ProofLeague
OverviewHow it worksPrivacyFAQ
Log inStart
Back to ProofLeague

Privacy

Effective August 16, 2026

What ProofLeague collects

ProofLeague stores the account details needed to run the service, including your Apple or Google sign-in identifier when you choose one of those options, a private-device guest identifier, profile name, email address supplied during signup or by your chosen sign-in provider, profile and league photos you choose, league membership and rules, started workouts, workout-selfie request, reaction, comment, and validity-vote activity, private league-chat messages and photos, replies, mentions, message reactions and read state, time zone, notification preferences, and a device token or browser push subscription.

When a member sends a direct league invite, ProofLeague collects the recipient email address and delivery details needed to send and protect that invitation.

A fresh workout selfie is collected only after a league member requests one and you choose to share it. For one workout started in multiple leagues, the sharing screen lets you choose whether that same fresh capture may satisfy later requests from the other selected leagues before the shared deadline. This choice is enabled initially for that workout and can be turned off before sharing. A league receives the selfie only if one of its members requests it. ProofLeague asks for the live camera (front or rear) and does not accept a photo-library upload for this step. ProofLeague does not use face recognition, create biometric templates, or automatically identify or verify the person in a selfie.

How information is used

Information is used to operate leagues, deliver notifications you enable, send league invites you request, enforce league schedules, daily limits, shared deadlines and member validity votes, record submitted workout selfies as social check-ins, show current-season request and reaction standings, host comments attached to approved selfies, operate private league chat, show unread state, deliver the chat, mention and reply notifications you select, prevent abuse, and maintain the reliability of ProofLeague.

ProofLeague also collects product-interaction, app lifecycle, performance, device, and session-replay data to understand how the web, iOS, and Android apps are used and to diagnose bugs. Replays may include the screens and controls used during a session; password and secure text inputs are masked by the analytics software.

Who can see workout selfies

Started workouts and submitted workout selfies are available only to current members of the relevant league. Reusing one capture for a multi-league workout creates a separate submission only for each league that requested it; leagues that did not request it cannot see it. ProofLeague does not offer a public selfie feed and does not sell workout selfies or use them for advertising. Eligible members may cast a one-time valid or not-valid vote for 24 hours. Members can also leave positive reactions and comments on an approved selfie. Those comments are visible only to current members of that league and are not direct messages or a public feed. The league sees aggregate vote progress; each member sees their own recorded choice.

Who can see league chat

League-chat messages, attached photos, replies, reactions, mentions, and read indicators are available only to current members of that private league. They are not public posts or direct messages outside the league. A chat photo may be taken with the camera or selected from the photo library when you choose to attach one. Members can delete their own messages, report another member’s message, and block unwanted interactions.

Safety reports and blocks

A report records the content or member reported, the reason you select, and any details you provide. A reported workout selfie, comment, or chat message is hidden from you immediately. Blocking a member hides interactions between both accounts. Safety reports are private and available only to the ProofLeague team for review and enforcement.

Support requests include the reply email and message you submit. They are used only to investigate and respond to that request. A one-way network-source token limits abuse; ProofLeague does not store the raw network address with the request.

Storage and service providers

ProofLeague uses infrastructure providers, including Supabase, Vercel, Resend, and PostHog, to store data, run the application, analyze product usage, deliver the web experience, and send transactional email. Apple and Google process authentication when you choose their sign-in options. Supabase stores a one-way password hash when you choose email and password; ProofLeague does not store your raw password. Apple Push Notification service, Expo Push Service, Firebase Cloud Messaging, and browser Web Push services operated by Apple, Google, Mozilla, or Microsoft deliver notifications that you enable. Access controls and private storage policies restrict workout selfies and chat images to authorized league members.

Your choices

  • Leave a league at any time.
  • Delete your own selfie comments and league-chat messages.
  • Report a workout selfie, comment, chat message, or member and block unwanted interactions.
  • Choose whether chat alerts cover all messages, mentions and replies, or are muted.
  • Control notification permissions in your device settings.
  • Turn optional activity and weekly emails on or off in ProofLeague.
  • Link a private-device account to email/password or Google so it can be recovered on another device.
  • Delete your account and associated uploaded workout selfies in the app.
  • Request account and associated-data deletion through the support form if you cannot access the in-app control.

Retention and deletion

Account and league information is kept while the account is active and while it is needed to provide the service, preserve league integrity, handle safety reports, or meet legal obligations. Workout selfies are queued for deletion 30 days after submission unless an open safety report requires review. After delivery is complete or retries end, invite recipient addresses and rendered transactional-email content are kept for up to 30 days for troubleshooting and abuse prevention. Limited non-content audit identifiers and delivery timestamps may be kept longer to monitor reliability and prevent duplicate sending. Selfie comments remain with their private thread until their author deletes them, the related workout is deleted, or the account is deleted. League-chat messages remain with their private league until their author deletes them or the related league or account is deleted. Deleting a chat message removes its text and queues its attached photo for permanent deletion. A limited report snapshot may be retained for safety review. Profile and league photos remain until they are replaced or the related account or league is deleted. In-app account deletion removes the account, its comments and chat activity, and queues uploaded photos for permanent deletion. Limited safety records may be retained when needed to prevent repeated abuse or comply with law.

Children

ProofLeague is not directed to children under 13, and they may not create an account, submit a workout selfie, post a comment, or send a chat message.

Questions

Use the private support form for privacy questions, safety concerns, or data requests. Material updates to this policy will be reflected on this page with a new effective date.