Privacy Policy
This policy explains what information Thrive handles, why, and the choices you have. It is a notice, not blanket consent.
1. About This Policy
This Privacy Policy describes how Thrive handles information when you use our fitness logging, progress tracking and social fitness application (the “app”) and this website. It is provided as a notice to help you understand our practices.
Reading this policy is not the same as agreeing to everything in it. Where the law requires your consent, we ask for it separately — for example, before enabling optional product analytics or another optional activity that requires consent. Operating-system permissions, such as camera, photos, location, notifications or HealthKit access, are technical permissions required to use certain features and are distinct from determining Thrive's legal basis under applicable law.
2. Who Operates Thrive
Thrive is operated by Jamie Liddicoat from Victoria, Australia. In this policy, “Thrive”, “we”, “us” and “our” refer to the operator of the app and website.
For any privacy question or request, you can contact us at customersupport.thrive@gmail.com.
3. Information You Provide
Depending on how you use Thrive, you may provide:
- Email address and authentication information
- When you use Google Sign-In, Thrive may receive the Google account email, name and basic profile information made available through the sign-in flow.
- Google Sign-In does not give Thrive your Google password, Gmail inbox, contacts or Google Drive.
- Username, display name, biography and profile image
- Date of birth or age information used for eligibility
- Workout exercises, sets, repetitions, weights, duration and history
- Weight and body-measurement information you enter manually
- Posts, Fit Reels, comments, likes, saved content and follows
- Uploaded images and videos
- AI Equipment Scanner images
- Training preferences and inputs submitted to AI features
- Reports, moderation information and blocked-user relationships
- Support emails and privacy requests
Thrive does not have access to your password in readable form. Authentication is handled through Supabase, which processes and stores authentication credentials.
4. Information Collected When You Use Thrive
When you use Thrive, we may collect:
- App version
- Operating system and device platform
- General device and technical information
- Internal account, installation or session identifiers
- Feature usage where PostHog consent is enabled
- Crash, performance and technical diagnostic information through Sentry
- Subscription product and entitlement status through RevenueCat
- Advertising delivery, fraud prevention and measurement information through AdMob
- Precise location coordinates only when you explicitly request current location for a post
Thrive may collect precise location coordinates only when you explicitly choose “Use current location” while adding a location to a post. Thrive does not collect location on launch or continuously, does not use background location, and does not use location for advertising or cross-app tracking. You can use Thrive without granting device location by manually typing or selecting a place instead.
5. Health App Information
On supported Apple devices, you may choose to allow Thrive to read Body Mass information from the Health app. Thrive uses this information only to import weight entries and provide requested fitness-tracking features. Thrive does not write information back to the Health app. Permission is optional and can be changed through Apple device settings. Information obtained through HealthKit is not sold, used for advertising, used for marketing, or included in PostHog product analytics.
- Health information may be stored in your Thrive account after import.
- Deleting a record in the Health app does not necessarily delete a previously imported Thrive record.
- You can delete imported entries through Thrive where supported.
- HealthKit access is read-only: Thrive does not write Body Mass data back to Apple Health.
- HealthKit-derived data is not intentionally included in PostHog or Sentry analytics payloads.
- If you revoke permission, Thrive will stop importing new Health app information.
If health information is treated as special-category data under applicable GDPR or UK GDPR law, Thrive processes it only when you actively enable the relevant feature and only where an applicable legal condition is available. Where explicit consent is required, Thrive must obtain it separately; you can withdraw that consent prospectively. Operating-system or HealthKit permissions are technical requirements for access and are distinct from determining Thrive's legal basis.
For more detail, see our Consumer Health Data Privacy Policy.
Thrive does not provide healthcare and is not a medical service.
6. Device Permissions
Thrive may request the following device permissions, only for the related feature:
- Camera: equipment scanning and creating social content
- Photos / Media Library: selecting media and profile images
- Microphone: recording video where that feature is used
- Notifications: workout, social or application notifications
- Location: optional precise location only after Create Post → Add Location → Use current location; iOS requests When-In-Use permission. This operating-system permission is distinct from any legal consent requirement.
