Privacy Policy

Effective Date: May 21, 2026  ·  Last Updated: May 22, 2026 (US-and-non-EU launch posture; CCPA + lawful basis + sensitive PI + retention specifics)

This Privacy Policy describes how Renshi ("we," "our," or "the App") collects, uses, and protects your information when you use the Renshi mobile application.

Renshi is operated by Ian Fritz as a sole proprietorship based in Utah, United States. Contact: renshicombat@yahoo.com.

Service availability. Renshi is currently offered to residents of the United States and other countries outside the European Union (EU), the European Economic Area (EEA), and the United Kingdom (UK). When you create an account, you affirm that you are not a resident of those regions. We do not knowingly accept signups from those jurisdictions at this time; we may expand availability in the future, and if we do, this policy will be updated to reflect the additional rights that apply to residents of those regions under the GDPR and UK GDPR.

1. Information We Collect

When you create an account and use Renshi, we collect:

Account information

Email address and password (passwords are hashed and never stored in plain text), display name, username (handle), self-selected training track (e.g., wrestling, BJJ, boxing, MMA), and an optional bio.

Profile content

Profile photo and banner image, if you choose to upload them.

Workout data

Activity type, intensity, duration, notes, focus areas (e.g., muscle groups, drilling focus), conditioning type, recovery type, and an optional photo attached to each workout. Includes derived statistics: XP totals, attribute scores, streak counts, weekly goals, training-camp progress, weight-cut entries, and badges.

Competition data

When you log a competition (tournament, meet, fight, or match), we collect: the event name, the date it occurred, your match results (a list of wins/losses with optional per-match notes, up to 50 entries), your self-rated intensity (1–5), short tags describing what went well and what needs work, free-text notes, and an optional photo. Competitions feed your win-loss record on your public profile and may be referenced in feed posts you choose to share.

Internal audit log

When you edit or delete a workout, we record an audit entry (timestamp, action taken, and a snapshot of the prior + new values). This log is visible only to you in your account's history view and is deleted with your account.

Social data

Follow relationships (who you follow and who follows you), team memberships, posts you share to the public Feed (which automatically expire from other users' feeds after 24 hours but remain visible on your profile), blocks, reports, and badges you've unlocked.

Subscription data

Subscription status, plan (monthly or yearly), trial dates, renewal status, and the Renshi user ID we pass to our subscription processor (RevenueCat) so it can associate purchase history with your account. Payment information (card details, Apple ID, App Store transaction IDs) is handled entirely by Apple and RevenueCat — we never see or store your payment method.

Device and usage data

Basic technical information necessary to operate the app, such as session tokens, timestamps, app version, and crash diagnostics.

Crash data

When the app encounters an unexpected error, we collect: a stack trace, the type of device (e.g., iPhone 15), the iOS version, and the Renshi app version. This is sent to our crash reporting provider (Sentry — see §3.1) to help us fix bugs. We do not attach your Renshi user ID, email, or handle to crash reports. Our crash reporter is configured to omit your IP address. Crash reports cannot be linked back to your identity by us or by Sentry.

Product interaction events

We log basic event signals (for example: "signed in," "completed onboarding," "logged workout," "subscribed to premium") to our own Supabase database. Each event includes the event name, a timestamp, the app version, the platform (iOS or Android), and (for signed-in users) your Renshi user ID. We use this to understand which features are being used and to spot drop-offs in onboarding or other flows. By design, event properties never contain personally identifying free-text fields — when we record a signal that might otherwise include identifying content (for example a handle collision during sign-up), we send only a derived signal such as the handle's length, never the handle itself. This is a convention enforced in our analytics module and at code review; we do not route raw user-generated text (handles, names, emails, bios, workout notes, feed-post bodies, comment text) through event properties. These events stay inside our own Supabase project — we do not share them with any third-party analytics, advertising, or attribution network.

Photo metadata is removed before upload

Before any photo you attach (workout, profile, or banner) leaves your device, we strip its EXIF data — including location, camera model, and date — using two layers of defense (the picker is configured to omit EXIF, and our upload pipeline re-encodes the image to drop any remaining metadata).

Sensitive personal information

Some of the data above (workout duration and intensity, weigh-in entries, training-camp progress, and similar fitness signals) qualifies as fitness or health-related information under California's CPRA and similar laws. We process this category of data solely to deliver the app's core training-tracker features — leaderboards, attribute scoring, training-camp planning, and weight-cut tracking — and not for advertising, profiling beyond those features, or any other purpose. You can stop generating new fitness data at any time by not logging workouts; you can erase all of it by deleting your account from Settings → Delete Account.

We do not collect:

2. How We Use Your Information

We use your information solely to operate, maintain, and improve Renshi. Specifically:

No marketing email. We do not send marketing or promotional email today. If we ever add a marketing channel, it will be opt-in only and every message will carry a one-tap unsubscribe link. The only emails you'll receive from Renshi today are the transactional messages listed above.

