Focal

Legal

Privacy Policy

Effective from 28 July 2026

This policy explains what data Focal collects, why it is used, how long it is kept, and the choices and rights you have.

This Privacy Policy explains how Aqil Rouf, based in England, United Kingdom, collects and uses personal data for Focal. This covers both the Focal mobile app and the Focal marketing website at joinfocal.app. Aqil Rouf is the data controller under UK data protection law.

In short

  • We only collect the information needed to provide Focal.
  • Your health data is only processed to deliver the features you choose to use.
  • We do not sell your personal information.
  • You can delete your account and associated data at any time from within the app.

1. Who we are

Focal is operated by Aqil Rouf, England, United Kingdom. The app name is Focal and the marketing website is joinfocal.app.

For privacy questions or rights requests, contact hello@joinfocal.app.

2. Data we collect

We collect only the data needed to provide the features you choose to use. This may include:

  • Account and identity data: sign-in details, authentication identifiers and account settings needed to create and secure your account.
  • Profile data: username, profile photo, bio, goals, preferences and other profile information you choose to provide.
  • Health and fitness data: workout history, body measurements, activity tracking, nutrition logs, goals and other health information you choose to provide.
  • Photos and media: profile photos, progress photos, meal photos and other images you upload.
  • Social and community data: follows, comments, shared content, leaderboard activity, Challenge participation and other interactions with other users.
  • Challenge and prize data: Challenge joins, progress, qualification or ranking results, winner status, prize claim actions and fulfilment status.
  • Location data: city, gym discovery and outdoor activity routes when you use location features.
  • Purchase and entitlement data: subscription status, referral codes and feature access.
  • Marketing preferences: whether you have chosen to receive marketing emails, and when you made or changed that choice.
  • Device and technical data: device type, app version, crash logs and push notification tokens.
  • Website data: analytics (with consent) and contact form messages sent through joinfocal.app.

3. How we collect data

  • Directly from you when you create an account, use app features, join Challenges, claim prizes, upload content, or change settings.
  • From device permissions that you choose to grant, such as Apple Health or Health Connect, camera, photo library, microphone, speech recognition, location, activity or motion access, background location and push notifications.
  • From trusted service providers that help us operate the app, such as authentication, cloud hosting, subscriptions, analytics, mapping, prize fulfilment and AI-powered features.
  • From the marketing website, including analytics events where you accept analytics cookies, and any details you submit through the contact form.

4. Why we use data

  • To provide, personalise and improve the app and features you choose to use.
  • To run Challenges, measure progress, select winners, prevent abuse and fulfil prizes you claim.
  • To process subscriptions, referrals, entitlements and billing-related questions.
  • To keep the app secure, debug issues, prevent abuse and provide support.
  • To send marketing emails about new features, product updates and training tips where you have opted in.
  • To understand how visitors use the marketing website and reply to enquiries, where analytics is used only with your consent.
  • To comply with legal obligations, enforce our terms and protect users or others.

5. Legal bases under UK GDPR

We rely on different legal bases depending on the purpose. Under Article 6 UK GDPR, these may include contract, consent, legitimate interests and legal obligation.

  • Contract: to provide the app, account, subscriptions and requested features.
  • Consent: for optional permissions such as Apple Health or Health Connect, push notifications, camera, photo library, microphone, speech recognition, activity or motion access, location and background location where consent is required, for website analytics cookies, and for marketing emails where you opt in.
  • Legitimate interests: to keep the app secure, prevent abuse, debug errors, improve features, understand reliability and respond to support requests, where those interests are not overridden by your rights.
  • Legal obligation: to keep records or respond where law requires it.

Some data is special category data under Article 9 UK GDPR, especially health, fitness, body, cycle, sleep, heart rate, heart rate variability, weight and nutrition data. Where we process special category data, we rely on Article 9 explicit consent where you choose to provide or connect that data, and where relevant on processing needed for legal claims or other conditions allowed by law.

