Faction Fitness < Home
Legal log

Your data. Your choices.

Privacy Policy

Last updated: 6 August 2026

This policy explains how Faction.Fitness collects, uses, shares, and protects personal data when you use our website, mobile applications, and connected services.

1. Who we are and scope

Faction.Fitness (“Faction”, “we”, “us”, or “our”) is operated by Kraken Castle, the UK-based controller responsible for the personal data described in this policy. You can contact us at [email protected].

This policy covers people using Faction worldwide. Faction is intended only for people aged 18 or over. We do not knowingly allow anyone under 18 to create an account.

2. Information we collect

Account and profile

Player name, email address, password hash, avatar, account identifiers, verification status, two-factor authentication details, and privacy settings.

Fitness and health

Steps, distance, activity type and duration, gym sessions you record, timestamps, connected provider, and synchronisation details.

Social and game activity

Friends, factions, challenges, streaks, rankings, leaderboard positions, progress, sharing choices, blocks, mutes, reports, and email addresses or phone numbers you provide when asking us to send an invitation.

Messages and interactions

Message content, reactions, emotes, sender and recipient identifiers, timestamps, delivery and read status, deletion status, and conversation and moderation records.

Technical and support

IP address, browser and device details, sessions, login and OAuth records, security logs, service messages, and correspondence with us.

What we do not collect

We do not collect precise location or GPS routes, address-book contacts, heart rate, sleep, diagnoses, medication or other clinical records, card details, prize-fulfilment details, or advertising profiles. Stripe collects card and payment details directly; Faction keeps only limited payment references, amount, currency, status, and subscription dates needed to provide and account for support.

We receive data directly from you, automatically from your use of the service, and—only when you connect one—from services we support, such as Apple Health, Health Connect by Android, Garmin Connect, or Samsung Health.

3. How and why we use data

We use personal data to:

  • Create and secure accounts, authenticate players, and provide support.
  • Import authorised fitness data and turn activity into progress, challenges, streaks, and rankings.
  • Provide friends, factions, leaderboards, and user-controlled sharing.
  • Deliver messages, reactions, and emotes between accepted friends and provide blocking, muting, reporting, and moderation tools.
  • Send an email or SMS invitation when an adventurer asks us to invite someone they know. We use the supplied contact detail for the invitation and related service messages.
  • Send verification, security, account, challenge, and operational messages. We do not send promotional marketing at launch.
  • Protect Faction, prevent misuse, troubleshoot faults, and comply with the law.

We rely on performance of our agreement with you for core account and game features; your consent and explicit consent for connected health data; our legitimate interests in operating and protecting the service; and legal obligations where the law requires processing.

Faction is a wellness and entertainment service. We do not use fitness information for medical diagnosis, insurance, employment, credit, or other decisions that have legal or similarly significant effects.

4. Connected fitness data and consent

Fitness information may reveal information about your health and can be special category data. Before importing it, we ask you to expressly choose a provider and grant the relevant permissions. This permission is separate from registering an account.

We never receive your Apple, Google, Garmin, or Samsung password. You can disconnect a provider at any time, which stops future imports. Disconnecting does not automatically erase information already imported; you can separately delete that activity history or delete your account.

You may withdraw consent at any time. Withdrawal does not affect processing that was lawful before you withdrew it.

Apple Health and HealthKit data

On supported Apple devices, you may choose to give Faction read-only access through HealthKit. Faction requests permission to read step count, walking and running distance, cycling distance, active energy burned, and workout records. From those records, Faction processes daily step and walking-distance totals and completed running or cycling activities, including the activity identifier and type, start time, duration, distance, active calories, and synchronisation time. Faction does not request permission to write to HealthKit and does not collect heart rate, sleep, diagnoses, medication, clinical records, precise location, or workout routes from HealthKit.

