Privacy Policy

Last updated: 14 May 2026 • Version: MVP

This Privacy Policy describes how ProveUp (“ProveUp,” “we,” “us,” or “our”) collects, uses, discloses, and protects information when you use the ProveUp mobile application for iOS and Android (the “Application”) and the services made available through it (collectively, the “Service”). This Policy is incorporated into and forms part of the ProveUp Terms of Service. Capitalized terms not defined here have the meanings given in the Terms of Service.

By using the Service you confirm that you have read this Privacy Policy and understand the data practices described in it. If you do not agree with these practices, please do not use the Service.

1. Who We Are and the Scope of This Policy

1.1 Data Controller

ProveUp is the controller of Personal Information processed in connection with the Service. For questions or to exercise your rights under this Policy, contact us at alpetpon51pro@gmail.com.

1.2 What This Policy Covers

This Policy applies to all data processed through the Application, including data captured by the device camera, microphone, and other sensors as described in Sections 5 and 5A of the Terms of Service. This Policy does not cover the privacy practices of third parties not affiliated with ProveUp, including BCS Arena and the operators of third-party authentication services (Apple, Google) and mobile-platform stores.

1.3 Children

The Service is not directed to children under thirteen (13). The Service uses an at-registration eligibility gate (date-of-birth entry plus an express attestation checkbox, as described in Section 2.2 of the Terms of Service) to prevent registration by such children. See Section 9 below for additional detail on age-related practices.

2. Categories of Data We Collect

We collect the following categories of information about Users. The exact data fields collected depend on which features of the Service you use.

2.1 Account & Profile Data

  • Authentication identifiers from Apple Sign-In, Google Sign-In, or SMS one-time-passcode verification (e.g., third-party user ID, verified phone number, basic profile claims released by the identity provider).
  • Username or nickname; first and last name.
  • Date of birth and age-eligibility attestation status (see Section 9).
  • Gender, country of residence, height, weight.

2.2 Camera and Video Data (AI-Tracking System)

  • Real-time Video Stream captured by your device camera while a Battle (Competitive or Friendly) or Solo Training session is active.
  • Pose/motion data derived from the Video Stream by the AI-Tracking System (skeletal keypoints, repetition counts, exercise classification, timing).
  • Session metadata: exercise type, duration, scores, error events.

To the extent any of this data constitutes “biometric information” under applicable state law (such as the Illinois Biometric Information Privacy Act (“BIPA”), 740 ILCS 14/1 et seq., or similar Texas, Washington, or other state statutes), we handle it consistent with Section 7 below.

2.3 Microphone and Voice Data (AI Coach)

  • Voice Input — raw audio captured by your device microphone while the AI Coach session is active and you are speaking to it.
  • Voice Transcripts — the textual conversion of Voice Input produced by speech-to-text (“STT”) processing.
  • AI Coach prompts and responses, including LLM-generated text and synthesized speech (“TTS”) output.
  • Voice-feature metadata such as session timestamps, language code, latency, and STT/TTS error counters.

Voice Input (raw audio) is handled subject to the retention limits described in Section 6.3. Voice Transcripts and AI Coach response logs are handled as described in Section 4.4.

2.4 Gameplay and In-Application Activity

  • Participation history in Competitive Battles, Friendly Battles, Solo Training, and Missions.
  • Energy, XP, Points balances and history; Virtual Goods owned.
  • Leaderboard ranking, level, and competitive metrics (derived from Competitive Battles only; Friendly Battle outcomes do not contribute to ranking or progression, consistent with Section 7.3 of the Terms of Service).
  • Avatar customization choices.

2.5 Device and Technical Data

  • Device model, operating system and version, app version, locale and language settings.
  • IP address, approximate (city/region) geolocation derived from IP, time zone.
  • Crash logs, performance diagnostics, and error telemetry.
  • Mobile advertising identifier (“IDFA” / “GAID”) only where you have not opted out at the OS level and only for permitted analytics or attribution purposes (no advertising as of this version of the Application).

