01Legal
Privacy policy
Effective 11 Sep 2026
This policy says what GBNETWORK collects, why it has it, who can see it, how long it is kept and how it is deleted. It is written from the app and its database, record by record, rather than from a template. Where a right exists but has no button in the app yet, this policy says so rather than implying one.
01Who we are, and who is accountable
GBNETWORK is a competitive lifting app operated from Kingston, Ontario, Canada. It is run by one person, and that person is accountable for privacy here. Write to inquiries@gbnetwork-app.com for their name and mailing address, or for anything else in this document. One person reads that inbox.
Two privacy laws apply. The federal Personal Information Protection and Electronic Documents Act, PIPEDA, applies to GBNETWORK everywhere in Canada, including Ontario, which has no separate private sector privacy law of its own. Quebec’s Law 25 applies to lifters who live in Quebec.
GBNETWORK is distributed in Canada only and does not target anyone in the European Economic Area, so the GDPR does not apply to it. We hold no privacy certification, we have not been audited by anyone, and we are not members of any privacy framework. If you see a claim like that about GBNETWORK anywhere, it did not come from us.
02The three claims
Three things are true of the build, and each one can be checked against the app itself rather than taken on trust.
- GBNETWORK never asks your phone for your location.
- GBNETWORK has no camera access and no photo upload.
- GBNETWORK never asks what you weigh, and ranks nothing by bodyweight.
The first two are absences in the binary. The location, camera and photo picker libraries are not installed, and the app declares no usage description for any of them, which is the string iOS requires before it will even show you a permission prompt. The third is an absence in the app and on the ranking path: no screen has a field for your weight, no table has a column for it, and none of the scoring formulas that would need one are in this version. Two numbers we do hold are worked out from a bodyweight, on a meet you claim from a public dataset, and the Bodyweight section below names them rather than leaving you to find them.
The app declares exactly one photo entitlement, and it is add-only. When you choose Save Image from the share sheet on your own Card, iOS writes that one image to your photo library. The app cannot read your photo library and never asks to.
03What we collect
This list is meant to be complete. It is written from the database, table by table, so if something is not named here then GBNETWORK is not holding it.
Your account
- The Apple sign-in identifier for your account, and the email address Apple relays to us. Sign in with Apple is the only way in, so we never see an Apple password, and if you chose Hide My Email then the address we hold is Apple’s relay rather than yours.
- Your display name, 2 to 14 characters, which is the name a board row carries.
- Your year of birth. The app asks for a date of birth on this phone, works out your exact age there, and sends only the year.
- Your home gym, and every gym you join.
- Your profile visibility setting, and whether you read weights in kilograms or in pounds.
- Your scoring category, if you set one.
- Your judge record: how many sets you have cosigned, and how many different lifters you have counted for.
The database has a column for a handle and a column for an avatar image path. No screen in this version writes either one, so both stay empty, and there is no photo anywhere on a profile.
Your lifting
- Your attempts: the movement, the rung, the gym, the nominal load, the actual mass on the bar to a hundredth of a kilogram, the reps you claimed, the reps that were counted, the tier and the times.
- The sets you log in the app to set a rung, and the personal records worked out from them.
- The rungs you have locked for the period, where each one was seeded from, and the estimate it was seeded at.
- Your board rows, each carrying your display name as it stood when the row was written.
- Your check-ins: which gym, when one started, and when it ended.
Witnessing
- The attestations you issue: which set, your display name as it stood at the moment you signed, the count you gave, and the time.
- Every time you enter a witness code: whether it worked, and when you tried. That is how a six-digit code is rate limited against guessing.
What you import or claim
- What your Hevy or Strong export produced: for each movement we could recognise, the movement we matched it to, your best set on it (the load, the reps and the date), an estimate of your one-rep max from that set, how many sets of it the file held, and whether it was trending up or down. Plus how many sessions the file covered, how long a span it ran over, and the names of any movements we could not match. The rung itself is worked out on the server from that summary rather than sent from the phone. The export file is read on this phone and is never uploaded.
- A record of the import: how many rows were read, how many were used, how many were skipped, and the exercise names we could not map.
