Privacy Policy

Scorch · Last updated 19 September 2026

This policy covers the Scorch app, scorch.run and early-access requests. Scorch combines outdoor activity recording, a territory game, private indoor training tools and optional community features. For privacy questions or requests, contact razanians313@gmail.com. Practical help is on our Support page.

Account and activity information

InformationPurpose and storage
Account and profileEmail, authentication records, account ID, username and optional bio, city, country and profile photo are handled by our Supabase app backend. They support sign-in, account security and your profile. Passwords are handled by the authentication service; the app does not store your password as a profile field.
Outdoor workouts and imported GPX filesRecorded GPS points can include precise latitude, longitude, time, accuracy and altitude. Saved workouts include activity type, distance, duration, pace, recording source and game-validation results. The app keeps recovery and pending-upload data on your device and sends saved workouts to Supabase for your history and eligible game actions.
Territory and game recordsTerritory shapes, capture times, activity type, strength, coins and cosmetic choices are stored in Supabase to calculate and display gameplay. Speed and route checks may flag a workout or prevent a territory reward; they are not medical assessments.
Clubs and Convoy groupsClub descriptions, membership and ownership, plus Convoy codes, start position, participants, activity and group results are stored in Supabase to run the group features.
Earlier coaching recordsCoach enrollment, the directory, profile editing, follows and coaching requests have been removed from the current app interface. Earlier coach roles, drafts, published profiles, follows and request records may remain in Supabase; requests can include participants, messages, status and timestamps. Removing these screens does not automatically delete those records or remove copies held by earlier app versions. Contact support about access or deletion, or use account deletion.
Safety and supportReports, block relationships, report details and relevant public-content snapshots support abuse handling. If you email support, your message and any information or attachments you choose to include are handled through email.

Local information and optional private backup

Body settings and goals: optional height, weight, birth year and sex support fitness estimates and personal settings. These fields are kept in account-scoped local storage and are not included in the app's workout uploads. Phone step and motion readings are used locally where the device supports them. These readings and estimates are not a diagnosis.

Indoor training: your indoor journal, unfinished sessions, duration, optional distance, exercises, sets, repetitions, load and notes are stored on your device. Optional private backup is being tested in eligible Expo Go previews; it remains disabled in production app builds. Before any upload or restore on a device, the signed-in account must explicitly choose to enable private backup. After that choice, new completed indoor and strength sessions can be sent to Supabase, including their record IDs, times and the training fields you entered, and restored to that account on another eligible device. Earlier device-only entries are not automatically uploaded. Unfinished sessions and Moments photos or videos are outside this backup feature. A local save or a pending upload is not confirmation that a cloud backup completed.

Moments and photo tools: selected photos and videos, captions, gym text and attached indoor statistics are stored in the app's private local journal. There is no public Moments feed or automatic upload of this journal. A profile picture is different: choosing one saves it to your cloud profile. Video files you select can retain their original embedded metadata.

Saved plans, recovery files and queued uploads also use local storage. The weekly Chapter and kit checklist have been removed from the current app interface, but earlier local preferences may remain until account cleanup; removing a screen does not erase its existing data. Language, appearance and other device preferences may remain between account changes. Local storage is not the same as an encrypted backup service; device security, operating-system backups and copies you export can affect how long information remains available.

Location and device permissions

You can change permissions in device settings. Refusing a permission limits the features that need it. The current app does not connect to Apple Health, Health Connect, Garmin or live heart-rate devices; recorded activities can instead be imported manually as GPX files.

What other people can see

Signed-in Scorch users can see community territory shapes, your username, chosen colour and game information. Map photos depend on your map-photo setting. Standings and recent captures can also display profile and game information. Hiding yourself from standings does not hide your territory or recent captures; switching off your map photo does not remove it from every other feature.

A privacy zone in Settings masks the chosen area from territory shapes shown to other users. Its centre is stored with your private profile so the server can apply it. It does not erase the underlying GPS workout, change your own map view or remove coordinates from your GPX exports. Hiding community content is a viewing preference, not a setting that makes your account invisible.

Club directories display club information; membership rosters are available to members with applicable visibility and block restrictions. Convoy participants can see group information and results. The current app no longer offers coach discovery or coaching interactions. Previously published coach information and participant-only requests are retained under the existing backend access rules; this interface change does not revoke earlier publication or perform a database deletion. Contact support to request removal of earlier records. Self-reported qualifications and social handles were not verified credentials or proof of account ownership.

Gym clans are currently in limited preview testing. In this preview, a community-created clan's name, venue, city and approximate map pin can be shown to other signed-in users, together with aggregate member counts and weekly consistency totals. These are community-supplied gym locations, not verified venues or member check-ins. A requested nearby search uses your position to calculate distance; it does not add that position to gym membership records. Membership and competition choices are stored for your account. Joining a clan and opting into consistency scoring are separate choices from enabling private backup. Only eligible new completed sessions backed up after joining and opting in can contribute. The clan summary does not publish your private workout, exercises, loads, notes, media, exact location or individual attendance. Visibility settings and supported blocks also affect the displayed totals.

Sharing a photo, video or export opens your device's share options. Scorch does not automatically post it to Instagram, Snapchat or another service. Recipients and services you choose can keep or redistribute copies, including previously shared Chapters, under their own rules. The current app has no connected Instagram account access, automatic social posting, public gym-video contest or event feed.

Use in-app report and block controls for supported community content. Reports are not public posts; they can preserve a restricted snapshot of the reported material. Blocking limits supported interactions and visibility, but cannot recall copies already obtained. See our Community Guidelines.