- Health: optional read-only Body Mass import
Operating-system permission prompts are technical permissions required by the platform to access a feature; they are not automatically legal consent for every related processing activity. You can deny or revoke them in your device settings. Thrive does not request location on launch, continuously monitor location or use background location. You can manually type or select a place without granting device location. If you save a post with a current location, its coordinates may be stored with that post and visible to people allowed to view it. Declining a permission may limit the related feature, but will not disable unrelated core functionality.
7. AI Features and AI Providers
Thrive offers AI features including the Equipment Scanner, Training Planner and Workout Insights. These features work as follows:
- AI inputs are processed only when you activate an AI feature.
- Equipment scanner images may be transmitted to Roboflow for equipment recognition.
- OpenAI may receive the scanner image or request as a fallback where applicable.
- These transfers occur only when you invoke the relevant scanner or AI feature.
- Scanner images are processed for the request and are not stored as user media in your Thrive account by the scanner flow.
- We seek to minimise unnecessary identifiers in what we send.
- Processing by third-party providers is also subject to their applicable data-processing terms and retention practices.
- Equipment images, workout information and training preferences may still be personal information.
- You should not upload images containing other people, documents, screens, addresses or other unnecessary identifying information.
- AI outputs may be inaccurate, incomplete or unsuitable.
- AI is not used to make decisions that produce legal or similarly significant effects.
- AI outputs are not diagnoses, treatment, emergency guidance or personalised medical advice.
- You can choose not to use AI features.
For more detail, see our AI & Fitness Disclaimer.
8. Optional Product Analytics — PostHog
If you enable Share Usage Analytics, Thrive uses PostHog's European Union service to understand how screens and features are used. Events may include screen names, feature interactions, app version, platform, subscription tier and broad operational outcomes. Thrive may associate these events with an internal account identifier so activity can be understood across authenticated sessions.
- Product analytics are off by default and entirely voluntary.
- You can change this at any time in Settings → Privacy → Share Usage Analytics.
- Disabling it stops future PostHog events.
- Your choice persists after logout locally unless you change it.
- Account deletion triggers a request to delete the associated PostHog person and event history where applicable.
- No raw dynamic route identifiers or authentication tokens are intentionally sent.
- PostHog EU ingest is used, GeoIP is disabled in the current client configuration, and Thrive does not use session replay.
- PostHog is first-party product analytics only, not cross-app advertising tracking, and is not Apple ATT consent.
- No Health app data, workout notes, exact body measurements, post text, comments, messages, AI prompt text or media URLs are intentionally included.
The internal account identifier used for analytics is derived from your Supabase account identifier. It is not your email or username, but it is not anonymous or non-personally identifiable either.
9. Crash and Technical Diagnostics — Sentry
Thrive uses Sentry to collect crash and technical diagnostic information so we can keep the app reliable and secure. Sentry operates independently of the optional PostHog analytics toggle.
- Diagnostic data may include app version, operating system, affected feature, technical error codes, timing and limited diagnostic context.
- We apply sanitisation intended to exclude user-entered content, authentication tokens, Health app information, workout notes, messages, AI prompts, captions and exact body data.
- No security control can guarantee that unintended diagnostic information is never captured.
- Sentry data is used for reliability, security and troubleshooting.
- sendDefaultPii is disabled, Thrive does not set a Sentry user, and event user identity is stripped.
- Sentry operates independently of the optional PostHog analytics setting.
10. Advertising — Google AdMob
Free users may see advertising within Thrive's social feed surfaces, including Fit Reels and All Posts.
- Ads are delivered by Google AdMob.
- Thrive configures ads as non-personalised.
- AdMob may process app/device information for ad delivery, frequency controls, fraud prevention, security and measurement under Google's own policies.
- Thrive does not sell your workout or Health app information to advertisers.
- Health app data is never used for advertising.
- Thrive sends non-personalised ad requests and does not use PostHog analytics consent to personalise ads.
- Thrive does not request Apple ATT consent, access IDFA through an ATT flow, or send your email, Supabase user ID or custom ad-targeting identifiers to AdMob.
- Ads may be suppressed by eligibility rules, including applicable paid, ad-free or age-ineligible states.
- Thrive does not use AdMob for cross-app tracking or personalised advertising.