Access is optional and requires your permission for each HealthKit data type. When you choose to synchronise, Faction reads up to the previous 30 days of authorised data from HealthKit on your device and securely transfers the resulting summaries and activities to Faction’s hosted application and database infrastructure. We use this data only to select Apple Health as a source for supported metrics, avoid duplicate counting, calculate activity balances, and provide Quest Boards, progress, challenges, rankings, and social fitness features.

We do not use HealthKit data for advertising, marketing profiles, data-broker services, medical diagnosis, insurance, employment, credit decisions, or training artificial-intelligence or machine-learning models. We do not sell or rent HealthKit data. Infrastructure providers acting on our behalf may process it only where necessary to host, secure, monitor, or back up Faction under contractual safeguards. Relevant derived progress may be visible to other adventurers only through the privacy and social features you choose. We do not disclose HealthKit data to another third party without your express permission unless required by law or necessary to protect rights and safety.

You can review or revoke Faction’s HealthKit permissions at any time in Apple Health or your device’s privacy settings. You can also disconnect Apple Health in Faction. Either action stops future imports; disconnecting Faction removes the Apple Health connection and metric-source selections but does not automatically erase activity already imported, so existing progress remains consistent. You can request deletion of imported data or delete your Faction account. Stored Apple Health data otherwise follows the retention, security, and deletion measures described below.

Health Connect by Android

On supported Android devices, Faction requests read-only Health Connect permissions for steps, distance, and exercise sessions. We use these records only to import daily activity, running and cycling sessions, calculate progress, and provide the quests, challenges, rankings, and social fitness features you choose to use. Faction does not write to or modify Health Connect data.

When you choose to synchronise, the authorised records are transferred securely from your device to Faction and stored with your Faction account. We do not sell Health Connect data, use it for advertising, or use it for medical diagnosis, insurance, employment, credit decisions, or unrelated purposes. Our infrastructure providers may process it only as necessary to host, secure, monitor, and back up Faction under contractual safeguards.

You can revoke Faction’s permissions in Android Health Connect settings at any time. Disconnecting Health Connect in Faction stops future imports and removes the connection and metric-source selections, but retains activity already imported so existing progress remains consistent. You can remove that stored data by deleting your Faction account or contacting us using the details below. Account deletion removes Health Connect records from active systems, subject to the backup and legal-retention periods in section 10.

5. Google user data

This section explains specifically how Faction accesses, uses, stores, shares, retains, and deletes information received from Google APIs. Google Sign-In and Google Health are separate, optional features. Connecting Google Health is not required to create or use a Faction account.

Google Sign-In data

If you choose Google Sign-In, we request your Google account identifier, verified email address, and name. We use this information only to create or find your Faction account, verify your email address, authenticate you, and protect the sign-in process. We store the Google account identifier and email address with your Faction account and use your name when creating a new account. We do not store the temporary Google Sign-In access token.

Google Health data

If you separately connect Google Health, we request permission to read your Google Health user identifier, steps, walking distance, floors climbed, active calories, and exercise records, including activity type, title, start and end times, duration, distance, and calories. This permission does not allow Faction to write to or change your Google Health data.

Optional gym-session syncing

Syncing gym sessions from Faction to Google Health is not enabled by default. If you choose to enable it, Faction also asks for permission to add fitness activity to your Google Health account. We use that permission only to send gym sessions you record in Faction, including the session’s activity details, timing, and duration. This permission does not allow Faction to read any additional Google Health data. You can leave this feature disabled or turn it off to stop future gym-session syncing.

We use Google Health data to import your authorised activity, let you choose which connected provider supplies each fitness metric, prevent duplicate counting, show your progress, and provide Faction challenges, streaks, rankings, and social fitness features. We do not use Google user data for advertising, medical diagnosis, insurance, employment, credit decisions, or any purpose unrelated to these visible user-facing features.

Imported Google Health data is stored on Faction servers with your account. Google Health access and refresh tokens are encrypted at rest and used only to maintain the connection and perform imports you have authorised. Data is protected in transit and subject to the access controls and security measures described in this policy.

