Legal

Privacy Policy

Last updated: July 25, 2026

This Privacy Policy explains how Dylan Yip-Chuck ("Risers", "we", "us") collects, uses, shares, and protects your information when you visit risers.fit or use the Risers mobile app (together, the "Service").

We built Risers around a simple promise: what you share is seen only by the small circle of people you invite. This policy describes the data behind that promise and the choices you have over it.

If you have questions, contact us at hello@risers.fit.

Who is responsible for your data

The data controller for the Service is:

Dylan Yip-Chuck
Tzschimmerstraße 15
01309 Dresden
Germany
hello@risers.fit

Information we collect

Information you give us

  • Account information. When you create an account, we collect your email address, a display name, and (optionally) a short bio and profile photo. If you sign in with Google, we receive your name, email, and profile image from Google. You can also use the app as an anonymous guest, in which case we create an account identifier without an email until you choose to register.
  • Your plans and check-ins. The daily commitments you create, whether you completed them, and any short notes you add.
  • Proof content. The photos and videos you capture or upload as proof, along with any captions.
  • Social content. Comments and reactions you post, and the connections that make up your inner circle (who you've invited or accepted).
  • Waitlist and referrals. If you join our launch waitlist, we collect your email address and, if you arrived through a referral link, the referral code that credited your invite.
  • Messages you send us. If you write to us through the contact form on our website, we collect your email address, the topic you chose, your message, and your name if you give one, so that a person can read it and reply.

Information we collect automatically

  • Device and technical data. To operate the app we process basic technical information such as your device's push-notification token (so we can send you notifications), your time zone (so plans display at the right local time), and standard connection information.
  • Website usage. Our website uses minimal, aggregate analytics to understand general traffic. We do not use advertising cookies or cross-site tracking.
  • Contact form abuse prevention. When you submit the contact form, we store a one-way hash of your IP address, never the address itself. It is used only to limit how many messages a single sender can submit in an hour.

What we deliberately do not collect

Risers does not use advertising identifiers (such as IDFA or GAID), does not use third-party analytics or tracking SDKs, does not access your phone contacts, and does not collect your location. We do not track you across other apps or websites.

Sensitive information

Risers is a wellness and accountability app, so the notes and proof you choose to share may touch on health, fitness, or personal goals. We do not ask you to provide this information and we do not treat it as structured health data — it is simply the content you decide to share with your circle. Please share only what you're comfortable with. Where this content constitutes special-category data under the GDPR, we process it on the basis of your explicit choice to share it through the Service.

How we use your information

We use your information to:

  • create and maintain your account and inner circle;
  • deliver the core experience — showing your plans, proof, and reactions to the people you've invited;
  • send push notifications and, where relevant, service emails;
  • notify you about launch and product updates if you joined the waitlist (you can opt out at any time);
  • operate our referral rewards program;
  • keep the Service secure, prevent abuse, and enforce our Terms; and
  • comply with our legal obligations.

Legal bases (GDPR). We rely on: performance of our contract with you (to provide the Service); your consent (for waitlist and marketing emails, which you can withdraw at any time); our legitimate interests (to keep the Service secure and to improve it); and compliance with legal obligations.

Who can see your content

This is the heart of Risers, so we want to be exact:

  • Your inner circle sees your display name, photo, and bio, and the plans, proof, check-ins, comments, and reactions you share. Your circle is invite-only and consent-based — no one joins without a mutual connection.
  • Other Risers members who are not in your circle can see only your display name, photo, and bio, and only if they already have your invite code or a direct connection to you. They cannot browse or search for you, and they cannot see your email, your activity, your check-ins, or who else is in your circle.
  • No one else. Your email address, device tokens, and your list of connections are visible only to you and to our systems.

We do not sell your personal information, and we do not share it for advertising.

Service providers we share data with

We share data only with the providers we need to run the Service, each bound by contractual confidentiality and data-protection obligations:

  • Google Firebase / Google Cloud — our core infrastructure for authentication, database, file storage, cloud functions, and push notifications.
  • Google Sign-In — if you choose to sign in with Google.
  • Our email delivery provider — to send waitlist and service emails.

We may also disclose information if required by law, to protect the rights and safety of our users or others, or in connection with a business transfer.

When Risers introduces paid subscriptions, our payments/subscription provider (Adapty) and the Apple App Store or Google Play will process your subscription and purchase data. This section will be updated before any paid plan goes live.

Where your data is stored and international transfers

Your data is hosted on Google Cloud infrastructure, primarily in the United States. If you are located in the European Economic Area, the United Kingdom, Switzerland, or Canada, this means your data is transferred internationally. These transfers are covered by appropriate safeguards, including the Standard Contractual Clauses and Google's certification under the EU–U.S. Data Privacy Framework.

How long we keep your data

  • Account data is kept for as long as your account is active. When you delete your account (see below), your data enters a 14-day recovery window, after which it is permanently deleted from our systems, and your proof photos and videos are removed from storage.
  • Waitlist emails are kept until we launch and you've been notified, or until you unsubscribe, whichever comes first.
  • Contact form messages are kept for as long as we need them to answer you and handle any follow-up. You can ask us to delete yours at any time.
  • We may retain limited information longer where necessary to comply with legal obligations, resolve disputes, or enforce our agreements.

Deleting your account

You can delete your account at any time from Settings → Delete account inside the app. Deletion is a two-step confirmation. For 14 days your account is deactivated and recoverable — sign back in and cancel to restore it. After 14 days, deletion is permanent: your profile, plans, proof, reactions, and connections are erased, comments you authored are anonymized, and your login is removed.

Deleting your account does not automatically cancel any app-store subscription — manage that in your Apple or Google account settings.

Your rights and choices

Depending on where you live, you have some or all of the following rights:

  • Access — request a copy of the personal data we hold about you.
  • Correction — ask us to fix inaccurate data (you can edit most profile data directly in the app).
  • Deletion — delete your account and data, as described above.
  • Restriction and objection — ask us to limit or stop certain processing.
  • Portability — receive your data in a portable format.
  • Withdraw consent — opt out of marketing emails at any time, and withdraw other consents without affecting prior processing.

EEA/UK users may lodge a complaint with their local data protection authority. California users have rights under the CCPA/CPRA to know, delete, and correct their personal information and to not be discriminated against for exercising these rights; note that we do not "sell" or "share" personal information as those terms are defined. Canadian users have rights of access and correction under PIPEDA.

To exercise any right, email us at hello@risers.fit. We will respond within the time required by applicable law.

Children

Risers is not intended for children under 16, and we do not knowingly collect data from anyone under 16. If you believe a child under 16 has provided us data, contact hello@risers.fit and we will delete it.

Security

We protect your data with encryption in transit, access controls, and a data model designed so that your private information is technically restricted to you and your invited circle — not merely hidden in the interface. No system is perfectly secure, but we work to protect your information and to respond promptly to any issue.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected in a new "Last updated" date and, where appropriate, communicated in the app or by email.

Contact

Questions or requests? Email us at hello@risers.fit.