- Any OpenPowerlifting entry you claim: the name that appears in that public dataset, the meet, the date, the federation, the equipment, the total, the two federation scores that entry carries beside the total (DOTS and GoodLift), and the moment you claimed it. For most people the name in that dataset is their legal name. Both of those scores are worked out from a bodyweight, and the Bodyweight section says so plainly and says who can read them.
Safety and moderation
- The accounts you block.
- Anything you report: what you reported, the category you chose, and the reason you wrote, up to 500 characters. We also hold the reference code we give that report, how urgent it was rated, when we picked it up and how it was resolved.
- Whether your account is suspended, until when, and the note saying why.
- If we ever stop an account from filing further reports because it has been filing false ones, the fact of that, until when, and the reason.
- Every moderation action we take, in a record that is added to and never edited: what was done, to what, who did it, the reason, and what the action overwrote, which can include a display name we replaced. This is the one record in the product that is never changed and never deleted, and the section on deleting your account explains why.
Text you save into a display name, a handle or a workout note is checked against a list of prohibited words at the moment you save it. The check happens on the server, it either accepts the text or refuses it, and it stores nothing beyond the text you were already saving.
That is the whole list. There is no advertising identifier, no device fingerprint, no contact list, no Apple Health data, no crash reporter and no analytics event of any kind, because there is no analytics in the app to raise one.
04What never leaves your phone
Some of what the app handles is deliberately never sent anywhere. This is that list.
- The full date of birth you enter at onboarding. The phone works out your age from it and sends the year alone.
- The name Apple offers the app at sign-in. GBNETWORK asks Apple for it, uses it as a suggested display name, and never uploads it. Change the suggestion and the name Apple gave is not used at all.
- The CSV file you import. It is parsed on the device, and the summary of what it found is what travels.
- The Card image you build to share a result. It is drawn on the device and handed to the iOS share sheet. We never receive a copy.
- Your session, which is stored encrypted on this phone with the key held in the iOS keychain, so a copy of the app’s storage without the keychain is unreadable.
05What we never collect
- Location. The app asks for no location permission of any kind. There is no map, no presence feed and no friend finder.
- Camera and photos. The app has no camera permission and no photo picker. Nothing is filmed here, at any tier, ever.
- Your bodyweight. No screen asks for it and no table has a column for it. The Bodyweight section names the two numbers we do hold that are worked out from one, on a meet you claim, and says who can read them.
- Your height, and your date of birth past the year we keep from it. Scoring category, which the Bodyweight section describes, is optional and is the one field here that is about sex.
- Contacts, health data and advertising identifiers.
- Payment details. There is nothing to buy.
06Why we have it, and on what basis
Our basis is your consent, which PIPEDA requires to be meaningful and given at or before collection. Nothing here is collected for advertising, for profiling or for resale, and none of it is used for a purpose this section does not name.
- Account and sign-in
- So the account is yours, and so only you can post as you.
- Year of birth
- To apply the 16 and over rule, which is the app’s age rating and a condition of appearing on a board.
- Display name
- Because a result with nobody’s name on it is not a result anyone can stand behind.
- Home gym and memberships
- A board is gym scoped, so membership is what decides who can read a row.
- Attempts and board rows
- These are the competition record. They are the product.
- Sets you log, and records
- To place you on the ladder, and to show you your own history.
- Locked rungs
- A rung is locked for the period so that sandbagging cannot pay.
- Check-ins
- So the server can decide whether a witness and a lifter were plausibly at the same gym on the same day.
- Attestations
- A cosign is a second identified account putting their name to a count. The name is the content.
- Witness-code attempts
- To rate limit a six-digit code against being guessed.
- Imports and claims
- To place you on the ladder from history you already have, so you do not start at the bottom.
- Blocks and reports
- So you can take somebody off your screens yourself, and so we can act on conduct.
- Suspension state
- So an account we have suspended cannot post while it is suspended, and so the suspension can be lifted.
- The moderation record
- So an action can be explained to the person it was taken against, and reversed if we got it wrong.
You can withdraw your consent at any time by deleting your account, and the section on deletion says exactly what that does and what it cannot undo.