Services that receive information

The current app does not include advertising or cross-app advertising-tracking integrations. Services below process information to provide features, deliver messages, operate infrastructure or diagnose problems. An external request can reveal your IP address and other network or device metadata even when Scorch does not attach your account ID.

ServiceInformation and purpose
SupabaseAuthentication and the app's cloud records listed above. The current main database is configured in West Europe (London, United Kingdom). That database region is not a guarantee that all provider operations or support processing stay in that country.
Resend and email servicesRecipient addresses, account-confirmation and security messages, and delivery information for transactional email. Your own email provider also receives messages delivered to your mailbox. Support correspondence uses email.
CloudflareWebsite requests and network information for hosting and security; submitted early-access details in D1. Waitlist abuse prevention uses a keyed identifier derived from the IP address rather than storing the raw IP in its rate-limit table. Identifiers rotate in ten-minute windows and expired counters are removed during cleanup; this does not describe Cloudflare's separate infrastructure logs.
Platform map servicesNative map display and device geocoding use the platform's map services, including Apple or Google depending on the device. Map areas, location and place queries may be processed to provide those features.
Photon, operated by KomootPlace-search text and, when used to rank nearby app results, coordinates rounded to two decimal places. Website city suggestions send the city text you type.
BRouterSelected route start, destination and intermediate coordinates, at up to six decimal places, plus a walking or cycling routing profile, to calculate a planned route.
Open-MeteoCoordinates rounded to three decimal places, approximately 100 metres, when you request a temperature sticker.
SentryOptional JavaScript crash diagnostics and sampled performance information help investigate reliability. Reporting is off by default. You can choose Settings → Privacy → Share diagnostics for the current account during this app session, and turn it off there at any time. A fresh choice is required after the app restarts. Signing out or switching accounts stops the previous account's reporting; a choice made by another account during this session applies only to that account. Known account, request, token and location fields are removed or redacted before diagnostic events are sent. These safeguards do not make every diagnostic necessarily anonymous. Turning reporting off prevents new collection; requests already transmitted cannot be recalled. Earlier reports remain subject to the provider's retention arrangements. Native crash collection, native diagnostic caching and reporting in development builds are disabled.
Services you open or share toSocial profiles, music apps, product resources and your chosen share destinations process your visit or shared content under their own policies. Opening a link is not a Scorch account connection or a purchase through Scorch.

These providers may process information internationally. A provider's infrastructure, support and retention arrangements can differ from the main database region. Contact us with questions about a particular service or transfer.

Website and early access

The website stores a language preference in your browser. Submitting early access saves your email, optional city and activity, signup source and timestamp in Cloudflare D1 so we can manage the list and contact you about availability. This does not create an app account. City suggestions can contact Photon before you submit the form.

To remove a waitlist entry or stop early-access messages, contact razanians313@gmail.com from the address you used. App-account deletion does not automatically remove a separate waitlist entry.

Retention and deletion

Cloud account and activity records remain while the account exists unless removed through an available control or a supported request. Local journals and files remain on that device until removed. Scorch does not currently apply a general automatic expiry period to account histories, indoor journals, Moments or early-access entries.

Deleting a privately backed-up indoor session removes its stored workout content and records a deletion marker linked to your account and that record ID. This marker prevents a delayed upload from recreating the session and lets other devices reconcile the deletion when they next sync. These markers do not currently expire automatically; deleting the account removes them. A device-only entry has no cloud backup to delete. Offline deletions remain pending until the service confirms them.

During gym-clan preview testing, deleting a contributing session, leaving its clan or withdrawing competition consent revokes the affected contributions. A private consumed-day marker remains to prevent scoring the same day again, even after changing clans or opting back in. It contains account, clan and session identifiers, the contribution day and receipt time, and revocation status; it does not retain the workout content. These markers have no automatic expiry and are removed with the account. Action receipts preserve membership changes and their results for safe retries.

Settings → Delete account requests removal of the current backend's sign-in record and associated profile, workouts, territories, coach records, privately backed-up indoor records and deletion markers. It also removes that account's gym membership, action receipts and contribution markers. The app then attempts to clear that account's local journals, media, private preferences, plans, queued uploads and recovery data. A failed local cleanup is reported. See Delete your account for the request route if you cannot use the app.

Deletion has limits:

Your choices and rights

Depending on applicable data-protection law, you may request access, correction, deletion, restriction or portability, object to processing, and withdraw consent where consent is the basis for processing. Withdrawal does not undo earlier lawful processing. Send requests to razanians313@gmail.com; we may need information to verify that a request concerns your account. Do not email passwords, confirmation codes or unnecessary identity documents.

You can edit profile information, manage supported visibility settings, remove local Moments and change device permissions. Available exports include an individual outdoor session as GPX, an indoor journal as JSON and media you choose to share. GPX exports contain the private route, including coordinates inside a privacy zone. These tools are not a complete export of every account record; contact us for other access requests.

You may raise a concern with your local data-protection authority. Our Support and account-deletion pages provide contact options.

Children

Scorch is intended for people aged 13 and over, subject to a higher minimum age or parental-consent requirements under applicable local law. The app does not verify age at registration; optional birth-year entry is a fitness setting, not age verification. Do not use Scorch if you do not meet the applicable requirements. If you believe an underage child has provided information, contact us so we can investigate and handle the account and data request.

Security and policy changes

Scorch uses encrypted network connections, account-scoped database access controls and secure native session storage. Local fitness journals and selected media are not all stored in the authentication keychain. Protect your device and account, and share only information you intend others to receive. No security control removes every risk.

The date above identifies this version. Updates will be published on this page. Read it alongside our Terms and Community Guidelines.