stored in EU West (Paris, eu-west-3) — no transfer outside EEA for stored data
- Anthropic (Claude API): data is processed in the United States for AI insight generation and is not retained after processing. Transfer safeguards include Standard Contractual Clauses (SCCs) and Anthropic's data processing commitments
- Expo: push notification routing through United States servers. Minimal data involved (push tokens and notification content)
For transfers to the United States, we rely on Standard Contractual Clauses (SCCs) as approved by the European Commission, or other appropriate safeguards under GDPR.
14. Data Retention
We retain your data according to the following schedule:
- Account and profile data: retained while your account is active, deleted within 30 days of account deletion request
- Training and performance data: retained while your account is active
- Health and injury data: retained while your account is active
- HealthKit data: retained while your account is active; stops syncing if permission revoked
- AI-generated insights: the resulting insight text is cached and retained in the App database while your account is active. Anthropic does not store your data after processing — only the generated insight output persists in our systems
- Coach notes: retained while both coach and athlete accounts are active
- Push notification tokens: updated on each app launch; removed on account deletion
Upon account deletion: all personal data is deleted within 30 days. Aggregated, anonymised statistics may be retained for service improvement. Backup copies are purged within 90 days.
15. Your Rights (GDPR)
Under the General Data Protection Regulation, you have the following rights:
- Right of access: request a copy of your personal data
- Right to rectification: correct inaccurate data
- Right to erasure: request deletion of your data
- Right to restriction: limit how we process your data
- Right to data portability: receive your data in a structured, machine-readable format
- Right to object: object to processing based on legitimate interest
- Right to withdraw consent: withdraw consent at any time (e.g. HealthKit access, AI processing)
To exercise any of these rights, contact us at matteodacruz@icloud.com. We will respond within 30 days as required by GDPR.
You also have the right to lodge a complaint with the Commission nationale pour la protection des données (CNPD), Luxembourg's data protection authority.
16. Security Measures
We implement appropriate technical and organisational measures to protect your personal data:
- Encrypted data transmission (HTTPS/TLS)
- Row-level security policies in Supabase (users can only access their own data)
- Secure authentication via Supabase Auth (bcrypt-hashed passwords)
- No plain-text storage of passwords or sensitive credentials
- Regular security reviews of database access policies
- Minimal data collection principle — we only collect what is necessary for App functionality
17. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes:
- We will update the "Effective Date" at the top of this policy
- We will notify you via push notification or in-app notice for significant changes
- Continued use of the App after changes constitutes acceptance of the revised policy
We recommend reviewing this policy periodically.
18. Contact Us
If you have questions about this Privacy Policy, your data, or wish to exercise your rights:
Email: qruza.app@gmail.com
Privacy policy URL: qruz.lu/privacy
We aim to respond to all enquiries within 30 days.