Privacy Policy
Last updated: 19 July 2026
Surgo is a competitive swimming app that turns your swim sessions into leaderboards, groups, and friendly rivalries. This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, and the rights and choices you have.
1. Who we are
Surgo is operated by Surgo Digital Labs Ltd (registration no. HE 492201) ("Surgo", "we", "us", or "our"), the data controller responsible for your personal data. Our registered address is:
Surgo Digital Labs Ltd
Gonia Tagmatarchi Dimitriou Pouliou & Kostaki Pantelidi
MELINA COURT, 2nd floor
8011 Paphos, Cyprus
For any privacy question or request, contact us at support@surgolbs.com.
2. Information we collect
Account information
When you sign in with Apple or Google, we receive your name, email address, and a unique account identifier. You choose a username and may add a profile photo. If you sign in with Apple using "Hide My Email", we only receive the relay address Apple provides.
Health & fitness data
With your explicit permission, Surgo reads swim workout data from Apple Health (HealthKit) — including distance, duration, pace, lap and split times, stroke type, SWOLF and similar efficiency metrics, heart-rate summaries where available, and workout dates. We use this data to score your sessions, power leaderboards, and generate your personal insights.
Because this information relates to your health and fitness, we treat it as a special category of personal data under the GDPR and process it only on the basis of your explicit consent (the HealthKit permission you grant). We never sell health data, never use it for advertising, and you can revoke access at any time in the iOS Health and Settings apps.
Activity & competition data
We store the groups you join, your logged sessions and scores, leaderboard rankings, coins, boosts, streaks, personal bests, reactions, and referrals so the game works across your devices and with the people you compete against.
Images you upload
If you upload a profile or group image, it is automatically screened for unsafe content before it is published (see "AI & automated processing" below). Images that pass are stored to display in the app.
AI-generated insights
If you use our AI reports feature, we send your swim activity data to our AI provider (OpenAI) to generate personalized summaries and coaching-style insights. This processing is used only to produce your report; it is not used to train third-party models and is not used for advertising.
Device & usage data
We collect limited technical data to operate, secure, and improve the app:
- Crash & performance data via Sentry (error reports, device model, operating-system version, and diagnostic context).
- Product analytics via PostHog (in-app events, such as which screens and features are used) to understand how the app is used and prioritize improvements.
- Push notification tokens so we can send you the reminders and competition updates you enable.
- Advertising identifiers — only if ads are enabled and you have permitted tracking — used by Google AdMob to serve and measure ads.
Purchases
Subscriptions and in-app purchases are processed by Apple. We use RevenueCat to manage your entitlement (i.e. whether a purchase is active) and to reconcile subscription status. We do not receive or store your full payment-card details.
Communications
If you email us or contact support, we keep your messages and contact details to respond and keep a record of the request.
3. How we collect information
- Directly from you — when you sign in, choose a username, upload an image, join groups, or contact us.
- Automatically — device and usage data generated as you use the app, and swim data read from HealthKit with your permission.
- From third parties — your name, email, and identifier from Apple or Google when you sign in, and subscription status from Apple via RevenueCat.
4. How we use your information
- Provide, maintain, and improve the app and its features.
- Score sessions and calculate leaderboards, coins, and rewards.
- Generate AI reports and personalized insights you request.
- Authenticate you and keep your account secure.
- Send you notifications and transactional emails you've enabled.
- Detect, prevent, and respond to fraud, abuse, and unsafe content.
- Understand usage and diagnose crashes and performance issues.
- Comply with legal obligations and enforce our Terms.
5. Legal bases for processing (GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Creating your account, authentication, running competitions and leaderboards | Performance of a contract |
| Reading and processing your HealthKit swim data; generating AI insights | Your explicit consent (special-category data) |
| Product analytics and app improvement | Legitimate interests (and/or consent where required) |
| Crash and performance monitoring, security, fraud and abuse prevention, content moderation | Legitimate interests; legal obligation |
| Personalized advertising identifiers | Consent (via Apple's App Tracking Transparency) |
| Marketing or non-transactional emails, if any | Consent |
| Complying with legal requests and defending legal claims | Legal obligation; legitimate interests |
6. AI & automated processing
We use automated tools to keep the community safe and to power certain features:
- Text moderation — usernames, group names, and other text you submit are screened for unsafe content using OpenAI.
