Skip to content

    Privacy Policy

    Last updated: July 2026

    Information We Collect

    We collect the information you give us when you create an account, buy tickets or merchandise, register for a fight camp, apply to Chimp-2-Champ, or contact us: your name, email address, phone number, date of birth (used to confirm your age), gender, and, where you provide them, your mailing address and social handles. Card details go directly to Stripe and never reach our servers. We also record what you do on the platform — training logs, class and camp attendance, Cred and Arena activity, orders and tickets, and messages you send through the app. Four kinds of information are collected automatically rather than typed in, and each has its own section below: your IP address, your location when you check in at a gym, health and nutrition data, and device and diagnostic data.

    IP address

    We store IP addresses in three places in our application records, and nowhere else in them: yours, when you submit a form on our site (including when you have no account); the scanning device's, when a ticket is scanned at an event door — that address belongs to the staff phone doing the scanning, powers a rate limit that blocks forged-ticket attempts, and is kept as evidence if a scan is later disputed; and yours, as part of the signed record when a fighter accepts a bout waiver in the app. Waiver records are readable by our systems only, never by our staff. Each of these is kept as part of the record it belongs to and is not deleted on a separate schedule. Separately, our sign-in service keeps standard security logs of account activity, and those logs include the IP address each sign-in came from. We never use your IP address to work out where you are.

    Location

    Location is used for exactly one thing: confirming that you are physically at a partner gym when you check in for training. It is never collected in the background — only while the app is open, only when you tap to check in, and only after you have given a separate, express consent for it. That consent is enforced on our server, not just in the app: without it on file, a location check-in is refused outright. Your device sends its coordinates so we can test them against the gym's boundary; we discard them immediately and keep only which venue matched, how far you were from its centre in metres, and how accurate your device reported the reading to be. Your exact position is never stored. The one exception is under your control: if you suggest a new training venue, the pin you submit is kept so we can review it, rounded to roughly 110 metres.

    Health, fitness and nutrition

    If you use the Fight-Camp Nutrition Guide or the training features, we hold sensitive health information: height, current and past weight, body-fat percentage and lean mass, biological sex, age, your goal and any weight-class target, allergies, dietary restrictions, meal logs, and any free-text notes you write. The nutrition intake includes a short eating-disorder screening questionnaire; your answers and the resulting score are stored, with restricted access. Your private profile may also hold an emergency contact and medical notes, and a coach may record an injury flag with a note and a date range. Coaches you train with can see this information by default; you can turn that sharing off at any time in your social preferences, and the screening answers are hidden from coaches whenever weight sharing is off. Guides are generated with help from an external AI provider — what is sent to it is listed under “Who processes your data” below, and it does not include your identity, your raw measurements, your medical notes or your questionnaire answers.

    Device and notifications

    If you turn on notifications, we store a push token for that device — or, on the web, a push endpoint and its keys — together with the browser or device description your device reports. We use it to deliver the alert and to stop sending to devices that no longer exist. Turning notifications off deactivates the token so nothing more is sent to it; the stored token itself is removed when you delete your account. The Android app also sends a device identifier to our update service — see “Diagnostics and error reporting” below.

    How We Use Your Information

    We use your information to provide and improve our services, process transactions, communicate with you about events and promotions, manage your fight camp enrollment, and ensure the security of our platform.

    Diagnostics and error reporting

    Two different things collect diagnostics, and they are not the same promise. On the website and web app, an error beacon records what broke and where: the message and technical details, the page it happened on (with identifiers removed), your browser type, and the app build. It carries no name, no email, no account ID and no IP address, it stays on our own infrastructure, and it is deleted after 90 days.

    In the Android app, over-the-air updates are delivered by Capgo, a third-party service. Every time the app checks for an update it sends Capgo a device identifier that survives reinstalling the app, along with your Android version and whether the app is running on an emulator. The app also reports crashes, freezes and out-of-memory shutdowns to Capgo, with the technical details of how the app stopped. None of this is tied to your name, email or account.

    You can turn the crash and performance reports off on this device using the controls below, or from your profile settings. Turning them off does not stop the device identifier — the app still has to ask whether an update exists — so if you would rather not be identified to our update service at all, use the web app instead of the Android app.

    Share error diagnostics

    Send first-party error and crash reports (technical details and browser type, not tied to your account) to help us fix bugs. Applies to this device.

    Data Retention

    We keep your personal information for as long as your account is active, or as long as we need it to provide the service. Training logs, fight records and camp participation are retained to keep historical records and leaderboards accurate. Some records outlast an account on purpose: door-scan records, including the IP address of the scanning device, are kept as an audit trail for disputed entries. Web diagnostics are deleted after 90 days. When you delete your account we remove your personal data as described on our account deletion page.

    Who processes your data

    We do not sell your personal information and we do not share it with advertisers. We do use service providers that process it on our instructions and under contract. These are all of them:

    • Supabase — our database, sign-in, file storage and server functions. This is where everything described above is held.
    • Cloudflare — serves the website and app. Sees your IP address and browser as it does so; holds no account data.
    • Stripe — payments, refunds and coach payouts. Handles your card details directly; we never receive your card number.
    • Google, through Firebase Cloud Messaging — delivers push notifications to your device.
    • Capgo — delivers over-the-air updates to the Android app and receives the app diagnostics described above.
    • OpenRouter, routing to Anthropic — generates your nutrition guide. It receives your goal, food preferences, allergies, dietary restrictions, your free-text notes, your calculated targets, your language, whether you are a minor, and your training and eating pattern: sessions per week, minutes per session, meals per day, budget, cooking ability, and camp phase — plus a signal if the screening questionnaire indicated a risk. It does not receive your name, your account, your raw measurements or your questionnaire answers.
    • Resend — sends transactional email such as camp and bout invitations.
    • Shopify — runs our merchandise store. Product images load into your browser directly from Shopify, so it sees your IP address, and any purchase you make there is between you and Shopify.
    • YouTube, part of Google — hosts embedded livestreams, replays and camp videos. When one of those players loads, YouTube receives your IP address and may set cookies.

    All of these providers operate on infrastructure in the United States, so your personal information is processed outside Quebec. We rely on contractual protections for that transfer rather than on any finding that United States law offers equivalent protection. You can ask our Privacy Officer for details.

    Privacy Officer (Person in charge of the protection of personal information)

    Caged Ape Fight Club has designated a Privacy Officer responsible for the protection of the personal information we hold and for overseeing our compliance with Quebec's Act respecting the protection of personal information in the private sector (Law 25).

    You may contact the Privacy Officer to ask a question about this policy, to access or correct your personal information, to withdraw consent, to request deletion or a copy of your data, or to make a privacy complaint:

    Privacy Officer — Caged Ape Fight Club

    Email: privacy@cagedapefightclub.com

    We respond to rights requests within 30 days. If you are not satisfied with our response, you may contact the Commission d'accès à l'information du Québec (cai.gouv.qc.ca).

    Contact Us

    If you have questions about this privacy policy or your personal data, please contact us at hello@cagedapefightclub.com