6. Apple HealthKit and Health Connect data

If you connect Apple Health on iPhone, the app may read steps, active energy, activity summaries, workouts, resting heart rate, heart rate variability, sleep and water, including for workout import and background Health updates where you allow them. The app may write traditional strength training workouts, check-in body weight and water to Apple Health when you use those features. If you connect Health Connect on Android, the app may read and write the same kinds of movement, recovery, sleep, workout, water and body weight data where you grant permission.

HealthKit data and Health Connect data are used only to provide health and fitness features that you choose to use. HealthKit data is not sold. HealthKit data is not used for advertising or marketing. HealthKit data is not used for use-based data mining. The same limits apply to Health Connect data.

You can grant, deny, or revoke Apple Health permissions in iOS and the Apple Health app, or Health Connect permissions in the Health Connect app and Android settings. If you revoke permissions, some features may stop updating. The app does not store personal health information in iCloud or a separate cloud health vault outside Apple Health and Health Connect.

7. Photos, camera, barcode, microphone and speech

Camera and photo access are used for scanning, logging and sharing features when you choose those actions. Camera feed is not continuously recorded by the app.

Microphone and speech recognition are used for voice input when you choose it. You can use text entry instead where available.

8. Location

You may provide a city for your profile and gym discovery. If you grant location permission, the app may use location while you are using gym discovery. If you start outdoor activity tracking and allow background location, the app may record GPS route points while an outdoor activity is active, including when the app is locked or in the background. GPS is not tracked when you are not using a location feature or tracking an outdoor activity.

9. Background audio and podcasts

If you play an In Focus podcast episode in the app, audio may continue when the app is locked or in the background so playback is not interrupted. You can pause or stop playback from system media controls or inside the app. Background audio is used only for media you choose to play.

10. Push notifications

If you allow push notifications, we store a device push token so alerts can be delivered for app events you have enabled. You can turn off notifications in the app settings or your device settings.

11. Marketing emails

If you choose to receive them, we may send occasional emails about new features, product updates and training tips. We only send marketing emails where you have given consent, and consent is never a condition of using the app.

You can withdraw consent at any time in the app settings or using the unsubscribe link in any marketing email. Withdrawing consent does not affect service emails we need to send, such as sign-in codes, billing and security notices.

We do not use Apple Health or Health Connect data, or any health, cycle or nutrition data, to decide who receives marketing emails.

12. Website analytics and cookies

On the marketing website at joinfocal.app we use PostHog to understand how visitors use the site so we can improve it. This includes pageviews, clicks, referring pages, approximate location derived from your IP address, device and browser details, and a randomly generated analytics identifier. We do not use this to identify you personally, and it is separate from your app account.

Website analytics runs only if you accept analytics cookies in our cookie banner. Until you accept, analytics is switched off and no analytics cookies are set. You can change or withdraw your choice at any time using the cookie controls, and we respect browser "Do Not Track" signals. Essential cookies needed for the site to function are always active.

PostHog acts as our processor and stores this website analytics data in the European Union. If you contact us through the website contact form, we use an email delivery provider to send and reply to your message, and we process the name, email address, subject and message you provide.

13. Social, public and shared content

Some content is visible to others depending on your settings and actions. This may include your profile, shared workouts or activities, comments, reactions, Challenge participation or rankings where shown in the app, and other community interactions.

Progress photos are private by default unless you choose to share them through a feature. Workout and outdoor activity sharing to Instagram, Instagram Stories, Facebook, or the system share sheet happens only when you choose to share.

14. Third-party services and processors

We share personal data only where necessary with trusted service providers that help us operate Focal, such as providers of cloud infrastructure, authentication, analytics, subscriptions, mapping, prize fulfilment, customer support and AI-powered features.

Cloud infrastructure providers

Purpose
Secure hosting, database and file storage for the app.
Data involved
Account data, user-generated content and app records needed to run the service.

Authentication providers

Purpose
Account creation and sign-in.
Data involved
Email address, sign-in identifiers, auth tokens and session data.

Subscription and payment processors

Purpose
Managing purchases, subscriptions and entitlements.
Data involved
App user identifier, product id, store, entitlement status and renewal information.

