Draft — review by counsel before launch.
This document was generated as a starting point. Have a qualified attorney review and adapt it to your jurisdiction before relying on it as a binding agreement.
Infinity Hoop Community
Privacy Policy
Last updated: May 7, 2026
Your privacy matters — especially because we collect data that's deeply personal: your weight, your photos, your goals. This Privacy Policy explains what we collect, why, who we share it with, and the rights you have over your information.
We are Infinity Hoop Community LLC ("Infinity Hoop"). This policy applies to the Platform — our website, mobile app, and services.
1. What we collect
Account information you give us
- Identity: Name, email, profile photo.
- Authentication: Managed by our auth provider Clerk — we never see your password.
- Onboarding answers: Goal, fitness level, age, workout preferences, ideal buddy description, check-in style.
- Subscription info: Status, plan, billing dates (we never see your full payment card — handled by Skio/Shopify).
Sensitive health and fitness data you share with us
These are private to you by default — only you see them on your private Progress page.
- Weight, waist, hip, chest, thigh, and arm measurements you log.
- Progress photos you upload (stored on Vercel Blob, served only to you).
- Mood and energy levels you rate (1–5 scale).
- Personal notes attached to your check-ins.
Activity we record as you use the Platform
- Workouts you watch and complete.
- Recipes you save.
- Posts, comments, likes, and direct messages.
- Streaks, freeze tokens, tier progression.
- Challenge participation and completion dates.
- Push-notification subscriptions per device.
- Real-time presence (which workout you're playing, while you're playing it — cleared 2 minutes after you stop).
Automatic / technical data
- IP address, browser, device type, timezone.
- Cookies (see our Cookie Policy).
- Server logs of API requests (retained 30 days for security and debugging).
2. How we use it
| Purpose | Data used |
|---|---|
| Run the Platform, authenticate you, show your dashboard | Identity, account, activity |
| Process payments and manage your subscription | Email, subscription info (passed to Skio/Shopify) |
| Recommend workouts, send push notifications you've opted into | Activity, onboarding answers, push subscriptions |
| Compute your private progress charts and insights | Weight, measurements, mood, energy, activity |
| Anonymous, aggregated analytics (e.g. "5,231 members hooped this week") | Activity (de-identified) |
| Support requests, fraud prevention, security investigations | Email, logs, technical data |
| Legal compliance and dispute resolution | Whatever's relevant to the request |
3. What we share — and what we don't
We never sell your personal data. We share it only in the limited cases below:
- Service providers — companies that help us run the Platform: Clerk (authentication), Supabase (database hosting), Vercel (web hosting + Blob storage), Cloudflare (video streaming), Mux (legacy video), Resend (transactional email), Skio + Shopify (subscription billing), ElevenLabs / OpenAI (if AI features are added). Each only receives the minimum data they need to do their job for us.
- Other members — your name, profile photo, tier badge, and the public content you post (posts, comments, likes, leaderboard placement) are visible to other members. Your private data (weight, measurements, photos, mood, energy, notes) is never shown to other members.
- Legal authorities — if required by law, subpoena, or to protect the rights, safety, or property of Infinity Hoop or its members.
- In a business transaction — if Infinity Hoop is sold, merged, or acquired, your data may transfer to the new owner. We'll notify you in advance.
4. How long we keep it
- Account data: for as long as your account is active, plus 30 days after you delete it.
- Private health data (weight, measurements, photos): deleted within 30 days of account deletion.
- Public content (posts, comments): may remain visible after you delete your account unless you also request removal.
- Server logs: 30 days.
- Subscription / billing records: 7 years (US tax law).
5. Your rights
Depending on where you live (especially in the EU, UK, California), you have rights to:
- Access — get a copy of your data.
- Correct — fix anything that's wrong.
- Delete — remove your account and private data.
- Restrict / object — limit how we use it.
- Portability — get your data in a portable format.
- Withdraw consent — for anything you previously opted into (push notifications, marketing email).
To exercise any of these, email hello@infinityhoop.com with the subject "Privacy Request". We'll respond within 30 days.
California residents: you have additional rights under the CCPA/CPRA. We don't sell or share personal information for cross-context behavioral advertising.
6. Children
The Platform isn't directed at children under 13, and we don't knowingly collect data from anyone under 13. If you believe a child under 13 has created an account, contact us and we'll remove it.
7. Security
We use industry-standard safeguards — encryption in transit (HTTPS), encryption at rest (Supabase managed Postgres), tightly-scoped service roles, audit logs, and least-privilege access. We can't promise perfect security; no online service can. If we ever experience a breach affecting your data, we'll notify you within 72 hours of discovery.
8. International transfers
Infinity Hoop is based in the United States. Your data is stored and processed on US-based servers (Supabase, Vercel). If you access the Platform from outside the US, your data is transferred to the US.
9. Changes to this policy
If we materially change this policy, we'll notify you by email or in-app at least 30 days before the change takes effect.
10. Contact
Privacy questions or requests: hello@infinityhoop.com