SILVERBACK STRENGTH CLUB
Privacy Policy
Last updated: May 2026
Silverback Strength Club ("the App", "we", "us") is operated by Silverback Gymwear Ltd, registered in England & Wales. This policy explains what data we collect, how we use it, and your rights under GDPR and applicable privacy laws.
1. What We Collect
- Account information: display name, username, email address, profile photo, password hash (when signing up or signing in via Google or Apple)
- Training data: lift type, weight, reps, video recordings of your lifts, AI analysis scores and feedback
- Profile data: gym location, town, county, country, age range, gender, weight class, bodyweight
- Usage data: app activity, leaderboard interactions, comments, kudos, follows, XP progression
- Device information: push notification token (only if you opt in for workout reminders)
2. How We Use Your Data
- To authenticate your account and keep it secure
- To display your lifts on the community leaderboard (only if you choose to share them)
- To provide AI-powered lift analysis and feedback
- To calculate DOTS scores and rank progression
- To send push notifications (only if you explicitly opt in)
- To send marketing emails (only if you explicitly opt in during registration)
- We do not sell your personal data to third parties
3. Legal Basis for Processing (GDPR)
- Contract: account creation, authentication, and core app functionality
- Consent: marketing communications, AI analysis of your videos, push notifications
- Legitimate interest: fraud prevention, app security, and community moderation
4. Third-Party Services
- Google Sign-In: we receive your name, email, and profile photo. We do not access Google Drive, Gmail, or other Google services.
- Apple Sign-In: we receive your name and email (or Apple private relay email).
- Cloudflare R2: stores your lift videos securely. Data is encrypted in transit and at rest.
- OpenAI: lift videos may be sent to OpenAI for AI form analysis. Videos are processed temporarily and not retained by OpenAI for training purposes per their API data policy.
- Klaviyo: used for marketing emails if you opt in. You can unsubscribe at any time.
5. AI Processing of Videos
When you request AI analysis of a lift video, the video is sent to OpenAI's API for processing. OpenAI does not use API-submitted data to train their models. Analysis results (scores and feedback text) are stored in our database and displayed to you. You can delete your videos and AI analysis at any time.
6. Video Data
Lift videos are stored securely on Cloudflare R2. Private lifts are only accessible to you. Public lifts are visible to the community. When you delete a lift or your account, the associated video files are permanently removed from R2 storage.
7. Data Retention
- Account data: retained while your account is active
- Deleted content: permanently removed within 30 days of deletion
- Backups: encrypted backups are retained for up to 90 days, after which deleted data is irretrievable
- Analytics: anonymised usage statistics may be retained indefinitely
8. Cookies and Local Storage
The App uses local storage for authentication tokens and user preferences. We do not use tracking cookies or third-party analytics cookies.
9. Your Rights (GDPR)
- Access: download all your personal data from Profile > Privacy & Data > Download My Data
- Correction: update your profile information at any time in the app
- Deletion: delete your account and all data from Profile > Privacy & Data > Delete Account
- Portability: your data export is provided in JSON format
- Objection: opt out of marketing emails via the unsubscribe link or by contacting us
- Restriction: contact us to restrict processing in specific circumstances
10. Children's Privacy
The App is not intended for users under 16. If you are under 16, do not use the App or provide any personal information. If we learn we have collected data from a child under 16, we will delete it promptly.
11. International Transfers
Your data is stored on servers in the United Kingdom and European Union. Video processing via OpenAI may involve temporary transfer to the United States. OpenAI participates in the EU-US Data Privacy Framework.
12. Security
All data is transmitted over HTTPS with TLS 1.3. Passwords are hashed using bcrypt. Videos are encrypted at rest on Cloudflare R2. We regularly review our security practices.
13. Changes
We may update this policy occasionally. Significant changes will be notified via email or in-app notice. Continued use of the app after changes constitutes acceptance of the updated policy.
14. Contact
Data Protection Officer:
Silverback Gymwear Ltd
Email: pete@silverbackgymwear.com
Website: silverbackgymwear.com
If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO).