Privacy Policy
This policy explains what personal information Trybe collects, why, how long we keep it, who else sees it, and what you can do about it. It is written to be read, not to be survived.
Trybe is a social fitness challenge app. Everything below follows from that: to run a challenge we need to know who is in it and how far they have got. We collect what that requires and, deliberately, not much else.
This policy is governed by the Protection of Personal Information Act 4 of 2013 (POPIA). Where you are in a country with its own data protection law, that law may give you additional rights; nothing here is intended to reduce them.
1. Who is responsible for your information
The responsible party (in GDPR terms, the data controller) is Trybe (Pty) Ltd, registration number 2026/625046/07.
The Information Officer required by POPIA s55 is the director of Trybe (Pty) Ltd, reachable at admin@trybefit.co.za. Write to that address for anything in this policy — access, correction, deletion, or a complaint — and it reaches the person responsible for answering it.
You can also complain directly to the Information Regulator (South Africa), inforegulator.org.za, at any time. You do not have to come to us first.
2. Health and fitness data is treated differently
Under POPIA s26, information about your health is special personal information. Processing it is prohibited unless a specific exception applies — in our case, your explicit consent. We treat that seriously, and it changes how the app is built:
- Consent to health data is separate. It is its own toggle, asked for on its own, with the purpose written next to it. It is never bundled into accepting the Terms of Use, and accepting the Terms does not grant it.
- Consent is granular. Connecting Apple Health is a different decision from connecting Health Connect, which is a different decision from connecting Strava.
- Consent is revocable at any time, in the app, without asking us and without explaining yourself. Withdrawing it stops future collection and deletes the activity data already ingested from that source.
- Refusing is a supported way to use Trybe. Honour-verified and photo-verified challenges work without any health app connected at all. You are not locked out of the product for declining.
- We record what you consented to and when, including the version of this policy in force at the time, so that both of us can tell later. This record survives revocation because proving what was agreed is the entire point of it.
What we never do with health data
These are commitments, not preferences, and they are enforced in the code:
- Never used for advertising or marketing. Trybe carries no advertising and contains no advertising or analytics SDK that could receive it.
- Never sold, rented, or traded. To anyone, in any form, aggregated or not.
- Never written to iCloud or any third-party cloud backup. Apple's HealthKit terms prohibit it, and we apply the same restriction to Android Health Connect data even though Google's terms are worded differently.
- Never used to make decisions about you beyond scoring the challenges you joined. No profiling, no risk scoring, no inference about your health.
- Never shared with other users as a value. Other people see your rank and your progress towards the shared goal, which is the point of a challenge. They do not get your underlying samples.
Your device sends us challenge-scoped measurements, not your health record. A typical upload is "8,421 steps on 5 August 2026, source: Apple Health, measured by device" attached to one challenge. We do not read, request or receive heart rate, sleep, weight, blood glucose, menstrual data, medical records or clinical notes.
3. What we collect
Information you give us
| What | Why |
|---|---|
| Email address | To create and secure your account. Trybe signs you in with a code sent to your email rather than a password. |
| Display name and handle | So the people you compete against know who they are competing against. Both are visible to other users. |
| Date of birth | Age verification only. Trybe is 13+, and under-18 accounts are handled differently (see section 8). Your date of birth is never shown to other users and never used for anything else — not birthday messages, not segmentation. |
| Profile photo, bio, country, career, interests | Optional. They exist so an opponent can size you up before accepting a challenge. Everything here is visible to other users; leave any of it blank. |
| Time zone | A streak has to break at midnight where you are. Read from your device. |
Information from your activity in the app
- Challenges you create, join, leave or are removed from, and your progress in each.
- Proof photos, for challenges verified by photo. See section 4 for what happens to them.
- Group chat messages and any photos you share in them, within a challenge or club.
- Social actions — cheers, club membership, who you have blocked, content you have reported.
- Competitive results — points, rank, streak length, trophies, medals. These are public by design; scouting the competition is a feature of the product, and you can turn off individual parts of it in Settings.
- Your subscription status — whether your free trial or subscription is running, which plan it is, which store it came from, and the dates it started, renewed, was cancelled or ends. This is what decides whether the app unlocks, so it is held on our side rather than taken from your phone. It contains no payment details of any kind. It is visible to you and to nobody else using Trybe.
Health and fitness data, only if you connect a source
- Apple Health (HealthKit) — steps, active energy, and where a challenge type requires it, distance and workouts. Read on your device.
- Android Health Connect — the same measurements. Read on your device. (Samsung Health writes into Health Connect; we read it from there.)
- Strava — activities, retrieved from Strava's servers after you authorise it.
We ask for the minimum scope a challenge needs, at the time it needs it, rather than everything up front. None of this is collected until you connect the source, and connecting one source says nothing about the others.
Information collected automatically
- Push notification token, device platform and app version, so we can send the notifications you have turned on. Marketing notifications are off by default and are opt-in.
- A device identifier, used to detect one person running several accounts to win a leaderboard. This is anti-cheat, and it is the only thing it is used for.
- Technical signals attached to activity data — which app wrote a measurement, whether it was entered by hand, the device model. Public worldwide leaderboards are unwinnable without some way to tell a walk from a typed number.
- Security logs, including a truncated IP address (the last part is discarded) recorded against a consent so we can evidence it later.
What we do not collect
- Precise location. The app never requests it and the permission is blocked in the build.
- Your contacts or address book.
- Audio. The microphone permission is removed from the app at build time.
- Advertising identifiers, cross-app tracking, or anything an advertising network could use. Trybe shows no adverts. There is no tracking permission prompt because there is nothing to track you with.
- Payment card details. Your subscription is sold and charged by Apple or Google; we never see your card. What reaches us is whether your subscription is active, and when it runs out.
4. Photos and proof
Photos you upload — profile pictures, challenge covers, proof of completion, chat images — are stored privately. No bucket is public. Every image is served through a link that expires: fifteen minutes for proof photos, an hour for everything else.
We strip photo metadata on upload, including GPS coordinates. The image is re-encoded server-side before it is stored, so the location, camera serial and timestamp embedded by your phone do not survive the upload and are never stored.
Proof photos are reviewed automatically by an AI model — Claude, run by Anthropic — to check they show what the challenge asked for. The photo is sent to Anthropic only for that check, is not used to train any model, and is not kept by them beyond it. Where that is inconclusive, or where another participant disputes it, the photo may be seen by the other participants in that challenge or by a Trybe reviewer. Proof photos are never shown outside the challenge they belong to.
5. Who else sees your information
Your employer, if you join a business account
If you join a company on Trybe, the people who administer that account see you as a member and see your results in the challenges their company runs — the same standings every participant sees. They never see your health data, your other challenges, your private messages or anything you do outside their challenges, and they cannot ask us for it. Joining a company challenge is your choice each time. If you are the person setting a company up, we ask for your work email address to confirm that the domain is yours, and we keep that address and the record of the confirmation.
We do not sell your personal information. There is no circumstance in which we would. Trybe is paid for by the people who use it — a subscription, not advertising — which is the whole reason it can say that.
Other users
Your display name, handle, photo, bio, rank, points, streak and trophies are visible to other users — that is what makes a leaderboard a leaderboard. Settings lets you hide your trophy cabinet, hide your streak, stop being discoverable in search, and stop strangers challenging you.
Service providers
| Who | What they process |
|---|---|
| Supabase (database, authentication, storage) | Everything, as our hosting provider. Hosted in the EU. |
| Vercel (web hosting) | This website and the invite pages. It does not hold your account data or any health data. |
| Apple / Google push services | The delivery of a notification. Not its contents beyond the message text. |
| Anthropic (AI proof review) | Proof photos, for the automated check described in section 4. Not used to train models. |
| Resend (email delivery) | Your email address and the message itself, for the emails Trybe sends you — for example the link a business owner opens to confirm their work domain. Email is not used for marketing unless you ask for it. |
| Payfast (business billing, South Africa) | Only for businesses that buy seats: the business name, the administrator’s email address and the amount. Payfast takes the payment on its own pages and gives us back the result — we never see or hold card details. Individual subscriptions do not go through Payfast at all. |
| RevenueCat (subscription billing) | Your Trybe account identifier and the state of your subscription, so that what the App Store or Google Play tells it reaches us. It never receives your card details, and it is not given your health data, your challenges or your messages. |
| Strava | Only if you connect it, and only the activity scopes you approve. |
Each is bound to process the information only on our instructions. None of them is permitted to use it for their own purposes.
Legal disclosure
We will disclose information where the law requires it, or to protect someone from serious harm. Where we are permitted to tell you, we will.
6. Where your information is stored
Trybe's database and file storage are hosted in the European Union (Ireland, eu-west-1).
For South African users this is a cross-border transfer, and POPIA s72 permits it because the recipient is subject to a law that provides a level of protection substantially similar to POPIA — the EU's GDPR does. This is recorded in our records of processing along with the contractual safeguards behind it.
7. How long we keep it
| What | How long |
|---|---|
| Raw activity samples from health sources | 24 months from when we received them, then deleted automatically. |
| Chat messages | 36 months, then deleted automatically. |
| Administrative audit records | 7 years. These record what our staff did, not what you did, and they exist so that action can be accounted for. |
| Account and profile | Until you delete your account. |
| Consent records | Kept after withdrawal, because a record that disappears when consent is withdrawn cannot evidence that consent existed. |
These are scheduled jobs, not a policy someone has to remember to apply.
8. Children and young people
Trybe is for 13 and over. We ask for your date of birth at signup to enforce that.
If you are under 18, POPIA s34 requires the consent of a competent person — normally a parent or guardian — before we may process your information. So:
- Your account is created in a limited state and you cannot use it yet. We email the guardian address you give us with a verification link.
- Until your guardian confirms, there are no social features and no public challenges. You cannot be found by strangers.
- No behavioural profiling of under-18s, ever — before or after confirmation. No targeted content, no marketing notifications.
- A guardian may withdraw consent at any time, which deletes the account and everything in it.
- The request expires if it is not answered, and the unconfirmed account is removed with it.
If you believe a child under 13 has an account, tell the Information Officer and we will remove it.
9. Your rights, and how to use them
POPIA gives you the following rights. Every one of them is exercisable inside the app, under Settings, because a right that requires writing an email and waiting is a right with a queue in front of it.
| Right | How |
|---|---|
| Access — see what we hold | Settings → Your data. Lists every category of information held about you. |
| Correction | Edit your profile directly. For information you cannot edit — a score, a verification result — request a correction from the same screen. |
| Deletion | Settings → Delete account. Your account is disabled immediately and permanently erased after 30 days, so that a deletion made in anger or under pressure can be reversed. Deletion cascades through everything, and third-party connections such as Strava are revoked at the provider. |
| Portability | Settings → Export my data. We build a complete JSON and CSV bundle and send you a private link to it. The link expires. |
| Objection and withdrawal of consent | Turn off any health connection, or any notification category, whenever you like. Withdrawing health consent deletes the ingested data as well as stopping collection. |
| Complaint | To our Information Officer, or directly to the Information Regulator. You do not need our permission or our involvement. |
A "disconnect" that leaves your data behind is not a disconnect, and we do not implement it that way.
10. How we protect it
- Access rules are enforced by the database itself, on every query, rather than by the app asking nicely. An attacker holding the app's public key and a valid account still cannot read another person's rows.
- Everything is encrypted in transit. Third-party access tokens are encrypted at rest.
- Sign-in tokens are stored in the device's secure hardware store — the iOS Keychain or the Android Keystore.
- All file storage is private. Nothing is served from a public bucket.
- Staff access to the administration console requires two-factor authentication, and every administrative action is recorded in a log that cannot be edited or deleted by anyone, including us.
- Health values never appear in application logs.
If a breach affects your personal information we will notify you and the Information Regulator as POPIA s22 requires.
11. Changes to this policy
If we change what we collect or what we do with it, we will update this page and the version recorded against your consent. Where the change is material, the app will ask you again rather than assume the old answer still applies. Continuing to use Trybe after a minor change means you accept the updated policy.
12. Contact
Information Officer: the director of Trybe (Pty) Ltd, admin@trybefit.co.za.
Postal address: 294 Outeniqua Avenue, Brentwood Park, Pomona, 1619, South Africa.
See also our Terms of Use.