App Privacy Policy
Effective date: September 8, 2026
Last updated: September 8, 2026
Compete For Causes (“we”, “us”, “our”) is operated by Compete for Causes LLC, a California limited liability company. This policy explains what information the Compete For Causes iOS application (the “App”) collects, why, who we share it with, and the choices you have.
This policy applies only to the App. Our website at competeforcauses.com is covered by a separate privacy policy available at https://competeforcauses.com/privacy-policy-website. If you interact with a charity or other organization through a link or code they provide, information you give directly to that organization (including donations made on the organization’s own website) is governed by that organization’s privacy policy, not this one.
1. Information we collect
Health and fitness data
With your explicit permission, we read the following from Apple Health (HealthKit):
· Active energy burned (calories)
· Basal energy burned (calories)
· Step count
· Workouts (via HealthKit background delivery and observer query)
We only read this data after you grant permission through Apple’s HealthKit prompt. You can revoke this permission at any time in the iOS Health app, under Sharing → Apps. The App does not write any data back to Apple Health. Some of the health data we read (including step count) is collected and stored on our backend to support current and planned features, even where it is not currently displayed in the App’s user interface.
What we do NOT collect from Apple Health, from your device, or otherwise: GPS location, activity routes, heart rate, HRV, VO2 max, blood pressure, blood glucose, sleep data, menstrual or reproductive health data, nutrition data, medical records, or any other biometric or clinical health data.
Information you provide
· Account credentials: email address and password. Passwords are handled by Google Firebase Authentication and are never visible to us.
· Profile: name (or display name), profile photo (optional), age, weight, and gender.
· Location (optional): if you enter a city or place in your profile using the “Enter location for challenges nearby” field, the App uses Apple Maps to resolve your entry to a place name and its approximate coordinates, which we store on your profile. This is user-declared location, not device-derived. The App does not access your device’s GPS or IP-based location and does not request location permission. This field is optional and can be cleared or changed at any time.
· Challenge codes: if you join a private challenge organized by a charity, company, or other organization, you enter a challenge code that organization gave you. We store your association with that challenge.
Age, weight and gender are used solely to calculate your personalized daily calorie target. We do not use them for advertising, profiling, targeted content, or any purpose other than that calculation and the App features described in this policy.
Information collected automatically
· Usage data: a defined set of in-App events collected through Google Firebase Analytics: profile_completed, profile_updated, profile_viewed, challenge_joined, leaderboard_viewed, calorie_target_changed, healthkit_authorization, and healthkit_sync_toggled. The App does not set custom Firebase Analytics user IDs or user properties tied to your account.
· Identifiers: a Firebase user ID assigned to your account, and an Apple Push Notification token used to deliver notifications you have enabled. We also generate a Firebase Cloud Messaging (FCM) token, which we store on your user profile in our database and use solely to deliver App push notifications through Google Firebase Cloud Messaging.
· Device and diagnostic data: device model, operating system version, App version, and language, collected through Google Firebase in connection with the services listed in Section 6. The App does not include Firebase Crashlytics or Firebase Performance Monitoring.
The App does not access device GPS or IP-based location and does not request location permission; we only store the optional, user-declared location described above (Information you provide). We do not use the Identifier for Advertisers (IDFA), and the App’s privacy manifest declares NSPrivacyTracking = false. We do not display advertising in the App, we do not track you across other companies’ apps or websites, and we do not ask for permission under Apple’s App Tracking Transparency framework because we do not track.
2. How we use your information
· To calculate your daily calorie target and track your challenge progress
· To display leaderboards, rankings, and team standings within challenges you join
· To award points, streaks, and achievements
· To send you notifications you have enabled about challenges, progress, and reminders
· To operate, secure, troubleshoot, and improve the App
· To communicate with you about the App, respond to support requests, and enforce our Terms
· To comply with legal obligations and to protect the rights, safety, or property of our users or of Compete for Causes LLC
3. Health data commitments
These commitments are core to how we designed the App and are also required by Apple’s App Review Guideline 5.1.3:
· We never use HealthKit data for advertising or marketing.
· We never sell HealthKit data, or any other personal data.
· We never disclose HealthKit data to third parties for their own use.