07Who can see what
Only you can read these, and the database enforces it row by row rather than the screen hiding them: the sets you log here, the records built from them, your locked rungs, your import record, the parsed result behind it, your check-ins, your blocks, and your witness-code attempts. No other lifter can read any of them at any visibility setting. The reports you file are readable by you and by us.
Your profile is private by default, in line with Quebec’s Law 25 section 9.1. A new account is set to Private, and at that setting no other lifter can read your profile: not your home gym, not your scoring category, and not your judge record. Settings has a Profile visibility row, and changing it from Private to My gym is what lets lifters who train where you train read those fields. You can change it back. No setting in this app puts your profile outside GBNETWORK.
Private is about your profile, not about your results. A board row is a separate record and it keeps your display name on it, so posting to a board shows that name to the lifters at that gym whatever your visibility is set to. If you do not want a result seen, do not post it.
Lifters who are members of the same gym can read your board rows, which carry your display name, the movement, the rung, the load, the reps and the tier of the set, and they can read the attempts you have had scored at that gym. A cosigned set is marked ATTESTED. It is never called verified, and it is not offered as proof that anyone was present: a cosign records that a second identified account entered a count with your consent, and nothing more.
Rows from an imported or claimed history are the exception. Nobody but you sees those on a board, because a row out of a CSV is not a result.
A meet you claim from the OpenPowerlifting data follows your profile rather than your board. It carries the name that appears in that public dataset, the federation, the date and the total, and lifters who train where you train can read it only while they can read your profile. At Private, nobody else in the app can see one at all.
A cosign is stored on the set it counted. It is one row attached to your set rather than a second copy kept inside the other person’s account, and what their own cosign history shows is that same row read from their side. Your name is not on it; theirs is. When you count a set for someone else, your display name is copied onto that attestation as it stood at the moment you signed, and it stays there. That is the point of putting two names on a number. The two directions of leaving are not symmetrical, and the section on deletion gives both: if the witness deletes their account the cosign stays on your set with their name replaced, and if you delete yours the set goes and the cosign on it goes with the set, which takes it out of their history too.
Blocking someone removes each of you from the other’s boards, hides each of you from the other’s profile and cosigns, stops them entering your code to cosign your set, and stops you entering theirs. Your check-in is not part of it, because a check-in was never something another lifter could read in the first place.
We can read the database, because somebody has to operate the app and answer reports. Nobody else can. There is no analytics provider, no advertising network, no data broker and no third party holding a copy. Nothing is sold and nothing is shared for anyone else’s purposes.
The moderation record is narrower still: the database refuses to return a single row of it to any account that is not an operator account, and no screen in the app reads it. The one thing from it a lifter ever sees is the reference code on a report they filed themselves, which is there so they can quote it back to us. You will never be told what happened to somebody else’s account, because that is their business and not yours.
08Checking in
Checking in at a gym is an authorisation fact. It is a flag the server reads when someone enters your witness code, so that a witness and a lifter are plausibly at the same gym on the same day. It is not a location reading, it is something you tell us rather than something we detect, and there is no screen anywhere in this app that lists who is at a gym right now. No other lifter can read your check-in, so there is nothing here for anyone to watch.
A check-in expires ninety minutes after it starts, and you can end one early from the same screen you started it on. Either way it stops authorising anything the moment it closes, and the row itself is deleted two hours after the point it would have expired, because an ended check-in that was kept would still be a permanent record of which building you were in and when.
09Bodyweight
GBNETWORK never asks you what you weigh. There is no field for it on any screen, no table in the database has a bodyweight column, and the scoring formulas that would need one are not in this version of the app. Nothing on a board, on a Card or in a rank is computed from a bodyweight. Your starting rung comes from your own lifting history, or from one calibration set if you have no history to import, and neither of those needs your weight.
