Last updated: 28 May 2026
This Privacy Policy explains what personal data Corporate Athlete (Powered by HybridOS) collects, why we collect it, how we use it, and what rights you have. We follow the principles of the GDPR (EU Regulation 2016/679) and equivalent local rules.
Corporate Athlete is operated as an independent project by the HybridOS team. For privacy questions or data-subject requests you can reach us at privacy@corporateathlete.app.
We collect only what we need to run the App:
We process your data on these legal grounds (GDPR Art. 6):
We work with carefully selected sub-processors. Each one acts under a data-processing agreement and only on our instructions:
Some of our sub-processors may store or process data outside the European Economic Area. Where that is the case we rely on appropriate safeguards (for example EU Standard Contractual Clauses) so that your data continues to receive an essentially equivalent level of protection.
We use a minimum of cookies and browser storage. Essential storage is used to keep you signed in, to remember your language and theme, and to keep your in-progress plan. We do not run third-party advertising cookies. Where non-essential analytics is used, it runs only with your consent or in an anonymized form.
We keep your data for as long as your account is active. After account deletion, personal data is removed from the production database within 30 days. Backups containing your data are rotated and aged out within 90 days. We may keep aggregated, non-identifying statistics longer.
Under the GDPR you can:
Most actions are available directly in the App under Account. You can also email privacy@corporateathlete.app and we will respond within 30 days. We may ask for proof of identity before acting on a request.
We apply reasonable technical and organizational measures: TLS in transit, encryption at rest provided by Supabase, hashed passwords, access controls, and audit logging on sensitive operations. No system is 100% secure. If we ever become aware of a personal-data breach affecting you, we will notify you and the supervisory authority as required by law.
The App is for adults. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, contact us and we will delete it.
We will update this Privacy Policy when our processing changes. Material changes will be communicated in-app or by email before they take effect.
privacy@corporateathlete.app for privacy matters. legal@corporateathlete.app for everything else.
© 2026 Corporate Athlete. Powered by HybridOS. All rights reserved.