Privacy Policy
Last updated: January 16, 2026
Introduction
Goal Gauntlet ("we," "our," or "us"), operated by Data Savvy, Inc., is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our mobile application.
Information We Collect
Account Information
When you create an account, we collect:
- Email address
- Display name
- Profile photo (optional)
Health and Fitness Data
With your explicit permission, we access health data from your device's health platform (Apple HealthKit on iOS, Health Connect on Android):
- Step count
- Distance traveled
- Calories burned (active and total)
- Exercise/workout data
- Sleep data
This health data is used solely to track your progress in fitness challenges. We sync this data to our servers to calculate leaderboard standings and challenge results.
Challenge and Activity Data
- Challenges you create or join
- Your progress and scores in challenges
- Team memberships and roles
- Chat messages within challenges
Payment Information
If you participate in challenges with prize pools ("buy-ins"):
- Payment transactions are processed by Stripe
- We do not store your full credit card information
- We receive confirmation of successful payments and basic transaction details
Device Information
- Device type and operating system
- App version
- Push notification tokens (if notifications are enabled)
How We Use Your Information
- To provide fitness challenge functionality and track your progress
- To calculate leaderboard standings and determine challenge winners
- To process prize pool distributions
- To enable team competitions and social features
- To send notifications about challenge updates, results, and reminders
- To improve our services and user experience
Data Sharing
We do not sell, trade, or rent your personal information. We may share data only:
- With other challenge participants: Your display name, profile photo, and challenge progress are visible to other participants in challenges you join
- With service providers:
- Supabase (database and authentication)
- Stripe (payment processing)
- Expo (push notifications)
- If required by law or to protect our rights
Data Retention
- Account data is retained until you delete your account
- Health data synced for challenges is retained for the duration of the challenge plus 90 days
- Completed challenge results are retained for historical records
- You can request deletion of your data at any time
Your Rights
You have the right to:
- Access your personal data through the app
- Update or correct your profile information
- Revoke health data permissions at any time through your device settings
- Delete your account and associated data
- Opt out of push notifications
Health Data Privacy
We take the privacy of your health data seriously:
How We Access Health Data
- Health data is only accessed when you explicitly grant permission
- We request read-only access; we never write to your health records
- You can revoke access at any time through your device's Health Connect (Android) or Apple Health (iOS) settings
- If you revoke permissions, we stop syncing new health data immediately
How We Use Health Data
- To track your progress in fitness challenges you have joined
- To calculate and display your ranking on challenge leaderboards
- To determine challenge winners based on verified activity metrics
- Health data is aggregated daily (e.g., total steps per day) for challenge tracking
What We Do NOT Do
- We do not sell your health data to third parties
- We do not share your health data with advertisers
- We do not use your health data for advertising or marketing purposes
- We do not share raw health data outside of challenge contexts
- We do not retain health data longer than necessary for challenge participation
Data Security
- Health data is transmitted securely using TLS encryption
- Data is stored in secure, access-controlled databases
- Only aggregated progress data (not raw health records) is visible to other challenge participants
Children's Privacy
Our service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us.
Security
We implement appropriate security measures to protect your information:
- All data transmission is encrypted using TLS/SSL
- Passwords are hashed and never stored in plain text
- Access to user data is restricted and logged
- Regular security audits and updates
International Data Transfers
Your data may be transferred to and processed in the United States where our servers are located. By using the app, you consent to this transfer.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes through the app or via email. Continued use of the app after changes constitutes acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy, please contact us at:
Email: support@doerfy.com
Address:
Data Savvy, Inc.
Jacksonville, Florida
United States