2.6 Communications and Support Data

  • Email correspondence with alpetpon51pro@gmail.com (e.g., support requests, deletion requests, arbitration opt-out notices).
  • Bug reports or feedback you voluntarily submit.

2.7 Data We Do NOT Collect

ProveUp does not knowingly collect, and asks Users not to provide, the following through the Application or the AI Coach:

  • Government-issued identification numbers.
  • Payment-card numbers, bank-account numbers, or other financial-account credentials. The Application does not process real-money transactions.
  • Health information beyond the limited self-reported profile fields listed in Section 2.1 (height, weight). The AI Coach is not a health-information-collection tool; do not disclose medical, diagnostic, or prescription information to it.
  • Precise (GPS) location.

3. How We Use This Data

We use the categories of data described above for the following purposes:

  • Service provision — to create and maintain your account, authenticate you, deliver the Application’s features (including Battles, Solo Training, AI Coach, Avatar, Missions, the in-Application Store, and Leaderboards), and operate the Virtual Item economy.
  • AI-Tracking System — to detect, classify, and count physical movements in real time so that exercise sessions can be tracked and scored within the Application.
  • AI Coach — to capture your voice, convert it to text, process it with a large language model, and return spoken and textual responses; and to log inputs and outputs in accordance with Section 4.4 for service operation, quality, and safety review.
  • Product improvement — to improve the accuracy of the AI-Tracking System and the AI Coach, to debug, to develop new features, and to evaluate Service performance — using aggregated, anonymized, or, where lawful, identifiable data within strict access controls.
  • Safety, fraud, and security — to detect, prevent, and respond to fraud, cheating, abuse, and security incidents; to enforce the Terms of Service; and to investigate misuse of the AI Coach (for example, attempts to submit prohibited content via voice).
  • Legal compliance — to comply with applicable law, respond to lawful requests, and exercise or defend legal claims.
  • Communications — to respond to support requests, send service-related notices (e.g., security alerts, material changes to the Terms or this Policy), and — only with your consent where required — send other notifications.

3.1 Legal Bases (EEA / UK Users)

If you are located in the European Economic Area, United Kingdom, or another jurisdiction with similar requirements, we rely on the following legal bases under the General Data Protection Regulation (“GDPR”) and equivalent law: (a) performance of a contract — to deliver the Service you requested when you agreed to the Terms; (b) your consent — for camera access, microphone access, and any processing of biometric-adjacent data, which you may withdraw at any time as described in Section 8; (c) our legitimate interests — in operating, improving, and securing the Service, where these interests are not overridden by your rights and freedoms; and (d) legal obligation — to comply with applicable law.

4. AI Coach — Voice Processing in Detail

IMPORTANT NOTICE: The AI Coach is a voice-enabled feature. It requires access to your device microphone and involves the transmission of your voice (or its textual conversion) to ProveUp and to authorized third-party speech and language-model providers. This Section 4 describes those flows in detail.

4.1 Microphone Permission

The Application requests microphone access at the operating-system level only when you first invoke the AI Coach or another voice-enabled feature. If you decline, the AI Coach will not be available in voice mode; you may, where supported, still interact with the AI Coach in text mode.

4.2 The Voice Pipeline

When you speak to the AI Coach, the following sequence occurs:

(a) Capture — The device microphone records Voice Input only while the AI Coach session is active and your microphone is unmuted in-Application.

(b) Streaming — Voice Input is streamed over an encrypted (TLS) connection to ProveUp’s backend infrastructure and/or directly to an authorized third-party STT provider.

(c) Speech-to-Text — The STT provider converts the audio into a Voice Transcript.

(d) LLM processing — The Voice Transcript is submitted to the LLM provider powering the AI Coach. The provider returns a textual response.

(e) Text-to-Speech — ProveUp and/or a TTS provider converts the LLM response into synthesized speech, which is streamed back to the Application for playback. The textual response may also be displayed in-Application.