· We never use HealthKit data for data mining or for any purpose other than health, fitness, and the App features described in this policy.
We do store the HealthKit data we read — active energy burned, basal energy burned, step count, and workout records — on our cloud infrastructure (Google Firebase, operated by Google LLC as our service provider) so that leaderboards, streaks, and challenge history work across your devices. This is described in Section 6.
4. What other users can see
Compete For Causes is a social, fitness challenge App. When you join a challenge, the following is visible to other participants in that challenge:
· Your name (or display name)
· Your profile photo, if you have added one
· Your points, rank, and challenge progress
· Team membership and team rankings
Your email address, age, weight, gender, and the raw health data we read from Apple Health are not shown to other users.
Public and private challenges. Compete for Causes challenges may be public (open to any registered App user to join without a passcode) or private (requiring a passcode shared by the Organizer). Public challenges are a supported product feature and their participant information is subject to the same visibility described above.
Choosing what to share about yourself. You are not required to submit a profile photo, and you may use a display name or nickname rather than your real name. If you prefer more privacy, we recommend using a display name and skipping the photo. You can change your name or photo, or remove your photo, from your profile at any time.
Sharing challenges outside the App. Within a challenge screen, you can tap a share button to send an invitation to a challenge (by text, email, or another messaging App on your device). When you do, the App uses the iOS system share sheet: we hand a text string to iOS, and iOS passes it to whichever App or contact you select. The Compete for Causes App does not receive, store, or process any information about the recipient you chose.
If you do not want your name or photo visible to other participants, do not join challenges.
5. Organizers of private challenges
Compete For Causes supports private challenges organized by charities, employers, clubs, for-profit companies, and other organizations (“Organizers”). If you enter a challenge code that an Organizer gave you, we associate your account with that Organizer’s challenge for the duration of the challenge.
Public visibility of Organizer challenges. All users of the App may see that a challenge exists, its name, and its Organizer’s name (for example, “Acme Wellness Challenge” or “Company X Team Challenge”). Non-participants do not see participant-level information.
Information Organizers may see. An Organizer that has an employee, representative, or contractor join a private challenge as a participant will, through that person’s participant account, see the same information any participant sees on the leaderboard: name (or display name), profile photo, points, rank, challenge progress, and team standings. Organizers do not have an administrator dashboard, back-end access to the App, or any ability to see participant-level information beyond what is displayed on the in-App leaderboard.
What Organizers do NOT receive from us. We do not send Organizers reports of participant-level information after a challenge. We do not share your email address, age, weight, gender, raw Apple Health data, or any information not visible on the in-App leaderboard with Organizers.
Donations and other transactions on Organizer websites. If an Organizer solicited donations or other payments from you on the Organizer’s own website in connection with a challenge, any information you provided there (including payment information, name, contact information, and donation or purchase amount) is governed by the Organizer’s own privacy policy. Compete for Causes LLC does not receive that information and is not responsible for that Organizer’s privacy practices. Our compensation from Organizers is handled offline between Compete for Causes LLC and the Organizer, and does not involve transfer of participant-level information to us.
6. Who we share information with
We do not sell or share your personal information for cross-context behavioral advertising, and we have not done so in the preceding twelve months. We disclose your information only as follows.
Service providers who process information on our behalf:
Google, Apple, and Intuit process this data on our instructions as our service providers. See Google’s privacy policy at https://policies.google.com/privacy, Apple’s privacy policy at https://www.apple.com/legal/privacy/, and Intuit’s Mailchimp privacy notice at https://www.intuit.com/privacy/statement/.
Email communications sent on behalf of Organizers. An Organizer of a private challenge (a charity, employer, club, for-profit company, or any other organization purchasing a private challenge) may contract with Compete for Causes LLC to send email communications to challenge participants on the Organizer’s behalf during the challenge. If an Organizer chooses this arrangement:
· The Organizer, not Compete for Causes LLC, obtains the recipient’s consent to be emailed and shares the recipient’s email address with us for this purpose. The Organizer’s own privacy policy governs how the Organizer collects and shares that information.