- Ad-Free and Thrive Pro remove advertising according to the product description.
Non-personalised advertising still involves some data processing by Google, and we do not claim that Google collects nothing.
11. Subscriptions and Purchases
Where Thrive offers paid subscriptions or purchases:
- Purchases are processed by the relevant app store (Apple App Store or Google Play).
- Thrive does not receive or store full payment-card details.
- RevenueCat receives store purchase/receipt information and may process the subscription product identifier, tier or entitlement, subscription status, renewal or expiry date, billing period, store platform, trial or introductory-period status, renewal status, and transaction price and currency metadata when supplied by the store or RevenueCat. Thrive does not store full card details.
- Thrive may use Resend to send transactional account and subscription lifecycle emails, including renewal reminders. These are not marketing emails. Resend may process your account email address, transactional metadata, provider message ID, and delivery, bounce or complaint status.
- Purchase records may remain with Apple, Google or RevenueCat under their own legal, tax, fraud and retention requirements.
- Account deletion does not cancel active subscriptions.
13. How We Use Information
We use information to:
- Provide and secure accounts
- Sync workouts and settings
- Display progress and statistics
- Operate social features
- Process AI requests
- Manage purchases and entitlements
- Deliver non-personalised ads
- Provide optional analytics
- Diagnose crashes
- Prevent fraud and abuse
- Moderate content
- Provide customer support
- Comply with legal obligations
- Enforce our Terms and Community Guidelines
14. Legal Bases for Processing
If you are in the European Economic Area (EEA) or the United Kingdom, we rely on the following legal bases:
- Performance of a contract: operating the account and app features you request
- Consent: where applicable, for optional processing for which Thrive separately asks for consent, such as optional product analytics and certain optional data-processing activities.
- Legitimate interests: security, fraud prevention, service reliability, crash diagnostics, moderation and service improvement, subject to your rights
- Legal obligations: billing, legal requests and regulatory compliance
Where we rely on consent, you can withdraw it at any time. Withdrawal does not affect processing that took place before you withdrew.
16. Third-Party Services
The following third-party services may process information as part of operating Thrive. Each provider processes data under its own privacy policy.
| Provider | Purpose | Data categories |
|---|---|---|
| Supabase | Authentication, database, storage and server functions | Account credentials, profile, workouts, social content, uploaded media, app data |
| RevenueCat | Subscription and entitlement management | Store purchase/receipt information, product identifiers, entitlement status, internal customer identifier |
| Apple App Store | Purchases and subscription management | Payment processing and purchase history (handled by Apple) |
| Google Play | Purchases and subscription management, where available | Payment processing and purchase history (handled by Google) |
| Google AdMob | Non-personalised advertising in social feed surfaces | App/device information for ad delivery, frequency control, fraud prevention and measurement |
| OpenAI | Processing selected AI feature inputs and scanner fallback requests | Equipment images, workout information and training preferences submitted to AI features |
| Roboflow | Equipment recognition for the AI Equipment Scanner | Equipment scanner images submitted when the scanner is invoked |
| Cloudflare Stream | Fit Reel video upload, processing, hosting, delivery and playback infrastructure | Fit Reel videos and technical information required to process and deliver them |
| Expo push infrastructure | Device push notification delivery | Push token and notification payload information required for delivery |
| Resend | Transactional account and subscription lifecycle emails | Account email address, transactional email metadata, provider message identifier, delivery, bounce and complaint status |
| PostHog EU | Optional product analytics (off by default) | Screen/feature usage events, app version, platform, subscription tier, internal account identifier |
| Sentry | Crash and technical diagnostics | App version, operating system, affected feature, technical error codes, timing, limited diagnostic context |
| Vercel | Website hosting and security logs | Basic request, IP, device and security log information for hosting this website |
| Apple Health / HealthKit | User-authorised Body Mass import (optional) | Body Mass entries you choose to import on supported Apple devices |
17. International Data Processing
- Thrive is operated from Australia.
- Depending on the provider and feature used, information may be processed in Australia, countries in the EEA, the United States and other jurisdictions in which our service providers maintain infrastructure.
- Privacy protections can differ by country.