There is one exception, and it is why this section is longer than that paragraph. When you claim a meet from the public OpenPowerlifting dataset, we copy that entry as the dataset holds it, and the entry carries two federation scores beside the total: DOTS and GoodLift. Each of those is the total multiplied by a coefficient read off the bodyweight you weighed in at, so a score stored beside its total implies that bodyweight to anybody who does the arithmetic. We copy them because a claim is a copy of a public record rather than a form you can type a number into. No screen in the app shows either score, nothing is ranked or seeded by them, and they describe one competition day you chose to claim rather than what you weigh now. They sit on the claim, so they have the claim’s audience and no wider one: you, and lifters who train where you train for as long as they can read your profile. At Private no other lifter can read them at all. Deleting the claim deletes them, and deleting your account deletes every claim you made.
Everyone standing on a rung puts the identical load on the bar and counts reps, whoever they are. There is no strength formula and no bodyweight adjustment in that comparison, which is why nothing here needs to know what you weigh.
Scoring category is the one related field, and it is optional. It is a men’s or a women’s category, and it is the only field in the product that is about sex. It picks a coefficient row and does nothing else: nothing is seeded from it and nothing is ranked by it. It sits on your profile like every other field there, so it follows your visibility setting, and at Private no other lifter can read it. You can leave it unset and lift every week without it.
10How long we keep it
PIPEDA principle 5 asks for a stated maximum rather than a sentence about keeping things as long as necessary, so here is the schedule, record by record.
- Account and profile
- Until you delete your account. There is no automatic expiry.
- Attempts, board rows, attestations, locked rungs, logged sets, personal records, memberships, claimed meets, import records, blocks
- Until you delete your account. These are the competition record, and a record that expired on a timer would not be one.
- Check-ins
- Deleted two hours after the point the check-in expires, which is ninety minutes after it starts.
- Witness-code attempts
- Deleted seven days after the attempt.
- The parsed import result
- Deleted thirty days after it was created, whether or not you ever claimed it. Deleting your account deletes it at once.
- Reports
- Kept after they are closed, so a pattern of conduct stays visible. Your identity comes off them when you delete your account.
- Suspension state on a profile
- Until you delete your account, or until we lift the suspension and note that we did.
- A mute on an account that files false reports
- The mute expires on the date it was set for. The record that it was set is part of the moderation record below.
- The moderation record
- Indefinitely. It is added to and never edited or deleted, it survives the deletion of the account it is about, and the section on deleting your account says why.
- Your session on this phone
- Until you sign out, delete the app, or delete your account.
Those clocks are enforced by scheduled jobs rather than at the instant they run out: the check-in sweep runs every fifteen minutes and the other two run once a day, so a row can outlive the time above by up to one sweep before it is removed.
11Where it lives
Your data sits in one Postgres database operated for us by Supabase, and in the file storage attached to it. The app talks to it over TLS. We keep no copy anywhere else: there is no data warehouse, no spreadsheet export and no third-party customer tool with a view of it.
The production database is to be created in Supabase’s Canada (Central) region, which is in Montreal, Quebec, so that it stays in Canada and inside Quebec for Law 25 purposes. If it is ever hosted in another region this section names that region before the change applies, and if that region is outside Quebec we will complete the privacy impact assessment Law 25 requires for it first.
GBNETWORK has not launched. At the time this version was written there is no production database and no account can exist yet, so nothing described in this policy is holding anybody’s data today.
The design reserves four file buckets, for avatars, share cards, imports and printed boards, and no screen in this version of the app writes to any of them: the Card is drawn on the device, the CSV is parsed on the device, and there is no photo upload anywhere. The buckets are not created by the app, and they are not part of the database setup it ships with, so on this build they do not exist at all. If they are ever created, nothing in this version would put a file in one.
12Deleting your account
Settings has Delete account. It runs inside the app, it needs no email to us first, there is no deactivated state to come back to, and it cannot be undone.
Deleted outright: your account, your profile and the name you posted under, every attempt you posted, every board row those attempts produced, every set you logged here and the records built from them, your locked rungs, your gym memberships, your check-ins, your claimed meets, your blocks, your import records, the parsed result behind them, and the session on this device.
Two things survive on purpose, and the delete screen names both before you confirm.
The cosigns you gave other people
If you counted a set for another lifter, that attestation stays on their result with your name replaced by the word Withdrawn. The count you gave stays, and the tier of their set stays. There are two reasons. The set is their record and not yours to erase, and a witness who could delete a cosign on the way out could quietly demote somebody else’s finished result months after the fact. What goes is the identifying part: your name and the link to your account. What stays is that somebody counted it.
