Legal

Privacy Policy

Effective January 1, 2026 · Last updated May 20, 2026

Your privacy matters to us. This Privacy Policy explains what information SUPER Inc. (“SUPER”, “we”, “our”) collects when you use the SUPER app and website (the “Service”), how we use it, and the choices you have.

1. Information We Collect

We collect information in three ways:

Information you provide

  • Account data — name, email address, and password when you register.
  • Profile data — age, sex, height, weight, and fitness goals you enter to personalise your experience.
  • Workout data — exercises, sets, reps, weights, duration, and any notes you log.
  • Communications — messages you send to our support team.

Information collected automatically

  • Device data — device model, operating system version, unique device identifiers, and IP address.
  • Usage data — features accessed, screens viewed, session duration, and crash reports.
  • Health & fitness sensor data — step count, heart rate, and other metrics from your device’s sensors or connected wearables, only with your explicit permission.

Information from third parties

  • If you sign in with Apple, Google, or another provider, we receive your name and email from that provider.
  • If you connect Apple Health, Google Fit, or a wearable device, we receive the data you authorise that integration to share.

2. How We Use Your Information

  • Provide, operate, and improve the Service.
  • Personalise your workout recommendations and progress insights.
  • Process payments and manage your subscription.
  • Send transactional emails (receipts, password resets) and, with your consent, product updates and offers.
  • Analyse aggregated, anonymised usage trends to improve app performance.
  • Comply with legal obligations and enforce our Terms of Service.
  • Detect and prevent fraud, abuse, and security incidents.

We do not sell your personal health or fitness data to advertisers.

3. Legal Bases for Processing (EEA / UK)

If you are in the European Economic Area or the United Kingdom, our legal bases for processing your data are:

  • Contract — processing needed to provide the Service you signed up for.
  • Legitimate interests — improving and securing the Service, provided our interests are not overridden by your rights.
  • Consent — marketing emails and health sensor access, which you may withdraw at any time.
  • Legal obligation — where we are required to process data by law.

4. How We Share Your Information

We do not sell your personal information. We share data only in the following circumstances:

  • Service providers — we share data with trusted vendors who help us operate the Service (cloud hosting, payment processing, analytics, email delivery). These vendors are contractually bound to use your data only on our behalf.
  • Business transfers — if SUPER is acquired or merged, your information may be transferred as part of that transaction. We will notify you before your data is subject to a different privacy policy.
  • Legal compliance — we may disclose information when required by law, court order, or to protect the safety of our users or the public.
  • With your consent — in any other circumstance where you have explicitly agreed.

5. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service. If you delete your account, we delete or anonymise your personal data within 30 days, except where we are required to retain it by law (e.g. for financial records) or to resolve disputes.

6. Data Security

We use industry-standard safeguards including TLS encryption in transit, AES-256 encryption at rest, and strict access controls. No method of transmission over the Internet is 100% secure; while we strive to protect your data, we cannot guarantee absolute security. Please use a strong, unique password and enable two-factor authentication when available.

7. Your Rights and Choices

Depending on your location, you may have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Correction — ask us to correct inaccurate or incomplete data.
  • Deletion— request deletion of your personal data (“right to be forgotten”).
  • Portability — receive your data in a machine-readable format.
  • Objection / restriction — object to or restrict certain processing activities.
  • Withdraw consent — for processing based on consent, such as marketing emails.

To exercise these rights, contact privacy@superapp.io. We will respond within 30 days. If you are in the EEA or UK and believe we have not addressed your concerns, you have the right to lodge a complaint with your local data protection authority.

8. Cookies and Tracking

Our website uses cookies and similar technologies for:

  • Essential cookies — required for the website to function (authentication sessions, security tokens).
  • Analytics cookies — anonymous data about how visitors use the site, collected via privacy-respecting analytics tools.
  • Preference cookies — remembering settings like dark mode.

You can control cookies through your browser settings. Disabling cookies may affect some features of the website.

9. Children's Privacy

The Service is not directed to children under 13 (or under 16 in the EEA). We do not knowingly collect personal data from children below these ages. If you believe we have inadvertently collected such data, please contact us and we will delete it promptly.

10. International Transfers

SUPER is based in the United States. If you access the Service from outside the US, your data will be transferred to and processed in the US, which may have different data protection laws than your country. Where required, we rely on Standard Contractual Clauses approved by the European Commission to safeguard international transfers.

11. Changes to This Policy

We may update this Privacy Policy periodically. When we do, we will revise the “Last updated” date and notify you of material changes via email or an in-app notice. We encourage you to review this policy whenever you use the Service.

12. Contact Us

For privacy-related questions or to exercise your rights, contact our Privacy Team:

SUPER Inc. – Privacy Team

548 Market St, PMB 12345

San Francisco, CA 94104, USA

privacy@superapp.io