No sale, no behavioral advertising. We do not sell your personal information, share it with advertisers, or use it for cross-app, cross-site, or cross-context behavioral tracking or advertising. Renshi has no advertising SDKs and does not collect data linked to your identity for tracking purposes (see App Store privacy label: "Tracking: No"). For California residents: under the CCPA/CPRA, "sale" and "sharing" have specific legal meanings; we do not engage in either as those terms are defined. See §10 (Your California Privacy Rights) for more.

Algorithmic leaderboards and scores are not "automated decisions." Renshi computes leaderboard rankings, XP totals, attribute scores, and your OVR rating algorithmically from the activity you log. These rankings are intended for the app's gamification and social features and have no legal effect on you, do not significantly affect your finances, employment, healthcare, or any other consequential aspect of your life, and are not "automated decision-making" in the regulatory sense.

Lawful bases for processing. Where applicable privacy laws (other than the GDPR — see Service availability above) require us to name a legal basis for each processing purpose, our bases are:

3. How Your Information Is Shared

3.1 Third-party service providers

Your information is processed by the following service providers under contract, who act on our behalf:

ProviderWhat it doesWhat it receivesPrivacy Policy
Supabase, Inc.Hosts our Postgres database, authentication system, and file storage (profile photos, banners, workout photos).All app data listed in §1, plus session tokens.supabase.com/privacy
RevenueCat, Inc.Processes subscription state, validates Apple receipts, and stores purchase history linked to your Renshi user ID.Your Supabase user UUID (passed to Purchases.logIn), subscription transaction history, plan, renewal status. No payment card data.revenuecat.com/privacy
Apple Inc.Processes payments, manages In-App Purchases, and distributes the app.Whatever you submit through the App Store: Apple ID, billing, App Store transaction IDs.apple.com/legal/privacy
Sentry (Functional Software, Inc.)Crash reporting — receives an automatic report each time the app encounters an unexpected error.Stack trace, iOS version, device model, app version. No Renshi user ID, no email, no handle, no IP address. Configured to drop personally-identifying information before any event leaves your device.sentry.io/privacy
GitHub, Inc.Hosts this Privacy Policy, our Terms of Service, and our password-reset web page via GitHub Pages (renshicombat.github.io).When you tap "Privacy Policy" or "Terms of Service" in the app, your device requests the page from GitHub. GitHub logs requests under their own terms (typically including IP address and User-Agent). No app data is sent to GitHub.github.com/site/privacy

We do not use any other third-party processors. We do not embed advertising SDKs, attribution SDKs, or product-analytics SDKs that track user behavior. The only diagnostic SDK we use is Sentry, configured solely for crash reporting (see above). Each processor above operates under a data-processing addendum or equivalent contractual safeguards consistent with their published terms.

3.2 What other Renshi users can see

Renshi is a social workout-tracking app. By design, certain information is visible to other authenticated Renshi users:

Always visible to all other authenticated Renshi users:

Conditionally visible:

Important disclosure (workouts). Individual workout records (including activity, intensity, duration, focus area, notes, and any attached photo) are stored in our database with row-level security policies that allow other authenticated Renshi users to read your workout records via the in-app social and leaderboard surfaces. This means that, technically, a determined user could read individual workout details by querying our backend directly — not only the summary statistics we surface in the UI. If this is not acceptable for your use case, please do not log sensitive notes or photos. We are evaluating tightening this access on a future release; this disclosure exists so you can make an informed choice today.

Profile content note. Because our profiles table is readable by every authenticated user (so the leaderboard, follow graph, team rosters, and Discover screen work), all of the "always visible" fields above are accessible to any user with a Renshi account, not only to your followers.

3.3 Legal disclosures

We will disclose your information if required by law, valid legal process, or to protect the safety, rights, or property of users or the public.

4. Data Retention and Deletion

While your account is active, we retain the data you generate (profile, workouts, competitions, training camps, weigh-ins, scheduled sessions, audit log entries, follows, team memberships, badges, achievements, Feed posts, blocks, reports, and any photos you've uploaded). You can delete your account and all associated data at any time from Settings → Delete Account, or by emailing us at renshicombat@yahoo.com.

Specific retention periods for non-account data:

Deletion is permanent and removes the following within 30 days:

After deletion completes, RevenueCat retains your subscription history under their separate retention policy (for tax, fraud, and accounting reasons) — see their policy for details. Apple separately retains your App Store purchase records under Apple's policies; we have no control over Apple's retention.

5. Your Rights — Including "Download My Data"

Depending on where you live, you may have the right to:

How to download a copy of your data

Renshi does not yet have an in-app "Export my data" button. To request a copy of your data:

  1. Email renshicombat@yahoo.com from the email address you signed up with.
  2. Include the subject line: "Data export request".
  3. State your Renshi handle (e.g., @yourhandle).

