Privacy Policy
How ileadit collects, uses, and protects your data.
Placeholder page — not reviewed, not legal advice, not for production
This privacy policyis layout and structure only. Every paragraph marked “PLACEHOLDER” below must be replaced with copy drafted and reviewed by a qualified legal professional before this page is linked from anywhere real. Do not ship this as-is.
1. Who we are and what this policy covers
What this section needs to cover
- Data controller identity and contact details (the legal entity operating ileadit)
- Which products this policy covers: the mobile app (Android, and iOS once it exists) and this website, including the corporate wellness portal
- That this policy applies to individual players and to employees invited into a company's private competition
Placeholder text — replace before publishing
Placeholder — company name, registered address, and contact details go here, along with a plain-English summary of what the policy covers.
2. Account and profile data we collect
What this section needs to cover
- Display name, avatar, profile photo, and city (shown to other players)
- First name, surname, email address, date of birth, gender, and country (kept private, not shown to other players)
- Why date of birth, gender, and country are collected: used for the 'Best At' weekly leaderboard feature (e.g. "Best 42-year-old in London"), and must be described as optional at signup where the product allows it
- That email is used for account identification and essential service communication only
Placeholder text — replace before publishing
Placeholder — description of account/profile fields collected at signup and during use of the app.
3. Step and activity data (Health Connect)
What this section needs to cover
- That step data is read from Android Health Connect (and HealthKit once an iOS app exists), and exactly which permission scope is requested
- That raw step counts are converted into a private points score against the player's own rolling average, and the underlying step count is never shown to other players, competition admins, or ileadit staff on any dashboard
- How long raw daily step records are retained, and whether/when they are deleted or aggregated after a competition ends
- That step data is never sold, and is never shared with sponsors or employers in raw or per-user form — only aggregated, anonymized competition-level statistics may be shared, and only with consent (RULES.md §7.1–7.2)
- Whether step data is processed on-device, in Firestore, or both, and what security controls apply to it in transit and at rest
Placeholder text — replace before publishing
Placeholder — the Health Connect data section. This is the most sensitive category of data ileadit handles and needs its own clearly-flagged subsection, not a buried bullet point.
4. Corporate wellness competitions
What this section needs to cover
- That an employer/company admin who creates a private competition can see only aggregate participation, points, and leaderboard position — never an individual's step count (RULES.md §7.1: "HR sees points and leaderboard position only—NEVER step counts")
- What data, if any, is visible to the company admin about who has and hasn't joined
- Data retention after an employee leaves the company or the competition ends
- Whether competition invites are sent via email, and what happens to that email address once the invite is accepted or expires (CLAUDE.md: invite emails must never be stored after sending)
Placeholder text — replace before publishing
Placeholder — corporate/B2B-specific privacy terms, written for an audience of both individual employees and the company that invited them.
5. Payments
What this section needs to cover
- That payment card details are handled entirely by Stripe and never touch ileadit's own servers
- What billing data is shared with Stripe versus retained by ileadit (name, email, invoice history)
Placeholder text — replace before publishing
Placeholder — Stripe as payment processor, what's shared, and a link to Stripe's own privacy policy.
6. Who we share data with
What this section needs to cover
- Sub-processors: Firebase/Google Cloud (hosting, authentication, database), Stripe (payments), and any analytics or crash-reporting tool actually in use
- That individual step counts and PII are never sold or shared for marketing purposes (RULES.md §7.2)
- Conditions under which data might be disclosed (legal requirement, safety)
Placeholder text — replace before publishing
Placeholder — sub-processor list and third-party sharing terms.
7. Cookies and analytics
What this section needs to cover
- That no analytics or tracking runs before consent is given, per the site's cookie banner
- Categories of cookies used (essential/session vs optional analytics) and how to withdraw consent later
Placeholder text — replace before publishing
Placeholder — cookie categories and consent mechanism, matching whatever the site's actual cookie banner implementation ends up being.
8. International data transfers
What this section needs to cover
- Where Firebase/Google Cloud data is physically stored and processed
- Transfer safeguards if data leaves the UK/EEA (e.g. Standard Contractual Clauses)
Placeholder text — replace before publishing
Placeholder — data residency and international transfer safeguards, once the actual Firebase region configuration is confirmed.
9. Your rights
What this section needs to cover
- Right to access, correct, export, and delete your data
- A direct link to the account deletion flow (see /account-deletion)
- Right to object to or restrict certain processing, and how to withdraw consent for optional data (date of birth, gender, country)
- Right to complain to a supervisory authority (e.g. the ICO in the UK) if unsatisfied with the response
Placeholder text — replace before publishing
Placeholder — GDPR/UK GDPR rights section with the actual process and response time commitments for each right.
10. Children
What this section needs to cover
- Minimum age to use ileadit, and what happens if an under-age account is discovered
Placeholder text — replace before publishing
Placeholder — minimum age policy.
11. Changes to this policy
What this section needs to cover
- How and where policy changes are announced, and whether material changes require re-consent
Placeholder text — replace before publishing
Placeholder — change notification process.
12. Contact us
What this section needs to cover
- A real contact email or address for privacy/data protection queries
Placeholder text — replace before publishing
Placeholder — contact details for privacy questions and data subject requests.