← Back to home
PRIVACY POLICY
Last updated: 2026-08-11
Information we collect
Account information: email address, username, password (stored securely and never visible to us in plain text), and any bio, country, or region you choose to add to your profile.
Content you create: photos and videos you upload as posts or challenges, captions, comments, and challenge results (e.g. weight lifted, reps, time) you choose to log.
Camera, microphone, and photo library access: used only when you choose to record or select media to post — Einher does not access these without your action.
Profile location (one-time, region-level only): when you first set up your profile, Einher may ask for your device location a single time in order to suggest your country/region for leaderboards. We do not continuously track your location for this purpose, and we do not store precise GPS coordinates from this step — only the country/region you confirm. You can skip this and set your region manually, and you can correct it at any time in Edit Profile.
Post location tagging (separate, optional, precise): when you choose to tag a location on an individual post, we do store the precise coordinates of the location you tagged, along with a display name, attached to that post. This is a separate, opt-in, per-post feature from the one-time profile region described above — it only happens when you actively tap "tag location" on a post.
Fitness and body data (optional): if you choose to add them in Edit Profile, we collect your bodyweight, height, date of birth, sex, and body-fat percentage, used to calculate relative-strength ratios, age/sex-adjusted fitness comparisons, and a body-composition tier. None of these fields are required — skipping them just means you see simpler stats without those comparisons.
Direct messages and group chat: the text content of messages you send, whether one-to-one or in a group, is stored on our servers so it can be delivered and so you can see your message history. Messages are not end-to-end encrypted.
Usage and social data: who you follow, who you block, likes, comments, and challenge participation, used to power your feed, profile stats, and leaderboards.
Push notification token: a device identifier used solely to deliver notifications. You can disable push notifications at any time in Settings.
Product usage analytics: we use PostHog to understand how people use the app so we can improve it. This is aggregate usage data, not the content of what you post or message.
Personalization data (only if you opt in): if you turn on "Personalize my feed & offers" in Settings — off by default — we track specific actions like which posts and products you view, add to cart, or share, and use that to show you more relevant content and connect you with vendors more relevant to you. You can turn this off at any time in Settings, and we stop collecting this data as soon as you do.
Crash and error data: we use Sentry to detect and fix crashes and bugs. When the app crashes or errors, Sentry may collect technical diagnostic information including your device's IP address, device type, and OS version.
Vendor/marketplace information (vendors only): if you register as a marketplace vendor, we additionally collect your business name, VAT/business registration number, and — once payments are live — a Mollie account identifier used to process payouts.
How we use this information
To operate the core features of the app: your feed, challenges, profile, leaderboards, and marketplace. To send notifications you've opted into. To enforce our community guidelines. To understand and improve how the app is used (PostHog) and to detect and fix crashes (Sentry). We do not sell your personal information to third parties. We do not use your data for advertising at this time — if that changes, this policy will be updated first.
Third-party services we use
Supabase (database, authentication, file storage) — hosts your account data and uploaded media.
Expo (push notification delivery) — relays notifications to your device.
Sentry (crash and error reporting) — receives technical diagnostic data, including IP address, when the app crashes or errors.
PostHog (product analytics, EU-hosted) — receives aggregate usage/interaction data to help us understand how the app is used.
Mollie (payment processing) — once marketplace payments are live, Mollie will process payment and payout information for marketplace purchases; this section will be expanded with specifics before that feature ships.
Each of these providers processes data on our behalf under their own security and privacy practices.
Your rights
You can edit or delete your profile information, posts, and challenges directly in the app, disable push notifications at any time, or request a copy of your data or full account deletion by contacting us at hello@einher.be. If you're in the EU/UK, you have rights under GDPR including access, correction, deletion, and data portability.
Data retention
We retain your information for as long as your account is active. If you request account deletion, we will remove your personal data within 90 days, except where required to retain it for legal reasons (for example, transaction records related to marketplace purchases).
Children's privacy
Einher is not directed at children under 13 (or 16 in the EU, where applicable). We do not knowingly collect information from children below this age.
Security
We use industry-standard practices (encrypted connections, access controls via Row Level Security) to protect your data, but no system is perfectly secure. Report security concerns to hello@einher.be.
Contact
Questions about this policy or your data: hello@einher.be