- We do not claim that every provider uses the same region or transfer mechanism. See the processor table above and each provider's privacy policy for further details.
- Where required, transfers are handled using recognised contractual or legal safeguards.
We do not guarantee that all data remains in Australia or the EU.
18. Data Retention
We keep information only as long as reasonably necessary for the purposes below.
| Category | Retention |
|---|---|
| Active account, profile and workout data | While your account remains active and as needed to provide the service |
| Social content (posts, Fit Reels, comments) | Until deleted, account deletion or moderation removal, subject to backups and safety records |
| AI inputs and outputs | Only where needed to process the requested feature or save an output to your account, subject to applicable provider and service retention arrangements |
| Optional analytics (PostHog) | While consent remains enabled and according to PostHog retention settings |
| Crash diagnostics (Sentry) | For the period reasonably needed for troubleshooting, security and reliability |
| Support communications | While needed to resolve the request and maintain appropriate records |
| Moderation, abuse and security records | As reasonably necessary to prevent harm, enforce policies, resolve disputes or comply with law |
| Billing records | According to store, RevenueCat, tax, fraud-prevention and legal requirements |
| Backups | Until overwritten or deleted through normal backup schedules |
Deletion from active systems may occur before all backup copies expire.
19. Account and Data Deletion
You may delete your account from Settings → Delete Account or request deletion without access to the app by contacting customersupport.thrive@gmail.com from the email associated with the account.
- Identity verification may be required.
- We will never ask you to email your password, authentication codes, tokens, sensitive workout information or Health information.
- Active account data is deleted from Thrive's primary systems.
- Associated storage and analytics deletion is attempted.
- Limited records may remain for security, fraud prevention, abuse and moderation, legal obligations, dispute resolution, billing or payment-provider records that Thrive cannot independently erase, and technical backups or logs where applicable.
- Apple/Google purchase history is controlled by those providers.
- Deleting Thrive does not cancel active subscriptions.
- Requests are handled promptly and within applicable legal timeframes.
See our Delete Account page for full instructions.
20. Security
Thrive uses reasonable technical and organisational safeguards to protect information, but no system is completely secure. Our measures include:
- Access controls
- Authentication
- Database policies
- Server-side entitlement verification
- Encryption in transit where supported
- Monitoring and abuse prevention
21. Children and Age Restrictions
Thrive is not intended for children under 13, or any higher minimum age required by local law. Social participation features such as posting, liking, commenting, saving and following require you to be at least 16. Reporting and blocking remain available as safety actions where appropriate.
22. Your Privacy Rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to or port your information, and to withdraw consent where we rely on it. EEA and UK users may also have rights to rectification, erasure, portability and complaint to a supervisory authority where GDPR or UK GDPR applies. Canadian, New Zealand, Australian, Victorian and US state rights apply where applicable under local law.
How to exercise your privacy rights: email the Privacy Contact at customersupport.thrive@gmail.com, explain your request and the account involved, or use Settings → Delete Account for in-app deletion. We may need to verify your identity before releasing, correcting or deleting account information.
23. Complaints
Contact our Privacy Contact first with the concern and the account information needed to investigate. Thrive will review the issue and respond within a reasonable period. If the issue is unresolved, you may have the right to complain to the Office of the Australian Information Commissioner (OAIC), the Victorian Health Complaints Commissioner for applicable health-record matters, or your local EEA, UK, New Zealand, Canadian or US privacy regulator, as applicable.
24. Website Hosting and Cookies
This website is hosted through Vercel. As part of hosting, Vercel may process basic request, IP, device and security log information to deliver and protect the site.
This website does not use advertising or marketing cookies. We use Vercel's privacy-friendly web analytics, which is designed to measure aggregate website usage without cookies and without tracking you across other sites. Because no non-essential tracking cookies are used, this website does not display a cookie consent banner.
25. Changes to This Policy
We may update this policy from time to time. Updates will change the Last updated date. Material changes may also be communicated through the app, website or email where appropriate.
26. Contact Us
For privacy questions or requests, contact us at customersupport.thrive@gmail.com. Thrive is operated by Jamie Liddicoat from Victoria, Australia.

12. Social Features and Public Content