· We use Mailchimp (operated by Intuit Inc.) as our email service provider to deliver these communications. Mailchimp processes the email addresses on our instructions.
· We use Organizer-provided email addresses only for communications relating to the specific challenge for which they were provided. We do not add these addresses to any general Compete for Causes marketing list, and we do not use them for our own marketing.
· We delete Organizer-provided email addresses from Mailchimp within 30 days after the challenge ends, unless a recipient has separately subscribed to Compete for Causes communications through our website, in which case the separate subscription is retained under our website privacy policy.
· Every email we send under this arrangement identifies the Organizer as the party on whose behalf we are writing, identifies Compete for Causes LLC as the sender, includes a physical mailing address, and includes a one-click unsubscribe link. Unsubscribing removes the recipient from the challenge’s mailing list immediately.
Organizers of private challenges. As described in Section 5, an Organizer whose employee or representative joins a private challenge as a participant will see the same leaderboard information any participant sees. This is the only participant-level information Organizers see through the App.
Aggregated and de-identified information. We may create and share aggregated or de-identified information (for example, the total points earned by all participants in a challenge, or the number of participants in a challenge community) that does not identify you or any individual participant. When we de-identify information, we commit not to attempt to re-identify it.
Legal, safety, and corporate transactions. We may disclose your information if required by law (for example, in response to a subpoena or court order), to enforce our Terms of Use, to prevent fraud or abuse, or to protect the rights, safety, or property of our users, of Compete for Causes LLC, or of others. If Compete for Causes LLC is involved in a merger, acquisition, financing, dissolution, or sale of assets, your information may be transferred as part of that transaction, subject to the recipient continuing to honor this policy or providing you notice of any material change.
7. Data retention and deletion
We keep your information for as long as your account is active and thereafter for the period described below. In deciding how long to retain information, we consider the amount, nature, and sensitivity of the information, the purposes for which we process it, whether we can achieve those purposes through other means, and applicable legal obligations.
In-App account deletion. You can delete your account at any time from within the App — go to your Profile and choose Delete Account. Once you confirm deletion, we permanently remove your account, profile, and associated calorie and step data from our active systems. It may take up to 45 days for the deletion to propagate to our backups and system logs, after which it will no longer be recoverable.
Organizer-provided email addresses. As described in Section 6, we delete Organizer-provided email addresses from Mailchimp within 30 days after the associated challenge ends, unless the recipient has separately subscribed to Compete for Causes communications through our website.
What deletion does not affect.
· Deleting the App from your device does not delete your account. To delete your account, use the in-App Delete Account flow.
· Deleting your account does not affect data stored in Apple Health, which remains on your device under your control.
· Aggregated or de-identified information that no longer identifies you may be retained.
· We may retain limited records where required by law, to prevent fraud, or to establish, exercise, or defend legal claims.
8. Your rights and choices
Depending on where you live, you may have the following rights with respect to your personal information. To exercise any right, contact us using the information in Section 12.
· Access: request a copy of the personal information we hold about you.
· Correction: request that we correct inaccurate information. You can also update your profile directly in the App.
· Deletion: request that we delete your information. Account deletion is available directly in the App as described in Section 7.
· Portability: request that we provide your information in a portable, machine-readable format.
· Objection and restriction: object to, or ask us to restrict, certain processing of your information.
· Withdraw consent: where we rely on your consent (including your Apple Health permission), you may withdraw it at any time, without affecting the lawfulness of prior processing.
· Unsubscribe from email: you can unsubscribe from any Organizer-sponsored challenge email by clicking the unsubscribe link in that email.
· Non-discrimination: we will not deny service, charge different prices, or provide a different level of quality because you exercised a right.
· Appeal: if we deny a request, you may appeal our decision by replying to our response.
We will respond to verifiable requests within the time required by applicable law (typically 45 days). We may ask for information reasonably necessary to verify your identity before responding. You may authorize an agent to act on your behalf; we may require proof of the authorization.
If you are in the European Economic Area, the United Kingdom, or Switzerland
Compete for Causes LLC is the controller of your personal information. Our legal bases for processing are:
· Consent (GDPR Article 6(1)(a) and Article 9(2)(a) for health data): for our reading of data from Apple Health, given through the HealthKit permission prompt, and for email communications sent on behalf of Organizers where the Organizer obtained your consent. You may withdraw consent at any time by revoking Health permissions in iOS, deleting your account, or clicking the unsubscribe link in a challenge email.
