Privacy Policy

Last updated: 19 July 2026

Surgo is a competitive swimming app that turns your swim sessions into leaderboards, groups, and friendly rivalries. This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, and the rights and choices you have.

1. Who we are

Surgo is operated by Surgo Digital Labs Ltd (registration no. HE 492201) ("Surgo", "we", "us", or "our"), the data controller responsible for your personal data. Our registered address is:

Surgo Digital Labs Ltd
Gonia Tagmatarchi Dimitriou Pouliou & Kostaki Pantelidi
MELINA COURT, 2nd floor
8011 Paphos, Cyprus

For any privacy question or request, contact us at support@surgolbs.com.

2. Information we collect

Account information

When you sign in with Apple or Google, we receive your name, email address, and a unique account identifier. You choose a username and may add a profile photo. If you sign in with Apple using "Hide My Email", we only receive the relay address Apple provides.

Health & fitness data

With your explicit permission, Surgo reads swim workout data from Apple Health (HealthKit) — including distance, duration, pace, lap and split times, stroke type, SWOLF and similar efficiency metrics, heart-rate summaries where available, and workout dates. We use this data to score your sessions, power leaderboards, and generate your personal insights.

Because this information relates to your health and fitness, we treat it as a special category of personal data under the GDPR and process it only on the basis of your explicit consent (the HealthKit permission you grant). We never sell health data, never use it for advertising, and you can revoke access at any time in the iOS Health and Settings apps.

Activity & competition data

We store the groups you join, your logged sessions and scores, leaderboard rankings, coins, boosts, streaks, personal bests, reactions, and referrals so the game works across your devices and with the people you compete against.

Images you upload

If you upload a profile or group image, it is automatically screened for unsafe content before it is published (see "AI & automated processing" below). Images that pass are stored to display in the app.

AI-generated insights

If you use our AI reports feature, we send your swim activity data to our AI provider (OpenAI) to generate personalized summaries and coaching-style insights. This processing is used only to produce your report; it is not used to train third-party models and is not used for advertising.

Device & usage data

We collect limited technical data to operate, secure, and improve the app:

Purchases

Subscriptions and in-app purchases are processed by Apple. We use RevenueCat to manage your entitlement (i.e. whether a purchase is active) and to reconcile subscription status. We do not receive or store your full payment-card details.

Communications

If you email us or contact support, we keep your messages and contact details to respond and keep a record of the request.

3. How we collect information

4. How we use your information

5. Legal bases for processing (GDPR)

If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases:

Purpose Legal basis
Creating your account, authentication, running competitions and leaderboards Performance of a contract
Reading and processing your HealthKit swim data; generating AI insights Your explicit consent (special-category data)
Product analytics and app improvement Legitimate interests (and/or consent where required)
Crash and performance monitoring, security, fraud and abuse prevention, content moderation Legitimate interests; legal obligation
Personalized advertising identifiers Consent (via Apple's App Tracking Transparency)
Marketing or non-transactional emails, if any Consent
Complying with legal requests and defending legal claims Legal obligation; legitimate interests

6. AI & automated processing

We use automated tools to keep the community safe and to power certain features:

These processes do not make legally or similarly significant decisions about you without human involvement. If moderation blocks content you submitted, you can contact us to ask us to review it.

7. Service providers & sharing

We share data with trusted providers only as needed to run the app. Each acts as our processor (or, where applicable, an independent controller) and is bound by appropriate contractual terms.

Provider Purpose
Supabase Database, authentication, and backend hosting
Apple Sign in with Apple, HealthKit source, in-app purchases, push delivery (APNs)
Google Google Sign-In, Firebase App Check (device attestation), Cloud Vision (image moderation), AdMob (advertising, when enabled)
OpenAI Text moderation and AI-generated insights
RevenueCat Subscription and entitlement management
PostHog Product analytics
Sentry Crash and error reporting
Resend Transactional email delivery
Expo Push notification delivery

We also share information with other users as part of the app's social features — for example, your username, profile photo, and competition results are visible to members of groups you join and on leaderboards.

We may disclose information to comply with the law, enforce our Terms, or protect the rights, safety, and property of Surgo, our users, or others. If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

We do not sell your personal data.

8. International data transfers

We are based in Cyprus (EU). Some of our providers process data in countries outside the EEA, including the United States. Where we transfer personal data outside the EEA, UK, or Switzerland, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision (including the EU–US Data Privacy Framework where a provider is certified).

9. Data retention

We keep personal data only for as long as we need it:

10. Your rights & choices

In-app controls

GDPR rights (EEA, UK, Switzerland)

You have the right to:

California rights (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect and how we use it, to request access to or deletion of that information, to correct inaccurate information, and to opt out of any "sale" or "sharing" of personal information. We will not discriminate against you for exercising these rights. As stated above, we do not sell your personal data.

To exercise any of these rights, email support@surgolbs.com. We will respond within the timeframe required by applicable law and may need to verify your identity first.

11. Advertising & tracking

Surgo is a native mobile app and does not use website cookies. When ads are enabled, Google AdMob may use your device's advertising identifier to serve and measure ads. On iOS, this only occurs if you allow tracking through Apple's App Tracking Transparency prompt; you can change your choice at any time in iOS Settings. We use PostHog and Sentry SDKs for analytics and diagnostics as described above.

12. Security

We use industry-standard measures — encryption in transit, device attestation (Firebase App Check), access controls, and least-privilege backend policies — to protect your data. No method of transmission or storage is 100% secure, but we work continuously to protect your information and will notify you and the relevant authorities of a data breach where required by law.

13. Children's privacy

Surgo is not directed to children. You must be at least 13 years old (or the minimum age required in your country) to use Surgo. We do not knowingly collect personal data from children below that age. If you believe a child has provided us data, contact us and we will delete it.

14. Changes to this policy

We may update this policy from time to time. We'll revise the "Last updated" date above and, for material changes, notify you in the app or by email.

15. Contact

Questions or requests about this policy? Email support@surgolbs.com or write to Surgo Digital Labs Ltd at the address in Section 1.