We do not sell Google user data. We share it only with service providers that process data on our behalf where necessary to host, secure, back up, support, or deliver Faction; when you choose to make relevant progress visible to other players through your privacy settings; when required by law or necessary to protect rights and safety; or as part of a genuine business reorganisation after obtaining explicit prior consent where Google’s Limited Use requirements require it. Service providers may not use Google user data for their own advertising or unrelated purposes.

Disconnecting Google Health revokes the connection where available, deletes the stored Google Health access and refresh tokens and Google Health connection identifier, and stops future imports. It does not automatically delete fitness data already imported into Faction. You can separately delete imported activity where that option is available, request deletion, or delete your Faction account. Google Sign-In information and imported Google Health data otherwise follow the retention periods in section 10 below.

Faction’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

6. Garmin data

This section specifically explains how Faction collects, uses, processes, stores, and shares data received through the Garmin Connect Developer Program. Connecting Garmin Connect™ is optional and is not required to create or use a Faction account.

If you connect Garmin Connect and grant the relevant permissions, Garmin sends Faction your Garmin API user identifier, granted permissions, daily health summaries, and completed activity summaries. The fields Faction currently processes are steps, walking distance, floors climbed, active calories, activity identifier, activity type and name, start time, duration, distance, calories, and synchronisation timestamps. Faction does not receive your Garmin password.

Faction processes this Garmin data only to maintain your authorised connection, import and reconcile activity, let you select Garmin as the source for supported metrics, avoid duplicate counting, calculate your personal activity balance, and provide the Quest Board, progress, challenge, ranking, and social fitness features visible in the service. We do not use Garmin data for advertising, medical diagnosis, insurance, employment, credit decisions, or training an artificial-intelligence or machine-learning model.

Imported Garmin data is stored with your Faction account on Faction’s hosted application and database infrastructure. Garmin access and refresh tokens are encrypted at rest. Data is encrypted in transit, access is limited to authorised operational purposes, and protected backups follow the retention and security measures described below.

Faction does not sell or rent Garmin data. Infrastructure providers acting on our behalf may process it only where necessary to host, secure, monitor, or back up Faction under contractual safeguards. Relevant derived progress may be shown to other adventurers only according to the visibility and social features you choose. We may also disclose data when legally required or necessary to protect rights and safety. We do not send Garmin data to third-party AI services, and third parties may not use it for advertising or unrelated purposes.

Disconnecting Garmin Connect calls Garmin’s registration-deletion endpoint, deletes Faction’s stored Garmin tokens and connection record, and stops future imports. It does not automatically erase Garmin data already imported into Faction; you can separately request its deletion or delete your Faction account. Imported Garmin data otherwise follows the retention periods below.

7. Profile and activity visibility

New accounts are private by default. You can choose to share profile or progress information with friends, faction members, or publicly.

If you make information public, anyone may be able to view, copy, or share it, and search engines may index it. Review your visibility settings before publishing information.

8. Messages, recipients, and moderation

When you send a message, reaction, or emote, we process its content and associated metadata to deliver it to the accepted friend you selected, show conversation history and read or delivery state, send notifications according to the recipient’s settings, prevent misuse, and keep the service secure. The recipient can view and may copy, screenshot, or share what you send.

Message content is not end-to-end encrypted. It is protected in transit and through our service access controls. Authorised personnel and service providers may access content only where reasonably necessary to operate or secure messaging, investigate a report or suspected breach, protect a person, enforce our terms, or comply with law.

A report may include the reported message and enough surrounding conversation context to understand it. We may use automated spam and rate-limit signals, but material moderation and account-enforcement decisions are reviewed by an authorised person where appropriate. We do not use private messages for advertising or to train artificial-intelligence or machine-learning models.

Blocking stops new direct contact through the blocked relationship but does not remove copies already seen, saved, or captured by another person. Notification previews may display sender or message information on a device lock screen if the recipient enables previews in their device settings.