· Performance of a contract (Article 6(1)(b)): for creating and operating your account and delivering the App’s core features.
· Legitimate interests (Article 6(1)(f)): for securing the App, preventing fraud and abuse, troubleshooting, and improving the product. Where we rely on legitimate interests, we have determined that our interests are not overridden by your interests or fundamental rights.
· Legal obligation (Article 6(1)(c)): where we must process information to comply with law.
International transfers. We are based in the United States, and our service providers (including Google and Intuit) process data in the United States and other countries. Where we transfer personal information from the EEA, the UK, or Switzerland to the United States, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum to the Standard Contractual Clauses, where applicable) as our transfer mechanism. Google’s and Intuit’s certifications and transfer safeguards apply as described in their respective privacy policies.
Right to complain. You have the right to lodge a complaint with your local data protection supervisory authority. A directory of EEA authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en, and the UK Information Commissioner’s Office is at https://ico.org.uk.
If you reside in California, Colorado, Connecticut, Delaware, Iowa, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah, Virginia, or another US state with a comprehensive consumer privacy law
You have the rights listed at the top of this Section 8. In addition:
· Categories of personal information we collect. Identifiers (email address, Firebase user ID, Firebase Cloud Messaging (FCM) token, push notification token), customer records (name or display name, profile photo, age, weight, gender, and optional user-declared city and coarse coordinates), geolocation (approximate/coarse, only where the user has entered a city or place in their profile), internet or other electronic network activity (in-App usage events, device and App version), and sensitive personal information consisting of health and fitness data (active energy burned, basal energy burned, step count, and workouts read from Apple Health with your consent).
· Sources of information. Directly from you, automatically from your use of the App, from Apple HealthKit (with your permission), and from Organizers who have your consent to share your email address with us for challenge communications.
· Business purposes. As described in Section 2 and Section 6.
· Categories of recipients. Service providers (as described in Section 6), Organizers of private challenges (as described in Section 5), and legal or corporate-transaction recipients (as described in Section 6).
· Sale and sharing. We do not sell your personal information and we do not share it for cross-context behavioral advertising, as those terms are defined by the California Consumer Privacy Act (CCPA/CPRA) and similar state laws. We have not done so in the preceding twelve months.
· Sensitive personal information. We do not use or disclose sensitive personal information (including your Apple Health data) for purposes other than providing the App and the services you have requested, and as otherwise permitted by law. As a result, we are not required to offer a separate “Limit the Use of My Sensitive Personal Information” link.
· Retention. As described in Section 7.
9. Children’s privacy
Compete For Causes is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will delete it. If you are a parent or guardian and believe your child under 13 has provided us with personal information, please contact us at the address in Section 12 and we will delete it.
10. Security
We use administrative, technical, and physical safeguards designed to protect your information, including encryption in transit and authenticated access. Our backend enforces authentication for all reads and writes; further restrictions on what authenticated users can read are described in Section 4 and are being actively improved. No method of transmission or storage over the internet is completely secure, and we cannot guarantee absolute security. You can help protect your account by using a strong, unique password and by promptly notifying us if you believe your account has been compromised.
11. International users
Compete for Causes LLC is based in the United States and our service providers process data in the United States. If you access the App from outside the United States, your information will be transferred to and processed in the United States. For EEA, UK, and Swiss users, please see the additional information in Section 8, including the transfer mechanisms we rely on.
12. Contact us
If you have questions about this policy or want to exercise your privacy rights, contact us:
Compete for Causes LLC
Attn: Privacy
525 San Julio Rd
Solana Beach, California 92075-2121
United States
Email: privacy@competeforcauses.com
13. Changes to this policy
We may update this policy from time to time. We will revise the “Effective date” and “Last updated” dates above. Where changes materially affect how we handle your personal information, we will provide additional notice, such as an in-App notification, before the changes take effect. Your continued use of the App after the effective date of an updated policy constitutes acceptance of the updated policy.