Security & Privacy

Built to protect the people who use it.

Athivo handles sensitive fitness data, live location, and identity. Here’s exactly what we do to earn and keep your trust.

Our privacy principles

Privacy by design

GDPR compliance is built into every feature from the start — not added as an afterthought. Every new feature is assessed for data minimisation before it ships.

Data minimisation

We collect only what we need. Live location is never stored. Raw biometric data from identity verification is never retained by Athivo.

You control your data

You can download all your data, correct your profile, or delete your account entirely — from within the app, at any time.

No advertising

We do not sell, share, or licence your data to advertisers or data brokers. Athivo is funded by subscriptions, not by monetising your attention.

Security measures

🔒

Encrypted in transit

All data between the app and our servers uses TLS 1.3. Connections that do not meet this standard are rejected.

💾

Encrypted at rest

Your data is encrypted at rest in our database and file storage, using AES-256.

🛡️

Row-level security

Every database table has row-level security (RLS) enforced at the database layer. You can only read and write your own data.

🔑

Admin MFA required

All administrative access to our infrastructure requires multi-factor authentication. Production credentials are rotated regularly.

🕵️

Vulnerability monitoring

Our dependencies are scanned continuously for known vulnerabilities. Critical issues are patched within 72 hours of disclosure.

📋

Minimal data access

We apply the principle of least privilege. No team member has access to production data they do not need for their role.

Compliance status

Active

UK GDPR

We operate in full compliance with the UK General Data Protection Regulation and the Data Protection Act 2018. Our Privacy Policy is maintained and updated with every feature change.

Active

App Store & Play Store

Athivo meets Apple’s App Store and Google’s Play Store privacy requirements, including compliant account deletion, data export, and in-app privacy disclosures.

Planned

SOC 2 Type II

We are building toward SOC 2 Type II certification, covering Security, Availability, and Confidentiality trust service criteria. Target: 2027.

Planned

ISO/IEC 27001

Our Information Security Management System (ISMS) roadmap targets ISO 27001 readiness as we scale toward enterprise features. Target: 2027.

Subprocessors

We use the following third-party services to operate Athivo. Each has a signed Data Processing Agreement (DPA) where required.

ServiceRoleRegionDPA
SupabaseDatabase, auth, storageEU
PostHogProduct analyticsEU
Google Maps PlatformAddress search & geocodingEU/US
Apple (APNs)Push notifications & Sign InUS
Google (FCM)Push notificationsUS
ExpoApp infrastructure & OTA updatesUS
Identity verification providerID & liveness verificationEU

Your rights, in the app

Download your data

Export everything we hold about you as a structured JSON file. Profile → Download My Data.

Correct your data

Update your profile, city, photo, bio, and preferences at any time from Profile → Manage Profile.

Delete your account

Permanently delete your account and all personal data in under 30 seconds. Profile → Delete Account.

Responsible disclosure

If you discover a security vulnerability in Athivo, please report it to us privately before disclosing it publicly. We commit to:

  • Acknowledging your report within 72 hours
  • Investigating and providing a status update within 7 days
  • Working with you on a coordinated disclosure timeline
  • Publicly crediting researchers who responsibly disclose valid issues

Report to: privacy@athivo.co.uk with the subject line “Security Disclosure”.

Please do not perform destructive tests, access other users’ data, or disclose before we have had a reasonable opportunity to address the issue.