4.3 Third-Party Voice / LLM Subprocessors

ProveUp uses authorized third-party subprocessors for STT, LLM, and TTS functions. The current list of subprocessors, including their location of processing, is maintained at https://ProveUp.app/subprocessors and will be updated from time to time. Each subprocessor is bound by a written data-processing agreement that requires the subprocessor to: (a) process Voice Input, Voice Transcripts, prompts, and responses solely to provide the contracted service to ProveUp; (b) refrain from using such data to train the subprocessor’s own foundation models, except to the extent expressly permitted by ProveUp and consistent with this Policy; (c) maintain appropriate technical and organizational security measures, including encryption in transit and at rest where applicable; and (d) delete or return all such data upon termination of the subprocessor engagement, subject to legal retention requirements.

4.4 What We Log, What We Don’t

Raw audio (Voice Input). ProveUp does not retain raw Voice Input audio beyond the duration of an AI Coach session. Audio is used solely for real-time STT conversion and is discarded once the corresponding Voice Transcript has been produced, except where: (i) short-term in-memory buffering is technically required to deliver the service (typically seconds); (ii) retention is necessary to investigate a specific security incident, fraud, or violation of the Terms of Service, in which case the audio is retained only for the minimum period required and on a need-to-know basis; or (iii) retention is required by applicable law or legal process.

Voice Transcripts and AI Coach responses. Voice Transcripts (textual) and the corresponding AI Coach responses may be logged in ProveUp’s systems and reviewed by authorized ProveUp personnel or contractors for service operation, safety review, abuse investigation, and product-quality improvement, subject to Section 6 retention limits.

Voice-feature metadata. Aggregated or anonymized voice metrics (latency, language code, error rates) may be retained for operational and analytic purposes without identifying individual Users.

4.5 Sensitive Information — Please Do Not Disclose

Because Voice Transcripts may be reviewed and retained as described above, please do not disclose to the AI Coach — by voice or in text — any medical, diagnostic, prescription, financial, government-identification, or other sensitive personal information about yourself or any third party. If you do, ProveUp will treat such information consistently with this Policy, but you should not rely on the AI Coach as a confidential channel.

5. Camera and Video Processing

5.1 Camera Permission

The Application requests camera access at the operating-system level when you first invoke a feature requiring the AI-Tracking System. If you decline, AI-Tracking System functionality is unavailable; other Application features may remain accessible.

5.2 What Is Transmitted

While the AI-Tracking System is active, the Video Stream (or motion/pose data derived from the Video Stream) is transmitted to ProveUp’s servers and/or to authorized third-party computer-vision processing infrastructure. Each third-party computer-vision subprocessor is contractually required to: (a) process Video Stream data solely to provide the AI-Tracking System to ProveUp; (b) maintain appropriate security measures; and (c) delete or return such data upon termination of the engagement.

5.3 Friendly Battles

Camera processing applies to Friendly Battles in the same manner as Competitive Battles — the AI-Tracking System requires the Video Stream to detect movements regardless of competitive mode. As described in the Terms of Service, Friendly Battles do not consume Energy, do not award XP/Points, and do not affect Leaderboards; this does not change the camera-data handling.

5.4 Retention of Video Data

  • Raw Video Stream frames are not retained beyond the duration of a session, except where retention is necessary for dispute resolution, fraud prevention, or compliance with applicable law.
  • Aggregated or anonymized motion analytics may be retained for product improvement in a form that does not identify individual Users.
  • Upon account deletion, User-specific Video Stream data and identifiable derived data will be deleted within thirty (30) days, subject to legally mandated retention obligations.

6. Retention

We retain Personal Information only for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. The following retention rules apply by category:

6.1 Account & Gameplay Data

Retained for the life of your account. Upon account deletion, deleted within thirty (30) days, except where a longer period is required by law (e.g., to satisfy legal-hold or financial-record obligations).

6.2 Camera / Video Data

As described in Section 5.4 above.

6.3 Microphone / Voice Data

  • Raw Voice Input audio: not retained beyond the session, except for the narrow security and legal carve-outs described in Section 4.4.
  • Voice Transcripts and AI Coach responses: retained for up to twelve (12) months from creation, or such shorter period as we determine appropriate, after which they are deleted or fully anonymized.
  • Upon account deletion, identifiable Voice Transcripts associated with the account will be deleted within thirty (30) days, subject to legally mandated retention obligations.

