AWAKEN

Privacy Policy

Last updated: 2026-09-20

Who we are

Awaken ("the app") is operated by Deividas Karuza, Woellmerstrasse 17, 21075 Hamburg, Germany ("we"), who is also the controller for the purposes of the GDPR. Contact: support@getawaken.app.

What we collect

Account data. Your email address and a hashed password (or, in future, your Google account identity), managed by our backend provider Supabase.

Fitness profile. What you enter during onboarding and profile edits: age, height, weight, self-reported sex, training experience and history, weekly schedule, training goal, and free-text injury notes. This calibrates your in-game character and your training plan.

Training activity. Workout logs (exercises, sets, reps, weights, timestamps), quest and game progress (XP, levels, ranks, coins, skills, titles), and your training-plan state.

Social content. Content you choose to publish: public profile (display name, avatar image, bio, badges), posts and attached photos, comments, likes, follows, guild membership and contributions, and chat messages (global, guild, and direct). Posts, comments, and profiles are visible to all app users. Direct messages are visible to their participants.

Feedback and reports. Feedback you submit (with app version and platform) and any content reports you file.

Crash diagnostics. If the app crashes, a report is sent to Sentry containing the error, a stack trace, your app version, and device model and OS version. It is not tied to your name and carries no training data.

What we do NOT collect. No advertising identifiers, no location data, no contacts, no background sensor data, and nothing from Google Fit, Health Connect or any other health platform. The app itself contains no ads and no analytics or tracking SDKs. Nothing is shared for advertising, and nothing is sold.

Subscription data. If you buy Ascendant, we store your subscription status, tier, renewal date and an anonymous purchase identifier so the app knows what you are entitled to. We never receive or store your card details — Google Play handles payment as seller of record, and we only learn whether a subscription is active.

Website analytics. Our website at getawaken.app uses Vercel Web Analytics to count visits. It sets no cookies and stores nothing on your device, and it does not track you across other sites. It records the page you viewed, the site that referred you, and a coarse device type, browser and country. These are aggregated for traffic statistics and are not linked to your account, your email, or any identifier that lets us single you out. This applies to the website only — installing the app does not enable any of it.

How we use it

We do not sell your data or use it for advertising.

Where it lives

Data is stored in our Supabase project — a Postgres database plus file storage for avatar and post images — hosted in the European Union (Ireland, eu-west-1). Row-level security restricts access at the database level: your private data (logs, plans, quests, messages) is readable only by your account; public content is readable by signed-in users. Progression values are writable only by our server, never by a device.

Who processes it for us

We use these providers, each only for the purpose named:

Provider Purpose Where
Supabase database, authentication, file storage EU (Ireland)
Sentry crash reports EU (Germany)
Google Gemini API generating and adapting training plans Google infrastructure
Resend transactional email (sign-up, password reset) EU/US
Expo (EAS) app distribution and over-the-air updates US
Google Play app distribution, and payments if you subscribe Google infrastructure
Vercel our website, the waitlist form, and website analytics EU/US
RevenueCat subscription status and purchase validation US

Where a provider processes data outside the EU, that transfer relies on the European Commission's Standard Contractual Clauses.

Retention and deletion

Your data is kept while your account exists. You can delete your account in-app (Settings → Account & Security → Delete account). Deletion removes your auth record and cascades to your character, logs, plans, posts, comments, messages, image metadata, and social graph.

Three things outlive that deletion, and you should know about all three: encrypted database backups hold data for up to 7 days before rotating out; reports other users filed about your content are kept as moderation history, though once your account is gone the reference identifies nobody; and closed-season leaderboard results are kept as a record of the game, with your name and picture cleared from them. Crash reports expire on Sentry's own retention schedule (90 days).

A guild you founded is not deleted with you: it passes to its longest-serving remaining member. See Delete your account for the full list of what goes and what stays.

Legal bases

Under the GDPR we rely on: contract (Art. 6(1)(b)) to run your account, your training and the game; legitimate interests (Art. 6(1)(f)) to keep the service secure, moderate the community and fix crashes; and consent (Art. 6(1)(a)) where you choose to publish content or submit free-text injury notes for plan generation. You can withdraw consent by deleting that content or your account.

Your rights

You have the right to access, rectify, export, restrict, object to, and erase your data, and to lodge a complaint with a supervisory authority. Write to support@getawaken.app and we will respond within one month; in-app account deletion covers erasure immediately.

The competent authority for us is the Hamburgische Beauftragte für Datenschutz und Informationsfreiheit, Ludwig-Erhard-Str. 22, 20459 Hamburg.

Children

The app is not for anyone under 16. We do not knowingly collect data from children under 16; if you believe a child has an account, write to us and we will remove it.

Changes

We may update this policy during the beta; material changes will be announced in-app.