9. Sharing and data sales

We do not and will not sell or rent your personal data.

We do not use personal data for targeted advertising or cross-service advertising profiles. We disclose data only where needed:

  • To vetted providers supporting hosting, databases, backups, email, security, support, and content delivery under contractual safeguards.
  • To Stripe when you choose to donate, subscribe, or manage billing. Stripe processes the payment and related fraud-prevention data under its own privacy terms.
  • To Apple, Google, Garmin, Samsung, or another supported provider when you direct us to connect its service.
  • To other players according to the visibility settings you choose.
  • To the intended recipient when you send a message, reaction, or emote, and to a reporting user where needed to communicate the outcome of a report without unnecessarily disclosing another person’s data.
  • To authorities or professional advisers when required to comply with law, protect rights and safety, or resolve disputes.
  • To a successor during a genuine business reorganisation, with notice and continued privacy protections. This is not a sale of personal data for advertising or data-broker purposes.

10. Cookies and similar technologies

Our website uses strictly necessary cookies and local storage for sessions, security and CSRF protection, sign-in preferences, and appearance settings. These technologies are required to provide features you request and keep the service secure.

We do not currently use non-essential analytics or advertising cookies. If that changes, we will update this policy and ask for consent before setting them where required.

11. International transfers

Some vetted providers may process data outside the United Kingdom. Where required, we use UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum, or another recognised safeguard. Contact us for more information about safeguards relevant to your data.

12. How long we keep data

  • Account, activity, and game history is kept while your account is active.
  • Ordinary message content and metadata is kept while the conversation and sender’s account remain active. If the sender deletes a message or their account, we remove the message from active conversation systems without undue delay, normally within 30 days, although a recipient may already have made a separate copy.
  • Reported messages, relevant conversation context, reports, blocks, and moderation decisions may be kept for up to 12 months after the report is closed so we can prevent repeated abuse, handle complaints, and establish or defend legal claims. We may keep a specific record longer when law, an active investigation, or an ongoing safety risk requires it.
  • After 24 months of inactivity, we give at least 30 days’ notice before deleting or anonymising the account.
  • When you delete activity or your account, we remove it from active systems without undue delay. Copies may remain in protected backups until those backups are overwritten through our normal retention cycle. While retained in a backup, deleted data is kept beyond routine use and is not used for any other purpose. If a backup must be restored, we take steps to reapply the deletion.
  • Essential security logs may be kept for up to 90 days.

We may retain limited information for longer where necessary to meet a legal obligation, prevent fraud, establish or defend legal claims, or record a privacy request.

13. Security

We use proportionate technical and organisational measures designed to protect personal data, including password hashing, encrypted connections, secure mobile token storage, access controls, monitoring, and protected backups where appropriate.

No online service can promise absolute security. Please use a unique password, protect your device, and contact us if you believe your account has been compromised.

14. Your rights and choices

Under UK data-protection law, you may have the right to:

  • Ask for a copy of your personal data.
  • Correct inaccurate or incomplete data.
  • Delete data or restrict how it is used.
  • Receive portable data in a commonly used machine-readable format.
  • Object to processing based on legitimate interests.
  • Withdraw consent for connected fitness data.

Email [email protected] to exercise a right. We may verify your identity before acting and normally respond within one month.

You can also complain to the Information Commissioner’s Office .

15. Children

Faction is not intended for anyone under 18. If you believe a person under 18 has created an account, contact us so we can investigate and delete the account where appropriate.

16. Changes to this policy

We may update this policy as Faction develops or legal requirements change. We will post the revised policy with a new date and give additional notice through the service or by email when a change materially affects your rights or how we use data.

Any change to this policy concerning Garmin data will be submitted to the Garmin Connect Developer Program team and will not be implemented until Garmin has provided written approval.

17. Contact us

Faction.Fitness

United Kingdom

Email: [email protected]

Web v0.5.29