6.4 Technical / Diagnostic Data

Crash logs and performance telemetry are typically retained for up to ninety (90) days, then aggregated or deleted.

6.5 Communications

Support correspondence is retained for as long as reasonably necessary to provide support and to address legal claims, typically up to two (2) years from the most recent interaction.

7. Biometric Privacy Notice (BIPA and Similar Laws)

The AI-Tracking System processes images of your body to detect pose and motion. Although ProveUp does not use this data to identify individuals (no facial recognition, no biometric identifier creation for identity-verification purposes), some of this data may, depending on the jurisdiction, fall within the scope of biometric-privacy statutes such as the Illinois Biometric Information Privacy Act (740 ILCS 14/1 et seq.), the Texas Capture or Use of Biometric Identifier statute, or the Washington biometric law.

7.1 Purpose of Collection

Where any data we process constitutes a “biometric identifier” or “biometric information” under applicable law, we collect, store, and use it solely to provide the AI-Tracking System feature — i.e., to detect physical movements and count exercise repetitions in the course of Battles and Solo Training.

7.2 Disclosure

We do not sell, lease, trade, or otherwise profit from biometric-adjacent data. We disclose such data only to: (a) authorized service providers that process it solely on our behalf to provide the Service, under written agreements consistent with Section 5.2 above; or (b) where required by law, valid legal process, or to protect the rights, property, or safety of ProveUp, our Users, or others.

7.3 Retention and Destruction

Biometric-adjacent data is retained no longer than necessary for the purposes described above and in any event is destroyed in accordance with the timelines in Sections 5.4 and 6.3, or earlier as required by applicable law.

8. Your Choices and Rights

8.1 Permissions and Withdrawing Consent

  • Camera. You may revoke camera permission at any time through your device operating system settings. The AI-Tracking System will be disabled.
  • Microphone. You may revoke microphone permission at any time through your device operating system settings. The voice mode of the AI Coach will be disabled.
  • Notifications, advertising identifiers. Manage through your device operating system settings.

Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

8.2 Account Deletion

You may delete your account at any time through the in-Application settings or by contacting alpetpon51pro@gmail.com. Upon deletion, retention rules in Section 6 apply.

8.3 Rights Under U.S. State Privacy Laws (CCPA / CPRA and Similar)

If you are a resident of California, Virginia, Colorado, Connecticut, Utah, or another U.S. state with comprehensive consumer privacy legislation, you may have the right to:

  • Know what Personal Information we have collected about you and how we use and disclose it.
  • Access a copy of that Personal Information.
  • Correct inaccurate Personal Information.
  • Delete Personal Information, subject to legal exceptions.
  • Opt out of “sales” or “sharing” of Personal Information, and of certain profiling. ProveUp does not sell Personal Information and does not share Personal Information for cross-context behavioral advertising.
  • Be free from discrimination for exercising your rights.

To exercise these rights, contact alpetpon51pro@gmail.com. We may need to verify your identity before responding. You may authorize an agent to act on your behalf; we will require reasonable proof of such authorization.

8.4 Rights Under EEA / UK Law (GDPR)

If you are located in the EEA or UK, you have the rights of access, rectification, erasure, restriction, objection, portability, and the right to withdraw consent at any time. You also have the right to lodge a complaint with your local data-protection authority.

8.5 How to Submit a Request

Send privacy requests to alpetpon51pro@gmail.com with the subject line “PRIVACY REQUEST”. We respond within the time limits set by applicable law (generally 30–45 days).

9. Age Eligibility and Parental or Guardian Consent

9.1 Minimum Age

The Service is intended for Users who are at least thirteen (13) years of age. We do not knowingly collect Personal Information from children under thirteen (13).

9.2 MVP Self-Attestation Model

During the current MVP release of the Application, ProveUp does not deploy verifiable parental-consent infrastructure (such as credit-card verification, government-ID verification, or independent identity-verification services). Instead, at registration each User is required to: (a) enter a date of birth; and (b) expressly confirm, by means of a checkbox attestation, that the User is at least eighteen (18) years of age or, if the User is between thirteen (13) and seventeen (17) years of age, that the User has obtained the consent of a parent or legal guardian to use the Service.