If you want your name off a cosign without deleting your account, write to inquiries@gbnetwork-app.com and ask. There is no button for it in this version. We replace the name with Withdrawn by hand, on the records you name or on all of them, and we tell you when it is done. We will not remove the count itself, because that would rewrite another lifter’s result.
The reports you filed
A report you sent us stays, in the queue or in its closed state, with your identity removed from it. The category and the reason you wrote remain, and the link to your account is gone. A report is about somebody else’s conduct, and closing your account should not close it.
The record of any moderation action about you
If we ever took an action on your account, for instance removing a result after a report or replacing a display name, the record of that action stays after you delete your account. It carries what was done, when, why, and what it overwrote, which can include the display name we replaced. It does not carry your attempts, your sets, your imports or anything else from the list above.
It stays for two reasons, and neither is convenience. An action taken against somebody has to be explainable to them, and a record that can be deleted by the person it is about is not one. And an account that was ejected and returns under a new sign-in is only recognisable at all from what was written down at the time. The record is append-only: we cannot quietly edit it either, and a correction to it is a new line rather than a rewritten one.
If we never took an action on your account, there is no such record and nothing survives here at all. Most accounts will never have one.
What does not survive, and one thing worth knowing
Nothing else of yours survives. Other lifters’ results and ranks do not change when you leave, because your rows are removed from the boards rather than reassigned to anybody.
One thing goes that you might not expect, and it belongs to somebody else. A cosign lives on the set it counted, so the cosigns other people signed on your sets are deleted with your sets. Their count of how many sets they have cosigned is not reduced when that happens, so after a deletion that number can be larger than the cosigns still on record behind it. The count is a tally of signatures given and it is not a link back to anything of yours.
A block is keyed to two accounts, so it ends when either account is deleted. If somebody you blocked deletes their account, your block on them goes with it, and a new sign-in would arrive with no block in place. That is a real limit of the design rather than an oversight, and it is why a report is worth filing as well as a block: a report stays with us.
13Your rights, and how to use them
A copy of your data
Settings has Export my data. It builds the file on this phone and hands it to your own mail app, in the body of a new message with the recipient left empty, so the copy goes only where you choose to send it. That means it needs a mail account set up on the phone, and the row says so when there is none.
The export covers your profile, your gym memberships, your locked rungs, your attempts, the cosigns you issued, your board rows, the sets you logged, your personal records, your import records and the parsed results behind them, your claimed meets, your check-ins, your blocks, the reports you filed, and your witness-code attempts. A section it cannot read is named in the file rather than dropped from it, so the export never looks complete when it is not.
Two things the export does not carry: the cosigns other people signed on your own sets, and any report somebody else filed about you. You can read the first on each result inside the app. Ask us in writing for either and we will send what we are allowed to send.
If you would rather we sent the copy, or you want something the export does not carry, write to inquiries@gbnetwork-app.com. We answer an access request within thirty days of receiving it. If we need longer we will tell you inside those thirty days, take the one further extension of up to thirty days that PIPEDA allows, and say why we needed it.
Portability
Law 25 gives you the right to receive the personal information you gave us in a structured, commonly used technological format. The export is JSON, which is that, and it is built from the database grants rather than from whatever a screen happens to show.
Correction
Tell us what is wrong and we will fix it. Two things are worth knowing about how a correction lands in this build, because neither is obvious.
- Changing your display name in Settings changes your profile, and the next result you post at a rung rewrites the name on that board row. It does not retroactively rewrite the board rows you already hold, and it never rewrites the name on a cosign you already signed, because both of those are snapshots taken at the moment they were written. Ask us and we will rewrite both: we have an operator tool that does it in one pass and tells us how many rows it touched. What we cannot do is rewrite them without leaving a line in the moderation record saying that we did.
- Your year of birth cannot be changed in the app at all. It is written once, at onboarding. If it is wrong, write to us.
Withdrawing consent
Delete your account. That is the withdrawal, and the section above says exactly what it does.