- Image moderation — profile and group images are screened for unsafe content using Google Cloud Vision (SafeSearch) before they are published.
- AI reports — your swim data is processed by OpenAI to generate personalized insights, as described above.
These processes do not make legally or similarly significant decisions about you without human involvement. If moderation blocks content you submitted, you can contact us to ask us to review it.
7. Service providers & sharing
We share data with trusted providers only as needed to run the app. Each acts as our processor (or, where applicable, an independent controller) and is bound by appropriate contractual terms.
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication, and backend hosting |
| Apple | Sign in with Apple, HealthKit source, in-app purchases, push delivery (APNs) |
| Google Sign-In, Firebase App Check (device attestation), Cloud Vision (image moderation), AdMob (advertising, when enabled) | |
| OpenAI | Text moderation and AI-generated insights |
| RevenueCat | Subscription and entitlement management |
| PostHog | Product analytics |
| Sentry | Crash and error reporting |
| Resend | Transactional email delivery |
| Expo | Push notification delivery |
We also share information with other users as part of the app's social features — for example, your username, profile photo, and competition results are visible to members of groups you join and on leaderboards.
We may disclose information to comply with the law, enforce our Terms, or protect the rights, safety, and property of Surgo, our users, or others. If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
We do not sell your personal data.
8. International data transfers
We are based in Cyprus (EU). Some of our providers process data in countries outside the EEA, including the United States. Where we transfer personal data outside the EEA, UK, or Switzerland, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision (including the EU–US Data Privacy Framework where a provider is certified).
9. Data retention
We keep personal data only for as long as we need it:
- Account & activity data — for as long as your account is active.
- After account deletion — we delete or anonymize your personal data within 90 days, except where we must retain it to comply with legal obligations, resolve disputes, or prevent abuse.
- Crash & analytics data — retained on a rolling basis in line with our providers' default retention periods.
- Backups — residual copies may persist in secure backups for a limited period before being overwritten.
10. Your rights & choices
In-app controls
- Access, correct, or delete your account data from within the app.
- Revoke HealthKit access at any time in iOS Settings.
- Disable push notifications in iOS Settings.
- Control ad tracking via Apple's App Tracking Transparency prompt and iOS Settings.
GDPR rights (EEA, UK, Switzerland)
You have the right to:
- access a copy of the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased ("right to be forgotten");
- restrict or object to certain processing;
- data portability (receive your data in a portable format);
- withdraw consent at any time, without affecting prior processing;
- lodge a complaint with a supervisory authority — in Cyprus, the Office of the Commissioner for Personal Data Protection, or the authority in your country of residence.
California rights (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect and how we use it, to request access to or deletion of that information, to correct inaccurate information, and to opt out of any "sale" or "sharing" of personal information. We will not discriminate against you for exercising these rights. As stated above, we do not sell your personal data.
To exercise any of these rights, email support@surgolbs.com. We will respond within the timeframe required by applicable law and may need to verify your identity first.
11. Advertising & tracking
Surgo is a native mobile app and does not use website cookies. When ads are enabled, Google AdMob may use your device's advertising identifier to serve and measure ads. On iOS, this only occurs if you allow tracking through Apple's App Tracking Transparency prompt; you can change your choice at any time in iOS Settings. We use PostHog and Sentry SDKs for analytics and diagnostics as described above.
12. Security
We use industry-standard measures — encryption in transit, device attestation (Firebase App Check), access controls, and least-privilege backend policies — to protect your data. No method of transmission or storage is 100% secure, but we work continuously to protect your information and will notify you and the relevant authorities of a data breach where required by law.
13. Children's privacy
Surgo is not directed to children. You must be at least 13 years old (or the minimum age required in your country) to use Surgo. We do not knowingly collect personal data from children below that age. If you believe a child has provided us data, contact us and we will delete it.
14. Changes to this policy
We may update this policy from time to time. We'll revise the "Last updated" date above and, for material changes, notify you in the app or by email.
15. Contact
Questions or requests about this policy? Email support@surgolbs.com or write to Surgo Digital Labs Ltd at the address in Section 1.
Surgo