We will reply within 30 days with a JSON or CSV bundle containing your profile, workouts, follows, posts, badges, and team memberships — and signed URLs for any photos you've uploaded. The bundle excludes derived data we cannot meaningfully port (e.g., other users' content), and excludes payment data (which lives with Apple / RevenueCat).

To exercise any other right, email renshicombat@yahoo.com. We respond within 30 days.

6. Security

We use industry-standard security measures, including:

No system is perfect; we cannot guarantee absolute security. If we discover a breach that affects your data, we will notify you and the relevant authorities within the timeframes required by applicable law.

7. Children's Privacy and Moderation

Renshi requires you to be at least 13 years old to create an account. We do not knowingly collect information from anyone under that age.

If you believe a child has provided us information, or if you encounter user content involving a suspected minor in distress, please email renshicombat@yahoo.com with the subject line "Minor safety report". We review every such report within 24 hours and remove violating content immediately, suspend the reporting target's account, and — if the content suggests harm to a child — file a report with the National Center for Missing & Exploited Children (NCMEC) when applicable.

For minor-safety reports specifically, please use the email path described above — it reaches us directly and is the fastest escalation route. The in-app Report flow also offers a "Minor in danger" reason that opens your mail app pre-addressed to that inbox with the correct subject line; tapping it routes your report through the same email channel as if you'd composed it manually.

For all other report categories (spam, harassment, sexual content, violence or self-harm, or "other"), tapping the menu on any Feed post, profile, or team files the report into our moderation console. We review the moderation console regularly with a target review time of 24 hours.

8. International Users

Renshi is operated from the United States. Our service providers (Supabase, RevenueCat, Sentry, Apple, GitHub) primarily process data in the United States. If you use the App from outside the U.S., your data will be transferred to and processed in the U.S., where data protection laws may differ from your country.

As stated at the top of this policy, Renshi is not currently offered to residents of the European Union, European Economic Area, or United Kingdom. When you create an account you affirm that you are not a resident of those regions. If we expand availability to those jurisdictions in the future, we will update this policy to disclose the additional cross-border-transfer mechanisms (Standard Contractual Clauses, the EU-US Data Privacy Framework, and equivalents) that apply, and we will provide the additional GDPR / UK GDPR rights and contact paths (including an EU representative) that residents of those regions are entitled to.

For all other international users: by using Renshi, you consent to your data being transferred to and processed in the United States.

9. App Tracking Transparency (iOS)

Renshi does not track you across other apps or websites. Specifically:

If we ever add a feature that requires tracking, we will request ATT permission before any tracking event fires, update this Privacy Policy with the relevant disclosures, and update the App Store nutrition label.

10. Your California Privacy Rights

This section is provided for California residents under the California Consumer Privacy Act of 2018 ("CCPA"), as amended by the California Privacy Rights Act of 2020 ("CPRA"). Renshi may or may not meet the statutory thresholds that make every CCPA obligation legally binding on us; we adopt these practices proactively as a baseline. If you are a California resident, you have the rights described below.

Categories of personal information we collect and have collected in the last 12 months:

CCPA categorySpecific data
IdentifiersEmail, display name, handle, Renshi user ID, Supabase auth UUID, RevenueCat user ID
Customer recordsAccount information (§1 above)
Commercial informationSubscription status, plan, trial dates, redemption history
Internet / electronic network activityProduct interaction events, crash diagnostics, app version, platform
GeolocationNone. We do not collect precise or coarse location data.
Audio, electronic, visual informationProfile photo, banner image, workout photos, competition photos (no audio)
Professional / employmentNone.
EducationNone.
InferencesDerived statistics (XP totals, attribute scores, streak counts, OVR rating)
Sensitive personal information (CPRA)Fitness / health-related data (workout intensity, duration, weigh-ins, training-camp progress)

Purposes: see §2 ("How We Use Your Information").

Sources: directly from you (when you create an account, log workouts, etc.) and from our service providers (subscription state from RevenueCat, crash data from Sentry).

Recipients: the service providers listed in §3.1 (Supabase, RevenueCat, Apple, Sentry, GitHub). We do not "sell" your personal information and we do not "share" it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We have not sold or shared personal information in the preceding 12 months.

Your CCPA/CPRA rights:

How to exercise these rights: email renshicombat@yahoo.com with the subject line "CCPA request" and state which right you're exercising. We will respond within 45 days (we may extend by another 45 days with notice if needed).

"Shine the Light" (California Civil Code §1798.83): Renshi does not share personal information with third parties for those third parties' own direct marketing purposes, so there is nothing to disclose under this law.

11. Changes to This Policy

We may update this policy from time to time. When we do, we'll change the "Last Updated" date above and, for material changes, notify users in the App or by email. Continued use of Renshi after a change means you accept the updated policy.

12. Contact

Questions about this policy? Email renshicombat@yahoo.com.

For privacy / data rights requests, please use the subject line patterns listed in §5 and §10 so we can route them quickly.