Privacy Policy
Last updated 11 September 2026
The short version
UNIsport is a fitness app for university students. To work, it needs to know who you are, what you like to train, and who you train with. We collect what the app needs for that and nothing else. We do not sell your data, we do not run ads, and we do not hand your information to your university. The one exception is deliberate and you choose it: if you join a varsity team, your coach sees your training on that team.
UNIsport is an independent product. It is not affiliated with, endorsed by, or operated by Harvard University or any other university.
Who is responsible for your data
UNIsport is operated by Martin Houska, based in the Czech Republic, who is the data controller for everything described here. For any privacy question, correction, or deletion request, email martinhouska777@gmail.com.
What we collect
Account details. Your email address and a password. Passwords are stored only as a salted hash by our authentication provider — we never see or store your actual password. If you sign in with Google instead, we receive your email address, your name, and your Google profile picture. We do not receive your Google password. Signing in with Google does not give us access to your Gmail, Drive, Calendar, or contacts — the separate, optional Drive permission used by varsity video has its own section below.
Your profile. What you enter during onboarding and later edit on your profile:
- Name, class year, sex, and campus residence or house
- Concentration, hometown country, languages, and interests
- A short bio and a profile photo, if you add them
- Training details — your main activity, experience level, split, preferred gyms, weekly schedule, and running or cardio details
- Partner and mentoring preferences
- Personal records, if you add them
Training activity. Sessions you log: the date, activity type, gym, who you trained with, exercises with sets, reps and weights, distance and duration, notes, and any photos you attach.
Social activity. Direct messages, posts in community channels, session plans you propose or accept, buddy board posts, who you follow, and who you record as a training partner.
Gym crowd reports. If you tap how busy a gym is, we store that answer with your account and the time. Other students at your school see it only as a level and a count (“2 people said Busy”), never your name, and it stops being shown after two hours.
Notifications. If you turn on push notifications, we store the subscription your browser issues and your browser's user-agent string, so we can deliver notifications to the right device. If you leave the log reminder on, we also record the day each reminder was sent, so you are never sent two in one day.
Varsity athletes. If your team uses UNIsport, this also covers training plans, session logs, race results, lineups, and the notes your coach writes about you.
Photos of an erg monitor. If you use the camera to read a workout off a rowing machine, that photo is sent to Anthropic, who read the numbers off the screen and return them to the app. We do not store the photo.
Stored only on your device. Your gym favourites, gym ratings, and the email address of your last sign-in stay in your browser's local storage and are not sent to our servers. Clearing your browser data removes them.
Why we are allowed to use it
Under UK and EU data protection law we have to say what entitles us to hold each kind of data. In plain terms:
- Your account, profile, matches, messages and logs — because you asked us to give you the app, and it cannot work without them.
- Your training details, personal records, session logs and the photos you attach — with your consent. Some of it says something about your body and your health, which the law treats as a special category, so we hold it only because you chose to enter it, and you can remove it, or your whole account, at any time.
- Push notifications — with your consent, given when your browser asks and withdrawn by turning them off.
- Keeping the app working, safe, and free of abuse — our legitimate interest in running a service people can trust.
What other people can see
Other signed-in UNIsport users can see your profile: your name, photo, class year, residence, training details, bio, and interests. This is the point of the app — it is how people find a training partner.
Your session photos and personal records are shown on your public profile only if you leave those sections switched on. You can turn either off from your profile at any time.
Your logged sessions, direct messages, and notification settings are private to you and, where relevant, the person you exchanged them with. Posts in community channels are visible to everyone in that channel.
If you are on a varsity team. Your coach sees your team training: the sessions you log against the team plan, your results, the lineups you are in, the videos uploaded for your crew, and the notes they write about you. Your teammates see your name, photo, the lineups you share with them, and what is published to the whole squad. What happens on the student side of the app — your matches, your direct messages, and the community feed — is not part of the coach's console.
Who we share it with
We do not sell your data and we do not share it for advertising. We use a small number of service providers to run the app, and they only process data on our behalf:
- Supabase — database, accounts, and authentication
- Vercel — hosting and delivery of the website
- Google — if you choose to sign in with Google, and for the varsity video upload described below
- Anthropic — only for reading a photo of an erg monitor, when you use that feature
- Your browser's push service (Apple, Google, or Mozilla, depending on your device) — only if you enable notifications
We may also disclose information if we are legally required to, or where it is necessary to protect someone's safety.
Google Drive, and your crew's videos
This applies only to varsity teams, and only if you upload a video. It is optional — the rest of the app never asks for it.
A crew's videos belong to the squad, not to us, so they go into the squad's own Google Drive folder rather than onto our servers. To put a file into a folder your team already made, Google requires the broad Drive permission: the narrower one only ever sees files the app itself created, which is not where your team keeps its videos.
We use that permission for exactly two things, and nothing else:
- creating the dated folders for a session inside your team's folder, if they are not there yet;
- uploading the video you picked, and giving it a link your teammates can open.
We do not read, list, download, or index anything else in your Drive, and no other file of yours is ever copied to our servers. The permission itself is a short-lived key that lives in the tab you are using, expires within the hour, and is never sent to us or stored by us. You can withdraw it at any time at myaccount.google.com/permissions.
One thing to know before you upload: so that teammates can actually watch a clip, the app asks Drive to make that file viewable by anyone who has its link. The link is only shown inside your team's part of the app, but treat it as you would any shareable link. The file stays in your team's Drive, under your team's control — deleting it there deletes it, and we cannot bring it back.
Where your data is stored
Our database and accounts are hosted by Supabase on servers in the United States (AWS, Northern Virginia). The website itself is delivered by Vercel's global network. Videos are stored in your team's Google Drive, wherever Google holds it.
If you are in the UK or EU, that means your data leaves the UK and the EEA. Those transfers are covered by our providers' data processing agreements, which include the European Commission's standard contractual clauses.
How long we keep it
We keep your data for as long as your account exists. If you ask us to delete your account, we remove your profile, logs, messages, and posts. Some records may persist briefly in routine backups before being overwritten. Videos in your team's Google Drive are not ours to delete — ask whoever administers that folder.
Your rights
You can view and edit most of your information directly in the app, from your profile. You can also ask us to give you a copy of your data, correct it, or delete it entirely — email the address above and we will action it. If you are in the UK or EU, you have these rights under the GDPR, including the right to withdraw consent at any time and the right to complain to your local data protection authority.
Security
Data is transmitted over HTTPS and stored with access rules that restrict each row to the people entitled to see it. No system is perfectly secure, but we do not store passwords in readable form and we keep the data we collect to what the app genuinely needs.
Children
UNIsport is intended for university students. It is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will remove it.
Changes to this policy
If we change what we collect or how we use it, we will update this page and change the date at the top. Significant changes will be flagged in the app.