Privacy Policy for Journey Together
Last updated: August 2026
This Privacy Policy describes how Journey Together ("we", "us", or "our") collects, uses, and protects your personal information when you use our mobile application.
1. Information We Collect
1.1 Account Information
- Username
- Email address (used to log in and for password reset)
- Date of birth (collected at sign up solely to verify you meet the 18+ minimum age requirement — see Section 10)
Note: We do not store your plaintext password. Credential handling is performed by Firebase Authentication. In the app UI, you sign in using your email and password; your username is a separate, public profile handle used for follows and journeys. Your date of birth is private and is never shown to other users.
1.2 Health and Fitness Data
- Step count data that you enter manually in the app
- Step counts synced from your device health platform (Apple Health on iOS / Health Connect on Android) only if you explicitly grant permission
- Your daily step goal
We store step counts only. We read step counts only — no other health or fitness data is read from your device's health platform.
1.3 Social and Journey Information
- Who you follow and who follows you, and pending follow requests
- Journey membership, invites, and the progress you share with other members of that journey
- The visibility level you choose for your profile and journeys (public, followers-only, or invite-only)
1.4 Feedback
- The message and category (feedback, bug report, feature request) you submit through in-app feedback
1.5 Diagnostic and Usage Data
- Crash and error reports (device model, OS version, app version, and stack traces) collected automatically via Firebase Crashlytics
- App usage data (app opens, session length, screens viewed, and general interaction patterns) collected automatically via Firebase Analytics
This data is tied to an installation/device identifier, not directly to your name or email, and is used only for diagnosing problems and understanding overall app usage — not for advertising.
2. How We Use Your Information
We use your information to:
- Provide and maintain the Journey Together service
- Authenticate your account and ensure security
- Display your fitness progress and achievements
- Enable social features like follows and shared journeys, and share your journey progress with other members of that journey
- Send password-reset emails via Firebase Authentication
- Review and respond to feedback and bug reports
- Diagnose and fix crashes and bugs, and understand how the app is used, so we can improve it
- Improve app functionality and user experience
- Comply with legal obligations
3. Who Can See Your Information
- Depending on your privacy settings, your username and step history may be visible to your followers.
- Journey progress is visible to other members of that journey.
- Setting your profile to private, or a journey to followers-only or invite-only, limits who can see it.
4. Legal Basis for Processing (UK/EU Users)
Under UK GDPR and EU GDPR, we process your data based on:
- Your consent (for health data)
- Contract performance (to provide the service)
- Legitimate interests (for security, crash diagnostics, and app improvements)
- Legal obligations (for data protection and safety)
Health data (including step counts) is "special category data" under UK/EU GDPR Article 9. We rely on your explicit consent as the legal basis for processing it.
5. Data Sharing and Disclosure
We do not sell your personal data. We may share your information:
- With Google Firebase/Google Cloud (our cloud services provider)
- When required by law or to protect rights
6. International Data Transfers
Your data is stored on Firebase/Google Cloud servers, which may involve transfers outside your country. Where required, we rely on appropriate transfer mechanisms (for example, Standard Contractual Clauses).
7. Data Retention
- Account data is retained while your account is active.
- When you delete your account, we delete your profile, step history, follow connections, and journey memberships stored under your account.
- If you own a journey, deleting your account deletes that journey for all of its members. If you're a member (not the owner) of a journey, you're removed from it but the journey continues for other members.
- Feedback and bug reports you submitted are no longer linked to your account, but may be kept for as long as needed to review, fix issues, and improve the app.
8. Your Rights (UK/EU Users)
You have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict or object to processing
- Data portability
- Withdraw consent at any time
- Lodge a complaint with the ICO (UK) or supervisory authority (EU)
9. Users Outside the UK/EU
These Terms and this Privacy Policy apply to all users of Journey Together regardless of location. The GDPR-specific rights and procedures described above are guaranteed to UK/EU users. Users elsewhere do not have statutory rights under UK/EU GDPR, but we apply the same data-handling and account-deletion practices to all users as a matter of policy, regardless of where they're located.
10. Children's Privacy
This app is not intended for anyone under 18 years old. We do not knowingly collect data from anyone under 18. We ask for your date of birth at sign up and do not create accounts for anyone who does not meet this age requirement.
11. Security Measures
We use Firebase services. Data transmitted between your device and Firebase is encrypted in transit (TLS). Firebase/Google Cloud also provides encryption at rest for stored data.
12. Medical Disclaimer
Journey Together is a fitness and lifestyle app. It is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. Always consult a qualified healthcare professional for medical advice, diagnosis, or treatment.
13. Changes to This Policy
We will notify you of material changes via the app or email. Continued use constitutes acceptance of the updated policy.
14. Contact Information
Data Controller: Benjamin Ward, trading as BabyofDoom
Email: bod.headquarters@gmail.com
For UK users: You can contact the Information Commissioner's Office (ICO) if you have concerns.
For EU users: Contact your local data protection authority.
15. UK/EU Specific Information
- We comply with UK GDPR and EU GDPR requirements
- We respond to Subject Access Requests within 30 days