Built to protect the people who use it.
Athivo handles sensitive fitness data, live location, and identity. Here’s exactly what we do to earn and keep your trust.
Our privacy principles
Privacy by design
GDPR compliance is built into every feature from the start — not added as an afterthought. Every new feature is assessed for data minimisation before it ships.
Data minimisation
We collect only what we need. Live location is never stored. Raw biometric data from identity verification is never retained by Athivo.
You control your data
You can download all your data, correct your profile, or delete your account entirely — from within the app, at any time.
No advertising
We do not sell, share, or licence your data to advertisers or data brokers. Athivo is funded by subscriptions, not by monetising your attention.
Security measures
Encrypted in transit
All data between the app and our servers uses TLS 1.3. Connections that do not meet this standard are rejected.
Encrypted at rest
Your data is encrypted at rest in our database and file storage, using AES-256.
Row-level security
Every database table has row-level security (RLS) enforced at the database layer. You can only read and write your own data.
Admin MFA required
All administrative access to our infrastructure requires multi-factor authentication. Production credentials are rotated regularly.
Vulnerability monitoring
Our dependencies are scanned continuously for known vulnerabilities. Critical issues are patched within 72 hours of disclosure.
Minimal data access
We apply the principle of least privilege. No team member has access to production data they do not need for their role.
Compliance status
UK GDPR
We operate in full compliance with the UK General Data Protection Regulation and the Data Protection Act 2018. Our Privacy Policy is maintained and updated with every feature change.
App Store & Play Store
Athivo meets Apple’s App Store and Google’s Play Store privacy requirements, including compliant account deletion, data export, and in-app privacy disclosures.
SOC 2 Type II
We are building toward SOC 2 Type II certification, covering Security, Availability, and Confidentiality trust service criteria. Target: 2027.
ISO/IEC 27001
Our Information Security Management System (ISMS) roadmap targets ISO 27001 readiness as we scale toward enterprise features. Target: 2027.
Subprocessors
We use the following third-party services to operate Athivo. Each has a signed Data Processing Agreement (DPA) where required.
| Service | Role | Region | DPA |
|---|---|---|---|
| Supabase | Database, auth, storage | EU | ✓ |
| PostHog | Product analytics | EU | ✓ |
| Google Maps Platform | Address search & geocoding | EU/US | ✓ |
| Apple (APNs) | Push notifications & Sign In | US | ✓ |
| Google (FCM) | Push notifications | US | ✓ |
| Expo | App infrastructure & OTA updates | US | ✓ |
| Identity verification provider | ID & liveness verification | EU | ✓ |
Your rights, in the app
Export everything we hold about you as a structured JSON file. Profile → Download My Data.
Update your profile, city, photo, bio, and preferences at any time from Profile → Manage Profile.
Permanently delete your account and all personal data in under 30 seconds. Profile → Delete Account.
Responsible disclosure
If you discover a security vulnerability in Athivo, please report it to us privately before disclosing it publicly. We commit to:
- Acknowledging your report within 72 hours
- Investigating and providing a status update within 7 days
- Working with you on a coordinated disclosure timeline
- Publicly crediting researchers who responsibly disclose valid issues
Report to: privacy@athivo.co.uk with the subject line “Security Disclosure”.
Please do not perform destructive tests, access other users’ data, or disclose before we have had a reasonable opportunity to address the issue.