Stopping dissemination, and de-indexing
Law 25 section 28.1 lets you ask us to stop disseminating your personal information, or to de-index a link to it, where the dissemination contravenes the law or causes you serious injury to reputation or privacy that outweighs the public interest in it. Nothing in GBNETWORK is published to the open web and nothing in it is indexed by a search engine: a board is readable only by signed-in members of the same gym, and this website carries no lifter’s data at all. So in practice the remedy here is removal inside the app, which means the deletion path or the by-hand withdrawal of a name from a cosign. Write to inquiries@gbnetwork-app.com and say what you want stopped.
14When we can refuse
PIPEDA lets us withhold part of what you ask for, and in two cases we will.
- Where answering would reveal personal information about another person. The clearest case is a report somebody else filed about you, whose reason text can identify the person who wrote it. We sever what we can and give you the rest.
- Where we are not permitted to say. If a request touches something we are legally barred from disclosing, we will tell you we are withholding and on what ground.
There is one limit on erasure rather than on access, and it is worth stating in the same place. The moderation record cannot be edited or deleted by anybody, including us: the database refuses the write. If you believe a line in it is wrong, tell us and we will add a line saying so, which is the only correction an append-only record can take.
If we refuse, we say so in writing, we say why, and we tell you that you can take it to the Office of the Privacy Commissioner of Canada, or to the Commission d’accès à l’information du Québec if you live in Quebec.
15Complaints
Write to inquiries@gbnetwork-app.com first. One person reads that inbox and will answer you.
If that does not resolve it, you can complain to the Office of the Privacy Commissioner of Canada, which oversees PIPEDA. If you live in Quebec you can complain to the Commission d’accès à l’information du Québec, which oversees Law 25. Both take complaints directly, and neither of them requires you to come through us first.
16A breach
If personal information we hold is lost, taken or exposed in a way that creates a real risk of significant harm to you, we will report it to the Office of the Privacy Commissioner of Canada, notify you directly, and keep a record of the breach. That is what PIPEDA section 10.1 requires. If you live in Quebec we will also notify the Commission d’accès à l’information du Québec.
What we will tell you: what was taken, when, what we have done about it, and what you can do. We will not wait until we are certain of every detail before telling you that something happened.
17Sixteen and older
GBNETWORK is for people 16 and older. That is the app’s declared age rating and a condition of appearing on a board.
How the check works: the app asks for your date of birth, works out your exact age on this phone, and refuses to create the account if you are under 16. Only the year is sent to the server, and the server re-checks the rule against that year. So the phone checks your exact age and the server checks to the year.
We do not knowingly keep an account for anyone under 16, and an account we learn belongs to somebody younger is deleted. If you are a parent or guardian and believe your child has an account here, write to inquiries@gbnetwork-app.com and we will remove it. Law 25 requires parental consent for people under 14, which this product does not reach, because nobody under 16 can have an account at all.
If you are 16 or 17
The age of majority in Ontario is 18, and these documents are an agreement, so if you are under 18 we ask you to read the Terms and this policy with a parent or guardian before you make an account.
Nothing in the app treats a 17 year old differently from a 25 year old: the same board, the same gym scope, the same Private profile by default. The one thing worth saying plainly is what attestation means for a minor. Cosigning a set attaches your display name to another person’s record and leaves it there, other members of that gym can read it, and there is no button in this version that takes it off again: deleting your account, or asking us to withdraw it by hand, replaces that name with Withdrawn rather than removing the record. Decide to cosign with that in mind.
19Changes
This policy can change. The effective date at the top is the version you are reading, and the Terms carry the same date.
When a change matters we will put a notice in the app before the new version applies. What this build cannot do is prove which version you read: nothing in it records a policy version against your account. So the effective date is the thing to check, and if it has moved, the document has moved with it.
20Contact
Write to inquiries@gbnetwork-app.com for access, correction, a copy of your data, taking your name off a cosign, a complaint, or anything else in this document. One person reads it.
The same address is on the legal row and the report row inside the app, so you can reach us without leaving it.
The rules for using GBNETWORK are in the Terms. Both documents carry the effective date at the top of this page, and both are in the app under Settings, Legal.