Users who fail to meet the age gate or fail to make the required attestation cannot complete registration.

9.3 Limitations of the MVP Model

ProveUp acknowledges that self-attestation is a less robust mechanism than verifiable parental consent. The MVP model is appropriate for a service that (i) is not directed to children under 13 and (ii) does not, when used as intended, knowingly collect Personal Information from such children. We commit to:

  • Promptly delete Personal Information if we become aware that it was collected from a child under thirteen (13).
  • Provide a clear and easy mechanism for parents and guardians to request review, access, or deletion of Personal Information about a Minor User by contacting alpetpon51pro@gmail.com.
  • Evaluate, ahead of any post-MVP release that materially expands the Service or its audience, whether to introduce additional age-assurance or verifiable parental-consent measures consistent with applicable law (including COPPA, the EU’s GDPR-K provisions, the UK Age-Appropriate Design Code, and U.S. state child-privacy laws).

9.4 Parental / Guardian Contact

Parents or guardians who believe that a child under thirteen (13) has provided Personal Information through the Service, or who wish to review, correct, or delete information about a Minor User between thirteen (13) and seventeen (17), should contact us at alpetpon51pro@gmail.com. We will respond within the timelines required by applicable law.

10. When and With Whom We Share Data

We disclose Personal Information only as follows:

  • Service providers / subprocessors. Cloud hosting, computer-vision, STT, LLM, TTS, analytics, crash reporting, and customer support providers — each engaged under written agreements that limit their use of data to providing the contracted service to ProveUp. The current list of subprocessors is at https://ProveUp.app/subprocessors.
  • Authentication providers. Apple and Google receive the authentication information necessary to verify your sign-in; SMS gateway providers receive your phone number to deliver one-time passcodes.
  • Other Users. Public profile information (username, Avatar, level, XP, Competitive Battle performance statistics, Leaderboard standings) is visible to other Users by design. Friendly Battle results are not displayed on public Leaderboards.
  • Legal and safety. Where required by law, valid legal process, or to protect the rights, property, or safety of ProveUp, our Users, or others (e.g., fraud investigations, response to a court order).
  • Business transfers. In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or substantially all of our assets, Personal Information may be transferred subject to standard confidentiality safeguards and to this Policy.

We do not sell Personal Information. We do not share Personal Information for cross-context behavioral advertising. The Application currently displays no third-party advertising.

10.1 BCS Arena and Other Third-Party Links

If you follow a link from the Application to BCS Arena or any other third-party site, that site’s own privacy policy will govern. ProveUp does not transfer your Personal Information to BCS Arena as part of the navigation.

11. International Data Transfers

ProveUp operates from, and processes data in, the United States. If you access the Service from outside the United States, your information will be transferred to, stored in, and processed in the United States and other jurisdictions in which our service providers operate. Where we transfer Personal Information of EEA / UK / Swiss data subjects across borders, we rely on appropriate transfer mechanisms such as the European Commission’s Standard Contractual Clauses (SCCs) or the UK International Data Transfer Addendum, supplemented by additional safeguards where necessary.

12. Security

ProveUp maintains administrative, technical, and physical safeguards designed to protect Personal Information against unauthorized access, alteration, disclosure, or destruction, including encryption in transit (TLS), encryption at rest where applicable, access controls, and incident-response procedures. No system is perfectly secure, however, and you are responsible for keeping your authentication credentials confidential. Promptly notify ProveUp at alpetpon51pro@gmail.com of any actual or suspected unauthorized use of your account.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will post the revised Policy to the Application and, where required by law or otherwise appropriate, provide advance notice through the Application or by email. The “Last updated” date at the top reflects the most recent revision. Your continued use of the Service after the effective date of a revised Policy constitutes your acceptance of the revised Policy, except where additional consent is required by law.

© 2026 ProveUp. All rights reserved.