TribeLog Privacy Policy

Last updated: July 31, 2026

TribeLog, from Rise With The Tribe, helps members join fitness challenges, log activity, build streaks, earn badges, and share progress. We collect only the information needed to run those features, protect the community, and support your account.

Information We Collect

Account details, profile appearance, optional Instagram handle, challenge participation, activity logs, badges, referrals, feature submissions, optional challenge proof photos and captions, proof vouches and reports, support requests, report/block records, optional notification device tokens, and optional health-sync activity imported only after permission is granted.

For a challenge that explicitly requires Tribe Verified proof, you choose whether to attach a photo and caption to a progress claim. TribeLog re-encodes the image to remove embedded metadata such as EXIF and location data before it is made available. The proof is available only through short-lived authenticated access to active members of that challenge and authorized moderators. A private report reason is visible only to the reporter and authorized moderators; vouching and moderation state are used to decide whether the claimed progress counts.

Health sync is optional for general TribeLog use. On iOS, TribeLog reads Apple Health workouts and step count only after you grant permission. If you choose Watch workout mode, permission to save that workout to Apple Health is required for the Watch workout to start. Heart rate, active energy, and distance are optional: if you deny them, those metrics are simply omitted. For an outdoor Watch workout, location is requested only when you start that activity, and you may continue without GPS. Route coordinates are written directly to Apple Health and are not uploaded to TribeLog. On Android, exercise-session access is required for workout import; distance and steps are optional enrichment permissions. A separate, optional workout auto-sync control requests background Health Connect access only after you enable it. While enabled and signed in, Android periodically reads a bounded recent window of permitted exercise, step, and distance records so your private TribeLog activity history and derived progress can stay current when the app is not open. You can turn auto sync off in TribeLog or revoke access in Health Connect at any time. Manual activity logging on your phone remains available without health permission.

For an imported or Watch-created activity, we save a normalized activity summary to your private TribeLog account in Firebase. This can include activity type, value or duration, points, date, source provider and provider-app identifier, an opaque source record ID, start and end timestamps, source last-modified timestamp, and whether the Apple Health record was complete or interrupted. These fields let us attribute the activity and prevent duplicate workouts or points. Apple Health permission does not enable private cloud workout metrics. If you separately opt in on Apple Watch, TribeLog may also save active duration, active energy, distance, elevation gain, heart-rate minimum/average/maximum, sample count, coverage, and one-minute heart-rate averages. Raw heart-rate samples, GPS coordinates, exercise routes, Apple Health workout UUIDs, raw Apple Health or Health Connect payloads, and watch/device identifiers are not uploaded to TribeLog. No Health data is used for advertising, tracking, medical diagnosis or data mining.

Product Analytics and Diagnostics

When analytics collection is enabled for a disclosed app build or test cohort, TribeLog uses Firebase Analytics to record a limited set of product events such as onboarding completion, joining or creating a tribe, logging a first activity, sharing or accepting an invitation, opening a Pro offer, starting or restoring a purchase, and using creator or Tribe Momentum features. Event properties are limited to non-identifying codes such as platform, app version, entry point, Free or Pro plan, result or reason code, trial state, challenge type, and a non-identifying cohort key. For signed-in members, TribeLog may also use a one-way, app-specific hash of the Firebase account identifier as an Analytics User-ID so the same member is counted consistently across TribeLog platforms and devices. The raw Firebase account identifier, name, and email address are not sent as Analytics User-ID values.

When diagnostic collection is enabled, Firebase Crashlytics and Firebase Performance Monitoring may receive crash stack traces, app version, operating-system and device-class information, launch and screen timing, network timing, and technical failure codes needed to diagnose reliability and loading performance. TribeLog does not intentionally send names, email addresses, message text, raw account identifiers, invite codes, activity or workout details, Health fields, precise location, purchase receipts, or user-generated challenge text to analytics, crash, or performance events.

Analytics and diagnostic collection remains disabled in builds where the corresponding privacy and store disclosures have not been approved. Development and staged-test measurements are reviewed before broader release.

Subscriptions

If you start or manage TribeLog Pro, Apple or Google processes the store transaction. RevenueCat may process the store, product identifier, trial or subscription lifecycle state, expiry, and an app-specific account identifier so TribeLog can verify and synchronize access across your signed-in devices. TribeLog does not store your card number. Raw receipts, purchase tokens, transaction identifiers, and store-account details are not placed in product analytics.

How We Use Information

We use this information to authenticate users, show progress, run challenges and leaderboards, sync eligible activity, send challenge reminders only after notification permission, verify subscription access, process support and safety requests, diagnose crashes and loading problems, and improve the product experience.

Sharing

We do not sell personal data. We do not use app data to track users across other companies' apps and websites for advertising. Feature submissions are reviewed manually and are only considered for reposting when consent is provided. We use service providers such as Firebase, RevenueCat, Apple and Google app-store billing, Google Sign-In, Apple Sign in, Apple Health and Android Health Connect permission services, and notification services to operate the app.

Imported workout details, provider-app identifiers, source record IDs, and source timestamps are not automatically published to the Tribe Feed or exposed to other members. Imported activity can affect derived TribeLog points, streaks, badges, challenge progress, and leaderboard or profile totals according to the visibility of those TribeLog surfaces. Sharing a detailed workout summary requires a separate user action.

A Tribe Verified proof photo, caption, claimed tasks, and pending or verified status are shared only within the relevant challenge, with access limited to active challenge members and authorized moderators. Reporting can hide the proof from the reporter or the whole challenge while it is reviewed. Proof photos are not public and are not used for advertising or cross-app tracking.

Your Choices

You can update your profile, turn Android workout auto sync off, disconnect health permissions through your device settings, turn private cloud workout metrics off independently in TribeLog, delete one or all stored workout-metric summaries, and request account or data deletion from the data deletion page. Revoking a Health read category stops that category from appearing in future Watch workouts and imports. Turning cloud workout metrics off immediately stops new metric uploads but does not change Apple Health permission. Revoking workout-write permission prevents new Watch workouts from starting but does not block phone logging. These choices do not automatically erase workouts already saved in Apple Health.

Retention and Deletion

We retain account and challenge records as needed to operate TribeLog, protect the service, comply with legal obligations, and resolve support or safety issues. Tribe Verified source uploads are removed after server processing, and the privacy-processed proof image is scheduled for deletion after seven days. You can remove your image sooner, withdraw a pending proof, or delete your account. Proof status, vouch, report, moderation, and score-audit records may be retained after the image is removed where needed to preserve challenge integrity, safety decisions, and accurate progress. Private health-source IDs and reconciliation records are retained while needed to maintain an imported activity, reconcile edits or deletions, and prevent duplicate awards. Account deletion removes the user's imported activity, private wearable reconciliation records, and owned challenge-proof media and identity links, subject to any limited retention required by law or for documented security and dispute handling. You can request account or data deletion in the app or from the data deletion page.

Health and Fitness Disclaimer

TribeLog is a fitness accountability tool, not a medical app. It does not provide diagnosis, treatment, medical advice, risk scoring, or guaranteed fitness outcomes.

Contact

Questions can be sent through the support page or by email at support@risewiththetribe.app.