Prize fulfilment providers

Purpose
Delivering Challenge prizes you claim, such as cash payout links or gift card links.
Data involved
Account identifiers and prize claim or fulfilment details needed to issue the prize.

Analytics providers

Purpose
Understanding how the marketing website is used, only where you accept analytics cookies.
Data involved
Pageviews, clicks, referrer, approximate location derived from IP, device and browser metadata, and a randomly generated analytics identifier. No account or health data.

Mapping and location providers

Purpose
Gym discovery, geocoding and route maps.
Data involved
Location coordinates, search text and map request metadata when you use location features.

AI service providers

Purpose
Processing requests you choose to submit through AI-powered features.
Data involved
Prompts, images, text and other inputs needed for the feature you use.

Crash monitoring and diagnostics providers

Purpose
Keeping the app stable and secure.
Data involved
Device information, error logs, app version and anonymised session diagnostics.

Email and customer support providers

Purpose
Delivering contact form messages, support replies, and marketing emails to users who have opted in.
Data involved
Your name, email address, subject, message content and delivery metadata.

Content and media providers

Purpose
Exercise, food, nutrition, recipe and video content used in the app.
Data involved
Search queries, content identifiers and metadata needed to support app content.

Apple HealthKit

Purpose
Optional health read and write features on Apple devices.
Data involved
Health and fitness data you choose to share through Apple Health.

Health Connect

Purpose
Optional health read and write features on Android devices.
Data involved
Health and fitness data you choose to share through Health Connect.

Apple App Store

Purpose
iOS subscription purchase, cancellation and refund handling.
Data involved
Purchase and billing information handled by Apple.

Google Play Billing

Purpose
Android subscription purchase, cancellation and refund handling.
Data involved
Purchase and billing information handled by Google.

We require third parties to protect personal data appropriately for the service they provide. Some providers may process data outside the United Kingdom. Where personal data is transferred outside the UK, we rely on adequacy regulations, the UK International Data Transfer Agreement, Standard Contractual Clauses, or another lawful transfer mechanism where required.

15. Retention

  • Personal data is generally kept until you delete it or delete your account.
  • Crash, security and diagnostic records are kept only as long as needed for debugging, security and service improvement.
  • Purchase and entitlement records may be kept as needed for subscription access, fraud prevention, accounting, legal compliance and support.
  • Challenge participation and prize fulfilment records may be kept as needed to run Challenges, issue prizes, prevent abuse, handle disputes, accounting, legal compliance and support.
  • Some public or shared records may be retained for moderation, safety or legal reasons where the law allows, but we aim to remove or anonymise account-linked data when deletion is completed.

16. Account deletion and data deletion

You can delete your account and data inside the app from Profile settings. Deletion starts straight away when you confirm it, removes associated personal data unless we are legally required or allowed to keep limited information, requests removal of the linked third-party sign-in account where supported, and signs you out. Deleting your account does not cancel subscriptions managed by Apple or Google. You should cancel any active subscription in Apple Account or Google Play subscription settings.

17. Your UK GDPR rights

Depending on the circumstances, you may have the right to access your personal data, correct it, delete it, restrict processing, object to processing, receive data portability, withdraw consent, and complain to a supervisory authority.

To exercise rights, contact hello@joinfocal.app. We may need to verify your identity before responding. Some rights are not absolute and may depend on the legal basis and context.

18. Children

The app is not intended for children under 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided personal data, contact us so we can take appropriate action.

19. Security

We use reasonable technical and organisational measures to protect personal data. No app, network, or storage system is perfectly secure. You should keep your sign-in method secure and tell us if you suspect unauthorised access.

20. Changes to this policy

We may update this Privacy Policy from time to time. If changes are material, we will take reasonable steps to tell you in the app or by another appropriate method. The latest version will show the effective date.

21. Complaints

We hope you contact us first so we can try to resolve any concern. You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority for data protection.

Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Helpline: 0303 123 1113. You can also lodge a complaint through the Information Commissioner's Office complaint page.

22. Contact

Privacy questions and rights requests can be sent to hello@joinfocal.app.